Description

Redpanda operator helm chart

Overview

IdentityNamespaceAutomountSecretsPermissionsWorkloadsRisk
operatordefault751Critical
operator-migration-jobdefault651Critical

Numbers in the last two columns indicate how many bindings or workloads involve each ServiceAccount.


Identities

🤖 operator

Namespace: default  |  Automount:

🔑 Permissions (75)

RoleResourceVerbsRiskTags
ClusterRole operator-defaultrbac.authorization.k8s.io/clusterrolebindingscreate · delete · get · list · patch · update · watchCriticalBindingToPrivilegedRole ClusterAdminAccess InformationDisclosure PrivilegeEscalation RBACManipulation (+2 more)
ClusterRole operator-defaultrbac.authorization.k8s.io/clusterrolescreate · delete · get · list · patch · update · watchCriticalClusterAdminAccess InformationDisclosure PrivilegeEscalation RBACManipulation RBACQuery (+1 more)
ClusterRole operator-defaultcore/configmapscreate · delete · get · list · patch · update · watchCriticalConfigMapAccess DataExposure InformationDisclosure PotentialPrivilegeEscalation Tampering
ClusterRole operator-defaultapps/deploymentscreate · delete · get · list · patch · update · watchCriticalPersistence PotentialPrivilegeEscalation PrivilegeEscalation Tampering WorkloadLifecycle
ClusterRole operator-defaultcore/endpointscreate · delete · get · list · patch · update · watchCriticalDenialOfService ManInTheMiddle NetworkManipulation Tampering TrafficRedirection
ClusterRole operator-defaultdiscovery.k8s.io/endpointslicescreate · delete · get · list · patch · update · watchCriticalDenialOfService ManInTheMiddle NetworkManipulation Tampering TrafficRedirection
ClusterRole operator-defaultbatch/jobscreate · delete · get · list · patch · update · watchCriticalPotentialPrivilegeEscalation PrivilegeEscalation Tampering WorkloadLifecycle
ClusterRole operator-defaultcoordination.k8s.io/leasescreate · delete · get · list · patch · update · watchCriticalControlPlaneDisruption CriticalNamespace DenialOfService LeaderElectionAbuse Tampering
ClusterRole operator-defaultcore/podscreate · delete · get · list · patch · update · watchCriticalLateralMovement Persistence PotentialPrivilegeEscalation PrivilegeEscalation Tampering (+1 more)
ClusterRole operator-additional-controllers-defaultcore/secretsget · list · watchCriticalClusterWideSecretAccess CredentialAccess DataExposure InformationDisclosure SecretAccess
ClusterRole operator-defaultcore/secretscreate · delete · get · list · patch · update · watchCriticalClusterWideSecretAccess CredentialAccess DataExposure InformationDisclosure Persistence (+4 more)
ClusterRole operator-defaultcore/servicescreate · delete · get · list · patch · update · watchCriticalDenialOfService NetworkManipulation ServiceExposure Tampering
ClusterRole operator-defaultapps/statefulsetscreate · delete · get · list · patch · update · watchCriticalPersistence PotentialPrivilegeEscalation PrivilegeEscalation Tampering WorkloadLifecycle
ClusterRole operator-additional-controllers-defaultcore/configmapsget · list · watchHighConfigMapAccess DataExposure InformationDisclosure
