Description

An operator to take scheduled snapshots of Kubernetes persistent volumes

Overview

IdentityNamespaceAutomountSecretsPermissionsWorkloadsRisk
snapschedulerdefault102Critical

Numbers in the last two columns indicate how many bindings or workloads involve each ServiceAccount.


Identities

🤖 snapscheduler

Namespace: default  |  Automount:

🔑 Permissions (10)

RoleResourceVerbsRiskTags
Role snapscheduler-leader-electioncoordination.k8s.io/leasescreate · delete · get · list · patch · update · watchCriticalControlPlaneDisruption CriticalNamespace DenialOfService Tampering
Role snapscheduler-leader-electioncore/configmapscreate · delete · get · list · patch · update · watchHighConfigMapAccess DataExposure InformationDisclosure PotentialPrivilegeEscalation Tampering
ClusterRole snapscheduler-proxyauthorization.k8s.io/subjectaccessreviewscreateMediumInformationDisclosure RBACQuery
ClusterRole snapscheduler-proxyauthentication.k8s.io/tokenreviewscreateMediumCredentialAccess InformationDisclosure RBACQuery
Role snapscheduler-leader-electioncore/eventscreate · patchLow
ClusterRole snapschedulercore/persistentvolumeclaimsget · list · watchLow
ClusterRole snapschedulersnapscheduler.backube/snapshotschedulescreate · delete · get · list · patch · update · watchLow
ClusterRole snapschedulersnapscheduler.backube/snapshotschedules/finalizersupdateLow
ClusterRole snapschedulersnapscheduler.backube/snapshotschedules/statusget · patch · updateLow
ClusterRole snapschedulersnapshot.storage.k8s.io/volumesnapshotscreate · delete · get · list · patch · update · watchLow

⚠️ Potential Abuse (6)

The following security risks were found based on the above permissions:

📦 Workloads (2)

KindNameContainerImage
Deploymentsnapschedulerkube-rbac-proxyquay.io/brancz/kube-rbac-proxy:v0.19.1@sha256:9f21034731c7c3228611b9d40807f3230ce8ed2b286b913bf2d1e760d8d866fc
Deploymentsnapschedulermanagerquay.io/backube/snapscheduler:3.5.0