Description

The Kubedoop operator for Apache airflow

Overview

IdentityNamespaceAutomountSecretsPermissionsWorkloadsRisk
airflow-operatordefault101Critical

Numbers in the last two columns indicate how many bindings or workloads involve each ServiceAccount.


Identities

🤖 airflow-operator

Namespace: default  |  Automount:

🔑 Permissions (10)

RoleResourceVerbsRiskTags
ClusterRole airflow-operatorcore/configmapscreate · delete · get · list · patch · update · watchCriticalConfigMapAccess DataExposure InformationDisclosure PotentialPrivilegeEscalation Tampering
ClusterRole airflow-operatorcore/secretscreate · delete · get · list · patch · update · watchCriticalClusterWideSecretAccess CredentialAccess DataExposure InformationDisclosure Persistence (+4 more)
ClusterRole airflow-operatorcore/servicescreate · delete · get · list · patch · update · watchCriticalDenialOfService NetworkManipulation ServiceExposure Tampering
ClusterRole airflow-operatorapps/statefulsetscreate · delete · get · list · patch · update · watchCriticalPersistence PotentialPrivilegeEscalation PrivilegeEscalation Tampering WorkloadLifecycle
ClusterRole airflow-operatorcore/serviceaccountscreate · delete · get · list · patch · update · watchHighIdentityManagement PotentialPrivilegeEscalation Tampering
ClusterRole airflow-operatorpolicy/poddisruptionbudgetscreate · delete · get · list · patch · update · watchMediumAvailabilityImpact DenialOfService Tampering
ClusterRole airflow-operatorairflow.kubedoop.dev/airflowclusterscreate · delete · get · list · patch · update · watchLow
ClusterRole airflow-operatorairflow.kubedoop.dev/airflowclusters/finalizersupdateLow
ClusterRole airflow-operatorairflow.kubedoop.dev/airflowclusters/statusget · patch · updateLow
ClusterRole airflow-operatorauthentication.kubedoop.dev/authenticationclassesget · list · watchLow

⚠️ Potential Abuse (16)

The following security risks were found based on the above permissions:

📦 Workloads (1)

KindNameContainerImage
Deploymentairflow-operatorairflow-operatorquay.io/zncdatadev/airflow-operator:0.2.0