ClusterRole operator-defaultnetworking.k8s.io/ingressescreate · delete · get · list · patch · update · watchHighDenialOfService NetworkManipulation ServiceExposure Tampering
ClusterRole operator-defaultcore/pods/logget · listHighClusterWideLogAccess DataExposure InformationDisclosure LogAccess
ClusterRole operator-defaultrbac.authorization.k8s.io/rolebindingscreate · delete · get · list · patch · update · watchHighBindingToPrivilegedRole InformationDisclosure PrivilegeEscalation RBACManipulation RBACQuery (+1 more)
ClusterRole operator-defaultrbac.authorization.k8s.io/rolescreate · delete · get · list · patch · update · watchHighInformationDisclosure PrivilegeEscalation RBACManipulation RBACQuery Reconnaissance
ClusterRole operator-defaultcore/serviceaccountscreate · delete · get · list · patch · update · watchHighIdentityManagement PotentialPrivilegeEscalation Tampering
ClusterRole operator-defaultpolicy/poddisruptionbudgetscreate · delete · get · list · patch · update · watchMediumAvailabilityImpact DenialOfService Tampering
ClusterRole operator-defaultauthorization.k8s.io/subjectaccessreviewscreateMediumInformationDisclosure RBACQuery
ClusterRole operator-defaultauthentication.k8s.io/tokenreviewscreateMediumCredentialAccess InformationDisclosure RBACQuery
ClusterRole operator-defaultcert-manager.io/certificatescreate · delete · get · list · patch · update · watchLow
ClusterRole operator-defaultcluster.redpanda.com/consolescreate · delete · get · list · patch · update · watchLow
ClusterRole operator-defaultcluster.redpanda.com/consoles/statusget · patch · updateLow
ClusterRole operator-defaultapps/controllerrevisionsget · list · watchLow
ClusterRole operator-additional-controllers-defaultcore/eventscreate · patchLow
ClusterRole operator-defaultcore/eventscreate · get · list · patchLow
ClusterRole operator-defaultcluster.redpanda.com/groupsget · list · patch · update · watchLow
ClusterRole operator-defaultcluster.redpanda.com/groups/finalizersupdateLow
ClusterRole operator-defaultcluster.redpanda.com/groups/statusget · patch · updateLow
ClusterRole operator-defaultautoscaling/horizontalpodautoscalerscreate · delete · get · list · patch · update · watchLow
ClusterRole operator-defaultcert-manager.io/issuerscreate · delete · get · list · patch · update · watchLow
ClusterRole operator-defaultcore/limitrangesget · listLow
ClusterRole operator-defaultcore/namespacesget · list · watchLowClusterStructure InformationDisclosure Reconnaissance
ClusterRole operator-defaultcluster.redpanda.com/nodepoolscreate · delete · get · list · patch · update · watchLow
ClusterRole operator-defaultcluster.redpanda.com/nodepools/finalizersupdateLow
ClusterRole operator-defaultcluster.redpanda.com/nodepools/statusget · patch · updateLow
ClusterRole operator-additional-controllers-defaultcore/nodesget · list · watchLow
ClusterRole operator-defaultcore/nodesgetLow
ClusterRole operator-additional-controllers-defaultcore/persistentvolumeclaimsdelete · get · list · patch · update · watchLow
ClusterRole operator-defaultcore/persistentvolumeclaimsdelete · get · list · watchLow
