Description

A Helm chart for EDP Install

Overview

IdentityNamespaceAutomountSecretsPermissionsWorkloadsRisk
edp-cd-pipeline-operatordefault321Critical
edp-reconcilerstub-namespace471High
gitlab-cistub-namespace140High
edp-admin-consoledefault161Medium
edp-admin-console-operatordefault231Medium
edp-jenkins-operatordefault651Medium
jenkinsdefault201Medium
edp-codebase-operatordefault01
edp-dbstub-namespace01
edp-gerrit-operatordefault01
edp-kanikostub-namespace00
edp-keycloak-operatordefault01
edp-nexus-operatordefault01
edp-perf-operatordefault01
edp-sonar-operatordefault01
gerritdefault01
nexusdefault01
sonardefault02

Numbers in the last two columns indicate how many bindings or workloads involve each ServiceAccount.


Identities

🤖 edp-cd-pipeline-operator

Namespace: default  |  Automount:

🔑 Permissions (32)

RoleResourceVerbsRiskTags
ClusterRole edp-cd-pipeline-operator-stub-namespace*/configmaps*CriticalClusterWideAccess ConfigMapAccess DataExposure InformationDisclosure PotentialPrivilegeEscalation (+2 more)
ClusterRole edp-cd-pipeline-operator-stub-namespace*/cdpipelines*HighClusterWideAccess WildcardPermission
ClusterRole edp-cd-pipeline-operator-stub-namespace*/cdpipelines/finalizers*HighClusterWideAccess WildcardPermission
ClusterRole edp-cd-pipeline-operator-stub-namespace*/cdpipelines/status*HighClusterWideAccess WildcardPermission
ClusterRole edp-cd-pipeline-operator-stub-namespace*/codebasebranches*HighClusterWideAccess WildcardPermission
ClusterRole edp-cd-pipeline-operator-stub-namespace*/codebasebranches/finalizers*HighClusterWideAccess WildcardPermission
ClusterRole edp-cd-pipeline-operator-stub-namespace*/codebasebranches/status*HighClusterWideAccess WildcardPermission
ClusterRole edp-cd-pipeline-operator-stub-namespace*/codebaseimagestreams*HighClusterWideAccess WildcardPermission
ClusterRole edp-cd-pipeline-operator-stub-namespace*/codebaseimagestreams/finalizers*HighClusterWideAccess WildcardPermission
ClusterRole edp-cd-pipeline-operator-stub-namespace*/codebaseimagestreams/status*HighClusterWideAccess WildcardPermission
ClusterRole edp-cd-pipeline-operator-stub-namespace*/codebases*HighClusterWideAccess WildcardPermission
ClusterRole edp-cd-pipeline-operator-stub-namespace*/codebases/finalizers*HighClusterWideAccess WildcardPermission
ClusterRole edp-cd-pipeline-operator-stub-namespace*/codebases/status*HighClusterWideAccess WildcardPermission
ClusterRole edp-cd-pipeline-operator-stub-namespace*/deploymentconfigsget · listHighClusterWideAccess WildcardPermission
ClusterRole edp-cd-pipeline-operator-stub-namespace*/edpcomponents*HighClusterWideAccess WildcardPermission
ClusterRole edp-cd-pipeline-operator-stub-namespace*/edpcomponents/finalizers*HighClusterWideAccess WildcardPermission
ClusterRole edp-cd-pipeline-operator-stub-namespace*/edpcomponents/status*HighClusterWideAccess WildcardPermission
ClusterRole edp-cd-pipeline-operator-stub-namespace*/gitservers*HighClusterWideAccess WildcardPermission
ClusterRole edp-cd-pipeline-operator-stub-namespace*/gitservers/finalizers*HighClusterWideAccess WildcardPermission
ClusterRole edp-cd-pipeline-operator-stub-namespace*/gitservers/status*HighClusterWideAccess WildcardPermission
ClusterRole edp-cd-pipeline-operator-stub-namespace*/jenkinsfolders*HighClusterWideAccess WildcardPermission
ClusterRole edp-cd-pipeline-operator-stub-namespace*/jenkinsfolders/finalizers*HighClusterWideAccess WildcardPermission
ClusterRole edp-cd-pipeline-operator-stub-namespace*/jenkinsfolders/status*HighClusterWideAccess WildcardPermission
ClusterRole edp-cd-pipeline-operator-stub-namespace*/jenkinsjobs*HighClusterWideAccess WildcardPermission
ClusterRole edp-cd-pipeline-operator-stub-namespace*/jenkinsjobs/finalizers*HighClusterWideAccess WildcardPermission
ClusterRole edp-cd-pipeline-operator-stub-namespace*/jenkinsjobs/status*HighClusterWideAccess WildcardPermission
ClusterRole edp-cd-pipeline-operator-stub-namespace*/stages*HighClusterWideAccess WildcardPermission
ClusterRole edp-cd-pipeline-operator-stub-namespace*/stages/finalizers*HighClusterWideAccess WildcardPermission
ClusterRole edp-cd-pipeline-operator-stub-namespace*/stages/status*HighClusterWideAccess WildcardPermission
ClusterRole edp-cd-pipeline-operator-stub-namespace*/events*MediumClusterWideAccess InformationDisclosure OperationalData Reconnaissance WildcardPermission
ClusterRole edp-cd-pipeline-operator-stub-namespaceapps/deploymentsget · listLow
ClusterRole edp-cd-pipeline-operator-stub-namespacecoordination.k8s.io/leasescreate · get · list · updateLow

