Description

The Dynatrace Operator Helm chart for Kubernetes and OpenShift

Overview

IdentityNamespaceAutomountSecretsPermissionsWorkloadsRisk
dynatrace-kubernetes-monitoringdefault570Medium
dynatrace-operatordefault11Low

Numbers in the last two columns indicate how many bindings or workloads involve each ServiceAccount.


Identities

🤖 dynatrace-kubernetes-monitoring

Namespace: default  |  Automount:

🔑 Permissions (57)

RoleResourceVerbsRiskTags
ClusterRole dynatrace-kubernetes-monitoringcore/eventsget · list · watchMediumInformationDisclosure OperationalData Reconnaissance
ClusterRole dynatrace-kubernetes-monitoringcore/resourcequotasget · list · watchMediumInformationDisclosure QuotaTampering Reconnaissance ResourceConfiguration
ClusterRole dynatrace-kubernetes-monitoringapps/cronjobsget · list · watchLow
ClusterRole dynatrace-kubernetes-monitoringapps.openshift.io/cronjobsget · list · watchLow
ClusterRole dynatrace-kubernetes-monitoringbatch/cronjobsget · list · watchLow
ClusterRole dynatrace-kubernetes-monitoringcore/cronjobsget · list · watchLow
ClusterRole dynatrace-kubernetes-monitoringapps/daemonsetsget · list · watchLow
ClusterRole dynatrace-kubernetes-monitoringapps.openshift.io/daemonsetsget · list · watchLow
ClusterRole dynatrace-kubernetes-monitoringbatch/daemonsetsget · list · watchLow
ClusterRole dynatrace-kubernetes-monitoringcore/daemonsetsget · list · watchLow
ClusterRole dynatrace-kubernetes-monitoringapps/deploymentconfigsget · list · watchLow
ClusterRole dynatrace-kubernetes-monitoringapps.openshift.io/deploymentconfigsget · list · watchLow
ClusterRole dynatrace-kubernetes-monitoringbatch/deploymentconfigsget · list · watchLow
ClusterRole dynatrace-kubernetes-monitoringcore/deploymentconfigsget · list · watchLow
ClusterRole dynatrace-kubernetes-monitoringapps/deploymentsget · list · watchLow
ClusterRole dynatrace-kubernetes-monitoringapps.openshift.io/deploymentsget · list · watchLow
ClusterRole dynatrace-kubernetes-monitoringbatch/deploymentsget · list · watchLow
ClusterRole dynatrace-kubernetes-monitoringcore/deploymentsget · list · watchLow
ClusterRole dynatrace-kubernetes-monitoringapps/eventsget · list · watchLow
ClusterRole dynatrace-kubernetes-monitoringapps.openshift.io/eventsget · list · watchLow
ClusterRole dynatrace-kubernetes-monitoringbatch/eventsget · list · watchLow
ClusterRole dynatrace-kubernetes-monitoringapps/jobsget · list · watchLow
ClusterRole dynatrace-kubernetes-monitoringapps.openshift.io/jobsget · list · watchLow
ClusterRole dynatrace-kubernetes-monitoringbatch/jobsget · list · watchLow
ClusterRole dynatrace-kubernetes-monitoringcore/jobsget · list · watchLow
ClusterRole dynatrace-kubernetes-monitoringapps/namespacesget · list · watchLow
ClusterRole dynatrace-kubernetes-monitoringapps.openshift.io/namespacesget · list · watchLow
ClusterRole dynatrace-kubernetes-monitoringbatch/namespacesget · list · watchLow
ClusterRole dynatrace-kubernetes-monitoringcore/namespacesget · list · watchLowClusterStructure InformationDisclosure Reconnaissance
ClusterRole dynatrace-kubernetes-monitoringapps/nodesget · list · watchLow
ClusterRole dynatrace-kubernetes-monitoringapps.openshift.io/nodesget · list · watchLow
ClusterRole dynatrace-kubernetes-monitoringbatch/nodesget · list · watchLow
ClusterRole dynatrace-kubernetes-monitoringcore/nodesget · list · watchLow
ClusterRole dynatrace-kubernetes-monitoringapps/podsget · list · watchLow
ClusterRole dynatrace-kubernetes-monitoringapps.openshift.io/podsget · list · watchLow
ClusterRole dynatrace-kubernetes-monitoringbatch/podsget · list · watchLow
ClusterRole dynatrace-kubernetes-monitoringcore/podsget · list · watchLow
ClusterRole dynatrace-kubernetes-monitoringapps/pods/proxyget · list · watchLow
ClusterRole dynatrace-kubernetes-monitoringapps.openshift.io/pods/proxyget · list · watchLow
ClusterRole dynatrace-kubernetes-monitoringbatch/pods/proxyget · list · watchLow
ClusterRole dynatrace-kubernetes-monitoringcore/pods/proxyget · list · watchLow
ClusterRole dynatrace-kubernetes-monitoringapps/replicasetsget · list · watchLow
ClusterRole dynatrace-kubernetes-monitoringapps.openshift.io/replicasetsget · list · watchLow
ClusterRole dynatrace-kubernetes-monitoringbatch/replicasetsget · list · watchLow
ClusterRole dynatrace-kubernetes-monitoringcore/replicasetsget · list · watchLow
ClusterRole dynatrace-kubernetes-monitoringapps/replicationcontrollersget · list · watchLow
ClusterRole dynatrace-kubernetes-monitoringapps.openshift.io/replicationcontrollersget · list · watchLow
ClusterRole dynatrace-kubernetes-monitoringbatch/replicationcontrollersget · list · watchLow
ClusterRole dynatrace-kubernetes-monitoringcore/replicationcontrollersget · list · watchLow
ClusterRole dynatrace-kubernetes-monitoringapps/resourcequotasget · list · watchLow
ClusterRole dynatrace-kubernetes-monitoringapps.openshift.io/resourcequotasget · list · watchLow
ClusterRole dynatrace-kubernetes-monitoringbatch/resourcequotasget · list · watchLow
ClusterRole dynatrace-kubernetes-monitoringapps/statefulsetsget · list · watchLow
ClusterRole dynatrace-kubernetes-monitoringapps.openshift.io/statefulsetsget · list · watchLow
ClusterRole dynatrace-kubernetes-monitoringbatch/statefulsetsget · list · watchLow
ClusterRole dynatrace-kubernetes-monitoringcore/statefulsetsget · list · watchLow
Role dynatrace-kubernetes-monitoringpolicy/podsecuritypolicies (restricted to: dynatrace-kubernetes-monitoring)useLowResourceNameRestricted

⚠️ Potential Abuse (5)

The following security risks were found based on the above permissions:

📦 Workloads (0)

No workloads use this ServiceAccount.


🤖 dynatrace-operator

Namespace: default  |  Automount:

🔑 Permissions (1)

RoleResourceVerbsRiskTags
ClusterRole dynatrace-operatorcore/namespaces (restricted to: kube-system)get · list · watchLowClusterStructure InformationDisclosure Reconnaissance ResourceNameRestricted

⚠️ Potential Abuse (2)

The following security risks were found based on the above permissions:

📦 Workloads (1)

KindNameContainerImage
Deploymentdynatrace-operatordynatrace-operatordocker.io/dynatrace/dynatrace-operator:v0.1.0