Description

A Helm chart for installing Hazelcast Platform Operator which automates common management tasks such as configuring, creating, scaling, and recovering Hazelcast clusters on Kubernetes and Red Hat OpenShift. By taking care of manual deployment and life-cycle management, Hazelcast Platform Operator makes it simpler to work with Hazelcast clusters.

Overview

IdentityNamespaceAutomountSecretsPermissionsWorkloadsRisk
hazelcast-platform-operatordefault731Critical

Numbers in the last two columns indicate how many bindings or workloads involve each ServiceAccount.


Identities

🤖 hazelcast-platform-operator

Namespace: default  |  Automount:

🔑 Permissions (73)

RoleResourceVerbsRiskTags
ClusterRole hazelcast-platform-operatorrbac.authorization.k8s.io/clusterrolebindingscreate · delete · get · list · patch · update · watchCriticalBindingToPrivilegedRole ClusterAdminAccess InformationDisclosure PrivilegeEscalation RBACManipulation (+2 more)
ClusterRole hazelcast-platform-operatorrbac.authorization.k8s.io/clusterrolescreate · delete · get · list · patch · update · watchCriticalClusterAdminAccess InformationDisclosure PrivilegeEscalation RBACManipulation RBACQuery (+1 more)
ClusterRole hazelcast-platform-operatorcore/configmapscreate · delete · get · list · patch · update · watchCriticalConfigMapAccess DataExposure InformationDisclosure PotentialPrivilegeEscalation Tampering
ClusterRole hazelcast-platform-operatorcore/endpointscreate · delete · get · list · patch · update · watchCriticalDenialOfService ManInTheMiddle NetworkManipulation Tampering TrafficRedirection
Role hazelcast-platform-operatorcoordination.k8s.io/leasescreate · delete · get · list · patch · update · watchCriticalControlPlaneDisruption CriticalNamespace DenialOfService Tampering
ClusterRole hazelcast-platform-operatorcore/podscreate · delete · get · list · patch · update · watchCriticalLateralMovement Persistence PotentialPrivilegeEscalation PrivilegeEscalation Tampering (+1 more)
ClusterRole hazelcast-platform-operatorcore/secretscreate · delete · get · list · patch · update · watchCriticalClusterWideSecretAccess CredentialAccess DataExposure InformationDisclosure Persistence (+4 more)
ClusterRole hazelcast-platform-operatorcore/servicescreate · delete · get · list · patch · update · watchCriticalDenialOfService NetworkManipulation ServiceExposure Tampering
ClusterRole hazelcast-platform-operatorapps/statefulsetscreate · delete · get · list · patch · update · watchCriticalPersistence PotentialPrivilegeEscalation PrivilegeEscalation Tampering WorkloadLifecycle
ClusterRole hazelcast-platform-operatornetworking.k8s.io/ingressescreate · delete · get · list · patch · update · watchHighDenialOfService NetworkManipulation ServiceExposure Tampering
ClusterRole hazelcast-platform-operatorrbac.authorization.k8s.io/rolebindingscreate · delete · get · list · patch · update · watchHighBindingToPrivilegedRole InformationDisclosure PrivilegeEscalation RBACManipulation RBACQuery (+1 more)
ClusterRole hazelcast-platform-operatorrbac.authorization.k8s.io/rolescreate · delete · get · list · patch · update · watchHighInformationDisclosure PrivilegeEscalation RBACManipulation RBACQuery Reconnaissance
ClusterRole hazelcast-platform-operatorcore/serviceaccountscreate · delete · get · list · patch · update · watchHighIdentityManagement PotentialPrivilegeEscalation Tampering
ClusterRole hazelcast-platform-operatorcore/eventscreate · delete · get · list · patch · update · watchMediumInformationDisclosure OperationalData Reconnaissance
ClusterRole hazelcast-platform-operatorhazelcast.com/cachescreate · delete · get · list · patch · update · watchLow
ClusterRole hazelcast-platform-operatorhazelcast.com/caches/finalizersupdateLow
ClusterRole hazelcast-platform-operatorhazelcast.com/caches/statusget · patch · updateLow
ClusterRole hazelcast-platform-operatorhazelcast.com/cronhotbackupscreate · delete · get · list · patch · update · watchLow
ClusterRole hazelcast-platform-operatorhazelcast.com/cronhotbackups/finalizersupdateLow
ClusterRole hazelcast-platform-operatorhazelcast.com/cronhotbackups/statusget · patch · updateLow
Role hazelcast-platform-operatorapps/deploymentsgetLow
ClusterRole hazelcast-platform-operatorhazelcast.com/flowscreate · delete · get · list · patch · update · watchLow
ClusterRole hazelcast-platform-operatorhazelcast.com/flows/finalizersupdateLow
ClusterRole hazelcast-platform-operatorhazelcast.com/flows/statusget · patch · updateLow
ClusterRole hazelcast-platform-operatorhazelcast.com/hazelcastendpointscreate · delete · get · list · patch · update · watchLow
ClusterRole hazelcast-platform-operatorhazelcast.com/hazelcastendpoints/finalizersupdateLow
ClusterRole hazelcast-platform-operatorhazelcast.com/hazelcastendpoints/statusget · patch · updateLow
ClusterRole hazelcast-platform-operatorhazelcast.com/hazelcastscreate · delete · get · list · patch · update · watchLow
ClusterRole hazelcast-platform-operatorhazelcast.com/hazelcasts/finalizersupdateLow
ClusterRole hazelcast-platform-operatorhazelcast.com/hazelcasts/statusget · patch · updateLow
ClusterRole hazelcast-platform-operatorhazelcast.com/hotbackupscreate · delete · get · list · patch · update · watchLow
ClusterRole hazelcast-platform-operatorhazelcast.com/hotbackups/finalizersupdateLow
ClusterRole hazelcast-platform-operatorhazelcast.com/hotbackups/statusget · patch · updateLow
ClusterRole hazelcast-platform-operatorhazelcast.com/jetjobscreate · delete · get · list · patch · update · watchLow
ClusterRole hazelcast-platform-operatorhazelcast.com/jetjobs/finalizersupdateLow
ClusterRole hazelcast-platform-operatorhazelcast.com/jetjobs/statusget · patch · updateLow
ClusterRole hazelcast-platform-operatorhazelcast.com/jetjobsnapshotscreate · delete · get · list · patch · update · watchLow
ClusterRole hazelcast-platform-operatorhazelcast.com/jetjobsnapshots/finalizersupdateLow
ClusterRole hazelcast-platform-operatorhazelcast.com/jetjobsnapshots/statusget · patch · updateLow
ClusterRole hazelcast-platform-operatorhazelcast.com/managementcenterscreate · delete · get · list · patch · update · watchLow
ClusterRole hazelcast-platform-operatorhazelcast.com/managementcenters/finalizersupdateLow
ClusterRole hazelcast-platform-operatorhazelcast.com/managementcenters/statusget · patch · updateLow
ClusterRole hazelcast-platform-operatorhazelcast.com/mapscreate · delete · get · list · patch · update · watchLow
ClusterRole hazelcast-platform-operatorhazelcast.com/maps/finalizersupdateLow
ClusterRole hazelcast-platform-operatorhazelcast.com/maps/statusget · patch · updateLow
ClusterRole hazelcast-platform-operatorhazelcast.com/multimapscreate · delete · get · list · patch · update · watchLow
ClusterRole hazelcast-platform-operatorhazelcast.com/multimaps/finalizersupdateLow
ClusterRole hazelcast-platform-operatorhazelcast.com/multimaps/statusget · patch · updateLow
ClusterRole hazelcast-platform-operatorcore/nodesget · list · watchLow
ClusterRole hazelcast-platform-operatorhazelcast.com/queuescreate · delete · get · list · patch · update · watchLow
ClusterRole hazelcast-platform-operatorhazelcast.com/queues/finalizersupdateLow
ClusterRole hazelcast-platform-operatorhazelcast.com/queues/statusget · patch · updateLow
ClusterRole hazelcast-platform-operatorhazelcast.com/replicatedmapscreate · delete · get · list · patch · update · watchLow
ClusterRole hazelcast-platform-operatorhazelcast.com/replicatedmaps/finalizersupdateLow
ClusterRole hazelcast-platform-operatorhazelcast.com/replicatedmaps/statusget · patch · updateLow
ClusterRole hazelcast-platform-operatorroute.openshift.io/routescreate · delete · get · list · patch · update · watchLow
ClusterRole hazelcast-platform-operatorroute.openshift.io/routes/custom-hostcreateLow
ClusterRole hazelcast-platform-operatorroute.openshift.io/routes/statusgetLow
ClusterRole hazelcast-platform-operatorhazelcast.com/topicscreate · delete · get · list · patch · update · watchLow
ClusterRole hazelcast-platform-operatorhazelcast.com/topics/finalizersupdateLow
ClusterRole hazelcast-platform-operatorhazelcast.com/topics/statusget · patch · updateLow
ClusterRole hazelcast-platform-operatorhazelcast.com/usercodenamespacescreate · delete · get · list · patch · update · watchLow
ClusterRole hazelcast-platform-operatorhazelcast.com/usercodenamespaces/finalizersupdateLow
ClusterRole hazelcast-platform-operatorhazelcast.com/usercodenamespaces/statusget · patch · updateLow
ClusterRole hazelcast-platform-operatorhazelcast.com/vectorcollectionscreate · delete · get · list · patch · update · watchLow
ClusterRole hazelcast-platform-operatorhazelcast.com/vectorcollections/finalizersupdateLow
ClusterRole hazelcast-platform-operatorhazelcast.com/vectorcollections/statusget · patch · updateLow
ClusterRole hazelcast-platform-operatorhazelcast.com/wanreplicationscreate · delete · get · list · patch · update · watchLow
ClusterRole hazelcast-platform-operatorhazelcast.com/wanreplications/finalizersupdateLow
ClusterRole hazelcast-platform-operatorhazelcast.com/wanreplications/statusget · patch · updateLow
ClusterRole hazelcast-platform-operatorhazelcast.com/wansyncscreate · delete · get · list · patch · update · watchLow
ClusterRole hazelcast-platform-operatorhazelcast.com/wansyncs/finalizersupdateLow
ClusterRole hazelcast-platform-operatorhazelcast.com/wansyncs/statusget · patch · updateLow

⚠️ Potential Abuse (29)

The following security risks were found based on the above permissions:

📦 Workloads (1)

KindNameContainerImage
Deploymenthazelcast-platform-operatormanagerhazelcast/hazelcast-platform-operator:5.15.0