{
  "schemaVersion": "catalog-shared-check-receipt-v1",
  "subject": {
    "id": "istio-istiod-1-30-0-default",
    "chart": "istio/istiod",
    "version": "1.30.0",
    "base": "default",
    "renderPath": "recipes/istio/istiod/1.30.0/revisions/default/r001/rendered/release-objects.yaml",
    "renderFileSHA256": "sha256:53385181293dd9a8228f37a370148dde3cc77acecf5a3a8539fa1b8eb0f9afdf"
  },
  "catalogReview": {
    "path": "recipes/istio/istiod/1.30.0/revisions/default/r001/receipts/scan-receipt.yaml",
    "note": "Separate chart-specific Catalog review; not a cub check result."
  },
  "scannerResult": {
    "schema_version": "risk-scan-findings-v1",
    "surface": "cub-scan",
    "finding_count": 14,
    "findings": [
      {
        "id": "CCVE-2025-3725",
        "name": "Deployment omits spec.replicas and relies on implicit single replica",
        "category": "CONFIG",
        "track": "misconfiguration",
        "detection_method": "native_rule",
        "severity": "warning",
        "confidence": "high",
        "tool": "kubernetes",
        "resource": {
          "kind": "Deployment",
          "name": "istiod",
          "namespace": "default"
        },
        "message": "Deployment omits spec.replicas; Kubernetes defaults to a single replica",
        "remedy_type": "config_fix",
        "remedy_safety": "safe_auto",
        "remediation": {
          "steps": [
            "Set spec.replicas explicitly in the workload manifest",
            "Use at least two replicas for workloads requiring basic availability",
            "If HPA manages scale, document that intent and set safe minReplicas"
          ],
          "commands": [
            "kubectl get deployment <name> -n <namespace> -o jsonpath='{.spec.replicas}'",
            "kubectl patch deployment <name> -n <namespace> --type=merge -p '{\"spec\":{\"replicas\":2}}'"
          ]
        },
        "evidence_source": "native",
        "action_type": "mutating",
        "next_step": {
          "action": "apply_fix",
          "description": "Set spec.replicas explicitly in the workload manifest",
          "command": "kubectl get deployment <name> -n <namespace> -o jsonpath='{.spec.replicas}'",
          "doc_ref": "cub-scan --explain CCVE-2025-3725"
        }
      },
      {
        "id": "CCVE-2025-3728",
        "name": "Deployment containers omit resource limits",
        "category": "CONFIG",
        "track": "misconfiguration",
        "detection_method": "native_rule",
        "severity": "warning",
        "confidence": "high",
        "tool": "kubernetes",
        "resource": {
          "kind": "Deployment",
          "name": "istiod",
          "namespace": "default"
        },
        "message": "Deployment containers omit resource limits",
        "remedy_type": "config_fix",
        "remedy_safety": "safe_auto",
        "remediation": {
          "steps": [
            "Add resources.limits for memory and CPU to each container",
            "Add resources.requests to enable proper scheduling",
            "Consider LimitRange defaults at the namespace level"
          ],
          "commands": [
            "kubectl get deployment <name> -n <namespace> -o yaml | grep -A10 resources",
            "kubectl set resources deployment <name> -n <namespace> --limits=cpu=500m,memory=256Mi --requests=cpu=100m,memory=128Mi"
          ]
        },
        "evidence_source": "native",
        "control_ids": [
          "CTRL-WORKLOAD-0002"
        ],
        "action_type": "mutating",
        "next_step": {
          "action": "apply_fix",
          "description": "Add resources.limits for memory and CPU to each container",
          "command": "kubectl get deployment <name> -n <namespace> -o yaml | grep -A10 resources",
          "doc_ref": "cub-scan --explain CCVE-2025-3728"
        }
      },
      {
        "id": "CCVE-2025-3745",
        "name": "emptyDir volume has no sizeLimit",
        "category": "CONFIG",
        "track": "misconfiguration",
        "detection_method": "native_rule",
        "severity": "info",
        "confidence": "high",
