Description

Meshery Operator chart.

Overview

IdentityNamespaceAutomountSecretsPermissionsWorkloadsRisk
meshery-operatordefault82Critical
meshery-serverdefault112Critical

Numbers in the last two columns indicate how many bindings or workloads involve each ServiceAccount.


Identities

🤖 meshery-operator

Namespace: default  |  Automount:

🔑 Permissions (8)

RoleResourceVerbsRiskTags
ClusterRole meshery-controller-role*create · delete · get · list · patch · update · watchCriticalAPIServerDoS APIServiceManipulation AuthorizationBypass AvailabilityImpact BackupAccess (+64 more)
Role meshery-leader-election-rolecore/configmapscreate · delete · get · list · patch · update · watchHighConfigMapAccess DataExposure InformationDisclosure PotentialPrivilegeEscalation Tampering
ClusterRole meshery-proxy-roleauthorization.k8s.io/subjectaccessreviewscreateMediumInformationDisclosure RBACQuery
ClusterRole meshery-proxy-roleauthentication.k8s.io/tokenreviewscreateMediumCredentialAccess InformationDisclosure RBACQuery
ClusterRole meshery-operator-rolemeshery.layer5.io/brokerscreate · delete · get · list · patch · update · watchLow
ClusterRole meshery-operator-rolemeshery.layer5.io/brokers/statusget · patch · updateLow
Role meshery-leader-election-rolecore/configmaps/statusget · patch · updateLow
Role meshery-leader-election-rolecore/eventscreate · patchLow

⚠️ Potential Abuse (98)

The following security risks were found based on the above permissions:

📦 Workloads (2)

KindNameContainerImage
Deploymentmeshery-operatorkube-rbac-proxygcr.io/kubebuilder/kube-rbac-proxy:v0.5.0
Deploymentmeshery-operatormanagerlayer5/meshery-operator:stable-latest

🤖 meshery-server

Namespace: default  |  Automount:

🔑 Permissions (1)

RoleResourceVerbsRiskTags
ClusterRole meshery-server**CriticalAPIServerDoS APIServiceManipulation AuthorizationBypass AvailabilityImpact BackupAccess (+68 more)

⚠️ Potential Abuse (106)

The following security risks were found based on the above permissions:

📦 Workloads (12)

KindNameContainerImage
Deploymentmesherymesherylayer5/meshery:stable-latest
Deploymentmeshery-app-meshmeshery-app-meshlayer5/meshery-app-mesh:stable-latest
Deploymentmeshery-consulmeshery-consullayer5/meshery-consul:stable-latest
Deploymentmeshery-cpxmeshery-cpxlayer5/meshery-cpx:stable-latest
Deploymentmeshery-istiomeshery-istiolayer5/meshery-istio:stable-latest
Deploymentmeshery-kumameshery-kumalayer5/meshery-kuma:stable-latest
Deploymentmeshery-linkerdmeshery-linkerdlayer5/meshery-linkerd:stable-latest
Deploymentmeshery-nginx-smmeshery-nginx-smlayer5/meshery-nginx-sm:stable-latest
Deploymentmeshery-nsmmeshery-nsmlayer5/meshery-nsm:stable-latest
Deploymentmeshery-osmmeshery-osmlayer5/meshery-osm:stable-latest
Deploymentmeshery-perfmeshery-perflayer5/meshery-perf:stable-latest
Deploymentmeshery-traefik-meshmeshery-traefik-meshlayer5/meshery-traefik-mesh:stable-latest