Description

Kubernetes operator for managing Authorino instances, a K8s-native AuthN/AuthZ service to protect your APIs.

Overview

IdentityNamespaceAutomountSecretsPermissionsWorkloadsRisk
authorino-operatordefault221Critical

Numbers in the last two columns indicate how many bindings or workloads involve each ServiceAccount.


Identities

🤖 authorino-operator

Namespace: default  |  Automount:

🔑 Permissions (22)

RoleResourceVerbsRiskTags
ClusterRole authorino-operator-managercore/configmapscreate · delete · get · list · patch · update · watchCriticalConfigMapAccess DataExposure InformationDisclosure PotentialPrivilegeEscalation Tampering
ClusterRole authorino-operator-managerapps/deploymentscreate · delete · get · list · patch · update · watchCriticalPersistence PotentialPrivilegeEscalation PrivilegeEscalation Tampering WorkloadLifecycle
Role authorino-operator-leader-electioncoordination.k8s.io/leasescreate · delete · get · list · patch · update · watchCriticalControlPlaneDisruption CriticalNamespace DenialOfService Tampering
ClusterRole authorino-operator-managercore/secretsget · list · watchCriticalClusterWideSecretAccess CredentialAccess DataExposure InformationDisclosure SecretAccess
Role authorino-operator-leader-electioncore/configmapscreate · delete · get · list · patch · update · watchHighConfigMapAccess DataExposure InformationDisclosure PotentialPrivilegeEscalation Tampering
ClusterRole authorino-operator-managerrbac.authorization.k8s.io/clusterrolebindingscreate · get · list · update · watchMediumInformationDisclosure RBACQuery Reconnaissance
ClusterRole authorino-operator-managerrbac.authorization.k8s.io/clusterrolescreate · get · list · update · watchMediumInformationDisclosure RBACQuery Reconnaissance
ClusterRole authorino-operator-managerrbac.authorization.k8s.io/rolebindingscreate · get · list · update · watchMediumInformationDisclosure RBACQuery Reconnaissance
ClusterRole authorino-operator-managerrbac.authorization.k8s.io/rolescreate · get · list · update · watchMediumInformationDisclosure RBACQuery Reconnaissance
ClusterRole authorino-operator-managerauthorization.k8s.io/subjectaccessreviewscreateMediumInformationDisclosure RBACQuery
ClusterRole authorino-operator-managerauthentication.k8s.io/tokenreviewscreateMediumCredentialAccess InformationDisclosure RBACQuery
ClusterRole authorino-operator-managerauthorino.kuadrant.io/authconfigscreate · delete · get · list · patch · update · watchLow
ClusterRole authorino-operator-managerauthorino.kuadrant.io/authconfigs/statusget · patch · updateLow
ClusterRole authorino-operator-manageroperator.authorino.kuadrant.io/authorinoscreate · delete · get · list · patch · update · watchLow
ClusterRole authorino-operator-manageroperator.authorino.kuadrant.io/authorinos/finalizersupdateLow
ClusterRole authorino-operator-manageroperator.authorino.kuadrant.io/authorinos/statusget · patch · updateLow
ClusterRole authorino-operator-managercore/configmaps/statusdelete · get · patch · updateLow
ClusterRole authorino-operator-managercore/eventscreate · patchLow
Role authorino-operator-leader-electioncore/eventscreate · patchLow
ClusterRole authorino-operator-managercoordination.k8s.io/leasescreate · get · list · updateLow
ClusterRole authorino-operator-managercore/serviceaccountscreate · get · list · update · watchLow
ClusterRole authorino-operator-managercore/servicescreate · get · list · update · watchLow

⚠️ Potential Abuse (13)

The following security risks were found based on the above permissions:

📦 Workloads (1)

KindNameContainerImage
Deploymentauthorino-operatormanagerquay.io/kuadrant/authorino-operator:v0.18.0