Description

Helm chart for MinIO AIStor Key Manager operator

Overview

IdentityNamespaceAutomountSecretsPermissionsWorkloadsRisk
minkmsdefault201Critical

Numbers in the last two columns indicate how many bindings or workloads involve each ServiceAccount.


Identities

🤖 minkms

Namespace: default  |  Automount:

🔑 Permissions (20)

RoleResourceVerbsRiskTags
ClusterRole minkms:minkmscore/secretscreate · delete · get · list · update · watchCriticalClusterWideSecretAccess CredentialAccess DataExposure InformationDisclosure SecretAccess
Role minkms-operatorcore/secretsget · list · watchCriticalCredentialAccess DataExposure InformationDisclosure SecretAccess
ClusterRole minkms:certificate-managementcertificates.k8s.io/certificatesigningrequestscreate · delete · get · list · watchMediumCSRCreation DenialOfService InformationDisclosure PotentialPrivilegeEscalation Spoofing (+1 more)
Role minkms-operatorcore/configmapsget · list · watchMediumConfigMapAccess DataExposure InformationDisclosure
ClusterRole minkms:minkmsrbac.authorization.k8s.io/rolebindingscreate · delete · list · update · watchMediumInformationDisclosure RBACQuery Reconnaissance
ClusterRole minkms:certificate-managementcertificates.k8s.io/certificatesigningrequests/approvalget · updateLow
ClusterRole minkms:certificate-managementcertificates.k8s.io/certificatesigningrequests/statusgetLow
ClusterRole minkms:minkmscore/eventscreate · patchLow
Role minkms-operatorcoordination.k8s.io/leasescreate · get · updateLow
ClusterRole minkms:minkmsminkms.min.io/minkmsesget · list · watchLow
ClusterRole minkms:minkmsminkms.min.io/minkmses/finalizersupdateLow
ClusterRole minkms:minkmsminkms.min.io/minkmses/statusupdateLow
ClusterRole minkms:certificate-managementcore/nodeslistLow
ClusterRole minkms:minkmscore/podsdelete · list · watchLow
Role minkms-operatorcore/podspatchLow
ClusterRole minkms:minkmscore/serviceaccountscreate · list · update · watchLow
ClusterRole minkms:minkmscore/servicescreate · list · update · watchLow
ClusterRole minkms:certificate-managementcertificates.k8s.io/signersapproveLow
ClusterRole minkms:minkmsapps/statefulsetscreate · list · update · watchLow
ClusterRole minkms:minkmsrbac.authorization.k8s.io/clusterroles (restricted to: minkms:minkms:pods)bindLowBindingToPrivilegedRole ClusterAdminAccess PrivilegeEscalation RBACManipulation ResourceNameRestricted

⚠️ Potential Abuse (8)

The following security risks were found based on the above permissions:

📦 Workloads (1)

KindNameContainerImage
Deploymentminkms-operatorcontrollerquay.io/minio/aistor/operator:RELEASE.2026-06-10T05-02-21Z