Description

File, Block, and Object Storage Services for your Cloud-Native Environment

Overview

IdentityNamespaceAutomountSecretsPermissionsWorkloadsRisk
rook-ceph-systemdefault151Critical
rook-ceph-cmd-reporterdefault20High
rook-ceph-mgrdefault50Medium
rook-ceph-osddefault40Medium
rook-csi-rbd-provisioner-sadefault40Medium
rook-csi-cephfs-plugin-sadefault10Low
rook-csi-cephfs-provisioner-sadefault40Low
rook-csi-rbd-plugin-sadefault10Low

Numbers in the last two columns indicate how many bindings or workloads involve each ServiceAccount.


Identities

🤖 rook-ceph-system

Namespace: default  |  Automount:

🔑 Permissions (15)

RoleResourceVerbsRiskTags
ClusterRole rook-ceph-object-bucketcore/configmaps*CriticalClusterWideAccess ConfigMapAccess DataExposure InformationDisclosure PotentialPrivilegeEscalation (+2 more)
ClusterRole rook-ceph-object-bucketcore/secrets*CriticalClusterWideAccess ClusterWideSecretAccess CredentialAccess DataExposure InformationDisclosure (+6 more)
ClusterRole rook-ceph-object-bucketobjectbucket.io/**HighClusterWideAccess WildcardPermission
Role rook-ceph-systemcore/configmapscreate · delete · get · list · patch · update · watchHighConfigMapAccess DataExposure InformationDisclosure PotentialPrivilegeEscalation Tampering
Role rook-ceph-systemcore/podscreate · delete · get · list · patch · update · watchHighLateralMovement Persistence PotentialPrivilegeEscalation Tampering WorkloadExecution
Role rook-ceph-systemcore/servicescreate · delete · get · list · patch · update · watchHighDenialOfService NetworkManipulation ServiceExposure Tampering
Role rook-ceph-systemapps/daemonsetscreate · delete · get · list · update · watchLow
Role rook-ceph-systemextensions/daemonsetscreate · delete · get · list · update · watchLow
Role rook-ceph-systemapps/deploymentscreate · delete · get · list · update · watchLow
Role rook-ceph-systemextensions/deploymentscreate · delete · get · list · update · watchLow
Role rook-ceph-systemk8s.cni.cncf.io/network-attachment-definitionsgetLow
Role rook-ceph-systemapps/statefulsetscreate · delete · get · list · update · watchLow
Role rook-ceph-systemextensions/statefulsetscreate · delete · get · list · update · watchLow
ClusterRole rook-ceph-object-bucketstorage.k8s.io/storageclassesget · list · watchLow
ClusterRole psp:rookpolicy/podsecuritypolicies (restricted to: 00-rook-ceph-operator)useLowDeprecatedFeature NodeAccess PodSecurityPolicy PrivilegeEscalation ResourceNameRestricted

⚠️ Potential Abuse (14)

The following security risks were found based on the above permissions:

📦 Workloads (1)

KindNameContainerImage
Deploymentrook-ceph-operatorrook-ceph-operatorrook/ceph:v1.3.9

🤖 rook-ceph-cmd-reporter

Namespace: default  |  Automount:

🔑 Permissions (2)

RoleResourceVerbsRiskTags
Role rook-ceph-cmd-reportercore/podscreate · delete · get · list · update · watchHighLateralMovement Persistence PotentialPrivilegeEscalation WorkloadExecution
Role rook-ceph-cmd-reportercore/configmapscreate · delete · get · list · update · watchMediumConfigMapAccess DataExposure InformationDisclosure

⚠️ Potential Abuse (3)

The following security risks were found based on the above permissions:

📦 Workloads (0)

No workloads use this ServiceAccount.


🤖 rook-ceph-mgr

Namespace: default  |  Automount:

🔑 Permissions (5)

RoleResourceVerbsRiskTags
Role rook-ceph-mgrceph.rook.io/**MediumNamespaceAdmin NamespaceWideAccess WildcardPermission
Role rook-ceph-mgrcore/pods/logdelete · get · list · watchMediumDataExposure InformationDisclosure LogAccess
Role rook-ceph-mgrbatch/jobscreate · delete · get · list · update · watchLow
Role rook-ceph-mgrcore/podsdelete · get · list · watchLow
Role rook-ceph-mgrcore/servicesdelete · get · list · watchLow

⚠️ Potential Abuse (3)

The following security risks were found based on the above permissions:

📦 Workloads (0)

No workloads use this ServiceAccount.


🤖 rook-ceph-osd

Namespace: default  |  Automount:

🔑 Permissions (4)

RoleResourceVerbsRiskTags
Role rook-ceph-osdcore/configmapscreate · delete · get · list · update · watchMediumConfigMapAccess DataExposure InformationDisclosure
Role rook-ceph-osdceph.rook.io/cephclusterscreate · delete · get · list · updateLow
Role rook-ceph-osdceph.rook.io/cephclusters/finalizerscreate · delete · get · list · updateLow
ClusterRole rook-ceph-osdcore/nodesget · listLow

⚠️ Potential Abuse (2)

The following security risks were found based on the above permissions:

📦 Workloads (0)

No workloads use this ServiceAccount.


🤖 rook-csi-rbd-provisioner-sa

Namespace: default  |  Automount:

🔑 Permissions (4)

RoleResourceVerbsRiskTags
Role rbd-external-provisioner-cfgcore/configmapscreate · delete · get · list · watchMediumConfigMapAccess DataExposure InformationDisclosure
Role rbd-external-provisioner-cfgcore/endpointscreate · delete · get · list · update · watchLow
Role rbd-external-provisioner-cfgcoordination.k8s.io/leasescreate · delete · get · list · update · watchLow
ClusterRole psp:rookpolicy/podsecuritypolicies (restricted to: 00-rook-ceph-operator)useLowDeprecatedFeature NodeAccess PodSecurityPolicy PrivilegeEscalation ResourceNameRestricted

⚠️ Potential Abuse (3)

The following security risks were found based on the above permissions:

📦 Workloads (0)

No workloads use this ServiceAccount.


🤖 rook-csi-cephfs-provisioner-sa

Namespace: default  |  Automount:

🔑 Permissions (4)

RoleResourceVerbsRiskTags
Role cephfs-external-provisioner-cfgcore/configmapscreate · delete · get · listLow
Role cephfs-external-provisioner-cfgcore/endpointscreate · delete · get · list · update · watchLow
Role cephfs-external-provisioner-cfgcoordination.k8s.io/leasescreate · delete · get · list · update · watchLow
ClusterRole psp:rookpolicy/podsecuritypolicies (restricted to: 00-rook-ceph-operator)useLowDeprecatedFeature NodeAccess PodSecurityPolicy PrivilegeEscalation ResourceNameRestricted

⚠️ Potential Abuse (2)

The following security risks were found based on the above permissions:

📦 Workloads (0)

No workloads use this ServiceAccount.


🤖 rook-csi-cephfs-plugin-sa

Namespace: default  |  Automount:

🔑 Permissions (1)

RoleResourceVerbsRiskTags
ClusterRole psp:rookpolicy/podsecuritypolicies (restricted to: 00-rook-ceph-operator)useLowDeprecatedFeature NodeAccess PodSecurityPolicy PrivilegeEscalation ResourceNameRestricted

⚠️ Potential Abuse (2)

The following security risks were found based on the above permissions:

📦 Workloads (0)

No workloads use this ServiceAccount.


🤖 rook-csi-rbd-plugin-sa

Namespace: default  |  Automount:

🔑 Permissions (1)

RoleResourceVerbsRiskTags
ClusterRole psp:rookpolicy/podsecuritypolicies (restricted to: 00-rook-ceph-operator)useLowDeprecatedFeature NodeAccess PodSecurityPolicy PrivilegeEscalation ResourceNameRestricted

⚠️ Potential Abuse (2)

The following security risks were found based on the above permissions:

📦 Workloads (0)

No workloads use this ServiceAccount.