Description

Deploy Kong Gateway Operator

Overview

IdentityNamespaceAutomountSecretsPermissionsWorkloadsRisk
controller-managerdefault1621Critical

Numbers in the last two columns indicate how many bindings or workloads involve each ServiceAccount.


Identities

🤖 controller-manager

Namespace: default  |  Automount:

🔑 Permissions (162)

RoleResourceVerbsRiskTags
ClusterRole gateway-operator-gateway-operator-manager-rolerbac.authorization.k8s.io/clusterrolebindingscreate · delete · get · list · patch · update · watchCriticalBindingToPrivilegedRole ClusterAdminAccess InformationDisclosure PrivilegeEscalation RBACManipulation (+2 more)
ClusterRole gateway-operator-gateway-operator-manager-rolerbac.authorization.k8s.io/clusterrolescreate · delete · get · list · patch · update · watchCriticalClusterAdminAccess InformationDisclosure PrivilegeEscalation RBACManipulation RBACQuery (+1 more)
ClusterRole gateway-operator-gateway-operator-manager-rolecore/configmapscreate · delete · get · list · patch · update · watchCriticalConfigMapAccess DataExposure InformationDisclosure PotentialPrivilegeEscalation Tampering
ClusterRole gateway-operator-gateway-operator-manager-roleapps/deploymentscreate · delete · get · list · patch · update · watchCriticalPersistence PotentialPrivilegeEscalation PrivilegeEscalation Tampering WorkloadLifecycle
ClusterRole gateway-operator-gateway-operator-manager-rolecoordination.k8s.io/leasescreate · delete · get · list · patch · update · watchCriticalControlPlaneDisruption CriticalNamespace DenialOfService LeaderElectionAbuse Tampering
Role gateway-operator-gateway-operator-leader-election-rolecoordination.k8s.io/leasescreate · delete · get · list · patch · update · watchCriticalControlPlaneDisruption CriticalNamespace DenialOfService Tampering
ClusterRole gateway-operator-gateway-operator-manager-rolenetworking.k8s.io/networkpoliciescreate · delete · get · list · patch · update · watchCriticalDenialOfService LateralMovement NetworkManipulation NetworkPolicyManagement Tampering
ClusterRole gateway-operator-gateway-operator-manager-rolecore/secretsdelete · get · list · patch · update · watchCriticalClusterWideSecretAccess CredentialAccess DataExposure InformationDisclosure SecretAccess
ClusterRole gateway-operator-gateway-operator-manager-rolecore/servicescreate · delete · get · list · patch · update · watchCriticalDenialOfService NetworkManipulation ServiceExposure Tampering
ClusterRole gateway-operator-gateway-operator-manager-roleadmissionregistration.k8s.io/validatingwebhookconfigurationscreate · delete · get · list · patch · update · watchCriticalDenialOfService InformationDisclosure Reconnaissance Tampering WebhookManipulation (+1 more)
Role gateway-operator-gateway-operator-leader-election-rolecore/configmapscreate · delete · get · list · patch · update · watchHighConfigMapAccess DataExposure InformationDisclosure PotentialPrivilegeEscalation Tampering
ClusterRole gateway-operator-gateway-operator-manager-rolerbac.authorization.k8s.io/rolebindingscreate · delete · get · list · patch · update · watchHighBindingToPrivilegedRole InformationDisclosure PrivilegeEscalation RBACManipulation RBACQuery (+1 more)
ClusterRole gateway-operator-gateway-operator-manager-rolerbac.authorization.k8s.io/rolescreate · delete · get · list · patch · update · watchHighInformationDisclosure PrivilegeEscalation RBACManipulation RBACQuery Reconnaissance
ClusterRole gateway-operator-gateway-operator-manager-rolecore/serviceaccountscreate · delete · get · list · patch · update · watchHighIdentityManagement PotentialPrivilegeEscalation Tampering
ClusterRole gateway-operator-gateway-operator-manager-rolepolicy/poddisruptionbudgetscreate · delete · get · list · patch · update · watchMediumAvailabilityImpact DenialOfService Tampering
ClusterRole gateway-operator-gateway-operator-proxy-roleauthorization.k8s.io/subjectaccessreviewscreateMediumInformationDisclosure RBACQuery
ClusterRole gateway-operator-gateway-operator-proxy-roleauthentication.k8s.io/tokenreviewscreateMediumCredentialAccess InformationDisclosure RBACQuery
ClusterRole gateway-operator-gateway-operator-manager-rolegateway-operator.konghq.com/aigatewayscreate · delete · get · list · patch · update · watchLow
ClusterRole gateway-operator-gateway-operator-manager-rolegateway-operator.konghq.com/aigateways/finalizersupdateLow
ClusterRole gateway-operator-gateway-operator-manager-rolegateway-operator.konghq.com/aigateways/statuspatch · updateLow
ClusterRole gateway-operator-gateway-operator-manager-rolegateway.networking.k8s.io/backendtlspoliciesget · list · watchLow
ClusterRole gateway-operator-gateway-operator-manager-rolegateway.networking.k8s.io/backendtlspolicies/statuspatch · updateLow
ClusterRole gateway-operator-gateway-operator-manager-rolecert-manager.io/certificatescreate · delete · get · list · patch · update · watchLow
ClusterRole gateway-operator-gateway-operator-manager-rolegateway-operator.konghq.com/controlplaneget · list · watchLow
ClusterRole gateway-operator-gateway-operator-manager-rolegateway-operator.konghq.com/controlplanescreate · delete · get · list · patch · update · watchLow
ClusterRole gateway-operator-gateway-operator-manager-rolegateway-operator.konghq.com/controlplanes/finalizersupdateLow
ClusterRole gateway-operator-gateway-operator-manager-rolegateway-operator.konghq.com/controlplanes/statuspatch · updateLow
ClusterRole gateway-operator-gateway-operator-manager-roleapiextensions.k8s.io/customresourcedefinitionslist · watchLow
ClusterRole gateway-operator-gateway-operator-manager-rolegateway-operator.konghq.com/dataplanemetricsextensionsget · list · watchLow
ClusterRole gateway-operator-gateway-operator-manager-rolegateway-operator.konghq.com/dataplanescreate · delete · get · list · patch · update · watchLow
ClusterRole gateway-operator-gateway-operator-manager-rolegateway-operator.konghq.com/dataplanes/finalizersupdateLow
ClusterRole gateway-operator-gateway-operator-manager-rolegateway-operator.konghq.com/dataplanes/statuspatch · updateLow
ClusterRole gateway-operator-gateway-operator-manager-rolediscovery.k8s.io/endpointslicesget · list · watchLow
ClusterRole gateway-operator-gateway-operator-manager-rolecore/eventscreate · patchLow
Role gateway-operator-gateway-operator-leader-election-rolecore/eventscreate · patchLow
ClusterRole gateway-operator-gateway-operator-manager-rolegateway.networking.k8s.io/gatewayclassesget · list · watchLow
ClusterRole gateway-operator-gateway-operator-manager-rolegateway.networking.k8s.io/gatewayclasses/statusget · patch · updateLow
ClusterRole gateway-operator-gateway-operator-manager-rolegateway-operator.konghq.com/gatewayconfigurationsget · list · watchLow
ClusterRole gateway-operator-gateway-operator-manager-rolegateway.networking.k8s.io/gatewayscreate · delete · get · list · patch · update · watchLow
ClusterRole gateway-operator-gateway-operator-manager-rolegateway.networking.k8s.io/gateways/finalizersupdateLow
ClusterRole gateway-operator-gateway-operator-manager-rolegateway.networking.k8s.io/gateways/statusget · patch · updateLow
ClusterRole gateway-operator-gateway-operator-manager-rolegateway.networking.k8s.io/grpcroutesget · list · watchLow
ClusterRole gateway-operator-gateway-operator-manager-rolegateway.networking.k8s.io/grpcroutes/statusget · patch · updateLow
ClusterRole gateway-operator-gateway-operator-manager-roleautoscaling/horizontalpodautoscalerscreate · delete · get · list · patch · watchLow
ClusterRole gateway-operator-gateway-operator-manager-rolegateway.networking.k8s.io/httproutescreate · delete · get · list · patch · update · watchLow
ClusterRole gateway-operator-gateway-operator-manager-rolegateway.networking.k8s.io/httproutes/statusget · updateLow
ClusterRole gateway-operator-gateway-operator-manager-rolenetworking.k8s.io/ingressclassesget · list · watchLow
ClusterRole gateway-operator-gateway-operator-manager-roleconfiguration.konghq.com/ingressclassparametersesget · list · watchLow
ClusterRole gateway-operator-gateway-operator-manager-rolenetworking.k8s.io/ingressesget · list · watchLow
ClusterRole gateway-operator-gateway-operator-manager-rolenetworking.k8s.io/ingresses/statusget · patch · updateLow
ClusterRole gateway-operator-gateway-operator-manager-roleconfiguration.konghq.com/kongcacertificatesget · list · patch · update · watchLow
ClusterRole gateway-operator-gateway-operator-manager-roleconfiguration.konghq.com/kongcacertificates/finalizerspatch · updateLow
ClusterRole gateway-operator-gateway-operator-manager-roleconfiguration.konghq.com/kongcacertificates/statuspatch · updateLow
ClusterRole gateway-operator-gateway-operator-manager-roleconfiguration.konghq.com/kongcertificatesget · list · patch · update · watchLow
ClusterRole gateway-operator-gateway-operator-manager-roleconfiguration.konghq.com/kongcertificates/finalizerspatch · updateLow
ClusterRole gateway-operator-gateway-operator-manager-roleconfiguration.konghq.com/kongcertificates/statuspatch · updateLow
ClusterRole gateway-operator-gateway-operator-manager-roleconfiguration.konghq.com/kongclusterpluginsget · list · watchLow
ClusterRole gateway-operator-gateway-operator-manager-roleconfiguration.konghq.com/kongclusterplugins/statusget · patch · updateLow
ClusterRole gateway-operator-gateway-operator-manager-roleconfiguration.konghq.com/kongconsumergroupsget · list · patch · update · watchLow
ClusterRole gateway-operator-gateway-operator-manager-roleconfiguration.konghq.com/kongconsumergroups/finalizerspatch · updateLow
ClusterRole gateway-operator-gateway-operator-manager-roleconfiguration.konghq.com/kongconsumergroups/statusget · patch · updateLow
ClusterRole gateway-operator-gateway-operator-manager-roleconfiguration.konghq.com/kongconsumersget · list · patch · update · watchLow
ClusterRole gateway-operator-gateway-operator-manager-roleconfiguration.konghq.com/kongconsumers/finalizerspatch · updateLow
ClusterRole gateway-operator-gateway-operator-manager-roleconfiguration.konghq.com/kongconsumers/statusget · patch · updateLow
ClusterRole gateway-operator-gateway-operator-manager-roleconfiguration.konghq.com/kongcredentialaclscreate · delete · get · list · patch · update · watchLow
ClusterRole gateway-operator-gateway-operator-manager-roleconfiguration.konghq.com/kongcredentialacls/finalizerspatch · updateLow
ClusterRole gateway-operator-gateway-operator-manager-roleconfiguration.konghq.com/kongcredentialacls/statuspatch · updateLow
ClusterRole gateway-operator-gateway-operator-manager-roleconfiguration.konghq.com/kongcredentialapikeyscreate · delete · get · list · patch · update · watchLow
ClusterRole gateway-operator-gateway-operator-manager-roleconfiguration.konghq.com/kongcredentialapikeys/finalizerspatch · updateLow
ClusterRole gateway-operator-gateway-operator-manager-roleconfiguration.konghq.com/kongcredentialapikeys/statuspatch · updateLow
ClusterRole gateway-operator-gateway-operator-manager-roleconfiguration.konghq.com/kongcredentialbasicauthscreate · delete · get · list · patch · update · watchLow
ClusterRole gateway-operator-gateway-operator-manager-roleconfiguration.konghq.com/kongcredentialbasicauths/finalizerspatch · updateLow
ClusterRole gateway-operator-gateway-operator-manager-roleconfiguration.konghq.com/kongcredentialbasicauths/statuspatch · updateLow
ClusterRole gateway-operator-gateway-operator-manager-roleconfiguration.konghq.com/kongcredentialhmacscreate · delete · get · list · patch · update · watchLow
ClusterRole gateway-operator-gateway-operator-manager-roleconfiguration.konghq.com/kongcredentialhmacs/finalizerspatch · updateLow
ClusterRole gateway-operator-gateway-operator-manager-roleconfiguration.konghq.com/kongcredentialhmacs/statuspatch · updateLow
ClusterRole gateway-operator-gateway-operator-manager-roleconfiguration.konghq.com/kongcredentialjwtscreate · delete · get · list · patch · update · watchLow
ClusterRole gateway-operator-gateway-operator-manager-roleconfiguration.konghq.com/kongcredentialjwts/finalizerspatch · updateLow
ClusterRole gateway-operator-gateway-operator-manager-roleconfiguration.konghq.com/kongcredentialjwts/statuspatch · updateLow
ClusterRole gateway-operator-gateway-operator-manager-roleconfiguration.konghq.com/kongcustomentitiesget · list · watchLow
ClusterRole gateway-operator-gateway-operator-manager-roleconfiguration.konghq.com/kongcustomentities/statusget · patch · updateLow
ClusterRole gateway-operator-gateway-operator-manager-roleconfiguration.konghq.com/kongdataplaneclientcertificatesget · list · patch · update · watchLow
ClusterRole gateway-operator-gateway-operator-manager-roleconfiguration.konghq.com/kongdataplaneclientcertificates/finalizerspatch · updateLow
ClusterRole gateway-operator-gateway-operator-manager-roleconfiguration.konghq.com/kongdataplaneclientcertificates/statuspatch · updateLow
ClusterRole gateway-operator-gateway-operator-manager-roleconfiguration.konghq.com/kongingressesget · list · watchLow
ClusterRole gateway-operator-gateway-operator-manager-roleconfiguration.konghq.com/kongingresses/statusget · patch · updateLow
ClusterRole gateway-operator-gateway-operator-manager-roleconfiguration.konghq.com/kongkeysget · list · patch · update · watchLow
ClusterRole gateway-operator-gateway-operator-manager-roleconfiguration.konghq.com/kongkeys/finalizerspatch · updateLow
ClusterRole gateway-operator-gateway-operator-manager-roleconfiguration.konghq.com/kongkeys/statuspatch · updateLow
ClusterRole gateway-operator-gateway-operator-manager-roleconfiguration.konghq.com/kongkeysetsget · list · patch · update · watchLow
ClusterRole gateway-operator-gateway-operator-manager-roleconfiguration.konghq.com/kongkeysets/finalizerspatch · updateLow
ClusterRole gateway-operator-gateway-operator-manager-roleconfiguration.konghq.com/kongkeysets/statuspatch · updateLow
ClusterRole gateway-operator-gateway-operator-manager-roleconfiguration.konghq.com/konglicensesget · list · watchLow
ClusterRole gateway-operator-gateway-operator-manager-roleconfiguration.konghq.com/konglicenses/statusget · patch · updateLow
ClusterRole gateway-operator-gateway-operator-manager-roleconfiguration.konghq.com/kongpluginbindingscreate · delete · get · list · patch · update · watchLow
ClusterRole gateway-operator-gateway-operator-manager-roleconfiguration.konghq.com/kongpluginbindings/statuspatch · updateLow
ClusterRole gateway-operator-gateway-operator-manager-rolegateway-operator.konghq.com/kongplugininstallationsget · list · patch · update · watchLow
ClusterRole gateway-operator-gateway-operator-manager-rolegateway-operator.konghq.com/kongplugininstallations/statuspatch · updateLow
ClusterRole gateway-operator-gateway-operator-manager-roleconfiguration.konghq.com/kongpluginscreate · delete · get · list · patch · update · watchLow
ClusterRole gateway-operator-gateway-operator-manager-roleconfiguration.konghq.com/kongplugins/statusget · patch · updateLow
ClusterRole gateway-operator-gateway-operator-manager-roleconfiguration.konghq.com/kongroutesdelete · get · list · patch · update · watchLow
ClusterRole gateway-operator-gateway-operator-manager-roleconfiguration.konghq.com/kongroutes/finalizerspatch · updateLow
ClusterRole gateway-operator-gateway-operator-manager-roleconfiguration.konghq.com/kongroutes/statuspatch · updateLow
ClusterRole gateway-operator-gateway-operator-manager-roleincubator.ingress-controller.konghq.com/kongservicefacadesget · list · watchLow
ClusterRole gateway-operator-gateway-operator-manager-roleincubator.ingress-controller.konghq.com/kongservicefacades/statusget · patch · updateLow
ClusterRole gateway-operator-gateway-operator-manager-roleconfiguration.konghq.com/kongservicesget · list · patch · update · watchLow
ClusterRole gateway-operator-gateway-operator-manager-roleconfiguration.konghq.com/kongservices/finalizerspatch · updateLow
ClusterRole gateway-operator-gateway-operator-manager-roleconfiguration.konghq.com/kongservices/statuspatch · updateLow
ClusterRole gateway-operator-gateway-operator-manager-roleconfiguration.konghq.com/kongsnisget · list · patch · update · watchLow
ClusterRole gateway-operator-gateway-operator-manager-roleconfiguration.konghq.com/kongsnis/finalizerspatch · updateLow
ClusterRole gateway-operator-gateway-operator-manager-roleconfiguration.konghq.com/kongsnis/statuspatch · updateLow
ClusterRole gateway-operator-gateway-operator-manager-roleconfiguration.konghq.com/kongtargetsget · list · patch · update · watchLow
ClusterRole gateway-operator-gateway-operator-manager-roleconfiguration.konghq.com/kongtargets/finalizerspatch · updateLow
ClusterRole gateway-operator-gateway-operator-manager-roleconfiguration.konghq.com/kongtargets/statuspatch · updateLow
ClusterRole gateway-operator-gateway-operator-manager-roleconfiguration.konghq.com/kongupstreampoliciesget · list · watchLow
ClusterRole gateway-operator-gateway-operator-manager-roleconfiguration.konghq.com/kongupstreampolicies/statusget · patch · updateLow
ClusterRole gateway-operator-gateway-operator-manager-roleconfiguration.konghq.com/kongupstreamsget · list · patch · update · watchLow
ClusterRole gateway-operator-gateway-operator-manager-roleconfiguration.konghq.com/kongupstreams/finalizerspatch · updateLow
ClusterRole gateway-operator-gateway-operator-manager-roleconfiguration.konghq.com/kongupstreams/statuspatch · updateLow
ClusterRole gateway-operator-gateway-operator-manager-roleconfiguration.konghq.com/kongvaultsget · list · patch · update · watchLow
ClusterRole gateway-operator-gateway-operator-manager-roleconfiguration.konghq.com/kongvaults/finalizerspatch · updateLow
ClusterRole gateway-operator-gateway-operator-manager-roleconfiguration.konghq.com/kongvaults/statusget · patch · updateLow
ClusterRole gateway-operator-gateway-operator-manager-rolekonnect.konghq.com/konnectapiauthconfigurationsget · list · patch · update · watchLow
ClusterRole gateway-operator-gateway-operator-manager-rolekonnect.konghq.com/konnectapiauthconfigurations/finalizerspatch · updateLow
ClusterRole gateway-operator-gateway-operator-manager-rolekonnect.konghq.com/konnectapiauthconfigurations/statuspatch · updateLow
ClusterRole gateway-operator-gateway-operator-manager-rolekonnect.konghq.com/konnectcloudgatewaydataplanegroupconfigurationsget · list · patch · update · watchLow
ClusterRole gateway-operator-gateway-operator-manager-rolekonnect.konghq.com/konnectcloudgatewaydataplanegroupconfigurations/finalizerspatch · updateLow
ClusterRole gateway-operator-gateway-operator-manager-rolekonnect.konghq.com/konnectcloudgatewaydataplanegroupconfigurations/statuspatch · updateLow
ClusterRole gateway-operator-gateway-operator-manager-rolekonnect.konghq.com/konnectcloudgatewaynetworksget · list · patch · update · watchLow
ClusterRole gateway-operator-gateway-operator-manager-rolekonnect.konghq.com/konnectcloudgatewaynetworks/finalizerspatch · updateLow
ClusterRole gateway-operator-gateway-operator-manager-rolekonnect.konghq.com/konnectcloudgatewaynetworks/statuspatch · updateLow
ClusterRole gateway-operator-gateway-operator-manager-rolekonnect.konghq.com/konnectcloudgatewaytransitgatewaysget · list · patch · update · watchLow
