Description

Installs the Tigera operator for Calico

Overview

IdentityNamespaceAutomountSecretsPermissionsWorkloadsRisk
tigera-operatortigera-operator301Critical

Numbers in the last two columns indicate how many bindings or workloads involve each ServiceAccount.


Identities

🤖 tigera-operator

Namespace: tigera-operator  |  Automount:

🔑 Permissions (30)

RoleResourceVerbsRiskTags
ClusterRole tigera-operatorrbac.authorization.k8s.io/clusterrolesbind · create · delete · escalate · get · list · update · watchCriticalBindingToPrivilegedRole ClusterAdminAccess InformationDisclosure PrivilegeEscalation RBACManipulation (+2 more)
ClusterRole tigera-operatorapps/daemonsetscreate · delete · get · list · patch · update · watchCriticalNodeAccess Persistence PrivilegeEscalation Tampering WorkloadLifecycle
ClusterRole tigera-operatorapps/deploymentscreate · delete · get · list · patch · update · watchCriticalPersistence PotentialPrivilegeEscalation PrivilegeEscalation Tampering WorkloadLifecycle
ClusterRole tigera-operatorcore/podscreate · delete · get · list · update · watchCriticalLateralMovement Persistence PotentialPrivilegeEscalation PrivilegeEscalation WorkloadExecution
ClusterRole tigera-operatorcore/secretscreate · delete · get · list · update · watchCriticalClusterWideSecretAccess CredentialAccess DataExposure InformationDisclosure SecretAccess
ClusterRole tigera-operatorapps/statefulsetscreate · delete · get · list · patch · update · watchCriticalPersistence PotentialPrivilegeEscalation PrivilegeEscalation Tampering WorkloadLifecycle
ClusterRole tigera-operatoroperator.tigera.io/*create · delete · get · list · patch · update · watchHighClusterWideAccess WildcardPermission
ClusterRole tigera-operatorcore/configmapscreate · delete · get · list · update · watchHighConfigMapAccess DataExposure InformationDisclosure
ClusterRole tigera-operatorcore/namespacescreate · delete · get · list · update · watchHighClusterStructure DenialOfService InformationDisclosure NamespaceLifecycle Reconnaissance (+1 more)
ClusterRole tigera-operatorrbac.authorization.k8s.io/clusterrolebindingsbind · create · delete · escalate · get · list · update · watchMediumInformationDisclosure RBACQuery Reconnaissance
ClusterRole tigera-operatorcore/eventscreate · delete · get · list · update · watchMediumInformationDisclosure OperationalData Reconnaissance
ClusterRole tigera-operatorrbac.authorization.k8s.io/rolebindingsbind · create · delete · escalate · get · list · update · watchMediumInformationDisclosure RBACQuery Reconnaissance
ClusterRole tigera-operatorrbac.authorization.k8s.io/rolesbind · create · delete · escalate · get · list · update · watchMediumInformationDisclosure RBACQuery Reconnaissance
ClusterRole tigera-operatorapiregistration.k8s.io/apiserviceslist · watchLow
ClusterRole tigera-operatorcertificates.k8s.io/certificatesigningrequestslistLow
ClusterRole tigera-operatorcore/endpointscreate · delete · get · list · update · watchLow
ClusterRole tigera-operatorcrd.projectcalico.org/felixconfigurationspatchLow
ClusterRole tigera-operatorcrd.projectcalico.org/ippoolsget · list · watchLow
ClusterRole tigera-operatorcrd.projectcalico.org/kubecontrollersconfigurationsget · list · watchLow
ClusterRole tigera-operatorcoordination.k8s.io/leasescreate · delete · get · list · update · watchLow
ClusterRole tigera-operatorcore/nodesget · list · patch · watchLow
ClusterRole tigera-operatorpolicy/poddisruptionbudgetscreate · delete · get · list · update · watchLow
ClusterRole tigera-operatorpolicy/podsecuritypoliciescreate · get · list · update · watchLow
ClusterRole tigera-operatorcore/podtemplatescreate · delete · get · list · update · watchLow
ClusterRole tigera-operatorscheduling.k8s.io/priorityclassescreate · delete · get · list · update · watchLow
ClusterRole tigera-operatorcore/serviceaccountscreate · delete · get · list · update · watchLow
ClusterRole tigera-operatormonitoring.coreos.com/servicemonitorscreate · getLow
ClusterRole tigera-operatorcore/servicescreate · delete · get · list · update · watchLow
ClusterRole tigera-operatorapps/deployments/finalizers (restricted to: tigera-operator)updateLowResourceNameRestricted
ClusterRole tigera-operatorpolicy/podsecuritypolicies (restricted to: tigera-operator)useLowDeprecatedFeature NodeAccess PodSecurityPolicy PrivilegeEscalation ResourceNameRestricted

⚠️ Potential Abuse (21)

The following security risks were found based on the above permissions:

📦 Workloads (1)

KindNameContainerImage
Deploymenttigera-operatortigera-operatorquay.io/tigera/operator:v1.17.8