Description

StackGres Operator

Overview

IdentityNamespaceAutomountSecretsPermissionsWorkloadsRisk
stackgres-operatordefault901Critical
stackgres-operator-grafanadefault32Critical
stackgres-operator-kube-state-metricsdefault331Critical
stackgres-operator-prometh-operatordefault202Critical
stackgres-operator-prometh-prometheusdefault90Critical
stackgres-restapidefault52Critical
stackgres-operator-grafana-testdefault11Low
stackgres-operator-prometh-admissiondefault42Low
stackgres-operator-prometh-alertmanagerdefault10Low
stackgres-operator-prometheus-node-exporterdefault11Low
stackgres-operator-initdefault04

Numbers in the last two columns indicate how many bindings or workloads involve each ServiceAccount.


Identities

🤖 stackgres-operator

Namespace: default  |  Automount:

🔑 Permissions (90)

RoleResourceVerbsRiskTags
ClusterRole stackgres-operatorcore/configmapscreate · delete · get · list · patch · update · watchCriticalConfigMapAccess DataExposure InformationDisclosure PotentialPrivilegeEscalation Tampering
ClusterRole stackgres-operatorbatch/cronjobscreate · delete · get · list · patch · update · watchCriticalPersistence PotentialPrivilegeEscalation PrivilegeEscalation Tampering WorkloadLifecycle
ClusterRole stackgres-operatorcore/endpointscreate · delete · get · list · patch · update · watchCriticalDenialOfService ManInTheMiddle NetworkManipulation Tampering TrafficRedirection
ClusterRole stackgres-operatorbatch/jobscreate · delete · get · list · patch · update · watchCriticalPotentialPrivilegeEscalation PrivilegeEscalation Tampering WorkloadLifecycle
ClusterRole stackgres-operatorcore/podscreate · delete · get · list · patch · update · watchCriticalLateralMovement Persistence PotentialPrivilegeEscalation PrivilegeEscalation Tampering (+1 more)
ClusterRole stackgres-operatorcore/pods/execcreate · delete · get · list · patch · update · watchCriticalClusterWidePodExec CodeExecution ElevationOfPrivilege LateralMovement PodExec (+1 more)
ClusterRole stackgres-operatorcore/secretscreate · delete · get · list · patch · update · watchCriticalClusterWideSecretAccess CredentialAccess DataExposure InformationDisclosure Persistence (+4 more)
ClusterRole stackgres-operatorcore/servicescreate · delete · get · list · patch · update · watchCriticalDenialOfService NetworkManipulation ServiceExposure Tampering
ClusterRole stackgres-operatorapps/statefulsetscreate · delete · get · list · patch · update · watchCriticalPersistence PotentialPrivilegeEscalation PrivilegeEscalation Tampering WorkloadLifecycle
ClusterRole stackgres-operatorcore/namespacescreate · delete · get · list · patch · update · watchHighClusterStructure DenialOfService InformationDisclosure NamespaceLifecycle Reconnaissance (+1 more)
ClusterRole stackgres-operatorrbac.authorization.k8s.io/rolebindingscreate · delete · get · list · patch · update · watchHighBindingToPrivilegedRole InformationDisclosure PrivilegeEscalation RBACManipulation RBACQuery (+1 more)
ClusterRole stackgres-operatorrbac.authorization.k8s.io/rolescreate · delete · get · list · patch · update · watchHighInformationDisclosure PrivilegeEscalation RBACManipulation RBACQuery Reconnaissance
ClusterRole stackgres-operatorcore/serviceaccountscreate · delete · get · list · patch · update · watchHighIdentityManagement PotentialPrivilegeEscalation Tampering
ClusterRole stackgres-operatorcore/eventscreate · delete · get · list · patch · update · watchMediumInformationDisclosure OperationalData Reconnaissance
ClusterRole stackgres-operatorapps/configmapscreate · delete · get · list · patch · update · watchLow
ClusterRole stackgres-operatorbatch/configmapscreate · delete · get · list · patch · update · watchLow
ClusterRole stackgres-operatorextensions/configmapscreate · delete · get · list · patch · update · watchLow
ClusterRole stackgres-operatorrbac.authorization.k8s.io/configmapscreate · delete · get · list · patch · update · watchLow
