Description

A Helm chart for Keptn Metrics Operator, a subproject of Keptn

Overview

IdentityNamespaceAutomountSecretsPermissionsWorkloadsRisk
metrics-operatordefault151Critical

Numbers in the last two columns indicate how many bindings or workloads involve each ServiceAccount.


Identities

🤖 metrics-operator

Namespace: default  |  Automount:

🔑 Permissions (15)

RoleResourceVerbsRiskTags
Role metrics-operator-leader-election-rolecoordination.k8s.io/leasescreate · delete · get · list · patch · update · watchCriticalControlPlaneDisruption CriticalNamespace DenialOfService Tampering
ClusterRole metrics-operator-rolecore/configmapsget · list · watchHighConfigMapAccess DataExposure InformationDisclosure
Role metrics-operator-leader-election-rolecore/configmapscreate · delete · get · list · patch · update · watchHighConfigMapAccess DataExposure InformationDisclosure PotentialPrivilegeEscalation Tampering
ClusterRole metrics-operator-rolemetrics.keptn.sh/analysescreate · delete · get · list · patch · update · watchLow
ClusterRole metrics-operator-rolemetrics.keptn.sh/analyses/finalizersupdateLow
ClusterRole metrics-operator-rolemetrics.keptn.sh/analyses/statusget · patch · updateLow
ClusterRole metrics-operator-rolemetrics.keptn.sh/analysisdefinitionsget · list · watchLow
ClusterRole metrics-operator-rolemetrics.keptn.sh/analysisvaluetemplatesget · list · watchLow
Role metrics-operator-leader-election-rolecore/eventscreate · patchLow
ClusterRole metrics-operator-rolemetrics.keptn.sh/keptnmetricsget · list · watchLow
ClusterRole metrics-operator-rolemetrics.keptn.sh/keptnmetrics/finalizersupdateLow
ClusterRole metrics-operator-rolemetrics.keptn.sh/keptnmetrics/statusget · patch · updateLow
ClusterRole metrics-operator-rolemetrics.keptn.sh/keptnmetricsprovidersget · list · watchLow
ClusterRole metrics-operator-rolemetrics.keptn.sh/providersget · list · watchLow
ClusterRole metrics-operator-rolecore/secretsgetLow

⚠️ Potential Abuse (5)

The following security risks were found based on the above permissions:

📦 Workloads (1)

KindNameContainerImage
Deploymentmetrics-operatormetrics-operatorghcr.io/keptn/metrics-operator:v2.1.0