Description

A Helm chart for Grafana Operator by AppsCode

Overview

IdentityNamespaceAutomountSecretsPermissionsWorkloadsRisk
grafana-operatordefault202Critical

Numbers in the last two columns indicate how many bindings or workloads involve each ServiceAccount.


Identities

🤖 grafana-operator

Namespace: default  |  Automount:

🔑 Permissions (20)

RoleResourceVerbsRiskTags
ClusterRole grafana-operatorapiextensions.k8s.io/customresourcedefinitions*CriticalCRDManipulation ClusterWideAccess PotentialPrivilegeEscalation Tampering WildcardPermission
ClusterRole grafana-operatorcore/podscreate · get · listCriticalLateralMovement Persistence PotentialPrivilegeEscalation PrivilegeEscalation WorkloadExecution
ClusterRole grafana-operatorcore/pods/execcreate · get · listCriticalClusterWidePodExec CodeExecution ElevationOfPrivilege LateralMovement PodExec (+1 more)
ClusterRole grafana-operatorappcatalog.appscode.com/**HighClusterWideAccess WildcardPermission
ClusterRole grafana-operatoropenviz.dev/**HighClusterWideAccess WildcardPermission
ClusterRole grafana-operatorcore/configmapscreate · get · list · patch · watchHighConfigMapAccess DataExposure InformationDisclosure
ClusterRole grafana-operatormonitoring.coreos.com/servicemonitors*HighClusterWideAccess WildcardPermission
ClusterRole grafana-operatoradmissionregistration.k8s.io/mutatingwebhookconfigurationsdelete · list · patch · watchMediumInformationDisclosure Reconnaissance WebhookReconnaissance
ClusterRole grafana-operatoradmissionregistration.k8s.io/validatingwebhookconfigurationsdelete · list · patch · watchMediumInformationDisclosure Reconnaissance WebhookReconnaissance
ClusterRole grafana-operatorapiregistration.k8s.io/apiservicesdelete · get · patchLow
ClusterRole grafana-operatorrbac.authorization.k8s.io/clusterrolebindingscreate · get · patch · updateLow
ClusterRole grafana-operatorrbac.authorization.k8s.io/clusterrolescreate · get · patch · updateLow
ClusterRole grafana-operatorapps/deploymentscreate · get · patch · updateLow
ClusterRole grafana-operatorcore/eventscreateLow
ClusterRole grafana-operatorcore/nodeslistLow
ClusterRole grafana-operatorrbac.authorization.k8s.io/rolebindingscreate · get · patch · updateLow
ClusterRole grafana-operatorrbac.authorization.k8s.io/rolescreate · get · patch · updateLow
ClusterRole grafana-operatorcore/secretscreate · get · patchLow
ClusterRole grafana-operatorcore/serviceaccountscreate · get · patchLow
ClusterRole grafana-operatorcore/servicescreate · get · patchLow

⚠️ Potential Abuse (11)

The following security risks were found based on the above permissions:

📦 Workloads (2)

KindNameContainerImage
Deploymentgrafana-operatoroperatorappscode/grafana-tools:v0.0.1
Jobgrafana-operator-cleanerkubectlappscode/kubectl:v1.22