⚠️ Potential Abuse (7)

The following security risks were found based on the above permissions:

📦 Workloads (1)

KindNameContainerImage
Deploymentcd-pipeline-operatorcd-pipeline-operatorepamedp/cd-pipeline-operator:2.11.0

🤖 edp-reconciler

Namespace: stub-namespace  |  Automount:

🔑 Permissions (47)

RoleResourceVerbsRiskTags
Role edp-reconciler*/services*HighDenialOfService NamespaceAdmin NamespaceWideAccess NetworkManipulation ServiceExposure (+2 more)
Role edp-reconciler*/cdpipelines*MediumNamespaceAdmin NamespaceWideAccess WildcardPermission
Role edp-reconciler*/cdpipelines/finalizers*MediumNamespaceAdmin NamespaceWideAccess WildcardPermission
Role edp-reconciler*/cdpipelines/status*MediumNamespaceAdmin NamespaceWideAccess WildcardPermission
Role edp-reconciler*/codebasebranches*MediumNamespaceAdmin NamespaceWideAccess WildcardPermission
Role edp-reconciler*/codebasebranches/finalizers*MediumNamespaceAdmin NamespaceWideAccess WildcardPermission
Role edp-reconciler*/codebasebranches/status*MediumNamespaceAdmin NamespaceWideAccess WildcardPermission
Role edp-reconciler*/codebaseimagestreams*MediumNamespaceAdmin NamespaceWideAccess WildcardPermission
Role edp-reconciler*/codebaseimagestreams/finalizers*MediumNamespaceAdmin NamespaceWideAccess WildcardPermission
Role edp-reconciler*/codebaseimagestreams/status*MediumNamespaceAdmin NamespaceWideAccess WildcardPermission
Role edp-reconciler*/codebases*MediumNamespaceAdmin NamespaceWideAccess WildcardPermission
Role edp-reconciler*/codebases/finalizers*MediumNamespaceAdmin NamespaceWideAccess WildcardPermission
Role edp-reconciler*/codebases/status*MediumNamespaceAdmin NamespaceWideAccess WildcardPermission
Role edp-reconciler*/edpcomponents*MediumNamespaceAdmin NamespaceWideAccess WildcardPermission
Role edp-reconciler*/events*MediumNamespaceAdmin NamespaceWideAccess WildcardPermission
Role edp-reconciler*/gitservers*MediumNamespaceAdmin NamespaceWideAccess WildcardPermission
Role edp-reconciler*/gitservers/finalizers*MediumNamespaceAdmin NamespaceWideAccess WildcardPermission
Role edp-reconciler*/gitservers/status*MediumNamespaceAdmin NamespaceWideAccess WildcardPermission
Role edp-reconciler*/jenkins*MediumNamespaceAdmin NamespaceWideAccess WildcardPermission
Role edp-reconciler*/jenkins/finalizers*MediumNamespaceAdmin NamespaceWideAccess WildcardPermission
Role edp-reconciler*/jenkins/status*MediumNamespaceAdmin NamespaceWideAccess WildcardPermission
Role edp-reconciler*/jenkinses*MediumNamespaceAdmin NamespaceWideAccess WildcardPermission
Role edp-reconciler*/jenkinses/finalizers*MediumNamespaceAdmin NamespaceWideAccess WildcardPermission
Role edp-reconciler*/jenkinses/status*MediumNamespaceAdmin NamespaceWideAccess WildcardPermission
Role edp-reconciler*/jenkinsjobs*MediumNamespaceAdmin NamespaceWideAccess WildcardPermission
Role edp-reconciler*/jenkinsjobs/finalizers*MediumNamespaceAdmin NamespaceWideAccess WildcardPermission
Role edp-reconciler*/jenkinsjobs/status*MediumNamespaceAdmin NamespaceWideAccess WildcardPermission
Role edp-reconciler*/jenkinsscripts*MediumNamespaceAdmin NamespaceWideAccess WildcardPermission
Role edp-reconciler*/jenkinsserviceaccounts*MediumNamespaceAdmin NamespaceWideAccess WildcardPermission
Role edp-reconciler*/jenkinsserviceaccounts/finalizers*MediumNamespaceAdmin NamespaceWideAccess WildcardPermission
Role edp-reconciler*/jenkinsserviceaccounts/status*MediumNamespaceAdmin NamespaceWideAccess WildcardPermission
Role edp-reconciler*/jiraservers*MediumNamespaceAdmin NamespaceWideAccess WildcardPermission
Role edp-reconciler*/jiraservers/finalizers*MediumNamespaceAdmin NamespaceWideAccess WildcardPermission
Role edp-reconciler*/jiraservers/status*MediumNamespaceAdmin NamespaceWideAccess WildcardPermission
Role edp-reconciler*/perfdatasourcejenkinses*MediumNamespaceAdmin NamespaceWideAccess WildcardPermission
Role edp-reconciler*/perfdatasourcejenkinses/finalizers*MediumNamespaceAdmin NamespaceWideAccess WildcardPermission
Role edp-reconciler*/perfdatasourcejenkinses/status*MediumNamespaceAdmin NamespaceWideAccess WildcardPermission
Role edp-reconciler*/perfdatasourcesonars*MediumNamespaceAdmin NamespaceWideAccess WildcardPermission
Role edp-reconciler*/perfdatasourcesonars/finalizers*MediumNamespaceAdmin NamespaceWideAccess WildcardPermission
Role edp-reconciler*/perfdatasourcesonars/status*MediumNamespaceAdmin NamespaceWideAccess WildcardPermission
Role edp-reconciler*/perfservers*MediumNamespaceAdmin NamespaceWideAccess WildcardPermission
Role edp-reconciler*/perfservers/finalizers*MediumNamespaceAdmin NamespaceWideAccess WildcardPermission
Role edp-reconciler*/perfservers/status*MediumNamespaceAdmin NamespaceWideAccess WildcardPermission
Role edp-reconciler*/stages*MediumNamespaceAdmin NamespaceWideAccess WildcardPermission
Role edp-reconciler*/stages/finalizers*MediumNamespaceAdmin NamespaceWideAccess WildcardPermission
Role edp-reconciler*/stages/status*MediumNamespaceAdmin NamespaceWideAccess WildcardPermission
Role edp-reconcilercoordination.k8s.io/leasescreate · get · list · updateLow

