Default GitOps ArgoCD instance allows reading resources for unprivileged users.
Issue
The default instance of ArgoCD (openshift-gitops in namespace openshift-gitops) has the default role set to role:readonly. This is a potential security risk as any user (without any privileges) that is able to login to OCP can see all resources managed by the ArgoCD instance (secrets, network policies, routes, ...). This ArgoCD instance is intended for Cluster management so there is high chance of potential misuse of sensitive data.
Environment
- Red Hat OpenShift GitOps 1.9 and earlier
Subscriber exclusive content
A Red Hat subscription provides unlimited access to our knowledgebase, tools, and much more.