Description

The Kubedoop Operator for Apache Hive

Overview

IdentityNamespaceAutomountSecretsPermissionsWorkloadsRisk
hive-operatordefault101Critical

Numbers in the last two columns indicate how many bindings or workloads involve each ServiceAccount.


Identities

🤖 hive-operator

Namespace: default  |  Automount:

🔑 Permissions (10)

RoleResourceVerbsRiskTags
ClusterRole hive-operatorcore/configmapscreate · delete · get · list · patch · update · watchCriticalConfigMapAccess DataExposure InformationDisclosure PotentialPrivilegeEscalation Tampering
ClusterRole hive-operatorcore/servicescreate · delete · get · list · patch · update · watchCriticalDenialOfService NetworkManipulation ServiceExposure Tampering
ClusterRole hive-operatorapps/statefulsetscreate · delete · get · list · patch · update · watchCriticalPersistence PotentialPrivilegeEscalation PrivilegeEscalation Tampering WorkloadLifecycle
ClusterRole hive-operatorpolicy/poddisruptionbudgetscreate · delete · get · list · patch · update · watchMediumAvailabilityImpact DenialOfService Tampering
ClusterRole hive-operatorhive.kubedoop.dev/hivemetastorescreate · delete · get · list · patch · update · watchLow
ClusterRole hive-operatorhive.kubedoop.dev/hivemetastores/finalizersupdateLow
ClusterRole hive-operatorhive.kubedoop.dev/hivemetastores/statusget · patch · updateLow
ClusterRole hive-operatorcore/podsget · list · watchLow
ClusterRole hive-operators3.kubedoop.dev/s3bucketsget · list · watchLow
ClusterRole hive-operators3.kubedoop.dev/s3connectionsget · list · watchLow

⚠️ Potential Abuse (10)

The following security risks were found based on the above permissions:

📦 Workloads (1)

KindNameContainerImage
Deploymenthive-operatorhive-operatorquay.io/zncdatadev/hive-operator:0.2.0