Description

Deploy Kong Gateway Operator

Overview

IdentityNamespaceAutomountSecretsPermissionsWorkloadsRisk
controller-managerdefault1512Critical

Numbers in the last two columns indicate how many bindings or workloads involve each ServiceAccount.


Identities

🤖 controller-manager

Namespace: default  |  Automount:

🔑 Permissions (151)

RoleResourceVerbsRiskTags
ClusterRole gateway-operator-gateway-operator-manager-rolerbac.authorization.k8s.io/clusterrolebindingscreate · delete · get · list · patch · update · watchCriticalBindingToPrivilegedRole ClusterAdminAccess InformationDisclosure PrivilegeEscalation RBACManipulation (+2 more)
ClusterRole gateway-operator-gateway-operator-manager-rolerbac.authorization.k8s.io/clusterrolescreate · delete · get · list · patch · update · watchCriticalClusterAdminAccess InformationDisclosure PrivilegeEscalation RBACManipulation RBACQuery (+1 more)
ClusterRole gateway-operator-gateway-operator-manager-rolecore/configmapscreate · delete · get · list · patch · update · watchCriticalConfigMapAccess DataExposure InformationDisclosure PotentialPrivilegeEscalation Tampering
ClusterRole gateway-operator-gateway-operator-manager-roleapps/deploymentscreate · delete · get · list · patch · update · watchCriticalPersistence PotentialPrivilegeEscalation PrivilegeEscalation Tampering WorkloadLifecycle
ClusterRole gateway-operator-gateway-operator-manager-rolecoordination.k8s.io/leasescreate · delete · get · list · patch · update · watchCriticalControlPlaneDisruption CriticalNamespace DenialOfService LeaderElectionAbuse Tampering
Role gateway-operator-gateway-operator-leader-election-rolecoordination.k8s.io/leasescreate · delete · get · list · patch · update · watchCriticalControlPlaneDisruption CriticalNamespace DenialOfService Tampering
ClusterRole gateway-operator-gateway-operator-manager-rolenetworking.k8s.io/networkpoliciescreate · delete · get · list · patch · update · watchCriticalDenialOfService LateralMovement NetworkManipulation NetworkPolicyManagement Tampering
ClusterRole gateway-operator-gateway-operator-manager-rolecore/secretscreate · delete · get · list · watchCriticalClusterWideSecretAccess CredentialAccess DataExposure InformationDisclosure SecretAccess
ClusterRole gateway-operator-gateway-operator-manager-rolecore/servicescreate · delete · get · list · patch · update · watchCriticalDenialOfService NetworkManipulation ServiceExposure Tampering
ClusterRole gateway-operator-gateway-operator-manager-roleadmissionregistration.k8s.io/validatingwebhookconfigurationscreate · delete · get · list · patch · update · watchCriticalDenialOfService InformationDisclosure Reconnaissance Tampering WebhookManipulation (+1 more)
Role gateway-operator-gateway-operator-leader-election-rolecore/configmapscreate · delete · get · list · patch · update · watchHighConfigMapAccess DataExposure InformationDisclosure PotentialPrivilegeEscalation Tampering
ClusterRole gateway-operator-gateway-operator-manager-rolecore/serviceaccountscreate · delete · get · list · patch · update · watchHighIdentityManagement PotentialPrivilegeEscalation Tampering
ClusterRole gateway-operator-gateway-operator-manager-rolepolicy/poddisruptionbudgetscreate · delete · get · list · patch · update · watchMediumAvailabilityImpact DenialOfService Tampering
ClusterRole gateway-operator-gateway-operator-proxy-roleauthorization.k8s.io/subjectaccessreviewscreateMediumInformationDisclosure RBACQuery
ClusterRole gateway-operator-gateway-operator-proxy-roleauthentication.k8s.io/tokenreviewscreateMediumCredentialAccess InformationDisclosure RBACQuery
