Description

A Helm chart for Grafana Operator by AppsCode

Overview

IdentityNamespaceAutomountSecretsPermissionsWorkloadsRisk
grafana-operatordefault221Critical

Numbers in the last two columns indicate how many bindings or workloads involve each ServiceAccount.


Identities

🤖 grafana-operator

Namespace: default  |  Automount:

🔑 Permissions (22)

RoleResourceVerbsRiskTags
ClusterRole grafana-operatorapiextensions.k8s.io/customresourcedefinitions*CriticalCRDManipulation ClusterWideAccess PotentialPrivilegeEscalation Tampering WildcardPermission
ClusterRole grafana-operatorcore/podscreate · get · listCriticalLateralMovement Persistence PotentialPrivilegeEscalation PrivilegeEscalation WorkloadExecution
ClusterRole grafana-operatorcore/pods/execcreate · get · listCriticalClusterWidePodExec CodeExecution ElevationOfPrivilege LateralMovement PodExec (+1 more)
ClusterRole grafana-operatorcore/secretscreate · get · list · patch · watchCriticalClusterWideSecretAccess CredentialAccess DataExposure InformationDisclosure SecretAccess
ClusterRole grafana-operatorappcatalog.appscode.com/**HighClusterWideAccess WildcardPermission
ClusterRole grafana-operatoropenviz.dev/**HighClusterWideAccess WildcardPermission
ClusterRole grafana-operatorcore/configmapscreate · get · list · patch · watchHighConfigMapAccess DataExposure InformationDisclosure
ClusterRole grafana-operatormonitoring.coreos.com/servicemonitors*HighClusterWideAccess WildcardPermission
ClusterRole grafana-operatoradmissionregistration.k8s.io/mutatingwebhookconfigurationsdelete · list · patch · watchMediumInformationDisclosure Reconnaissance WebhookReconnaissance
ClusterRole grafana-operatoradmissionregistration.k8s.io/validatingwebhookconfigurationsdelete · list · patch · watchMediumInformationDisclosure Reconnaissance WebhookReconnaissance
ClusterRole grafana-operatorapiregistration.k8s.io/apiservicesdelete · get · patchLow
ClusterRole grafana-operatorrbac.authorization.k8s.io/clusterrolebindingscreate · get · patch · updateLow
ClusterRole grafana-operatorrbac.authorization.k8s.io/clusterrolescreate · get · patch · updateLow
ClusterRole grafana-operatorapps/deploymentscreate · get · patch · updateLow
ClusterRole grafana-operatorcore/eventscreate · patchLow
ClusterRole grafana-operatoropenviz.dev/grafanadashboards/finalizersupdateLow
ClusterRole grafana-operatoropenviz.dev/grafanadatasources/finalizersupdateLow
ClusterRole grafana-operatorcore/nodeslistLow
ClusterRole grafana-operatorrbac.authorization.k8s.io/rolebindingscreate · get · patch · updateLow
ClusterRole grafana-operatorrbac.authorization.k8s.io/rolescreate · get · patch · updateLow
ClusterRole grafana-operatorcore/serviceaccountscreate · get · list · patch · watchLow
ClusterRole grafana-operatorcore/servicescreate · get · list · patch · watchLow

⚠️ Potential Abuse (13)

The following security risks were found based on the above permissions:

📦 Workloads (1)

KindNameContainerImage
Deploymentgrafana-operatoroperatorghcr.io/appscode/grafana-tools:v0.4.1