Description

Prometheus Operator Admission Webhook

Overview

IdentityNamespaceAutomountSecretsPermissionsWorkloadsRisk
prometheus-operator-admission-webhook-auxdefault32Low
prometheus-operator-admission-webhookdefault01

Numbers in the last two columns indicate how many bindings or workloads involve each ServiceAccount.


Identities

🤖 prometheus-operator-admission-webhook-aux

Namespace: default  |  Automount:

🔑 Permissions (3)

RoleResourceVerbsRiskTags
ClusterRole prometheus-operator-admission-webhook-auxadmissionregistration.k8s.io/mutatingwebhookconfigurationsget · updateLow
Role prometheus-operator-admission-webhook-auxcore/secretscreate · getLow
ClusterRole prometheus-operator-admission-webhook-auxadmissionregistration.k8s.io/validatingwebhookconfigurationsget · updateLow

⚠️ Potential Abuse (1)

The following security risks were found based on the above permissions:

📦 Workloads (2)

KindNameContainerImage
Jobprometheus-operator-admission-webhook-createcreateregistry.k8s.io/ingress-nginx/kube-webhook-certgen:v1.6.0
Jobprometheus-operator-admission-webhook-patchpatchregistry.k8s.io/ingress-nginx/kube-webhook-certgen:v1.6.0

🤖 prometheus-operator-admission-webhook

Namespace: default  |  Automount:

🔑 Permissions (0)

No explicit RBAC bindings.

📦 Workloads (1)

KindNameContainerImage
Deploymentprometheus-operator-admission-webhookprometheus-operator-admission-webhookquay.io/prometheus-operator/admission-webhook:v0.83.0