Description

A Helm chart for EDP Install

Overview

IdentityNamespaceAutomountSecretsPermissionsWorkloadsRisk
edp-codebase-operatordefault691Critical
edp-cd-pipeline-operatordefault321High
edp-gerrit-operatordefault321Medium
edp-nexus-operatordefault211Medium
edp-tekton-dashboarddefault201Medium
tektondefault160Medium
edp-tekton-interceptordefault121Low
tekton-resource-prunerdefault21Low
edp-headlampdefault01
edp-keycloak-operatordefault01
edp-sonar-operatordefault01
gerritdefault01
nexusdefault01
nexus-proxydefault01
sonardefault02
tekton-triggers-sa-defaultdefault00

Numbers in the last two columns indicate how many bindings or workloads involve each ServiceAccount.


Identities

🤖 edp-codebase-operator

Namespace: default  |  Automount:

🔑 Permissions (69)

RoleResourceVerbsRiskTags
Role edp-codebase-operatorcoordination.k8s.io/leasescreate · delete · get · list · patch · update · watchCriticalControlPlaneDisruption CriticalNamespace DenialOfService Tampering
Role edp-codebase-operator*/configmaps*HighConfigMapAccess DataExposure InformationDisclosure NamespaceAdmin NamespaceWideAccess (+3 more)
Role edp-codebase-operator*/adminconsoles*MediumNamespaceAdmin NamespaceWideAccess WildcardPermission
Role edp-codebase-operator*/adminconsoles/finalizers*MediumNamespaceAdmin NamespaceWideAccess WildcardPermission
Role edp-codebase-operator*/adminconsoles/status*MediumNamespaceAdmin NamespaceWideAccess WildcardPermission
Role edp-codebase-operator*/cdstagedeployments*MediumNamespaceAdmin NamespaceWideAccess WildcardPermission
Role edp-codebase-operator*/cdstagedeployments/finalizers*MediumNamespaceAdmin NamespaceWideAccess WildcardPermission
Role edp-codebase-operator*/cdstagedeployments/status*MediumNamespaceAdmin NamespaceWideAccess WildcardPermission
Role edp-codebase-operator*/cdstagejenkinsdeployments*MediumNamespaceAdmin NamespaceWideAccess WildcardPermission
Role edp-codebase-operator*/cdstagejenkinsdeployments/finalizers*MediumNamespaceAdmin NamespaceWideAccess WildcardPermission
Role edp-codebase-operator*/cdstagejenkinsdeployments/status*MediumNamespaceAdmin NamespaceWideAccess WildcardPermission
Role edp-codebase-operator*/codebasebranches*MediumNamespaceAdmin NamespaceWideAccess WildcardPermission
Role edp-codebase-operator*/codebasebranches/finalizers*MediumNamespaceAdmin NamespaceWideAccess WildcardPermission
Role edp-codebase-operator*/codebasebranches/status*MediumNamespaceAdmin NamespaceWideAccess WildcardPermission
Role edp-codebase-operator*/codebaseimagestreams*MediumNamespaceAdmin NamespaceWideAccess WildcardPermission
Role edp-codebase-operator*/codebaseimagestreams/finalizers*MediumNamespaceAdmin NamespaceWideAccess WildcardPermission
Role edp-codebase-operator*/codebaseimagestreams/status*MediumNamespaceAdmin NamespaceWideAccess WildcardPermission
