Description

Redpanda operator helm chart

Overview

IdentityNamespaceAutomountSecretsPermissionsWorkloadsRisk
operatordefault541Critical
operator-crd-jobdefault00

Numbers in the last two columns indicate how many bindings or workloads involve each ServiceAccount.


Identities

🤖 operator

Namespace: default  |  Automount:

🔑 Permissions (54)

RoleResourceVerbsRiskTags
ClusterRole operator-defaultrbac.authorization.k8s.io/clusterrolebindingscreate · delete · get · list · patch · update · watchCriticalBindingToPrivilegedRole ClusterAdminAccess InformationDisclosure PrivilegeEscalation RBACManipulation (+2 more)
ClusterRole operator-defaultrbac.authorization.k8s.io/clusterrolescreate · delete · get · list · patch · update · watchCriticalClusterAdminAccess InformationDisclosure PrivilegeEscalation RBACManipulation RBACQuery (+1 more)
ClusterRole operator-defaultcore/configmapscreate · delete · get · list · patch · update · watchCriticalConfigMapAccess DataExposure InformationDisclosure PotentialPrivilegeEscalation Tampering
ClusterRole operator-defaultapps/deploymentscreate · delete · get · list · patch · update · watchCriticalPersistence PotentialPrivilegeEscalation PrivilegeEscalation Tampering WorkloadLifecycle
ClusterRole operator-defaultbatch/jobscreate · delete · get · list · patch · update · watchCriticalPotentialPrivilegeEscalation PrivilegeEscalation Tampering WorkloadLifecycle
ClusterRole operator-defaultcoordination.k8s.io/leasescreate · delete · get · list · patch · update · watchCriticalControlPlaneDisruption CriticalNamespace DenialOfService LeaderElectionAbuse Tampering
ClusterRole operator-defaultcore/podscreate · delete · get · list · patch · update · watchCriticalLateralMovement Persistence PotentialPrivilegeEscalation PrivilegeEscalation Tampering (+1 more)
ClusterRole operator-additional-controllers-defaultcore/secretsget · list · watchCriticalClusterWideSecretAccess CredentialAccess DataExposure InformationDisclosure SecretAccess
ClusterRole operator-defaultcore/secretscreate · delete · get · list · patch · update · watchCriticalClusterWideSecretAccess CredentialAccess DataExposure InformationDisclosure Persistence (+4 more)
ClusterRole operator-defaultcore/servicescreate · delete · get · list · patch · update · watchCriticalDenialOfService NetworkManipulation ServiceExposure Tampering
ClusterRole operator-defaultapps/statefulsetscreate · delete · get · list · patch · update · watchCriticalPersistence PotentialPrivilegeEscalation PrivilegeEscalation Tampering WorkloadLifecycle
ClusterRole operator-additional-controllers-defaultcore/configmapsget · list · watchHighConfigMapAccess DataExposure InformationDisclosure
ClusterRole operator-defaultnetworking.k8s.io/ingressescreate · delete · get · list · patch · update · watchHighDenialOfService NetworkManipulation ServiceExposure Tampering
ClusterRole operator-defaultcore/pods/logget · listHighClusterWideLogAccess DataExposure InformationDisclosure LogAccess
ClusterRole operator-defaultrbac.authorization.k8s.io/rolebindingscreate · delete · get · list · patch · update · watchHighBindingToPrivilegedRole InformationDisclosure PrivilegeEscalation RBACManipulation RBACQuery (+1 more)
ClusterRole operator-defaultrbac.authorization.k8s.io/rolescreate · delete · get · list · patch · update · watchHighInformationDisclosure PrivilegeEscalation RBACManipulation RBACQuery Reconnaissance
ClusterRole operator-defaultcore/serviceaccountscreate · delete · get · list · patch · update · watchHighIdentityManagement PotentialPrivilegeEscalation Tampering
ClusterRole operator-defaultpolicy/poddisruptionbudgetscreate · delete · get · list · patch · update · watchMediumAvailabilityImpact DenialOfService Tampering
