Description

bind a resource to a resource

Overview

IdentityNamespaceAutomountSecretsPermissionsWorkloadsRisk
resource-binding-operatordefault91Critical

Numbers in the last two columns indicate how many bindings or workloads involve each ServiceAccount.


Identities

🤖 resource-binding-operator

Namespace: default  |  Automount:

🔑 Permissions (9)

RoleResourceVerbsRiskTags
ClusterRole resource-binding-operator*get · list · watchCriticalClusterStructure ClusterWideAccess ClusterWideLogAccess ClusterWideSecretAccess ConfigMapAccess (+15 more)
ClusterRole resource-binding-operatorcore/configmapscreate · delete · get · list · patch · update · watchCriticalConfigMapAccess DataExposure InformationDisclosure PotentialPrivilegeEscalation Tampering
ClusterRole resource-binding-operatorcoordination.k8s.io/leasescreate · delete · get · list · patch · update · watchCriticalControlPlaneDisruption CriticalNamespace DenialOfService LeaderElectionAbuse Tampering
ClusterRole resource-binding-operatorauthorization.k8s.io/subjectaccessreviewscreateMediumInformationDisclosure RBACQuery
ClusterRole resource-binding-operatorauthentication.k8s.io/tokenreviewscreateMediumCredentialAccess InformationDisclosure RBACQuery
ClusterRole resource-binding-operatorcore/eventscreate · patchLow
ClusterRole resource-binding-operatorresourcebinding.rock8s.com/resourcebindingscreate · delete · get · list · patch · update · watchLow
ClusterRole resource-binding-operatorresourcebinding.rock8s.com/resourcebindings/finalizersupdateLow
ClusterRole resource-binding-operatorresourcebinding.rock8s.com/resourcebindings/statusget · patch · updateLow

⚠️ Potential Abuse (26)

The following security risks were found based on the above permissions:

📦 Workloads (1)

KindNameContainerImage
Deploymentresource-binding-operatorresource-binding-operatorregistry.gitlab.com/bitspur/rock8s/resource-binding-operator:0.1.0