Description

Redpanda operator helm chart

Overview

IdentityNamespaceAutomountSecretsPermissionsWorkloadsRisk
operatordefault891Critical

Numbers in the last two columns indicate how many bindings or workloads involve each ServiceAccount.


Identities

🤖 operator

Namespace: default  |  Automount:

🔑 Permissions (89)

RoleResourceVerbsRiskTags
ClusterRole operatorrbac.authorization.k8s.io/clusterrolebindingscreate · delete · get · list · patch · update · watchCriticalBindingToPrivilegedRole ClusterAdminAccess InformationDisclosure PrivilegeEscalation RBACManipulation (+2 more)
ClusterRole operatorrbac.authorization.k8s.io/clusterrolescreate · delete · get · list · patch · update · watchCriticalClusterAdminAccess InformationDisclosure PrivilegeEscalation RBACManipulation RBACQuery (+1 more)
Role operatorcoordination.k8s.io/leasescreate · delete · get · list · patch · update · watchCriticalControlPlaneDisruption CriticalNamespace DenialOfService Tampering
Role operator-election-rolecoordination.k8s.io/leasescreate · delete · get · list · patch · update · watchCriticalControlPlaneDisruption CriticalNamespace DenialOfService Tampering
ClusterRole operator-additional-controllerscore/secretsget · list · watchCriticalClusterWideSecretAccess CredentialAccess DataExposure InformationDisclosure SecretAccess
Role operatorcore/secretscreate · delete · get · list · patch · update · watchCriticalCredentialAccess DataExposure InformationDisclosure Persistence PotentialPrivilegeEscalation (+2 more)
Role operator-additional-controllerscore/secretsget · list · watchCriticalCredentialAccess DataExposure InformationDisclosure SecretAccess
ClusterRole operator-additional-controllerscore/configmapsget · list · watchHighConfigMapAccess DataExposure InformationDisclosure
Role operatorcore/configmapscreate · delete · get · list · patch · update · watchHighConfigMapAccess DataExposure InformationDisclosure PotentialPrivilegeEscalation Tampering
Role operator-election-rolecore/configmapscreate · delete · get · list · patch · update · watchHighConfigMapAccess DataExposure InformationDisclosure PotentialPrivilegeEscalation Tampering
Role operatorapps/deploymentscreate · delete · get · list · patch · update · watchHighPersistence PotentialPrivilegeEscalation Tampering WorkloadLifecycle
Role operatornetworking.k8s.io/ingressescreate · delete · get · list · patch · update · watchHighDenialOfService NetworkManipulation ServiceExposure Tampering
Role operatorbatch/jobscreate · delete · get · list · patch · update · watchHighPotentialPrivilegeEscalation Tampering WorkloadLifecycle
Role operatorcore/podscreate · delete · get · list · patch · update · watchHighLateralMovement Persistence PotentialPrivilegeEscalation Tampering WorkloadExecution
ClusterRole operator-compatcore/pods/logget · listHighClusterWideLogAccess DataExposure InformationDisclosure LogAccess
Role operatorrbac.authorization.k8s.io/rolebindingscreate · delete · get · list · patch · update · watchHighBindingToPrivilegedRole PrivilegeEscalation RBACManipulation
Role operatorrbac.authorization.k8s.io/rolescreate · delete · get · list · patch · update · watchHighPrivilegeEscalation RBACManipulation
Role operatorcore/servicescreate · delete · get · list · patch · update · watchHighDenialOfService NetworkManipulation ServiceExposure Tampering
Role operatorapps/statefulsetscreate · delete · get · list · patch · update · watchHighPersistence PotentialPrivilegeEscalation Tampering WorkloadLifecycle
Role operator-rpk-bundlecore/pods/logget · listMediumDataExposure InformationDisclosure LogAccess
Role operatorcore/serviceaccountscreate · delete · get · list · patch · update · watchMediumIdentityManagement PotentialPrivilegeEscalation Tampering
ClusterRole operatorauthorization.k8s.io/subjectaccessreviewscreateMediumInformationDisclosure RBACQuery
ClusterRole operatorauthentication.k8s.io/tokenreviewscreateMediumCredentialAccess InformationDisclosure RBACQuery
Role operatorsource.toolkit.fluxcd.io/bucketscreate · delete · get · list · patch · update · watchLow
Role operatorsource.toolkit.fluxcd.io/buckets/finalizersupdateLow
Role operatorsource.toolkit.fluxcd.io/buckets/statusget · patch · updateLow
Role operatorcert-manager.io/certificatescreate · delete · get · list · patch · update · watchLow
ClusterRole operator-compatcore/configmapsget · listLow
Role operator-rpk-bundlecore/configmapsget · listLow
ClusterRole operator-compatcore/endpointsget · listLow
Role operator-rpk-bundlecore/endpointsget · listLow
ClusterRole operator-compatcore/eventsget · listLow
Role operatorcore/eventscreate · patchLow
