Description

Kubernetes operator for managing Limitador instances, a rate limiting service to protect your APIs.

Overview

IdentityNamespaceAutomountSecretsPermissionsWorkloadsRisk
limitador-operator-controller-managerdefault151Critical

Numbers in the last two columns indicate how many bindings or workloads involve each ServiceAccount.


Identities

🤖 limitador-operator-controller-manager

Namespace: default  |  Automount:

🔑 Permissions (15)

RoleResourceVerbsRiskTags
Role limitador-operator-leader-election-rolecoordination.k8s.io/leasescreate · delete · get · list · patch · update · watchCriticalControlPlaneDisruption CriticalNamespace DenialOfService Tampering
ClusterRole limitador-operator-manager-rolecore/secretscreate · delete · get · list · update · watchCriticalClusterWideSecretAccess CredentialAccess DataExposure InformationDisclosure SecretAccess
ClusterRole limitador-operator-manager-rolecore/configmapscreate · delete · get · list · update · watchHighConfigMapAccess DataExposure InformationDisclosure
Role limitador-operator-leader-election-rolecore/configmapscreate · delete · get · list · patch · update · watchHighConfigMapAccess DataExposure InformationDisclosure PotentialPrivilegeEscalation Tampering
Role limitador-operator-leader-election-rolecoordination.k8s.io/configmapscreate · delete · get · list · patch · update · watchLow
ClusterRole limitador-operator-manager-roleapps/deploymentscreate · delete · get · list · update · watchLow
Role limitador-operator-leader-election-rolecore/eventscreate · patchLow
Role limitador-operator-leader-election-rolecore/leasescreate · delete · get · list · patch · update · watchLow
ClusterRole limitador-operator-manager-rolelimitador.kuadrant.io/limitadorscreate · delete · get · list · patch · update · watchLow
ClusterRole limitador-operator-manager-rolelimitador.kuadrant.io/limitadors/finalizersupdateLow
ClusterRole limitador-operator-manager-rolelimitador.kuadrant.io/limitadors/statusget · patch · updateLow
ClusterRole limitador-operator-manager-rolecore/persistentvolumeclaimscreate · delete · get · list · update · watchLow
ClusterRole limitador-operator-manager-rolepolicy/poddisruptionbudgetscreate · delete · get · list · update · watchLow
ClusterRole limitador-operator-manager-rolecore/podslist · update · watchLow
ClusterRole limitador-operator-manager-rolecore/servicescreate · delete · get · list · update · watchLow

⚠️ Potential Abuse (7)

The following security risks were found based on the above permissions:

📦 Workloads (1)

KindNameContainerImage
Deploymentlimitador-operator-controller-managermanagerquay.io/kuadrant/limitador-operator:v0.14.0