Description

A Helm chart for MinIO Operator

Overview

IdentityNamespaceAutomountSecretsPermissionsWorkloadsRisk
minio-operatordefault291Critical

Numbers in the last two columns indicate how many bindings or workloads involve each ServiceAccount.


Identities

🤖 minio-operator

Namespace: default  |  Automount:

🔑 Permissions (29)

RoleResourceVerbsRiskTags
ClusterRole minio-operator-rolecore/configmapscreate · delete · deletecollection · get · list · patch · update · watchCriticalConfigMapAccess DataExposure InformationDisclosure PotentialPrivilegeEscalation Tampering
ClusterRole minio-operator-roleapps/deploymentscreate · delete · get · list · patch · update · watchCriticalPersistence PotentialPrivilegeEscalation PrivilegeEscalation Tampering WorkloadLifecycle
ClusterRole minio-operator-rolebatch/jobscreate · delete · get · list · patch · update · watchCriticalPotentialPrivilegeEscalation PrivilegeEscalation Tampering WorkloadLifecycle
ClusterRole minio-operator-rolecore/podscreate · delete · deletecollection · get · list · patch · update · watchCriticalLateralMovement Persistence PotentialPrivilegeEscalation PrivilegeEscalation Tampering (+1 more)
ClusterRole minio-operator-rolecore/secretscreate · delete · deletecollection · get · list · update · watchCriticalClusterWideSecretAccess CredentialAccess DataExposure InformationDisclosure SecretAccess
ClusterRole minio-operator-rolecore/servicescreate · delete · deletecollection · get · list · patch · update · watchCriticalDenialOfService NetworkManipulation ServiceExposure Tampering
ClusterRole minio-operator-roleapps/statefulsetscreate · delete · get · list · patch · update · watchCriticalPersistence PotentialPrivilegeEscalation PrivilegeEscalation Tampering WorkloadLifecycle
ClusterRole minio-operator-rolejob.min.io/**HighClusterWideAccess WildcardPermission
ClusterRole minio-operator-rolemin.io/**HighClusterWideAccess WildcardPermission
ClusterRole minio-operator-roleminio.min.io/**HighClusterWideAccess WildcardPermission
ClusterRole minio-operator-rolests.min.io/**HighClusterWideAccess WildcardPermission
ClusterRole minio-operator-rolerbac.authorization.k8s.io/rolebindingscreate · delete · get · list · patch · update · watchHighBindingToPrivilegedRole InformationDisclosure PrivilegeEscalation RBACManipulation RBACQuery (+1 more)
ClusterRole minio-operator-rolerbac.authorization.k8s.io/rolescreate · delete · get · list · patch · update · watchHighInformationDisclosure PrivilegeEscalation RBACManipulation RBACQuery Reconnaissance
ClusterRole minio-operator-rolecore/serviceaccountscreate · delete · get · list · patch · update · watchHighIdentityManagement PotentialPrivilegeEscalation Tampering
ClusterRole minio-operator-rolecertificates.k8s.io/certificatesigningrequestscreate · delete · get · list · updateMediumCSRCreation PotentialPrivilegeEscalation Spoofing
ClusterRole minio-operator-rolecore/eventscreate · delete · deletecollection · get · list · patch · update · watchMediumInformationDisclosure OperationalData Reconnaissance
ClusterRole minio-operator-rolepolicy/poddisruptionbudgetscreate · delete · deletecollection · get · list · patch · updateMediumAvailabilityImpact DenialOfService Tampering
ClusterRole minio-operator-roleauthentication.k8s.io/tokenreviewscreateMediumCredentialAccess InformationDisclosure RBACQuery
ClusterRole minio-operator-rolecertificates.k8s.io/certificatesigningrequests/approvalcreate · delete · get · list · updateLow
ClusterRole minio-operator-rolecertificates.k8s.io/certificatesigningrequests/statuscreate · delete · get · list · updateLow
ClusterRole minio-operator-roleapiextensions.k8s.io/customresourcedefinitionsget · updateLow
ClusterRole minio-operator-roleapps/deployments/finalizerscreate · delete · get · list · patch · update · watchLow
ClusterRole minio-operator-rolecoordination.k8s.io/leasescreate · get · updateLow
ClusterRole minio-operator-rolecore/namespacescreate · get · list · watchLowClusterStructure InformationDisclosure Reconnaissance
ClusterRole minio-operator-rolecore/nodescreate · get · list · watchLow
ClusterRole minio-operator-rolecore/persistentvolumeclaimsget · list · updateLow
ClusterRole minio-operator-rolemonitoring.coreos.com/prometheusagentsget · list · updateLow
ClusterRole minio-operator-rolemonitoring.coreos.com/prometheusesget · list · updateLow
ClusterRole minio-operator-rolecertificates.k8s.io/signersapprove · signLow

⚠️ Potential Abuse (30)

The following security risks were found based on the above permissions:

📦 Workloads (1)

KindNameContainerImage
Deploymentminio-operatoroperatorquay.io/minio/operator:v7.1.1