⚠️ Potential Abuse (3)

The following security risks were found based on the above permissions:

📦 Workloads (1)

KindNameContainerImage
Deploymentreconcilerreconcilerepamedp/reconciler:2.11.0

🤖 gitlab-ci

Namespace: stub-namespace  |  Automount:

🔑 Permissions (14)

RoleResourceVerbsRiskTags
Role gitlab-ci*/configmaps*HighConfigMapAccess DataExposure InformationDisclosure NamespaceAdmin NamespaceWideAccess (+3 more)
Role gitlab-ci*/codebasebranches*MediumNamespaceAdmin NamespaceWideAccess WildcardPermission
Role gitlab-ci*/codebasebranches/status*MediumNamespaceAdmin NamespaceWideAccess WildcardPermission
Role gitlab-ci*/codebaseimagestreams*MediumNamespaceAdmin NamespaceWideAccess WildcardPermission
Role gitlab-ci*/codebaseimagestreams/status*MediumNamespaceAdmin NamespaceWideAccess WildcardPermission
Role gitlab-ci*/gittags*MediumNamespaceAdmin NamespaceWideAccess WildcardPermission
Role gitlab-ci*/gittags/status*MediumNamespaceAdmin NamespaceWideAccess WildcardPermission
Role gitlab-ci*/imagestreamimages*MediumNamespaceAdmin NamespaceWideAccess WildcardPermission
Role gitlab-ci*/imagestreammappings*MediumNamespaceAdmin NamespaceWideAccess WildcardPermission
Role gitlab-ci*/imagestreams*MediumNamespaceAdmin NamespaceWideAccess WildcardPermission
Role gitlab-ci*/imagestreams/layers*MediumNamespaceAdmin NamespaceWideAccess WildcardPermission
Role gitlab-ci*/imagestreams/secrets*MediumNamespaceAdmin NamespaceWideAccess WildcardPermission
Role gitlab-ci*/imagestreamtags*MediumNamespaceAdmin NamespaceWideAccess WildcardPermission
Role gitlab-ci*/imagestreamtags/status*MediumNamespaceAdmin NamespaceWideAccess WildcardPermission

⚠️ Potential Abuse (3)

The following security risks were found based on the above permissions:

📦 Workloads (0)

No workloads use this ServiceAccount.


