index.html 62 KB

12345678910111213141516171819202122232425262728293031323334353637383940414243444546474849505152535455565758596061626364656667686970717273747576777879808182838485868788899091929394959697989910010110210310410510610710810911011111211311411511611711811912012112212312412512612712812913013113213313413513613713813914014114214314414514614714814915015115215315415515615715815916016116216316416516616716816917017117217317417517617717817918018118218318418518618718818919019119219319419519619719819920020120220320420520620720820921021121221321421521621721821922022122222322422522622722822923023123223323423523623723823924024124224324424524624724824925025125225325425525625725825926026126226326426526626726826927027127227327427527627727827928028128228328428528628728828929029129229329429529629729829930030130230330430530630730830931031131231331431531631731831932032132232332432532632732832933033133233333433533633733833934034134234334434534634734834935035135235335435535635735835936036136236336436536636736836937037137237337437537637737837938038138238338438538638738838939039139239339439539639739839940040140240340440540640740840941041141241341441541641741841942042142242342442542642742842943043143243343443543643743843944044144244344444544644744844945045145245345445545645745845946046146246346446546646746846947047147247347447547647747847948048148248348448548648748848949049149249349449549649749849950050150250350450550650750850951051151251351451551651751851952052152252352452552652752852953053153253353453553653753853954054154254354454554654754854955055155255355455555655755855956056156256356456556656756856957057157257357457557657757857958058158258358458558658758858959059159259359459559659759859960060160260360460560660760860961061161261361461561661761861962062162262362462562662762862963063163263363463563663763863964064164264364464564664764864965065165265365465565665765865966066166266366466566666766866967067167267367467567667767867968068168268368468568668768868969069169269369469569669769869970070170270370470570670770870971071171271371471571671771871972072172272372472572672772872973073173273373473573673773873974074174274374474574674774874975075175275375475575675775875976076176276376476576676776876977077177277377477577677777877978078178278378478578678778878979079179279379479579679779879980080180280380480580680780880981081181281381481581681781881982082182282382482582682782882983083183283383483583683783883984084184284384484584684784884985085185285385485585685785885986086186286386486586686786886987087187287387487587687787887988088188288388488588688788888989089189289389489589689789889990090190290390490590690790890991091191291391491591691791891992092192292392492592692792892993093193293393493593693793893994094194294394494594694794894995095195295395495595695795895996096196296396496596696796896997097197297397497597697797897998098198298398498598698798898999099199299399499599699799899910001001100210031004100510061007100810091010101110121013101410151016101710181019102010211022102310241025102610271028102910301031103210331034103510361037103810391040104110421043104410451046104710481049105010511052105310541055105610571058105910601061106210631064106510661067106810691070107110721073107410751076107710781079108010811082108310841085108610871088108910901091109210931094109510961097109810991100110111021103110411051106110711081109111011111112111311141115111611171118111911201121112211231124112511261127112811291130113111321133113411351136113711381139114011411142114311441145114611471148114911501151115211531154115511561157115811591160116111621163116411651166116711681169117011711172117311741175117611771178117911801181118211831184118511861187118811891190119111921193119411951196119711981199120012011202120312041205120612071208120912101211121212131214121512161217121812191220122112221223122412251226122712281229123012311232123312341235123612371238123912401241124212431244124512461247124812491250125112521253125412551256125712581259126012611262126312641265126612671268126912701271127212731274127512761277127812791280128112821283128412851286128712881289129012911292129312941295129612971298129913001301130213031304130513061307130813091310131113121313131413151316131713181319132013211322132313241325132613271328132913301331133213331334133513361337133813391340134113421343134413451346134713481349135013511352135313541355135613571358135913601361136213631364136513661367136813691370137113721373137413751376137713781379138013811382138313841385138613871388138913901391139213931394139513961397139813991400140114021403140414051406140714081409141014111412141314141415141614171418141914201421142214231424142514261427142814291430143114321433143414351436143714381439144014411442144314441445144614471448144914501451145214531454145514561457145814591460146114621463146414651466146714681469147014711472147314741475147614771478147914801481148214831484148514861487148814891490149114921493149414951496149714981499150015011502150315041505150615071508150915101511151215131514151515161517151815191520152115221523152415251526152715281529153015311532153315341535153615371538153915401541154215431544154515461547154815491550155115521553155415551556155715581559156015611562156315641565156615671568156915701571157215731574157515761577157815791580158115821583158415851586158715881589159015911592159315941595159615971598159916001601160216031604160516061607160816091610161116121613161416151616161716181619162016211622162316241625162616271628162916301631163216331634163516361637163816391640164116421643164416451646164716481649165016511652165316541655165616571658165916601661166216631664166516661667166816691670167116721673167416751676167716781679168016811682168316841685168616871688168916901691169216931694169516961697169816991700170117021703170417051706170717081709171017111712171317141715171617171718171917201721172217231724172517261727172817291730173117321733173417351736173717381739174017411742174317441745174617471748174917501751175217531754175517561757175817591760176117621763176417651766176717681769177017711772177317741775177617771778177917801781178217831784178517861787178817891790179117921793179417951796179717981799180018011802180318041805180618071808180918101811181218131814181518161817181818191820182118221823182418251826182718281829183018311832183318341835183618371838183918401841184218431844184518461847184818491850185118521853185418551856185718581859186018611862186318641865186618671868186918701871187218731874187518761877187818791880188118821883188418851886188718881889189018911892189318941895189618971898189919001901190219031904190519061907190819091910191119121913191419151916191719181919192019211922192319241925192619271928192919301931193219331934193519361937193819391940194119421943194419451946194719481949195019511952195319541955195619571958195919601961196219631964196519661967196819691970197119721973197419751976197719781979198019811982198319841985198619871988198919901991199219931994199519961997199819992000200120022003200420052006200720082009201020112012201320142015201620172018201920202021202220232024202520262027202820292030203120322033203420352036203720382039204020412042204320442045204620472048204920502051205220532054205520562057205820592060206120622063206420652066206720682069207020712072207320742075207620772078207920802081208220832084208520862087208820892090209120922093209420952096209720982099210021012102210321042105210621072108210921102111211221132114211521162117211821192120212121222123212421252126212721282129213021312132213321342135213621372138213921402141214221432144214521462147214821492150215121522153215421552156215721582159216021612162216321642165216621672168216921702171217221732174217521762177217821792180218121822183218421852186218721882189219021912192219321942195219621972198219922002201220222032204220522062207220822092210221122122213221422152216221722182219222022212222222322242225222622272228222922302231223222332234223522362237223822392240224122422243224422452246224722482249225022512252225322542255225622572258225922602261226222632264226522662267226822692270227122722273227422752276227722782279228022812282228322842285228622872288228922902291229222932294229522962297229822992300230123022