youtube image
From YouTube: Attacking Argo CD with Argo CD (and then Defending) - Michael Crenshaw, Intuit


Attacking Argo CD with Argo CD (and then Defending) - Michael Crenshaw, Intuit

Argo CD manages Kubernetes resources, and Argo CD is itself a set of Kubernetes resources. This talk will show how a lax RBAC configuration could allow users to escalate their privileges by using Argo CD to modify Argo CD. We’ll start with a trivial attack and then incrementally restrict Argo CD RBAC and Project restrictions until no attack is possible. This talk will demonstrate the process that every Argo CD admin should follow when setting up their Argo CD RBAC and Project settings.