Cluster Overview: https://10.43.0.1:443

Mostly smooth sailing
Grade: B+
Score: 88%

Score is the percentage of passing checks. Warnings get half the weight of dangerous checks.

  • 808 passing checks
  • 68 warning checks
  • 71 dangerous checks
Some checks were skipped based on configured exemptions. Click here to view the report with these checks included.

Results by Category

EfficiencyScore: 69%

Configuring resource requests and limits for workloads running in Kubernetes helps ensure that every container will have access to all the resources it needs. These are also a crucial part of cluster autoscaling logic, as new nodes are only spun up when there is insufficient capacity on existing infrastructure for new pod(s). By default, Polaris validates that resource requests and limits are set, it also includes optional functionality to ensure these requests and limits fall within specified ranges. Refer to the Polaris documentation about Efficiency for more information.

ReliabilityScore: 78%

Kubernetes is built to reliabily run highly available applications. Polaris includes a number of checks to ensure that you are maximizing the reliability potential of Kubernetes. Refer to the Polaris documentation about Reliability for more information.

SecurityScore: 96%

Kubernetes provides a great deal of configurability when it comes to the security of your workloads. A key principle here involves limiting the level of access any individual workload has. Polaris has validations for a number of best practices, mostly focused on ensuring that unnecessary access has not been granted to an application workload. Refer to the Polaris documentation about Security for more information.

Filter by Namespace

Cluster Resources

ClusterRole: admin

Spec:

  • The ClusterRole does not allow pods/exec or pods/attach
ClusterRole: argocd-application-controller

Spec: no checks applied

ClusterRole: argocd-server

Spec: no checks applied

ClusterRole: cert-manager-cainjector

Spec:

  • The ClusterRole does not allow pods/exec or pods/attach
ClusterRole: cert-manager-cluster-view

Spec:

  • The ClusterRole does not allow pods/exec or pods/attach
ClusterRole: cert-manager-controller-approve:cert-manager-io

Spec:

  • The ClusterRole does not allow pods/exec or pods/attach
ClusterRole: cert-manager-controller-certificates

Spec:

  • The ClusterRole does not allow pods/exec or pods/attach
ClusterRole: cert-manager-controller-certificatesigningrequests

Spec:

  • The ClusterRole does not allow pods/exec or pods/attach
ClusterRole: cert-manager-controller-challenges

Spec:

  • The ClusterRole does not allow pods/exec or pods/attach
ClusterRole: cert-manager-controller-clusterissuers

Spec:

  • The ClusterRole does not allow pods/exec or pods/attach
ClusterRole: cert-manager-controller-ingress-shim

Spec:

  • The ClusterRole does not allow pods/exec or pods/attach
ClusterRole: cert-manager-controller-issuers

Spec:

  • The ClusterRole does not allow pods/exec or pods/attach
ClusterRole: cert-manager-controller-orders

Spec:

  • The ClusterRole does not allow pods/exec or pods/attach
ClusterRole: cert-manager-edit

Spec:

  • The ClusterRole does not allow pods/exec or pods/attach
ClusterRole: cert-manager-view

Spec:

  • The ClusterRole does not allow pods/exec or pods/attach
ClusterRole: cert-manager-webhook:subjectaccessreviews

Spec:

  • The ClusterRole does not allow pods/exec or pods/attach
ClusterRole: cluster-admin

Spec:

  • The ClusterRole does not allow pods/exec or pods/attach
ClusterRole: clustercidrs-node

Spec:

  • The ClusterRole does not allow pods/exec or pods/attach
ClusterRole: edit

Spec:

  • The ClusterRole does not allow pods/exec or pods/attach
ClusterRole: k3s-cloud-controller-manager

Spec:

  • The ClusterRole does not allow pods/exec or pods/attach
ClusterRole: local-path-provisioner-role

Spec:

  • The ClusterRole does not allow pods/exec or pods/attach
ClusterRole: polaris

Spec:

  • The ClusterRole does not allow pods/exec or pods/attach
ClusterRole: secrets-unsealer

Spec:

  • The ClusterRole does not allow pods/exec or pods/attach
ClusterRole: system:aggregate-to-admin

Spec:

  • The ClusterRole does not allow pods/exec or pods/attach
ClusterRole: system:aggregate-to-edit

Spec:

  • The ClusterRole does not allow pods/exec or pods/attach
ClusterRole: system:aggregate-to-view

Spec:

  • The ClusterRole does not allow pods/exec or pods/attach
ClusterRole: system:aggregated-metrics-reader

Spec:

  • The ClusterRole does not allow pods/exec or pods/attach
ClusterRole: system:auth-delegator

Spec:

  • The ClusterRole does not allow pods/exec or pods/attach
ClusterRole: system:basic-user

Spec:

  • The ClusterRole does not allow pods/exec or pods/attach
ClusterRole: system:certificates.k8s.io:certificatesigningrequests:nodeclient

Spec:

  • The ClusterRole does not allow pods/exec or pods/attach
ClusterRole: system:certificates.k8s.io:certificatesigningrequests:selfnodeclient

Spec:

  • The ClusterRole does not allow pods/exec or pods/attach
ClusterRole: system:certificates.k8s.io:kube-apiserver-client-approver

Spec:

  • The ClusterRole does not allow pods/exec or pods/attach
ClusterRole: system:certificates.k8s.io:kube-apiserver-client-kubelet-approver

Spec:

  • The ClusterRole does not allow pods/exec or pods/attach
ClusterRole: system:certificates.k8s.io:kubelet-serving-approver

Spec:

  • The ClusterRole does not allow pods/exec or pods/attach
ClusterRole: system:certificates.k8s.io:legacy-unknown-approver

Spec:

  • The ClusterRole does not allow pods/exec or pods/attach
ClusterRole: system:controller:attachdetach-controller

Spec:

  • The ClusterRole does not allow pods/exec or pods/attach
ClusterRole: system:controller:certificate-controller

Spec:

  • The ClusterRole does not allow pods/exec or pods/attach
ClusterRole: system:controller:clusterrole-aggregation-controller

Spec:

  • The ClusterRole does not allow pods/exec or pods/attach
ClusterRole: system:controller:cronjob-controller

Spec:

  • The ClusterRole does not allow pods/exec or pods/attach
ClusterRole: system:controller:daemon-set-controller

Spec:

  • The ClusterRole does not allow pods/exec or pods/attach
ClusterRole: system:controller:deployment-controller

Spec:

  • The ClusterRole does not allow pods/exec or pods/attach
ClusterRole: system:controller:disruption-controller

Spec:

  • The ClusterRole does not allow pods/exec or pods/attach
ClusterRole: system:controller:endpoint-controller

Spec:

  • The ClusterRole does not allow pods/exec or pods/attach
ClusterRole: system:controller:endpointslice-controller

Spec:

  • The ClusterRole does not allow pods/exec or pods/attach
ClusterRole: system:controller:endpointslicemirroring-controller

Spec:

  • The ClusterRole does not allow pods/exec or pods/attach
ClusterRole: system:controller:ephemeral-volume-controller

Spec:

  • The ClusterRole does not allow pods/exec or pods/attach
ClusterRole: system:controller:expand-controller

Spec:

  • The ClusterRole does not allow pods/exec or pods/attach
ClusterRole: system:controller:generic-garbage-collector

Spec:

  • The ClusterRole does not allow pods/exec or pods/attach
ClusterRole: system:controller:horizontal-pod-autoscaler

Spec:

  • The ClusterRole does not allow pods/exec or pods/attach
ClusterRole: system:controller:job-controller

Spec:

  • The ClusterRole does not allow pods/exec or pods/attach
ClusterRole: system:controller:legacy-service-account-token-cleaner

Spec:

  • The ClusterRole does not allow pods/exec or pods/attach
ClusterRole: system:controller:namespace-controller

Spec:

  • The ClusterRole does not allow pods/exec or pods/attach
ClusterRole: system:controller:node-controller

Spec:

  • The ClusterRole does not allow pods/exec or pods/attach
ClusterRole: system:controller:persistent-volume-binder

Spec:

  • The ClusterRole does not allow pods/exec or pods/attach
ClusterRole: system:controller:pod-garbage-collector

Spec:

  • The ClusterRole does not allow pods/exec or pods/attach
ClusterRole: system:controller:pv-protection-controller

Spec:

  • The ClusterRole does not allow pods/exec or pods/attach
ClusterRole: system:controller:pvc-protection-controller

Spec:

  • The ClusterRole does not allow pods/exec or pods/attach
ClusterRole: system:controller:replicaset-controller

Spec:

  • The ClusterRole does not allow pods/exec or pods/attach
ClusterRole: system:controller:replication-controller

Spec:

  • The ClusterRole does not allow pods/exec or pods/attach
ClusterRole: system:controller:resource-claim-controller

Spec:

  • The ClusterRole does not allow pods/exec or pods/attach
ClusterRole: system:controller:resourcequota-controller

Spec:

  • The ClusterRole does not allow pods/exec or pods/attach
ClusterRole: system:controller:root-ca-cert-publisher

Spec:

  • The ClusterRole does not allow pods/exec or pods/attach
ClusterRole: system:controller:route-controller

Spec:

  • The ClusterRole does not allow pods/exec or pods/attach
ClusterRole: system:controller:selinux-warning-controller

Spec:

