Description

Installs the Tigera operator for Calico

Overview

IdentityNamespaceAutomountSecretsPermissionsWorkloadsRisk
tigera-operatordefault351Critical

Numbers in the last two columns indicate how many bindings or workloads involve each ServiceAccount.


Identities

🤖 tigera-operator

Namespace: default  |  Automount:

🔑 Permissions (35)

RoleResourceVerbsRiskTags
ClusterRole tigera-operatorrbac.authorization.k8s.io/clusterrolesbind · create · delete · escalate · get · list · update · watchCriticalBindingToPrivilegedRole ClusterAdminAccess InformationDisclosure PrivilegeEscalation RBACManipulation (+2 more)
ClusterRole tigera-operatorapps/daemonsetscreate · delete · get · list · patch · update · watchCriticalNodeAccess Persistence PrivilegeEscalation Tampering WorkloadLifecycle
ClusterRole tigera-operatorapps/deploymentscreate · delete · get · list · patch · update · watchCriticalPersistence PotentialPrivilegeEscalation PrivilegeEscalation Tampering WorkloadLifecycle
ClusterRole tigera-operatorcore/podscreate · delete · get · list · update · watchCriticalLateralMovement Persistence PotentialPrivilegeEscalation PrivilegeEscalation WorkloadExecution
ClusterRole tigera-operatorcore/secretscreate · delete · get · list · update · watchCriticalClusterWideSecretAccess CredentialAccess DataExposure InformationDisclosure SecretAccess
ClusterRole tigera-operatorapps/statefulsetscreate · delete · get · list · patch · update · watchCriticalPersistence PotentialPrivilegeEscalation PrivilegeEscalation Tampering WorkloadLifecycle
ClusterRole tigera-operatoroperator.tigera.io/*create · delete · get · list · patch · update · watchHighClusterWideAccess WildcardPermission
ClusterRole tigera-operatorcore/configmapscreate · delete · get · list · update · watchHighConfigMapAccess DataExposure InformationDisclosure
ClusterRole tigera-operatorcore/namespacescreate · delete · get · list · update · watchHighClusterStructure DenialOfService InformationDisclosure NamespaceLifecycle Reconnaissance (+1 more)
ClusterRole tigera-operatorrbac.authorization.k8s.io/clusterrolebindingsbind · create · delete · escalate · get · list · update · watchMediumInformationDisclosure RBACQuery Reconnaissance
ClusterRole tigera-operatorcore/eventscreate · delete · get · list · update · watchMediumInformationDisclosure OperationalData Reconnaissance
ClusterRole tigera-operatorcore/resourcequotasget · list · watchMediumInformationDisclosure QuotaTampering Reconnaissance ResourceConfiguration
ClusterRole tigera-operatorrbac.authorization.k8s.io/rolebindingsbind · create · delete · escalate · get · list · update · watchMediumInformationDisclosure RBACQuery Reconnaissance
ClusterRole tigera-operatorrbac.authorization.k8s.io/rolesbind · create · delete · escalate · get · list · update · watchMediumInformationDisclosure RBACQuery Reconnaissance
ClusterRole tigera-operatorapiregistration.k8s.io/apiservicescreate · list · update · watchLow
ClusterRole tigera-operatorcrd.projectcalico.org/bgpconfigurationsget · list · watchLow
ClusterRole tigera-operatorcertificates.k8s.io/certificatesigningrequestslist · watchLow
ClusterRole tigera-operatorstorage.k8s.io/csidriverscreate · delete · get · list · update · watchLow
ClusterRole tigera-operatorcore/endpointscreate · delete · get · list · update · watchLow
ClusterRole tigera-operatorcrd.projectcalico.org/felixconfigurationscreate · get · list · patch · watchLow
ClusterRole tigera-operatorcrd.projectcalico.org/ippoolsget · list · watchLow
ClusterRole tigera-operatorcrd.projectcalico.org/kubecontrollersconfigurationsget · list · watchLow
ClusterRole tigera-operatorcoordination.k8s.io/leasescreate · delete · get · list · update · watchLow
ClusterRole tigera-operatornetworking.k8s.io/networkpoliciescreate · delete · get · list · update · watchLow
ClusterRole tigera-operatorcore/nodesget · list · patch · watchLow
ClusterRole tigera-operatorpolicy/poddisruptionbudgetscreate · delete · get · list · update · watchLow
ClusterRole tigera-operatorpolicy/podsecuritypoliciescreate · delete · get · list · update · watchLow
ClusterRole tigera-operatorcore/podtemplatescreate · delete · get · list · update · watchLow
ClusterRole tigera-operatorscheduling.k8s.io/priorityclassescreate · delete · get · list · update · watchLow
ClusterRole tigera-operatorcore/serviceaccountscreate · delete · get · list · update · watchLow
ClusterRole tigera-operatorcore/servicescreate · delete · get · list · update · watchLow
ClusterRole tigera-operatorcore/resourcequotas (restricted to: calico-critical-pods)create · delete · get · list · update · watchLowInformationDisclosure QuotaTampering Reconnaissance ResourceConfiguration ResourceNameRestricted
ClusterRole tigera-operatorcore/resourcequotas (restricted to: tigera-critical-pods)create · delete · get · list · update · watchLowInformationDisclosure QuotaTampering Reconnaissance ResourceConfiguration ResourceNameRestricted
ClusterRole tigera-operatorapps/deployments/finalizers (restricted to: tigera-operator)updateLowResourceNameRestricted
ClusterRole tigera-operatorpolicy/podsecuritypolicies (restricted to: tigera-operator)useLowDeprecatedFeature NodeAccess PodSecurityPolicy PrivilegeEscalation ResourceNameRestricted

⚠️ Potential Abuse (23)

The following security risks were found based on the above permissions:

📦 Workloads (1)

KindNameContainerImage
Deploymenttigera-operatortigera-operatorquay.io/tigera/operator:v1.30.7