Description

Kubernetes operator responsible for reconciling DNS Record custom resources.

Overview

IdentityNamespaceAutomountSecretsPermissionsWorkloadsRisk
dns-operator-controller-managerdefault111Critical
dns-operator-remote-clusterdefault20Low

Numbers in the last two columns indicate how many bindings or workloads involve each ServiceAccount.


Identities

🤖 dns-operator-controller-manager

Namespace: default  |  Automount:

🔑 Permissions (11)

RoleResourceVerbsRiskTags
Role dns-operator-leader-election-rolecoordination.k8s.io/leasescreate · delete · get · list · patch · update · watchCriticalControlPlaneDisruption CriticalNamespace DenialOfService Tampering
ClusterRole dns-operator-manager-rolecore/secretsget · list · watchCriticalClusterWideSecretAccess CredentialAccess DataExposure InformationDisclosure SecretAccess
Role dns-operator-leader-election-rolecore/configmapscreate · delete · get · list · patch · update · watchHighConfigMapAccess DataExposure InformationDisclosure PotentialPrivilegeEscalation Tampering
ClusterRole dns-operator-manager-rolekuadrant.io/dnshealthcheckprobescreate · delete · get · list · patch · update · watchLow
ClusterRole dns-operator-manager-rolekuadrant.io/dnshealthcheckprobes/finalizersupdateLow
ClusterRole dns-operator-manager-rolekuadrant.io/dnshealthcheckprobes/statusget · patch · updateLow
ClusterRole dns-operator-manager-rolekuadrant.io/dnsrecordscreate · delete · get · list · patch · update · watchLow
ClusterRole dns-operator-manager-rolekuadrant.io/dnsrecords/finalizersupdateLow
ClusterRole dns-operator-manager-rolekuadrant.io/dnsrecords/statusget · patch · updateLow
Role dns-operator-leader-election-rolecore/eventscreate · patchLow
ClusterRole dns-operator-manager-rolecore/namespacesget · list · watchLowClusterStructure InformationDisclosure Reconnaissance

⚠️ Potential Abuse (7)

The following security risks were found based on the above permissions:

📦 Workloads (1)

KindNameContainerImage
Deploymentdns-operator-controller-managermanagerquay.io/kuadrant/dns-operator:v0.15.0

🤖 dns-operator-remote-cluster

Namespace: default  |  Automount:

🔑 Permissions (2)

RoleResourceVerbsRiskTags
ClusterRole dns-operator-remote-cluster-rolekuadrant.io/dnsrecordsget · list · watchLow
ClusterRole dns-operator-remote-cluster-rolekuadrant.io/dnsrecords/statusget · patch · updateLow

⚠️ Potential Abuse (1)

The following security risks were found based on the above permissions:

📦 Workloads (0)

No workloads use this ServiceAccount.