Description

DEPRECATED: Moved to https://github.com/newrelic/newrelic-infra-operator/tree/master/charts/newrelic-infra-operator

Overview

IdentityNamespaceAutomountSecretsPermissionsWorkloadsRisk
newrelic-infra-operatordefault101Critical
newrelic-infra-operator-admissiondefault32Low

Numbers in the last two columns indicate how many bindings or workloads involve each ServiceAccount.


Identities

🤖 newrelic-infra-operator

Namespace: default  |  Automount:

🔑 Permissions (10)

RoleResourceVerbsRiskTags
ClusterRole newrelic-infra-operatorcore/nodes/proxyget · listCriticalAuthorizationBypass ClusterAdminAccess CodeExecution ElevationOfPrivilege LateralMovement (+1 more)
ClusterRole newrelic-infra-operatorrbac.authorization.k8s.io/clusterrolebindingsget · list · watchMediumInformationDisclosure RBACQuery Reconnaissance
ClusterRole newrelic-infra-operatorcore/nodesget · listLow
ClusterRole newrelic-infra-operatorcore/nodes/metricsget · listLow
ClusterRole newrelic-infra-operatorcore/nodes/statsget · listLow
ClusterRole newrelic-infra-operatorcore/podsget · listLow
ClusterRole newrelic-infra-operatorcore/secretscreateLow
ClusterRole newrelic-infra-operatorcore/servicesget · listLow
ClusterRole newrelic-infra-operatorcore/secrets (restricted to: newrelic-infra-operator-config)get · patch · updateLowResourceNameRestricted
ClusterRole newrelic-infra-operatorrbac.authorization.k8s.io/clusterrolebindings (restricted to: newrelic-infra-operator-infra-agent)updateLowResourceNameRestricted

⚠️ Potential Abuse (3)

The following security risks were found based on the above permissions:

📦 Workloads (1)

KindNameContainerImage
Deploymentnewrelic-infra-operatornewrelic-infra-operatornewrelic/newrelic-infra-operator:0.6.0

🤖 newrelic-infra-operator-admission

Namespace: default  |  Automount:

🔑 Permissions (3)

RoleResourceVerbsRiskTags
ClusterRole newrelic-infra-operator-admissionadmissionregistration.k8s.io/mutatingwebhookconfigurationsget · updateLow
Role newrelic-infra-operator-admissioncore/secretscreate · getLow
ClusterRole newrelic-infra-operator-admissionpolicy/podsecuritypolicies (restricted to: newrelic-infra-operator-admission)useLowDeprecatedFeature NodeAccess PodSecurityPolicy PrivilegeEscalation ResourceNameRestricted

⚠️ Potential Abuse (2)

The following security risks were found based on the above permissions:

📦 Workloads (2)

KindNameContainerImage
Jobnewrelic-infra-operator-admission-createcreatek8s.gcr.io/ingress-nginx/kube-webhook-certgen:v1.1.1
Jobnewrelic-infra-operator-admission-patchpatchk8s.gcr.io/ingress-nginx/kube-webhook-certgen:v1.1.1