ClusterRole gateway-operator-gateway-operator-manager-rolegateway-operator.konghq.com/aigatewayscreate · delete · get · list · patch · update · watchLow
ClusterRole gateway-operator-gateway-operator-manager-rolegateway-operator.konghq.com/aigateways/finalizersupdateLow
ClusterRole gateway-operator-gateway-operator-manager-rolegateway-operator.konghq.com/aigateways/statusget · patch · updateLow
ClusterRole gateway-operator-gateway-operator-manager-rolecert-manager.io/certificatescreate · delete · get · list · patch · update · watchLow
ClusterRole gateway-operator-gateway-operator-manager-rolerbac.authorization.k8s.io/clusterrolebindings/statusgetLow
ClusterRole gateway-operator-gateway-operator-manager-rolerbac.authorization.k8s.io/clusterroles/statusgetLow
ClusterRole gateway-operator-gateway-operator-manager-rolecore/configmaps/statusgetLow
ClusterRole gateway-operator-gateway-operator-manager-rolegateway-operator.konghq.com/controlplanescreate · delete · get · list · patch · update · watchLow
ClusterRole gateway-operator-gateway-operator-manager-rolegateway-operator.konghq.com/controlplanes/finalizersupdateLow
ClusterRole gateway-operator-gateway-operator-manager-rolegateway-operator.konghq.com/controlplanes/statusget · patch · updateLow
ClusterRole gateway-operator-gateway-operator-manager-roleapiextensions.k8s.io/customresourcedefinitionslist · watchLow
ClusterRole gateway-operator-gateway-operator-manager-rolegateway-operator.konghq.com/dataplanemetricsextensionsget · list · watchLow
ClusterRole gateway-operator-gateway-operator-manager-rolegateway-operator.konghq.com/dataplanescreate · delete · get · list · patch · update · watchLow
ClusterRole gateway-operator-gateway-operator-manager-rolegateway-operator.konghq.com/dataplanes/finalizersupdateLow
ClusterRole gateway-operator-gateway-operator-manager-rolegateway-operator.konghq.com/dataplanes/statusget · patch · updateLow
ClusterRole gateway-operator-gateway-operator-manager-roleapps/deployments/statusgetLow
ClusterRole gateway-operator-gateway-operator-manager-rolediscovery.k8s.io/endpointslicesget · list · watchLow
ClusterRole gateway-operator-gateway-operator-manager-rolecore/eventscreate · patchLow
Role gateway-operator-gateway-operator-leader-election-rolecore/eventscreate · patchLow
ClusterRole gateway-operator-gateway-operator-manager-rolegateway.networking.k8s.io/gatewayclassesget · list · watchLow
ClusterRole gateway-operator-gateway-operator-manager-rolegateway.networking.k8s.io/gatewayclasses/statusget · patch · updateLow
ClusterRole gateway-operator-gateway-operator-manager-rolegateway-operator.konghq.com/gatewayconfigurationsget · list · watchLow
ClusterRole gateway-operator-gateway-operator-manager-rolegateway.networking.k8s.io/gatewayscreate · delete · get · list · patch · update · watchLow
ClusterRole gateway-operator-gateway-operator-manager-rolegateway.networking.k8s.io/gateways/finalizersupdateLow
ClusterRole gateway-operator-gateway-operator-manager-rolegateway.networking.k8s.io/gateways/statusget · patch · updateLow
ClusterRole gateway-operator-gateway-operator-manager-rolegateway.networking.k8s.io/grpcroutesget · list · watchLow
ClusterRole gateway-operator-gateway-operator-manager-rolegateway.networking.k8s.io/grpcroutes/statusget · patch · updateLow
ClusterRole gateway-operator-gateway-operator-manager-roleautoscaling/horizontalpodautoscalerscreate · delete · get · list · patch · watchLow