🤖 edp-jenkins-operator

Namespace: default  |  Automount:

🔑 Permissions (65)

RoleResourceVerbsRiskTags
Role edp-jenkins-operator-stub-namespace*/adminconsoles*MediumNamespaceAdmin NamespaceWideAccess WildcardPermission
Role edp-jenkins-operator-stub-namespace*/cdpipelines*MediumNamespaceAdmin NamespaceWideAccess WildcardPermission
Role edp-jenkins-operator-stub-namespace*/cdpipelines/finalizers*MediumNamespaceAdmin NamespaceWideAccess WildcardPermission
Role edp-jenkins-operator-stub-namespace*/cdpipelines/status*MediumNamespaceAdmin NamespaceWideAccess WildcardPermission
Role edp-jenkins-operator-stub-namespace*/cdstagedeployments*MediumNamespaceAdmin NamespaceWideAccess WildcardPermission
Role edp-jenkins-operator-stub-namespace*/cdstagedeployments/finalizers*MediumNamespaceAdmin NamespaceWideAccess WildcardPermission
Role edp-jenkins-operator-stub-namespace*/cdstagedeployments/status*MediumNamespaceAdmin NamespaceWideAccess WildcardPermission
Role edp-jenkins-operator-stub-namespace*/cdstagejenkinsdeployments*MediumNamespaceAdmin NamespaceWideAccess WildcardPermission
Role edp-jenkins-operator-stub-namespace*/cdstagejenkinsdeployments/finalizers*MediumNamespaceAdmin NamespaceWideAccess WildcardPermission
Role edp-jenkins-operator-stub-namespace*/cdstagejenkinsdeployments/status*MediumNamespaceAdmin NamespaceWideAccess WildcardPermission
Role edp-jenkins-operator-stub-namespace*/codebasebranches*MediumNamespaceAdmin NamespaceWideAccess WildcardPermission
Role edp-jenkins-operator-stub-namespace*/codebaseimagestreams*MediumNamespaceAdmin NamespaceWideAccess WildcardPermission
Role edp-jenkins-operator-stub-namespace*/codebases*MediumNamespaceAdmin NamespaceWideAccess WildcardPermission
Role edp-jenkins-operator-stub-namespace*/codebases/finalizers*MediumNamespaceAdmin NamespaceWideAccess WildcardPermission
Role edp-jenkins-operator-stub-namespace*/edpcomponents*MediumNamespaceAdmin NamespaceWideAccess WildcardPermission
Role edp-jenkins-operator-stub-namespace*/events*MediumNamespaceAdmin NamespaceWideAccess WildcardPermission
Role edp-jenkins-operator-stub-namespace*/gerrits*MediumNamespaceAdmin NamespaceWideAccess WildcardPermission
Role edp-jenkins-operator-stub-namespace*/gitservers*MediumNamespaceAdmin NamespaceWideAccess WildcardPermission
Role edp-jenkins-operator-stub-namespace*/jenkins*MediumNamespaceAdmin NamespaceWideAccess WildcardPermission
Role edp-jenkins-operator-stub-namespace*/jenkins/finalizers*MediumNamespaceAdmin NamespaceWideAccess WildcardPermission
Role edp-jenkins-operator-stub-namespace*/jenkins/status*MediumNamespaceAdmin NamespaceWideAccess WildcardPermission
Role edp-jenkins-operator-stub-namespace*/jenkinsagents*MediumNamespaceAdmin NamespaceWideAccess WildcardPermission
Role edp-jenkins-operator-stub-namespace*/jenkinsagents/finalizers*MediumNamespaceAdmin NamespaceWideAccess WildcardPermission
Role edp-jenkins-operator-stub-namespace*/jenkinsagents/status*MediumNamespaceAdmin NamespaceWideAccess WildcardPermission
Role edp-jenkins-operator-stub-namespace*/jenkinsauthorizationrolemappings*MediumNamespaceAdmin NamespaceWideAccess WildcardPermission
Role edp-jenkins-operator-stub-namespace*/jenkinsauthorizationrolemappings/finalizers*MediumNamespaceAdmin NamespaceWideAccess WildcardPermission
Role edp-jenkins-operator-stub-namespace*/jenkinsauthorizationrolemappings/status*MediumNamespaceAdmin NamespaceWideAccess WildcardPermission
Role edp-jenkins-operator-stub-namespace*/jenkinsauthorizationroles*MediumNamespaceAdmin NamespaceWideAccess WildcardPermission
Role edp-jenkins-operator-stub-namespace*/jenkinsauthorizationroles/finalizers*MediumNamespaceAdmin NamespaceWideAccess WildcardPermission
Role edp-jenkins-operator-stub-namespace*/jenkinsauthorizationroles/status*MediumNamespaceAdmin NamespaceWideAccess WildcardPermission
Role edp-jenkins-operator-stub-namespace*/jenkinses*MediumNamespaceAdmin NamespaceWideAccess WildcardPermission
Role edp-jenkins-operator-stub-namespace*/jenkinses/finalizers*MediumNamespaceAdmin NamespaceWideAccess WildcardPermission
Role edp-jenkins-operator-stub-namespace*/jenkinses/status*MediumNamespaceAdmin NamespaceWideAccess WildcardPermission
Role edp-jenkins-operator-stub-namespace*/jenkinsfolders*MediumNamespaceAdmin NamespaceWideAccess WildcardPermission
Role edp-jenkins-operator-stub-namespace*/jenkinsfolders/finalizers*MediumNamespaceAdmin NamespaceWideAccess WildcardPermission
Role edp-jenkins-operator-stub-namespace*/jenkinsfolders/status*MediumNamespaceAdmin NamespaceWideAccess WildcardPermission
Role edp-jenkins-operator-stub-namespace*/jenkinsjobbuildruns*MediumNamespaceAdmin NamespaceWideAccess WildcardPermission
Role edp-jenkins-operator-stub-namespace*/jenkinsjobbuildruns/status*MediumNamespaceAdmin NamespaceWideAccess WildcardPermission
Role edp-jenkins-operator-stub-namespace*/jenkinsjobs*MediumNamespaceAdmin NamespaceWideAccess WildcardPermission
Role edp-jenkins-operator-stub-namespace*/jenkinsjobs/finalizers*MediumNamespaceAdmin NamespaceWideAccess WildcardPermission
Role edp-jenkins-operator-stub-namespace*/jenkinsjobs/status*MediumNamespaceAdmin NamespaceWideAccess WildcardPermission
Role edp-jenkins-operator-stub-namespace*/jenkinsscripts*MediumNamespaceAdmin NamespaceWideAccess WildcardPermission
Role edp-jenkins-operator-stub-namespace*/jenkinsscripts/finalizers*MediumNamespaceAdmin NamespaceWideAccess WildcardPermission
Role edp-jenkins-operator-stub-namespace*/jenkinsscripts/status*MediumNamespaceAdmin NamespaceWideAccess WildcardPermission
Role edp-jenkins-operator-stub-namespace*/jenkinsserviceaccounts*MediumNamespaceAdmin NamespaceWideAccess WildcardPermission
Role edp-jenkins-operator-stub-namespace*/jenkinsserviceaccounts/finalizers*MediumNamespaceAdmin NamespaceWideAccess WildcardPermission
Role edp-jenkins-operator-stub-namespace*/jenkinsserviceaccounts/status*MediumNamespaceAdmin NamespaceWideAccess WildcardPermission
Role edp-jenkins-operator-stub-namespace*/jenkinssharedlibraries*MediumNamespaceAdmin NamespaceWideAccess WildcardPermission
Role edp-jenkins-operator-stub-namespace*/jenkinssharedlibraries/finalizers*MediumNamespaceAdmin NamespaceWideAccess WildcardPermission
Role edp-jenkins-operator-stub-namespace*/jenkinssharedlibraries/status*MediumNamespaceAdmin NamespaceWideAccess WildcardPermission
Role edp-jenkins-operator-stub-namespace*/jirafixversions*MediumNamespaceAdmin NamespaceWideAccess WildcardPermission
Role edp-jenkins-operator-stub-namespace*/keycloakclients*MediumNamespaceAdmin NamespaceWideAccess WildcardPermission
Role edp-jenkins-operator-stub-namespace*/keycloakclients/finalizers*MediumNamespaceAdmin NamespaceWideAccess WildcardPermission
Role edp-jenkins-operator-stub-namespace*/keycloakclients/status*MediumNamespaceAdmin NamespaceWideAccess WildcardPermission
Role edp-jenkins-operator-stub-namespace*/keycloakrealms*MediumNamespaceAdmin NamespaceWideAccess WildcardPermission
Role edp-jenkins-operator-stub-namespace*/keycloakrealms/status*MediumNamespaceAdmin NamespaceWideAccess WildcardPermission
Role edp-jenkins-operator-stub-namespace*/keycloaks*MediumNamespaceAdmin NamespaceWideAccess WildcardPermission
Role edp-jenkins-operator-stub-namespace*/keycloaks/status*MediumNamespaceAdmin NamespaceWideAccess WildcardPermission
Role edp-jenkins-operator-stub-namespace*/nexuses*MediumNamespaceAdmin NamespaceWideAccess WildcardPermission
Role edp-jenkins-operator-stub-namespace*/podsecuritypoliciesget · list · updateMediumNamespaceAdmin NamespaceWideAccess WildcardPermission
Role edp-jenkins-operator-stub-namespace*/projectrequests*MediumNamespaceAdmin NamespaceWideAccess WildcardPermission
Role edp-jenkins-operator-stub-namespace*/stages*MediumNamespaceAdmin NamespaceWideAccess WildcardPermission
Role edp-jenkins-operator-stub-namespace*/stages/finalizers*MediumNamespaceAdmin NamespaceWideAccess WildcardPermission
Role edp-jenkins-operator-stub-namespace*/stages/status*MediumNamespaceAdmin NamespaceWideAccess WildcardPermission
Role edp-jenkins-operator-stub-namespacecoordination.k8s.io/leasescreate · get · list · updateLow

