Description

Datadog Operator

Overview

IdentityNamespaceAutomountSecretsPermissionsWorkloadsRisk
datadog-operatordefault521Critical

Numbers in the last two columns indicate how many bindings or workloads involve each ServiceAccount.


Identities

🤖 datadog-operator

Namespace: default  |  Automount:

🔑 Permissions (52)

RoleResourceVerbsRiskTags
ClusterRole datadog-operatorapiregistration.k8s.io/apiservices*CriticalAPIServiceManipulation ClusterWideAccess DenialOfService InformationDisclosure PrivilegeEscalation (+2 more)
ClusterRole datadog-operatorrbac.authorization.k8s.io/clusterrolebindings*CriticalBindingToPrivilegedRole ClusterAdminAccess ClusterWideAccess InformationDisclosure PrivilegeEscalation (+4 more)
ClusterRole datadog-operatorrbac.authorization.k8s.io/clusterroles*CriticalBindingToPrivilegedRole ClusterAdminAccess ClusterWideAccess InformationDisclosure PrivilegeEscalation (+4 more)
ClusterRole datadog-operatorcore/configmaps*CriticalClusterWideAccess ConfigMapAccess DataExposure InformationDisclosure PotentialPrivilegeEscalation (+2 more)
ClusterRole datadog-operatorapps/daemonsets*CriticalClusterWideAccess NodeAccess Persistence PrivilegeEscalation Tampering (+2 more)
ClusterRole datadog-operatorapps/deployments*CriticalClusterWideAccess Persistence PotentialPrivilegeEscalation PrivilegeEscalation Tampering (+2 more)
ClusterRole datadog-operatorcore/endpoints*CriticalClusterWideAccess DenialOfService ManInTheMiddle NetworkManipulation Tampering (+2 more)
ClusterRole datadog-operatorcoordination.k8s.io/leases*CriticalClusterWideAccess ControlPlaneDisruption CriticalNamespace DenialOfService LeaderElectionAbuse (+2 more)
ClusterRole datadog-operatoradmissionregistration.k8s.io/mutatingwebhookconfigurations*CriticalClusterWideAccess DenialOfService InformationDisclosure PrivilegeEscalation Reconnaissance (+4 more)
ClusterRole datadog-operatornetworking.k8s.io/networkpolicies*CriticalClusterWideAccess DenialOfService LateralMovement NetworkManipulation NetworkPolicyManagement (+2 more)
ClusterRole datadog-operatorcore/nodes/proxygetCriticalAuthorizationBypass ClusterAdminAccess CodeExecution ElevationOfPrivilege LateralMovement (+1 more)
ClusterRole datadog-operatorcore/pods*CriticalClusterWideAccess LateralMovement Persistence PotentialPrivilegeEscalation PrivilegeEscalation (+3 more)
ClusterRole datadog-operatorcore/secrets*CriticalClusterWideAccess ClusterWideSecretAccess CredentialAccess DataExposure InformationDisclosure (+6 more)
ClusterRole datadog-operatorcore/serviceaccounts*CriticalClusterAdminAccess ClusterWideAccess IdentityManagement Impersonation PotentialPrivilegeEscalation (+4 more)
ClusterRole datadog-operatorcore/services*CriticalClusterWideAccess DenialOfService NetworkManipulation ServiceExposure Tampering (+1 more)
ClusterRole datadog-operatorauthorization.k8s.io/clusterrolebindings*HighClusterWideAccess WildcardPermission
ClusterRole datadog-operatorroles.rbac.authorization.k8s.io/clusterrolebindings*HighClusterWideAccess WildcardPermission
ClusterRole datadog-operatorauthorization.k8s.io/clusterroles*HighClusterWideAccess WildcardPermission
ClusterRole datadog-operatorroles.rbac.authorization.k8s.io/clusterroles*HighClusterWideAccess WildcardPermission
ClusterRole datadog-operatordatadoghq.com/extendeddaemonsets*HighClusterWideAccess WildcardPermission
