Uploaded image for project: 'OpenShift GitOps'
  1. OpenShift GitOps
  2. GITOPS-7786 Unwanted RHSDLC tasks
  3. GITOPS-7784

Secure Deployment Weakness: Argo CD Secrets with External Secret Operator

XMLWordPrintable

    • Icon: Sub-task Sub-task
    • Resolution: Done
    • Icon: Major Major
    • None
    • 1.17.0
    • Documentation
    • False
    • Hide

      None

      Show
      None
    • False

      An external researcher found a way using External Secrets Operator(ESO) in Kubernetes ArgoCD to enable privilege escalation and authentication bypass. They want to know if there is a OpenShift GitOps x ESO deployment and if it’s secured, so this doesn’t happen.

      Discussed 06/23/25 with rh-ee-sghadi and jprabhak@redhat.com. This should be handled according to the Weakness Management Standard.

      Action

      • Recreate GitOps with AWS Secrets Manager deployment from ArgoCD Secrets Write-Up to confirm if GitOps is affected
      • Referencing Recommendations from slide 16

              rh-ee-sghadi Siddhesh Ghadi
              rh-ee-ellin Elise Lin
              Votes:
              0 Vote for this issue
              Watchers:
              1 Start watching this issue

                Created:
                Updated:
                Resolved: