Description

File, Block, and Object Storage Services for your Cloud-Native Environment

Overview

IdentityNamespaceAutomountSecretsPermissionsWorkloadsRisk
rook-ceph-systemdefault1161Critical
rook-csi-rbd-provisioner-sadefault240Critical
rook-ceph-cmd-reporterdefault20High
rook-ceph-mgrdefault300High
rook-ceph-osddefault50Medium
rook-csi-cephfs-provisioner-sadefault220Medium
rook-csi-rbd-plugin-sadefault80Medium
objectstorage-provisionerdefault110Low
rook-ceph-purge-osddefault40Low
rook-csi-cephfs-plugin-sadefault50Low
rook-ceph-defaultdefault00
rook-ceph-rgwdefault00

Numbers in the last two columns indicate how many bindings or workloads involve each ServiceAccount.


Identities

🤖 rook-ceph-system

Namespace: default  |  Automount:

🔑 Permissions (116)

RoleResourceVerbsRiskTags
ClusterRole rook-ceph-globalcore/endpointscreate · delete · get · list · patch · update · watchCriticalDenialOfService ManInTheMiddle NetworkManipulation Tampering TrafficRedirection
ClusterRole rook-ceph-globaldiscovery.k8s.io/endpointscreate · delete · get · list · patch · update · watchCriticalDenialOfService ManInTheMiddle NetworkManipulation Tampering TrafficRedirection
ClusterRole rook-ceph-globalcore/endpointslicescreate · delete · get · list · patch · update · watchCriticalDenialOfService ManInTheMiddle NetworkManipulation Tampering TrafficRedirection
ClusterRole rook-ceph-globaldiscovery.k8s.io/endpointslicescreate · delete · get · list · patch · update · watchCriticalDenialOfService ManInTheMiddle NetworkManipulation Tampering TrafficRedirection
ClusterRole rook-ceph-systemcore/pods/execcreateCriticalClusterWidePodExec CodeExecution ElevationOfPrivilege LateralMovement PodExec (+1 more)
ClusterRole rook-ceph-globalcore/secretsget · list · watchCriticalClusterWideSecretAccess CredentialAccess DataExposure InformationDisclosure SecretAccess
ClusterRole rook-ceph-globalcore/servicescreate · delete · get · list · patch · update · watchCriticalDenialOfService NetworkManipulation ServiceExposure Tampering
ClusterRole rook-ceph-globalcore/configmapsget · list · watchHighConfigMapAccess DataExposure InformationDisclosure
Role rook-ceph-systemcore/configmapscreate · delete · get · list · patch · update · watchHighConfigMapAccess DataExposure InformationDisclosure PotentialPrivilegeEscalation Tampering
Role rook-ceph-systemcore/podscreate · delete · get · list · patch · update · watchHighLateralMovement Persistence PotentialPrivilegeEscalation Tampering WorkloadExecution
ClusterRole rook-ceph-systemcore/pods/logget · listHighClusterWideLogAccess DataExposure InformationDisclosure LogAccess
Role rook-ceph-systemcore/servicescreate · delete · get · list · patch · update · watchHighDenialOfService NetworkManipulation ServiceExposure Tampering
ClusterRole rook-ceph-globalcore/eventscreate · delete · get · list · patch · update · watchMediumInformationDisclosure OperationalData Reconnaissance
ClusterRole rook-ceph-globalceph.rook.io/cephblockpoolradosnamespacesget · list · update · watchLow
ClusterRole rook-ceph-globalceph.rook.io/cephblockpoolradosnamespaces/finalizersupdateLow
ClusterRole rook-ceph-globalceph.rook.io/cephblockpoolradosnamespaces/statusupdateLow
ClusterRole rook-ceph-globalceph.rook.io/cephblockpoolsget · list · update · watchLow
ClusterRole rook-ceph-globalceph.rook.io/cephblockpools/finalizersupdateLow
ClusterRole rook-ceph-globalceph.rook.io/cephblockpools/statusupdateLow
ClusterRole rook-ceph-globalceph.rook.io/cephbucketnotificationsget · list · update · watchLow
ClusterRole rook-ceph-globalceph.rook.io/cephbucketnotifications/finalizersupdateLow
ClusterRole rook-ceph-globalceph.rook.io/cephbucketnotifications/statusupdateLow
ClusterRole rook-ceph-globalceph.rook.io/cephbuckettopicsget · list · update · watchLow
ClusterRole rook-ceph-globalceph.rook.io/cephbuckettopics/finalizersupdateLow
ClusterRole rook-ceph-globalceph.rook.io/cephbuckettopics/statusupdateLow
ClusterRole rook-ceph-globalceph.rook.io/cephclientsget · list · update · watchLow
ClusterRole rook-ceph-globalceph.rook.io/cephclients/finalizersupdateLow
ClusterRole rook-ceph-globalceph.rook.io/cephclients/statusupdateLow
ClusterRole rook-ceph-globalceph.rook.io/cephclustersget · list · update · watchLow
ClusterRole rook-ceph-globalceph.rook.io/cephclusters/finalizersupdateLow
ClusterRole rook-ceph-globalceph.rook.io/cephclusters/statusupdateLow
ClusterRole rook-ceph-systemcsi.ceph.io/cephconnectionscreate · delete · get · list · update · watchLow
ClusterRole rook-ceph-globalceph.rook.io/cephcosidriversget · list · update · watchLow
ClusterRole rook-ceph-globalceph.rook.io/cephfilesystemmirrorsget · list · update · watchLow
ClusterRole rook-ceph-globalceph.rook.io/cephfilesystemmirrors/finalizersupdateLow
ClusterRole rook-ceph-globalceph.rook.io/cephfilesystemmirrors/statusupdateLow
ClusterRole rook-ceph-globalceph.rook.io/cephfilesystemsget · list · update · watchLow
ClusterRole rook-ceph-globalceph.rook.io/cephfilesystems/finalizersupdateLow
ClusterRole rook-ceph-globalceph.rook.io/cephfilesystems/statusupdateLow
ClusterRole rook-ceph-globalceph.rook.io/cephfilesystemsubvolumegroupsget · list · update · watchLow
ClusterRole rook-ceph-globalceph.rook.io/cephfilesystemsubvolumegroups/finalizersupdateLow
ClusterRole rook-ceph-globalceph.rook.io/cephfilesystemsubvolumegroups/statusupdateLow
ClusterRole rook-ceph-globalceph.rook.io/cephnfsesget · list · update · watchLow
ClusterRole rook-ceph-globalceph.rook.io/cephnfses/finalizersupdateLow
ClusterRole rook-ceph-globalceph.rook.io/cephnfses/statusupdateLow
ClusterRole rook-ceph-globalceph.rook.io/cephobjectrealmsget · list · update · watchLow
ClusterRole rook-ceph-globalceph.rook.io/cephobjectrealms/finalizersupdateLow
ClusterRole rook-ceph-globalceph.rook.io/cephobjectrealms/statusupdateLow
ClusterRole rook-ceph-globalceph.rook.io/cephobjectstoresget · list · update · watchLow
ClusterRole rook-ceph-globalceph.rook.io/cephobjectstores/finalizersupdateLow
ClusterRole rook-ceph-globalceph.rook.io/cephobjectstores/statusupdateLow
ClusterRole rook-ceph-globalceph.rook.io/cephobjectstoreusersget · list · update · watchLow
ClusterRole rook-ceph-globalceph.rook.io/cephobjectstoreusers/finalizersupdateLow
ClusterRole rook-ceph-globalceph.rook.io/cephobjectstoreusers/statusupdateLow
ClusterRole rook-ceph-globalceph.rook.io/cephobjectzonegroupsget · list · update · watchLow
ClusterRole rook-ceph-globalceph.rook.io/cephobjectzonegroups/finalizersupdateLow
ClusterRole rook-ceph-globalceph.rook.io/cephobjectzonegroups/statusupdateLow
ClusterRole rook-ceph-globalceph.rook.io/cephobjectzonesget · list · update · watchLow
ClusterRole rook-ceph-globalceph.rook.io/cephobjectzones/finalizersupdateLow
ClusterRole rook-ceph-globalceph.rook.io/cephobjectzones/statusupdateLow
ClusterRole rook-ceph-globalceph.rook.io/cephrbdmirrorsget · list · update · watchLow
ClusterRole rook-ceph-globalceph.rook.io/cephrbdmirrors/finalizersupdateLow
ClusterRole rook-ceph-globalceph.rook.io/cephrbdmirrors/statusupdateLow
Role rook-ceph-systemcert-manager.io/certificatescreate · delete · getLow
ClusterRole rook-ceph-systemcsi.ceph.io/clientprofilescreate · delete · get · list · update · watchLow
ClusterRole rook-ceph-object-bucketcore/configmapscreate · delete · get · updateLow
ClusterRole rook-ceph-globalbatch/cronjobscreate · delete · deletecollection · get · list · update · watchLow
Role rook-ceph-systembatch/cronjobsdeleteLow
ClusterRole rook-ceph-globalstorage.k8s.io/csidriverscreate · delete · get · updateLow
ClusterRole rook-ceph-systemapiextensions.k8s.io/customresourcedefinitionsgetLow
Role rook-ceph-systemapps/daemonsetscreate · delete · deletecollection · get · list · update · watchLow
Role rook-ceph-systemextensions/daemonsetscreate · delete · deletecollection · get · list · update · watchLow
ClusterRole rook-ceph-globalapps/deploymentscreate · delete · deletecollection · get · list · update · watchLow
Role rook-ceph-systemapps/deploymentscreate · delete · deletecollection · get · list · update · watchLow
ClusterRole rook-ceph-globalextensions/deploymentscreate · delete · deletecollection · get · list · update · watchLow
Role rook-ceph-systemextensions/deploymentscreate · delete · deletecollection · get · list · update · watchLow
ClusterRole rook-ceph-globalpolicy/deploymentscreate · delete · deletecollection · get · list · update · watchLow
ClusterRole rook-ceph-globalapps/deployments/finalizersupdateLow
ClusterRole rook-ceph-systemcsi.ceph.io/driverscreate · delete · get · list · update · watchLow
ClusterRole rook-ceph-globalcore/endpointslices/restrictedcreate · delete · get · list · patch · update · watchLow
ClusterRole rook-ceph-globaldiscovery.k8s.io/endpointslices/restrictedcreate · delete · get · list · patch · update · watchLow
ClusterRole rook-ceph-globaldiscovery.k8s.io/eventscreate · delete · get · list · patch · update · watchLow
Role rook-ceph-systemcert-manager.io/issuerscreate · delete · getLow
ClusterRole rook-ceph-globalbatch/jobscreate · delete · deletecollection · get · list · update · watchLow
ClusterRole rook-ceph-globalhealthchecking.openshift.io/machinedisruptionbudgetscreate · delete · get · list · update · watchLow
ClusterRole rook-ceph-globalmachine.openshift.io/machinescreate · delete · get · list · update · watchLow
ClusterRole rook-ceph-globalk8s.cni.cncf.io/network-attachment-definitionsgetLow
ClusterRole rook-ceph-systemcsiaddons.openshift.io/networkfencescreate · delete · deletecollection · get · list · update · watchLow
ClusterRole rook-ceph-globalcore/nodesget · list · watchLow
ClusterRole rook-ceph-globalcore/nodes/proxyget · list · watchLow
ClusterRole rook-ceph-object-bucketobjectbucket.io/objectbucketclaimsget · list · update · watchLow
ClusterRole rook-ceph-object-bucketobjectbucket.io/objectbucketclaims/finalizersupdateLow
ClusterRole rook-ceph-object-bucketobjectbucket.io/objectbucketclaims/statusupdateLow
ClusterRole rook-ceph-object-bucketobjectbucket.io/objectbucketscreate · delete · get · list · update · watchLow
ClusterRole rook-ceph-object-bucketobjectbucket.io/objectbuckets/finalizersupdateLow
ClusterRole rook-ceph-object-bucketobjectbucket.io/objectbuckets/statusupdateLow
ClusterRole rook-ceph-systemcsi.ceph.io/operatorconfigscreate · delete · get · list · update · watchLow
ClusterRole rook-ceph-globalcore/persistentvolumeclaimscreate · delete · get · list · patch · update · watchLow
ClusterRole rook-ceph-globaldiscovery.k8s.io/persistentvolumeclaimscreate · delete · get · list · patch · update · watchLow
ClusterRole rook-ceph-globalcore/persistentvolumescreate · delete · get · list · patch · update · watchLow
ClusterRole rook-ceph-globaldiscovery.k8s.io/persistentvolumescreate · delete · get · list · patch · update · watchLow
ClusterRole rook-ceph-globalapps/poddisruptionbudgetscreate · delete · deletecollection · get · list · update · watchLow
ClusterRole rook-ceph-globalextensions/poddisruptionbudgetscreate · delete · deletecollection · get · list · update · watchLow
ClusterRole rook-ceph-globalpolicy/poddisruptionbudgetscreate · delete · deletecollection · get · list · update · watchLow
ClusterRole rook-ceph-globalcore/podsget · list · watchLow
ClusterRole rook-ceph-systemcore/podsget · listLow
ClusterRole rook-ceph-globalapps/replicasetscreate · delete · deletecollection · get · list · update · watchLow
ClusterRole rook-ceph-globalextensions/replicasetscreate · delete · deletecollection · get · list · update · watchLow
ClusterRole rook-ceph-globalpolicy/replicasetscreate · delete · deletecollection · get · list · update · watchLow
ClusterRole rook-ceph-object-bucketcore/secretscreate · delete · get · updateLow
Role rook-ceph-systemmulticluster.x-k8s.io/serviceexportscreate · getLow
ClusterRole rook-ceph-globaldiscovery.k8s.io/servicescreate · delete · get · list · patch · update · watchLow
Role rook-ceph-systemapps/statefulsetscreate · delete · deletecollection · get · list · update · watchLow
Role rook-ceph-systemextensions/statefulsetscreate · delete · deletecollection · get · list · update · watchLow
ClusterRole rook-ceph-globalstorage.k8s.io/storageclassesget · list · watchLow
ClusterRole rook-ceph-object-bucketstorage.k8s.io/storageclassesgetLow

⚠️ Potential Abuse (17)

The following security risks were found based on the above permissions:

📦 Workloads (1)

KindNameContainerImage
Deploymentrook-ceph-operatorrook-ceph-operatordocker.io/rook/ceph:v1.17.4

🤖 rook-csi-rbd-provisioner-sa

Namespace: default  |  Automount:

🔑 Permissions (24)

RoleResourceVerbsRiskTags
ClusterRole rbd-external-provisioner-runnercore/secretsget · list · watchCriticalClusterWideSecretAccess CredentialAccess DataExposure InformationDisclosure SecretAccess
ClusterRole rbd-external-provisioner-runnerstorage.k8s.io/csinodesget · list · watchMediumInformationDisclosure NodeAccess Reconnaissance StorageDetailsDisclosure
ClusterRole rbd-external-provisioner-runnerauthentication.k8s.io/tokenreviewscreateMediumCredentialAccess InformationDisclosure RBACQuery
ClusterRole rbd-external-provisioner-runnercore/configmapsgetLow
ClusterRole rbd-external-provisioner-runnercore/eventscreate · list · patch · update · watchLow
Role rbd-external-provisioner-cfgcoordination.k8s.io/leasescreate · delete · get · list · update · watchLow
ClusterRole rbd-external-provisioner-runnercore/nodesget · list · watchLow
ClusterRole rbd-external-provisioner-runnercore/persistentvolumeclaimsget · list · update · watchLow
ClusterRole rbd-external-provisioner-runnercore/persistentvolumeclaims/statuspatchLow
ClusterRole rbd-external-provisioner-runnercore/persistentvolumescreate · delete · get · list · patch · update · watchLow
ClusterRole rbd-external-provisioner-runnercore/serviceaccountsgetLow
ClusterRole rbd-external-provisioner-runnercore/serviceaccounts/tokencreateLow
ClusterRole rbd-external-provisioner-runnerstorage.k8s.io/storageclassesget · list · watchLow
ClusterRole rbd-external-provisioner-runnerstorage.k8s.io/volumeattachmentsget · list · patch · watchLow
ClusterRole rbd-external-provisioner-runnerstorage.k8s.io/volumeattachments/statuspatchLow
ClusterRole rbd-external-provisioner-runnerreplication.storage.openshift.io/volumegroupreplicationclassesget · list · watchLow
ClusterRole rbd-external-provisioner-runnerreplication.storage.openshift.io/volumegroupreplicationcontentsget · list · watchLow
ClusterRole rbd-external-provisioner-runnergroupsnapshot.storage.k8s.io/volumegroupsnapshotclassesget · list · watchLow
ClusterRole rbd-external-provisioner-runnergroupsnapshot.storage.k8s.io/volumegroupsnapshotcontentsget · list · patch · update · watchLow
ClusterRole rbd-external-provisioner-runnergroupsnapshot.storage.k8s.io/volumegroupsnapshotcontents/statuspatch · updateLow
ClusterRole rbd-external-provisioner-runnersnapshot.storage.k8s.io/volumesnapshotclassesget · list · watchLow
ClusterRole rbd-external-provisioner-runnersnapshot.storage.k8s.io/volumesnapshotcontentsget · list · patch · update · watchLow
ClusterRole rbd-external-provisioner-runnersnapshot.storage.k8s.io/volumesnapshotcontents/statuspatch · updateLow
ClusterRole rbd-external-provisioner-runnersnapshot.storage.k8s.io/volumesnapshotsget · list · watchLow

⚠️ Potential Abuse (5)

The following security risks were found based on the above permissions:

📦 Workloads (0)

No workloads use this ServiceAccount.


🤖 rook-ceph-mgr

Namespace: default  |  Automount:

🔑 Permissions (30)

RoleResourceVerbsRiskTags
ClusterRole rook-ceph-mgr-clustercore/configmapsget · list · watchHighConfigMapAccess DataExposure InformationDisclosure
Role rook-ceph-mgrcore/podscreate · delete · get · list · update · watchHighLateralMovement Persistence PotentialPrivilegeEscalation WorkloadExecution
ClusterRole rook-ceph-mgr-clustercore/eventscreate · get · list · patch · watchMediumInformationDisclosure OperationalData Reconnaissance
Role rook-ceph-mgrcore/pods/logcreate · delete · get · list · update · watchMediumDataExposure InformationDisclosure LogAccess
Role rook-ceph-mgrceph.rook.io/cephblockpoolradosnamespacescreate · delete · get · list · patch · update · watchLow
Role rook-ceph-mgrceph.rook.io/cephblockpoolscreate · delete · get · list · patch · update · watchLow
Role rook-ceph-mgrceph.rook.io/cephbucketnotificationscreate · delete · get · list · patch · update · watchLow
Role rook-ceph-mgrceph.rook.io/cephbuckettopicscreate · delete · get · list · patch · update · watchLow
Role rook-ceph-mgrceph.rook.io/cephclientscreate · delete · get · list · patch · update · watchLow
Role rook-ceph-mgrceph.rook.io/cephclusterscreate · delete · get · list · patch · update · watchLow
Role rook-ceph-mgrceph.rook.io/cephcosidriverscreate · delete · get · list · patch · update · watchLow
Role rook-ceph-mgrceph.rook.io/cephfilesystemmirrorscreate · delete · get · list · patch · update · watchLow
Role rook-ceph-mgrceph.rook.io/cephfilesystemscreate · delete · get · list · patch · update · watchLow
Role rook-ceph-mgrceph.rook.io/cephfilesystemsubvolumegroupscreate · delete · get · list · patch · update · watchLow
Role rook-ceph-mgrceph.rook.io/cephnfsescreate · delete · get · list · patch · update · watchLow
Role rook-ceph-mgrceph.rook.io/cephobjectrealmscreate · delete · get · list · patch · update · watchLow
Role rook-ceph-mgrceph.rook.io/cephobjectstorescreate · delete · get · list · patch · update · watchLow
Role rook-ceph-mgrceph.rook.io/cephobjectstoreuserscreate · delete · get · list · patch · update · watchLow
Role rook-ceph-mgrceph.rook.io/cephobjectzonegroupscreate · delete · get · list · patch · update · watchLow
Role rook-ceph-mgrceph.rook.io/cephobjectzonescreate · delete · get · list · patch · update · watchLow
Role rook-ceph-mgrceph.rook.io/cephrbdmirrorscreate · delete · get · list · patch · update · watchLow
Role rook-ceph-mgrapps/deploymentsdelete · patchLow
Role rook-ceph-mgrapps/deployments/scaledelete · patchLow
Role rook-ceph-mgrbatch/jobscreate · delete · get · list · update · watchLow
ClusterRole rook-ceph-mgr-clustercore/nodesget · list · watchLow
ClusterRole rook-ceph-mgr-clustercore/nodes/proxyget · list · watchLow
Role rook-ceph-mgrcore/persistentvolumeclaimsdeleteLow
ClusterRole rook-ceph-mgr-clustercore/persistentvolumesget · list · watchLow
Role rook-ceph-mgrcore/servicescreate · delete · get · list · update · watchLow
ClusterRole rook-ceph-mgr-clusterstorage.k8s.io/storageclassesget · list · watchLow

⚠️ Potential Abuse (6)

The following security risks were found based on the above permissions:

📦 Workloads (0)

No workloads use this ServiceAccount.


🤖 rook-ceph-cmd-reporter

Namespace: default  |  Automount:

🔑 Permissions (2)

RoleResourceVerbsRiskTags
Role rook-ceph-cmd-reportercore/podscreate · delete · get · list · update · watchHighLateralMovement Persistence PotentialPrivilegeEscalation WorkloadExecution
Role rook-ceph-cmd-reportercore/configmapscreate · delete · get · list · update · watchMediumConfigMapAccess DataExposure InformationDisclosure

⚠️ Potential Abuse (3)

The following security risks were found based on the above permissions:

📦 Workloads (0)

No workloads use this ServiceAccount.


🤖 rook-csi-cephfs-provisioner-sa

Namespace: default  |  Automount:

🔑 Permissions (22)

RoleResourceVerbsRiskTags
ClusterRole cephfs-external-provisioner-runnerstorage.k8s.io/csinodesget · list · watchMediumInformationDisclosure NodeAccess Reconnaissance StorageDetailsDisclosure
ClusterRole cephfs-external-provisioner-runnerauthentication.k8s.io/tokenreviewscreateMediumCredentialAccess InformationDisclosure RBACQuery
ClusterRole cephfs-external-provisioner-runnercore/configmapsgetLow
ClusterRole cephfs-external-provisioner-runnercore/eventscreate · list · patch · update · watchLow
Role cephfs-external-provisioner-cfgcoordination.k8s.io/leasescreate · delete · get · list · update · watchLow
ClusterRole cephfs-external-provisioner-runnercore/nodesget · list · watchLow
ClusterRole cephfs-external-provisioner-runnercore/persistentvolumeclaimsget · list · patch · update · watchLow
ClusterRole cephfs-external-provisioner-runnercore/persistentvolumeclaims/statuspatchLow
ClusterRole cephfs-external-provisioner-runnercore/persistentvolumescreate · delete · get · list · patch · update · watchLow
ClusterRole cephfs-external-provisioner-runnercore/secretsget · listLow
ClusterRole cephfs-external-provisioner-runnercore/serviceaccountsgetLow
ClusterRole cephfs-external-provisioner-runnercore/serviceaccounts/tokencreateLow
ClusterRole cephfs-external-provisioner-runnerstorage.k8s.io/storageclassesget · list · watchLow
ClusterRole cephfs-external-provisioner-runnerstorage.k8s.io/volumeattachmentsget · list · patch · watchLow
ClusterRole cephfs-external-provisioner-runnerstorage.k8s.io/volumeattachments/statuspatchLow
ClusterRole cephfs-external-provisioner-runnergroupsnapshot.storage.k8s.io/volumegroupsnapshotclassesget · list · watchLow
ClusterRole cephfs-external-provisioner-runnergroupsnapshot.storage.k8s.io/volumegroupsnapshotcontentsget · list · patch · update · watchLow
ClusterRole cephfs-external-provisioner-runnergroupsnapshot.storage.k8s.io/volumegroupsnapshotcontents/statuspatch · updateLow
ClusterRole cephfs-external-provisioner-runnersnapshot.storage.k8s.io/volumesnapshotclassesget · list · watchLow
ClusterRole cephfs-external-provisioner-runnersnapshot.storage.k8s.io/volumesnapshotcontentsget · list · patch · update · watchLow
ClusterRole cephfs-external-provisioner-runnersnapshot.storage.k8s.io/volumesnapshotcontents/statuspatch · updateLow
ClusterRole cephfs-external-provisioner-runnersnapshot.storage.k8s.io/volumesnapshotsget · list · watchLow

⚠️ Potential Abuse (3)

The following security risks were found based on the above permissions:

📦 Workloads (0)

No workloads use this ServiceAccount.


🤖 rook-csi-rbd-plugin-sa

Namespace: default  |  Automount:

🔑 Permissions (8)

RoleResourceVerbsRiskTags
ClusterRole rbd-csi-nodepluginauthentication.k8s.io/tokenreviewscreateMediumCredentialAccess InformationDisclosure RBACQuery
ClusterRole rbd-csi-nodeplugincore/configmapsgetLow
ClusterRole rbd-csi-nodeplugincore/nodesgetLow
ClusterRole rbd-csi-nodeplugincore/persistentvolumesget · listLow
ClusterRole rbd-csi-nodeplugincore/secretsget · listLow
ClusterRole rbd-csi-nodeplugincore/serviceaccountsgetLow
ClusterRole rbd-csi-nodeplugincore/serviceaccounts/tokencreateLow
ClusterRole rbd-csi-nodepluginstorage.k8s.io/volumeattachmentsget · listLow

⚠️ Potential Abuse (2)

The following security risks were found based on the above permissions:

📦 Workloads (0)

No workloads use this ServiceAccount.


🤖 rook-ceph-osd

Namespace: default  |  Automount:

🔑 Permissions (5)

RoleResourceVerbsRiskTags
Role rook-ceph-osdcore/configmapscreate · delete · get · list · update · watchMediumConfigMapAccess DataExposure InformationDisclosure
Role rook-ceph-osdceph.rook.io/cephclusterscreate · delete · get · list · updateLow
Role rook-ceph-osdceph.rook.io/cephclusters/finalizerscreate · delete · get · list · updateLow
ClusterRole rook-ceph-osdcore/nodesget · listLow
Role rook-ceph-osdcore/secretsget · updateLow

⚠️ Potential Abuse (2)

The following security risks were found based on the above permissions:

📦 Workloads (0)

No workloads use this ServiceAccount.


🤖 objectstorage-provisioner

Namespace: default  |  Automount:

🔑 Permissions (11)

RoleResourceVerbsRiskTags
ClusterRole objectstorage-provisioner-roleobjectstorage.k8s.io/bucketaccessclassescreate · delete · get · list · update · watchLow
ClusterRole objectstorage-provisioner-roleobjectstorage.k8s.io/bucketaccessclasses/statuscreate · delete · get · list · update · watchLow
ClusterRole objectstorage-provisioner-roleobjectstorage.k8s.io/bucketaccessescreate · delete · get · list · update · watchLow
ClusterRole objectstorage-provisioner-roleobjectstorage.k8s.io/bucketaccesses/statuscreate · delete · get · list · update · watchLow
ClusterRole objectstorage-provisioner-roleobjectstorage.k8s.io/bucketclaimscreate · delete · get · list · update · watchLow
ClusterRole objectstorage-provisioner-roleobjectstorage.k8s.io/bucketclaims/statuscreate · delete · get · list · update · watchLow
ClusterRole objectstorage-provisioner-roleobjectstorage.k8s.io/bucketscreate · delete · get · list · update · watchLow
ClusterRole objectstorage-provisioner-roleobjectstorage.k8s.io/buckets/statuscreate · delete · get · list · update · watchLow
ClusterRole objectstorage-provisioner-rolecore/eventscreate · delete · get · updateLow
ClusterRole objectstorage-provisioner-rolecoordination.k8s.io/leasescreate · delete · get · list · update · watchLow
ClusterRole objectstorage-provisioner-rolecore/secretscreate · delete · get · updateLow

⚠️ Potential Abuse (1)

The following security risks were found based on the above permissions:

📦 Workloads (0)

No workloads use this ServiceAccount.


🤖 rook-csi-cephfs-plugin-sa

Namespace: default  |  Automount:

🔑 Permissions (5)

RoleResourceVerbsRiskTags
ClusterRole cephfs-csi-nodeplugincore/configmapsgetLow
ClusterRole cephfs-csi-nodeplugincore/nodesgetLow
ClusterRole cephfs-csi-nodeplugincore/secretsgetLow
ClusterRole cephfs-csi-nodeplugincore/serviceaccountsgetLow
ClusterRole cephfs-csi-nodeplugincore/serviceaccounts/tokencreateLow

⚠️ Potential Abuse (1)

The following security risks were found based on the above permissions:

📦 Workloads (0)

No workloads use this ServiceAccount.


🤖 rook-ceph-purge-osd

Namespace: default  |  Automount:

🔑 Permissions (4)

RoleResourceVerbsRiskTags
Role rook-ceph-purge-osdcore/configmapsgetLow
Role rook-ceph-purge-osdapps/deploymentsdelete · getLow
Role rook-ceph-purge-osdbatch/jobsdelete · get · listLow
Role rook-ceph-purge-osdcore/persistentvolumeclaimsdelete · get · list · updateLow

⚠️ Potential Abuse (1)

The following security risks were found based on the above permissions:

📦 Workloads (0)

No workloads use this ServiceAccount.


🤖 rook-ceph-default

Namespace: default  |  Automount:

🔑 Permissions (0)

No explicit RBAC bindings.

📦 Workloads (0)

No workloads use this ServiceAccount.


🤖 rook-ceph-rgw

Namespace: default  |  Automount:

🔑 Permissions (0)

No explicit RBAC bindings.

📦 Workloads (0)

No workloads use this ServiceAccount.