ClusterRole datadog-operatorauthorization.k8s.io/rolebindings*HighClusterWideAccess WildcardPermission
ClusterRole datadog-operatorrbac.authorization.k8s.io/rolebindings*HighBindingToPrivilegedRole ClusterWideAccess InformationDisclosure PrivilegeEscalation RBACManipulation (+3 more)
ClusterRole datadog-operatorroles.rbac.authorization.k8s.io/rolebindings*HighClusterWideAccess WildcardPermission
ClusterRole datadog-operatorauthorization.k8s.io/roles*HighClusterWideAccess WildcardPermission
ClusterRole datadog-operatorrbac.authorization.k8s.io/roles*HighClusterWideAccess InformationDisclosure PrivilegeEscalation RBACManipulation RBACQuery (+2 more)
ClusterRole datadog-operatorroles.rbac.authorization.k8s.io/roles*HighClusterWideAccess WildcardPermission
ClusterRole datadog-operatorcore/componentstatusesget · list · watchMediumControlPlaneDisruption InformationDisclosure Reconnaissance
ClusterRole datadog-operatorcore/events*MediumClusterWideAccess InformationDisclosure OperationalData Reconnaissance WildcardPermission
ClusterRole datadog-operatorpolicy/poddisruptionbudgets*MediumAvailabilityImpact ClusterWideAccess DenialOfService Tampering WildcardPermission
ClusterRole datadog-operatorauthorization.k8s.io/subjectaccessreviewscreateMediumInformationDisclosure RBACQuery
ClusterRole datadog-operatorquota.openshift.io/clusterresourcequotasget · listLow
ClusterRole datadog-operatorbatch/cronjobsget · list · watchLow
ClusterRole datadog-operatordatadoghq.com/datadogagentscreate · delete · get · list · patch · update · watchLow
ClusterRole datadog-operatordatadoghq.com/datadogagents/finalizerscreate · delete · get · list · patch · update · watchLow
ClusterRole datadog-operatordatadoghq.com/datadogagents/statusget · patch · updateLow
ClusterRole datadog-operatordatadoghq.com/datadogmetricscreate · delete · get · list · update · watchLow
ClusterRole datadog-operatordatadoghq.com/datadogmetrics/statusupdateLow
ClusterRole datadog-operatordatadoghq.com/datadogmonitorscreate · delete · get · list · update · watchLow
ClusterRole datadog-operatordatadoghq.com/datadogmonitors/statusupdateLow
ClusterRole datadog-operatorbatch/jobsget · list · watchLow
ClusterRole datadog-operatorcore/namespacesget · list · watchLowClusterStructure InformationDisclosure Reconnaissance
ClusterRole datadog-operatorcore/nodesget · list · watchLow
ClusterRole datadog-operatorcore/nodes/metricsgetLow
ClusterRole datadog-operatorcore/nodes/specgetLow
ClusterRole datadog-operatorcore/nodes/statsgetLow
ClusterRole datadog-operatorpolicy/podsecuritypoliciesget · list · watchLow
ClusterRole datadog-operatorapps/replicasetsget · list · watchLow
ClusterRole datadog-operatorauthorization.k8s.io/selfsubjectaccessreviewscreateLow
ClusterRole datadog-operatorauthorization.k8s.io/selfsubjectrulesreviewscreateLowInformationDisclosure RBACQuery Reconnaissance SelfPermissionReviewQuery
ClusterRole datadog-operatorapps/statefulsetsget · list · watchLow
ClusterRole datadog-operatordatadoghq.com/watermarkpodautoscalersget · list · watchLow
ClusterRole datadog-operatorsecurity.openshift.io/securitycontextconstraints (restricted to: restricted)useLowResourceNameRestricted

⚠️ Potential Abuse (46)

The following security risks were found based on the above permissions:

📦 Workloads (1)

KindNameContainerImage
Deploymentdatadog-operatordatadog-operatorgcr.io/datadoghq/operator:0.6.0