Description

A Helm chart for OpenShift

Overview

IdentityNamespaceAutomountSecretsPermissionsWorkloadsRisk
operator-shard-managerdefault41Critical

Numbers in the last two columns indicate how many bindings or workloads involve each ServiceAccount.


Identities

🤖 operator-shard-manager

Namespace: default  |  Automount:

🔑 Permissions (4)

RoleResourceVerbsRiskTags
ClusterRole operator-shard-manager*create · get · list · patch · update · watchCriticalAvailabilityImpact CSRApproval CSRCreation CertificateManagement ClusterAdminAccess (+47 more)
Role operator-shard-manager:leader-electioncoordination.k8s.io/leasescreate · delete · get · list · patch · update · watchCriticalControlPlaneDisruption CriticalNamespace DenialOfService Tampering
Role operator-shard-manager:leader-electioncore/configmapscreate · delete · get · list · patch · update · watchHighConfigMapAccess DataExposure InformationDisclosure PotentialPrivilegeEscalation Tampering
Role operator-shard-manager:leader-electioncore/eventscreate · patchLow

⚠️ Potential Abuse (52)

The following security risks were found based on the above permissions:

📦 Workloads (1)

KindNameContainerImage
Deploymentoperator-shard-manageroperatorghcr.io/appscode/operator-shard-manager:v0.0.3