ClusterRole stackgres-operatorapps/cronjobscreate · delete · get · list · patch · update · watchLow
ClusterRole stackgres-operatorcore/cronjobscreate · delete · get · list · patch · update · watchLow
ClusterRole stackgres-operatorextensions/cronjobscreate · delete · get · list · patch · update · watchLow
ClusterRole stackgres-operatorrbac.authorization.k8s.io/cronjobscreate · delete · get · list · patch · update · watchLow
ClusterRole stackgres-operatorapiextensions.k8s.io/customresourcedefinitionsget · list · watchLow
ClusterRole stackgres-operatorcustomresourcedefinitions.apiextensions.k8s.io/customresourcedefinitionsget · list · watchLow
ClusterRole stackgres-operatorapps/endpointscreate · delete · get · list · patch · update · watchLow
ClusterRole stackgres-operatorbatch/endpointscreate · delete · get · list · patch · update · watchLow
ClusterRole stackgres-operatorextensions/endpointscreate · delete · get · list · patch · update · watchLow
ClusterRole stackgres-operatorrbac.authorization.k8s.io/endpointscreate · delete · get · list · patch · update · watchLow
ClusterRole stackgres-operatorapps/eventscreate · delete · get · list · patch · update · watchLow
ClusterRole stackgres-operatorbatch/eventscreate · delete · get · list · patch · update · watchLow
ClusterRole stackgres-operatorextensions/eventscreate · delete · get · list · patch · update · watchLow
ClusterRole stackgres-operatorrbac.authorization.k8s.io/eventscreate · delete · get · list · patch · update · watchLow
ClusterRole stackgres-operatorapps/jobscreate · delete · get · list · patch · update · watchLow
ClusterRole stackgres-operatorcore/jobscreate · delete · get · list · patch · update · watchLow
ClusterRole stackgres-operatorextensions/jobscreate · delete · get · list · patch · update · watchLow
ClusterRole stackgres-operatorrbac.authorization.k8s.io/jobscreate · delete · get · list · patch · update · watchLow
ClusterRole stackgres-operatorapps/namespacescreate · delete · get · list · patch · update · watchLow
ClusterRole stackgres-operatorbatch/namespacescreate · delete · get · list · patch · update · watchLow
ClusterRole stackgres-operatorextensions/namespacescreate · delete · get · list · patch · update · watchLow
ClusterRole stackgres-operatorrbac.authorization.k8s.io/namespacescreate · delete · get · list · patch · update · watchLow
ClusterRole stackgres-operatorapps/persistentvolumeclaimscreate · delete · get · list · patch · update · watchLow
ClusterRole stackgres-operatorbatch/persistentvolumeclaimscreate · delete · get · list · patch · update · watchLow
ClusterRole stackgres-operatorcore/persistentvolumeclaimscreate · delete · get · list · patch · update · watchLow
ClusterRole stackgres-operatorextensions/persistentvolumeclaimscreate · delete · get · list · patch · update · watchLow
ClusterRole stackgres-operatorrbac.authorization.k8s.io/persistentvolumeclaimscreate · delete · get · list · patch · update · watchLow
ClusterRole stackgres-operatormonitoring.coreos.com/podmonitorsget · listLow
ClusterRole stackgres-operatorapps/podscreate · delete · get · list · patch · update · watchLow
ClusterRole stackgres-operatorbatch/podscreate · delete · get · list · patch · update · watchLow
ClusterRole stackgres-operatorextensions/podscreate · delete · get · list · patch · update · watchLow
ClusterRole stackgres-operatorrbac.authorization.k8s.io/podscreate · delete · get · list · patch · update · watchLow
ClusterRole stackgres-operatorapps/pods/execcreate · delete · get · list · patch · update · watchLow
ClusterRole stackgres-operatorbatch/pods/execcreate · delete · get · list · patch · update · watchLow
ClusterRole stackgres-operatorextensions/pods/execcreate · delete · get · list · patch · update · watchLow
ClusterRole stackgres-operatorrbac.authorization.k8s.io/pods/execcreate · delete · get · list · patch · update · watchLow
