Description

Official Helm chart for HCP Terraform Operator for Kubernetes.

Overview

IdentityNamespaceAutomountSecretsPermissionsWorkloadsRisk
hcp-terraform-operatordefault212Critical

Numbers in the last two columns indicate how many bindings or workloads involve each ServiceAccount.


Identities

🤖 hcp-terraform-operator

Namespace: default  |  Automount:

🔑 Permissions (21)

RoleResourceVerbsRiskTags
ClusterRole hcp-terraform-operator-manager-roleapps/deploymentscreate · delete · get · list · patch · update · watchCriticalPersistence PotentialPrivilegeEscalation PrivilegeEscalation Tampering WorkloadLifecycle
Role hcp-terraform-operator-leader-election-rolecoordination.k8s.io/leasescreate · delete · get · list · patch · update · watchCriticalControlPlaneDisruption CriticalNamespace DenialOfService Tampering
Role hcp-terraform-operator-leader-election-rolecore/configmapscreate · delete · get · list · patch · update · watchHighConfigMapAccess DataExposure InformationDisclosure PotentialPrivilegeEscalation Tampering
ClusterRole hcp-terraform-operator-proxy-roleauthorization.k8s.io/subjectaccessreviewscreateMediumInformationDisclosure RBACQuery
ClusterRole hcp-terraform-operator-proxy-roleauthentication.k8s.io/tokenreviewscreateMediumCredentialAccess InformationDisclosure RBACQuery
ClusterRole hcp-terraform-operator-manager-roleapp.terraform.io/agentpoolscreate · delete · get · list · patch · update · watchLow
ClusterRole hcp-terraform-operator-manager-roleapp.terraform.io/agentpools/finalizersupdateLow
ClusterRole hcp-terraform-operator-manager-roleapp.terraform.io/agentpools/statusget · patch · updateLow
ClusterRole hcp-terraform-operator-manager-rolecore/configmapscreate · list · update · watchLow
ClusterRole hcp-terraform-operator-manager-rolecore/eventscreate · patchLow
Role hcp-terraform-operator-leader-election-rolecore/eventscreate · patchLow
ClusterRole hcp-terraform-operator-manager-roleapp.terraform.io/modulescreate · delete · get · list · patch · update · watchLow
ClusterRole hcp-terraform-operator-manager-roleapp.terraform.io/modules/finalizersupdateLow
ClusterRole hcp-terraform-operator-manager-roleapp.terraform.io/modules/statusget · patch · updateLow
ClusterRole hcp-terraform-operator-manager-roleapp.terraform.io/projectscreate · delete · get · list · patch · update · watchLow
ClusterRole hcp-terraform-operator-manager-roleapp.terraform.io/projects/finalizersupdateLow
ClusterRole hcp-terraform-operator-manager-roleapp.terraform.io/projects/statusget · patch · updateLow
ClusterRole hcp-terraform-operator-manager-rolecore/secretscreate · list · update · watchLow
ClusterRole hcp-terraform-operator-manager-roleapp.terraform.io/workspacescreate · delete · get · list · patch · update · watchLow
ClusterRole hcp-terraform-operator-manager-roleapp.terraform.io/workspaces/finalizersupdateLow
ClusterRole hcp-terraform-operator-manager-roleapp.terraform.io/workspaces/statusget · patch · updateLow

⚠️ Potential Abuse (8)

The following security risks were found based on the above permissions:

📦 Workloads (2)

KindNameContainerImage
Deploymenthcp-terraform-operatorkube-rbac-proxyquay.io/brancz/kube-rbac-proxy:v0.19.1
Deploymenthcp-terraform-operatormanagerhashicorp/hcp-terraform-operator:2.9.2