Description

Install Rancher Server to manage Kubernetes clusters across providers.

Overview

IdentityNamespaceAutomountSecretsPermissionsWorkloadsRisk
rancher-post-deletedefault171Low
rancherdefault01

Numbers in the last two columns indicate how many bindings or workloads involve each ServiceAccount.


Identities

🤖 rancher-post-delete

Namespace: default  |  Automount:

🔑 Permissions (17)

RoleResourceVerbsRiskTags
ClusterRole rancher-post-deleterbac.authorization.k8s.io/clusterrolebindingscreate · delete · get · listLow
ClusterRole rancher-post-deleterbac.authorization.k8s.io/clusterrolescreate · delete · get · listLow
ClusterRole rancher-post-deletecore/configmapsdelete · get · listLow
ClusterRole rancher-post-deleteapps/deploymentsdelete · get · listLow
ClusterRole rancher-post-deleteextensions/deploymentsdelete · get · listLow
ClusterRole rancher-post-deletenetworking.k8s.io/ingressesdeleteLow
ClusterRole rancher-post-deletecert-manager.io/issuersdeleteLow
ClusterRole rancher-post-deletebatch/jobscreate · delete · get · list · watchLow
ClusterRole rancher-post-deleteadmissionregistration.k8s.io/mutatingwebhookconfigurationsdelete · get · listLow
ClusterRole rancher-post-deletenetworking.k8s.io/networkpoliciesdelete · get · listLow
ClusterRole rancher-post-deletecore/podsdelete · get · listLow
ClusterRole rancher-post-deleterbac.authorization.k8s.io/rolebindingscreate · delete · get · listLow
ClusterRole rancher-post-deleterbac.authorization.k8s.io/rolescreate · delete · get · listLow
ClusterRole rancher-post-deletecore/secretsdelete · get · listLow
ClusterRole rancher-post-deletecore/serviceaccountscreate · delete · get · listLow
ClusterRole rancher-post-deletecore/servicesdelete · get · listLow
ClusterRole rancher-post-deleteadmissionregistration.k8s.io/validatingwebhookconfigurationsdelete · get · listLow

⚠️ Potential Abuse (1)

The following security risks were found based on the above permissions:

📦 Workloads (1)

KindNameContainerImage
Jobrancher-post-deleterancher-post-deleterancher/shell:v0.4.1

🤖 rancher

Namespace: default  |  Automount:

🔑 Permissions (0)

No explicit RBAC bindings.

📦 Workloads (1)

KindNameContainerImage
Deploymentrancherrancherrancher/rancher:v2.11.2