Default GitOps ArgoCD instance allows reading resources for unprivileged users.

Solution Verified - Updated -

Issue

The default instance of ArgoCD (openshift-gitops in namespace openshift-gitops) has the default role set to role:readonly. This is a potential security risk as any user (without any privileges) that is able to login to OCP can see all resources managed by the ArgoCD instance (secrets, network policies, routes, ...). This ArgoCD instance is intended for Cluster management so there is high chance of potential misuse of sensitive data.

Environment

  • Red Hat OpenShift GitOps 1.9 and earlier

Subscriber exclusive content

A Red Hat subscription provides unlimited access to our knowledgebase, tools, and much more.

Current Customers and Partners

Log in for full access

Log In

New to Red Hat?

Learn more about Red Hat subscriptions

Using a Red Hat product through a public cloud?

How to access this content