ClusterRole stackgres-operatormonitoring.coreos.com/prometheusget · listLow
ClusterRole stackgres-operatormonitoring.coreos.com/prometheusesget · listLow
ClusterRole stackgres-operatorapps/rolebindingscreate · delete · get · list · patch · update · watchLow
ClusterRole stackgres-operatorbatch/rolebindingscreate · delete · get · list · patch · update · watchLow
ClusterRole stackgres-operatorcore/rolebindingscreate · delete · get · list · patch · update · watchLow
ClusterRole stackgres-operatorextensions/rolebindingscreate · delete · get · list · patch · update · watchLow
ClusterRole stackgres-operatorapps/rolescreate · delete · get · list · patch · update · watchLow
ClusterRole stackgres-operatorbatch/rolescreate · delete · get · list · patch · update · watchLow
ClusterRole stackgres-operatorcore/rolescreate · delete · get · list · patch · update · watchLow
ClusterRole stackgres-operatorextensions/rolescreate · delete · get · list · patch · update · watchLow
ClusterRole stackgres-operatorapps/secretscreate · delete · get · list · patch · update · watchLow
ClusterRole stackgres-operatorbatch/secretscreate · delete · get · list · patch · update · watchLow
ClusterRole stackgres-operatorextensions/secretscreate · delete · get · list · patch · update · watchLow
ClusterRole stackgres-operatorrbac.authorization.k8s.io/secretscreate · delete · get · list · patch · update · watchLow
ClusterRole stackgres-operatorapps/serviceaccountscreate · delete · get · list · patch · update · watchLow
ClusterRole stackgres-operatorbatch/serviceaccountscreate · delete · get · list · patch · update · watchLow
ClusterRole stackgres-operatorextensions/serviceaccountscreate · delete · get · list · patch · update · watchLow
ClusterRole stackgres-operatorrbac.authorization.k8s.io/serviceaccountscreate · delete · get · list · patch · update · watchLow
ClusterRole stackgres-operatormonitoring.coreos.com/servicemonitorscreate · delete · get · list · patch · updateLow
ClusterRole stackgres-operatorapps/servicescreate · delete · get · list · patch · update · watchLow
ClusterRole stackgres-operatorbatch/servicescreate · delete · get · list · patch · update · watchLow
ClusterRole stackgres-operatorextensions/servicescreate · delete · get · list · patch · update · watchLow
ClusterRole stackgres-operatorrbac.authorization.k8s.io/servicescreate · delete · get · list · patch · update · watchLow
ClusterRole stackgres-operatorstackgres.io/sgbackupconfigscreate · delete · get · list · patch · update · watchLow
ClusterRole stackgres-operatorstackgres.io/sgbackupscreate · delete · get · list · patch · update · watchLow
ClusterRole stackgres-operatorstackgres.io/sgclusterscreate · delete · get · list · patch · update · watchLow
ClusterRole stackgres-operatorstackgres.io/sgdistributedlogscreate · delete · get · list · patch · update · watchLow
ClusterRole stackgres-operatorstackgres.io/sginstanceprofilescreate · delete · get · list · patch · update · watchLow
ClusterRole stackgres-operatorstackgres.io/sgpgconfigscreate · delete · get · list · patch · update · watchLow
ClusterRole stackgres-operatorstackgres.io/sgpoolconfigscreate · delete · get · list · patch · update · watchLow
ClusterRole stackgres-operatorstackgres.io/sgrestoreconfigscreate · delete · get · list · patch · update · watchLow
ClusterRole stackgres-operatorbatch/statefulsetscreate · delete · get · list · patch · update · watchLow
ClusterRole stackgres-operatorcore/statefulsetscreate · delete · get · list · patch · update · watchLow
ClusterRole stackgres-operatorextensions/statefulsetscreate · delete · get · list · patch · update · watchLow
ClusterRole stackgres-operatorrbac.authorization.k8s.io/statefulsetscreate · delete · get · list · patch · update · watchLow
ClusterRole stackgres-operatorstorage.k8s.io/storageclassesget · listLow

