Description

The Kubedoop operator for Trino

Overview

IdentityNamespaceAutomountSecretsPermissionsWorkloadsRisk
trino-operatordefault71Critical

Numbers in the last two columns indicate how many bindings or workloads involve each ServiceAccount.


Identities

🤖 trino-operator

Namespace: default  |  Automount:

🔑 Permissions (7)

RoleResourceVerbsRiskTags
ClusterRole trino-operatorcore/configmapscreate · delete · get · list · patch · update · watchCriticalConfigMapAccess DataExposure InformationDisclosure PotentialPrivilegeEscalation Tampering
ClusterRole trino-operatorcore/servicescreate · delete · get · list · patch · update · watchCriticalDenialOfService NetworkManipulation ServiceExposure Tampering
ClusterRole trino-operatorapps/statefulsetscreate · delete · get · list · patch · update · watchCriticalPersistence PotentialPrivilegeEscalation PrivilegeEscalation Tampering WorkloadLifecycle
ClusterRole trino-operatortrino.kubedoop.dev/trinocatalogscreate · delete · get · list · patch · update · watchLow
ClusterRole trino-operatortrino.kubedoop.dev/trinoclusterscreate · delete · get · list · patch · update · watchLow
ClusterRole trino-operatortrino.kubedoop.dev/trinoclusters/finalizersupdateLow
ClusterRole trino-operatortrino.kubedoop.dev/trinoclusters/statusget · patch · updateLow

⚠️ Potential Abuse (9)

The following security risks were found based on the above permissions:

📦 Workloads (1)

KindNameContainerImage
Deploymenttrino-operatortrino-operatorquay.io/zncdatadev/trino-operator:0.2.0