⚠️ Potential Abuse (2)

The following security risks were found based on the above permissions:

📦 Workloads (1)

KindNameContainerImage
Deploymentjenkins-operatorjenkins-operatorepamedp/jenkins-operator:2.11.1

🤖 edp-admin-console-operator

Namespace: default  |  Automount:

🔑 Permissions (23)

RoleResourceVerbsRiskTags
Role edp-admin-console-operator-stub-namespace*/adminconsoles*MediumNamespaceAdmin NamespaceWideAccess WildcardPermission
Role edp-admin-console-operator-stub-namespace*/adminconsoles/finalizers*MediumNamespaceAdmin NamespaceWideAccess WildcardPermission
Role edp-admin-console-operator-stub-namespace*/adminconsoles/status*MediumNamespaceAdmin NamespaceWideAccess WildcardPermission
Role edp-admin-console-operator-stub-namespace*/cdpipelines*MediumNamespaceAdmin NamespaceWideAccess WildcardPermission
Role edp-admin-console-operator-stub-namespace*/cdpipelines/finalizers*MediumNamespaceAdmin NamespaceWideAccess WildcardPermission
Role edp-admin-console-operator-stub-namespace*/codebasebranches*MediumNamespaceAdmin NamespaceWideAccess WildcardPermission
Role edp-admin-console-operator-stub-namespace*/codebasebranches/finalizers*MediumNamespaceAdmin NamespaceWideAccess WildcardPermission
Role edp-admin-console-operator-stub-namespace*/codebases*MediumNamespaceAdmin NamespaceWideAccess WildcardPermission
Role edp-admin-console-operator-stub-namespace*/codebases/finalizers*MediumNamespaceAdmin NamespaceWideAccess WildcardPermission
Role edp-admin-console-operator-stub-namespace*/configmapsgetMediumNamespaceAdmin NamespaceWideAccess WildcardPermission
Role edp-admin-console-operator-stub-namespace*/edpcomponents*MediumNamespaceAdmin NamespaceWideAccess WildcardPermission
Role edp-admin-console-operator-stub-namespace*/events*MediumNamespaceAdmin NamespaceWideAccess WildcardPermission
Role edp-admin-console-operator-stub-namespace*/keycloakclients*MediumNamespaceAdmin NamespaceWideAccess WildcardPermission
Role edp-admin-console-operator-stub-namespace*/keycloakclients/finalizers*MediumNamespaceAdmin NamespaceWideAccess WildcardPermission
Role edp-admin-console-operator-stub-namespace*/keycloakclients/status*MediumNamespaceAdmin NamespaceWideAccess WildcardPermission
Role edp-admin-console-operator-stub-namespace*/keycloakrealms*MediumNamespaceAdmin NamespaceWideAccess WildcardPermission
Role edp-admin-console-operator-stub-namespace*/keycloakrealms/status*MediumNamespaceAdmin NamespaceWideAccess WildcardPermission
Role edp-admin-console-operator-stub-namespace*/keycloaks*MediumNamespaceAdmin NamespaceWideAccess WildcardPermission
Role edp-admin-console-operator-stub-namespace*/keycloaks/status*MediumNamespaceAdmin NamespaceWideAccess WildcardPermission
Role edp-admin-console-operator-stub-namespace*/stages*MediumNamespaceAdmin NamespaceWideAccess WildcardPermission
Role edp-admin-console-operator-stub-namespace*/stages/finalizers*MediumNamespaceAdmin NamespaceWideAccess WildcardPermission
Role edp-admin-console-operator-stub-namespacecoordination.k8s.io/leasescreate · get · list · updateLow
Role edp-admin-console-operator-stub-namespacestorage.k8s.io/storageclassesget · listLow