303230423052306230723082309231023112312231323142315231623172318231923202321232223232324232523262327232823292330233123322333233423352336233723382339234023412342234323442345234623472348234923502351235223532354235523562357235823592360236123622363236423652366236723682369237023712372237323742375237623772378237923802381238223832384238523862387238823892390239123922393239423952396239723982399240024012402240324042405240624072408240924102411241224132414241524162417241824192420242124222423242424252426242724282429243024312432243324342435243624372438243924402441244224432444244524462447244824492450245124522453245424552456245724582459246024612462246324642465246624672468246924702471247224732474247524762477247824792480248124822483248424852486248724882489249024912492249324942495249624972498249925002501250225032504250525062507250825092510251125122513251425152516251725182519252025212522252325242525252625272528252925302531253225332534253525362537253825392540254125422543254425452546254725482549255025512552255325542555255625572558255925602561256225632564256525662567256825692570257125722573257425752576257725782579258025812582258325842585258625872588258925902591259225932594259525962597259825992600260126022603260426052606260726082609261026112612261326142615261626172618261926202621262226232624262526262627262826292630263126322633263426352636263726382639264026412642264326442645264626472648264926502651265226532654265526562657265826592660266126622663266426652666266726682669267026712672267326742675267626772678267926802681268226832684268526862687268826892690269126922693
  1. <!doctype html>
  2. <html lang="en" class="no-js">
  3. <head>
  4. <meta charset="utf-8">
  5. <meta name="viewport" content="width=device-width,initial-scale=1">
  6. <link rel="prev" href="../security-best-practices/">
  7. <link rel="next" href="../v1beta1/">
  8. <link rel="icon" href="../../assets/images/favicon.png">
  9. <meta name="generator" content="mkdocs-1.4.3, mkdocs-material-9.1.9">
  10. <title>Threat Model - External Secrets Operator</title>
  11. <link rel="stylesheet" href="../../assets/stylesheets/main.85bb2934.min.css">
  12. <link rel="preconnect" href="https://fonts.gstatic.com" crossorigin>
  13. <link rel="stylesheet" href="https://fonts.googleapis.com/css?family=Roboto:300,300i,400,400i,700,700i%7CRoboto+Mono:400,400i,700,700i&display=fallback">
  14. <style>:root{--md-text-font:"Roboto";--md-code-font:"Roboto Mono"}</style>
  15. <script>__md_scope=new URL("../..",location),__md_hash=e=>[...e].reduce((e,_)=>(e<<5)-e+_.charCodeAt(0),0),__md_get=(e,_=localStorage,t=__md_scope)=>JSON.parse(_.getItem(t.pathname+"."+e)),__md_set=(e,_,t=localStorage,a=__md_scope)=>{try{t.setItem(a.pathname+"."+e,JSON.stringify(_))}catch(e){}}</script>
  16. <script id="__analytics">function __md_analytics(){function n(){dataLayer.push(arguments)}window.dataLayer=window.dataLayer||[],n("js",new Date),n("config","G-QP38TD8K7V"),document.addEventListener("DOMContentLoaded",function(){document.forms.search&&document.forms.search.query.addEventListener("blur",function(){this.value&&n("event","search",{search_term:this.value})}),document$.subscribe(function(){var a=document.forms.feedback;if(void 0!==a)for(var e of a.querySelectorAll("[type=submit]"))e.addEventListener("click",function(e){e.preventDefault();var t=document.location.pathname,e=this.getAttribute("data-md-value");n("event","feedback",{page:t,data:e}),a.firstElementChild.disabled=!0;e=a.querySelector(".md-feedback__note [data-md-value='"+e+"']");e&&(e.hidden=!1)}),a.hidden=!1}),location$.subscribe(function(e){n("config","G-QP38TD8K7V",{page_path:e.pathname})})});var e=document.createElement("script");e.async=!0,e.src="https://www.googletagmanager.com/gtag/js?id=G-QP38TD8K7V",document.getElementById("__analytics").insertAdjacentElement("afterEnd",e)}</script>
  17. <script>"undefined"!=typeof __md_analytics&&__md_analytics()</script>
  18. </head>
  19. <body dir="ltr">
  20. <script>var palette=__md_get("__palette");if(palette&&"object"==typeof palette.color)for(var key of Object.keys(palette.color))document.body.setAttribute("data-md-color-"+key,palette.color[key])</script>
  21. <input class="md-toggle" data-md-toggle="drawer" type="checkbox" id="__drawer" autocomplete="off">
  22. <input class="md-toggle" data-md-toggle="search" type="checkbox" id="__search" autocomplete="off">
  23. <label class="md-overlay" for="__drawer"></label>
  24. <div data-md-component="skip">
  25. <a href="#background" class="md-skip">
  26. Skip to content
  27. </a>
  28. </div>
  29. <div data-md-component="announce">
  30. </div>
  31. <div data-md-color-scheme="default" data-md-component="outdated" hidden>
  32. <aside class="md-banner md-banner--warning">
  33. <div class="md-banner__inner md-grid md-typeset">
  34. You're not viewing the latest version.
  35. <a href="../../..">
  36. <strong>Click here to go to latest.</strong>
  37. </a>
  38. </div>
  39. <script>var el=document.querySelector("[data-md-component=outdated]"),outdated=__md_get("__outdated",sessionStorage);!0===outdated&&el&&(el.hidden=!1)</script>
  40. </aside>
  41. </div>
  42. <header class="md-header" data-md-component="header">
  43. <nav class="md-header__inner md-grid" aria-label="Header">
  44. <a href="../.." title="External Secrets Operator" class="md-header__button md-logo" aria-label="External Secrets Operator" data-md-component="logo">
  45. <svg xmlns="http://www.w3.org/2000/svg" viewBox="0 0 24 24"><path d="M12 8a3 3 0 0 0 3-3 3 3 0 0 0-3-3 3 3 0 0 0-3 3 3 3 0 0 0 3 3m0 3.54C9.64 9.35 6.5 8 3 8v11c3.5 0 6.64 1.35 9 3.54 2.36-2.19 5.5-3.54 9-3.54V8c-3.5 0-6.64 1.35-9 3.54Z"/></svg>
  46. </a>
  47. <label class="md-header__button md-icon" for="__drawer">
  48. <svg xmlns="http://www.w3.org/2000/svg" viewBox="0 0 24 24"><path d="M3 6h18v2H3V6m0 5h18v2H3v-2m0 5h18v2H3v-2Z"/></svg>
  49. </label>
  50. <div class="md-header__title" data-md-component="header-title">
  51. <div class="md-header__ellipsis">
  52. <div class="md-header__topic">
  53. <span class="md-ellipsis">
  54. External Secrets Operator
  55. </span>
  56. </div>
  57. <div class="md-header__topic" data-md-component="header-topic">
  58. <span class="md-ellipsis">
  59. Threat Model
  60. </span>
  61. </div>
  62. </div>
  63. </div>
  64. <label class="md-header__button md-icon" for="__search">
  65. <svg xmlns="http://www.w3.org/2000/svg" viewBox="0 0 24 24"><path d="M9.5 3A6.5 6.5 0 0 1 16 9.5c0 1.61-.59 3.09-1.56 4.23l.27.27h.79l5 5-1.5 1.5-5-5v-.79l-.27-.27A6.516 6.516 0 0 1 9.5 16 6.5 6.5 0 0 1 3 9.5 6.5 6.5 0 0 1 9.5 3m0 2C7 5 5 7 5 9.5S7 14 9.5 14 14 12 14 9.5 12 5 9.5 5Z"/></svg>
  66. </label>
  67. <div class="md-search" data-md-component="search" role="dialog">
  68. <label class="md-search__overlay" for="__search"></label>
  69. <div class="md-search__inner" role="search">
  70. <form class="md-search__form" name="search">
  71. <input type="text" class="md-search__input" name="query" aria-label="Search" placeholder="Search" autocapitalize="off" autocorrect="off" autocomplete="off" spellcheck="false" data-md-component="search-query" required>
  72. <label class="md-search__icon md-icon" for="__search">
  73. <svg xmlns="http://www.w3.org/2000/svg" viewBox="0 0 24 24"><path d="M9.5 3A6.5 6.5 0 0 1 16 9.5c0 1.61-.59 3.09-1.56 4.23l.27.27h.79l5 5-1.5 1.5-5-5v-.79l-.27-.27A6.516 6.516 0 0 1 9.5 16 6.5 6.5 0 0 1 3 9.5 6.5 6.5 0 0 1 9.5 3m0 2C7 5 5 7 5 9.5S7 14 9.5 14 14 12 14 9.5 12 5 9.5 5Z"/></svg>
  74. <svg xmlns="http://www.w3.org/2000/svg" viewBox="0 0 24 24"><path d="M20 11v2H8l5.5 5.5-1.42 1.42L4.16 12l7.92-7.92L13.5 5.5 8 11h12Z"/></svg>
  75. </label>
  76. <nav class="md-search__options" aria-label="Search">
  77. <button type="reset" class="md-search__icon md-icon" title="Clear" aria-label="Clear" tabindex="-1">
  78. <svg xmlns="http://www.w3.org/2000/svg" viewBox="0 0 24 24"><path d="M19 6.41 17.59 5 12 10.59 6.41 5 5 6.41 10.59 12 5 17.59 6.41 19 12 13.41 17.59 19 19 17.59 13.41 12 19 6.41Z"/></svg>
  79. </button>
  80. </nav>
  81. </form>
  82. <div class="md-search__output">