ClusterRole gateway-operator-gateway-operator-manager-rolegateway.networking.k8s.io/httproutescreate · delete · get · list · patch · update · watchLow
ClusterRole gateway-operator-gateway-operator-manager-rolegateway.networking.k8s.io/httproutes/statusget · updateLow
ClusterRole gateway-operator-gateway-operator-manager-rolenetworking.k8s.io/ingressclassesget · list · watchLow
ClusterRole gateway-operator-gateway-operator-manager-roleconfiguration.konghq.com/ingressclassparametersesget · list · watchLow
ClusterRole gateway-operator-gateway-operator-manager-rolenetworking.k8s.io/ingressesget · list · watchLow
ClusterRole gateway-operator-gateway-operator-manager-rolenetworking.k8s.io/ingresses/statusget · patch · updateLow
ClusterRole gateway-operator-gateway-operator-manager-rolebatch/jobscreate · delete · getLow
ClusterRole gateway-operator-gateway-operator-manager-roleconfiguration.konghq.com/kongcacertificatesget · list · patch · update · watchLow
ClusterRole gateway-operator-gateway-operator-manager-roleconfiguration.konghq.com/kongcacertificates/finalizerspatch · updateLow
ClusterRole gateway-operator-gateway-operator-manager-roleconfiguration.konghq.com/kongcacertificates/statuspatch · updateLow
ClusterRole gateway-operator-gateway-operator-manager-roleconfiguration.konghq.com/kongcertificatesget · list · patch · update · watchLow
ClusterRole gateway-operator-gateway-operator-manager-roleconfiguration.konghq.com/kongcertificates/finalizerspatch · updateLow
ClusterRole gateway-operator-gateway-operator-manager-roleconfiguration.konghq.com/kongcertificates/statuspatch · updateLow
ClusterRole gateway-operator-gateway-operator-manager-roleconfiguration.konghq.com/kongclusterpluginsget · list · watchLow
ClusterRole gateway-operator-gateway-operator-manager-roleconfiguration.konghq.com/kongclusterplugins/statusget · patch · updateLow
ClusterRole gateway-operator-gateway-operator-manager-roleconfiguration.konghq.com/kongconsumergroupsget · list · patch · update · watchLow
ClusterRole gateway-operator-gateway-operator-manager-roleconfiguration.konghq.com/kongconsumergroups/finalizerspatch · updateLow
ClusterRole gateway-operator-gateway-operator-manager-roleconfiguration.konghq.com/kongconsumergroups/statusget · patch · updateLow
ClusterRole gateway-operator-gateway-operator-manager-roleconfiguration.konghq.com/kongconsumersget · list · patch · update · watchLow
ClusterRole gateway-operator-gateway-operator-manager-roleconfiguration.konghq.com/kongconsumers/finalizerspatch · updateLow
ClusterRole gateway-operator-gateway-operator-manager-roleconfiguration.konghq.com/kongconsumers/statusget · patch · updateLow
ClusterRole gateway-operator-gateway-operator-manager-roleconfiguration.konghq.com/kongcredentialaclsget · list · patch · update · watchLow
ClusterRole gateway-operator-gateway-operator-manager-roleconfiguration.konghq.com/kongcredentialacls/finalizerspatch · updateLow
ClusterRole gateway-operator-gateway-operator-manager-roleconfiguration.konghq.com/kongcredentialacls/statuspatch · updateLow
ClusterRole gateway-operator-gateway-operator-manager-roleconfiguration.konghq.com/kongcredentialapikeysget · list · patch · update · watchLow
ClusterRole gateway-operator-gateway-operator-manager-roleconfiguration.konghq.com/kongcredentialapikeys/finalizerspatch · updateLow
ClusterRole gateway-operator-gateway-operator-manager-roleconfiguration.konghq.com/kongcredentialapikeys/statuspatch · updateLow
ClusterRole gateway-operator-gateway-operator-manager-roleconfiguration.konghq.com/kongcredentialbasicauthsget · list · patch · update · watchLow