ClusterRole operator-additional-controllers-defaultcore/persistentvolumesdelete · get · list · patch · update · watchLow
ClusterRole operator-defaultcore/persistentvolumesget · list · patch · watchLow
ClusterRole operator-defaultmonitoring.coreos.com/podmonitorscreate · delete · get · list · patch · update · watchLow
ClusterRole operator-additional-controllers-defaultcore/podsdelete · get · list · watchLow
ClusterRole operator-defaultcluster.redpanda.com/redpandarolesget · list · patch · update · watchLow
ClusterRole operator-defaultcluster.redpanda.com/redpandaroles/finalizersupdateLow
ClusterRole operator-defaultcluster.redpanda.com/redpandaroles/statusget · patch · updateLow
ClusterRole operator-additional-controllers-defaultcluster.redpanda.com/redpandasget · list · watchLow
ClusterRole operator-defaultcluster.redpanda.com/redpandascreate · delete · get · list · patch · update · watchLow
ClusterRole operator-defaultcluster.redpanda.com/redpandas/finalizersupdateLow
ClusterRole operator-defaultcluster.redpanda.com/redpandas/statusget · patch · updateLow
ClusterRole operator-defaultcore/replicationcontrollersget · listLow
ClusterRole operator-defaultcore/resourcequotasget · listLow
ClusterRole operator-defaultcluster.redpanda.com/schemasget · list · patch · update · watchLow
ClusterRole operator-defaultcluster.redpanda.com/schemas/finalizersupdateLow
ClusterRole operator-defaultcluster.redpanda.com/schemas/statusget · patch · updateLow
ClusterRole operator-defaultmulticluster.x-k8s.io/serviceexportscreate · delete · get · list · patch · update · watchLow
ClusterRole operator-defaultmulticluster.x-k8s.io/serviceimportscreate · delete · get · list · patch · update · watchLow
ClusterRole operator-defaultmonitoring.coreos.com/servicemonitorscreate · delete · get · list · patch · update · watchLow
ClusterRole operator-defaultcluster.redpanda.com/shadowlinksget · list · patch · update · watchLow
ClusterRole operator-defaultcluster.redpanda.com/shadowlinks/finalizersupdateLow
ClusterRole operator-defaultcluster.redpanda.com/shadowlinks/statusget · patch · updateLow
ClusterRole operator-additional-controllers-defaultapps/statefulsetsget · list · watchLow
ClusterRole operator-additional-controllers-defaultapps/statefulsets/statuspatch · updateLow
ClusterRole operator-defaultcluster.redpanda.com/stretchclustersget · list · patch · update · watchLow
ClusterRole operator-defaultcluster.redpanda.com/stretchclusters/finalizersupdateLow
ClusterRole operator-defaultcluster.redpanda.com/stretchclusters/statusget · patch · updateLow
ClusterRole operator-defaultcluster.redpanda.com/topicsget · list · patch · update · watchLow
ClusterRole operator-defaultcluster.redpanda.com/topics/finalizersupdateLow
ClusterRole operator-defaultcluster.redpanda.com/topics/statusget · patch · updateLow
ClusterRole operator-defaultcluster.redpanda.com/usersget · list · patch · update · watchLow
ClusterRole operator-defaultcluster.redpanda.com/users/finalizersupdateLow
ClusterRole operator-defaultcluster.redpanda.com/users/statusget · patch · updateLow

