Description

Helm chart for MinIO AIStor Key Manager operator

Overview

IdentityNamespaceAutomountSecretsPermissionsWorkloadsRisk
aistor-keymanagerdefault331Critical

Numbers in the last two columns indicate how many bindings or workloads involve each ServiceAccount.


Identities

🤖 aistor-keymanager

Namespace: default  |  Automount:

🔑 Permissions (33)

RoleResourceVerbsRiskTags
ClusterRole aistor-keymanagercore/configmapscreate · delete · deletecollection · get · list · patch · update · watchCriticalConfigMapAccess DataExposure InformationDisclosure PotentialPrivilegeEscalation Tampering
ClusterRole aistor-keymanagerapps/daemonsetscreate · delete · get · list · patch · update · watchCriticalNodeAccess Persistence PrivilegeEscalation Tampering WorkloadLifecycle
ClusterRole aistor-keymanagerapps/deploymentscreate · delete · get · list · patch · update · watchCriticalPersistence PotentialPrivilegeEscalation PrivilegeEscalation Tampering WorkloadLifecycle
ClusterRole aistor-keymanagerbatch/jobscreate · delete · get · list · patch · update · watchCriticalPotentialPrivilegeEscalation PrivilegeEscalation Tampering WorkloadLifecycle
ClusterRole aistor-keymanagercore/podscreate · delete · deletecollection · get · list · patch · update · watchCriticalLateralMovement Persistence PotentialPrivilegeEscalation PrivilegeEscalation Tampering (+1 more)
ClusterRole aistor-keymanagercore/secretscreate · delete · deletecollection · get · list · update · watchCriticalClusterWideSecretAccess CredentialAccess DataExposure InformationDisclosure SecretAccess
ClusterRole aistor-keymanagercore/servicescreate · delete · deletecollection · get · list · patch · update · watchCriticalDenialOfService NetworkManipulation ServiceExposure Tampering
ClusterRole aistor-keymanagerapps/statefulsetscreate · delete · get · list · patch · update · watchCriticalPersistence PotentialPrivilegeEscalation PrivilegeEscalation Tampering WorkloadLifecycle
ClusterRole aistor-keymanageraistor.min.io/**HighClusterWideAccess WildcardPermission
ClusterRole aistor-keymanagerjob.min.io/**HighClusterWideAccess WildcardPermission
ClusterRole aistor-keymanagermin.io/**HighClusterWideAccess WildcardPermission
ClusterRole aistor-keymanagersts.min.io/**HighClusterWideAccess WildcardPermission
ClusterRole aistor-keymanagermonitoring.coreos.com/prometheuses*HighClusterWideAccess WildcardPermission
ClusterRole aistor-keymanagerrbac.authorization.k8s.io/rolebindingscreate · delete · get · list · patch · update · watchHighBindingToPrivilegedRole InformationDisclosure PrivilegeEscalation RBACManipulation RBACQuery (+1 more)
ClusterRole aistor-keymanagerrbac.authorization.k8s.io/rolescreate · delete · get · list · patch · update · watchHighInformationDisclosure PrivilegeEscalation RBACManipulation RBACQuery Reconnaissance
ClusterRole aistor-keymanagercore/serviceaccountscreate · delete · get · list · patch · update · watchHighIdentityManagement PotentialPrivilegeEscalation Tampering
ClusterRole aistor-keymanagercertificates.k8s.io/certificatesigningrequestscreate · delete · get · list · updateMediumCSRCreation PotentialPrivilegeEscalation Spoofing
ClusterRole aistor-keymanagercore/eventscreate · delete · deletecollection · get · list · patch · update · watchMediumInformationDisclosure OperationalData Reconnaissance
ClusterRole aistor-keymanagerpolicy/poddisruptionbudgetscreate · delete · deletecollection · get · list · patch · updateMediumAvailabilityImpact DenialOfService Tampering
ClusterRole aistor-keymanagerauthentication.k8s.io/tokenreviewscreateMediumCredentialAccess InformationDisclosure RBACQuery
ClusterRole aistor-keymanagercertificates.k8s.io/certificatesigningrequests/approvalcreate · delete · get · list · updateLow
ClusterRole aistor-keymanagercertificates.k8s.io/certificatesigningrequests/statuscreate · delete · get · list · updateLow
ClusterRole aistor-keymanagerrbac.authorization.k8s.io/clusterrolebindingscreate · get · updateLow
ClusterRole aistor-keymanagerapiextensions.k8s.io/customresourcedefinitionsget · list · update · watchLow
ClusterRole aistor-keymanagerapps/deployments/finalizerscreate · delete · get · list · patch · update · watchLow
ClusterRole aistor-keymanagercoordination.k8s.io/leasescreate · get · updateLow
ClusterRole aistor-keymanagercore/namespacesget · list · watchLowClusterStructure InformationDisclosure Reconnaissance
ClusterRole aistor-keymanagercore/nodesget · list · watchLow
ClusterRole aistor-keymanagercore/persistentvolumeclaimsget · list · updateLow
ClusterRole aistor-keymanagercertificates.k8s.io/signers (restricted to: beta.eks.amazonaws.com/app-serving)approve · signLowResourceNameRestricted
ClusterRole aistor-keymanagercertificates.k8s.io/signers (restricted to: kubernetes.io/kube-apiserver-client)approve · signLowResourceNameRestricted
ClusterRole aistor-keymanagercertificates.k8s.io/signers (restricted to: kubernetes.io/kubelet-serving)approve · signLowResourceNameRestricted
ClusterRole aistor-keymanagercertificates.k8s.io/signers (restricted to: kubernetes.io/legacy-unknown)approve · signLowResourceNameRestricted

⚠️ Potential Abuse (32)

The following security risks were found based on the above permissions:

📦 Workloads (1)

KindNameContainerImage
Deploymentkeymanager-operatorcontrollerquay.io/minio/aistor/operator:RELEASE.2025-08-19T17-53-00Z