ClusterRole gateway-operator-gateway-operator-manager-roleconfiguration.konghq.com/kongcredentialbasicauths/finalizerspatch · updateLow
ClusterRole gateway-operator-gateway-operator-manager-roleconfiguration.konghq.com/kongcredentialbasicauths/statuspatch · updateLow
ClusterRole gateway-operator-gateway-operator-manager-roleconfiguration.konghq.com/kongcredentialhmacsget · list · patch · update · watchLow
ClusterRole gateway-operator-gateway-operator-manager-roleconfiguration.konghq.com/kongcredentialhmacs/finalizerspatch · updateLow
ClusterRole gateway-operator-gateway-operator-manager-roleconfiguration.konghq.com/kongcredentialhmacs/statuspatch · updateLow
ClusterRole gateway-operator-gateway-operator-manager-roleconfiguration.konghq.com/kongcredentialjwtsget · list · patch · update · watchLow
ClusterRole gateway-operator-gateway-operator-manager-roleconfiguration.konghq.com/kongcredentialjwts/finalizerspatch · updateLow
ClusterRole gateway-operator-gateway-operator-manager-roleconfiguration.konghq.com/kongcredentialjwts/statuspatch · updateLow
ClusterRole gateway-operator-gateway-operator-manager-roleconfiguration.konghq.com/kongcustomentitiesget · list · watchLow
ClusterRole gateway-operator-gateway-operator-manager-roleconfiguration.konghq.com/kongcustomentities/statusget · patch · updateLow
ClusterRole gateway-operator-gateway-operator-manager-roleconfiguration.konghq.com/kongdataplaneclientcertificatesget · list · patch · update · watchLow
ClusterRole gateway-operator-gateway-operator-manager-roleconfiguration.konghq.com/kongdataplaneclientcertificates/finalizerspatch · updateLow
ClusterRole gateway-operator-gateway-operator-manager-roleconfiguration.konghq.com/kongdataplaneclientcertificates/statuspatch · updateLow
ClusterRole gateway-operator-gateway-operator-manager-roleconfiguration.konghq.com/kongingressesget · list · watchLow
ClusterRole gateway-operator-gateway-operator-manager-roleconfiguration.konghq.com/kongingresses/statusget · patch · updateLow
ClusterRole gateway-operator-gateway-operator-manager-roleconfiguration.konghq.com/kongkeysget · list · patch · update · watchLow
ClusterRole gateway-operator-gateway-operator-manager-roleconfiguration.konghq.com/kongkeys/finalizerspatch · updateLow
ClusterRole gateway-operator-gateway-operator-manager-roleconfiguration.konghq.com/kongkeys/statuspatch · updateLow
ClusterRole gateway-operator-gateway-operator-manager-roleconfiguration.konghq.com/kongkeysetsget · list · patch · update · watchLow
ClusterRole gateway-operator-gateway-operator-manager-roleconfiguration.konghq.com/kongkeysets/finalizerspatch · updateLow
ClusterRole gateway-operator-gateway-operator-manager-roleconfiguration.konghq.com/kongkeysets/statuspatch · updateLow
ClusterRole gateway-operator-gateway-operator-manager-roleconfiguration.konghq.com/konglicensesget · list · watchLow
ClusterRole gateway-operator-gateway-operator-manager-roleconfiguration.konghq.com/konglicenses/statusget · patch · updateLow
ClusterRole gateway-operator-gateway-operator-manager-roleconfiguration.konghq.com/kongpluginbindingscreate · delete · get · list · patch · update · watchLow
ClusterRole gateway-operator-gateway-operator-manager-roleconfiguration.konghq.com/kongpluginbindings/statuspatch · updateLow
ClusterRole gateway-operator-gateway-operator-manager-rolegateway-operator.konghq.com/kongplugininstallationsget · list · patch · update · watchLow
ClusterRole gateway-operator-gateway-operator-manager-rolegateway-operator.konghq.com/kongplugininstallations/statusget · patch · updateLow
ClusterRole gateway-operator-gateway-operator-manager-roleconfiguration.konghq.com/kongpluginscreate · delete · get · list · patch · update · watchLow
ClusterRole gateway-operator-gateway-operator-manager-roleconfiguration.konghq.com/kongplugins/statusget · patch · updateLow
ClusterRole gateway-operator-gateway-operator-manager-roleconfiguration.konghq.com/kongroutesget · list · patch · update · watchLow
ClusterRole gateway-operator-gateway-operator-manager-roleconfiguration.konghq.com/kongroutes/finalizerspatch · updateLow
ClusterRole gateway-operator-gateway-operator-manager-roleconfiguration.konghq.com/kongroutes/statuspatch · updateLow
ClusterRole gateway-operator-gateway-operator-manager-roleincubator.ingress-controller.konghq.com/kongservicefacadesget · list · watchLow
ClusterRole gateway-operator-gateway-operator-manager-roleincubator.ingress-controller.konghq.com/kongservicefacades/statusget · patch · updateLow
ClusterRole gateway-operator-gateway-operator-manager-roleconfiguration.konghq.com/kongservicesget · list · patch · update · watchLow
ClusterRole gateway-operator-gateway-operator-manager-roleconfiguration.konghq.com/kongservices/finalizerspatch · updateLow
ClusterRole gateway-operator-gateway-operator-manager-roleconfiguration.konghq.com/kongservices/statuspatch · updateLow
ClusterRole gateway-operator-gateway-operator-manager-roleconfiguration.konghq.com/kongsnisget · list · patch · update · watchLow
ClusterRole gateway-operator-gateway-operator-manager-roleconfiguration.konghq.com/kongsnis/finalizerspatch · updateLow
ClusterRole gateway-operator-gateway-operator-manager-roleconfiguration.konghq.com/kongsnis/statuspatch · updateLow
ClusterRole gateway-operator-gateway-operator-manager-roleconfiguration.konghq.com/kongtargetsget · list · patch · update · watchLow
ClusterRole gateway-operator-gateway-operator-manager-roleconfiguration.konghq.com/kongtargets/finalizerspatch · updateLow
ClusterRole gateway-operator-gateway-operator-manager-roleconfiguration.konghq.com/kongtargets/statuspatch · updateLow
ClusterRole gateway-operator-gateway-operator-manager-roleconfiguration.konghq.com/kongupstreampoliciesget · list · watchLow
ClusterRole gateway-operator-gateway-operator-manager-roleconfiguration.konghq.com/kongupstreampolicies/statusget · patch · updateLow
ClusterRole gateway-operator-gateway-operator-manager-roleconfiguration.konghq.com/kongupstreamsget · list · patch · update · watchLow
ClusterRole gateway-operator-gateway-operator-manager-roleconfiguration.konghq.com/kongupstreams/finalizerspatch · updateLow
ClusterRole gateway-operator-gateway-operator-manager-roleconfiguration.konghq.com/kongupstreams/statuspatch · updateLow
ClusterRole gateway-operator-gateway-operator-manager-roleconfiguration.konghq.com/kongvaultsget · list · patch · update · watchLow
ClusterRole gateway-operator-gateway-operator-manager-roleconfiguration.konghq.com/kongvaults/finalizerspatch · updateLow
ClusterRole gateway-operator-gateway-operator-manager-roleconfiguration.konghq.com/kongvaults/statusget · patch · updateLow
ClusterRole gateway-operator-gateway-operator-manager-rolekonnect.konghq.com/konnectapiauthconfigurationsget · list · patch · update · watchLow
ClusterRole gateway-operator-gateway-operator-manager-rolekonnect.konghq.com/konnectapiauthconfigurations/finalizerspatch · updateLow
ClusterRole gateway-operator-gateway-operator-manager-rolekonnect.konghq.com/konnectapiauthconfigurations/statusget · patch · updateLow
