Description

A Helm chart for velero

Overview

IdentityNamespaceAutomountSecretsPermissionsWorkloadsRisk
velero-serverdefault11Critical
velero-server-upgrade-crdsdefault11Low

Numbers in the last two columns indicate how many bindings or workloads involve each ServiceAccount.


Identities

🤖 velero-server

Namespace: default  |  Automount:

🔑 Permissions (1)

RoleResourceVerbsRiskTags
Role velero-server/*CriticalAvailabilityImpact BindingToPrivilegedRole CodeExecution ConfigMapAccess ControlPlaneDisruption (+40 more)

⚠️ Potential Abuse (39)

The following security risks were found based on the above permissions:

📦 Workloads (1)

KindNameContainerImage
Deploymentvelerovelerovelero/velero:v1.16.1

🤖 velero-server-upgrade-crds

Namespace: default  |  Automount:

🔑 Permissions (1)

RoleResourceVerbsRiskTags
ClusterRole velero-upgrade-crdsapiextensions.k8s.io/customresourcedefinitionscreate · get · list · patch · updateLow

⚠️ Potential Abuse (1)

The following security risks were found based on the above permissions:

📦 Workloads (1)

KindNameContainerImage
Jobvelero-upgrade-crdsvelerovelero/velero:v1.16.1