Description

DirectPV - AIStor Volume Manager

Overview

IdentityNamespaceAutomountSecretsPermissionsWorkloadsRisk
directpv-min-iodirectpv197Critical

Numbers in the last two columns indicate how many bindings or workloads involve each ServiceAccount.


Identities

🤖 directpv-min-io

Namespace: directpv  |  Automount:

🔑 Permissions (19)

RoleResourceVerbsRiskTags
ClusterRole directpv-min-ioapiextensions.k8s.io/customresourcedefinitionscreate · delete · get · list · patch · update · watchCriticalCRDManipulation PotentialPrivilegeEscalation Tampering
ClusterRole directpv-min-iopolicy/podsecuritypoliciesuseCriticalDeprecatedFeature NodeAccess PodSecurityPolicy PrivilegeEscalation
ClusterRole directpv-min-iocore/secretsget · list · watchCriticalClusterWideSecretAccess CredentialAccess DataExposure InformationDisclosure SecretAccess
ClusterRole directpv-min-iostorage.k8s.io/csinodesget · list · watchMediumInformationDisclosure NodeAccess Reconnaissance StorageDetailsDisclosure
ClusterRole directpv-min-iocore/eventscreate · list · patch · update · watchMediumInformationDisclosure OperationalData Reconnaissance
ClusterRole directpv-min-iodirectpv.min.io/directpvdrivescreate · delete · get · list · update · watchLow
ClusterRole directpv-min-iodirectpv.min.io/directpvinitrequestscreate · delete · get · list · update · watchLow
ClusterRole directpv-min-iodirectpv.min.io/directpvnodescreate · delete · get · list · update · watchLow
ClusterRole directpv-min-iodirectpv.min.io/directpvvolumescreate · delete · get · list · update · watchLow
ClusterRole directpv-min-iocore/endpointscreate · delete · get · list · update · watchLow
ClusterRole directpv-min-iocoordination.k8s.io/leasescreate · delete · get · list · update · watchLow
Role directpv-min-iocoordination.k8s.io/leasescreate · delete · get · list · update · watchLow
ClusterRole directpv-min-iocore/nodesget · list · watchLow
ClusterRole directpv-min-iocore/persistentvolumeclaimsget · list · update · watchLow
ClusterRole directpv-min-iocore/persistentvolumeclaims/statuspatchLow
ClusterRole directpv-min-iocore/persistentvolumescreate · delete · get · list · patch · watchLow
ClusterRole directpv-min-iocore/podsget · list · watchLow
ClusterRole directpv-min-iostorage.k8s.io/storageclassesget · list · watchLow
ClusterRole directpv-min-iostorage.k8s.io/volumeattachmentsget · list · watchLow

⚠️ Potential Abuse (7)

The following security risks were found based on the above permissions:

📦 Workloads (7)

KindNameContainerImage
DaemonSetnode-serverliveness-probequay.io/minio/livenessprobe:v2.15.0-0
DaemonSetnode-servernode-controllerquay.io/minio/directpv:v5.0.2
DaemonSetnode-servernode-driver-registrarquay.io/minio/csi-node-driver-registrar:v2.13.0-0
DaemonSetnode-servernode-serverquay.io/minio/directpv:v5.0.2
Deploymentcontrollercontrollerquay.io/minio/directpv:v5.0.2
Deploymentcontrollercsi-provisionerquay.io/minio/csi-provisioner:v5.2.0-0
Deploymentcontrollercsi-resizerquay.io/minio/csi-resizer:v1.13.1-0