Description

A Helm chart to deploy the Capsule Operator for easily implementing, managing, and maintaining mutitenancy and access control in Kubernetes.

Overview

IdentityNamespaceAutomountSecretsPermissionsWorkloadsRisk
capsuledefault23Medium

Numbers in the last two columns indicate how many bindings or workloads involve each ServiceAccount.


Identities

🤖 capsule

Namespace: default  |  Automount:

🔑 Permissions (2)

RoleResourceVerbsRiskTags
ClusterRole capsule-proxy-roleauthorization.k8s.io/subjectaccessreviewscreateMediumInformationDisclosure RBACQuery
ClusterRole capsule-proxy-roleauthentication.k8s.io/tokenreviewscreateMediumCredentialAccess InformationDisclosure RBACQuery

⚠️ Potential Abuse (3)

The following security risks were found based on the above permissions:

📦 Workloads (3)

KindNameContainerImage
Deploymentcapsule-controller-managermanagerghcr.io/projectcapsule/capsule:v0.3.3
Jobcapsule-rbac-cleanerpre-delete-jobdocker.io/clastix/kubectl:v1.20
Jobcapsule-waiting-certspost-install-jobdocker.io/clastix/kubectl:v1.20