Description

A Helm chart for EDP Codebase Operator

Overview

IdentityNamespaceAutomountSecretsPermissionsWorkloadsRisk
edp-codebase-operatordefault691Critical

Numbers in the last two columns indicate how many bindings or workloads involve each ServiceAccount.


Identities

🤖 edp-codebase-operator

Namespace: default  |  Automount:

🔑 Permissions (69)

RoleResourceVerbsRiskTags
Role edp-codebase-operatorcoordination.k8s.io/leasescreate · delete · get · list · patch · update · watchCriticalControlPlaneDisruption CriticalNamespace DenialOfService Tampering
Role edp-codebase-operator*/configmaps*HighConfigMapAccess DataExposure InformationDisclosure NamespaceAdmin NamespaceWideAccess (+3 more)
Role edp-codebase-operator*/adminconsoles*MediumNamespaceAdmin NamespaceWideAccess WildcardPermission
Role edp-codebase-operator*/adminconsoles/finalizers*MediumNamespaceAdmin NamespaceWideAccess WildcardPermission
Role edp-codebase-operator*/adminconsoles/status*MediumNamespaceAdmin NamespaceWideAccess WildcardPermission
Role edp-codebase-operator*/cdstagedeployments*MediumNamespaceAdmin NamespaceWideAccess WildcardPermission
Role edp-codebase-operator*/cdstagedeployments/finalizers*MediumNamespaceAdmin NamespaceWideAccess WildcardPermission
Role edp-codebase-operator*/cdstagedeployments/status*MediumNamespaceAdmin NamespaceWideAccess WildcardPermission
Role edp-codebase-operator*/cdstagejenkinsdeployments*MediumNamespaceAdmin NamespaceWideAccess WildcardPermission
Role edp-codebase-operator*/cdstagejenkinsdeployments/finalizers*MediumNamespaceAdmin NamespaceWideAccess WildcardPermission
Role edp-codebase-operator*/cdstagejenkinsdeployments/status*MediumNamespaceAdmin NamespaceWideAccess WildcardPermission
Role edp-codebase-operator*/codebasebranches*MediumNamespaceAdmin NamespaceWideAccess WildcardPermission
Role edp-codebase-operator*/codebasebranches/finalizers*MediumNamespaceAdmin NamespaceWideAccess WildcardPermission
Role edp-codebase-operator*/codebasebranches/status*MediumNamespaceAdmin NamespaceWideAccess WildcardPermission
Role edp-codebase-operator*/codebaseimagestreams*MediumNamespaceAdmin NamespaceWideAccess WildcardPermission
Role edp-codebase-operator*/codebaseimagestreams/finalizers*MediumNamespaceAdmin NamespaceWideAccess WildcardPermission
Role edp-codebase-operator*/codebaseimagestreams/status*MediumNamespaceAdmin NamespaceWideAccess WildcardPermission
Role edp-codebase-operator*/codebases*MediumNamespaceAdmin NamespaceWideAccess WildcardPermission
Role edp-codebase-operator*/codebases/finalizers*MediumNamespaceAdmin NamespaceWideAccess WildcardPermission
Role edp-codebase-operator*/codebases/status*MediumNamespaceAdmin NamespaceWideAccess WildcardPermission
Role edp-codebase-operator*/edpcomponents*MediumNamespaceAdmin NamespaceWideAccess WildcardPermission
Role edp-codebase-operator*/edpcomponents/finalizers*MediumNamespaceAdmin NamespaceWideAccess WildcardPermission
Role edp-codebase-operator*/edpcomponents/status*MediumNamespaceAdmin NamespaceWideAccess WildcardPermission
Role edp-codebase-operator*/gitservers*MediumNamespaceAdmin NamespaceWideAccess WildcardPermission
Role edp-codebase-operator*/gitservers/finalizers*MediumNamespaceAdmin NamespaceWideAccess WildcardPermission
Role edp-codebase-operator*/gitservers/status*MediumNamespaceAdmin NamespaceWideAccess WildcardPermission
Role edp-codebase-operator*/jenkins*MediumNamespaceAdmin NamespaceWideAccess WildcardPermission
Role edp-codebase-operator*/jenkins/finalizers*MediumNamespaceAdmin NamespaceWideAccess WildcardPermission
Role edp-codebase-operator*/jenkins/status*MediumNamespaceAdmin NamespaceWideAccess WildcardPermission
Role edp-codebase-operator*/jenkinses*MediumNamespaceAdmin NamespaceWideAccess WildcardPermission
Role edp-codebase-operator*/jenkinses/finalizers*MediumNamespaceAdmin NamespaceWideAccess WildcardPermission
Role edp-codebase-operator*/jenkinses/status*MediumNamespaceAdmin NamespaceWideAccess WildcardPermission
Role edp-codebase-operator*/jenkinsfolders*MediumNamespaceAdmin NamespaceWideAccess WildcardPermission
Role edp-codebase-operator*/jenkinsfolders/finalizers*MediumNamespaceAdmin NamespaceWideAccess WildcardPermission
Role edp-codebase-operator*/jenkinsfolders/status*MediumNamespaceAdmin NamespaceWideAccess WildcardPermission
Role edp-codebase-operator*/jenkinsjobs*MediumNamespaceAdmin NamespaceWideAccess WildcardPermission
Role edp-codebase-operator*/jenkinsjobs/finalizers*MediumNamespaceAdmin NamespaceWideAccess WildcardPermission
Role edp-codebase-operator*/jenkinsjobs/status*MediumNamespaceAdmin NamespaceWideAccess WildcardPermission
Role edp-codebase-operator*/jenkinsscripts*MediumNamespaceAdmin NamespaceWideAccess WildcardPermission
Role edp-codebase-operator*/jenkinsscripts/finalizers*MediumNamespaceAdmin NamespaceWideAccess WildcardPermission
Role edp-codebase-operator*/jenkinsscripts/status*MediumNamespaceAdmin NamespaceWideAccess WildcardPermission
Role edp-codebase-operator*/jenkinsserviceaccounts*MediumNamespaceAdmin NamespaceWideAccess WildcardPermission
Role edp-codebase-operator*/jenkinsserviceaccounts/finalizers*MediumNamespaceAdmin NamespaceWideAccess WildcardPermission
Role edp-codebase-operator*/jenkinsserviceaccounts/status*MediumNamespaceAdmin NamespaceWideAccess WildcardPermission
Role edp-codebase-operator*/jirafixversions*MediumNamespaceAdmin NamespaceWideAccess WildcardPermission
Role edp-codebase-operator*/jirafixversions/status*MediumNamespaceAdmin NamespaceWideAccess WildcardPermission
Role edp-codebase-operator*/jiraissuemetadatas*MediumNamespaceAdmin NamespaceWideAccess WildcardPermission
Role edp-codebase-operator*/jiraissuemetadatas/finalizers*MediumNamespaceAdmin NamespaceWideAccess WildcardPermission
Role edp-codebase-operator*/jiraissuemetadatas/status*MediumNamespaceAdmin NamespaceWideAccess WildcardPermission
Role edp-codebase-operator*/jiraservers*MediumNamespaceAdmin NamespaceWideAccess WildcardPermission
Role edp-codebase-operator*/jiraservers/finalizers*MediumNamespaceAdmin NamespaceWideAccess WildcardPermission
Role edp-codebase-operator*/jiraservers/status*MediumNamespaceAdmin NamespaceWideAccess WildcardPermission
Role edp-codebase-operator*/perfdatasourcegitlabs*MediumNamespaceAdmin NamespaceWideAccess WildcardPermission
Role edp-codebase-operator*/perfdatasourcegitlabs/finalizers*MediumNamespaceAdmin NamespaceWideAccess WildcardPermission
Role edp-codebase-operator*/perfdatasourcegitlabs/status*MediumNamespaceAdmin NamespaceWideAccess WildcardPermission
Role edp-codebase-operator*/perfdatasourcejenkinses*MediumNamespaceAdmin NamespaceWideAccess WildcardPermission
Role edp-codebase-operator*/perfdatasourcejenkinses/finalizers*MediumNamespaceAdmin NamespaceWideAccess WildcardPermission
Role edp-codebase-operator*/perfdatasourcejenkinses/status*MediumNamespaceAdmin NamespaceWideAccess WildcardPermission
Role edp-codebase-operator*/perfdatasourcesonars*MediumNamespaceAdmin NamespaceWideAccess WildcardPermission
Role edp-codebase-operator*/perfdatasourcesonars/finalizers*MediumNamespaceAdmin NamespaceWideAccess WildcardPermission
Role edp-codebase-operator*/perfdatasourcesonars/status*MediumNamespaceAdmin NamespaceWideAccess WildcardPermission
Role edp-codebase-operator*/stages*MediumNamespaceAdmin NamespaceWideAccess WildcardPermission
Role edp-codebase-operator*/stages/finalizers*MediumNamespaceAdmin NamespaceWideAccess WildcardPermission
Role edp-codebase-operator*/stages/status*MediumNamespaceAdmin NamespaceWideAccess WildcardPermission
Role edp-codebase-operatorargoproj.io/applicationsget · list · patch · update · watchLow
Role edp-codebase-operatorcore/eventscreate · patchLow
Role edp-codebase-operatornetworking.k8s.io/ingressesget · list · watchLow
ClusterRole edp-codebase-operator-defaultadmissionregistration.k8s.io/validatingwebhookconfigurationsget · patch · updateLow
Role edp-codebase-operatorcore/secrets (restricted to: edp-codebase-operator-webhook-certs)create · get · patch · updateLowResourceNameRestricted

⚠️ Potential Abuse (5)

The following security risks were found based on the above permissions:

📦 Workloads (1)

KindNameContainerImage
Deploymentcodebase-operatorcodebase-operatorepamedp/codebase-operator:2.19.0