Description

Grafana Operator is a Kubernetes operator that enables the installation and management of Grafana instances, dashboards and plugins.

Overview

IdentityNamespaceAutomountSecretsPermissionsWorkloadsRisk
grafana-operatordefault441Critical

Numbers in the last two columns indicate how many bindings or workloads involve each ServiceAccount.


Identities

🤖 grafana-operator

Namespace: default  |  Automount:

🔑 Permissions (44)

RoleResourceVerbsRiskTags
ClusterRole grafana-operator-defaultcore/configmapscreate · delete · get · list · patch · update · watchCriticalConfigMapAccess DataExposure InformationDisclosure PotentialPrivilegeEscalation Tampering
ClusterRole grafana-operator-defaultapps/deploymentscreate · delete · get · list · patch · update · watchCriticalPersistence PotentialPrivilegeEscalation PrivilegeEscalation Tampering WorkloadLifecycle
ClusterRole grafana-operator-defaultcoordination.k8s.io/leasescreate · delete · get · list · patch · update · watchCriticalControlPlaneDisruption CriticalNamespace DenialOfService LeaderElectionAbuse Tampering
ClusterRole grafana-operator-defaultcore/secretscreate · delete · get · list · patch · update · watchCriticalClusterWideSecretAccess CredentialAccess DataExposure InformationDisclosure Persistence (+4 more)
ClusterRole grafana-operator-defaultcore/servicescreate · delete · get · list · patch · update · watchCriticalDenialOfService NetworkManipulation ServiceExposure Tampering
ClusterRole grafana-operator-defaultnetworking.k8s.io/ingressescreate · delete · get · list · patch · update · watchHighDenialOfService NetworkManipulation ServiceExposure Tampering
ClusterRole grafana-operator-defaultcore/serviceaccountscreate · delete · get · list · patch · update · watchHighIdentityManagement PotentialPrivilegeEscalation Tampering
ClusterRole grafana-operator-defaultcore/eventscreate · get · list · patch · watchMediumInformationDisclosure OperationalData Reconnaissance
ClusterRole grafana-operator-defaultgrafana.integreatly.org/grafanaalertrulegroupscreate · delete · get · list · patch · update · watchLow
ClusterRole grafana-operator-defaultgrafana.integreatly.org/grafanaalertrulegroups/finalizersupdateLow
ClusterRole grafana-operator-defaultgrafana.integreatly.org/grafanaalertrulegroups/statusget · patch · updateLow
ClusterRole grafana-operator-defaultgrafana.integreatly.org/grafanacontactpointscreate · delete · get · list · patch · update · watchLow
ClusterRole grafana-operator-defaultgrafana.integreatly.org/grafanacontactpoints/finalizersupdateLow
ClusterRole grafana-operator-defaultgrafana.integreatly.org/grafanacontactpoints/statusget · patch · updateLow
ClusterRole grafana-operator-defaultgrafana.integreatly.org/grafanadashboardscreate · delete · get · list · patch · update · watchLow
ClusterRole grafana-operator-defaultgrafana.integreatly.org/grafanadashboards/finalizersupdateLow
ClusterRole grafana-operator-defaultgrafana.integreatly.org/grafanadashboards/statusget · patch · updateLow
ClusterRole grafana-operator-defaultgrafana.integreatly.org/grafanadatasourcescreate · delete · get · list · patch · update · watchLow
ClusterRole grafana-operator-defaultgrafana.integreatly.org/grafanadatasources/finalizersupdateLow
ClusterRole grafana-operator-defaultgrafana.integreatly.org/grafanadatasources/statusget · patch · updateLow
ClusterRole grafana-operator-defaultgrafana.integreatly.org/grafanafolderscreate · delete · get · list · patch · update · watchLow
ClusterRole grafana-operator-defaultgrafana.integreatly.org/grafanafolders/finalizersupdateLow
ClusterRole grafana-operator-defaultgrafana.integreatly.org/grafanafolders/statusget · patch · updateLow
ClusterRole grafana-operator-defaultgrafana.integreatly.org/grafanalibrarypanelscreate · delete · get · list · patch · update · watchLow
ClusterRole grafana-operator-defaultgrafana.integreatly.org/grafanalibrarypanels/finalizersupdateLow
ClusterRole grafana-operator-defaultgrafana.integreatly.org/grafanalibrarypanels/statusget · patch · updateLow
ClusterRole grafana-operator-defaultgrafana.integreatly.org/grafanamutetimingscreate · delete · get · list · patch · update · watchLow
ClusterRole grafana-operator-defaultgrafana.integreatly.org/grafanamutetimings/finalizersupdateLow
ClusterRole grafana-operator-defaultgrafana.integreatly.org/grafanamutetimings/statusget · patch · updateLow
ClusterRole grafana-operator-defaultgrafana.integreatly.org/grafananotificationpoliciescreate · delete · get · list · patch · update · watchLow
ClusterRole grafana-operator-defaultgrafana.integreatly.org/grafananotificationpolicies/finalizersupdateLow
ClusterRole grafana-operator-defaultgrafana.integreatly.org/grafananotificationpolicies/statusget · patch · updateLow
ClusterRole grafana-operator-defaultgrafana.integreatly.org/grafananotificationpolicyroutescreate · delete · get · list · patch · update · watchLow
ClusterRole grafana-operator-defaultgrafana.integreatly.org/grafananotificationpolicyroutes/finalizersupdateLow
ClusterRole grafana-operator-defaultgrafana.integreatly.org/grafananotificationpolicyroutes/statusget · patch · updateLow
ClusterRole grafana-operator-defaultgrafana.integreatly.org/grafananotificationtemplatescreate · delete · get · list · patch · update · watchLow
ClusterRole grafana-operator-defaultgrafana.integreatly.org/grafananotificationtemplates/finalizersupdateLow
ClusterRole grafana-operator-defaultgrafana.integreatly.org/grafananotificationtemplates/statusget · patch · updateLow
ClusterRole grafana-operator-defaultgrafana.integreatly.org/grafanascreate · delete · get · list · patch · update · watchLow
ClusterRole grafana-operator-defaultgrafana.integreatly.org/grafanas/finalizersupdateLow
ClusterRole grafana-operator-defaultgrafana.integreatly.org/grafanas/statusget · patch · updateLow
ClusterRole grafana-operator-defaultcore/persistentvolumeclaimscreate · delete · get · list · patch · update · watchLow
ClusterRole grafana-operator-defaultroute.openshift.io/routescreate · delete · get · list · update · watchLow
ClusterRole grafana-operator-defaultroute.openshift.io/routes/custom-hostcreate · delete · get · list · update · watchLow

⚠️ Potential Abuse (19)

The following security risks were found based on the above permissions:

📦 Workloads (1)

KindNameContainerImage
Deploymentgrafana-operatorgrafana-operatordocker.io/bitnami/grafana-operator:5.18.0-debian-12-r5