⚠️ Potential Abuse (2)

The following security risks were found based on the above permissions:

📦 Workloads (1)

KindNameContainerImage
Deploymentadmin-console-operatoradmin-console-operatorepamedp/admin-console-operator:2.11.0

🤖 jenkins

Namespace: default  |  Automount:

🔑 Permissions (20)

RoleResourceVerbsRiskTags
Role edp-jenkins-role*/adminconsolescreate · delete · get · list · patch · updateMediumNamespaceAdmin NamespaceWideAccess WildcardPermission
Role edp-jenkins-role*/cdpipelinescreate · delete · get · list · patch · updateMediumNamespaceAdmin NamespaceWideAccess WildcardPermission
Role edp-jenkins-role*/codebasebranchescreate · delete · get · list · patch · updateMediumNamespaceAdmin NamespaceWideAccess WildcardPermission
Role edp-jenkins-role*/codebaseimagestreamscreate · delete · get · list · patch · updateMediumNamespaceAdmin NamespaceWideAccess WildcardPermission
Role edp-jenkins-role*/codebasescreate · delete · get · list · patch · updateMediumNamespaceAdmin NamespaceWideAccess WildcardPermission
Role edp-jenkins-role*/codebases/finalizerscreate · delete · get · list · patch · updateMediumNamespaceAdmin NamespaceWideAccess WildcardPermission
Role edp-jenkins-role*/edpcomponentscreate · delete · get · list · patch · updateMediumNamespaceAdmin NamespaceWideAccess WildcardPermission
Role edp-jenkins-role*/gitserverscreate · delete · get · list · patch · updateMediumNamespaceAdmin NamespaceWideAccess WildcardPermission
Role edp-jenkins-role*/jenkinscreate · delete · get · list · patch · updateMediumNamespaceAdmin NamespaceWideAccess WildcardPermission
Role edp-jenkins-role*/jenkinsescreate · delete · get · list · patch · updateMediumNamespaceAdmin NamespaceWideAccess WildcardPermission
Role edp-jenkins-role*/jirafixversionscreate · delete · get · list · patch · updateMediumNamespaceAdmin NamespaceWideAccess WildcardPermission
Role edp-jenkins-role*/jiraissuemetadatascreate · delete · get · list · patch · updateMediumNamespaceAdmin NamespaceWideAccess WildcardPermission
Role edp-jenkins-role*/jiraissuemetadatas/finalizerscreate · delete · get · list · patch · updateMediumNamespaceAdmin NamespaceWideAccess WildcardPermission
Role edp-jenkins-role*/jiraissuemetadatas/statuscreate · delete · get · list · patch · updateMediumNamespaceAdmin NamespaceWideAccess WildcardPermission
Role edp-jenkins-role*/keycloakrealmscreate · delete · get · list · patch · updateMediumNamespaceAdmin NamespaceWideAccess WildcardPermission
Role edp-jenkins-role*/nexusescreate · delete · get · list · patch · updateMediumNamespaceAdmin NamespaceWideAccess WildcardPermission
Role edp-jenkins-role*/stagescreate · delete · get · list · patch · updateMediumNamespaceAdmin NamespaceWideAccess WildcardPermission
Role edp-jenkins-rolebuild.openshift.io/buildconfigslistLow
Role edp-jenkins-rolebuild.openshift.io/buildslistLow
Role edp-jenkins-roleimage.openshift.io/imagestreamslistLow

⚠️ Potential Abuse (2)

The following security risks were found based on the above permissions:

📦 Workloads (1)

KindNameContainerImage
Deploymentjenkinsjenkinsepamedp/edp-jenkins:2.11.0

🤖 edp-admin-console

Namespace: default  |  Automount:

🔑 Permissions (16)