        "tool": "kubernetes",
        "resource": {
          "kind": "Deployment",
          "name": "istiod",
          "namespace": "default"
        },
        "message": "Volume local-certs uses emptyDir without sizeLimit; may exhaust node disk",
        "remedy_type": "config_fix",
        "remedy_safety": "safe_auto",
        "remediation": {
          "steps": [
            "Set sizeLimit on all emptyDir volumes",
            "Size the limit based on expected usage with headroom",
            "{'Consider using memory-backed emptyDir (medium': 'Memory) for small caches'}"
          ],
          "commands": [
            "kubectl get deployment <name> -n <namespace> -o jsonpath='{.spec.template.spec.volumes}'"
          ]
        },
        "evidence_source": "native",
        "action_type": "mutating",
        "next_step": {
          "action": "apply_fix",
          "description": "Set sizeLimit on all emptyDir volumes",
          "command": "kubectl get deployment <name> -n <namespace> -o jsonpath='{.spec.template.spec.volumes}'",
          "doc_ref": "cub-scan --explain CCVE-2025-3745"
        }
      },
      {
        "id": "CCVE-2025-3746",
        "name": "Deployment does not disable automountServiceAccountToken",
        "category": "SECURITY",
        "track": "misconfiguration",
        "detection_method": "native_rule",
        "severity": "warning",
        "confidence": "high",
        "tool": "kubernetes",
        "resource": {
          "kind": "Deployment",
          "name": "istiod",
          "namespace": "default"
        },
        "message": "Deployment does not set automountServiceAccountToken: false; pods get unnecessary API credentials",
        "remedy_type": "config_fix",
        "remedy_safety": "safe_auto",
        "remediation": {
          "steps": [
            "Set automountServiceAccountToken to false in the pod spec",
            "Only enable it for pods that genuinely need Kubernetes API access",
            "Use dedicated service accounts with minimal RBAC for pods that need API access"
          ],
          "commands": [
            "kubectl get deployment <name> -n <namespace> -o jsonpath='{.spec.template.spec.automountServiceAccountToken}'"
          ]
        },
        "evidence_source": "native",
        "control_ids": [
          "CTRL-RBAC-0002"
        ],
        "action_type": "mutating",
        "next_step": {
          "action": "apply_fix",
          "description": "Set automountServiceAccountToken to false in the pod spec",
          "command": "kubectl get deployment <name> -n <namespace> -o jsonpath='{.spec.template.spec.automountServiceAccountToken}'",
          "doc_ref": "cub-scan --explain CCVE-2025-3746"
        }
      },
      {
        "id": "CCVE-2025-4005",
        "name": "CCVE-2025-4005",
        "category": "CONFIGURATION",
        "track": "misconfiguration",
        "detection_method": "native_rule",
        "severity": "warning",
        "confidence": "unknown",
        "tool": "kubernetes",
        "resource": {
          "kind": "ClusterRoleBinding",
          "name": "istio-reader-clusterrole-default",
          "namespace": "default"
        },
        "message": "ClusterRoleBinding subject ServiceAccount istio-system/istio-reader-service-account is not present in scanned documents",
        "remedy_type": "manual_only",
        "remedy_safety": "manual_only",
        "remediation": {
          "steps": [
            "Verify the ConfigMap or Secret name in the volume reference matches an existing resource",
            "Create the missing ConfigMap/Secret or correct the volume reference"
          ],
          "commands": [
            "kubectl get configmap -n <namespace>",
            "kubectl get secret -n <namespace>"
          ]
        },
        "evidence_source": "native",
        "action_type": "human-decision",
        "next_step": {
          "action": "update_config",
          "description": "Verify the ConfigMap or Secret name in the volume reference matches an existing resource",
          "command": "kubectl get configmap -n <namespace>",
