Description

Helm Chart for Capsule Proxy, addon for Capsule, the multi-tenant Operator

Overview

IdentityNamespaceAutomountSecretsPermissionsWorkloadsRisk
capsule-proxy-crdsdefault21Low
capsule-proxydefault02

Numbers in the last two columns indicate how many bindings or workloads involve each ServiceAccount.


Identities

🤖 capsule-proxy-crds

Namespace: default  |  Automount:

🔑 Permissions (2)

RoleResourceVerbsRiskTags
ClusterRole capsule-proxy-crdsapiextensions.k8s.io/customresourcedefinitionscreate · delete · get · patchLow
ClusterRole capsule-proxy-crdscore/jobscreate · deleteLow

⚠️ Potential Abuse (1)

The following security risks were found based on the above permissions:

📦 Workloads (1)

KindNameContainerImage
Jobcapsule-proxy-crdscrds-hookdocker.io/clastix/kubectl:v1.20

🤖 capsule-proxy

Namespace: default  |  Automount:

🔑 Permissions (0)

No explicit RBAC bindings.

📦 Workloads (2)

KindNameContainerImage
Deploymentcapsule-proxycapsule-proxyghcr.io/projectcapsule/capsule-proxy:v0.9.8
Jobcapsule-proxy-certgenpost-install-jobregistry.k8s.io/ingress-nginx/kube-webhook-certgen:v1.5.4