Description

The Kubedoop Secret Operator

Overview

IdentityNamespaceAutomountSecretsPermissionsWorkloadsRisk
secret-operatordefault144Critical

Numbers in the last two columns indicate how many bindings or workloads involve each ServiceAccount.


Identities

🤖 secret-operator

Namespace: default  |  Automount:

🔑 Permissions (14)

RoleResourceVerbsRiskTags
ClusterRole secret-operator-daemonsetstorage.k8s.io/csidriverscreate · delete · get · list · patch · update · watchCriticalNodeAccess PrivilegeEscalation StorageManipulation Tampering
ClusterRole secret-operator-daemonsetcore/podscreate · get · list · patch · update · watchCriticalLateralMovement Persistence PotentialPrivilegeEscalation PrivilegeEscalation Tampering (+1 more)
ClusterRole secret-operator-daemonsetcore/secretscreate · get · list · patch · update · watchCriticalClusterWideSecretAccess CredentialAccess DataExposure InformationDisclosure SecretAccess
ClusterRole secret-operator-daemonsetcore/eventscreate · get · list · patch · update · watchMediumInformationDisclosure OperationalData Reconnaissance
ClusterRole secret-operator-daemonsetcore/nodesget · list · watchLow
ClusterRole secret-operator-daemonsetcore/persistentvolumeclaimsget · list · watchLow
ClusterRole secret-operator-daemonsetcore/persistentvolumescreate · delete · get · list · patch · watchLow
ClusterRole secret-operator-daemonsetsecrets.kubedoop.dev/secretclassescreate · delete · get · list · patch · update · watchLow
ClusterRole secret-operator-daemonsetsecrets.kubedoop.dev/secretclasses/finalizersupdateLow
ClusterRole secret-operator-daemonsetsecrets.kubedoop.dev/secretclasses/statusget · patch · updateLow
ClusterRole secret-operator-daemonsetsecrets.kubedoop.dev/secretcsiscreate · delete · get · list · patch · update · watchLow
ClusterRole secret-operator-daemonsetsecrets.kubedoop.dev/secretcsis/finalizersupdateLow
ClusterRole secret-operator-daemonsetsecrets.kubedoop.dev/secretcsis/statusget · patch · updateLow
ClusterRole secret-operator-daemonsetstorage.k8s.io/storageclassesget · list · watchLow

⚠️ Potential Abuse (9)

The following security risks were found based on the above permissions:

📦 Workloads (4)

KindNameContainerImage
DaemonSetsecret-operator-daemonsetcsi-provisionerregistry.k8s.io/sig-storage/csi-provisioner:v5.1.0
DaemonSetsecret-operator-daemonsetliveness-proberegistry.k8s.io/sig-storage/livenessprobe:v2.14.0
DaemonSetsecret-operator-daemonsetnode-driver-registrarregistry.k8s.io/sig-storage/csi-node-driver-registrar:v2.12.0
DaemonSetsecret-operator-daemonsetsecret-operatorquay.io/zncdatadev/secret-csi-driver:0.1.0