⚠️ Potential Abuse (39)

The following security risks were found based on the above permissions:

📦 Workloads (1)

KindNameContainerImage
Deploymentoperatormanagerdocker.redpanda.com/redpandadata/redpanda-operator:v26.2.1-beta.1

🤖 operator-migration-job

Namespace: default  |  Automount:

🔑 Permissions (65)

RoleResourceVerbsRiskTags
ClusterRole operator-migration-job-defaultrbac.authorization.k8s.io/clusterrolebindingscreate · delete · get · list · patch · update · watchCriticalBindingToPrivilegedRole ClusterAdminAccess InformationDisclosure PrivilegeEscalation RBACManipulation (+2 more)
ClusterRole operator-migration-job-defaultrbac.authorization.k8s.io/clusterrolescreate · delete · get · list · patch · update · watchCriticalClusterAdminAccess InformationDisclosure PrivilegeEscalation RBACManipulation RBACQuery (+1 more)
ClusterRole operator-migration-job-defaultcore/configmapscreate · delete · get · list · patch · update · watchCriticalConfigMapAccess DataExposure InformationDisclosure PotentialPrivilegeEscalation Tampering
ClusterRole operator-migration-job-defaultapps/deploymentscreate · delete · get · list · patch · update · watchCriticalPersistence PotentialPrivilegeEscalation PrivilegeEscalation Tampering WorkloadLifecycle
ClusterRole operator-migration-job-defaultcore/endpointscreate · delete · get · list · patch · update · watchCriticalDenialOfService ManInTheMiddle NetworkManipulation Tampering TrafficRedirection
ClusterRole operator-migration-job-defaultdiscovery.k8s.io/endpointslicescreate · delete · get · list · patch · update · watchCriticalDenialOfService ManInTheMiddle NetworkManipulation Tampering TrafficRedirection
ClusterRole operator-migration-job-defaultbatch/jobscreate · delete · get · list · patch · update · watchCriticalPotentialPrivilegeEscalation PrivilegeEscalation Tampering WorkloadLifecycle
ClusterRole operator-migration-job-defaultcoordination.k8s.io/leasescreate · delete · get · list · patch · update · watchCriticalControlPlaneDisruption CriticalNamespace DenialOfService LeaderElectionAbuse Tampering
ClusterRole operator-migration-job-defaultcore/podscreate · delete · get · list · patch · update · watchCriticalLateralMovement Persistence PotentialPrivilegeEscalation PrivilegeEscalation Tampering (+1 more)
ClusterRole operator-migration-job-defaultcore/secretscreate · delete · get · list · patch · update · watchCriticalClusterWideSecretAccess CredentialAccess DataExposure InformationDisclosure Persistence (+4 more)
ClusterRole operator-migration-job-defaultcore/servicescreate · delete · get · list · patch · update · watchCriticalDenialOfService NetworkManipulation ServiceExposure Tampering
ClusterRole operator-migration-job-defaultapps/statefulsetscreate · delete · get · list · patch · update · watchCriticalPersistence PotentialPrivilegeEscalation PrivilegeEscalation Tampering WorkloadLifecycle
ClusterRole operator-migration-job-defaultnetworking.k8s.io/ingressescreate · delete · get · list · patch · update · watchHighDenialOfService NetworkManipulation ServiceExposure Tampering
ClusterRole operator-migration-job-defaultcore/pods/logget · listHighClusterWideLogAccess DataExposure InformationDisclosure LogAccess
ClusterRole operator-migration-job-defaultrbac.authorization.k8s.io/rolebindingscreate · delete · get · list · patch · update · watchHighBindingToPrivilegedRole InformationDisclosure PrivilegeEscalation RBACManipulation RBACQuery (+1 more)
ClusterRole operator-migration-job-defaultrbac.authorization.k8s.io/rolescreate · delete · get · list · patch · update · watchHighInformationDisclosure PrivilegeEscalation RBACManipulation RBACQuery Reconnaissance
ClusterRole operator-migration-job-defaultcore/serviceaccountscreate · delete · get · list · patch · update · watchHighIdentityManagement PotentialPrivilegeEscalation Tampering
ClusterRole operator-migration-job-defaultpolicy/poddisruptionbudgetscreate · delete · get · list · patch · update · watchMediumAvailabilityImpact DenialOfService Tampering
ClusterRole operator-migration-job-defaultauthorization.k8s.io/subjectaccessreviewscreateMediumInformationDisclosure RBACQuery
ClusterRole operator-migration-job-defaultauthentication.k8s.io/tokenreviewscreateMediumCredentialAccess InformationDisclosure RBACQuery
ClusterRole operator-migration-job-defaultcert-manager.io/certificatescreate · delete · get · list · patch · update · watchLow
ClusterRole operator-migration-job-defaultcluster.redpanda.com/consolescreate · delete · get · list · patch · update · watchLow
ClusterRole operator-migration-job-defaultcluster.redpanda.com/consoles/statusget · patch · updateLow