          "doc_ref": "cub-scan --explain CCVE-2025-4005"
        }
      },
      {
        "id": "CCVE-2025-4005",
        "name": "CCVE-2025-4005",
        "category": "CONFIGURATION",
        "track": "misconfiguration",
        "detection_method": "native_rule",
        "severity": "warning",
        "confidence": "unknown",
        "tool": "kubernetes",
        "resource": {
          "kind": "Deployment",
          "name": "istiod",
          "namespace": "default"
        },
        "message": "Volume cacerts references Secret default/cacerts which is not present in scanned documents",
        "remedy_type": "manual_only",
        "remedy_safety": "manual_only",
        "remediation": {
          "steps": [
            "Verify the ConfigMap or Secret name in the volume reference matches an existing resource",
            "Create the missing ConfigMap/Secret or correct the volume reference"
          ],
          "commands": [
            "kubectl get configmap -n <namespace>",
            "kubectl get secret -n <namespace>"
          ]
        },
        "evidence_source": "native",
        "action_type": "human-decision",
        "next_step": {
          "action": "update_config",
          "description": "Verify the ConfigMap or Secret name in the volume reference matches an existing resource",
          "command": "kubectl get configmap -n <namespace>",
          "doc_ref": "cub-scan --explain CCVE-2025-4005"
        }
      },
      {
        "id": "CCVE-2025-4075",
        "name": "ClusterRole grants nodes/proxy enabling Kubelet API RCE",
        "category": "SECURITY",
        "track": "misconfiguration",
        "detection_method": "native_rule",
        "severity": "critical",
        "confidence": "high",
        "tool": "kubernetes",
        "resource": {
          "kind": "ClusterRole",
          "name": "istio-reader-clusterrole-default",
          "namespace": "default"
        },
        "message": "ClusterRole grants nodes/proxy access, enabling full Kubelet API (exec/run/attach) on all nodes",
        "remedy_type": "config_fix",
        "remedy_safety": "safe_auto",
        "remediation": {
          "steps": [
            "Audit all ClusterRoles for nodes/proxy permissions",
            "Remove nodes/proxy from ClusterRole rules unless strictly required",
            "Implement network policies restricting pod access to port 10250",
            "Deploy node-level runtime detection (Falco, Tetragon) for Kubelet connections",
            "Consider deploying Kyverno policy restrict-clusterrole-nodesproxy as admission guard",
            "Kyverno equivalents: KPOL-0279 and KPOL-0367",
            "Monitor KEP-2862 progress for fine-grained Kubelet authorization (K8s 1.36+)"
          ],
          "commands": [
            "kubectl get clusterroles -o json | jq '.items[] | select(.rules[]?.resources[]? == \"nodes/proxy\") | .metadata.name'",
            "kubectl get clusterrolebindings -o json | jq '.items[] | select(.roleRef.name == \"<ROLE_NAME>\") | {name: .metadata.name, subjects: .subjects}'"
          ]
        },
        "evidence_source": "native",
        "control_ids": [
          "CTRL-RBAC-0001"
        ],
        "action_type": "mutating",
        "next_step": {
          "action": "apply_fix",
          "description": "Audit all ClusterRoles for nodes/proxy permissions",
          "command": "kubectl get clusterroles -o json | jq '.items[] | select(.rules[]?.resources[]? == \"nodes/proxy\") | .metadata.name'",
          "doc_ref": "cub-scan --explain CCVE-2025-4075"
        }
      },
      {
        "id": "CCVE-2025-4075",
        "name": "ClusterRole grants nodes/proxy enabling Kubelet API RCE",
        "category": "SECURITY",
        "track": "misconfiguration",
        "detection_method": "native_rule",
        "severity": "critical",
        "confidence": "high",
        "tool": "kubernetes",
        "resource": {
          "kind": "ClusterRole",
          "name": "istiod-clusterrole-default",
          "namespace": "default"
        },