  83. <div class="md-search__scrollwrap" data-md-scrollfix>
  84. <div class="md-search-result" data-md-component="search-result">
  85. <div class="md-search-result__meta">
  86. Initializing search
  87. </div>
  88. <ol class="md-search-result__list" role="presentation"></ol>
  89. </div>
  90. </div>
  91. </div>
  92. </div>
  93. </div>
  94. <div class="md-header__source">
  95. <a href="https://github.com/external-secrets/external-secrets" title="Go to repository" class="md-source" data-md-component="source">
  96. <div class="md-source__icon md-icon">
  97. <svg xmlns="http://www.w3.org/2000/svg" viewBox="0 0 448 512"><!--! Font Awesome Free 6.4.0 by @fontawesome - https://fontawesome.com License - https://fontawesome.com/license/free (Icons: CC BY 4.0, Fonts: SIL OFL 1.1, Code: MIT License) Copyright 2023 Fonticons, Inc.--><path d="M439.55 236.05 244 40.45a28.87 28.87 0 0 0-40.81 0l-40.66 40.63 51.52 51.52c27.06-9.14 52.68 16.77 43.39 43.68l49.66 49.66c34.23-11.8 61.18 31 35.47 56.69-26.49 26.49-70.21-2.87-56-37.34L240.22 199v121.85c25.3 12.54 22.26 41.85 9.08 55a34.34 34.34 0 0 1-48.55 0c-17.57-17.6-11.07-46.91 11.25-56v-123c-20.8-8.51-24.6-30.74-18.64-45L142.57 101 8.45 235.14a28.86 28.86 0 0 0 0 40.81l195.61 195.6a28.86 28.86 0 0 0 40.8 0l194.69-194.69a28.86 28.86 0 0 0 0-40.81z"/></svg>
  98. </div>
  99. <div class="md-source__repository">
  100. External Secrets Operator
  101. </div>
  102. </a>
  103. </div>
  104. </nav>
  105. </header>
  106. <div class="md-container" data-md-component="container">
  107. <nav class="md-tabs" aria-label="Tabs" data-md-component="tabs">
  108. <div class="md-grid">
  109. <ul class="md-tabs__list">
  110. <li class="md-tabs__item">
  111. <a href="../.." class="md-tabs__link">
  112. Introduction
  113. </a>
  114. </li>
  115. <li class="md-tabs__item">
  116. <a href="../../api/components/" class="md-tabs__link">
  117. API
  118. </a>
  119. </li>
  120. <li class="md-tabs__item">
  121. <a href="../introduction/" class="md-tabs__link md-tabs__link--active">
  122. Guides
  123. </a>
  124. </li>
  125. <li class="md-tabs__item">
  126. <a href="../../provider/aws-secrets-manager/" class="md-tabs__link">
  127. Provider
  128. </a>
  129. </li>
  130. <li class="md-tabs__item">
  131. <a href="../../examples/gitops-using-fluxcd/" class="md-tabs__link">
  132. Examples
  133. </a>
  134. </li>
  135. <li class="md-tabs__item">
  136. <a href="../../contributing/devguide/" class="md-tabs__link">
  137. Community
  138. </a>
  139. </li>
  140. </ul>
  141. </div>
  142. </nav>
  143. <main class="md-main" data-md-component="main">
  144. <div class="md-main__inner md-grid">
  145. <div class="md-sidebar md-sidebar--primary" data-md-component="sidebar" data-md-type="navigation" >
  146. <div class="md-sidebar__scrollwrap">
  147. <div class="md-sidebar__inner">
  148. <nav class="md-nav md-nav--primary md-nav--lifted" aria-label="Navigation" data-md-level="0">
  149. <label class="md-nav__title" for="__drawer">
  150. <a href="../.." title="External Secrets Operator" class="md-nav__button md-logo" aria-label="External Secrets Operator" data-md-component="logo">
  151. <svg xmlns="http://www.w3.org/2000/svg" viewBox="0 0 24 24"><path d="M12 8a3 3 0 0 0 3-3 3 3 0 0 0-3-3 3 3 0 0 0-3 3 3 3 0 0 0 3 3m0 3.54C9.64 9.35 6.5 8 3 8v11c3.5 0 6.64 1.35 9 3.54 2.36-2.19 5.5-3.54 9-3.54V8c-3.5 0-6.64 1.35-9 3.54Z"/></svg>
  152. </a>
  153. External Secrets Operator
  154. </label>
  155. <div class="md-nav__source">
  156. <a href="https://github.com/external-secrets/external-secrets" title="Go to repository" class="md-source" data-md-component="source">
  157. <div class="md-source__icon md-icon">
  158. <svg xmlns="http://www.w3.org/2000/svg" viewBox="0 0 448 512"><!--! Font Awesome Free 6.4.0 by @fontawesome - https://fontawesome.com License - https://fontawesome.com/license/free (Icons: CC BY 4.0, Fonts: SIL OFL 1.1, Code: MIT License) Copyright 2023 Fonticons, Inc.--><path d="M439.55 236.05 244 40.45a28.87 28.87 0 0 0-40.81 0l-40.66 40.63 51.52 51.52c27.06-9.14 52.68 16.77 43.39 43.68l49.66 49.66c34.23-11.8 61.18 31 35.47 56.69-26.49 26.49-70.21-2.87-56-37.34L240.22 199v121.85c25.3 12.54 22.26 41.85 9.08 55a34.34 34.34 0 0 1-48.55 0c-17.57-17.6-11.07-46.91 11.25-56v-123c-20.8-8.51-24.6-30.74-18.64-45L142.57 101 8.45 235.14a28.86 28.86 0 0 0 0 40.81l195.61 195.6a28.86 28.86 0 0 0 40.8 0l194.69-194.69a28.86 28.86 0 0 0 0-40.81z"/></svg>
  159. </div>
  160. <div class="md-source__repository">
  161. External Secrets Operator
  162. </div>
  163. </a>
  164. </div>
  165. <ul class="md-nav__list" data-md-scrollfix>
  166. <li class="md-nav__item md-nav__item--nested">
  167. <input class="md-nav__toggle md-toggle md-toggle--indeterminate" type="checkbox" id="__nav_1" >
  168. <div class="md-nav__link md-nav__link--index ">
  169. <a href="../..">Introduction</a>
  170. <label for="__nav_1">
  171. <span class="md-nav__icon md-icon"></span>
  172. </label>
  173. </div>
  174. <nav class="md-nav" data-md-level="1" aria-labelledby="__nav_1_label" aria-expanded="false">
  175. <label class="md-nav__title" for="__nav_1">
  176. <span class="md-nav__icon md-icon"></span>
  177. Introduction
  178. </label>
  179. <ul class="md-nav__list" data-md-scrollfix>
  180. <li class="md-nav__item">
  181. <a href="../../introduction/overview/" class="md-nav__link">
  182. Overview
  183. </a>
  184. </li>
  185. <li class="md-nav__item">
  186. <a href="../../introduction/getting-started/" class="md-nav__link">
  187. Getting started
  188. </a>
  189. </li>
  190. <li class="md-nav__item">
  191. <a href="../../introduction/faq/" class="md-nav__link">
  192. FAQ
  193. </a>
  194. </li>
  195. <li class="md-nav__item">
  196. <a href="../../introduction/stability-support/" class="md-nav__link">
  197. Stability and Support
  198. </a>
  199. </li>
  200. <li class="md-nav__item">
  201. <a href="../../introduction/deprecation-policy/" class="md-nav__link">
  202. Deprecation Policy
  203. </a>
  204. </li>
  205. </ul>
  206. </nav>
  207. </li>
  208. <li class="md-nav__item md-nav__item--nested">
  209. <input class="md-nav__toggle md-toggle md-toggle--indeterminate" type="checkbox" id="__nav_2" >
  210. <label class="md-nav__link" for="__nav_2" id="__nav_2_label" tabindex="0">
  211. API
  212. <span class="md-nav__icon md-icon"></span>
  213. </label>
  214. <nav class="md-nav" data-md-level="1" aria-labelledby="__nav_2_label" aria-expanded="false">
  215. <label class="md-nav__title" for="__nav_2">
  216. <span class="md-nav__icon md-icon"></span>
  217. API
  218. </label>
  219. <ul class="md-nav__list" data-md-scrollfix>
  220. <li class="md-nav__item">
  221. <a href="../../api/components/" class="md-nav__link">
  222. Components
  223. </a>
  224. </li>
  225. <li class="md-nav__item md-nav__item--nested">
  226. <input class="md-nav__toggle md-toggle md-toggle--indeterminate" type="checkbox" id="__nav_2_2" >
  227. <label class="md-nav__link" for="__nav_2_2" id="__nav_2_2_label" tabindex="0">
  228. Core Resources
  229. <span class="md-nav__icon md-icon"></span>
  230. </label>
  231. <nav class="md-nav" data-md-level="2" aria-labelledby="__nav_2_2_label" aria-expanded="false">
  232. <label class="md-nav__title" for="__nav_2_2">
  233. <span class="md-nav__icon md-icon"></span>
  234. Core Resources
  235. </label>
  236. <ul class="md-nav__list" data-md-scrollfix>
  237. <li class="md-nav__item">
  238. <a href="../../api/externalsecret/" class="md-nav__link">
  239. ExternalSecret
  240. </a>
  241. </li>
  242. <li class="md-nav__item">
  243. <a href="../../api/secretstore/" class="md-nav__link">
  244. SecretStore
  245. </a>
  246. </li>
  247. <li class="md-nav__item">
  248. <a href="../../api/clustersecretstore/" class="md-nav__link">
  249. ClusterSecretStore
  250. </a>
  251. </li>
  252. <li class="md-nav__item">
  253. <a href="../../api/clusterexternalsecret/" class="md-nav__link">
  254. ClusterExternalSecret
  255. </a>
  256. </li>
  257. <li class="md-nav__item">
  258. <a href="../../api/pushsecret/" class="md-nav__link">
  259. PushSecret
