kube-prometheus-stack collects Kubernetes manifests, Grafana dashboards, and Prometheus rules combined with documentation and scripts to provide easy to operate end-to-end Kubernetes cluster monitoring with Prometheus using the Prometheus Operator.
RBAC Atlas is a curated database of identities and the Role Based Access Control (RBAC) policies associated with them in popular Kubernetes open-source projects. Each entry includes security annotations that highlight granted permissions, potential risks, and possible abuse scenarios.
Why is RBAC important? RBAC is the final layer of defense in Kubernetes security. If workloads are compromised and an identity is stolen, a misconfigured or overly permissive RBAC policy (common with Operators) can enable attackers to move laterally within your cluster, potentially leading to a complete Kubernetes cluster takeover.
RBAC Atlas is a collaborative project created by Lenin Alevski, and contributions of additional RBAC rules are welcome. Check out the source on GitHub: rbac-scope (the CLI tool) and rbac-atlas (this website).
🚀 Top Risks
📦 Top Categories
monitoring operator kubernetes prometheus metric observability database edp alerting metrics timeseries metricsql tsdb victoriametrics ci kube-prometheus cluster argoproj gitops authentication See All →
📜 All Projects
kube-state-metrics
v7.1.0Install kube-state-metrics to generate and expose cluster-level metrics
kubernetes-dashboard
v7.14.0General-purpose web UI for Kubernetes clusters
kubestash-operator
v0.23.0-rc.0KubeStash, Kubernetes native backup operator by AppsCode
kubevault-operator
v0.24.0-rc.0KubeVault Operator by AppsCode - HashiCorp Vault operator for Kubernetes
kubevious
v1.2.2A Helm chart for Kubevious
kured
v5.11.0A Helm chart for kured
kyverno
v3.7.0-rc.1Kubernetes Native Policy Management
lightrun-k8s-operator
v0.3.17A Helm chart for Lightrun k8s operator
limitador-operator
v0.16.0Kubernetes operator for managing Limitador instances, a rate limiting service to protect your APIs.