Description

A Traefik based Kubernetes ingress controller

Overview

IdentityNamespaceAutomountSecretsPermissionsWorkloadsRisk
traefikdefault211Critical

Numbers in the last two columns indicate how many bindings or workloads involve each ServiceAccount.


Identities

🤖 traefik

Namespace: default  |  Automount:

🔑 Permissions (21)

RoleResourceVerbsRiskTags
ClusterRole traefik-defaultcore/secretsget · list · watchCriticalClusterWideSecretAccess CredentialAccess DataExposure InformationDisclosure SecretAccess
ClusterRole traefik-defaultcore/configmapsget · list · watchHighConfigMapAccess DataExposure InformationDisclosure
ClusterRole traefik-defaultdiscovery.k8s.io/endpointsliceslist · watchLow
ClusterRole traefik-defaultextensions/ingressclassesget · list · watchLow
ClusterRole traefik-defaultnetworking.k8s.io/ingressclassesget · list · watchLow
ClusterRole traefik-defaultextensions/ingressesget · list · watchLow
ClusterRole traefik-defaultnetworking.k8s.io/ingressesget · list · watchLow
ClusterRole traefik-defaultextensions/ingresses/statusupdateLow
ClusterRole traefik-defaultnetworking.k8s.io/ingresses/statusupdateLow
ClusterRole traefik-defaulttraefik.io/ingressroutesget · list · watchLow
ClusterRole traefik-defaulttraefik.io/ingressroutetcpsget · list · watchLow
ClusterRole traefik-defaulttraefik.io/ingressrouteudpsget · list · watchLow
ClusterRole traefik-defaulttraefik.io/middlewaresget · list · watchLow
ClusterRole traefik-defaulttraefik.io/middlewaretcpsget · list · watchLow
ClusterRole traefik-defaultcore/nodesget · list · watchLow
ClusterRole traefik-defaulttraefik.io/serverstransportsget · list · watchLow
ClusterRole traefik-defaulttraefik.io/serverstransporttcpsget · list · watchLow
ClusterRole traefik-defaultcore/servicesget · list · watchLow
ClusterRole traefik-defaulttraefik.io/tlsoptionsget · list · watchLow
ClusterRole traefik-defaulttraefik.io/tlsstoresget · list · watchLow
ClusterRole traefik-defaulttraefik.io/traefikservicesget · list · watchLow

⚠️ Potential Abuse (5)

The following security risks were found based on the above permissions:

📦 Workloads (1)

KindNameContainerImage
Deploymenttraefiktraefikdocker.io/traefik:v3.4.1