  • The ClusterRole does not allow pods/exec or pods/attach
ClusterRole: system:controller:service-account-controller

Spec:

  • The ClusterRole does not allow pods/exec or pods/attach
ClusterRole: system:controller:service-cidrs-controller

Spec:

  • The ClusterRole does not allow pods/exec or pods/attach
ClusterRole: system:controller:service-controller

Spec:

  • The ClusterRole does not allow pods/exec or pods/attach
ClusterRole: system:controller:statefulset-controller

Spec:

  • The ClusterRole does not allow pods/exec or pods/attach
ClusterRole: system:controller:ttl-after-finished-controller

Spec:

  • The ClusterRole does not allow pods/exec or pods/attach
ClusterRole: system:controller:ttl-controller

Spec:

  • The ClusterRole does not allow pods/exec or pods/attach
ClusterRole: system:controller:validatingadmissionpolicy-status-controller

Spec:

  • The ClusterRole does not allow pods/exec or pods/attach
ClusterRole: system:controller:volumeattributesclass-protection-controller

Spec:

  • The ClusterRole does not allow pods/exec or pods/attach
ClusterRole: system:coredns

Spec:

  • The ClusterRole does not allow pods/exec or pods/attach
ClusterRole: system:discovery

Spec:

  • The ClusterRole does not allow pods/exec or pods/attach
ClusterRole: system:heapster

Spec:

  • The ClusterRole does not allow pods/exec or pods/attach
ClusterRole: system:k3s-controller

Spec:

  • The ClusterRole does not allow pods/exec or pods/attach
ClusterRole: system:kube-aggregator

Spec:

  • The ClusterRole does not allow pods/exec or pods/attach
ClusterRole: system:kube-controller-manager

Spec:

  • The ClusterRole does not allow pods/exec or pods/attach
ClusterRole: system:kube-dns

Spec:

  • The ClusterRole does not allow pods/exec or pods/attach
ClusterRole: system:kube-scheduler

Spec:

  • The ClusterRole does not allow pods/exec or pods/attach
ClusterRole: system:kubelet-api-admin

Spec:

  • The ClusterRole does not allow pods/exec or pods/attach
ClusterRole: system:metrics-server

Spec:

  • The ClusterRole does not allow pods/exec or pods/attach
ClusterRole: system:monitoring

Spec:

  • The ClusterRole does not allow pods/exec or pods/attach
ClusterRole: system:node

Spec:

  • The ClusterRole does not allow pods/exec or pods/attach
ClusterRole: system:node-bootstrapper

Spec:

  • The ClusterRole does not allow pods/exec or pods/attach
ClusterRole: system:node-problem-detector

Spec:

  • The ClusterRole does not allow pods/exec or pods/attach
ClusterRole: system:node-proxier

Spec:

  • The ClusterRole does not allow pods/exec or pods/attach
ClusterRole: system:persistent-volume-provisioner

Spec:

  • The ClusterRole does not allow pods/exec or pods/attach
ClusterRole: system:public-info-viewer

Spec:

  • The ClusterRole does not allow pods/exec or pods/attach
ClusterRole: system:service-account-issuer-discovery

Spec:

  • The ClusterRole does not allow pods/exec or pods/attach
ClusterRole: system:volume-scheduler

Spec:

  • The ClusterRole does not allow pods/exec or pods/attach
ClusterRole: traefik-kube-system

Spec:

  • The ClusterRole does not allow pods/exec or pods/attach
ClusterRole: view

Spec:

  • The ClusterRole does not allow pods/exec or pods/attach
ClusterRoleBinding: argocd-application-controller

Spec: no checks applied

ClusterRoleBinding: argocd-server

Spec: no checks applied

ClusterRoleBinding: cert-manager-cainjector

Spec:

  • The ClusterRoleBinding does not reference the default cluster-admin ClusterRole or one with wildcard permissions
  • The ClusterRoleBinding does not reference a ClusterRole allowing pods/exec or pods/attach
ClusterRoleBinding: cert-manager-controller-approve:cert-manager-io

Spec:

  • The ClusterRoleBinding does not reference the default cluster-admin ClusterRole or one with wildcard permissions
  • The ClusterRoleBinding does not reference a ClusterRole allowing pods/exec or pods/attach
ClusterRoleBinding: cert-manager-controller-certificates

Spec:

  • The ClusterRoleBinding does not reference the default cluster-admin ClusterRole or one with wildcard permissions
  • The ClusterRoleBinding does not reference a ClusterRole allowing pods/exec or pods/attach
ClusterRoleBinding: cert-manager-controller-certificatesigningrequests

Spec:

  • The ClusterRoleBinding does not reference the default cluster-admin ClusterRole or one with wildcard permissions
  • The ClusterRoleBinding does not reference a ClusterRole allowing pods/exec or pods/attach
ClusterRoleBinding: cert-manager-controller-challenges

Spec:

  • The ClusterRoleBinding does not reference the default cluster-admin ClusterRole or one with wildcard permissions
  • The ClusterRoleBinding does not reference a ClusterRole allowing pods/exec or pods/attach
ClusterRoleBinding: cert-manager-controller-clusterissuers

Spec:

  • The ClusterRoleBinding does not reference a ClusterRole allowing pods/exec or pods/attach
  • The ClusterRoleBinding does not reference the default cluster-admin ClusterRole or one with wildcard permissions
ClusterRoleBinding: cert-manager-controller-ingress-shim

Spec:

  • The ClusterRoleBinding does not reference the default cluster-admin ClusterRole or one with wildcard permissions
  • The ClusterRoleBinding does not reference a ClusterRole allowing pods/exec or pods/attach
ClusterRoleBinding: cert-manager-controller-issuers

Spec:

  • The ClusterRoleBinding does not reference the default cluster-admin ClusterRole or one with wildcard permissions
  • The ClusterRoleBinding does not reference a ClusterRole allowing pods/exec or pods/attach
ClusterRoleBinding: cert-manager-controller-orders

Spec:

  • The ClusterRoleBinding does not reference the default cluster-admin ClusterRole or one with wildcard permissions
  • The ClusterRoleBinding does not reference a ClusterRole allowing pods/exec or pods/attach
ClusterRoleBinding: cert-manager-webhook:subjectaccessreviews

Spec:

  • The ClusterRoleBinding does not reference the default cluster-admin ClusterRole or one with wildcard permissions
  • The ClusterRoleBinding does not reference a ClusterRole allowing pods/exec or pods/attach
ClusterRoleBinding: cluster-admin

Spec:

  • The ClusterRoleBinding does not reference a ClusterRole allowing pods/exec or pods/attach
  • The ClusterRoleBinding does not reference the default cluster-admin ClusterRole or one with wildcard permissions
ClusterRoleBinding: clustercidrs-node

Spec:

  • The ClusterRoleBinding does not reference the default cluster-admin ClusterRole or one with wildcard permissions
  • The ClusterRoleBinding does not reference a ClusterRole allowing pods/exec or pods/attach
ClusterRoleBinding: helm-kube-system-traefik

Spec: no checks applied

ClusterRoleBinding: helm-kube-system-traefik-crd

Spec: no checks applied

ClusterRoleBinding: k3s-cloud-controller-manager

Spec:

  • The ClusterRoleBinding does not reference a ClusterRole allowing pods/exec or pods/attach
  • The ClusterRoleBinding does not reference the default cluster-admin ClusterRole or one with wildcard permissions
ClusterRoleBinding: k3s-cloud-controller-manager-auth-delegator

Spec:

  • The ClusterRoleBinding does not reference a ClusterRole allowing pods/exec or pods/attach
  • The ClusterRoleBinding does not reference the default cluster-admin ClusterRole or one with wildcard permissions
ClusterRoleBinding: kube-apiserver-kubelet-admin

Spec:

  • The ClusterRoleBinding does not reference the default cluster-admin ClusterRole or one with wildcard permissions
  • The ClusterRoleBinding does not reference a ClusterRole allowing pods/exec or pods/attach
ClusterRoleBinding: local-path-provisioner-bind

Spec:

  • The ClusterRoleBinding does not reference the default cluster-admin ClusterRole or one with wildcard permissions
  • The ClusterRoleBinding does not reference a ClusterRole allowing pods/exec or pods/attach
ClusterRoleBinding: metrics-server:system:auth-delegator

Spec:

  • The ClusterRoleBinding does not reference the default cluster-admin ClusterRole or one with wildcard permissions
  • The ClusterRoleBinding does not reference a ClusterRole allowing pods/exec or pods/attach
ClusterRoleBinding: polaris

Spec:

  • The ClusterRoleBinding does not reference a ClusterRole allowing pods/exec or pods/attach
  • The ClusterRoleBinding does not reference the default cluster-admin ClusterRole or one with wildcard permissions
ClusterRoleBinding: polaris-view

Spec:

  • The ClusterRoleBinding does not reference the default cluster-admin ClusterRole or one with wildcard permissions
  • The ClusterRoleBinding does not reference a ClusterRole allowing pods/exec or pods/attach
ClusterRoleBinding: sealed-secrets-controller

Spec:

  • The ClusterRoleBinding does not reference the default cluster-admin ClusterRole or one with wildcard permissions
  • The ClusterRoleBinding does not reference a ClusterRole allowing pods/exec or pods/attach
ClusterRoleBinding: system:basic-user

Spec:

  • The ClusterRoleBinding does not reference a ClusterRole allowing pods/exec or pods/attach
  • The ClusterRoleBinding does not reference the default cluster-admin ClusterRole or one with wildcard permissions
ClusterRoleBinding: system:controller:attachdetach-controller

Spec:

  • The ClusterRoleBinding does not reference a ClusterRole allowing pods/exec or pods/attach
  • The ClusterRoleBinding does not reference the default cluster-admin ClusterRole or one with wildcard permissions
ClusterRoleBinding: system:controller:certificate-controller

Spec:

  • The ClusterRoleBinding does not reference the default cluster-admin ClusterRole or one with wildcard permissions
  • The ClusterRoleBinding does not reference a ClusterRole allowing pods/exec or pods/attach
ClusterRoleBinding: system:controller:clusterrole-aggregation-controller

Spec:

  • The ClusterRoleBinding does not reference the default cluster-admin ClusterRole or one with wildcard permissions
  • The ClusterRoleBinding does not reference a ClusterRole allowing pods/exec or pods/attach
ClusterRoleBinding: system:controller:cronjob-controller

Spec:

  • The ClusterRoleBinding does not reference the default cluster-admin ClusterRole or one with wildcard permissions
  • The ClusterRoleBinding does not reference a ClusterRole allowing pods/exec or pods/attach
ClusterRoleBinding: system:controller:daemon-set-controller

Spec:

  • The ClusterRoleBinding does not reference the default cluster-admin ClusterRole or one with wildcard permissions
  • The ClusterRoleBinding does not reference a ClusterRole allowing pods/exec or pods/attach
ClusterRoleBinding: system:controller:deployment-controller

Spec:

  • The ClusterRoleBinding does not reference the default cluster-admin ClusterRole or one with wildcard permissions
  • The ClusterRoleBinding does not reference a ClusterRole allowing pods/exec or pods/attach
ClusterRoleBinding: system:controller:disruption-controller

Spec:

  • The ClusterRoleBinding does not reference a ClusterRole allowing pods/exec or pods/attach
  • The ClusterRoleBinding does not reference the default cluster-admin ClusterRole or one with wildcard permissions
ClusterRoleBinding: system:controller:endpoint-controller

Spec:

  • The ClusterRoleBinding does not reference the default cluster-admin ClusterRole or one with wildcard permissions
  • The ClusterRoleBinding does not reference a ClusterRole allowing pods/exec or pods/attach
ClusterRoleBinding: system:controller:endpointslice-controller

Spec:

  • The ClusterRoleBinding does not reference the default cluster-admin ClusterRole or one with wildcard permissions
  • The ClusterRoleBinding does not reference a ClusterRole allowing pods/exec or pods/attach
ClusterRoleBinding: system:controller:endpointslicemirroring-controller

Spec:

  • The ClusterRoleBinding does not reference the default cluster-admin ClusterRole or one with wildcard permissions
  • The ClusterRoleBinding does not reference a ClusterRole allowing pods/exec or pods/attach
ClusterRoleBinding: system:controller:ephemeral-volume-controller

Spec:

  • The ClusterRoleBinding does not reference a ClusterRole allowing pods/exec or pods/attach
  • The ClusterRoleBinding does not reference the default cluster-admin ClusterRole or one with wildcard permissions
ClusterRoleBinding: system:controller:expand-controller

Spec:

  • The ClusterRoleBinding does not reference the default cluster-admin ClusterRole or one with wildcard permissions
  • The ClusterRoleBinding does not reference a ClusterRole allowing pods/exec or pods/attach
ClusterRoleBinding: system:controller:generic-garbage-collector

Spec:

  • The ClusterRoleBinding does not reference the default cluster-admin ClusterRole or one with wildcard permissions
  • The ClusterRoleBinding does not reference a ClusterRole allowing pods/exec or pods/attach
ClusterRoleBinding: system:controller:horizontal-pod-autoscaler

Spec:

  • The ClusterRoleBinding does not reference the default cluster-admin ClusterRole or one with wildcard permissions
  • The ClusterRoleBinding does not reference a ClusterRole allowing pods/exec or pods/attach
ClusterRoleBinding: system:controller:job-controller

Spec:

  • The ClusterRoleBinding does not reference the default cluster-admin ClusterRole or one with wildcard permissions
  • The ClusterRoleBinding does not reference a ClusterRole allowing pods/exec or pods/attach
ClusterRoleBinding: system:controller:legacy-service-account-token-cleaner

Spec:

  • The ClusterRoleBinding does not reference the default cluster-admin ClusterRole or one with wildcard permissions
  • The ClusterRoleBinding does not reference a ClusterRole allowing pods/exec or pods/attach
ClusterRoleBinding: system:controller:namespace-controller

Spec:

  • The ClusterRoleBinding does not reference the default cluster-admin ClusterRole or one with wildcard permissions
  • The ClusterRoleBinding does not reference a ClusterRole allowing pods/exec or pods/attach
ClusterRoleBinding: system:controller:node-controller

Spec:

  • The ClusterRoleBinding does not reference the default cluster-admin ClusterRole or one with wildcard permissions
  • The ClusterRoleBinding does not reference a ClusterRole allowing pods/exec or pods/attach
ClusterRoleBinding: system:controller:persistent-volume-binder

Spec:

  • The ClusterRoleBinding does not reference the default cluster-admin ClusterRole or one with wildcard permissions
  • The ClusterRoleBinding does not reference a ClusterRole allowing pods/exec or pods/attach
ClusterRoleBinding: system:controller:pod-garbage-collector

Spec:

  • The ClusterRoleBinding does not reference the default cluster-admin ClusterRole or one with wildcard permissions
  • The ClusterRoleBinding does not reference a ClusterRole allowing pods/exec or pods/attach
ClusterRoleBinding: system:controller:pv-protection-controller

Spec:

  • The ClusterRoleBinding does not reference the default cluster-admin ClusterRole or one with wildcard permissions
  • The ClusterRoleBinding does not reference a ClusterRole allowing pods/exec or pods/attach
ClusterRoleBinding: system:controller:pvc-protection-controller

Spec:

  • The ClusterRoleBinding does not reference the default cluster-admin ClusterRole or one with wildcard permissions
  • The ClusterRoleBinding does not reference a ClusterRole allowing pods/exec or pods/attach
ClusterRoleBinding: system:controller:replicaset-controller

Spec:

  • The ClusterRoleBinding does not reference the default cluster-admin ClusterRole or one with wildcard permissions
  • The ClusterRoleBinding does not reference a ClusterRole allowing pods/exec or pods/attach
ClusterRoleBinding: system:controller:replication-controller

Spec:

  • The ClusterRoleBinding does not reference the default cluster-admin ClusterRole or one with wildcard permissions
  • The ClusterRoleBinding does not reference a ClusterRole allowing pods/exec or pods/attach
ClusterRoleBinding: system:controller:resource-claim-controller

Spec:

  • The ClusterRoleBinding does not reference the default cluster-admin ClusterRole or one with wildcard permissions
  • The ClusterRoleBinding does not reference a ClusterRole allowing pods/exec or pods/attach
ClusterRoleBinding: system:controller:resourcequota-controller

Spec:

  • The ClusterRoleBinding does not reference the default cluster-admin ClusterRole or one with wildcard permissions
  • The ClusterRoleBinding does not reference a ClusterRole allowing pods/exec or pods/attach
ClusterRoleBinding: system:controller:root-ca-cert-publisher

Spec:

  • The ClusterRoleBinding does not reference the default cluster-admin ClusterRole or one with wildcard permissions
  • The ClusterRoleBinding does not reference a ClusterRole allowing pods/exec or pods/attach
ClusterRoleBinding: system:controller:route-controller

Spec:

  • The ClusterRoleBinding does not reference the default cluster-admin ClusterRole or one with wildcard permissions
  • The ClusterRoleBinding does not reference a ClusterRole allowing pods/exec or pods/attach
ClusterRoleBinding: system:controller:selinux-warning-controller

Spec:

  • The ClusterRoleBinding does not reference the default cluster-admin ClusterRole or one with wildcard permissions
  • The ClusterRoleBinding does not reference a ClusterRole allowing pods/exec or pods/attach
ClusterRoleBinding: system:controller:service-account-controller

Spec:

  • The ClusterRoleBinding does not reference the default cluster-admin ClusterRole or one with wildcard permissions
  • The ClusterRoleBinding does not reference a ClusterRole allowing pods/exec or pods/attach
ClusterRoleBinding: system:controller:service-cidrs-controller

Spec:

  • The ClusterRoleBinding does not reference a ClusterRole allowing pods/exec or pods/attach
  • The ClusterRoleBinding does not reference the default cluster-admin ClusterRole or one with wildcard permissions
ClusterRoleBinding: system:controller:service-controller

Spec:

  • The ClusterRoleBinding does not reference the default cluster-admin ClusterRole or one with wildcard permissions
  • The ClusterRoleBinding does not reference a ClusterRole allowing pods/exec or pods/attach
ClusterRoleBinding: system:controller:statefulset-controller

Spec:

  • The ClusterRoleBinding does not reference the default cluster-admin ClusterRole or one with wildcard permissions
  • The ClusterRoleBinding does not reference a ClusterRole allowing pods/exec or pods/attach
ClusterRoleBinding: system:controller:ttl-after-finished-controller

Spec:

  • The ClusterRoleBinding does not reference the default cluster-admin ClusterRole or one with wildcard permissions
  • The ClusterRoleBinding does not reference a ClusterRole allowing pods/exec or pods/attach
ClusterRoleBinding: system:controller:ttl-controller

Spec:

  • The ClusterRoleBinding does not reference the default cluster-admin ClusterRole or one with wildcard permissions
  • The ClusterRoleBinding does not reference a ClusterRole allowing pods/exec or pods/attach
ClusterRoleBinding: system:controller:validatingadmissionpolicy-status-controller

Spec:

  • The ClusterRoleBinding does not reference the default cluster-admin ClusterRole or one with wildcard permissions
  • The ClusterRoleBinding does not reference a ClusterRole allowing pods/exec or pods/attach
ClusterRoleBinding: system:controller:volumeattributesclass-protection-controller

Spec:

  • The ClusterRoleBinding does not reference the default cluster-admin ClusterRole or one with wildcard permissions
  • The ClusterRoleBinding does not reference a ClusterRole allowing pods/exec or pods/attach
ClusterRoleBinding: system:coredns

Spec:

  • The ClusterRoleBinding does not reference the default cluster-admin ClusterRole or one with wildcard permissions
  • The ClusterRoleBinding does not reference a ClusterRole allowing pods/exec or pods/attach
ClusterRoleBinding: system:discovery

Spec:

  • The ClusterRoleBinding does not reference the default cluster-admin ClusterRole or one with wildcard permissions
  • The ClusterRoleBinding does not reference a ClusterRole allowing pods/exec or pods/attach
ClusterRoleBinding: system:k3s-controller

Spec:

  • The ClusterRoleBinding does not reference the default cluster-admin ClusterRole or one with wildcard permissions
  • The ClusterRoleBinding does not reference a ClusterRole allowing pods/exec or pods/attach
ClusterRoleBinding: system:kube-controller-manager

Spec:

  • The ClusterRoleBinding does not reference the default cluster-admin ClusterRole or one with wildcard permissions
  • The ClusterRoleBinding does not reference a ClusterRole allowing pods/exec or pods/attach
ClusterRoleBinding: system:kube-dns

Spec:

  • The ClusterRoleBinding does not reference a ClusterRole allowing pods/exec or pods/attach
  • The ClusterRoleBinding does not reference the default cluster-admin ClusterRole or one with wildcard permissions
ClusterRoleBinding: system:kube-scheduler

Spec:

  • The ClusterRoleBinding does not reference the default cluster-admin ClusterRole or one with wildcard permissions
  • The ClusterRoleBinding does not reference a ClusterRole allowing pods/exec or pods/attach
ClusterRoleBinding: system:metrics-server

Spec:

  • The ClusterRoleBinding does not reference the default cluster-admin ClusterRole or one with wildcard permissions
  • The ClusterRoleBinding does not reference a ClusterRole allowing pods/exec or pods/attach
ClusterRoleBinding: system:monitoring

Spec:

  • The ClusterRoleBinding does not reference a ClusterRole allowing pods/exec or pods/attach
  • The ClusterRoleBinding does not reference the default cluster-admin ClusterRole or one with wildcard permissions
ClusterRoleBinding: system:node

Spec:

  • The ClusterRoleBinding does not reference the default cluster-admin ClusterRole or one with wildcard permissions
  • The ClusterRoleBinding does not reference a ClusterRole allowing pods/exec or pods/attach
ClusterRoleBinding: system:node-proxier

Spec:

  • The ClusterRoleBinding does not reference the default cluster-admin ClusterRole or one with wildcard permissions
  • The ClusterRoleBinding does not reference a ClusterRole allowing pods/exec or pods/attach
ClusterRoleBinding: system:public-info-viewer

Spec:

  • The ClusterRoleBinding does not reference the default cluster-admin ClusterRole or one with wildcard permissions
  • The ClusterRoleBinding does not reference a ClusterRole allowing pods/exec or pods/attach
ClusterRoleBinding: system:service-account-issuer-discovery

Spec:

  • The ClusterRoleBinding does not reference a ClusterRole allowing pods/exec or pods/attach
  • The ClusterRoleBinding does not reference the default cluster-admin ClusterRole or one with wildcard permissions
ClusterRoleBinding: system:volume-scheduler

Spec:

  • The ClusterRoleBinding does not reference the default cluster-admin ClusterRole or one with wildcard permissions
  • The ClusterRoleBinding does not reference a ClusterRole allowing pods/exec or pods/attach
ClusterRoleBinding: traefik-kube-system

Spec:

  • The ClusterRoleBinding does not reference the default cluster-admin ClusterRole or one with wildcard permissions
  • The ClusterRoleBinding does not reference a ClusterRole allowing pods/exec or pods/attach

Namespace: argocd

ConfigMap: argocd-cm

Spec:

  • The ConfigMap does not contain potentially sensitive content in its keys and values
ConfigMap: argocd-cmd-params-cm

Spec:

  • The ConfigMap does not contain potentially sensitive content in its keys and values
ConfigMap: argocd-gpg-keys-cm

Spec:

  • The ConfigMap does not contain potentially sensitive content in its keys and values
ConfigMap: argocd-image-updater-config

Spec:

  • The ConfigMap does not contain potentially sensitive content in its keys and values
ConfigMap: argocd-image-updater-ssh-config

Spec:

  • The ConfigMap does not contain potentially sensitive content in its keys and values
ConfigMap: argocd-rbac-cm

Spec:

  • The ConfigMap does not contain potentially sensitive content in its keys and values
ConfigMap: argocd-redis-health-configmap

Spec:

  • The ConfigMap does not contain potentially sensitive content in its keys and values
ConfigMap: argocd-ssh-known-hosts-cm

Spec:

  • The ConfigMap does not contain potentially sensitive content in its keys and values
ConfigMap: argocd-tls-certs-cm

Spec:

  • The ConfigMap does not contain potentially sensitive content in its keys and values
ConfigMap: kube-root-ca.crt

Spec:

  • The ConfigMap does not contain potentially sensitive content in its keys and values
Deployment: argocd-applicationset-controller

Spec:

  • Only one replica is scheduled
  • Label app.kubernetes.io/instance must match metadata.name
  • Should have a PodDisruptionBudget
  • PDB and HPA are correctly configured

Pod Spec:

  • A NetworkPolicy should match pod labels and contain applied egress and ingress rules
  • Priority class should be set
  • Pod should be configured with a valid topology spread constraint
  • HostPath volumes are not configured
  • Host network is not configured
  • Host PID is not configured
  • Privileged access to the host check is valid
  • The default /proc masks are set up to reduce attack surface, and should be required
  • Host IPC is not configured

Container applicationset-controller:

  • Image pull policy should be "Always"
  • Readiness probe should be configured
  • Memory limits should be set
  • CPU limits should be set
  • Memory requests should be set
  • CPU requests should be set
  • Liveness probe should be configured
  • Image tag is specified
  • Container does not have any insecure capabilities
  • One of AppArmor, Seccomp, SELinux, or dropping Linux Capabilities are used to restrict containers using unwanted privileges
  • Not running as privileged
  • Container does not have any dangerous capabilities
  • Host port is not configured
  • Is not allowed to run as root
  • The container does not set potentially sensitive environment variables
  • Filesystem is read only
  • Privilege escalation not allowed
Deployment: argocd-redis

Spec:

  • Should have a PodDisruptionBudget
  • Only one replica is scheduled
  • Label app.kubernetes.io/instance must match metadata.name
  • PDB and HPA are correctly configured

Pod Spec:

  • A NetworkPolicy should match pod labels and contain applied egress and ingress rules
  • Priority class should be set
  • The ServiceAccount will be automounted
  • Pod should be configured with a valid topology spread constraint
  • Privileged access to the host check is valid
  • Host network is not configured
  • The default /proc masks are set up to reduce attack surface, and should be required
  • Host IPC is not configured
  • Host PID is not configured
  • HostPath volumes are not configured

Container redis:

  • CPU limits should be set
  • Memory requests should be set
  • Memory limits should be set
  • Readiness probe should be configured
  • CPU requests should be set
  • Liveness probe should be configured
  • Image pull policy should be "Always"
  • Privilege escalation not allowed
  • Not running as privileged
  • Container does not have any dangerous capabilities
  • The container does not set potentially sensitive environment variables
  • Host port is not configured
  • Container does not have any insecure capabilities
  • One of AppArmor, Seccomp, SELinux, or dropping Linux Capabilities are used to restrict containers using unwanted privileges
  • Filesystem is read only
  • Is not allowed to run as root
  • Image tag is specified
Deployment: argocd-repo-server

Spec:

  • Only one replica is scheduled
  • Should have a PodDisruptionBudget
  • PDB and HPA are correctly configured

Pod Spec:

  • Priority class should be set
  • A NetworkPolicy should match pod labels and contain applied egress and ingress rules
  • Pod should be configured with a valid topology spread constraint
  • Host IPC is not configured
  • Host PID is not configured
  • HostPath volumes are not configured
  • Host network is not configured
  • Privileged access to the host check is valid
  • The default /proc masks are set up to reduce attack surface, and should be required

Container copyutil:

  • Container does not have any insecure capabilities
  • One of AppArmor, Seccomp, SELinux, or dropping Linux Capabilities are used to restrict containers using unwanted privileges
  • Privilege escalation not allowed
  • Is not allowed to run as root
  • Container does not have any dangerous capabilities
  • Filesystem is read only
  • Not running as privileged
  • The container does not set potentially sensitive environment variables
  • Image tag is specified
  • Host port is not configured

Container repo-server:

  • Image pull policy should be "Always"
  • Memory limits should be set
  • CPU limits should be set
  • Container does not have any insecure capabilities
  • One of AppArmor, Seccomp, SELinux, or dropping Linux Capabilities are used to restrict containers using unwanted privileges
  • Memory requests are set
  • Filesystem is read only
  • CPU requests are set
  • The container does not set potentially sensitive environment variables
  • Not running as privileged
  • Host port is not configured
  • Liveness probe is configured
  • Privilege escalation not allowed
  • Container does not have any dangerous capabilities
  • Readiness probe is configured
  • Is not allowed to run as root
  • Image tag is specified
Deployment: argocd-server

Spec:

  • Only one replica is scheduled
  • Should have a PodDisruptionBudget
  • PDB and HPA are correctly configured

Pod Spec:

  • Priority class should be set
  • A NetworkPolicy should match pod labels and contain applied egress and ingress rules
  • Pod should be configured with a valid topology spread constraint
  • Host network is not configured
  • Host PID is not configured
  • HostPath volumes are not configured
  • The default /proc masks are set up to reduce attack surface, and should be required
  • Host IPC is not configured
  • Privileged access to the host check is valid

Container server:

  • Memory requests should be set
  • Memory limits should be set
  • Image pull policy should be "Always"
  • CPU limits should be set
  • CPU requests should be set
  • One of AppArmor, Seccomp, SELinux, or dropping Linux Capabilities are used to restrict containers using unwanted privileges
  • Privilege escalation not allowed
  • Container does not have any insecure capabilities
  • Liveness probe is configured
  • Readiness probe is configured
  • The container does not set potentially sensitive environment variables
  • Host port is not configured
  • Filesystem is read only
  • Not running as privileged
  • Container does not have any dangerous capabilities
  • Is not allowed to run as root
  • Image tag is specified
Deployment: image-updater-argocd-image-updater

Spec:

  • Only one replica is scheduled
  • Label app.kubernetes.io/instance must match metadata.name
  • Should have a PodDisruptionBudget
  • PDB and HPA are correctly configured

Pod Spec:

  • A NetworkPolicy should match pod labels and contain applied egress and ingress rules
  • Pod should be configured with a valid topology spread constraint
  • HostPath volumes are not configured
  • Privileged access to the host check is valid
  • The default /proc masks are set up to reduce attack surface, and should be required
  • Host IPC is not configured
  • Host network is not configured
  • Host PID is not configured

Container argocd-image-updater:

  • Container does not have any insecure capabilities
  • Filesystem is read only
  • The container does not set potentially sensitive environment variables
  • Readiness probe is configured
  • Not running as privileged
  • Image tag is specified
  • CPU limits are set
  • Host port is not configured
  • Liveness probe is configured
  • Memory requests are set
  • CPU requests are set
  • One of AppArmor, Seccomp, SELinux, or dropping Linux Capabilities are used to restrict containers using unwanted privileges
  • Memory limits are set
  • Privilege escalation not allowed
  • Image pull policy is "Always"
  • Is not allowed to run as root
  • Container does not have any dangerous capabilities
Role: argocd-application-controller

Spec: no checks applied

Role: argocd-applicationset-controller

Spec:

  • The Role does not allow pods/exec or pods/attach
Role: argocd-redis-secret-init

Spec:

  • The Role does not allow pods/exec or pods/attach
Role: argocd-repo-server

Spec: no checks applied

Role: argocd-server

Spec: no checks applied

Role: image-updater-argocd-image-updater

Spec:

  • The Role does not allow pods/exec or pods/attach
RoleBinding: argocd-application-controller

Spec: no checks applied

RoleBinding: argocd-applicationset-controller

Spec:

  • The RoleBinding does not reference the default cluster-admin ClusterRole or one with wildcard permissions
  • The RoleBinding does not reference a Role with wildcard permissions
  • The RoleBinding does not reference a ClusterRole allowing pods/exec or pods/attach
  • The RoleBinding does not reference a Role allowing Pod exec or attach
RoleBinding: argocd-redis-secret-init

Spec:

  • The RoleBinding does not reference the default cluster-admin ClusterRole or one with wildcard permissions
  • The RoleBinding does not reference a Role with wildcard permissions
  • The RoleBinding does not reference a ClusterRole allowing pods/exec or pods/attach
  • The RoleBinding does not reference a Role allowing Pod exec or attach
RoleBinding: argocd-repo-server

Spec: no checks applied

RoleBinding: argocd-server

Spec: no checks applied

RoleBinding: image-updater-argocd-image-updater

Spec:

  • The RoleBinding does not reference a Role allowing Pod exec or attach
  • The RoleBinding does not reference the default cluster-admin ClusterRole or one with wildcard permissions
  • The RoleBinding does not reference a Role with wildcard permissions
  • The RoleBinding does not reference a ClusterRole allowing pods/exec or pods/attach
ServiceAccount: argocd-application-controller

Spec: no checks applied

ServiceAccount: argocd-applicationset-controller

Spec: no checks applied

ServiceAccount: argocd-redis-secret-init

Spec: no checks applied

ServiceAccount: argocd-repo-server

Spec: no checks applied

ServiceAccount: argocd-server

Spec: no checks applied

ServiceAccount: default

Spec: no checks applied

ServiceAccount: image-updater-argocd-image-updater

Spec: no checks applied

StatefulSet: argocd-application-controller

Spec: no checks applied

Pod Spec:

  • A NetworkPolicy should match pod labels and contain applied egress and ingress rules
  • Priority class should be set
  • Pod should be configured with a valid topology spread constraint
  • The default /proc masks are set up to reduce attack surface, and should be required
  • Host PID is not configured
  • Privileged access to the host check is valid
  • Host IPC is not configured
  • Host network is not configured
  • HostPath volumes are not configured

Container application-controller:

  • Image pull policy should be "Always"
  • CPU limits should be set
  • Liveness probe should be configured
  • Memory limits should be set
  • CPU requests are set
  • Is not allowed to run as root
  • Host port is not configured
  • Filesystem is read only
  • The container does not set potentially sensitive environment variables
  • Container does not have any dangerous capabilities
  • One of AppArmor, Seccomp, SELinux, or dropping Linux Capabilities are used to restrict containers using unwanted privileges
  • Memory requests are set
  • Not running as privileged
  • Container does not have any insecure capabilities
  • Privilege escalation not allowed
  • Readiness probe is configured
  • Image tag is specified

Namespace: cert-manager

ConfigMap: kube-root-ca.crt

Spec:

  • The ConfigMap does not contain potentially sensitive content in its keys and values
Deployment: cert-manager

Spec:

  • Should have a PodDisruptionBudget
  • Only one replica is scheduled
  • Label app.kubernetes.io/instance matches metadata.name
  • PDB and HPA are correctly configured

Pod Spec:

  • A NetworkPolicy should match pod labels and contain applied egress and ingress rules
  • Priority class should be set
  • Pod should be configured with a valid topology spread constraint
  • Host IPC is not configured
  • Host PID is not configured
  • HostPath volumes are not configured
  • Privileged access to the host check is valid
  • The default /proc masks are set up to reduce attack surface, and should be required
  • Host network is not configured

Container cert-manager-controller:

  • Memory limits should be set
  • CPU limits should be set
  • CPU requests should be set
  • Memory requests should be set
  • Image pull policy should be "Always"
  • Readiness probe should be configured
  • Container does not have any dangerous capabilities
  • Container does not have any insecure capabilities
  • Host port is not configured
  • Privilege escalation not allowed
  • Image tag is specified
  • One of AppArmor, Seccomp, SELinux, or dropping Linux Capabilities are used to restrict containers using unwanted privileges
  • Liveness probe is configured
  • Filesystem is read only
  • Not running as privileged
  • Is not allowed to run as root
  • The container does not set potentially sensitive environment variables
Deployment: cert-manager-cainjector

Spec:

  • Only one replica is scheduled
  • Label app.kubernetes.io/instance must match metadata.name
  • Should have a PodDisruptionBudget
  • PDB and HPA are correctly configured

Pod Spec:

  • A NetworkPolicy should match pod labels and contain applied egress and ingress rules
  • Priority class should be set
  • Pod should be configured with a valid topology spread constraint
  • Host network is not configured
  • Host PID is not configured
  • Privileged access to the host check is valid
  • Host IPC is not configured
  • HostPath volumes are not configured
  • The default /proc masks are set up to reduce attack surface, and should be required

Container cert-manager-cainjector:

  • Readiness probe should be configured
  • Memory requests should be set
  • Memory limits should be set
  • CPU limits should be set
  • Liveness probe should be configured
  • CPU requests should be set
  • Image pull policy should be "Always"
  • Image tag is specified
  • Not running as privileged
  • One of AppArmor, Seccomp, SELinux, or dropping Linux Capabilities are used to restrict containers using unwanted privileges
  • Filesystem is read only
  • Privilege escalation not allowed
  • The container does not set potentially sensitive environment variables
  • Container does not have any dangerous capabilities
  • Host port is not configured
  • Is not allowed to run as root
  • Container does not have any insecure capabilities
Deployment: cert-manager-webhook

