Description

The Kubedoop operator for Apache HDFS

Overview

IdentityNamespaceAutomountSecretsPermissionsWorkloadsRisk
hdfs-operatordefault111Critical

Numbers in the last two columns indicate how many bindings or workloads involve each ServiceAccount.


Identities

🤖 hdfs-operator

Namespace: default  |  Automount:

🔑 Permissions (11)

RoleResourceVerbsRiskTags
ClusterRole hdfs-operatorcore/configmapscreate · delete · get · list · patch · update · watchCriticalConfigMapAccess DataExposure InformationDisclosure PotentialPrivilegeEscalation Tampering
ClusterRole hdfs-operatorcore/secretscreate · delete · get · list · patch · update · watchCriticalClusterWideSecretAccess CredentialAccess DataExposure InformationDisclosure Persistence (+4 more)
ClusterRole hdfs-operatorcore/servicescreate · delete · get · list · patch · update · watchCriticalDenialOfService NetworkManipulation ServiceExposure Tampering
ClusterRole hdfs-operatorapps/statefulsetscreate · delete · get · list · patch · update · watchCriticalPersistence PotentialPrivilegeEscalation PrivilegeEscalation Tampering WorkloadLifecycle
ClusterRole hdfs-operatorcore/serviceaccountscreate · delete · get · list · patch · update · watchHighIdentityManagement PotentialPrivilegeEscalation Tampering
ClusterRole hdfs-operatorauthentication.kubedoop.dev/authenticationclassesget · list · watchLow
ClusterRole hdfs-operatorhdfs.kubedoop.dev/hdfsclusterscreate · delete · get · list · patch · update · watchLow
ClusterRole hdfs-operatorhdfs.kubedoop.dev/hdfsclusters/finalizersupdateLow
ClusterRole hdfs-operatorhdfs.kubedoop.dev/hdfsclusters/statusget · patch · updateLow
ClusterRole hdfs-operatorlisteners.kubedoop.dev/listenerscreate · delete · get · list · patch · update · watchLow
ClusterRole hdfs-operatorcore/podsget · list · watchLow

⚠️ Potential Abuse (15)

The following security risks were found based on the above permissions:

📦 Workloads (1)

KindNameContainerImage
Deploymenthdfs-operatorhdfs-operatorquay.io/zncdatadev/hdfs-operator:0.2.0