A flaw was found in argocd. Any unprivileged user is able to deploy argocd in their namespace and with the created ServiceAccount argocd-argocd-server, the unprivileged user is able to read all resources of the cluster including all secrets which might enable privilege escalations. The highest threat from this vulnerability is to data confidentiality.
В классическом CI/CD пайплайн заканчивается деплоем, но дальше состояние Kubernetes‑кластера может незаметно разойтись с конфигурацией в Git. Разбираемся, как ArgoCD обнаруживает и исправляет такой дрейф, как настроить синхронизацию и где автоматизация GitOps требует особенно осторожного подхода. Разобрать практику
В какой-то момент в нашей команде стало очевидно: пора тащить всю инфраструктуру в Git — по-взрослому, через GitOps. Kubernetes у нас уже был, ArgoCD тоже. Осталось «дотащить» туда AWS-ресурсы, которые мы описываем с помощью AWS CDK.Идея казалась простой: есть CDK-код в Git, запускается ArgoCD, всё красиво
Argo CD is a declarative continuous deployment for Kubernetes. All versions of ArgoCD starting from v2.4 have a bug where the ArgoCD repo-server component is vulnerable to a Denial-of-Service attack vector. Specifically, the said component extracts a user-controlled tar.gz file without validating the size of its inner files. As a result, a malicious, low-privileged user can send a malicious tar.gz file that exploits this vulnerability to the repo-server, thereby harming the system's functionality and…