ArgoCD: Use of Risky or Missing Cryptographic Algorithms in Redis Cache
github.com
github.com
https://github.com/argoproj/argo-helm/blob/main/charts/argo-...
If you're using a CNI that supports network policy (e.g. AWS VPC CNI on EKS, Calico, etc.), I think this should more or less cover you, but I haven't personally tested it.
I think it's also probably a better practice to install "control plane" type software like Argo on a different, dedicated cluster. Argo supports this concept (and can in fact manage deployments in multiple clusters remotely). This way your main mission workloads are completely segmented from your privileged control plane software. Just as another defense-in-depth measure
An attacker would need to be inside your cluster/virtual/private network, no? You have bigger problems after that, right? This is an internally facing, not-externally-exposed Redis instance?
You can meme it with SPIFFE/SPIRE.
> Secrets objects, which aren't really secret because there's no encryption, but that's another topic
This isn't universally true anymore, at least with AWS EKS.
The underlying etcd being encrypted at rest doesn't really change the fact that anything with access to the running etcd has full access to all secrets (okay, there are ACLs, but they're quite complex).