olares-chart
Warn
Audited by Socket on Sep 10, 2026
1 alert found:
SecuritySecurityreferences/olares-chart-dind.md
MEDIUMSecurityMEDIUM
references/olares-chart-dind.md
No explicit malicious payload is evident in the provided DinD template fragment. However, the design intentionally enables a privileged `dockerd` sidecar and exposes an unauthenticated plaintext Docker API on TCP 2375, backed by persistent hostPath Docker storage and shared workspace mounts. This creates a high-impact control channel: if any attacker can run code in (or otherwise reach) the pod environment, they may leverage the Docker API to create/execute containers and persist artifacts via `/var/lib/docker`. Treat this as a security-critical configuration rather than benign infrastructure.
Confidence: 70%Severity: 88%
Audit Metadata