Description

A Helm chart for KubeRocketCI Gerrit Operator

Overview

IdentityNamespaceAutomountSecretsPermissionsWorkloadsRisk
edp-gerrit-operatordefault291Medium
gerritdefault01

Numbers in the last two columns indicate how many bindings or workloads involve each ServiceAccount.


Identities

🤖 edp-gerrit-operator

Namespace: default  |  Automount:

🔑 Permissions (29)

RoleResourceVerbsRiskTags
Role edp-gerrit-operator*/events*MediumNamespaceAdmin NamespaceWideAccess WildcardPermission
Role edp-gerrit-operator*/gerritgroupmembers*MediumNamespaceAdmin NamespaceWideAccess WildcardPermission
Role edp-gerrit-operator*/gerritgroupmembers/finalizers*MediumNamespaceAdmin NamespaceWideAccess WildcardPermission
Role edp-gerrit-operator*/gerritgroupmembers/status*MediumNamespaceAdmin NamespaceWideAccess WildcardPermission
Role edp-gerrit-operator*/gerritgroups*MediumNamespaceAdmin NamespaceWideAccess WildcardPermission
Role edp-gerrit-operator*/gerritgroups/status*MediumNamespaceAdmin NamespaceWideAccess WildcardPermission
Role edp-gerrit-operator*/gerritmergerequests*MediumNamespaceAdmin NamespaceWideAccess WildcardPermission
Role edp-gerrit-operator*/gerritmergerequests/finalizers*MediumNamespaceAdmin NamespaceWideAccess WildcardPermission
Role edp-gerrit-operator*/gerritmergerequests/status*MediumNamespaceAdmin NamespaceWideAccess WildcardPermission
Role edp-gerrit-operator*/gerritprojectaccesses*MediumNamespaceAdmin NamespaceWideAccess WildcardPermission
Role edp-gerrit-operator*/gerritprojectaccesses/finalizers*MediumNamespaceAdmin NamespaceWideAccess WildcardPermission
Role edp-gerrit-operator*/gerritprojectaccesses/status*MediumNamespaceAdmin NamespaceWideAccess WildcardPermission
Role edp-gerrit-operator*/gerritprojects*MediumNamespaceAdmin NamespaceWideAccess WildcardPermission
Role edp-gerrit-operator*/gerritprojects/finalizers*MediumNamespaceAdmin NamespaceWideAccess WildcardPermission
Role edp-gerrit-operator*/gerritprojects/status*MediumNamespaceAdmin NamespaceWideAccess WildcardPermission
Role edp-gerrit-operator*/gerritreplicationconfigs*MediumNamespaceAdmin NamespaceWideAccess WildcardPermission
Role edp-gerrit-operator*/gerritreplicationconfigs/status*MediumNamespaceAdmin NamespaceWideAccess WildcardPermission
Role edp-gerrit-operator*/gerrits*MediumNamespaceAdmin NamespaceWideAccess WildcardPermission
Role edp-gerrit-operator*/gerrits/finalizers*MediumNamespaceAdmin NamespaceWideAccess WildcardPermission
Role edp-gerrit-operator*/gerrits/status*MediumNamespaceAdmin NamespaceWideAccess WildcardPermission
Role edp-gerrit-operator*/keycloakclients*MediumNamespaceAdmin NamespaceWideAccess WildcardPermission
Role edp-gerrit-operator*/keycloakclients/finalizers*MediumNamespaceAdmin NamespaceWideAccess WildcardPermission
Role edp-gerrit-operator*/keycloakclients/status*MediumNamespaceAdmin NamespaceWideAccess WildcardPermission
Role edp-gerrit-operator*/keycloakrealms*MediumNamespaceAdmin NamespaceWideAccess WildcardPermission
Role edp-gerrit-operator*/keycloakrealms/status*MediumNamespaceAdmin NamespaceWideAccess WildcardPermission
Role edp-gerrit-operator*/keycloaks*MediumNamespaceAdmin NamespaceWideAccess WildcardPermission
Role edp-gerrit-operator*/keycloaks/status*MediumNamespaceAdmin NamespaceWideAccess WildcardPermission
Role edp-gerrit-operator*/securitycontextconstraintscreate · delete · get · list · patch · updateMediumNamespaceAdmin NamespaceWideAccess WildcardPermission
Role edp-gerrit-operatorcoordination.k8s.io/leasescreate · get · list · updateLow

⚠️ Potential Abuse (2)

The following security risks were found based on the above permissions:

📦 Workloads (1)

KindNameContainerImage
Deploymentgerrit-operatorgerrit-operatorepamedp/gerrit-operator:2.23.1

🤖 gerrit

Namespace: default  |  Automount:

🔑 Permissions (0)

No explicit RBAC bindings.

📦 Workloads (1)

KindNameContainerImage
Deploymentgerritgerritepamedp/edp-gerrit:3.6.2-oauth