Description

The Kubedoop operator for Apache Kafka

Overview

IdentityNamespaceAutomountSecretsPermissionsWorkloadsRisk
kafka-operatordefault101Critical

Numbers in the last two columns indicate how many bindings or workloads involve each ServiceAccount.


Identities

🤖 kafka-operator

Namespace: default  |  Automount:

🔑 Permissions (10)

RoleResourceVerbsRiskTags
ClusterRole kafka-operatorcore/configmapscreate · delete · get · list · patch · update · watchCriticalConfigMapAccess DataExposure InformationDisclosure PotentialPrivilegeEscalation Tampering
ClusterRole kafka-operatorcore/servicescreate · delete · get · list · patch · update · watchCriticalDenialOfService NetworkManipulation ServiceExposure Tampering
ClusterRole kafka-operatorapps/statefulsetscreate · delete · get · list · patch · update · watchCriticalPersistence PotentialPrivilegeEscalation PrivilegeEscalation Tampering WorkloadLifecycle
ClusterRole kafka-operatorrbac.authorization.k8s.io/rolebindingscreate · delete · get · list · patch · update · watchHighBindingToPrivilegedRole InformationDisclosure PrivilegeEscalation RBACManipulation RBACQuery (+1 more)
ClusterRole kafka-operatorrbac.authorization.k8s.io/rolescreate · delete · get · list · patch · update · watchHighInformationDisclosure PrivilegeEscalation RBACManipulation RBACQuery Reconnaissance
ClusterRole kafka-operatorcore/serviceaccountscreate · delete · get · list · patch · update · watchHighIdentityManagement PotentialPrivilegeEscalation Tampering
ClusterRole kafka-operatorkafka.kubedoop.dev/kafkaclusterscreate · delete · get · list · patch · update · watchLow
ClusterRole kafka-operatorkafka.kubedoop.dev/kafkaclusters/finalizersupdateLow
ClusterRole kafka-operatorkafka.kubedoop.dev/kafkaclusters/statusget · patch · updateLow
ClusterRole kafka-operatorcore/podsget · list · watchLow

⚠️ Potential Abuse (14)

The following security risks were found based on the above permissions:

📦 Workloads (1)

KindNameContainerImage
Deploymentkafka-operatorkafka-operatorquay.io/zncdatadev/kafka-operator:0.2.0