        "message": "ClusterRole grants nodes/proxy access, enabling full Kubelet API (exec/run/attach) on all nodes",
        "remedy_type": "config_fix",
        "remedy_safety": "safe_auto",
        "remediation": {
          "steps": [
            "Audit all ClusterRoles for nodes/proxy permissions",
            "Remove nodes/proxy from ClusterRole rules unless strictly required",
            "Implement network policies restricting pod access to port 10250",
            "Deploy node-level runtime detection (Falco, Tetragon) for Kubelet connections",
            "Consider deploying Kyverno policy restrict-clusterrole-nodesproxy as admission guard",
            "Kyverno equivalents: KPOL-0279 and KPOL-0367",
            "Monitor KEP-2862 progress for fine-grained Kubelet authorization (K8s 1.36+)"
          ],
          "commands": [
            "kubectl get clusterroles -o json | jq '.items[] | select(.rules[]?.resources[]? == \"nodes/proxy\") | .metadata.name'",
            "kubectl get clusterrolebindings -o json | jq '.items[] | select(.roleRef.name == \"<ROLE_NAME>\") | {name: .metadata.name, subjects: .subjects}'"
          ]
        },
        "evidence_source": "native",
        "control_ids": [
          "CTRL-RBAC-0001"
        ],
        "action_type": "mutating",
        "next_step": {
          "action": "apply_fix",
          "description": "Audit all ClusterRoles for nodes/proxy permissions",
          "command": "kubectl get clusterroles -o json | jq '.items[] | select(.rules[]?.resources[]? == \"nodes/proxy\") | .metadata.name'",
          "doc_ref": "cub-scan --explain CCVE-2025-4075"
        }
      },
      {
        "id": "CCVE-2025-4076",
        "name": "ClusterRoleBinding binds nodes/proxy ClusterRole to subjects",
        "category": "SECURITY",
        "track": "misconfiguration",
        "detection_method": "native_rule",
        "severity": "critical",
        "confidence": "high",
        "tool": "kubernetes",
        "resource": {
          "kind": "ClusterRoleBinding",
          "name": "istio-reader-clusterrole-default",
          "namespace": "default"
        },
        "message": "ClusterRoleBinding grants nodes/proxy via ClusterRole \"istio-reader-clusterrole-default\" to ServiceAccount istio-system/istio-reader-service-account",
        "remedy_type": "config_fix",
        "remedy_safety": "safe_auto",
        "remediation": {
          "steps": [
            "Identify which subjects are bound to the nodes/proxy ClusterRole",
            "Remove unnecessary bindings or switch to more restrictive ClusterRoles",
            "Audit ServiceAccount usage to verify necessity",
            "Restrict binding scope where possible",
            "Related policy controls: KPOL-0279 and KPOL-0367"
          ],
          "commands": [
            "kubectl get clusterrolebindings -o json | jq '.items[] | select(.roleRef.name == \"<ROLE_NAME>\") | {name: .metadata.name, subjects: .subjects}'"
          ]
        },
        "evidence_source": "native",
        "control_ids": [
          "CTRL-RBAC-0001"
        ],
        "action_type": "mutating",
        "next_step": {
          "action": "apply_fix",
          "description": "Identify which subjects are bound to the nodes/proxy ClusterRole",
          "command": "kubectl get clusterrolebindings -o json | jq '.items[] | select(.roleRef.name == \"<ROLE_NAME>\") | {name: .metadata.name, subjects: .subjects}'",
          "doc_ref": "cub-scan --explain CCVE-2025-4076"
        }
      },
      {
        "id": "CCVE-2025-4076",
        "name": "ClusterRoleBinding binds nodes/proxy ClusterRole to subjects",
        "category": "SECURITY",
        "track": "misconfiguration",
        "detection_method": "native_rule",
        "severity": "critical",
        "confidence": "high",
        "tool": "kubernetes",
        "resource": {
          "kind": "ClusterRoleBinding",
          "name": "istiod-clusterrole-default",
          "namespace": "default"
        },
        "message": "ClusterRoleBinding grants nodes/proxy via ClusterRole \"istiod-clusterrole-default\" to ServiceAccount istio-system/istiod",
