Description

The Kubedoop operator for Trino

Overview

IdentityNamespaceAutomountSecretsPermissionsWorkloadsRisk
trino-operatordefault101Critical

Numbers in the last two columns indicate how many bindings or workloads involve each ServiceAccount.


Identities

🤖 trino-operator

Namespace: default  |  Automount:

🔑 Permissions (10)

RoleResourceVerbsRiskTags
ClusterRole trino-operatorcore/configmapscreate · delete · get · list · patch · update · watchCriticalConfigMapAccess DataExposure InformationDisclosure PotentialPrivilegeEscalation Tampering
ClusterRole trino-operatorcore/secretscreate · delete · get · list · patch · update · watchCriticalClusterWideSecretAccess CredentialAccess DataExposure InformationDisclosure Persistence (+4 more)
ClusterRole trino-operatorcore/servicescreate · delete · get · list · patch · update · watchCriticalDenialOfService NetworkManipulation ServiceExposure Tampering
ClusterRole trino-operatorapps/statefulsetscreate · delete · get · list · patch · update · watchCriticalPersistence PotentialPrivilegeEscalation PrivilegeEscalation Tampering WorkloadLifecycle
ClusterRole trino-operatorpolicy/poddisruptionbudgetscreate · delete · get · list · patch · update · watchMediumAvailabilityImpact DenialOfService Tampering
ClusterRole trino-operatorauthentication.kubedoop.dev/authenticationclassesget · list · watchLow
ClusterRole trino-operatortrino.kubedoop.dev/trinocatalogscreate · delete · get · list · patch · update · watchLow
ClusterRole trino-operatortrino.kubedoop.dev/trinoclusterscreate · delete · get · list · patch · update · watchLow
ClusterRole trino-operatortrino.kubedoop.dev/trinoclusters/finalizersupdateLow
ClusterRole trino-operatortrino.kubedoop.dev/trinoclusters/statusget · patch · updateLow

⚠️ Potential Abuse (14)

The following security risks were found based on the above permissions:

📦 Workloads (1)

KindNameContainerImage
Deploymenttrino-operatortrino-operatorquay.io/zncdatadev/trino-operator:0.4.0-dev