Description

A Helm chart for Kubernetes

Overview

IdentityNamespaceAutomountSecretsPermissionsWorkloadsRisk
(orphaned-bindings)290Critical

Numbers in the last two columns indicate how many bindings or workloads involve each ServiceAccount.


Identities

⚠️ (orphaned-bindings)

Warning: The following RBAC bindings exist but are not associated with any active service accounts in the cluster.

🔑 Permissions (29)

RoleResourceVerbsRiskTags
ClusterRole ais-operator-manager-rolecore/configmapscreate · delete · get · list · patch · update · watchCriticalConfigMapAccess DataExposure InformationDisclosure PotentialPrivilegeEscalation Tampering
ClusterRole ais-operator-manager-roleapps/deploymentscreate · delete · get · list · patch · update · watchCriticalPersistence PotentialPrivilegeEscalation PrivilegeEscalation Tampering WorkloadLifecycle
Role ais-operator-leader-election-rolecoordination.k8s.io/leasescreate · delete · get · list · patch · update · watchCriticalControlPlaneDisruption CriticalNamespace DenialOfService Tampering
ClusterRole ais-operator-manager-rolecore/podscreate · delete · get · list · update · watchCriticalLateralMovement Persistence PotentialPrivilegeEscalation PrivilegeEscalation WorkloadExecution
ClusterRole ais-operator-manager-rolecore/secretsget · list · watchCriticalClusterWideSecretAccess CredentialAccess DataExposure InformationDisclosure SecretAccess
ClusterRole ais-operator-manager-rolecore/servicescreate · delete · get · list · patch · update · watchCriticalDenialOfService NetworkManipulation ServiceExposure Tampering
ClusterRole ais-operator-manager-roleapps/statefulsetscreate · delete · get · list · patch · update · watchCriticalPersistence PotentialPrivilegeEscalation PrivilegeEscalation Tampering WorkloadLifecycle
Role ais-operator-leader-election-rolecore/configmapscreate · delete · get · list · patch · update · watchHighConfigMapAccess DataExposure InformationDisclosure PotentialPrivilegeEscalation Tampering
ClusterRole ais-operator-manager-rolecore/pods/loggetHighClusterWideLogAccess DataExposure InformationDisclosure LogAccess
ClusterRole ais-operator-manager-rolepolicy/poddisruptionbudgetscreate · delete · get · list · patch · update · watchMediumAvailabilityImpact DenialOfService Tampering
ClusterRole ais-operator-manager-rolerbac.authorization.k8s.io/rolebindingscreate · delete · get · list · update · watchMediumInformationDisclosure RBACQuery Reconnaissance
ClusterRole ais-operator-manager-rolerbac.authorization.k8s.io/rolescreate · delete · get · list · update · watchMediumInformationDisclosure RBACQuery Reconnaissance
ClusterRole ais-operator-proxy-roleauthorization.k8s.io/subjectaccessreviewscreateMediumInformationDisclosure RBACQuery
ClusterRole ais-operator-proxy-roleauthentication.k8s.io/tokenreviewscreateMediumCredentialAccess InformationDisclosure RBACQuery
ClusterRole ais-operator-manager-roleais.nvidia.com/aistorescreate · delete · get · list · patch · update · watchLow
ClusterRole ais-operator-manager-roleais.nvidia.com/aistores/finalizersupdateLow
ClusterRole ais-operator-manager-roleais.nvidia.com/aistores/statusget · patch · updateLow
ClusterRole ais-operator-manager-rolerbac.authorization.k8s.io/clusterrolebindingsdeleteLow
ClusterRole ais-operator-manager-rolerbac.authorization.k8s.io/clusterrolesdeleteLow
Role ais-operator-leader-election-rolecoordination.k8s.io/configmapscreate · delete · get · list · patch · update · watchLow
ClusterRole ais-operator-manager-rolediscovery.k8s.io/endpointslicesget · list · watchLow
ClusterRole ais-operator-manager-rolecore/eventscreate · patchLow
Role ais-operator-leader-election-rolecore/eventscreate · patchLow
ClusterRole ais-operator-manager-rolebatch/jobsdelete · list · watchLow
Role ais-operator-leader-election-rolecore/leasescreate · delete · get · list · patch · update · watchLow
ClusterRole ais-operator-manager-rolecore/nodesget · list · watchLow
ClusterRole ais-operator-manager-rolecore/persistentvolumeclaimsdelete · list · watchLow
ClusterRole ais-operator-manager-rolecore/serviceaccountscreate · delete · get · list · update · watchLow
ClusterRole ais-operator-manager-rolestorage.k8s.io/storageclassesget · list · watchLow

⚠️ Potential Abuse (22)

The following security risks were found based on the above permissions: