Description

A Helm chart for monitoring-operator by AppsCode

Overview

IdentityNamespaceAutomountSecretsPermissionsWorkloadsRisk
monitoring-operatordefault281Critical

Numbers in the last two columns indicate how many bindings or workloads involve each ServiceAccount.


Identities

🤖 monitoring-operator

Namespace: default  |  Automount:

🔑 Permissions (28)

RoleResourceVerbsRiskTags
ClusterRole monitoring-operatorapiextensions.k8s.io/customresourcedefinitions*CriticalCRDManipulation ClusterWideAccess PotentialPrivilegeEscalation Tampering WildcardPermission
ClusterRole monitoring-operatorcore/secretscreate · get · list · patch · update · watchCriticalClusterWideSecretAccess CredentialAccess DataExposure InformationDisclosure SecretAccess
ClusterRole monitoring-operatorappcatalog.appscode.com/*get · list · watchHighClusterWideAccess WildcardPermission
ClusterRole monitoring-operatoropenviz.dev/**HighClusterWideAccess WildcardPermission
ClusterRole monitoring-operatorui.openviz.dev/**HighClusterWideAccess WildcardPermission
ClusterRole monitoring-operatorcore/configmapsget · list · watchHighConfigMapAccess DataExposure InformationDisclosure
ClusterRole monitoring-operatorcore/services/proxy*HighClusterWideAccess WildcardPermission
ClusterRole monitoring-operatorrbac.authorization.k8s.io/clusterrolebindingsget · list · watchMediumInformationDisclosure RBACQuery Reconnaissance
ClusterRole monitoring-operatorrbac.authorization.k8s.io/clusterrolescreate · get · list · patch · update · watchMediumInformationDisclosure RBACQuery Reconnaissance
ClusterRole monitoring-operatorrbac.authorization.k8s.io/rolebindingscreate · get · list · patch · update · watchMediumInformationDisclosure RBACQuery Reconnaissance
ClusterRole monitoring-operatorrbac.authorization.k8s.io/rolesget · list · watchMediumInformationDisclosure RBACQuery Reconnaissance
ClusterRole monitoring-operatormonitoring.coreos.com/alertmanagerconfigscreate · get · list · patch · watchLow
ClusterRole monitoring-operatormonitoring.coreos.com/alertmanagersget · list · watchLow
ClusterRole monitoring-operatorapiregistration.k8s.io/apiservicesget · list · watchLow
ClusterRole monitoring-operatorappcatalog.appscode.com/appbindingscreate · get · list · patch · update · watchLow
ClusterRole monitoring-operatorcharts.x-helm.dev/chartpresetscreate · delete · get · list · patch · update · watchLow
ClusterRole monitoring-operatorcharts.x-helm.dev/clusterchartpresetscreate · delete · get · list · patch · update · watchLow
ClusterRole monitoring-operatorcluster.open-cluster-management.io/clusterclaimsget · list · watchLow
ClusterRole monitoring-operatorapps/deploymentsget · list · watchLow
ClusterRole monitoring-operatorcore/endpointscreate · get · list · patch · update · watchLow
ClusterRole monitoring-operatoroperator.open-cluster-management.io/klusterletsget · list · watchLow
ClusterRole monitoring-operatorcore/namespacescreate · get · list · patch · update · watchLowClusterStructure InformationDisclosure Reconnaissance
ClusterRole monitoring-operatorcore/nodesget · list · watchLow
ClusterRole monitoring-operatormonitoring.coreos.com/prometheusesget · list · patch · update · watchLow
ClusterRole monitoring-operatormeta.k8s.appscode.com/resourcequeriescreateLow
ClusterRole monitoring-operatorcore/serviceaccountscreate · get · list · patch · update · watchLow
ClusterRole monitoring-operatormonitoring.coreos.com/servicemonitorscreate · get · list · patch · update · watchLow
ClusterRole monitoring-operatorcore/servicescreate · get · list · patch · update · watchLow

⚠️ Potential Abuse (9)

The following security risks were found based on the above permissions:

📦 Workloads (1)

KindNameContainerImage
Deploymentmonitoring-operatoroperatorghcr.io/appscode/grafana-tools:v0.4.1