ClusterRole gateway-operator-gateway-operator-manager-rolekonnect.konghq.com/konnectcloudgatewaytransitgateways/finalizerspatch · updateLow
ClusterRole gateway-operator-gateway-operator-manager-rolekonnect.konghq.com/konnectcloudgatewaytransitgateways/statuspatch · updateLow
ClusterRole gateway-operator-gateway-operator-manager-rolegateway-operator.konghq.com/konnectextensionsget · list · patch · update · watchLow
ClusterRole gateway-operator-gateway-operator-manager-rolekonnect.konghq.com/konnectextensionsget · list · patch · update · watchLow
ClusterRole gateway-operator-gateway-operator-manager-rolegateway-operator.konghq.com/konnectextensions/finalizerspatch · updateLow
ClusterRole gateway-operator-gateway-operator-manager-rolekonnect.konghq.com/konnectextensions/finalizerspatch · updateLow
ClusterRole gateway-operator-gateway-operator-manager-rolegateway-operator.konghq.com/konnectextensions/statuspatch · updateLow
ClusterRole gateway-operator-gateway-operator-manager-rolekonnect.konghq.com/konnectextensions/statuspatch · updateLow
ClusterRole gateway-operator-gateway-operator-manager-rolekonnect.konghq.com/konnectgatewaycontrolplanesget · list · patch · update · watchLow
ClusterRole gateway-operator-gateway-operator-manager-rolekonnect.konghq.com/konnectgatewaycontrolplanes/finalizerspatch · updateLow
ClusterRole gateway-operator-gateway-operator-manager-rolekonnect.konghq.com/konnectgatewaycontrolplanes/statuspatch · updateLow
ClusterRole gateway-operator-gateway-operator-manager-rolecore/namespacesget · list · watchLowClusterStructure InformationDisclosure Reconnaissance
ClusterRole gateway-operator-gateway-operator-manager-rolecore/nodeslist · watchLow
ClusterRole gateway-operator-gateway-operator-manager-rolecore/podsget · list · watchLow
ClusterRole gateway-operator-gateway-operator-manager-rolegateway.networking.k8s.io/referencegrantsget · list · watchLow
ClusterRole gateway-operator-gateway-operator-manager-rolegateway.networking.k8s.io/referencegrants/statusgetLow
ClusterRole gateway-operator-gateway-operator-kong-mtls-secret-rolecore/secretscreate · get · list · patch · updateLow
ClusterRole gateway-operator-gateway-operator-manager-rolecore/secrets/finalizerspatch · updateLow
ClusterRole gateway-operator-gateway-operator-manager-rolecore/services/statusget · patch · updateLow
ClusterRole gateway-operator-gateway-operator-manager-roleconfiguration.konghq.com/tcpingressesget · list · watchLow
ClusterRole gateway-operator-gateway-operator-manager-roleconfiguration.konghq.com/tcpingresses/statusget · patch · updateLow
ClusterRole gateway-operator-gateway-operator-manager-rolegateway.networking.k8s.io/tcproutesget · list · watchLow
ClusterRole gateway-operator-gateway-operator-manager-rolegateway.networking.k8s.io/tcproutes/statusget · updateLow
ClusterRole gateway-operator-gateway-operator-manager-rolegateway.networking.k8s.io/tlsroutesget · list · watchLow
ClusterRole gateway-operator-gateway-operator-manager-rolegateway.networking.k8s.io/tlsroutes/statusget · updateLow
ClusterRole gateway-operator-gateway-operator-manager-roleconfiguration.konghq.com/udpingressesget · list · watchLow
ClusterRole gateway-operator-gateway-operator-manager-roleconfiguration.konghq.com/udpingresses/statusget · patch · updateLow
ClusterRole gateway-operator-gateway-operator-manager-rolegateway.networking.k8s.io/udproutesget · list · watchLow
ClusterRole gateway-operator-gateway-operator-manager-rolegateway.networking.k8s.io/udproutes/statusget · updateLow
ClusterRole gateway-operator-gateway-operator-manager-rolegateway-operator.konghq.com/watchnamespacegrantslist · watchLow

⚠️ Potential Abuse (28)

The following security risks were found based on the above permissions:

📦 Workloads (1)

KindNameContainerImage
Deploymentgateway-operator-gateway-operator-controller-managermanagerdocker.io/kong/gateway-operator:1.6