Description

Datadog Operator

Overview

IdentityNamespaceAutomountSecretsPermissionsWorkloadsRisk
datadog-operatordefault241Critical

Numbers in the last two columns indicate how many bindings or workloads involve each ServiceAccount.


Identities

🤖 datadog-operator

Namespace: default  |  Automount:

🔑 Permissions (24)

RoleResourceVerbsRiskTags
ClusterRole datadog-operatorrbac.authorization.k8s.io/clusterrolebindings*CriticalBindingToPrivilegedRole ClusterAdminAccess ClusterWideAccess InformationDisclosure PrivilegeEscalation (+4 more)
ClusterRole datadog-operatorrbac.authorization.k8s.io/clusterroles*CriticalBindingToPrivilegedRole ClusterAdminAccess ClusterWideAccess InformationDisclosure PrivilegeEscalation (+4 more)
ClusterRole datadog-operatorauthorization.k8s.io/clusterrolebindings*HighClusterWideAccess WildcardPermission
ClusterRole datadog-operatorroles.rbac.authorization.k8s.io/clusterrolebindings*HighClusterWideAccess WildcardPermission
ClusterRole datadog-operatorauthorization.k8s.io/clusterroles*HighClusterWideAccess WildcardPermission
ClusterRole datadog-operatorroles.rbac.authorization.k8s.io/clusterroles*HighClusterWideAccess WildcardPermission
ClusterRole datadog-operatordatadoghq.com/datadogagents*HighClusterWideAccess WildcardPermission
ClusterRole datadog-operatordatadoghq.com/datadogagents/finalizers*HighClusterWideAccess WildcardPermission
ClusterRole datadog-operatordatadoghq.com/datadogagents/status*HighClusterWideAccess WildcardPermission
ClusterRole datadog-operatoradmissionregistration.k8s.io/mutatingwebhookconfigurationscreate · get · list · update · watchMediumInformationDisclosure Reconnaissance WebhookReconnaissance
ClusterRole datadog-operatorapiregistration.k8s.io/apiservicescreate · delete · get · list · update · watchLow
ClusterRole datadog-operatorapps/cronjobsgetLow
ClusterRole datadog-operatorbatch/cronjobsgetLow
ClusterRole datadog-operatorapps/deploymentsgetLow
ClusterRole datadog-operatorbatch/deploymentsgetLow
ClusterRole datadog-operatorapps/jobsgetLow
ClusterRole datadog-operatorbatch/jobsgetLow
ClusterRole datadog-operatorapps/replicasetsgetLow
ClusterRole datadog-operatorbatch/replicasetsgetLow
ClusterRole datadog-operatoradmissionregistration.k8s.io/secretscreate · get · list · update · watchLow
ClusterRole datadog-operatorapps/statefulsetsgetLow
ClusterRole datadog-operatorbatch/statefulsetsgetLow
ClusterRole datadog-operatordatadoghq.com/watermarkpodautoscalersget · list · watchLow
ClusterRole datadog-operatorsecurity.openshift.io/securitycontextconstraints (restricted to: restricted)useLowResourceNameRestricted

⚠️ Potential Abuse (8)

The following security risks were found based on the above permissions:

📦 Workloads (1)

KindNameContainerImage
Deploymentdatadog-operatordatadog-operatorgcr.io/datadoghq/operator:0.3.1