        "remedy_type": "config_fix",
        "remedy_safety": "safe_auto",
        "remediation": {
          "steps": [
            "Identify which subjects are bound to the nodes/proxy ClusterRole",
            "Remove unnecessary bindings or switch to more restrictive ClusterRoles",
            "Audit ServiceAccount usage to verify necessity",
            "Restrict binding scope where possible",
            "Related policy controls: KPOL-0279 and KPOL-0367"
          ],
          "commands": [
            "kubectl get clusterrolebindings -o json | jq '.items[] | select(.roleRef.name == \"<ROLE_NAME>\") | {name: .metadata.name, subjects: .subjects}'"
          ]
        },
        "evidence_source": "native",
        "control_ids": [
          "CTRL-RBAC-0001"
        ],
        "action_type": "mutating",
        "next_step": {
          "action": "apply_fix",
          "description": "Identify which subjects are bound to the nodes/proxy ClusterRole",
          "command": "kubectl get clusterrolebindings -o json | jq '.items[] | select(.roleRef.name == \"<ROLE_NAME>\") | {name: .metadata.name, subjects: .subjects}'",
          "doc_ref": "cub-scan --explain CCVE-2025-4076"
        }
      },
      {
        "id": "CCVE-2025-4078",
        "name": "ClusterRole grants secrets read permissions",
        "category": "SECURITY",
        "track": "misconfiguration",
        "detection_method": "native_rule",
        "severity": "critical",
        "confidence": "high",
        "tool": "kubernetes",
        "resource": {
          "kind": "ClusterRole",
          "name": "istio-reader-clusterrole-default",
          "namespace": "default"
        },
        "message": "ClusterRole grants secrets get/list, enabling credential exfiltration across namespaces",
        "remedy_type": "config_fix",
        "remedy_safety": "safe_auto",
        "remediation": {
          "steps": [
            "Remove secrets get/list permissions from ClusterRoles that do not require credential access",
            "Scope secret access to namespaced Role bindings where possible"
          ],
          "commands": [
            "kubectl get clusterroles -o json | jq '.items[] | select(any(.rules[]?; any(.resources[]?; .==\"secrets\"))) | .metadata.name'"
          ]
        },
        "evidence_source": "native",
        "control_ids": [
          "CTRL-RBAC-0001"
        ],
        "action_type": "mutating",
        "next_step": {
          "action": "apply_fix",
          "description": "Remove secrets get/list permissions from ClusterRoles that do not require credential access",
          "command": "kubectl get clusterroles -o json | jq '.items[] | select(any(.rules[]?; any(.resources[]?; .==\"secrets\"))) | .metadata.name'",
          "doc_ref": "cub-scan --explain CCVE-2025-4078"
        }
      },
      {
        "id": "CCVE-2025-4078",
        "name": "ClusterRole grants secrets read permissions",
        "category": "SECURITY",
        "track": "misconfiguration",
        "detection_method": "native_rule",
        "severity": "critical",
        "confidence": "high",
        "tool": "kubernetes",
        "resource": {
          "kind": "ClusterRole",
          "name": "istiod-clusterrole-default",
          "namespace": "default"
        },
        "message": "ClusterRole grants secrets get/list, enabling credential exfiltration across namespaces",
        "remedy_type": "config_fix",
        "remedy_safety": "safe_auto",
        "remediation": {
          "steps": [
            "Remove secrets get/list permissions from ClusterRoles that do not require credential access",
            "Scope secret access to namespaced Role bindings where possible"
          ],
          "commands": [
            "kubectl get clusterroles -o json | jq '.items[] | select(any(.rules[]?; any(.resources[]?; .==\"secrets\"))) | .metadata.name'"
          ]
        },
        "evidence_source": "native",
        "control_ids": [
          "CTRL-RBAC-0001"
        ],
        "action_type": "mutating",
        "next_step": {
          "action": "apply_fix",