ClusterRole operator-migration-job-defaultapps/controllerrevisionsget · list · watchLow
ClusterRole operator-migration-job-defaultcore/eventscreate · get · list · patchLow
ClusterRole operator-migration-job-defaultcluster.redpanda.com/groupsget · list · patch · update · watchLow
ClusterRole operator-migration-job-defaultcluster.redpanda.com/groups/finalizersupdateLow
ClusterRole operator-migration-job-defaultcluster.redpanda.com/groups/statusget · patch · updateLow
ClusterRole operator-migration-job-defaultautoscaling/horizontalpodautoscalerscreate · delete · get · list · patch · update · watchLow
ClusterRole operator-migration-job-defaultcert-manager.io/issuerscreate · delete · get · list · patch · update · watchLow
ClusterRole operator-migration-job-defaultcore/limitrangesget · listLow
ClusterRole operator-migration-job-defaultcore/namespacesget · list · watchLowClusterStructure InformationDisclosure Reconnaissance
ClusterRole operator-migration-job-defaultcluster.redpanda.com/nodepoolscreate · delete · get · list · patch · update · watchLow
ClusterRole operator-migration-job-defaultcluster.redpanda.com/nodepools/finalizersupdateLow
ClusterRole operator-migration-job-defaultcluster.redpanda.com/nodepools/statusget · patch · updateLow
ClusterRole operator-migration-job-defaultcore/nodesgetLow
ClusterRole operator-migration-job-defaultcore/persistentvolumeclaimsdelete · get · list · watchLow
ClusterRole operator-migration-job-defaultcore/persistentvolumesget · list · patch · watchLow
ClusterRole operator-migration-job-defaultmonitoring.coreos.com/podmonitorscreate · delete · get · list · patch · update · watchLow
ClusterRole operator-migration-job-defaultcluster.redpanda.com/redpandarolesget · list · patch · update · watchLow
ClusterRole operator-migration-job-defaultcluster.redpanda.com/redpandaroles/finalizersupdateLow
ClusterRole operator-migration-job-defaultcluster.redpanda.com/redpandaroles/statusget · patch · updateLow
ClusterRole operator-migration-job-defaultcluster.redpanda.com/redpandascreate · delete · get · list · patch · update · watchLow
ClusterRole operator-migration-job-defaultcluster.redpanda.com/redpandas/finalizersupdateLow
ClusterRole operator-migration-job-defaultcluster.redpanda.com/redpandas/statusget · patch · updateLow
ClusterRole operator-migration-job-defaultcore/replicationcontrollersget · listLow
ClusterRole operator-migration-job-defaultcore/resourcequotasget · listLow
ClusterRole operator-migration-job-defaultcluster.redpanda.com/schemasget · list · patch · update · watchLow
ClusterRole operator-migration-job-defaultcluster.redpanda.com/schemas/finalizersupdateLow
ClusterRole operator-migration-job-defaultcluster.redpanda.com/schemas/statusget · patch · updateLow
ClusterRole operator-migration-job-defaultmulticluster.x-k8s.io/serviceexportscreate · delete · get · list · patch · update · watchLow
ClusterRole operator-migration-job-defaultmulticluster.x-k8s.io/serviceimportscreate · delete · get · list · patch · update · watchLow
ClusterRole operator-migration-job-defaultmonitoring.coreos.com/servicemonitorscreate · delete · get · list · patch · update · watchLow
ClusterRole operator-migration-job-defaultcluster.redpanda.com/shadowlinksget · list · patch · update · watchLow
ClusterRole operator-migration-job-defaultcluster.redpanda.com/shadowlinks/finalizersupdateLow
ClusterRole operator-migration-job-defaultcluster.redpanda.com/shadowlinks/statusget · patch · updateLow
ClusterRole operator-migration-job-defaultcluster.redpanda.com/stretchclustersget · list · patch · update · watchLow
ClusterRole operator-migration-job-defaultcluster.redpanda.com/stretchclusters/finalizersupdateLow
ClusterRole operator-migration-job-defaultcluster.redpanda.com/stretchclusters/statusget · patch · updateLow
ClusterRole operator-migration-job-defaultcluster.redpanda.com/topicsget · list · patch · update · watchLow
ClusterRole operator-migration-job-defaultcluster.redpanda.com/topics/finalizersupdateLow
ClusterRole operator-migration-job-defaultcluster.redpanda.com/topics/statusget · patch · updateLow
ClusterRole operator-migration-job-defaultcluster.redpanda.com/usersget · list · patch · update · watchLow
ClusterRole operator-migration-job-defaultcluster.redpanda.com/users/finalizersupdateLow
ClusterRole operator-migration-job-defaultcluster.redpanda.com/users/statusget · patch · updateLow

⚠️ Potential Abuse (39)

The following security risks were found based on the above permissions:

📦 Workloads (1)

KindNameContainerImage
Joboperator-migrationmigrationdocker.redpanda.com/redpandadata/redpanda-operator:v26.2.1-beta.1