Description

Helm chart for frp Operator

Overview

IdentityNamespaceAutomountSecretsPermissionsWorkloadsRisk
controller-managerdefault122Critical

Numbers in the last two columns indicate how many bindings or workloads involve each ServiceAccount.


Identities

🤖 controller-manager

Namespace: default  |  Automount:

🔑 Permissions (12)

RoleResourceVerbsRiskTags
Role leader-election-rolecoordination.k8s.io/leasescreate · delete · get · list · patch · update · watchCriticalControlPlaneDisruption CriticalNamespace DenialOfService Tampering
ClusterRole manager-rolecore/podscreate · delete · get · list · patch · update · watchCriticalLateralMovement Persistence PotentialPrivilegeEscalation PrivilegeEscalation Tampering (+1 more)
ClusterRole manager-rolecore/secretscreate · delete · get · list · patch · update · watchCriticalClusterWideSecretAccess CredentialAccess DataExposure InformationDisclosure Persistence (+4 more)
ClusterRole manager-rolecore/servicescreate · delete · get · list · patch · update · watchCriticalDenialOfService NetworkManipulation ServiceExposure Tampering
Role leader-election-rolecore/configmapscreate · delete · get · list · patch · update · watchHighConfigMapAccess DataExposure InformationDisclosure PotentialPrivilegeEscalation Tampering
ClusterRole proxy-roleauthorization.k8s.io/subjectaccessreviewscreateMediumInformationDisclosure RBACQuery
ClusterRole proxy-roleauthentication.k8s.io/tokenreviewscreateMediumCredentialAccess InformationDisclosure RBACQuery
Role leader-election-rolecore/eventscreate · patchLow
ClusterRole manager-rolefrp.aureum.cloud/exitserverscreate · delete · get · list · patch · update · watchLow
ClusterRole manager-rolefrp.aureum.cloud/exitservers/finalizersupdateLow
ClusterRole manager-rolefrp.aureum.cloud/exitservers/statusget · patch · updateLow
ClusterRole manager-rolefrp.aureum.cloud/tunnelsget · list · watchLow

⚠️ Potential Abuse (16)

The following security risks were found based on the above permissions:

📦 Workloads (2)

KindNameContainerImage
Deploymentfrp-operatorkube-rbac-proxygcr.io/kubebuilder/kube-rbac-proxy:v0.8.0
Deploymentfrp-operatormanagerghcr.io/aureum-cloud/frp-operator:v1.0.0