  260. </a>
  261. </li>
  262. </ul>
  263. </nav>
  264. </li>
  265. <li class="md-nav__item md-nav__item--nested">
  266. <input class="md-nav__toggle md-toggle md-toggle--indeterminate" type="checkbox" id="__nav_2_3" >
  267. <div class="md-nav__link md-nav__link--index ">
  268. <a href="../../api/generator/">Generators</a>
  269. <label for="__nav_2_3">
  270. <span class="md-nav__icon md-icon"></span>
  271. </label>
  272. </div>
  273. <nav class="md-nav" data-md-level="2" aria-labelledby="__nav_2_3_label" aria-expanded="false">
  274. <label class="md-nav__title" for="__nav_2_3">
  275. <span class="md-nav__icon md-icon"></span>
  276. Generators
  277. </label>
  278. <ul class="md-nav__list" data-md-scrollfix>
  279. <li class="md-nav__item">
  280. <a href="../../api/generator/acr/" class="md-nav__link">
  281. Azure Container Registry
  282. </a>
  283. </li>
  284. <li class="md-nav__item">
  285. <a href="../../api/generator/ecr/" class="md-nav__link">
  286. AWS Elastic Container Registry
  287. </a>
  288. </li>
  289. <li class="md-nav__item">
  290. <a href="../../api/generator/gcr/" class="md-nav__link">
  291. Google Container Registry
  292. </a>
  293. </li>
  294. <li class="md-nav__item">
  295. <a href="../../api/generator/vault/" class="md-nav__link">
  296. Vault Dynamic Secret
  297. </a>
  298. </li>
  299. <li class="md-nav__item">
  300. <a href="../../api/generator/password/" class="md-nav__link">
  301. Password
  302. </a>
  303. </li>
  304. <li class="md-nav__item">
  305. <a href="../../api/generator/fake/" class="md-nav__link">
  306. Fake
  307. </a>
  308. </li>
  309. </ul>
  310. </nav>
  311. </li>
  312. <li class="md-nav__item md-nav__item--nested">
  313. <input class="md-nav__toggle md-toggle md-toggle--indeterminate" type="checkbox" id="__nav_2_4" >
  314. <label class="md-nav__link" for="__nav_2_4" id="__nav_2_4_label" tabindex="0">
  315. Reference Docs
  316. <span class="md-nav__icon md-icon"></span>
  317. </label>
  318. <nav class="md-nav" data-md-level="2" aria-labelledby="__nav_2_4_label" aria-expanded="false">
  319. <label class="md-nav__title" for="__nav_2_4">
  320. <span class="md-nav__icon md-icon"></span>
  321. Reference Docs
  322. </label>
  323. <ul class="md-nav__list" data-md-scrollfix>
  324. <li class="md-nav__item">
  325. <a href="../../api/spec/" class="md-nav__link">
  326. API specification
  327. </a>
  328. </li>
  329. <li class="md-nav__item">
  330. <a href="../../api/controller-options/" class="md-nav__link">
  331. Controller Options
  332. </a>
  333. </li>
  334. <li class="md-nav__item">
  335. <a href="../../api/metrics/" class="md-nav__link">
  336. Metrics
  337. </a>
  338. </li>
  339. </ul>
  340. </nav>
  341. </li>
  342. </ul>
  343. </nav>
  344. </li>
  345. <li class="md-nav__item md-nav__item--active md-nav__item--nested">
  346. <input class="md-nav__toggle md-toggle " type="checkbox" id="__nav_3" checked>
  347. <label class="md-nav__link" for="__nav_3" id="__nav_3_label" tabindex="0">
  348. Guides
  349. <span class="md-nav__icon md-icon"></span>
  350. </label>
  351. <nav class="md-nav" data-md-level="1" aria-labelledby="__nav_3_label" aria-expanded="true">
  352. <label class="md-nav__title" for="__nav_3">
  353. <span class="md-nav__icon md-icon"></span>
  354. Guides
  355. </label>
  356. <ul class="md-nav__list" data-md-scrollfix>
  357. <li class="md-nav__item">
  358. <a href="../introduction/" class="md-nav__link">
  359. Introduction
  360. </a>
  361. </li>
  362. <li class="md-nav__item md-nav__item--nested">
  363. <input class="md-nav__toggle md-toggle md-toggle--indeterminate" type="checkbox" id="__nav_3_2" >
  364. <label class="md-nav__link" for="__nav_3_2" id="__nav_3_2_label" tabindex="0">
  365. External Secrets
  366. <span class="md-nav__icon md-icon"></span>
  367. </label>
  368. <nav class="md-nav" data-md-level="2" aria-labelledby="__nav_3_2_label" aria-expanded="false">
  369. <label class="md-nav__title" for="__nav_3_2">
  370. <span class="md-nav__icon md-icon"></span>
  371. External Secrets
  372. </label>
  373. <ul class="md-nav__list" data-md-scrollfix>
  374. <li class="md-nav__item">
  375. <a href="../all-keys-one-secret/" class="md-nav__link">
  376. Extract structured data
  377. </a>
  378. </li>
  379. <li class="md-nav__item">
  380. <a href="../getallsecrets/" class="md-nav__link">
  381. Find Secrets by Name or Metadata
  382. </a>
  383. </li>
  384. <li class="md-nav__item">
  385. <a href="../datafrom-rewrite/" class="md-nav__link">
  386. Rewriting Keys
  387. </a>
  388. </li>
  389. <li class="md-nav__item md-nav__item--nested">
  390. <input class="md-nav__toggle md-toggle md-toggle--indeterminate" type="checkbox" id="__nav_3_2_4" >
  391. <label class="md-nav__link" for="__nav_3_2_4" id="__nav_3_2_4_label" tabindex="0">
  392. Advanced Templating
  393. <span class="md-nav__icon md-icon"></span>
  394. </label>
  395. <nav class="md-nav" data-md-level="3" aria-labelledby="__nav_3_2_4_label" aria-expanded="false">
  396. <label class="md-nav__title" for="__nav_3_2_4">
  397. <span class="md-nav__icon md-icon"></span>
  398. Advanced Templating
  399. </label>
  400. <ul class="md-nav__list" data-md-scrollfix>
  401. <li class="md-nav__item">
  402. <a href="../templating/" class="md-nav__link">
  403. v2
  404. </a>
  405. </li>
  406. <li class="md-nav__item">
  407. <a href="../templating-v1/" class="md-nav__link">
  408. v1
  409. </a>
  410. </li>
  411. </ul>
  412. </nav>
  413. </li>
  414. <li class="md-nav__item">
  415. <a href="../common-k8s-secret-types/" class="md-nav__link">
  416. Kubernetes Secret Types
  417. </a>
  418. </li>
  419. <li class="md-nav__item">
  420. <a href="../ownership-deletion-policy/" class="md-nav__link">
  421. Lifecycle: ownership & deletion
  422. </a>
  423. </li>
  424. <li class="md-nav__item">
  425. <a href="../decoding-strategy/" class="md-nav__link">
  426. Decoding Strategies
  427. </a>
  428. </li>
  429. <li class="md-nav__item">
  430. <a href="../controller-class/" class="md-nav__link">
  431. Controller Classes
  432. </a>
  433. </li>
  434. </ul>
  435. </nav>
  436. </li>
  437. <li class="md-nav__item">
  438. <a href="../generator/" class="md-nav__link">
  439. Generators
  440. </a>
  441. </li>
  442. <li class="md-nav__item md-nav__item--active md-nav__item--nested">
  443. <input class="md-nav__toggle md-toggle " type="checkbox" id="__nav_3_4" checked>
  444. <label class="md-nav__link" for="__nav_3_4" id="__nav_3_4_label" tabindex="0">
  445. Operations
  446. <span class="md-nav__icon md-icon"></span>
  447. </label>
  448. <nav class="md-nav" data-md-level="2" aria-labelledby="__nav_3_4_label" aria-expanded="true">
  449. <label class="md-nav__title" for="__nav_3_4">
  450. <span class="md-nav__icon md-icon"></span>
  451. Operations
  452. </label>
  453. <ul class="md-nav__list" data-md-scrollfix>
  454. <li class="md-nav__item">
  455. <a href="../multi-tenancy/" class="md-nav__link">
  456. Multi Tenancy
  457. </a>
  458. </li>
  459. <li class="md-nav__item">
  460. <a href="../security-best-practices/" class="md-nav__link">
  461. Security Best Practices
  462. </a>
  463. </li>
  464. <li class="md-nav__item md-nav__item--active">
  465. <input class="md-nav__toggle md-toggle" type="checkbox" id="__toc">
  466. <label class="md-nav__link md-nav__link--active" for="__toc">
  467. Threat Model
  468. <span class="md-nav__icon md-icon"></span>
  469. </label>
  470. <a href="./" class="md-nav__link md-nav__link--active">
  471. Threat Model
  472. </a>
  473. <nav class="md-nav md-nav--secondary" aria-label="Table of contents">
  474. <label class="md-nav__title" for="__toc">
  475. <span class="md-nav__icon md-icon"></span>
  476. Table of contents
  477. </label>
  478. <ul class="md-nav__list" data-md-component="toc" data-md-scrollfix>
  479. <li class="md-nav__item">
  480. <a href="#background" class="md-nav__link">
  481. Background
  482. </a>
  483. <nav class="md-nav" aria-label="Background">
  484. <ul class="md-nav__list">
