Description

bind a resource to a resource

Overview

IdentityNamespaceAutomountSecretsPermissionsWorkloadsRisk
integration-operatordefault161Critical

Numbers in the last two columns indicate how many bindings or workloads involve each ServiceAccount.


Identities

🤖 integration-operator

Namespace: default  |  Automount:

🔑 Permissions (16)

RoleResourceVerbsRiskTags
ClusterRole integration-operatorcoordination.k8s.io/leasescreate · delete · get · list · patch · update · watchCriticalControlPlaneDisruption CriticalNamespace DenialOfService LeaderElectionAbuse Tampering
ClusterRole integration-operatorcore/podscreate · delete · get · list · patch · update · watchCriticalLateralMovement Persistence PotentialPrivilegeEscalation PrivilegeEscalation Tampering (+1 more)
ClusterRole integration-operatorcore/secretsget · list · watchCriticalClusterWideSecretAccess CredentialAccess DataExposure InformationDisclosure SecretAccess
ClusterRole integration-operatorcore/serviceaccountsimpersonateCriticalClusterAdminAccess Impersonation PrivilegeEscalation Spoofing
ClusterRole integration-operatorcore/servicescreate · delete · get · list · patch · update · watchCriticalDenialOfService NetworkManipulation ServiceExposure Tampering
ClusterRole integration-operatorcore/configmapsget · list · watchHighConfigMapAccess DataExposure InformationDisclosure
ClusterRole integration-operatorcore/eventscreate · delete · get · list · patch · update · watchMediumInformationDisclosure OperationalData Reconnaissance
ClusterRole integration-operatorintegration.rock8s.com/deferredresourcescreate · delete · get · list · patch · update · watchLow
ClusterRole integration-operatorintegration.rock8s.com/deferredresources/finalizersupdateLow
ClusterRole integration-operatorintegration.rock8s.com/deferredresources/statusget · patch · updateLow
ClusterRole integration-operatorintegration.rock8s.com/plugscreate · delete · get · list · patch · update · watchLow
ClusterRole integration-operatorintegration.rock8s.com/plugs/finalizersupdateLow
ClusterRole integration-operatorintegration.rock8s.com/plugs/statusget · patch · updateLow
ClusterRole integration-operatorintegration.rock8s.com/socketscreate · delete · get · list · patch · update · watchLow
ClusterRole integration-operatorintegration.rock8s.com/sockets/finalizersupdateLow
ClusterRole integration-operatorintegration.rock8s.com/sockets/statusget · patch · updateLow

⚠️ Potential Abuse (15)

The following security risks were found based on the above permissions:

📦 Workloads (1)

KindNameContainerImage
Deploymentintegration-operatorintegration-operatorregistry.gitlab.com/bitspur/rock8s/integration-operator:1.2.0