Role edp-codebase-operator*/codebases*MediumNamespaceAdmin NamespaceWideAccess WildcardPermission
Role edp-codebase-operator*/codebases/finalizers*MediumNamespaceAdmin NamespaceWideAccess WildcardPermission
Role edp-codebase-operator*/codebases/status*MediumNamespaceAdmin NamespaceWideAccess WildcardPermission
Role edp-codebase-operator*/edpcomponents*MediumNamespaceAdmin NamespaceWideAccess WildcardPermission
Role edp-codebase-operator*/edpcomponents/finalizers*MediumNamespaceAdmin NamespaceWideAccess WildcardPermission
Role edp-codebase-operator*/edpcomponents/status*MediumNamespaceAdmin NamespaceWideAccess WildcardPermission
Role edp-codebase-operator*/gitservers*MediumNamespaceAdmin NamespaceWideAccess WildcardPermission
Role edp-codebase-operator*/gitservers/finalizers*MediumNamespaceAdmin NamespaceWideAccess WildcardPermission
Role edp-codebase-operator*/gitservers/status*MediumNamespaceAdmin NamespaceWideAccess WildcardPermission
Role edp-codebase-operator*/jenkins*MediumNamespaceAdmin NamespaceWideAccess WildcardPermission
Role edp-codebase-operator*/jenkins/finalizers*MediumNamespaceAdmin NamespaceWideAccess WildcardPermission
Role edp-codebase-operator*/jenkins/status*MediumNamespaceAdmin NamespaceWideAccess WildcardPermission
Role edp-codebase-operator*/jenkinses*MediumNamespaceAdmin NamespaceWideAccess WildcardPermission
Role edp-codebase-operator*/jenkinses/finalizers*MediumNamespaceAdmin NamespaceWideAccess WildcardPermission
Role edp-codebase-operator*/jenkinses/status*MediumNamespaceAdmin NamespaceWideAccess WildcardPermission
Role edp-codebase-operator*/jenkinsfolders*MediumNamespaceAdmin NamespaceWideAccess WildcardPermission
Role edp-codebase-operator*/jenkinsfolders/finalizers*MediumNamespaceAdmin NamespaceWideAccess WildcardPermission
Role edp-codebase-operator*/jenkinsfolders/status*MediumNamespaceAdmin NamespaceWideAccess WildcardPermission
Role edp-codebase-operator*/jenkinsjobs*MediumNamespaceAdmin NamespaceWideAccess WildcardPermission
Role edp-codebase-operator*/jenkinsjobs/finalizers*MediumNamespaceAdmin NamespaceWideAccess WildcardPermission
Role edp-codebase-operator*/jenkinsjobs/status*MediumNamespaceAdmin NamespaceWideAccess WildcardPermission
Role edp-codebase-operator*/jenkinsscripts*MediumNamespaceAdmin NamespaceWideAccess WildcardPermission
Role edp-codebase-operator*/jenkinsscripts/finalizers*MediumNamespaceAdmin NamespaceWideAccess WildcardPermission
Role edp-codebase-operator*/jenkinsscripts/status*MediumNamespaceAdmin NamespaceWideAccess WildcardPermission
Role edp-codebase-operator*/jenkinsserviceaccounts*MediumNamespaceAdmin NamespaceWideAccess WildcardPermission
Role edp-codebase-operator*/jenkinsserviceaccounts/finalizers*MediumNamespaceAdmin NamespaceWideAccess WildcardPermission