  485. <li class="md-nav__item">
  486. <a href="#summary" class="md-nav__link">
  487. Summary
  488. </a>
  489. </li>
  490. <li class="md-nav__item">
  491. <a href="#components" class="md-nav__link">
  492. Components
  493. </a>
  494. </li>
  495. </ul>
  496. </nav>
  497. </li>
  498. <li class="md-nav__item">
  499. <a href="#overview" class="md-nav__link">
  500. Overview
  501. </a>
  502. <nav class="md-nav" aria-label="Overview">
  503. <ul class="md-nav__list">
  504. <li class="md-nav__item">
  505. <a href="#scope" class="md-nav__link">
  506. Scope
  507. </a>
  508. </li>
  509. <li class="md-nav__item">
  510. <a href="#assets" class="md-nav__link">
  511. Assets
  512. </a>
  513. <nav class="md-nav" aria-label="Assets">
  514. <ul class="md-nav__list">
  515. <li class="md-nav__item">
  516. <a href="#a01-cluster-level-access-to-secrets" class="md-nav__link">
  517. A01: Cluster-Level access to secrets
  518. </a>
  519. </li>
  520. <li class="md-nav__item">
  521. <a href="#a02-crd-and-webhook-write-access" class="md-nav__link">
  522. A02: CRD and Webhook Write access
  523. </a>
  524. </li>
  525. <li class="md-nav__item">
  526. <a href="#a03-secret-provider-access" class="md-nav__link">
  527. A03: secret provider access
  528. </a>
  529. </li>
  530. <li class="md-nav__item">
  531. <a href="#a04-capability-to-modify-resources" class="md-nav__link">
  532. A04: capability to modify resources
  533. </a>
  534. </li>
  535. </ul>
  536. </nav>
  537. </li>
  538. <li class="md-nav__item">
  539. <a href="#threats" class="md-nav__link">
  540. Threats
  541. </a>
  542. <nav class="md-nav" aria-label="Threats">
  543. <ul class="md-nav__list">
  544. <li class="md-nav__item">
  545. <a href="#t01-tampering-with-resources-through-mitm" class="md-nav__link">
  546. T01: Tampering with resources through MITM
  547. </a>
  548. </li>
  549. <li class="md-nav__item">
  550. <a href="#t02-webhook-dos" class="md-nav__link">
  551. T02: Webhook DOS
  552. </a>
  553. </li>
  554. <li class="md-nav__item">
  555. <a href="#t03-unauthorized-access-to-cluster-secrets" class="md-nav__link">
  556. T03: Unauthorized access to cluster secrets
  557. </a>
  558. </li>
  559. <li class="md-nav__item">
  560. <a href="#t04-unauthorized-access-to-secret-provider-credentials" class="md-nav__link">
  561. T04: unauthorized access to secret provider credentials
  562. </a>
  563. </li>
  564. <li class="md-nav__item">
  565. <a href="#t05-data-exfiltration-through-malicious-resources" class="md-nav__link">
  566. T05: data exfiltration through malicious resources
  567. </a>
  568. </li>
  569. <li class="md-nav__item">
  570. <a href="#t06-supply-chain-attacks" class="md-nav__link">
  571. T06: supply chain attacks
  572. </a>
  573. </li>
  574. <li class="md-nav__item">
  575. <a href="#t07-malicious-workloads-in-eso-namespace" class="md-nav__link">
  576. T07: malicious workloads in eso namespace
  577. </a>
  578. </li>
  579. </ul>
  580. </nav>
  581. </li>
  582. <li class="md-nav__item">
  583. <a href="#controls" class="md-nav__link">
  584. Controls
  585. </a>
  586. <nav class="md-nav" aria-label="Controls">
  587. <ul class="md-nav__list">
  588. <li class="md-nav__item">
  589. <a href="#c01-network-security-policy" class="md-nav__link">
  590. C01: Network Security Policy
  591. </a>
  592. </li>
  593. <li class="md-nav__item">
  594. <a href="#c02-least-privilege-rbac" class="md-nav__link">
  595. C02: Least Privilege RBAC
  596. </a>
  597. </li>
  598. <li class="md-nav__item">
  599. <a href="#c03-policy-enforcement" class="md-nav__link">
  600. C03: Policy Enforcement
  601. </a>
  602. </li>
  603. <li class="md-nav__item">
  604. <a href="#c04-provider-access-policy" class="md-nav__link">
  605. C04: Provider Access Policy
  606. </a>
  607. </li>
  608. <li class="md-nav__item">
  609. <a href="#c05-entirely-disable-crds" class="md-nav__link">
  610. C05: Entirely disable CRDs
  611. </a>
  612. </li>
  613. </ul>
  614. </nav>
  615. </li>
  616. </ul>
  617. </nav>
  618. </li>
  619. </ul>
  620. </nav>
  621. </li>
  622. <li class="md-nav__item">
  623. <a href="../v1beta1/" class="md-nav__link">
  624. Upgrading to v1beta1
  625. </a>
  626. </li>
  627. <li class="md-nav__item">
  628. <a href="../using-latest-image/" class="md-nav__link">
  629. Using Latest Image
  630. </a>
  631. </li>
  632. <li class="md-nav__item">
  633. <a href="../disable-cluster-features/" class="md-nav__link">
  634. Disable Cluster Features
  635. </a>
  636. </li>
  637. </ul>
  638. </nav>
  639. </li>
  640. </ul>
  641. </nav>
  642. </li>
  643. <li class="md-nav__item md-nav__item--nested">
  644. <input class="md-nav__toggle md-toggle md-toggle--indeterminate" type="checkbox" id="__nav_4" >
  645. <label class="md-nav__link" for="__nav_4" id="__nav_4_label" tabindex="0">
  646. Provider
  647. <span class="md-nav__icon md-icon"></span>
  648. </label>
  649. <nav class="md-nav" data-md-level="1" aria-labelledby="__nav_4_label" aria-expanded="false">
  650. <label class="md-nav__title" for="__nav_4">
  651. <span class="md-nav__icon md-icon"></span>
  652. Provider
  653. </label>
  654. <ul class="md-nav__list" data-md-scrollfix>
  655. <li class="md-nav__item">
  656. <a href="../../provider/aws-secrets-manager/" class="md-nav__link">
  657. AWS Secrets Manager
  658. </a>
  659. </li>
  660. <li class="md-nav__item">
  661. <a href="../../provider/aws-parameter-store/" class="md-nav__link">
  662. AWS Parameter Store
  663. </a>
  664. </li>
  665. <li class="md-nav__item">
  666. <a href="../../provider/azure-key-vault/" class="md-nav__link">
  667. Azure Key Vault
  668. </a>
  669. </li>
  670. <li class="md-nav__item">
  671. <a href="../../provider/conjur/" class="md-nav__link">
  672. CyberArk Conjur
  673. </a>
  674. </li>
  675. <li class="md-nav__item">
  676. <a href="../../provider/google-secrets-manager/" class="md-nav__link">
  677. Google Cloud Secret Manager
  678. </a>
  679. </li>
  680. <li class="md-nav__item">
  681. <a href="../../provider/hashicorp-vault/" class="md-nav__link">
  682. HashiCorp Vault
  683. </a>
  684. </li>
  685. <li class="md-nav__item">
  686. <a href="../../provider/kubernetes/" class="md-nav__link">
  687. Kubernetes
  688. </a>
  689. </li>
  690. <li class="md-nav__item">
  691. <a href="../../provider/ibm-secrets-manager/" class="md-nav__link">
  692. IBM Secrets Manager
  693. </a>
  694. </li>
  695. <li class="md-nav__item">
  696. <a href="../../provider/akeyless/" class="md-nav__link">
  697. Akeyless
  698. </a>
  699. </li>
  700. <li class="md-nav__item">
  701. <a href="../../provider/yandex-certificate-manager/" class="md-nav__link">
  702. Yandex Certificate Manager
  703. </a>
  704. </li>
  705. <li class="md-nav__item">
  706. <a href="../../provider/yandex-lockbox/" class="md-nav__link">
  707. Yandex Lockbox
  708. </a>
  709. </li>
  710. <li class="md-nav__item">
  711. <a href="../../provider/alibaba/" class="md-nav__link">
  712. Alibaba Cloud
  713. </a>
  714. </li>
  715. <li class="md-nav__item">
  716. <a href="../../provider/gitlab-variables/" class="md-nav__link">
  717. GitLab Variables
  718. </a>
  719. </li>
  720. <li class="md-nav__item">
  721. <a href="../../provider/oracle-vault/" class="md-nav__link">
  722. Oracle Vault
  723. </a>
  724. </li>
  725. <li class="md-nav__item">
  726. <a href="../../provider/1password-automation/" class="md-nav__link">
  727. 1Password Secrets Automation
  728. </a>
  729. </li>
  730. <li class="md-nav__item">
  731. <a href="../../provider/webhook/" class="md-nav__link">
  732. Webhook
  733. </a>
  734. </li>
  735. <li class="md-nav__item">
  736. <a href="../../provider/fake/" class="md-nav__link">
  737. Fake
  738. </a>
  739. </li>
  740. <li class="md-nav__item">
  741. <a href="../../provider/senhasegura-dsm/" class="md-nav__link">
  742. senhasegura DevOps Secrets Management (DSM)
  743. </a>
  744. </li>
  745. <li class="md-nav__item">
  746. <a href="../../provider/doppler/" class="md-nav__link">
