1 Service Accounts
1 Workloads
10 Bindings
3 Critical
2 Medium
5 Low
Description
Helm chart deploys sops-secrets-operator
Overview
| Identity | Namespace | Automount | Secrets | Permissions | Workloads | Risk |
|---|---|---|---|---|---|---|
sops-secrets-operator | default | ❌ | — | 10 | 1 | Critical |
Numbers in the last two columns indicate how many bindings or workloads involve each ServiceAccount.
Identities
🤖 sops-secrets-operator
Namespace: default | Automount: ❌
🔑 Permissions (10)
| Role | Resource | Verbs | Risk | Tags |
|---|---|---|---|---|
ClusterRole sops-secrets-operator | core/configmaps | * | Critical | ClusterWideAccess ConfigMapAccess DataExposure InformationDisclosure PotentialPrivilegeEscalation (+2 more) |
ClusterRole sops-secrets-operator | coordination.k8s.io/leases | * | Critical | ClusterWideAccess ControlPlaneDisruption CriticalNamespace DenialOfService LeaderElectionAbuse (+2 more) |
ClusterRole sops-secrets-operator | core/secrets | * | Critical | ClusterWideAccess ClusterWideSecretAccess CredentialAccess DataExposure InformationDisclosure (+6 more) |
ClusterRole sops-secrets-operator | core/events | * | Medium | ClusterWideAccess InformationDisclosure OperationalData Reconnaissance |
ClusterRole sops-secrets-operator | events.k8s.io/events | * | Medium | ClusterWideAccess InformationDisclosure OperationalData Reconnaissance |
ClusterRole sops-secrets-operator | core/secrets/status | get · patch · update | Low | |
ClusterRole sops-secrets-operator | monitoring.coreos.com/servicemonitors | create · get | Low | |
ClusterRole sops-secrets-operator | isindir.github.com/sopssecrets | create · delete · get · list · patch · update · watch | Low | |
ClusterRole sops-secrets-operator | isindir.github.com/sopssecrets/finalizers | update | Low | |
ClusterRole sops-secrets-operator | isindir.github.com/sopssecrets/status | get · patch · update | Low |
⚠️ Potential Abuse (13)
The following security risks were found based on the above permissions:
- Read secrets cluster-wide
- Read secrets in a namespace
- Modify secrets cluster-wide
- Modify secrets in a namespace
- Read ConfigMaps cluster-wide
- Read ConfigMaps in a namespace
- Modify ConfigMaps cluster-wide
- Modify ConfigMaps in a namespace
- Read events cluster-wide
- Manage Leases cluster-wide
- Manage Leases in kube-system or kube-node-lease namespace
📦 Workloads (1)
| Kind | Name | Container | Image |
|---|---|---|---|
| Deployment | sops-secrets-operator | sops-secrets-operator | quay.io/isindir/sops-secrets-operator:0.21.0 |