Role operator-additional-controllerscore/eventscreate · patchLow
Role operator-election-rolecore/eventscreate · patchLow
Role operator-rpk-bundlecore/eventsget · listLow
Role operatorsource.toolkit.fluxcd.io/gitrepositoriescreate · delete · get · list · patch · update · watchLow
Role operatorsource.toolkit.fluxcd.io/gitrepositories/finalizersupdateLow
Role operatorsource.toolkit.fluxcd.io/gitrepositories/statusget · patch · updateLow
Role operatorsource.toolkit.fluxcd.io/helmchartscreate · delete · get · list · patch · update · watchLow
Role operatorsource.toolkit.fluxcd.io/helmcharts/finalizersupdateLow
Role operatorsource.toolkit.fluxcd.io/helmcharts/statusget · patch · updateLow
Role operatorhelm.toolkit.fluxcd.io/helmreleasescreate · delete · get · list · patch · update · watchLow
Role operatorhelm.toolkit.fluxcd.io/helmreleases/finalizersupdateLow
Role operatorhelm.toolkit.fluxcd.io/helmreleases/statusget · patch · updateLow
Role operatorsource.toolkit.fluxcd.io/helmrepositoriescreate · delete · get · list · patch · update · watchLow
Role operatorsource.toolkit.fluxcd.io/helmrepositories/finalizersupdateLow
Role operatorsource.toolkit.fluxcd.io/helmrepositories/statusget · patch · updateLow
Role operatorautoscaling/horizontalpodautoscalerscreate · delete · get · list · patch · update · watchLow
Role operatorcert-manager.io/issuerscreate · delete · get · list · patch · update · watchLow
ClusterRole operator-compatcore/limitrangesget · listLow
Role operator-rpk-bundlecore/limitrangesget · listLow
ClusterRole operator-additional-controllerscore/nodesget · list · watchLow
ClusterRole operator-compatcore/persistentvolumeclaimsget · listLow
Role operator-additional-controllerscore/persistentvolumeclaimsdelete · get · list · patch · update · watchLow
Role operator-compatcore/persistentvolumeclaimsdelete · patch · update · watchLow
Role operator-rpk-bundlecore/persistentvolumeclaimsget · listLow
ClusterRole operator-additional-controllerscore/persistentvolumesdelete · get · list · patch · update · watchLow
Role operatorpolicy/poddisruptionbudgetscreate · delete · get · list · patch · update · watchLow
Role operatormonitoring.coreos.com/podmonitorscreate · delete · get · list · patch · update · watchLow
ClusterRole operator-compatcore/podsget · listLow
Role operator-additional-controllerscore/podsdelete · get · list · watchLow
Role operator-rpk-bundlecore/podsget · listLow
ClusterRole operatorcluster.redpanda.com/redpandascreate · delete · get · list · patch · update · watchLow
ClusterRole operator-additional-controllerscluster.redpanda.com/redpandasget · list · watchLow
ClusterRole operatorcluster.redpanda.com/redpandas/finalizersupdateLow
ClusterRole operatorcluster.redpanda.com/redpandas/statusget · patch · updateLow
Role operatorapps/replicasetscreate · delete · get · list · patch · update · watchLow
ClusterRole operator-compatcore/replicationcontrollersget · listLow
Role operator-rpk-bundlecore/replicationcontrollersget · listLow
ClusterRole operator-compatcore/resourcequotasget · listLow
Role operator-rpk-bundlecore/resourcequotasget · listLow
ClusterRole operatorcluster.redpanda.com/schemasget · list · patch · update · watchLow
ClusterRole operatorcluster.redpanda.com/schemas/finalizersupdateLow
ClusterRole operatorcluster.redpanda.com/schemas/statusget · patch · updateLow
ClusterRole operator-compatcore/serviceaccountsget · listLow
Role operator-rpk-bundlecore/serviceaccountsget · listLow
Role operatormonitoring.coreos.com/servicemonitorscreate · delete · get · list · patch · update · watchLow
ClusterRole operator-compatcore/servicesget · listLow
Role operator-rpk-bundlecore/servicesget · listLow
Role operator-additional-controllersapps/statefulsetsget · list · watchLow
Role operator-additional-controllersapps/statefulsets/statuspatch · updateLow
Role operator-compatapps/statefulsets/statuspatch · updateLow
ClusterRole operatorcluster.redpanda.com/topicsget · list · patch · update · watchLow
ClusterRole operatorcluster.redpanda.com/topics/finalizersupdateLow
ClusterRole operatorcluster.redpanda.com/topics/statusget · patch · updateLow
ClusterRole operatorcluster.redpanda.com/usersget · list · patch · update · watchLow
ClusterRole operatorcluster.redpanda.com/users/finalizersupdateLow
ClusterRole operatorcluster.redpanda.com/users/statusget · patch · updateLow

⚠️ Potential Abuse (25)

The following security risks were found based on the above permissions:

📦 Workloads (1)

KindNameContainerImage
Deploymentoperatormanagerdocker.redpanda.com/redpandadata/redpanda-operator:v2.4.2