Description

Helm chart for Cloudflare Operator

Overview

IdentityNamespaceAutomountSecretsPermissionsWorkloadsRisk
cloudflare-operatordefault151Critical

Numbers in the last two columns indicate how many bindings or workloads involve each ServiceAccount.


Identities

🤖 cloudflare-operator

Namespace: default  |  Automount:

🔑 Permissions (15)

RoleResourceVerbsRiskTags
ClusterRole cloudflare-operatorcore/secretsget · list · watchCriticalClusterWideSecretAccess CredentialAccess DataExposure InformationDisclosure SecretAccess
ClusterRole cloudflare-operatorcloudflare-operator.io/accountscreate · delete · get · list · patch · update · watchLow
ClusterRole cloudflare-operatorcloudflare-operator.io/accounts/finalizersupdateLow
ClusterRole cloudflare-operatorcloudflare-operator.io/accounts/statusget · patch · updateLow
ClusterRole cloudflare-operatorcloudflare-operator.io/dnsrecordscreate · delete · get · list · patch · update · watchLow
ClusterRole cloudflare-operatorcloudflare-operator.io/dnsrecords/finalizersupdateLow
ClusterRole cloudflare-operatorcloudflare-operator.io/dnsrecords/statusget · patch · updateLow
ClusterRole cloudflare-operatornetworking.k8s.io/ingressesget · list · watchLow
ClusterRole cloudflare-operatornetworking.k8s.io/ingresses/finalizersupdateLow
ClusterRole cloudflare-operatorcloudflare-operator.io/ipscreate · delete · get · list · patch · update · watchLow
ClusterRole cloudflare-operatorcloudflare-operator.io/ips/finalizersupdateLow
ClusterRole cloudflare-operatorcloudflare-operator.io/ips/statusget · patch · updateLow
ClusterRole cloudflare-operatorcloudflare-operator.io/zonescreate · delete · get · list · patch · update · watchLow
ClusterRole cloudflare-operatorcloudflare-operator.io/zones/finalizersupdateLow
ClusterRole cloudflare-operatorcloudflare-operator.io/zones/statusget · patch · updateLow

⚠️ Potential Abuse (3)

The following security risks were found based on the above permissions:

📦 Workloads (1)

KindNameContainerImage
Deploymentcloudflare-operatorcloudflare-operatorghcr.io/containeroo/cloudflare-operator:v1.5.1