ClusterRole gateway-operator-gateway-operator-manager-rolegateway-operator.konghq.com/konnectextensionsget · list · patch · update · watchLow
ClusterRole gateway-operator-gateway-operator-manager-rolegateway-operator.konghq.com/konnectextensions/finalizerspatch · updateLow
ClusterRole gateway-operator-gateway-operator-manager-rolegateway-operator.konghq.com/konnectextensions/statusget · patch · updateLow
ClusterRole gateway-operator-gateway-operator-manager-rolekonnect.konghq.com/konnectgatewaycontrolplanesget · list · patch · update · watchLow
ClusterRole gateway-operator-gateway-operator-manager-rolekonnect.konghq.com/konnectgatewaycontrolplanes/finalizerspatch · updateLow
ClusterRole gateway-operator-gateway-operator-manager-rolekonnect.konghq.com/konnectgatewaycontrolplanes/statuspatch · updateLow
ClusterRole gateway-operator-gateway-operator-manager-rolecore/namespacesget · list · watchLowClusterStructure InformationDisclosure Reconnaissance
ClusterRole gateway-operator-gateway-operator-manager-rolecore/nodeslist · watchLow
ClusterRole gateway-operator-gateway-operator-manager-rolecore/podsget · list · watchLow
ClusterRole gateway-operator-gateway-operator-manager-rolegateway.networking.k8s.io/referencegrantsget · list · watchLow
ClusterRole gateway-operator-gateway-operator-manager-rolegateway.networking.k8s.io/referencegrants/statusgetLow
ClusterRole gateway-operator-gateway-operator-manager-rolerbac.authorization.k8s.io/rolebindingscreate · delete · getLow
ClusterRole gateway-operator-gateway-operator-manager-rolerbac.authorization.k8s.io/rolescreate · delete · getLow
ClusterRole gateway-operator-gateway-operator-kong-mtls-secret-rolecore/secretscreate · get · list · patch · updateLow
ClusterRole gateway-operator-gateway-operator-manager-rolecore/serviceaccounts/statusgetLow
ClusterRole gateway-operator-gateway-operator-manager-rolecore/services/statusget · patch · updateLow
ClusterRole gateway-operator-gateway-operator-manager-roleconfiguration.konghq.com/tcpingressesget · list · watchLow
ClusterRole gateway-operator-gateway-operator-manager-roleconfiguration.konghq.com/tcpingresses/statusget · patch · updateLow
ClusterRole gateway-operator-gateway-operator-manager-rolegateway.networking.k8s.io/tcproutesget · list · watchLow
ClusterRole gateway-operator-gateway-operator-manager-rolegateway.networking.k8s.io/tcproutes/statusget · updateLow
ClusterRole gateway-operator-gateway-operator-manager-rolegateway.networking.k8s.io/tlsroutesget · list · watchLow
ClusterRole gateway-operator-gateway-operator-manager-rolegateway.networking.k8s.io/tlsroutes/statusget · updateLow
ClusterRole gateway-operator-gateway-operator-manager-roleconfiguration.konghq.com/udpingressesget · list · watchLow
ClusterRole gateway-operator-gateway-operator-manager-roleconfiguration.konghq.com/udpingresses/statusget · patch · updateLow
ClusterRole gateway-operator-gateway-operator-manager-rolegateway.networking.k8s.io/udproutesget · list · watchLow
ClusterRole gateway-operator-gateway-operator-manager-rolegateway.networking.k8s.io/udproutes/statusget · updateLow

⚠️ Potential Abuse (26)

The following security risks were found based on the above permissions:

📦 Workloads (2)

KindNameContainerImage
Deploymentgateway-operator-gateway-operator-controller-managerkube-rbac-proxygcr.io/kubebuilder/kube-rbac-proxy:v0.8.0
Deploymentgateway-operator-gateway-operator-controller-managermanagerdocker.io/kong/gateway-operator:1.4