RoleResourceVerbsRiskTags
Role edp-resources-admin*/cdpipelinescreate · delete · get · list · patch · updateMediumNamespaceAdmin NamespaceWideAccess WildcardPermission
Role edp-resources-admin*/cdpipelines/finalizerscreate · delete · get · list · patch · updateMediumNamespaceAdmin NamespaceWideAccess WildcardPermission
Role edp-resources-admin*/codebasebranchescreate · delete · get · list · patch · updateMediumNamespaceAdmin NamespaceWideAccess WildcardPermission
Role edp-resources-admin*/codebasebranches/finalizerscreate · delete · get · list · patch · updateMediumNamespaceAdmin NamespaceWideAccess WildcardPermission
Role edp-resources-admin*/codebaseimagestreamsget · listMediumNamespaceAdmin NamespaceWideAccess WildcardPermission
Role edp-resources-admin*/codebasescreate · delete · get · list · patch · updateMediumNamespaceAdmin NamespaceWideAccess WildcardPermission
Role edp-resources-admin*/codebases/finalizerscreate · delete · get · list · patch · updateMediumNamespaceAdmin NamespaceWideAccess WildcardPermission
Role edp-resources-admin*/edpcomponentsget · listMediumNamespaceAdmin NamespaceWideAccess WildcardPermission
Role edp-resources-admin*/gitserverslistMediumNamespaceAdmin NamespaceWideAccess WildcardPermission
Role edp-resources-admin*/jenkinsget · listMediumNamespaceAdmin NamespaceWideAccess WildcardPermission
Role edp-resources-admin*/jiraserverscreate · delete · get · list · patch · updateMediumNamespaceAdmin NamespaceWideAccess WildcardPermission
Role edp-resources-admin*/jiraservers/finalizerscreate · delete · get · list · patch · updateMediumNamespaceAdmin NamespaceWideAccess WildcardPermission
Role edp-resources-admin*/perfserverslistMediumNamespaceAdmin NamespaceWideAccess WildcardPermission
Role edp-resources-admin*/stagescreate · delete · get · list · patch · updateMediumNamespaceAdmin NamespaceWideAccess WildcardPermission
Role edp-resources-admin*/stages/finalizerscreate · delete · get · list · patch · updateMediumNamespaceAdmin NamespaceWideAccess WildcardPermission
Role edp-admin-console-stub-namespacestorage.k8s.io/storageclassesget · listLow

⚠️ Potential Abuse (2)

The following security risks were found based on the above permissions:

📦 Workloads (1)

KindNameContainerImage
Deploymentedp-admin-consoleedp-admin-consoleepamedp/edp-admin-console:2.12.0

🤖 edp-codebase-operator

Namespace: default  |  Automount:

🔑 Permissions (0)

No explicit RBAC bindings.

📦 Workloads (1)

KindNameContainerImage
Deploymentcodebase-operatorcodebase-operatorepamedp/codebase-operator:2.12.0

🤖 edp-db

Namespace: stub-namespace  |  Automount:

🔑 Permissions (0)

No explicit RBAC bindings.

📦 Workloads (1)

KindNameContainerImage
Deploymentedp-dbedp-dbpostgres:9.6

🤖 edp-gerrit-operator

Namespace: default  |  Automount:

🔑 Permissions (0)

No explicit RBAC bindings.

📦 Workloads (1)

KindNameContainerImage
Deploymentgerrit-operatorgerrit-operatorepamedp/gerrit-operator:2.11.0

🤖 edp-kaniko

Namespace: stub-namespace  |  Automount:

🔑 Permissions (0)

No explicit RBAC bindings.

📦 Workloads (0)

No workloads use this ServiceAccount.


🤖 edp-keycloak-operator

Namespace: default  |  Automount:

🔑 Permissions (0)

No explicit RBAC bindings.

📦 Workloads (1)

KindNameContainerImage
Deploymentkeycloak-operatorkeycloak-operatorepamedp/keycloak-operator:1.11.0

🤖 edp-nexus-operator

Namespace: default  |  Automount:

🔑 Permissions (0)

No explicit RBAC bindings.

📦 Workloads (1)

KindNameContainerImage
Deploymentnexus-operatornexus-operatorepamedp/nexus-operator:2.11.0

🤖 edp-perf-operator

Namespace: default  |  Automount:

🔑 Permissions (0)

No explicit RBAC bindings.

📦 Workloads (1)

KindNameContainerImage
Deploymentperf-operatorperf-operatorepamedp/perf-operator:2.11.0

🤖 edp-sonar-operator

Namespace: default  |  Automount:

🔑 Permissions (0)

No explicit RBAC bindings.

📦 Workloads (1)

KindNameContainerImage
Deploymentsonar-operatorsonar-operatorepamedp/sonar-operator:2.11.0

🤖 gerrit

Namespace: default  |  Automount:

🔑 Permissions (0)

No explicit RBAC bindings.

📦 Workloads (1)

KindNameContainerImage
Deploymentgerritgerritopenfrontier/gerrit:3.3.2

🤖 nexus

Namespace: default  |  Automount:

🔑 Permissions (0)

No explicit RBAC bindings.

📦 Workloads (1)

KindNameContainerImage
Deploymentnexusnexussonatype/nexus3:3.38.1

🤖 sonar

Namespace: default  |  Automount:

🔑 Permissions (0)

No explicit RBAC bindings.

📦 Workloads (2)

KindNameContainerImage
Deploymentsonarsonarsonarqube:8.9.8-community
Deploymentsonar-dbsonar-dbpostgres:9.6