Description

A Helm chart for KubeRocketCI Codebase Operator

Overview

IdentityNamespaceAutomountSecretsPermissionsWorkloadsRisk
edp-codebase-operatordefault371Critical

Numbers in the last two columns indicate how many bindings or workloads involve each ServiceAccount.


Identities

🤖 edp-codebase-operator

Namespace: default  |  Automount:

🔑 Permissions (37)

RoleResourceVerbsRiskTags
Role edp-codebase-operatorcoordination.k8s.io/leasescreate · delete · get · list · patch · update · watchCriticalControlPlaneDisruption CriticalNamespace DenialOfService Tampering
Role edp-codebase-operatorcore/secretscreate · get · list · patch · update · watchCriticalCredentialAccess DataExposure InformationDisclosure SecretAccess
Role edp-codebase-operator*/configmaps*HighConfigMapAccess DataExposure InformationDisclosure NamespaceAdmin NamespaceWideAccess (+3 more)
Role edp-codebase-operator*/cdpipelines*MediumNamespaceAdmin NamespaceWideAccess WildcardPermission
Role edp-codebase-operator*/cdstagedeployments*MediumNamespaceAdmin NamespaceWideAccess WildcardPermission
Role edp-codebase-operator*/cdstagedeployments/finalizers*MediumNamespaceAdmin NamespaceWideAccess WildcardPermission
Role edp-codebase-operator*/cdstagedeployments/status*MediumNamespaceAdmin NamespaceWideAccess WildcardPermission
Role edp-codebase-operator*/codebasebranches*MediumNamespaceAdmin NamespaceWideAccess WildcardPermission
Role edp-codebase-operator*/codebasebranches/finalizers*MediumNamespaceAdmin NamespaceWideAccess WildcardPermission
Role edp-codebase-operator*/codebasebranches/status*MediumNamespaceAdmin NamespaceWideAccess WildcardPermission
Role edp-codebase-operator*/codebaseimagestreams*MediumNamespaceAdmin NamespaceWideAccess WildcardPermission
Role edp-codebase-operator*/codebaseimagestreams/finalizers*MediumNamespaceAdmin NamespaceWideAccess WildcardPermission
Role edp-codebase-operator*/codebaseimagestreams/status*MediumNamespaceAdmin NamespaceWideAccess WildcardPermission
Role edp-codebase-operator*/codebases*MediumNamespaceAdmin NamespaceWideAccess WildcardPermission
Role edp-codebase-operator*/codebases/finalizers*MediumNamespaceAdmin NamespaceWideAccess WildcardPermission
Role edp-codebase-operator*/codebases/status*MediumNamespaceAdmin NamespaceWideAccess WildcardPermission
Role edp-codebase-operator*/gitservers*MediumNamespaceAdmin NamespaceWideAccess WildcardPermission
Role edp-codebase-operator*/gitservers/finalizers*MediumNamespaceAdmin NamespaceWideAccess WildcardPermission
Role edp-codebase-operator*/gitservers/status*MediumNamespaceAdmin NamespaceWideAccess WildcardPermission
Role edp-codebase-operator*/jirafixversions*MediumNamespaceAdmin NamespaceWideAccess WildcardPermission
Role edp-codebase-operator*/jirafixversions/status*MediumNamespaceAdmin NamespaceWideAccess WildcardPermission
Role edp-codebase-operator*/jiraissuemetadatas*MediumNamespaceAdmin NamespaceWideAccess WildcardPermission
Role edp-codebase-operator*/jiraissuemetadatas/finalizers*MediumNamespaceAdmin NamespaceWideAccess WildcardPermission
Role edp-codebase-operator*/jiraissuemetadatas/status*MediumNamespaceAdmin NamespaceWideAccess WildcardPermission
Role edp-codebase-operator*/jiraservers*MediumNamespaceAdmin NamespaceWideAccess WildcardPermission
Role edp-codebase-operator*/jiraservers/finalizers*MediumNamespaceAdmin NamespaceWideAccess WildcardPermission
Role edp-codebase-operator*/jiraservers/status*MediumNamespaceAdmin NamespaceWideAccess WildcardPermission
Role edp-codebase-operator*/quicklinks*MediumNamespaceAdmin NamespaceWideAccess WildcardPermission
Role edp-codebase-operator*/stages*MediumNamespaceAdmin NamespaceWideAccess WildcardPermission
Role edp-codebase-operator*/stages/finalizers*MediumNamespaceAdmin NamespaceWideAccess WildcardPermission
Role edp-codebase-operator*/stages/status*MediumNamespaceAdmin NamespaceWideAccess WildcardPermission
Role edp-codebase-operatorargoproj.io/applicationsget · list · patch · update · watchLow
Role edp-codebase-operatorcore/eventscreate · patchLow
Role edp-codebase-operatornetworking.k8s.io/ingressescreate · get · list · watchLow
Role edp-codebase-operatortekton.dev/pipelinerunscreate · get · list · patch · update · watchLow
Role edp-codebase-operatortriggers.tekton.dev/triggertemplatesget · list · watchLow
ClusterRole edp-codebase-operator-defaultadmissionregistration.k8s.io/validatingwebhookconfigurationsget · patch · updateLow

⚠️ Potential Abuse (6)

The following security risks were found based on the above permissions:

📦 Workloads (1)

KindNameContainerImage
Deploymentcodebase-operatorcodebase-operatorepamedp/codebase-operator:2.27.2