          "description": "Remove secrets get/list permissions from ClusterRoles that do not require credential access",
          "command": "kubectl get clusterroles -o json | jq '.items[] | select(any(.rules[]?; any(.resources[]?; .==\"secrets\"))) | .metadata.name'",
          "doc_ref": "cub-scan --explain CCVE-2025-4078"
        }
      },
      {
        "id": "CCVE-2025-4081",
        "name": "ClusterRole uses wildcard resources with broad verbs",
        "category": "SECURITY",
        "track": "misconfiguration",
        "detection_method": "native_rule",
        "severity": "critical",
        "confidence": "high",
        "tool": "kubernetes",
        "resource": {
          "kind": "ClusterRole",
          "name": "istio-reader-clusterrole-default",
          "namespace": "default"
        },
        "message": "ClusterRole uses wildcard resources with broad verbs, indicating overprivileged admin access",
        "remedy_type": "config_fix",
        "remedy_safety": "safe_auto",
        "remediation": {
          "steps": [
            "Replace wildcard resources with explicit resource lists",
            "Remove unnecessary broad verbs and keep least-privilege verbs only"
          ],
          "commands": [
            "kubectl get clusterroles -o json | jq '.items[] | select(any(.rules[]?; any(.resources[]?; .==\"*\"))) | .metadata.name'"
          ]
        },
        "evidence_source": "native",
        "control_ids": [
          "CTRL-RBAC-0001"
        ],
        "action_type": "mutating",
        "next_step": {
          "action": "apply_fix",
          "description": "Replace wildcard resources with explicit resource lists",
          "command": "kubectl get clusterroles -o json | jq '.items[] | select(any(.rules[]?; any(.resources[]?; .==\"*\"))) | .metadata.name'",
          "doc_ref": "cub-scan --explain CCVE-2025-4081"
        }
      },
      {
        "id": "CCVE-2025-4081",
        "name": "ClusterRole uses wildcard resources with broad verbs",
        "category": "SECURITY",
        "track": "misconfiguration",
        "detection_method": "native_rule",
        "severity": "critical",
        "confidence": "high",
        "tool": "kubernetes",
        "resource": {
          "kind": "ClusterRole",
          "name": "istiod-clusterrole-default",
          "namespace": "default"
        },
        "message": "ClusterRole uses wildcard resources with broad verbs, indicating overprivileged admin access",
        "remedy_type": "config_fix",
        "remedy_safety": "safe_auto",
        "remediation": {
          "steps": [
            "Replace wildcard resources with explicit resource lists",
            "Remove unnecessary broad verbs and keep least-privilege verbs only"
          ],
          "commands": [
            "kubectl get clusterroles -o json | jq '.items[] | select(any(.rules[]?; any(.resources[]?; .==\"*\"))) | .metadata.name'"
          ]
        },
        "evidence_source": "native",
        "control_ids": [
          "CTRL-RBAC-0001"
        ],
        "action_type": "mutating",
        "next_step": {
          "action": "apply_fix",
          "description": "Replace wildcard resources with explicit resource lists",
          "command": "kubectl get clusterroles -o json | jq '.items[] | select(any(.rules[]?; any(.resources[]?; .==\"*\"))) | .metadata.name'",
          "doc_ref": "cub-scan --explain CCVE-2025-4081"
        }
      }
    ],
    "provenance": {
      "source": "cub-scan",
      "source_version": "v0.7.3",
      "scan_time": "2026-08-24T16:00:36Z",
      "catalog_version": "risk-catalog-v1.json@7ff79a126ad9"
    },
    "pattern_bundle": {
      "schema_version": "bundle-manifest-v1",
      "version": "v0.7.3",
      "source_repo": "confighubai/confighub-scan",
      "manifest_sha256": "0405f6ffe21e567adf5d6a732d181c7f228194920456d046b4338baeb14de1a8",
      "catalog_sha256": "7ff79a126ad99bba2505fec8b2b7711c03f50eb362141128ec1c83e27a5036ba"
    },
    "input": {
      "object_count": 17,
      "object_set_sha256": "sha256:c62aaf0d8b5c30be5d5c8609a8d3b7b6341c9f2338dea291cde3937ef3091eaf"
    }
  }
}
