Description

jaeger-operator Helm chart for Kubernetes

Overview

IdentityNamespaceAutomountSecretsPermissionsWorkloadsRisk
jaeger-operatordefault331Critical

Numbers in the last two columns indicate how many bindings or workloads involve each ServiceAccount.


Identities

🤖 jaeger-operator

Namespace: default  |  Automount:

🔑 Permissions (33)

RoleResourceVerbsRiskTags
Role jaeger-operatorapps/daemonsetscreate · delete · get · list · patch · update · watchCriticalNodeAccess Persistence PrivilegeEscalation Tampering WorkloadLifecycle
Role jaeger-operatorcore/secretscreate · delete · get · list · patch · update · watchCriticalCredentialAccess DataExposure InformationDisclosure Persistence PotentialPrivilegeEscalation (+2 more)
Role jaeger-operatorcore/configmapscreate · delete · get · list · patch · update · watchHighConfigMapAccess DataExposure InformationDisclosure PotentialPrivilegeEscalation Tampering
Role jaeger-operatorbatch/cronjobscreate · delete · get · list · patch · update · watchHighPersistence PotentialPrivilegeEscalation Tampering WorkloadLifecycle
Role jaeger-operatorapps/deploymentscreate · delete · get · list · patch · update · watchHighPersistence PotentialPrivilegeEscalation Tampering WorkloadLifecycle
Role jaeger-operatornetworking.k8s.io/ingressescreate · delete · get · list · patch · update · watchHighDenialOfService NetworkManipulation ServiceExposure Tampering
Role jaeger-operatorbatch/jobscreate · delete · get · list · patch · update · watchHighPotentialPrivilegeEscalation Tampering WorkloadLifecycle
Role jaeger-operatorcore/podscreate · delete · get · list · patch · update · watchHighLateralMovement Persistence PotentialPrivilegeEscalation Tampering WorkloadExecution
Role jaeger-operatorcore/servicescreate · delete · get · list · patch · update · watchHighDenialOfService NetworkManipulation ServiceExposure Tampering
Role jaeger-operatorapps/statefulsetscreate · delete · get · list · patch · update · watchHighPersistence PotentialPrivilegeEscalation Tampering WorkloadLifecycle
Role jaeger-operatorcore/serviceaccountscreate · delete · get · list · patch · update · watchMediumIdentityManagement PotentialPrivilegeEscalation Tampering
Role jaeger-operatorrbac.authorization.k8s.io/clusterrolebindingscreate · delete · get · list · patch · update · watchLow
Role jaeger-operatorconsole.openshift.io/consolelinkscreate · delete · get · list · patch · update · watchLow
Role jaeger-operatorapps/deployments/statusget · patch · updateLow
Role jaeger-operatorlogging.openshift.io/elasticsearchcreate · delete · get · list · patch · update · watchLow
Role jaeger-operatorlogging.openshift.io/elasticsearchescreate · delete · get · list · patch · update · watchLow
Role jaeger-operatorautoscaling/horizontalpodautoscalerscreate · delete · get · list · patch · update · watchLow
Role jaeger-operatorimage.openshift.io/imagestreamsget · list · watchLow
Role jaeger-operatornetworking.k8s.io/ingressclasseslist · watchLow
Role jaeger-operatorextensions/ingressescreate · delete · get · list · patch · update · watchLow
Role jaeger-operatorjaegertracing.io/jaegerscreate · delete · get · list · patch · update · watchLow
Role jaeger-operatorjaegertracing.io/jaegers/finalizersupdateLow
Role jaeger-operatorjaegertracing.io/jaegers/statusget · patch · updateLow
Role jaeger-operatorkafka.strimzi.io/kafkascreate · delete · get · list · patch · update · watchLow
Role jaeger-operatorkafka.strimzi.io/kafkauserscreate · delete · get · list · patch · update · watchLow
Role jaeger-operatorcoordination.k8s.io/leasescreate · get · list · updateLow
Role jaeger-operatorcore/namespacescreate · delete · get · list · patch · update · watchLow
Role jaeger-operatorcore/namespaces/statusget · patch · updateLow
Role jaeger-operatorcore/persistentvolumeclaimscreate · delete · get · list · patch · update · watchLow
Role jaeger-operatorapps/replicasetscreate · delete · get · list · patch · update · watchLow
Role jaeger-operatorroute.openshift.io/routescreate · delete · get · list · patch · update · watchLow
Role jaeger-operatormonitoring.coreos.com/servicemonitorscreate · delete · get · list · patch · update · watchLow
Role jaeger-operatorcore/services/finalizerscreate · delete · get · list · patch · update · watchLow

⚠️ Potential Abuse (15)

The following security risks were found based on the above permissions:

📦 Workloads (1)

KindNameContainerImage
Deploymentjaeger-operatorjaeger-operatorjaegertracing/jaeger-operator:1.61.0