Spec:

  • Only one replica is scheduled
  • Label app.kubernetes.io/instance must match metadata.name
  • Should have a PodDisruptionBudget
  • PDB and HPA are correctly configured

Pod Spec:

  • A NetworkPolicy should match pod labels and contain applied egress and ingress rules
  • Priority class should be set
  • Pod should be configured with a valid topology spread constraint
  • Host IPC is not configured
  • Host PID is not configured
  • HostPath volumes are not configured
  • Privileged access to the host check is valid
  • The default /proc masks are set up to reduce attack surface, and should be required
  • Host network is not configured

Container cert-manager-webhook:

  • CPU requests should be set
  • Memory limits should be set
  • Memory requests should be set
  • Image pull policy should be "Always"
  • CPU limits should be set
  • Container does not have any dangerous capabilities
  • Liveness probe is configured
  • Filesystem is read only
  • Not running as privileged
  • Host port is not configured
  • One of AppArmor, Seccomp, SELinux, or dropping Linux Capabilities are used to restrict containers using unwanted privileges
  • The container does not set potentially sensitive environment variables
  • Image tag is specified
  • Readiness probe is configured
  • Is not allowed to run as root
  • Container does not have any insecure capabilities
  • Privilege escalation not allowed
NetworkPolicy: cert-manager-allow

Spec: no checks applied

Role: cert-manager-tokenrequest

Spec:

  • The Role does not allow pods/exec or pods/attach
Role: cert-manager-webhook:dynamic-serving

Spec:

  • The Role does not allow pods/exec or pods/attach
RoleBinding: cert-manager-tokenrequest

Spec:

  • The RoleBinding does not reference the default cluster-admin ClusterRole or one with wildcard permissions
  • The RoleBinding does not reference a Role with wildcard permissions
  • The RoleBinding does not reference a ClusterRole allowing pods/exec or pods/attach
  • The RoleBinding does not reference a Role allowing Pod exec or attach
RoleBinding: cert-manager-webhook:dynamic-serving

Spec:

  • The RoleBinding does not reference the default cluster-admin ClusterRole or one with wildcard permissions
  • The RoleBinding does not reference a Role with wildcard permissions
  • The RoleBinding does not reference a ClusterRole allowing pods/exec or pods/attach
  • The RoleBinding does not reference a Role allowing Pod exec or attach
ServiceAccount: cert-manager

Spec: no checks applied

ServiceAccount: cert-manager-cainjector

Spec: no checks applied

ServiceAccount: cert-manager-webhook

Spec: no checks applied

ServiceAccount: default

Spec: no checks applied

Namespace: default

ConfigMap: kube-root-ca.crt

Spec:

  • The ConfigMap does not contain potentially sensitive content in its keys and values
ServiceAccount: default

Spec: no checks applied

Namespace: kube-node-lease

ConfigMap: kube-root-ca.crt

Spec:

  • The ConfigMap does not contain potentially sensitive content in its keys and values
ServiceAccount: default

Spec: no checks applied

Namespace: kube-public

ConfigMap: kube-root-ca.crt

Spec:

  • The ConfigMap does not contain potentially sensitive content in its keys and values
Role: system:controller:bootstrap-signer

Spec:

  • The Role does not allow pods/exec or pods/attach
RoleBinding: system:controller:bootstrap-signer

Spec:

  • The RoleBinding does not reference a Role allowing Pod exec or attach
  • The RoleBinding does not reference the default cluster-admin ClusterRole or one with wildcard permissions
  • The RoleBinding does not reference a Role with wildcard permissions
  • The RoleBinding does not reference a ClusterRole allowing pods/exec or pods/attach
ServiceAccount: default

Spec: no checks applied

Namespace: kube-system

ConfigMap: chart-content-traefik

Spec: no checks applied

ConfigMap: chart-content-traefik-crd

Spec: no checks applied

ConfigMap: cluster-dns

Spec: no checks applied

ConfigMap: coredns

Spec: no checks applied

ConfigMap: extension-apiserver-authentication

Spec: no checks applied

ConfigMap: kube-apiserver-legacy-service-account-token-tracking

Spec: no checks applied

ConfigMap: kube-root-ca.crt

Spec: no checks applied

ConfigMap: local-path-config

Spec: no checks applied

DaemonSet: svclb-traefik-05a505e1

Spec: no checks applied

Pod Spec: no checks applied

Container lb-tcp-80: no checks applied

Container lb-tcp-443: no checks applied

Deployment: coredns

Spec: no checks applied

Pod Spec: no checks applied

Container coredns: no checks applied

Deployment: local-path-provisioner

Spec: no checks applied

Pod Spec: no checks applied

Container local-path-provisioner: no checks applied

Deployment: metrics-server

Spec: no checks applied

Pod Spec: no checks applied

Container metrics-server: no checks applied

Deployment: sealed-secrets-controller

Spec: no checks applied

Pod Spec: no checks applied

Container controller: no checks applied

Deployment: traefik

Spec: no checks applied

Pod Spec: no checks applied

Container traefik: no checks applied

Job: helm-install-traefik

Spec: no checks applied

Pod Spec: no checks applied

Container helm: no checks applied

Job: helm-install-traefik-crd

Spec: no checks applied

Pod Spec: no checks applied

Container helm: no checks applied

Role: cert-manager-cainjector:leaderelection

Spec: no checks applied

Role: cert-manager:leaderelection

Spec: no checks applied

Role: extension-apiserver-authentication-reader

Spec: no checks applied

Role: sealed-secrets-controller-key-admin

Spec: no checks applied

Role: sealed-secrets-controller-service-proxier

Spec: no checks applied

Role: system::leader-locking-kube-controller-manager

Spec: no checks applied

Role: system::leader-locking-kube-scheduler

Spec: no checks applied

Role: system:controller:bootstrap-signer

Spec: no checks applied

Role: system:controller:cloud-provider

Spec: no checks applied

Role: system:controller:token-cleaner

Spec: no checks applied

RoleBinding: cert-manager-cainjector:leaderelection

Spec: no checks applied

RoleBinding: cert-manager:leaderelection

Spec: no checks applied

RoleBinding: k3s-cloud-controller-manager-authentication-reader

Spec: no checks applied

RoleBinding: metrics-server-auth-reader

Spec: no checks applied

RoleBinding: sealed-secrets-controller-key-admin

Spec: no checks applied

RoleBinding: sealed-secrets-controller-service-proxier

Spec: no checks applied

RoleBinding: system::extension-apiserver-authentication-reader

Spec: no checks applied

RoleBinding: system::leader-locking-kube-controller-manager

Spec: no checks applied

RoleBinding: system::leader-locking-kube-scheduler

Spec: no checks applied

RoleBinding: system:controller:bootstrap-signer

Spec: no checks applied

RoleBinding: system:controller:cloud-provider

Spec: no checks applied

RoleBinding: system:controller:token-cleaner

Spec: no checks applied

ServiceAccount: attachdetach-controller

Spec: no checks applied

ServiceAccount: certificate-controller

Spec: no checks applied

ServiceAccount: clusterrole-aggregation-controller

Spec: no checks applied

ServiceAccount: coredns

Spec: no checks applied

ServiceAccount: cronjob-controller

Spec: no checks applied

ServiceAccount: daemon-set-controller

Spec: no checks applied

ServiceAccount: default

Spec: no checks applied

ServiceAccount: deployment-controller

Spec: no checks applied

ServiceAccount: disruption-controller

Spec: no checks applied

ServiceAccount: endpoint-controller

Spec: no checks applied

ServiceAccount: endpointslice-controller

Spec: no checks applied

ServiceAccount: endpointslicemirroring-controller

Spec: no checks applied

ServiceAccount: ephemeral-volume-controller

Spec: no checks applied

ServiceAccount: expand-controller

Spec: no checks applied

ServiceAccount: generic-garbage-collector

Spec: no checks applied

ServiceAccount: helm-traefik

Spec: no checks applied

ServiceAccount: helm-traefik-crd

Spec: no checks applied

ServiceAccount: horizontal-pod-autoscaler

Spec: no checks applied

ServiceAccount: job-controller

Spec: no checks applied

ServiceAccount: legacy-service-account-token-cleaner

Spec: no checks applied

ServiceAccount: local-path-provisioner-service-account

Spec: no checks applied

ServiceAccount: metrics-server

Spec: no checks applied

ServiceAccount: namespace-controller

Spec: no checks applied

ServiceAccount: node-controller

Spec: no checks applied

ServiceAccount: persistent-volume-binder

Spec: no checks applied

ServiceAccount: pod-garbage-collector

Spec: no checks applied

ServiceAccount: pv-protection-controller

Spec: no checks applied

ServiceAccount: pvc-protection-controller

Spec: no checks applied

ServiceAccount: replicaset-controller

Spec: no checks applied

ServiceAccount: replication-controller

Spec: no checks applied

ServiceAccount: resource-claim-controller

Spec: no checks applied

ServiceAccount: resourcequota-controller

Spec: no checks applied

ServiceAccount: root-ca-cert-publisher

Spec: no checks applied

ServiceAccount: sealed-secrets-controller

Spec: no checks applied

ServiceAccount: service-account-controller

Spec: no checks applied

ServiceAccount: service-cidrs-controller

Spec: no checks applied

ServiceAccount: statefulset-controller

Spec: no checks applied

ServiceAccount: svclb

Spec: no checks applied

ServiceAccount: token-cleaner

Spec: no checks applied

ServiceAccount: traefik

Spec: no checks applied

ServiceAccount: ttl-after-finished-controller

Spec: no checks applied

ServiceAccount: ttl-controller

Spec: no checks applied

ServiceAccount: validatingadmissionpolicy-status-controller

Spec: no checks applied

ServiceAccount: volumeattributesclass-protection-controller

Spec: no checks applied

Namespace: polaris

ConfigMap: kube-root-ca.crt

Spec:

  • The ConfigMap does not contain potentially sensitive content in its keys and values
ConfigMap: polaris

Spec:

  • The ConfigMap does not contain potentially sensitive content in its keys and values
Deployment: polaris-dashboard

Spec:

  • Only one replica is scheduled
  • Label app.kubernetes.io/instance must match metadata.name
  • A PodDisruptionBudget is attached
  • PDB and HPA are correctly configured

Pod Spec:

  • Privileged access to the host check is valid
  • Priority class has been set
  • Host PID is not configured
  • A NetworkPolicy matches pod labels and contains egress and ingress rules
  • The default /proc masks are set up to reduce attack surface, and should be required
  • Pod has a valid topology spread constraint
  • Host IPC is not configured
  • Host network is not configured
  • HostPath volumes are not configured

Container dashboard:

  • Memory requests are set
  • CPU limits are set
  • One of AppArmor, Seccomp, SELinux, or dropping Linux Capabilities are used to restrict containers using unwanted privileges
  • Memory limits are set
  • Privilege escalation not allowed
  • Container does not have any dangerous capabilities
  • Filesystem is read only
  • Not running as privileged
  • The container does not set potentially sensitive environment variables
  • Container does not have any insecure capabilities
  • Liveness probe is configured
  • Image pull policy is "Always"
  • Readiness probe is configured
  • Is not allowed to run as root
  • Image tag is specified
  • CPU requests are set
  • Host port is not configured
Deployment: polaris-webhook

Spec:

  • Only one replica is scheduled
  • Label app.kubernetes.io/instance must match metadata.name
  • A PodDisruptionBudget is attached
  • PDB and HPA are correctly configured

Pod Spec:

  • Host IPC is not configured
  • Host network is not configured
  • Host PID is not configured
  • Privileged access to the host check is valid
  • Priority class has been set
  • The default /proc masks are set up to reduce attack surface, and should be required
  • Pod has a valid topology spread constraint
  • HostPath volumes are not configured
  • A NetworkPolicy matches pod labels and contains egress and ingress rules

Container webhook:

  • One of AppArmor, Seccomp, SELinux, or dropping Linux Capabilities are used to restrict containers using unwanted privileges
  • Liveness probe is configured
  • Memory limits are set
  • Privilege escalation not allowed
  • Image pull policy is "Always"
  • Readiness probe is configured
  • Is not allowed to run as root
  • The container does not set potentially sensitive environment variables
  • CPU requests are set
  • Container does not have any dangerous capabilities
  • Host port is not configured
  • Memory requests are set
  • CPU limits are set
  • Not running as privileged
  • Image tag is specified
  • Container does not have any insecure capabilities
  • Filesystem is read only
NetworkPolicy: polaris-dashboard

Spec: no checks applied

NetworkPolicy: polaris-webhook

Spec: no checks applied

PodDisruptionBudget: polaris-dashboard

Spec:

  • Voluntary evictions are possible
PodDisruptionBudget: polaris-webhook

Spec:

  • Voluntary evictions are possible
ServiceAccount: default

Spec: no checks applied

ServiceAccount: polaris

Spec: no checks applied

Namespace: vitrine-apps

ConfigMap: kube-root-ca.crt

Spec:

  • The ConfigMap does not contain potentially sensitive content in its keys and values
ConfigMap: web-config

Spec:

  • The ConfigMap does not contain potentially sensitive content in its keys and values
Deployment: cms-deployment

Spec:

  • Multiple replicas are scheduled
  • Label app.kubernetes.io/instance matches metadata.name
  • A PodDisruptionBudget is attached
  • PDB and HPA are correctly configured

Pod Spec:

  • Host network is not configured
  • Host PID is not configured
  • HostPath volumes are not configured
  • A NetworkPolicy matches pod labels and contains egress and ingress rules
  • Priority class has been set
  • The ServiceAccount will not be automounted
  • Host IPC is not configured
  • Privileged access to the host check is valid
  • The default /proc masks are set up to reduce attack surface, and should be required
  • Pod has a valid topology spread constraint

Container wait-for-postgres:

  • Container does not have any insecure capabilities
  • One of AppArmor, Seccomp, SELinux, or dropping Linux Capabilities are used to restrict containers using unwanted privileges
  • Image pull policy is "Always"
  • Image tag is specified
  • Container does not have any dangerous capabilities
  • Host port is not configured
  • Filesystem is read only
  • Privilege escalation not allowed
  • Not running as privileged
  • Is not allowed to run as root
  • The container does not set potentially sensitive environment variables

Container cms-deployment:

  • CPU requests are set
  • Image pull policy is "Always"
  • Not running as privileged
  • CPU limits are set
  • Is not allowed to run as root
  • The container does not set potentially sensitive environment variables
  • Container does not have any dangerous capabilities
  • Liveness probe is configured
  • Memory limits are set
  • Filesystem is read only
  • Host port is not configured
  • Container does not have any insecure capabilities
  • One of AppArmor, Seccomp, SELinux, or dropping Linux Capabilities are used to restrict containers using unwanted privileges
  • Memory requests are set
  • Privilege escalation not allowed
  • Readiness probe is configured
  • Image tag is specified
Deployment: web-deployment

Spec:

  • Multiple replicas are scheduled
  • Label app.kubernetes.io/instance matches metadata.name
  • A PodDisruptionBudget is attached
  • PDB and HPA are correctly configured

Pod Spec:

  • Host IPC is not configured
  • Host network is not configured
  • HostPath volumes are not configured
  • Pod has a valid topology spread constraint
  • The ServiceAccount will not be automounted
  • Host PID is not configured
  • Privileged access to the host check is valid
  • A NetworkPolicy matches pod labels and contains egress and ingress rules
  • Priority class has been set
  • The default /proc masks are set up to reduce attack surface, and should be required

Container wait-for-schema:

  • Container does not have any dangerous capabilities
  • Host port is not configured
  • Filesystem is read only
  • Image pull policy is "Always"
  • Is not allowed to run as root
  • The container does not set potentially sensitive environment variables
  • Image tag is specified
  • Container does not have any insecure capabilities
  • One of AppArmor, Seccomp, SELinux, or dropping Linux Capabilities are used to restrict containers using unwanted privileges
  • Privilege escalation not allowed
  • Not running as privileged

Container web-deployment:

  • One of AppArmor, Seccomp, SELinux, or dropping Linux Capabilities are used to restrict containers using unwanted privileges
  • Filesystem is read only
  • The container does not set potentially sensitive environment variables
  • Image tag is specified
  • CPU limits are set
  • Container does not have any dangerous capabilities
  • Container does not have any insecure capabilities
  • Liveness probe is configured
  • Memory limits are set
  • Memory requests are set
  • Privilege escalation not allowed
  • CPU requests are set
  • Host port is not configured
  • Not running as privileged
  • Is not allowed to run as root
  • Image pull policy is "Always"
  • Readiness probe is configured
NetworkPolicy: cms-deployment

Spec: no checks applied

NetworkPolicy: cms-jobs

Spec: no checks applied

NetworkPolicy: web-deployment

Spec: no checks applied

PodDisruptionBudget: cms-deployment

Spec:

  • Voluntary evictions are possible
PodDisruptionBudget: web-deployment

Spec:

  • Voluntary evictions are possible
ServiceAccount: default

Spec: no checks applied

Namespace: vitrine-data

ConfigMap: kube-root-ca.crt

Spec:

  • The ConfigMap does not contain potentially sensitive content in its keys and values
ConfigMap: supabase-supabase-db-initdb

Spec:

  • The ConfigMap does not contain potentially sensitive content in its keys and values
ConfigMap: supabase-supabase-db-migrations

Spec:

  • The ConfigMap does not contain potentially sensitive content in its keys and values
ConfigMap: supabase-supabase-functions-main

Spec:

  • The ConfigMap does not contain potentially sensitive content in its keys and values
ConfigMap: supabase-supabase-kong

Spec:

  • The ConfigMap does not contain potentially sensitive content in its keys and values
Deployment: supabase-supabase-auth

Spec:

  • Label app.kubernetes.io/instance must match metadata.name
  • Should have a PodDisruptionBudget
  • Only one replica is scheduled
  • PDB and HPA are correctly configured

Pod Spec:

  • A NetworkPolicy should match pod labels and contain applied egress and ingress rules
  • Pod should be configured with a valid topology spread constraint
  • Host network is not configured
  • Privileged access to the host check is valid
  • The ServiceAccount will not be automounted
  • Host IPC is not configured
  • Host PID is not configured
  • HostPath volumes are not configured
  • Priority class has been set
  • The default /proc masks are set up to reduce attack surface, and should be required

Container init-db:

