Description

Redpanda operator helm chart

Overview

IdentityNamespaceAutomountSecretsPermissionsWorkloadsRisk
operatordefault551Critical

Numbers in the last two columns indicate how many bindings or workloads involve each ServiceAccount.


Identities

🤖 operator

Namespace: default  |  Automount:

🔑 Permissions (55)

RoleResourceVerbsRiskTags
ClusterRole operatorrbac.authorization.k8s.io/clusterrolebindingscreate · delete · get · list · patch · update · watchCriticalBindingToPrivilegedRole ClusterAdminAccess InformationDisclosure PrivilegeEscalation RBACManipulation (+2 more)
ClusterRole operatorrbac.authorization.k8s.io/clusterrolescreate · delete · get · list · patch · update · watchCriticalClusterAdminAccess InformationDisclosure PrivilegeEscalation RBACManipulation RBACQuery (+1 more)
Role operatorcoordination.k8s.io/leasescreate · delete · get · list · patch · update · watchCriticalControlPlaneDisruption CriticalNamespace DenialOfService Tampering
Role operator-election-rolecoordination.k8s.io/leasescreate · delete · get · list · patch · update · watchCriticalControlPlaneDisruption CriticalNamespace DenialOfService Tampering
Role operatorcore/secretscreate · delete · get · list · patch · update · watchCriticalCredentialAccess DataExposure InformationDisclosure Persistence PotentialPrivilegeEscalation (+2 more)
Role operatorcore/configmapscreate · delete · get · list · patch · update · watchHighConfigMapAccess DataExposure InformationDisclosure PotentialPrivilegeEscalation Tampering
Role operator-election-rolecore/configmapscreate · delete · get · list · patch · update · watchHighConfigMapAccess DataExposure InformationDisclosure PotentialPrivilegeEscalation Tampering
Role operatorapps/deploymentscreate · delete · get · list · patch · update · watchHighPersistence PotentialPrivilegeEscalation Tampering WorkloadLifecycle
Role operatornetworking.k8s.io/ingressescreate · delete · get · list · patch · update · watchHighDenialOfService NetworkManipulation ServiceExposure Tampering
Role operatorbatch/jobscreate · delete · get · list · patch · update · watchHighPotentialPrivilegeEscalation Tampering WorkloadLifecycle
Role operatorcore/podscreate · delete · get · list · patch · update · watchHighLateralMovement Persistence PotentialPrivilegeEscalation Tampering WorkloadExecution
Role operatorrbac.authorization.k8s.io/rolebindingscreate · delete · get · list · patch · update · watchHighBindingToPrivilegedRole PrivilegeEscalation RBACManipulation
Role operatorrbac.authorization.k8s.io/rolescreate · delete · get · list · patch · update · watchHighPrivilegeEscalation RBACManipulation
Role operatorcore/servicescreate · delete · get · list · patch · update · watchHighDenialOfService NetworkManipulation ServiceExposure Tampering
Role operatorapps/statefulsetscreate · delete · get · list · patch · update · watchHighPersistence PotentialPrivilegeEscalation Tampering WorkloadLifecycle
Role operatorcore/serviceaccountscreate · delete · get · list · patch · update · watchMediumIdentityManagement PotentialPrivilegeEscalation Tampering
ClusterRole operatorauthorization.k8s.io/subjectaccessreviewscreateMediumInformationDisclosure RBACQuery
ClusterRole operatorauthentication.k8s.io/tokenreviewscreateMediumCredentialAccess InformationDisclosure RBACQuery
Role operatorsource.toolkit.fluxcd.io/bucketscreate · delete · get · list · patch · update · watchLow
Role operatorsource.toolkit.fluxcd.io/buckets/finalizersupdateLow
Role operatorsource.toolkit.fluxcd.io/buckets/statusget · patch · updateLow
Role operatorcert-manager.io/certificatescreate · delete · get · list · patch · update · watchLow
Role operatorcore/eventscreate · patchLow
Role operator-election-rolecore/eventscreate · patchLow
Role operatorsource.toolkit.fluxcd.io/gitrepositoriescreate · delete · get · list · patch · update · watchLow
Role operatorsource.toolkit.fluxcd.io/gitrepositories/finalizersupdateLow
Role operatorsource.toolkit.fluxcd.io/gitrepositories/statusget · patch · updateLow
Role operatorsource.toolkit.fluxcd.io/helmchartscreate · delete · get · list · patch · update · watchLow
Role operatorsource.toolkit.fluxcd.io/helmcharts/finalizersupdateLow
Role operatorsource.toolkit.fluxcd.io/helmcharts/statusget · patch · updateLow
Role operatorhelm.toolkit.fluxcd.io/helmreleasescreate · delete · get · list · patch · update · watchLow
Role operatorhelm.toolkit.fluxcd.io/helmreleases/finalizersupdateLow
Role operatorhelm.toolkit.fluxcd.io/helmreleases/statusget · patch · updateLow
Role operatorsource.toolkit.fluxcd.io/helmrepositoriescreate · delete · get · list · patch · update · watchLow
Role operatorsource.toolkit.fluxcd.io/helmrepositories/finalizersupdateLow
Role operatorsource.toolkit.fluxcd.io/helmrepositories/statusget · patch · updateLow
Role operatorautoscaling/horizontalpodautoscalerscreate · delete · get · list · patch · update · watchLow
Role operatorcert-manager.io/issuerscreate · delete · get · list · patch · update · watchLow
Role operatorcore/persistentvolumeclaimsdelete · get · list · patch · update · watchLow
Role operatorpolicy/poddisruptionbudgetscreate · delete · get · list · patch · update · watchLow
Role operatormonitoring.coreos.com/podmonitorscreate · delete · get · list · patch · update · watchLow
ClusterRole operatorcluster.redpanda.com/redpandascreate · delete · get · list · patch · update · watchLow
ClusterRole operatorcluster.redpanda.com/redpandas/finalizersupdateLow
ClusterRole operatorcluster.redpanda.com/redpandas/statusget · patch · updateLow
ClusterRole operatorcluster.redpanda.com/schemasget · list · patch · update · watchLow
ClusterRole operatorcluster.redpanda.com/schemas/finalizersupdateLow
ClusterRole operatorcluster.redpanda.com/schemas/statusget · patch · updateLow
Role operatormonitoring.coreos.com/servicemonitorscreate · delete · get · list · patch · update · watchLow
Role operatorapps/statefulsets/statuspatch · updateLow
ClusterRole operatorcluster.redpanda.com/topicsget · list · patch · update · watchLow
ClusterRole operatorcluster.redpanda.com/topics/finalizersupdateLow
ClusterRole operatorcluster.redpanda.com/topics/statusget · patch · updateLow
ClusterRole operatorcluster.redpanda.com/usersget · list · patch · update · watchLow
ClusterRole operatorcluster.redpanda.com/users/finalizersupdateLow
ClusterRole operatorcluster.redpanda.com/users/statusget · patch · updateLow

⚠️ Potential Abuse (21)

The following security risks were found based on the above permissions:

📦 Workloads (1)

KindNameContainerImage
Deploymentoperatormanagerdocker.redpanda.com/redpandadata/redpanda-operator:v2.4.1