  747. Doppler
  748. </a>
  749. </li>
  750. <li class="md-nav__item">
  751. <a href="../../provider/keeper-security/" class="md-nav__link">
  752. Keeper Security
  753. </a>
  754. </li>
  755. <li class="md-nav__item">
  756. <a href="../../provider/cloak/" class="md-nav__link">
  757. Cloak End 2 End Encrypted Secrets
  758. </a>
  759. </li>
  760. <li class="md-nav__item">
  761. <a href="../../provider/scaleway/" class="md-nav__link">
  762. Scaleway
  763. </a>
  764. </li>
  765. <li class="md-nav__item">
  766. <a href="../../provider/delinea/" class="md-nav__link">
  767. Delinea
  768. </a>
  769. </li>
  770. </ul>
  771. </nav>
  772. </li>
  773. <li class="md-nav__item md-nav__item--nested">
  774. <input class="md-nav__toggle md-toggle md-toggle--indeterminate" type="checkbox" id="__nav_5" >
  775. <label class="md-nav__link" for="__nav_5" id="__nav_5_label" tabindex="0">
  776. Examples
  777. <span class="md-nav__icon md-icon"></span>
  778. </label>
  779. <nav class="md-nav" data-md-level="1" aria-labelledby="__nav_5_label" aria-expanded="false">
  780. <label class="md-nav__title" for="__nav_5">
  781. <span class="md-nav__icon md-icon"></span>
  782. Examples
  783. </label>
  784. <ul class="md-nav__list" data-md-scrollfix>
  785. <li class="md-nav__item">
  786. <a href="../../examples/gitops-using-fluxcd/" class="md-nav__link">
  787. FluxCD
  788. </a>
  789. </li>
  790. <li class="md-nav__item">
  791. <a href="../../examples/anchore-engine-credentials/" class="md-nav__link">
  792. Anchore Engine
  793. </a>
  794. </li>
  795. <li class="md-nav__item">
  796. <a href="../../examples/jenkins-kubernetes-credentials/" class="md-nav__link">
  797. Jenkins
  798. </a>
  799. </li>
  800. <li class="md-nav__item">
  801. <a href="../../examples/bitwarden/" class="md-nav__link">
  802. BitWarden
  803. </a>
  804. </li>
  805. </ul>
  806. </nav>
  807. </li>
  808. <li class="md-nav__item md-nav__item--nested">
  809. <input class="md-nav__toggle md-toggle md-toggle--indeterminate" type="checkbox" id="__nav_6" >
  810. <label class="md-nav__link" for="__nav_6" id="__nav_6_label" tabindex="0">
  811. Community
  812. <span class="md-nav__icon md-icon"></span>
  813. </label>
  814. <nav class="md-nav" data-md-level="1" aria-labelledby="__nav_6_label" aria-expanded="false">
  815. <label class="md-nav__title" for="__nav_6">
  816. <span class="md-nav__icon md-icon"></span>
  817. Community
  818. </label>
  819. <ul class="md-nav__list" data-md-scrollfix>
  820. <li class="md-nav__item md-nav__item--nested">
  821. <input class="md-nav__toggle md-toggle md-toggle--indeterminate" type="checkbox" id="__nav_6_1" >
  822. <label class="md-nav__link" for="__nav_6_1" id="__nav_6_1_label" tabindex="0">
  823. Contributing
  824. <span class="md-nav__icon md-icon"></span>
  825. </label>
  826. <nav class="md-nav" data-md-level="2" aria-labelledby="__nav_6_1_label" aria-expanded="false">
  827. <label class="md-nav__title" for="__nav_6_1">
  828. <span class="md-nav__icon md-icon"></span>
  829. Contributing
  830. </label>
  831. <ul class="md-nav__list" data-md-scrollfix>
  832. <li class="md-nav__item">
  833. <a href="../../contributing/devguide/" class="md-nav__link">
  834. Developer guide
  835. </a>
  836. </li>
  837. <li class="md-nav__item">
  838. <a href="../../contributing/process/" class="md-nav__link">
  839. Contributing Process
  840. </a>
  841. </li>
  842. <li class="md-nav__item">
  843. <a href="../../contributing/release/" class="md-nav__link">
  844. Release Process
  845. </a>
  846. </li>
  847. <li class="md-nav__item">
  848. <a href="../../contributing/coc/" class="md-nav__link">
  849. Code of Conduct
  850. </a>
  851. </li>
  852. <li class="md-nav__item">
  853. <a href="../../contributing/roadmap/" class="md-nav__link">
  854. Roadmap
  855. </a>
  856. </li>
  857. </ul>
  858. </nav>
  859. </li>
  860. <li class="md-nav__item md-nav__item--nested">
  861. <input class="md-nav__toggle md-toggle md-toggle--indeterminate" type="checkbox" id="__nav_6_2" >
  862. <label class="md-nav__link" for="__nav_6_2" id="__nav_6_2_label" tabindex="0">
  863. External Resources
  864. <span class="md-nav__icon md-icon"></span>
  865. </label>
  866. <nav class="md-nav" data-md-level="2" aria-labelledby="__nav_6_2_label" aria-expanded="false">
  867. <label class="md-nav__title" for="__nav_6_2">
  868. <span class="md-nav__icon md-icon"></span>
  869. External Resources
  870. </label>
  871. <ul class="md-nav__list" data-md-scrollfix>
  872. <li class="md-nav__item">
  873. <a href="../../eso-talks/" class="md-nav__link">
  874. Talks
  875. </a>
  876. </li>
  877. <li class="md-nav__item">
  878. <a href="../../eso-demos/" class="md-nav__link">
  879. Demos
  880. </a>
  881. </li>
  882. <li class="md-nav__item">
  883. <a href="../../eso-blogs/" class="md-nav__link">
  884. Blogs
  885. </a>
  886. </li>
  887. </ul>
  888. </nav>
  889. </li>
  890. </ul>
  891. </nav>
  892. </li>
  893. </ul>
  894. </nav>
  895. </div>
  896. </div>
  897. </div>
  898. <div class="md-sidebar md-sidebar--secondary" data-md-component="sidebar" data-md-type="toc" hidden>
  899. <div class="md-sidebar__scrollwrap">
  900. <div class="md-sidebar__inner">
  901. <nav class="md-nav md-nav--secondary" aria-label="Table of contents">
  902. <label class="md-nav__title" for="__toc">
  903. <span class="md-nav__icon md-icon"></span>
  904. Table of contents
  905. </label>
  906. <ul class="md-nav__list" data-md-component="toc" data-md-scrollfix>
  907. <li class="md-nav__item">
  908. <a href="#background" class="md-nav__link">
  909. Background
  910. </a>
  911. <nav class="md-nav" aria-label="Background">
  912. <ul class="md-nav__list">
  913. <li class="md-nav__item">
  914. <a href="#summary" class="md-nav__link">
  915. Summary
  916. </a>
  917. </li>
  918. <li class="md-nav__item">
  919. <a href="#components" class="md-nav__link">
  920. Components
  921. </a>
  922. </li>
  923. </ul>
  924. </nav>
  925. </li>
  926. <li class="md-nav__item">
  927. <a href="#overview" class="md-nav__link">
  928. Overview
  929. </a>
  930. <nav class="md-nav" aria-label="Overview">
  931. <ul class="md-nav__list">
  932. <li class="md-nav__item">
  933. <a href="#scope" class="md-nav__link">
  934. Scope
  935. </a>
  936. </li>
  937. <li class="md-nav__item">
  938. <a href="#assets" class="md-nav__link">
  939. Assets
  940. </a>
  941. <nav class="md-nav" aria-label="Assets">
  942. <ul class="md-nav__list">
  943. <li class="md-nav__item">
  944. <a href="#a01-cluster-level-access-to-secrets" class="md-nav__link">
  945. A01: Cluster-Level access to secrets
  946. </a>
  947. </li>
  948. <li class="md-nav__item">
  949. <a href="#a02-crd-and-webhook-write-access" class="md-nav__link">
  950. A02: CRD and Webhook Write access
  951. </a>
  952. </li>
  953. <li class="md-nav__item">
  954. <a href="#a03-secret-provider-access" class="md-nav__link">
  955. A03: secret provider access
  956. </a>
  957. </li>
  958. <li class="md-nav__item">
  959. <a href="#a04-capability-to-modify-resources" class="md-nav__link">
  960. A04: capability to modify resources
  961. </a>
  962. </li>
  963. </ul>
  964. </nav>
  965. </li>
  966. <li class="md-nav__item">
  967. <a href="#threats" class="md-nav__link">
  968. Threats
  969. </a>
  970. <nav class="md-nav" aria-label="Threats">
  971. <ul class="md-nav__list">
  972. <li class="md-nav__item">
  973. <a href="#t01-tampering-with-resources-through-mitm" class="md-nav__link">
  974. T01: Tampering with resources through MITM
  975. </a>
  976. </li>
  977. <li class="md-nav__item">
  978. <a href="#t02-webhook-dos" class="md-nav__link">
  979. T02: Webhook DOS
  980. </a>
  981. </li>
  982. <li class="md-nav__item">
  983. <a href="#t03-unauthorized-access-to-cluster-secrets" class="md-nav__link">
  984. T03: Unauthorized access to cluster secrets
  985. </a>
  986. </li>
  987. <li class="md-nav__item">
  988. <a href="#t04-unauthorized-access-to-secret-provider-credentials" class="md-nav__link">