  • Host port is not configured
  • Not running as privileged
  • The container does not set potentially sensitive environment variables
  • Image tag is specified

Container supabase-auth:

  • CPU requests are set
  • Liveness probe is configured
  • Memory limits are set
  • Memory requests are set
  • Readiness probe is configured
  • Not running as privileged
  • CPU limits are set
  • Host port is not configured
  • Image pull policy is "Always"
  • Image tag is specified
Deployment: supabase-supabase-functions

Spec:

  • Only one replica is scheduled
  • Label app.kubernetes.io/instance must match metadata.name
  • Should have a PodDisruptionBudget
  • PDB and HPA are correctly configured

Pod Spec:

  • A NetworkPolicy should match pod labels and contain applied egress and ingress rules
  • Pod should be configured with a valid topology spread constraint
  • Host PID is not configured
  • Priority class has been set
  • Host IPC is not configured
  • Host network is not configured
  • HostPath volumes are not configured
  • Privileged access to the host check is valid
  • The default /proc masks are set up to reduce attack surface, and should be required
  • The ServiceAccount will not be automounted

Container supabase-functions:

  • CPU limits are set
  • Host port is not configured
  • Liveness probe is configured
  • Memory requests are set
  • Image pull policy is "Always"
  • Readiness probe is configured
  • Not running as privileged
  • Image tag is specified
  • CPU requests are set
  • Memory limits are set
Deployment: supabase-supabase-kong

Spec:

  • Label app.kubernetes.io/instance must match metadata.name
  • Should have a PodDisruptionBudget
  • Only one replica is scheduled
  • PDB and HPA are correctly configured

Pod Spec:

  • A NetworkPolicy should match pod labels and contain applied egress and ingress rules
  • Pod should be configured with a valid topology spread constraint
  • Host IPC is not configured
  • Priority class has been set
  • The ServiceAccount will not be automounted
  • Host network is not configured
  • Host PID is not configured
  • HostPath volumes are not configured
  • Privileged access to the host check is valid
  • The default /proc masks are set up to reduce attack surface, and should be required

Container supabase-kong:

  • CPU limits are set
  • CPU requests are set
  • Image pull policy is "Always"
  • Readiness probe is configured
  • Image tag is specified
  • Host port is not configured
  • Liveness probe is configured
  • Memory limits are set
  • Memory requests are set
  • Not running as privileged
Deployment: supabase-supabase-meta

Spec:

  • Only one replica is scheduled
  • Label app.kubernetes.io/instance must match metadata.name
  • Should have a PodDisruptionBudget
  • PDB and HPA are correctly configured

Pod Spec:

  • A NetworkPolicy should match pod labels and contain applied egress and ingress rules
  • Pod should be configured with a valid topology spread constraint
  • The ServiceAccount will not be automounted
  • Host IPC is not configured
  • Privileged access to the host check is valid
  • Priority class has been set
  • Host network is not configured
  • Host PID is not configured
  • HostPath volumes are not configured
  • The default /proc masks are set up to reduce attack surface, and should be required

Container supabase-meta:

  • Image tag is specified
  • Liveness probe is configured
  • Memory requests are set
  • Image pull policy is "Always"
  • Readiness probe is configured
  • CPU limits are set
  • CPU requests are set
  • Host port is not configured
  • Memory limits are set
  • Not running as privileged
Deployment: supabase-supabase-realtime

Spec:

  • Should have a PodDisruptionBudget
  • Only one replica is scheduled
  • Label app.kubernetes.io/instance must match metadata.name
  • PDB and HPA are correctly configured

Pod Spec:

  • A NetworkPolicy should match pod labels and contain applied egress and ingress rules
  • Pod should be configured with a valid topology spread constraint
  • The ServiceAccount will not be automounted
  • Host network is not configured
  • Host PID is not configured
  • Privileged access to the host check is valid
  • Priority class has been set
  • The default /proc masks are set up to reduce attack surface, and should be required
  • Host IPC is not configured
  • HostPath volumes are not configured

Container init-db:

  • Image tag is specified
  • Host port is not configured
  • Not running as privileged
  • The container does not set potentially sensitive environment variables

Container supabase-realtime:

  • CPU requests are set
  • Liveness probe is configured
  • Memory requests are set
  • Image pull policy is "Always"
  • Not running as privileged
  • CPU limits are set
  • Host port is not configured
  • Memory limits are set
  • Readiness probe is configured
  • Image tag is specified
Deployment: supabase-supabase-rest

Spec:

  • Label app.kubernetes.io/instance must match metadata.name
  • Should have a PodDisruptionBudget
  • Only one replica is scheduled
  • PDB and HPA are correctly configured

Pod Spec:

  • A NetworkPolicy should match pod labels and contain applied egress and ingress rules
  • Pod should be configured with a valid topology spread constraint
  • The ServiceAccount will not be automounted
  • Privileged access to the host check is valid
  • Priority class has been set
  • The default /proc masks are set up to reduce attack surface, and should be required
  • Host IPC is not configured
  • Host network is not configured
  • Host PID is not configured
  • HostPath volumes are not configured

Container init-db:

  • Host port is not configured
  • Not running as privileged
  • The container does not set potentially sensitive environment variables
  • Image tag is specified

Container supabase-rest:

  • Readiness probe is configured
  • CPU requests are set
  • Host port is not configured
  • Liveness probe is configured
  • Memory requests are set
  • Not running as privileged
  • Image tag is specified
  • CPU limits are set
  • Memory limits are set
  • Image pull policy is "Always"
Deployment: supabase-supabase-storage

Spec:

  • Only one replica is scheduled
  • Label app.kubernetes.io/instance must match metadata.name
  • Should have a PodDisruptionBudget
  • PDB and HPA are correctly configured

Pod Spec:

  • A NetworkPolicy should match pod labels and contain applied egress and ingress rules
  • Pod should be configured with a valid topology spread constraint
  • Host IPC is not configured
  • Host network is not configured
  • HostPath volumes are not configured
  • Privileged access to the host check is valid
  • Priority class has been set
  • The ServiceAccount will not be automounted
  • Host PID is not configured
  • The default /proc masks are set up to reduce attack surface, and should be required

Container init-db:

  • Host port is not configured
  • Not running as privileged
  • The container does not set potentially sensitive environment variables
  • Image tag is specified

Container supabase-storage:

  • Liveness probe is configured
  • Memory limits are set
  • Image tag is specified
  • CPU requests are set
  • Host port is not configured
  • Memory requests are set
  • Image pull policy is "Always"
  • Readiness probe is configured
  • Not running as privileged
  • CPU limits are set
Deployment: supabase-supabase-studio

Spec:

  • Only one replica is scheduled
  • Label app.kubernetes.io/instance must match metadata.name
  • Should have a PodDisruptionBudget
  • PDB and HPA are correctly configured

Pod Spec:

  • A NetworkPolicy should match pod labels and contain applied egress and ingress rules
  • Pod should be configured with a valid topology spread constraint
  • The ServiceAccount will not be automounted
  • Host network is not configured
  • Host PID is not configured
  • HostPath volumes are not configured
  • Privileged access to the host check is valid
  • Priority class has been set
  • Host IPC is not configured
  • The default /proc masks are set up to reduce attack surface, and should be required

Container supabase-studio:

  • CPU limits are set
  • CPU requests are set
  • Memory requests are set
  • Readiness probe is configured
  • Not running as privileged
  • Image tag is specified
  • Host port is not configured
  • Liveness probe is configured
  • Memory limits are set
  • Image pull policy is "Always"
NetworkPolicy: supabase-allow-common

Spec: no checks applied

ServiceAccount: default

Spec: no checks applied

ServiceAccount: supabase-supabase-auth

Spec: no checks applied

ServiceAccount: supabase-supabase-db

Spec: no checks applied

ServiceAccount: supabase-supabase-functions

Spec: no checks applied

ServiceAccount: supabase-supabase-kong

Spec: no checks applied

ServiceAccount: supabase-supabase-meta

Spec: no checks applied

ServiceAccount: supabase-supabase-realtime

Spec: no checks applied

ServiceAccount: supabase-supabase-rest

Spec: no checks applied

ServiceAccount: supabase-supabase-storage

Spec: no checks applied

ServiceAccount: supabase-supabase-studio

Spec: no checks applied

StatefulSet: supabase-supabase-db

Spec:

  • Label app.kubernetes.io/instance must match metadata.name

Pod Spec:

  • A NetworkPolicy should match pod labels and contain applied egress and ingress rules
  • Pod should be configured with a valid topology spread constraint
  • Priority class has been set
  • The default /proc masks are set up to reduce attack surface, and should be required
  • The ServiceAccount will not be automounted
  • Host IPC is not configured
  • Host network is not configured
  • Host PID is not configured
  • HostPath volumes are not configured
  • Privileged access to the host check is valid

Container init-pgsodium:

  • The container does not set potentially sensitive environment variables
  • Image tag is specified
  • Host port is not configured
  • Not running as privileged

Container init-db:

  • Host port is not configured
  • Not running as privileged
  • The container does not set potentially sensitive environment variables
  • Image tag is specified

Container supabase-db:

  • Host port is not configured
  • Memory limits are set
  • Image pull policy is "Always"
  • Not running as privileged
  • CPU limits are set
  • CPU requests are set
  • Liveness probe is configured
  • Memory requests are set
  • Readiness probe is configured
  • Image tag is specified