Description

Automatic SRE Superpowers within your Kubernetes cluster

Overview

IdentityNamespaceAutomountSecretsPermissionsWorkloadsRisk
k8sgpt-operator-controller-managerdefault112Critical
k8sgpt-operator-interplexdefault01

Numbers in the last two columns indicate how many bindings or workloads involve each ServiceAccount.


Identities

🤖 k8sgpt-operator-controller-manager

Namespace: default  |  Automount:

🔑 Permissions (11)

RoleResourceVerbsRiskTags
ClusterRole k8sgpt-operator-manager-role*create · delete · get · list · patch · update · watchCriticalAPIServerDoS APIServiceManipulation AvailabilityImpact BackupAccess BindingToPrivilegedRole (+63 more)
ClusterRole k8sgpt-operator-manager-roleapiextensions.k8s.io/**CriticalCRDManipulation ClusterWideAccess PotentialPrivilegeEscalation Tampering WildcardPermission
Role k8sgpt-operator-leader-election-rolecoordination.k8s.io/leasescreate · delete · get · list · patch · update · watchCriticalControlPlaneDisruption CriticalNamespace DenialOfService Tampering
Role k8sgpt-operator-leader-election-rolecore/configmapscreate · delete · get · list · patch · update · watchHighConfigMapAccess DataExposure InformationDisclosure PotentialPrivilegeEscalation Tampering
ClusterRole k8sgpt-operator-proxy-roleauthorization.k8s.io/subjectaccessreviewscreateMediumInformationDisclosure RBACQuery
ClusterRole k8sgpt-operator-proxy-roleauthentication.k8s.io/tokenreviewscreateMediumCredentialAccess InformationDisclosure RBACQuery
Role k8sgpt-operator-leader-election-rolecore/eventscreate · patchLow
ClusterRole k8sgpt-operator-manager-rolecore.k8sgpt.ai/k8sgptscreate · delete · get · list · patch · update · watchLow
ClusterRole k8sgpt-operator-manager-rolecore.k8sgpt.ai/k8sgpts/finalizersupdateLow
ClusterRole k8sgpt-operator-manager-rolecore.k8sgpt.ai/k8sgpts/statusget · patch · updateLow
ClusterRole k8sgpt-operator-manager-rolecore.k8sgpt.ai/resultscreate · delete · get · list · patch · update · watchLow

⚠️ Potential Abuse (97)

The following security risks were found based on the above permissions:

📦 Workloads (2)

KindNameContainerImage
Deploymentk8sgpt-operator-controller-managerkube-rbac-proxyquay.io/brancz/kube-rbac-proxy:v0.19.1
Deploymentk8sgpt-operator-controller-managermanagerghcr.io/k8sgpt-ai/k8sgpt-operator:v0.2.22

🤖 k8sgpt-operator-interplex

Namespace: default  |  Automount:

🔑 Permissions (0)

No explicit RBAC bindings.

📦 Workloads (1)

KindNameContainerImage
StatefulSetk8sgpt-operator-interplexinterplexghcr.io/interplex-ai/interplex:v1.0.0