Description

Helm chart for MinIO AIStor Key Manager operator

Overview

IdentityNamespaceAutomountSecretsPermissionsWorkloadsRisk
minkmsdefault301Critical

Numbers in the last two columns indicate how many bindings or workloads involve each ServiceAccount.


Identities

🤖 minkms

Namespace: default  |  Automount:

🔑 Permissions (30)

RoleResourceVerbsRiskTags
ClusterRole minkmscore/configmapscreate · delete · deletecollection · get · list · patch · update · watchCriticalConfigMapAccess DataExposure InformationDisclosure PotentialPrivilegeEscalation Tampering
ClusterRole minkmsapps/daemonsetscreate · delete · get · list · patch · update · watchCriticalNodeAccess Persistence PrivilegeEscalation Tampering WorkloadLifecycle
ClusterRole minkmsapps/deploymentscreate · delete · get · list · patch · update · watchCriticalPersistence PotentialPrivilegeEscalation PrivilegeEscalation Tampering WorkloadLifecycle
ClusterRole minkmsbatch/jobscreate · delete · get · list · patch · update · watchCriticalPotentialPrivilegeEscalation PrivilegeEscalation Tampering WorkloadLifecycle
ClusterRole minkmscore/podscreate · delete · deletecollection · get · list · patch · update · watchCriticalLateralMovement Persistence PotentialPrivilegeEscalation PrivilegeEscalation Tampering (+1 more)
ClusterRole minkmscore/secretscreate · delete · deletecollection · get · list · update · watchCriticalClusterWideSecretAccess CredentialAccess DataExposure InformationDisclosure SecretAccess
ClusterRole minkmscore/servicescreate · delete · deletecollection · get · list · patch · update · watchCriticalDenialOfService NetworkManipulation ServiceExposure Tampering
ClusterRole minkmsapps/statefulsetscreate · delete · get · list · patch · update · watchCriticalPersistence PotentialPrivilegeEscalation PrivilegeEscalation Tampering WorkloadLifecycle
ClusterRole minkmsmin.io/**HighClusterWideAccess WildcardPermission
ClusterRole minkmsminkms.min.io/**HighClusterWideAccess WildcardPermission
ClusterRole minkmsmonitoring.coreos.com/prometheuses*HighClusterWideAccess WildcardPermission
ClusterRole minkmsrbac.authorization.k8s.io/rolebindingscreate · delete · get · list · patch · update · watchHighBindingToPrivilegedRole InformationDisclosure PrivilegeEscalation RBACManipulation RBACQuery (+1 more)
ClusterRole minkmsrbac.authorization.k8s.io/rolescreate · delete · get · list · patch · update · watchHighInformationDisclosure PrivilegeEscalation RBACManipulation RBACQuery Reconnaissance
ClusterRole minkmscore/serviceaccountscreate · delete · get · list · patch · update · watchHighIdentityManagement PotentialPrivilegeEscalation Tampering
ClusterRole minkmscertificates.k8s.io/certificatesigningrequestscreate · delete · get · list · update · watchMediumCSRCreation DenialOfService InformationDisclosure PotentialPrivilegeEscalation Spoofing (+1 more)
ClusterRole minkmscore/eventscreate · delete · deletecollection · get · list · patch · update · watchMediumInformationDisclosure OperationalData Reconnaissance
ClusterRole minkmspolicy/poddisruptionbudgetscreate · delete · deletecollection · get · list · patch · update · watchMediumAvailabilityImpact DenialOfService Tampering
ClusterRole minkmscertificates.k8s.io/certificatesigningrequests/approvalcreate · delete · get · list · update · watchLow
ClusterRole minkmscertificates.k8s.io/certificatesigningrequests/statuscreate · delete · get · list · update · watchLow
ClusterRole minkmsrbac.authorization.k8s.io/clusterrolebindingscreate · get · updateLow
ClusterRole minkmsapiextensions.k8s.io/customresourcedefinitionsget · list · update · watchLow
ClusterRole minkmsapps/deployments/finalizerscreate · delete · get · list · patch · update · watchLow
ClusterRole minkmscoordination.k8s.io/leasescreate · get · updateLow
ClusterRole minkmscore/namespacesget · list · watchLowClusterStructure InformationDisclosure Reconnaissance
ClusterRole minkmscore/nodesget · list · watchLow
ClusterRole minkmscore/persistentvolumeclaimsget · list · updateLow
ClusterRole minkmscertificates.k8s.io/signers (restricted to: beta.eks.amazonaws.com/app-serving)approve · signLowResourceNameRestricted
ClusterRole minkmscertificates.k8s.io/signers (restricted to: kubernetes.io/kube-apiserver-client)approve · signLowResourceNameRestricted
ClusterRole minkmscertificates.k8s.io/signers (restricted to: kubernetes.io/kubelet-serving)approve · signLowResourceNameRestricted
ClusterRole minkmscertificates.k8s.io/signers (restricted to: kubernetes.io/legacy-unknown)approve · signLowResourceNameRestricted

⚠️ Potential Abuse (32)

The following security risks were found based on the above permissions:

📦 Workloads (1)

KindNameContainerImage
Deploymentminkms-operatorcontrollerquay.io/minio/aistor/operator:RELEASE.2026-02-09T03-12-43Z