Description

OpenTelemetry Operator Helm chart for Kubernetes

Overview

IdentityNamespaceAutomountSecretsPermissionsWorkloadsRisk
opentelemetry-operator-controller-managerdefault202Critical

Numbers in the last two columns indicate how many bindings or workloads involve each ServiceAccount.


Identities

🤖 opentelemetry-operator-controller-manager

Namespace: default  |  Automount:

🔑 Permissions (20)

RoleResourceVerbsRiskTags
ClusterRole opentelemetry-operator-manager-rolecore/configmapscreate · delete · get · list · patch · update · watchCriticalConfigMapAccess DataExposure InformationDisclosure PotentialPrivilegeEscalation Tampering
ClusterRole opentelemetry-operator-manager-roleapps/daemonsetscreate · delete · get · list · patch · update · watchCriticalNodeAccess Persistence PrivilegeEscalation Tampering WorkloadLifecycle
ClusterRole opentelemetry-operator-manager-roleapps/deploymentscreate · delete · get · list · patch · update · watchCriticalPersistence PotentialPrivilegeEscalation PrivilegeEscalation Tampering WorkloadLifecycle
ClusterRole opentelemetry-operator-manager-rolecore/servicescreate · delete · get · list · patch · update · watchCriticalDenialOfService NetworkManipulation ServiceExposure Tampering
ClusterRole opentelemetry-operator-manager-roleapps/statefulsetscreate · delete · get · list · patch · update · watchCriticalPersistence PotentialPrivilegeEscalation PrivilegeEscalation Tampering WorkloadLifecycle
Role opentelemetry-operator-leader-election-rolecore/configmapscreate · delete · get · list · patch · update · watchHighConfigMapAccess DataExposure InformationDisclosure PotentialPrivilegeEscalation Tampering
ClusterRole opentelemetry-operator-manager-rolecore/serviceaccountscreate · delete · get · list · patch · update · watchHighIdentityManagement PotentialPrivilegeEscalation Tampering
ClusterRole opentelemetry-operator-proxy-roleauthorization.k8s.io/subjectaccessreviewscreateMediumInformationDisclosure RBACQuery
ClusterRole opentelemetry-operator-proxy-roleauthentication.k8s.io/tokenreviewscreateMediumCredentialAccess InformationDisclosure RBACQuery
Role opentelemetry-operator-leader-election-rolecore/configmaps/statusget · patch · updateLow
ClusterRole opentelemetry-operator-manager-rolecore/eventscreate · patchLow
Role opentelemetry-operator-leader-election-rolecore/eventscreate · patchLow
ClusterRole opentelemetry-operator-manager-roleautoscaling/horizontalpodautoscalerscreate · delete · get · list · patch · update · watchLow
ClusterRole opentelemetry-operator-manager-roleopentelemetry.io/instrumentationsget · list · patch · update · watchLow
ClusterRole opentelemetry-operator-manager-rolecoordination.k8s.io/leasescreate · get · list · updateLow
ClusterRole opentelemetry-operator-manager-rolecore/namespaceslist · watchLowClusterStructure InformationDisclosure Reconnaissance
ClusterRole opentelemetry-operator-manager-roleopentelemetry.io/opentelemetrycollectorscreate · delete · get · list · patch · update · watchLow
ClusterRole opentelemetry-operator-manager-roleopentelemetry.io/opentelemetrycollectors/finalizersget · patch · updateLow
ClusterRole opentelemetry-operator-manager-roleopentelemetry.io/opentelemetrycollectors/statusget · patch · updateLow
ClusterRole opentelemetry-operator-manager-roleapps/replicasetsget · list · watchLow

⚠️ Potential Abuse (18)

The following security risks were found based on the above permissions:

📦 Workloads (2)

KindNameContainerImage
Deploymentopentelemetry-operator-controller-managerkube-rbac-proxygcr.io/kubebuilder/kube-rbac-proxy:v0.11.0
Deploymentopentelemetry-operator-controller-managermanagerghcr.io/open-telemetry/opentelemetry-operator/opentelemetry-operator:v0.56.0