  989. T04: unauthorized access to secret provider credentials
  990. </a>
  991. </li>
  992. <li class="md-nav__item">
  993. <a href="#t05-data-exfiltration-through-malicious-resources" class="md-nav__link">
  994. T05: data exfiltration through malicious resources
  995. </a>
  996. </li>
  997. <li class="md-nav__item">
  998. <a href="#t06-supply-chain-attacks" class="md-nav__link">
  999. T06: supply chain attacks
  1000. </a>
  1001. </li>
  1002. <li class="md-nav__item">
  1003. <a href="#t07-malicious-workloads-in-eso-namespace" class="md-nav__link">
  1004. T07: malicious workloads in eso namespace
  1005. </a>
  1006. </li>
  1007. </ul>
  1008. </nav>
  1009. </li>
  1010. <li class="md-nav__item">
  1011. <a href="#controls" class="md-nav__link">
  1012. Controls
  1013. </a>
  1014. <nav class="md-nav" aria-label="Controls">
  1015. <ul class="md-nav__list">
  1016. <li class="md-nav__item">
  1017. <a href="#c01-network-security-policy" class="md-nav__link">
  1018. C01: Network Security Policy
  1019. </a>
  1020. </li>
  1021. <li class="md-nav__item">
  1022. <a href="#c02-least-privilege-rbac" class="md-nav__link">
  1023. C02: Least Privilege RBAC
  1024. </a>
  1025. </li>
  1026. <li class="md-nav__item">
  1027. <a href="#c03-policy-enforcement" class="md-nav__link">
  1028. C03: Policy Enforcement
  1029. </a>
  1030. </li>
  1031. <li class="md-nav__item">
  1032. <a href="#c04-provider-access-policy" class="md-nav__link">
  1033. C04: Provider Access Policy
  1034. </a>
  1035. </li>
  1036. <li class="md-nav__item">
  1037. <a href="#c05-entirely-disable-crds" class="md-nav__link">
  1038. C05: Entirely disable CRDs
  1039. </a>
  1040. </li>
  1041. </ul>
  1042. </nav>
  1043. </li>
  1044. </ul>
  1045. </nav>
  1046. </li>
  1047. </ul>
  1048. </nav>
  1049. </div>
  1050. </div>
  1051. </div>
  1052. <div class="md-content" data-md-component="content">
  1053. <article class="md-content__inner md-typeset">
  1054. <h1>Threat Model</h1>
  1055. <h2 id="background">Background</h2>
  1056. <p>The External Secrets Operator is a Kubernetes Operator that seamlessly incorporates external secret management systems into Kubernetes. This Operator retrieves data from the external API and generates Kubernetes Secret resources using the corresponding secret values. This process occurs continuously in the background through regular polling of the external API. Consequently, whenever a secret undergoes changes in the external API, the corresponding Kubernetes Secret will also be updated accordingly.</p>
  1057. <h3 id="summary">Summary</h3>
  1058. <table>
  1059. <thead>
  1060. <tr>
  1061. <th>Purpose</th>
  1062. <th>Description</th>
  1063. </tr>
  1064. </thead>
  1065. <tbody>
  1066. <tr>
  1067. <td>Intended Usage</td>
  1068. <td>Sync Secrets into Kubernetes</td>
  1069. </tr>
  1070. <tr>
  1071. <td>Data Classifiation</td>
  1072. <td>Critical</td>
  1073. </tr>
  1074. <tr>
  1075. <td>Highest Risk Impact</td>
  1076. <td>Organisation takeover</td>
  1077. </tr>
  1078. </tbody>
  1079. </table>
  1080. <h3 id="components">Components</h3>
  1081. <p>ESO comprises three main components: <code>webhook</code>, <code>cert controller</code> and a <code>core controller</code>. For more detailed information, please refer to the documentation on <a href="../../api/components/">components</a>.</p>
  1082. <h2 id="overview">Overview</h2>
  1083. <p>This section provides an overview of the security aspects of the External Secrets Operator (ESO) and includes information on assets, threats, and controls involved in its operation.</p>
  1084. <p>The following diagram illustrates the security perspective of how ESO functions, highlighting the assets (items to protect), threats (potential risks), and controls (measures to mitigate threats).</p>
  1085. <p><img alt="Overview" src="../../pictures/eso-threat-model-overview.drawio.png" /></p>
  1086. <h3 id="scope">Scope</h3>
  1087. <p>For the purpose of this threat model, we assume an ESO installation using helm and default settings on a public cloud provider. It is important to note that the <a href="https://github.com/kubernetes/community/tree/master/sig-security">Kubernetes SIG Security</a> team has defined an <a href="https://github.com/kubernetes/sig-security/blob/main/sig-security-docs/papers/admission-control/kubernetes-admission-control-threat-model.md">Admission Control Threat Model</a>, which is recommended reading for a better understanding of the security aspects that partially apply to External Secrets Operator.</p>
  1088. <p>ESO utilizes the <code>ValidatingWebhookConfiguration</code> mechanism to validate <code>(Cluster)SecretStore</code> and <code>(Cluster)ExternalSecret</code> resources. However, it is essential to understand that this validation process does not serve as a security control mechanism. Instead, ESO performs validation by enforcing additional rules that go beyond the <a href="https://kubernetes.io/docs/tasks/extend-kubernetes/custom-resources/custom-resource-definitions/#validation">CustomResourceDefinition OpenAPI v3 Validation schema</a>.</p>
  1089. <h3 id="assets">Assets</h3>
  1090. <h4 id="a01-cluster-level-access-to-secrets">A01: Cluster-Level access to secrets</h4>
  1091. <p>The controller possesses privileged access to the <code>kube-apiserver</code> and is authorized to read and write secret resources across all namespaces within a cluster.</p>
  1092. <h4 id="a02-crd-and-webhook-write-access">A02: CRD and Webhook Write access</h4>
  1093. <p>The cert-controller component has read/write access to <code>ValidatingWebhookConfigurations</code> and <code>CustomResourceDefinitions</code> resources. This access is necessary to inject/modify the caBundle property.</p>
  1094. <h4 id="a03-secret-provider-access">A03: secret provider access</h4>
  1095. <p>The <code>core-controller</code> component accesses a secret provider using user-supplied credentials. These credentials can be derived from environment variables, mounted service account tokens, files within the controller container, or fetched from the Kubernetes API (e.g., <code>Kind=Secret</code>). The scope of these credentials may vary, potentially providing full access to a cloud provider.</p>
  1096. <h4 id="a04-capability-to-modify-resources">A04: capability to modify resources</h4>
  1097. <p>The webhook component validates and converts ExternalSecret and SecretStore resources. The conversion webhook is essential for migrating resources from the old version <code>v1alpha1</code> to the new version <code>v1beta1</code>. The webhook component possesses the ability to modify resources during runtime.</p>
  1098. <h3 id="threats">Threats</h3>
  1099. <h4 id="t01-tampering-with-resources-through-mitm">T01: Tampering with resources through MITM</h4>
  1100. <p>An adversary could launch a Man-in-the-Middle (MITM) attack to hijack the webhook pod, enabling them to manipulate the data of the conversion webhook. This could involve injecting malicious resources or causing a Denial-of-Service (DoS) attack. To mitigate this threat, a mutual authentication mechanism should be enforced for the connection between the Kubernetes API server and the webhook service to ensure that only authenticated endpoints can communicate.</p>
  1101. <h4 id="t02-webhook-dos">T02: Webhook DOS</h4>
  1102. <p>Currently, ESO generates an X.509 certificate for webhook registration without authenticating the kube-apiserver. Consequently, if an attacker gains network access to the webhook Pod, they can overload the webhook server and initiate a DoS attack. As a result, modifications to ESO resources may fail, and the ESO core controller may be impacted due to the unavailability of the conversion webhook.</p>
  1103. <h4 id="t03-unauthorized-access-to-cluster-secrets">T03: Unauthorized access to cluster secrets</h4>
  1104. <p>An attacker can gain unauthorized access to secrets by utilizing the service account token of the ESO core controller Pod or exploiting software vulnerabilities. This unauthorized access allows the attacker to read secrets within the cluster, potentially leading to a cluster takeover.</p>