ClusterRole operator-defaultauthorization.k8s.io/subjectaccessreviewscreateMediumInformationDisclosure RBACQuery
ClusterRole operator-defaultauthentication.k8s.io/tokenreviewscreateMediumCredentialAccess InformationDisclosure RBACQuery
ClusterRole operator-defaultcert-manager.io/certificatescreate · delete · get · list · patch · update · watchLow
ClusterRole operator-defaultapps/controllerrevisionsget · list · watchLow
ClusterRole operator-defaultcore/endpointsget · listLow
ClusterRole operator-additional-controllers-defaultcore/eventscreate · patchLow
ClusterRole operator-defaultcore/eventscreate · get · list · patchLow
ClusterRole operator-defaultautoscaling/horizontalpodautoscalerscreate · delete · get · list · patch · update · watchLow
ClusterRole operator-defaultcert-manager.io/issuerscreate · delete · get · list · patch · update · watchLow
ClusterRole operator-defaultcore/limitrangesget · listLow
ClusterRole operator-additional-controllers-defaultcore/nodesget · list · watchLow
ClusterRole operator-defaultcore/nodesgetLow
ClusterRole operator-additional-controllers-defaultcore/persistentvolumeclaimsdelete · get · list · patch · update · watchLow
ClusterRole operator-defaultcore/persistentvolumeclaimsdelete · get · list · watchLow
ClusterRole operator-additional-controllers-defaultcore/persistentvolumesdelete · get · list · patch · update · watchLow
ClusterRole operator-defaultcore/persistentvolumesget · list · patch · watchLow
ClusterRole operator-defaultmonitoring.coreos.com/podmonitorscreate · delete · get · list · patch · update · watchLow
ClusterRole operator-additional-controllers-defaultcore/podsdelete · get · list · watchLow
ClusterRole operator-additional-controllers-defaultcluster.redpanda.com/redpandasget · list · watchLow
ClusterRole operator-defaultcluster.redpanda.com/redpandascreate · delete · get · list · patch · update · watchLow
ClusterRole operator-defaultcluster.redpanda.com/redpandas/finalizersupdateLow
ClusterRole operator-defaultcluster.redpanda.com/redpandas/statusget · patch · updateLow
ClusterRole operator-defaultcore/replicationcontrollersget · listLow
ClusterRole operator-defaultcore/resourcequotasget · listLow
ClusterRole operator-defaultcluster.redpanda.com/schemasget · list · patch · update · watchLow
ClusterRole operator-defaultcluster.redpanda.com/schemas/finalizersupdateLow
ClusterRole operator-defaultcluster.redpanda.com/schemas/statusget · patch · updateLow
ClusterRole operator-defaultmonitoring.coreos.com/servicemonitorscreate · delete · get · list · patch · update · watchLow
ClusterRole operator-additional-controllers-defaultapps/statefulsetsget · list · watchLow
ClusterRole operator-additional-controllers-defaultapps/statefulsets/statuspatch · updateLow
ClusterRole operator-defaultcluster.redpanda.com/topicsget · list · patch · update · watchLow
ClusterRole operator-defaultcluster.redpanda.com/topics/finalizersupdateLow
ClusterRole operator-defaultcluster.redpanda.com/topics/statusget · patch · updateLow
ClusterRole operator-defaultcluster.redpanda.com/usersget · list · patch · update · watchLow
ClusterRole operator-defaultcluster.redpanda.com/users/finalizersupdateLow
ClusterRole operator-defaultcluster.redpanda.com/users/statusget · patch · updateLow

⚠️ Potential Abuse (36)

The following security risks were found based on the above permissions:

📦 Workloads (1)

KindNameContainerImage
Deploymentoperatormanagerdocker.redpanda.com/redpandadata/redpanda-operator:v25.2.1-beta1

🤖 operator-crd-job

Namespace: default  |  Automount:

🔑 Permissions (0)

No explicit RBAC bindings.

📦 Workloads (0)

No workloads use this ServiceAccount.