Description

A Helm chart for Kubernetes

Overview

IdentityNamespaceAutomountSecretsPermissionsWorkloadsRisk
(orphaned-bindings)110Critical

Numbers in the last two columns indicate how many bindings or workloads involve each ServiceAccount.


Identities

⚠️ (orphaned-bindings)

Warning: The following RBAC bindings exist but are not associated with any active service accounts in the cluster.

🔑 Permissions (11)

RoleResourceVerbsRiskTags
ClusterRole ais-operator-manager-role**CriticalAPIServerDoS APIServiceManipulation AvailabilityImpact BackupAccess BindingToPrivilegedRole (+67 more)
Role ais-operator-leader-election-rolecoordination.k8s.io/leasescreate · delete · get · list · patch · update · watchCriticalControlPlaneDisruption CriticalNamespace DenialOfService Tampering
Role ais-operator-leader-election-rolecore/configmapscreate · delete · get · list · patch · update · watchHighConfigMapAccess DataExposure InformationDisclosure PotentialPrivilegeEscalation Tampering
ClusterRole ais-operator-proxy-roleauthorization.k8s.io/subjectaccessreviewscreateMediumInformationDisclosure RBACQuery
ClusterRole ais-operator-proxy-roleauthentication.k8s.io/tokenreviewscreateMediumCredentialAccess InformationDisclosure RBACQuery
ClusterRole ais-operator-manager-roleais.nvidia.com/aistorescreate · delete · get · list · patch · update · watchLow
ClusterRole ais-operator-manager-roleais.nvidia.com/aistores/finalizersupdateLow
ClusterRole ais-operator-manager-roleais.nvidia.com/aistores/statusget · patch · updateLow
Role ais-operator-leader-election-rolecoordination.k8s.io/configmapscreate · delete · get · list · patch · update · watchLow
Role ais-operator-leader-election-rolecore/eventscreate · patchLow
Role ais-operator-leader-election-rolecore/leasescreate · delete · get · list · patch · update · watchLow

⚠️ Potential Abuse (106)

The following security risks were found based on the above permissions: