Description

The Dash0 Operator makes observability easy for every Kubernetes setup, simply install the operator into your cluster to get OpenTelemetry data flowing from your applications and infrastructure to Dash0.

Overview

IdentityNamespaceAutomountSecretsPermissionsWorkloadsRisk
dash0-operator-controllerdefault483Critical

Numbers in the last two columns indicate how many bindings or workloads involve each ServiceAccount.


Identities

🤖 dash0-operator-controller

Namespace: default  |  Automount:

🔑 Permissions (48)

RoleResourceVerbsRiskTags
ClusterRole dash0-operator-manager-rolerbac.authorization.k8s.io/clusterrolebindingscreate · delete · get · list · patch · update · watchCriticalBindingToPrivilegedRole ClusterAdminAccess InformationDisclosure PrivilegeEscalation RBACManipulation (+2 more)
ClusterRole dash0-operator-manager-rolerbac.authorization.k8s.io/clusterrolescreate · delete · get · list · patch · update · watchCriticalClusterAdminAccess InformationDisclosure PrivilegeEscalation RBACManipulation RBACQuery (+1 more)
ClusterRole dash0-operator-manager-rolecore/configmapscreate · delete · get · list · patch · update · watchCriticalConfigMapAccess DataExposure InformationDisclosure PotentialPrivilegeEscalation Tampering
ClusterRole dash0-operator-manager-roleapps/daemonsetscreate · delete · get · list · patch · update · watchCriticalNodeAccess Persistence PrivilegeEscalation Tampering WorkloadLifecycle
ClusterRole dash0-operator-manager-roleapps/deploymentscreate · delete · get · list · patch · update · watchCriticalPersistence PotentialPrivilegeEscalation PrivilegeEscalation Tampering WorkloadLifecycle
Role dash0-operator-leader-election-rolecoordination.k8s.io/leasescreate · delete · get · list · patch · update · watchCriticalControlPlaneDisruption CriticalNamespace DenialOfService Tampering
ClusterRole dash0-operator-manager-rolecore/secretsget · list · watchCriticalClusterWideSecretAccess CredentialAccess DataExposure InformationDisclosure SecretAccess
ClusterRole dash0-operator-manager-rolecore/servicescreate · delete · get · list · patch · update · watchCriticalDenialOfService NetworkManipulation ServiceExposure Tampering
Role dash0-operator-leader-election-rolecore/configmapscreate · delete · get · list · patch · update · watchHighConfigMapAccess DataExposure InformationDisclosure PotentialPrivilegeEscalation Tampering
ClusterRole dash0-operator-manager-rolerbac.authorization.k8s.io/rolebindingscreate · delete · get · list · patch · update · watchHighBindingToPrivilegedRole InformationDisclosure PrivilegeEscalation RBACManipulation RBACQuery (+1 more)
ClusterRole dash0-operator-manager-rolerbac.authorization.k8s.io/rolescreate · delete · get · list · patch · update · watchHighInformationDisclosure PrivilegeEscalation RBACManipulation RBACQuery Reconnaissance
ClusterRole dash0-operator-manager-rolecore/serviceaccountscreate · delete · get · list · patch · update · watchHighIdentityManagement PotentialPrivilegeEscalation Tampering
ClusterRole dash0-operator-manager-rolecore/eventscreate · get · list · patch · update · watchMediumInformationDisclosure OperationalData Reconnaissance
ClusterRole dash0-operator-manager-rolecore/resourcequotasget · list · watchMediumInformationDisclosure QuotaTampering Reconnaissance ResourceConfiguration
ClusterRole dash0-operator-proxy-roleauthorization.k8s.io/subjectaccessreviewscreateMediumInformationDisclosure RBACQuery
ClusterRole dash0-operator-proxy-roleauthentication.k8s.io/tokenreviewscreateMediumCredentialAccess InformationDisclosure RBACQuery
ClusterRole dash0-operator-manager-rolebatch/cronjobsget · list · patch · update · watchLow
ClusterRole dash0-operator-manager-roleapiextensions.k8s.io/customresourcedefinitionsget · list · watchLow
ClusterRole dash0-operator-manager-roleextensions/daemonsetsget · list · watchLow
ClusterRole dash0-operator-manager-roleoperator.dash0.com/dash0monitoringscreate · delete · deletecollection · get · list · patch · update · watchLow
ClusterRole dash0-operator-manager-roleoperator.dash0.com/dash0monitorings/finalizersupdateLow
ClusterRole dash0-operator-manager-roleoperator.dash0.com/dash0monitorings/statusget · patch · updateLow
ClusterRole dash0-operator-manager-roleoperator.dash0.com/dash0operatorconfigurationscreate · delete · deletecollection · get · list · patch · update · watchLow
ClusterRole dash0-operator-manager-roleoperator.dash0.com/dash0operatorconfigurations/finalizersupdateLow
ClusterRole dash0-operator-manager-roleoperator.dash0.com/dash0operatorconfigurations/statusget · patch · updateLow
ClusterRole dash0-operator-manager-roleextensions/deploymentsget · list · watchLow
ClusterRole dash0-operator-manager-rolecore/endpointsget · list · watchLow
ClusterRole dash0-operator-manager-rolediscovery.k8s.io/endpointsliceslistLow
Role dash0-operator-leader-election-rolecore/eventscreate · patchLow
ClusterRole dash0-operator-manager-roleautoscaling/horizontalpodautoscalersget · list · watchLow
ClusterRole dash0-operator-manager-rolebatch/jobsget · list · patch · update · watchLow
ClusterRole dash0-operator-manager-rolecore/namespacesget · list · watchLowClusterStructure InformationDisclosure Reconnaissance
ClusterRole dash0-operator-manager-rolecore/namespaces/statusget · list · watchLow
ClusterRole dash0-operator-manager-rolecore/nodesget · list · watchLow
ClusterRole dash0-operator-manager-rolecore/nodes/proxygetLow
ClusterRole dash0-operator-manager-rolecore/nodes/specget · list · watchLow
ClusterRole dash0-operator-manager-rolecore/nodes/statsget · list · watchLow
ClusterRole dash0-operator-manager-roleperses.dev/persesdashboardsget · list · watchLow
ClusterRole dash0-operator-manager-rolecore/persistentvolumeclaimsget · list · watchLow
ClusterRole dash0-operator-manager-rolecore/persistentvolumesget · list · watchLow
ClusterRole dash0-operator-manager-rolecore/podsdelete · get · list · watchLow
ClusterRole dash0-operator-manager-rolecore/pods/statusget · list · watchLow
ClusterRole dash0-operator-manager-rolemonitoring.coreos.com/prometheusrulesget · list · watchLow
ClusterRole dash0-operator-manager-roleapps/replicasetsget · list · patch · update · watchLow
ClusterRole dash0-operator-manager-roleextensions/replicasetsget · list · watchLow
ClusterRole dash0-operator-manager-rolecore/replicationcontrollersget · list · watchLow
ClusterRole dash0-operator-manager-rolecore/replicationcontrollers/statusget · list · watchLow
ClusterRole dash0-operator-manager-roleapps/statefulsetsget · list · patch · update · watchLow

⚠️ Potential Abuse (27)

The following security risks were found based on the above permissions:

📦 Workloads (3)

KindNameContainerImage
Deploymentdash0-operator-controllerkube-rbac-proxyquay.io/brancz/kube-rbac-proxy:v0.18.0
Deploymentdash0-operator-controllermanagerghcr.io/dash0hq/operator-controller:0.74.0
Jobdash0-operator-pre-deletepre-delete-jobghcr.io/dash0hq/operator-controller:0.74.0