Role edp-codebase-operator*/jenkinsserviceaccounts/status*MediumNamespaceAdmin NamespaceWideAccess WildcardPermission
Role edp-codebase-operator*/jirafixversions*MediumNamespaceAdmin NamespaceWideAccess WildcardPermission
Role edp-codebase-operator*/jirafixversions/status*MediumNamespaceAdmin NamespaceWideAccess WildcardPermission
Role edp-codebase-operator*/jiraissuemetadatas*MediumNamespaceAdmin NamespaceWideAccess WildcardPermission
Role edp-codebase-operator*/jiraissuemetadatas/finalizers*MediumNamespaceAdmin NamespaceWideAccess WildcardPermission
Role edp-codebase-operator*/jiraissuemetadatas/status*MediumNamespaceAdmin NamespaceWideAccess WildcardPermission
Role edp-codebase-operator*/jiraservers*MediumNamespaceAdmin NamespaceWideAccess WildcardPermission
Role edp-codebase-operator*/jiraservers/finalizers*MediumNamespaceAdmin NamespaceWideAccess WildcardPermission
Role edp-codebase-operator*/jiraservers/status*MediumNamespaceAdmin NamespaceWideAccess WildcardPermission
Role edp-codebase-operator*/perfdatasourcegitlabs*MediumNamespaceAdmin NamespaceWideAccess WildcardPermission
Role edp-codebase-operator*/perfdatasourcegitlabs/finalizers*MediumNamespaceAdmin NamespaceWideAccess WildcardPermission
Role edp-codebase-operator*/perfdatasourcegitlabs/status*MediumNamespaceAdmin NamespaceWideAccess WildcardPermission
Role edp-codebase-operator*/perfdatasourcejenkinses*MediumNamespaceAdmin NamespaceWideAccess WildcardPermission
Role edp-codebase-operator*/perfdatasourcejenkinses/finalizers*MediumNamespaceAdmin NamespaceWideAccess WildcardPermission
Role edp-codebase-operator*/perfdatasourcejenkinses/status*MediumNamespaceAdmin NamespaceWideAccess WildcardPermission
Role edp-codebase-operator*/perfdatasourcesonars*MediumNamespaceAdmin NamespaceWideAccess WildcardPermission
Role edp-codebase-operator*/perfdatasourcesonars/finalizers*MediumNamespaceAdmin NamespaceWideAccess WildcardPermission
Role edp-codebase-operator*/perfdatasourcesonars/status*MediumNamespaceAdmin NamespaceWideAccess WildcardPermission
Role edp-codebase-operator*/stages*MediumNamespaceAdmin NamespaceWideAccess WildcardPermission
Role edp-codebase-operator*/stages/finalizers*MediumNamespaceAdmin NamespaceWideAccess WildcardPermission
Role edp-codebase-operator*/stages/status*MediumNamespaceAdmin NamespaceWideAccess WildcardPermission
Role edp-codebase-operatorargoproj.io/applicationsget · list · patch · update · watchLow
Role edp-codebase-operatorcore/eventscreate · patchLow
Role edp-codebase-operatornetworking.k8s.io/ingressesget · list · watchLow
ClusterRole edp-codebase-operator-defaultadmissionregistration.k8s.io/validatingwebhookconfigurationsget · patch · updateLow
Role edp-codebase-operatorcore/secrets (restricted to: edp-codebase-operator-webhook-certs)create · get · patch · updateLowResourceNameRestricted

⚠️ Potential Abuse (5)

The following security risks were found based on the above permissions:

📦 Workloads (1)

KindNameContainerImage
Deploymentcodebase-operatorcodebase-operatorepamedp/codebase-operator:2.18.0

🤖 edp-cd-pipeline-operator

Namespace: default  |  Automount:

🔑 Permissions (32)

RoleResourceVerbsRiskTags
Role edp-cd-pipeline-operator*/configmaps*HighConfigMapAccess DataExposure InformationDisclosure NamespaceAdmin NamespaceWideAccess (+3 more)
ClusterRole edp-cd-pipeline-operator-defaultcore/namespacescreate · delete · get · listHighDenialOfService NamespaceLifecycle ResourceDeletion
Role edp-cd-pipeline-operator*/cdpipelines*MediumNamespaceAdmin NamespaceWideAccess WildcardPermission
Role edp-cd-pipeline-operator*/cdpipelines/finalizers*MediumNamespaceAdmin NamespaceWideAccess WildcardPermission
Role edp-cd-pipeline-operator*/cdpipelines/status*MediumNamespaceAdmin NamespaceWideAccess WildcardPermission
Role edp-cd-pipeline-operator*/codebasebranches*MediumNamespaceAdmin NamespaceWideAccess WildcardPermission
Role edp-cd-pipeline-operator*/codebasebranches/finalizers*MediumNamespaceAdmin NamespaceWideAccess WildcardPermission
Role edp-cd-pipeline-operator*/codebasebranches/status*MediumNamespaceAdmin NamespaceWideAccess WildcardPermission
Role edp-cd-pipeline-operator*/codebaseimagestreams*MediumNamespaceAdmin NamespaceWideAccess WildcardPermission
Role edp-cd-pipeline-operator*/codebaseimagestreams/finalizers*MediumNamespaceAdmin NamespaceWideAccess WildcardPermission
Role edp-cd-pipeline-operator*/codebaseimagestreams/status*MediumNamespaceAdmin NamespaceWideAccess WildcardPermission
Role edp-cd-pipeline-operator*/codebases*MediumNamespaceAdmin NamespaceWideAccess WildcardPermission
Role edp-cd-pipeline-operator*/codebases/finalizers*MediumNamespaceAdmin NamespaceWideAccess WildcardPermission
Role edp-cd-pipeline-operator*/codebases/status*MediumNamespaceAdmin NamespaceWideAccess WildcardPermission
Role edp-cd-pipeline-operator*/edpcomponents*MediumNamespaceAdmin NamespaceWideAccess WildcardPermission
Role edp-cd-pipeline-operator*/edpcomponents/finalizers*MediumNamespaceAdmin NamespaceWideAccess WildcardPermission
Role edp-cd-pipeline-operator*/edpcomponents/status*MediumNamespaceAdmin NamespaceWideAccess WildcardPermission
Role edp-cd-pipeline-operator*/events*MediumNamespaceAdmin NamespaceWideAccess WildcardPermission
Role edp-cd-pipeline-operator*/gitservers*MediumNamespaceAdmin NamespaceWideAccess WildcardPermission
Role edp-cd-pipeline-operator*/gitservers/finalizers*MediumNamespaceAdmin NamespaceWideAccess WildcardPermission
Role edp-cd-pipeline-operator*/gitservers/status*MediumNamespaceAdmin NamespaceWideAccess WildcardPermission
Role edp-cd-pipeline-operator*/jenkins*MediumNamespaceAdmin NamespaceWideAccess WildcardPermission
Role edp-cd-pipeline-operator*/jenkinsfolders*MediumNamespaceAdmin NamespaceWideAccess WildcardPermission
Role edp-cd-pipeline-operator*/jenkinsfolders/finalizers*MediumNamespaceAdmin NamespaceWideAccess WildcardPermission
Role edp-cd-pipeline-operator*/jenkinsfolders/status*MediumNamespaceAdmin NamespaceWideAccess WildcardPermission
Role edp-cd-pipeline-operator*/jenkinsjobs*MediumNamespaceAdmin NamespaceWideAccess WildcardPermission
Role edp-cd-pipeline-operator*/jenkinsjobs/finalizers*MediumNamespaceAdmin NamespaceWideAccess WildcardPermission
Role edp-cd-pipeline-operator*/jenkinsjobs/status*MediumNamespaceAdmin NamespaceWideAccess WildcardPermission
Role edp-cd-pipeline-operator*/stages*MediumNamespaceAdmin NamespaceWideAccess WildcardPermission
Role edp-cd-pipeline-operator*/stages/finalizers*MediumNamespaceAdmin NamespaceWideAccess WildcardPermission
Role edp-cd-pipeline-operator*/stages/status*MediumNamespaceAdmin NamespaceWideAccess WildcardPermission
Role edp-cd-pipeline-operatorcoordination.k8s.io/leasescreate · get · list · updateLow

⚠️ Potential Abuse (5)

The following security risks were found based on the above permissions:

📦 Workloads (1)

KindNameContainerImage
Deploymentcd-pipeline-operatorcd-pipeline-operatorepamedp/cd-pipeline-operator:2.16.0

🤖 edp-gerrit-operator

Namespace: default  |  Automount:

🔑 Permissions (32)

RoleResourceVerbsRiskTags
Role edp-gerrit-operator*/edpcomponents*MediumNamespaceAdmin NamespaceWideAccess WildcardPermission
Role edp-gerrit-operator*/events*MediumNamespaceAdmin NamespaceWideAccess WildcardPermission
Role edp-gerrit-operator*/gerritgroupmembers*MediumNamespaceAdmin NamespaceWideAccess WildcardPermission
Role edp-gerrit-operator*/gerritgroupmembers/finalizers*MediumNamespaceAdmin NamespaceWideAccess WildcardPermission
Role edp-gerrit-operator*/gerritgroupmembers/status*MediumNamespaceAdmin NamespaceWideAccess WildcardPermission
Role edp-gerrit-operator*/gerritgroups*MediumNamespaceAdmin NamespaceWideAccess WildcardPermission
Role edp-gerrit-operator*/gerritgroups/status*MediumNamespaceAdmin NamespaceWideAccess WildcardPermission
Role edp-gerrit-operator*/gerritmergerequests*MediumNamespaceAdmin NamespaceWideAccess WildcardPermission
Role edp-gerrit-operator*/gerritmergerequests/finalizers*MediumNamespaceAdmin NamespaceWideAccess WildcardPermission
Role edp-gerrit-operator*/gerritmergerequests/status*MediumNamespaceAdmin NamespaceWideAccess WildcardPermission
Role edp-gerrit-operator*/gerritprojectaccesses*MediumNamespaceAdmin NamespaceWideAccess WildcardPermission
Role edp-gerrit-operator*/gerritprojectaccesses/finalizers*MediumNamespaceAdmin NamespaceWideAccess WildcardPermission
Role edp-gerrit-operator*/gerritprojectaccesses/status*MediumNamespaceAdmin NamespaceWideAccess WildcardPermission
Role edp-gerrit-operator*/gerritprojects*MediumNamespaceAdmin NamespaceWideAccess WildcardPermission
Role edp-gerrit-operator*/gerritprojects/finalizers*MediumNamespaceAdmin NamespaceWideAccess WildcardPermission
Role edp-gerrit-operator*/gerritprojects/status*MediumNamespaceAdmin NamespaceWideAccess WildcardPermission
Role edp-gerrit-operator*/gerritreplicationconfigs*MediumNamespaceAdmin NamespaceWideAccess WildcardPermission
Role edp-gerrit-operator*/gerritreplicationconfigs/status*MediumNamespaceAdmin NamespaceWideAccess WildcardPermission
Role edp-gerrit-operator*/gerrits*MediumNamespaceAdmin NamespaceWideAccess WildcardPermission
Role edp-gerrit-operator*/gerrits/finalizers*MediumNamespaceAdmin NamespaceWideAccess WildcardPermission
Role edp-gerrit-operator*/gerrits/status*MediumNamespaceAdmin NamespaceWideAccess WildcardPermission
Role edp-gerrit-operator*/jenkinsscripts*MediumNamespaceAdmin NamespaceWideAccess WildcardPermission
Role edp-gerrit-operator*/jenkinsserviceaccounts*MediumNamespaceAdmin NamespaceWideAccess WildcardPermission
Role edp-gerrit-operator*/keycloakclients*MediumNamespaceAdmin NamespaceWideAccess WildcardPermission
Role edp-gerrit-operator*/keycloakclients/finalizers*MediumNamespaceAdmin NamespaceWideAccess WildcardPermission
Role edp-gerrit-operator*/keycloakclients/status*MediumNamespaceAdmin NamespaceWideAccess WildcardPermission
Role edp-gerrit-operator*/keycloakrealms*MediumNamespaceAdmin NamespaceWideAccess WildcardPermission
Role edp-gerrit-operator*/keycloakrealms/status*MediumNamespaceAdmin NamespaceWideAccess WildcardPermission
Role edp-gerrit-operator*/keycloaks*MediumNamespaceAdmin NamespaceWideAccess WildcardPermission
Role edp-gerrit-operator*/keycloaks/status*MediumNamespaceAdmin NamespaceWideAccess WildcardPermission
Role edp-gerrit-operatorv2.edp.epam.com/jenkinsget · list · watchLow
Role edp-gerrit-operatorcoordination.k8s.io/leasescreate · get · list · updateLow

⚠️ Potential Abuse (2)

The following security risks were found based on the above permissions:

📦 Workloads (1)

KindNameContainerImage
Deploymentgerrit-operatorgerrit-operatorepamedp/gerrit-operator:2.17.0

🤖 edp-nexus-operator

Namespace: default  |  Automount:

🔑 Permissions (21)

RoleResourceVerbsRiskTags
Role edp-nexus-operator*/deployments/finalizers*MediumNamespaceAdmin NamespaceWideAccess WildcardPermission
Role edp-nexus-operator*/events*MediumNamespaceAdmin NamespaceWideAccess WildcardPermission
Role edp-nexus-operator*/jenkins*MediumNamespaceAdmin NamespaceWideAccess WildcardPermission
Role edp-nexus-operator*/jenkins/finalizers*MediumNamespaceAdmin NamespaceWideAccess WildcardPermission
Role edp-nexus-operator*/jenkins/status*MediumNamespaceAdmin NamespaceWideAccess WildcardPermission
Role edp-nexus-operator*/jenkinses*MediumNamespaceAdmin NamespaceWideAccess WildcardPermission
Role edp-nexus-operator*/jenkinses/finalizers*MediumNamespaceAdmin NamespaceWideAccess WildcardPermission
Role edp-nexus-operator*/jenkinses/status*MediumNamespaceAdmin NamespaceWideAccess WildcardPermission
Role edp-nexus-operator*/jenkinsscripts*MediumNamespaceAdmin NamespaceWideAccess WildcardPermission
Role edp-nexus-operator*/jenkinsscripts/finalizers*MediumNamespaceAdmin NamespaceWideAccess WildcardPermission
Role edp-nexus-operator*/jenkinsscripts/status*MediumNamespaceAdmin NamespaceWideAccess WildcardPermission
Role edp-nexus-operator*/jenkinsserviceaccounts*MediumNamespaceAdmin NamespaceWideAccess WildcardPermission
Role edp-nexus-operator*/jenkinsserviceaccounts/finalizers*MediumNamespaceAdmin NamespaceWideAccess WildcardPermission
Role edp-nexus-operator*/jenkinsserviceaccounts/status*MediumNamespaceAdmin NamespaceWideAccess WildcardPermission
Role edp-nexus-operator*/nexuses*MediumNamespaceAdmin NamespaceWideAccess WildcardPermission
Role edp-nexus-operator*/nexuses/finalizers*MediumNamespaceAdmin NamespaceWideAccess WildcardPermission
Role edp-nexus-operator*/nexuses/status*MediumNamespaceAdmin NamespaceWideAccess WildcardPermission
Role edp-nexus-operator*/nexususers*MediumNamespaceAdmin NamespaceWideAccess WildcardPermission
Role edp-nexus-operator*/nexususers/finalizers*MediumNamespaceAdmin NamespaceWideAccess WildcardPermission
Role edp-nexus-operator*/nexususers/status*MediumNamespaceAdmin NamespaceWideAccess WildcardPermission
Role edp-nexus-operatorcoordination.k8s.io/leasescreate · get · list · updateLow

⚠️ Potential Abuse (2)

The following security risks were found based on the above permissions:

📦 Workloads (1)

KindNameContainerImage
Deploymentnexus-operatornexus-operatorepamedp/nexus-operator:2.17.0

🤖 edp-tekton-dashboard

Namespace: default  |  Automount:

🔑 Permissions (20)

RoleResourceVerbsRiskTags
Role tekton-dashboard-tenantcore/pods/logget · list · watchMediumDataExposure InformationDisclosure LogAccess
Role tekton-dashboard-backendapiextensions.k8s.io/customresourcedefinitionsget · listLow
Role tekton-dashboard-tenanttriggers.tekton.dev/eventlistenerscreate · delete · get · list · patch · update · watchLow
Role tekton-dashboard-tenantcore/eventsget · list · watchLow
Role tekton-dashboard-backenddashboard.tekton.dev/extensionscreate · delete · patch · updateLow
Role tekton-dashboard-tenantdashboard.tekton.dev/extensionsget · list · watchLow
Role tekton-dashboard-tenanttriggers.tekton.dev/interceptorscreate · delete · get · list · patch · update · watchLow
Role tekton-dashboard-tenantcore/namespacesget · list · watchLow
Role tekton-dashboard-tenanttekton.dev/pipelineresourcescreate · delete · get · list · patch · update · watchLow
Role tekton-dashboard-tenanttekton.dev/pipelinerunscreate · delete · get · list · patch · update · watchLow
Role tekton-dashboard-tenanttekton.dev/pipelinescreate · delete · get · list · patch · update · watchLow
Role tekton-dashboard-tenantcore/podsget · list · watchLow
Role tekton-dashboard-tenanttekton.dev/runscreate · delete · get · list · patch · update · watchLow
Role tekton-dashboard-backendsecurity.openshift.io/securitycontextconstraintsuseLow
Role tekton-dashboard-backendcore/serviceaccountsget · list · watchLow
Role tekton-dashboard-tenanttekton.dev/taskrunscreate · delete · get · list · patch · update · watchLow
Role tekton-dashboard-tenanttekton.dev/taskscreate · delete · get · list · patch · update · watchLow
Role tekton-dashboard-tenanttriggers.tekton.dev/triggerbindingscreate · delete · get · list · patch · update · watchLow
Role tekton-dashboard-tenanttriggers.tekton.dev/triggerscreate · delete · get · list · patch · update · watchLow
Role tekton-dashboard-tenanttriggers.tekton.dev/triggertemplatescreate · delete · get · list · patch · update · watchLow

⚠️ Potential Abuse (2)

The following security risks were found based on the above permissions:

📦 Workloads (1)

KindNameContainerImage
Deploymentedp-tekton-dashboardtekton-dashboardgcr.io/tekton-releases/github.com/tektoncd/dashboard/cmd/dashboard:v0.39.0

🤖 tekton

Namespace: default  |  Automount:

🔑 Permissions (16)

RoleResourceVerbsRiskTags
Role tekton-pipeline-rolecore/configmapsget · list · watchMediumConfigMapAccess DataExposure InformationDisclosure
Role tekton-autotests-roleargoproj.io/applicationsget · listLow
Role tekton-pipeline-rolev2.edp.epam.com/cdpipelinesget · list · patch · updateLow
Role tekton-pipeline-rolev2.edp.epam.com/codebasebranchesget · list · patch · updateLow
Role tekton-pipeline-rolev2.edp.epam.com/codebasebranches/statusget · list · patch · updateLow
Role tekton-pipeline-rolev2.edp.epam.com/codebaseimagestreamsget · list · patch · updateLow
Role tekton-autotests-rolev2.edp.epam.com/codebasesget · list · watchLow
Role tekton-pipeline-rolev2.edp.epam.com/codebasesget · list · patch · updateLow
Role tekton-pipeline-rolev1.edp.epam.com/edpcomponentsgetLow
Role tekton-autotests-rolev2.edp.epam.com/gitserversget · list · watchLow
Role tekton-pipeline-rolev2.edp.epam.com/jiraissuemetadatascreate · getLow
Role tekton-autotests-roletekton.dev/pipelinerunscreate · get · list · patch · update · watchLow
Role tekton-autotests-roletekton.dev/pipelinescreate · get · list · patch · update · watchLow
Role tekton-autotests-rolev2.edp.epam.com/stagesget · list · watchLow
Role tekton-pipeline-rolev2.edp.epam.com/stagesget · list · patch · updateLow
Role tekton-pipeline-roletekton.dev/taskrunsget · list · watchLow

⚠️ Potential Abuse (2)

The following security risks were found based on the above permissions:

📦 Workloads (0)

No workloads use this ServiceAccount.


🤖 edp-tekton-interceptor

Namespace: default  |  Automount:

🔑 Permissions (12)

RoleResourceVerbsRiskTags
Role tekton-triggers-edp-interceptorv2.edp.epam.com/codebasebranchesget · list · watchLow
Role tekton-triggers-edp-interceptorv2.edp.epam.com/codebasebranches/finalizersget · list · watchLow
Role tekton-triggers-edp-interceptorv2.edp.epam.com/codebasebranches/statusget · list · watchLow
Role tekton-triggers-edp-interceptorv2.edp.epam.com/codebasesget · list · watchLow
Role tekton-triggers-edp-interceptorv2.edp.epam.com/codebases/finalizersget · list · watchLow
Role tekton-triggers-edp-interceptorv2.edp.epam.com/codebases/statusget · list · watchLow
Role tekton-triggers-edp-interceptorv2.edp.epam.com/gitserversget · list · watchLow
Role tekton-triggers-edp-interceptorv2.edp.epam.com/gitservers/finalizersget · list · watchLow
Role tekton-triggers-edp-interceptorv2.edp.epam.com/gitservers/statusget · list · watchLow
Role tekton-triggers-edp-interceptortriggers.tekton.dev/interceptorsget · list · update · watchLow
Role tekton-triggers-edp-interceptorcore/secretsgetLow
Role tekton-triggers-edp-interceptorcore/secrets (restricted to: tekton-edp-interceptor-certs)create · get · list · update · watchLowCredentialAccess DataExposure InformationDisclosure ResourceNameRestricted SecretAccess

⚠️ Potential Abuse (2)

The following security risks were found based on the above permissions:

📦 Workloads (1)

KindNameContainerImage
Deploymentedp-tekton-interceptortekton-triggers-edp-interceptorepamedp/edp-tekton:0.7.0

🤖 tekton-resource-pruner

Namespace: default  |  Automount:

🔑 Permissions (2)

RoleResourceVerbsRiskTags
Role tekton-resource-prunertekton.dev/pipelinerunsdelete · listLow
Role tekton-resource-prunertekton.dev/pipelinesdelete · listLow

⚠️ Potential Abuse (1)

The following security risks were found based on the above permissions:

📦 Workloads (1)

KindNameContainerImage
CronJobtekton-resource-prunerpruner-tkn-tekton-pipelinesgcr.io/tekton-releases/dogfooding/tkn@sha256:025de221fb059ca24a3b2d988889ea34bce48dc76c0cf0d6b4499edb8c21325f

🤖 edp-headlamp

Namespace: default  |  Automount:

🔑 Permissions (0)

No explicit RBAC bindings.

📦 Workloads (1)

KindNameContainerImage
Deploymentedp-headlampedp-headlampepamedp/edp-headlamp:0.9.0

🤖 edp-keycloak-operator

Namespace: default  |  Automount:

🔑 Permissions (0)

No explicit RBAC bindings.

📦 Workloads (1)

KindNameContainerImage
Deploymentkeycloak-operatorkeycloak-operatorepamedp/keycloak-operator:1.18.0

🤖 edp-sonar-operator

Namespace: default  |  Automount:

🔑 Permissions (0)

No explicit RBAC bindings.

📦 Workloads (1)

KindNameContainerImage
Deploymentsonar-operatorsonar-operatorepamedp/sonar-operator:2.14.1

🤖 gerrit

Namespace: default  |  Automount:

🔑 Permissions (0)

No explicit RBAC bindings.

📦 Workloads (1)

KindNameContainerImage
Deploymentgerritgerritepamedp/edp-gerrit:3.6.2

🤖 nexus

Namespace: default  |  Automount:

🔑 Permissions (0)

No explicit RBAC bindings.

📦 Workloads (1)

KindNameContainerImage
Deploymentnexusnexussonatype/nexus3:3.58.1

🤖 nexus-proxy

Namespace: default  |  Automount:

🔑 Permissions (0)

No explicit RBAC bindings.

📦 Workloads (1)

KindNameContainerImage
Deploymentnexus-proxynexus-proxyquay.io/oauth2-proxy/oauth2-proxy:v7.4.0

🤖 sonar

Namespace: default  |  Automount:

🔑 Permissions (0)

No explicit RBAC bindings.

📦 Workloads (2)

KindNameContainerImage
Deploymentsonarsonarsonarqube:8.9.10-community
Deploymentsonar-dbsonar-dbpostgres:9.6

🤖 tekton-triggers-sa-default

Namespace: default  |  Automount:

🔑 Permissions (0)

No explicit RBAC bindings.

📦 Workloads (0)

No workloads use this ServiceAccount.