  1105. <h4 id="t04-unauthorized-access-to-secret-provider-credentials">T04: unauthorized access to secret provider credentials</h4>
  1106. <p>An attacker can gain unauthorized access to credentials that provide access to external APIs storing secrets. If the credentials have overly broad permissions, this could result in an organization takeover.</p>
  1107. <h4 id="t05-data-exfiltration-through-malicious-resources">T05: data exfiltration through malicious resources</h4>
  1108. <p>An attacker can exfiltrate data from the cluster by utilizing maliciously crafted resources. Multiple attack vectors can be employed, e.g.:</p>
  1109. <ol>
  1110. <li>copying data from a namespace to an unauthorized namespace</li>
  1111. <li>exfiltrating data to an unauthorized secret provider</li>
  1112. <li>exfiltrating data through an authorized secret provider to a malicious provider account</li>
  1113. </ol>
  1114. <p>Successful data exfiltration can lead to intellectual property loss, information misuse, loss of customer trust, and damage to the brand or reputation.</p>
  1115. <h4 id="t06-supply-chain-attacks">T06: supply chain attacks</h4>
  1116. <p>An attack can infiltrate the ESO container through various attack vectors. The following are some potential entry points, although this is not an exhaustive list. For a comprehensive analysis, refer to <a href="https://slsa.dev/spec/v0.1/threats">SLSA Threats and mitigations</a> or <a href="https://cloud.google.com/software-supply-chain-security/docs/attack-vectors">GCP software supply chain threats</a>.</p>
  1117. <ol>
  1118. <li>Source Threats: Unauthorized changes or inclusion of vulnerable code in ESO through code submissions.</li>
  1119. <li>Build Threats: Creation and distribution of malicious builds of ESO, such as in container registries, Artifact Hub, or Operator Hub.</li>
  1120. <li>Dependency Threats: Introduction of vulnerable code into ESO dependencies.</li>
  1121. <li>Deployment and Runtime Threats: Injection of malicious code through compromised deployment processes.</li>
  1122. </ol>
  1123. <h4 id="t07-malicious-workloads-in-eso-namespace">T07: malicious workloads in eso namespace</h4>
  1124. <p>An attacker can deploy malicious workloads within the external-secrets namespace, taking advantage of the ESO service account with potentially cluster-wide privileges.</p>
  1125. <h3 id="controls">Controls</h3>
  1126. <h4 id="c01-network-security-policy">C01: Network Security Policy</h4>
  1127. <p>Implement a NetworkPolicy to restrict traffic in both inbound and outbound directions on all networks. Employ a "deny all" / "permit by exception" approach for inbound and outbound network traffic. The specific network policies for the core-controller depend on the chosen provider. The webhook and cert-controller have well-defined sets of endpoints they communicate with. Refer to the <a href="../security-best-practices/">Security Best Practices</a> documentation for inbound and outbound network requirements.</p>
  1128. <p>Please note that ESO does not provide pre-packaged network policies, and it is the user's responsibility to implement the necessary security controls.</p>
  1129. <h4 id="c02-least-privilege-rbac">C02: Least Privilege RBAC</h4>
  1130. <p>Adhere to the principle of least privilege by configuring Role-Based Access Control (RBAC) permissions not only for the ESO workload but also for all users interacting with it. Ensure that RBAC permissions on provider side are appropriate according to your setup, by for example limiting which sensitive information a given credential can have access to. Ensure that kubernetes RBAC are set up to grant access to ESO resources only where necessary. For example, allowing write access to <code>ClusterSecretStore</code>/<code>ExternalSecret</code> may be sufficient for a threat to become a reality.</p>
  1131. <h4 id="c03-policy-enforcement">C03: Policy Enforcement</h4>
  1132. <p>Implement a Policy Engine such as Kyverno or OPA to enforce restrictions on changes to ESO resources. The specific policies to be enforced depend on the environment. Here are a few suggestions:</p>
  1133. <ol>
  1134. <li>(Cluster)SecretStore: Restrict the allowed secret providers, disallowing unused or undesired providers (e.g. Webhook).</li>
  1135. <li>(Cluster)SecretStore: Restrict the permitted authentication mechanisms (e.g. prevent usage of <code>secretRef</code>).</li>
  1136. <li>(Cluster)SecretStore: Enforce limitations on modifications to provider-specific fields relevant for security, such as <code>caBundle</code>, <code>caProvider</code>, <code>region</code>, <code>role</code>, <code>url</code>, <code>environmentType</code>, <code>identityId</code>, and <code>others</code>.</li>
  1137. <li>ClusterSecretStore: Control the usage of <code>namespaceSelector</code>, such as forbidding or mandating the usage of the <code>kube-system</code> namespace.</li>
  1138. <li>ClusterExternalSecret: Restrict the usage of <code>namespaceSelector</code>.</li>
  1139. </ol>
  1140. <p>Please note that ESO does not provide pre-packaged policies, and it is the user's responsibility to implement the necessary security controls.</p>
  1141. <h4 id="c04-provider-access-policy">C04: Provider Access Policy</h4>
  1142. <p>Configure fine-grained access control on the HTTP endpoint of the secret provider to prevent data exfiltration across accounts or organizations. Consult the documentation of your specific provider (e.g.: <a href="https://docs.aws.amazon.com/secretsmanager/latest/userguide/vpc-endpoint-overview.html">AWS Secrets Manager VPC Endpoint Policies</a>, <a href="https://cloud.google.com/vpc/docs/private-service-connect">GCP Private Service Connect</a>, or <a href="https://learn.microsoft.com/en-us/azure/key-vault/general/private-link-service">Azure Private Link</a>) for guidance on setting up access policies.</p>
  1143. <h4 id="c05-entirely-disable-crds">C05: Entirely disable CRDs</h4>
  1144. <p>You should disable unused CRDs to narrow down your attack surface. Not all users require the use of <code>PushSecret</code>, <code>ClusterSecretStore</code> or <code>ClusterExternalSecret</code> resources.</p>
  1145. </article>
  1146. </div>
  1147. </div>
  1148. </main>
  1149. <footer class="md-footer">
  1150. <div class="md-footer-meta md-typeset">
  1151. <div class="md-footer-meta__inner md-grid">
  1152. <div class="md-copyright">
  1153. <div class="md-copyright__highlight">
  1154. &copy; 2023 The external-secrets Authors.<br/>
  1155. &copy; 2023 The Linux Foundation. All rights reserved.<br/><br/>
  1156. The Linux Foundation has registered trademarks and uses trademarks.<br/>
  1157. For a list of trademarks of The Linux Foundation, please see our <a href="https://www.linuxfoundation.org/trademark-usage/">Trademark Usage page</a>.
  1158. </div>
  1159. Made with
  1160. <a href="https://squidfunk.github.io/mkdocs-material/" target="_blank" rel="noopener">
  1161. Material for MkDocs
  1162. </a>
  1163. </div>
  1164. </div>
  1165. </div>
  1166. </footer>
  1167. </div>
  1168. <div class="md-dialog" data-md-component="dialog">
  1169. <div class="md-dialog__inner md-typeset"></div>
  1170. </div>
  1171. <script id="__config" type="application/json">{"base": "../..", "features": ["navigation.tabs", "navigation.indexes", "navigation.expand"], "search": "../../assets/javascripts/workers/search.208ed371.min.js", "translations": {"clipboard.copied": "Copied to clipboard", "clipboard.copy": "Copy to clipboard", "search.result.more.one": "1 more on this page", "search.result.more.other": "# more on this page", "search.result.none": "No matching documents", "search.result.one": "1 matching document", "search.result.other": "# matching documents", "search.result.placeholder": "Type to start searching", "search.result.term.missing": "Missing", "select.version": "Select version"}, "version": {"provider": "mike"}}</script>
  1172. <script src="../../assets/javascripts/bundle.fac441b0.min.js"></script>
  1173. </body>
  1174. </html>