⚠️ Potential Abuse (33)

The following security risks were found based on the above permissions:

📦 Workloads (1)

KindNameContainerImage
Deploymentstackgres-operatorstackgres-operatorstackgres/operator:0.9.3-jvm

🤖 stackgres-operator-kube-state-metrics

Namespace: default  |  Automount:

🔑 Permissions (33)

RoleResourceVerbsRiskTags
ClusterRole stackgres-operator-kube-state-metricscore/secretslist · watchCriticalClusterWideSecretAccess CredentialAccess DataExposure InformationDisclosure SecretAccess
ClusterRole stackgres-operator-kube-state-metricscore/configmapslist · watchHighConfigMapAccess DataExposure InformationDisclosure
ClusterRole stackgres-operator-kube-state-metricsadmissionregistration.k8s.io/mutatingwebhookconfigurationslist · watchMediumInformationDisclosure Reconnaissance WebhookReconnaissance
ClusterRole stackgres-operator-kube-state-metricscore/resourcequotaslist · watchMediumInformationDisclosure QuotaTampering Reconnaissance ResourceConfiguration
ClusterRole stackgres-operator-kube-state-metricsadmissionregistration.k8s.io/validatingwebhookconfigurationslist · watchMediumInformationDisclosure Reconnaissance WebhookReconnaissance
ClusterRole stackgres-operator-kube-state-metricscertificates.k8s.io/certificatesigningrequestslist · watchLow
ClusterRole stackgres-operator-kube-state-metricsbatch/cronjobslist · watchLow
ClusterRole stackgres-operator-kube-state-metricsapps/daemonsetslist · watchLow
ClusterRole stackgres-operator-kube-state-metricsextensions/daemonsetslist · watchLow
ClusterRole stackgres-operator-kube-state-metricsapps/deploymentslist · watchLow
ClusterRole stackgres-operator-kube-state-metricsextensions/deploymentslist · watchLow
ClusterRole stackgres-operator-kube-state-metricscore/endpointslist · watchLow
ClusterRole stackgres-operator-kube-state-metricsautoscaling/horizontalpodautoscalerslist · watchLow
ClusterRole stackgres-operator-kube-state-metricsextensions/ingresseslist · watchLow
ClusterRole stackgres-operator-kube-state-metricsnetworking.k8s.io/ingresseslist · watchLow
ClusterRole stackgres-operator-kube-state-metricsbatch/jobslist · watchLow
ClusterRole stackgres-operator-kube-state-metricscore/limitrangeslist · watchLowInformationDisclosure Reconnaissance ResourceConfiguration
ClusterRole stackgres-operator-kube-state-metricscore/namespaceslist · watchLowClusterStructure InformationDisclosure Reconnaissance
ClusterRole stackgres-operator-kube-state-metricsnetworking.k8s.io/networkpolicieslist · watchLow
ClusterRole stackgres-operator-kube-state-metricscore/nodeslist · watchLow
ClusterRole stackgres-operator-kube-state-metricscore/persistentvolumeclaimslist · watchLow
ClusterRole stackgres-operator-kube-state-metricscore/persistentvolumeslist · watchLow
ClusterRole stackgres-operator-kube-state-metricspolicy/poddisruptionbudgetslist · watchLow
ClusterRole stackgres-operator-kube-state-metricscore/podslist · watchLow
ClusterRole stackgres-operator-kube-state-metricsapps/replicasetslist · watchLow
ClusterRole stackgres-operator-kube-state-metricsextensions/replicasetslist · watchLow
ClusterRole stackgres-operator-kube-state-metricscore/replicationcontrollerslist · watchLow
ClusterRole stackgres-operator-kube-state-metricscore/serviceslist · watchLow
ClusterRole stackgres-operator-kube-state-metricsapps/statefulsetslist · watchLow
ClusterRole stackgres-operator-kube-state-metricsstorage.k8s.io/storageclasseslist · watchLow
ClusterRole stackgres-operator-kube-state-metricsautoscaling.k8s.io/verticalpodautoscalerslist · watchLow
ClusterRole stackgres-operator-kube-state-metricsstorage.k8s.io/volumeattachmentslist · watchLow
ClusterRole psp-stackgres-operator-kube-state-metricspolicy/podsecuritypolicies (restricted to: stackgres-operator-kube-state-metrics)useLowDeprecatedFeature NodeAccess PodSecurityPolicy PrivilegeEscalation ResourceNameRestricted

⚠️ Potential Abuse (12)

The following security risks were found based on the above permissions:

📦 Workloads (1)

KindNameContainerImage
Deploymentstackgres-operator-kube-state-metricskube-state-metricsquay.io/coreos/kube-state-metrics:v1.9.5

🤖 stackgres-operator-prometh-operator

Namespace: default  |  Automount:

🔑 Permissions (20)

RoleResourceVerbsRiskTags
ClusterRole stackgres-operator-prometh-operatorcore/configmaps*CriticalClusterWideAccess ConfigMapAccess DataExposure InformationDisclosure PotentialPrivilegeEscalation (+2 more)
ClusterRole stackgres-operator-prometh-operatorapiextensions.k8s.io/customresourcedefinitions*CriticalCRDManipulation ClusterWideAccess PotentialPrivilegeEscalation Tampering WildcardPermission
ClusterRole stackgres-operator-prometh-operatorcore/secrets*CriticalClusterWideAccess ClusterWideSecretAccess CredentialAccess DataExposure InformationDisclosure (+6 more)
ClusterRole stackgres-operator-prometh-operatorapps/statefulsets*CriticalClusterWideAccess Persistence PotentialPrivilegeEscalation PrivilegeEscalation Tampering (+2 more)
ClusterRole stackgres-operator-prometh-operatormonitoring.coreos.com/alertmanagers*HighClusterWideAccess WildcardPermission
ClusterRole stackgres-operator-prometh-operatormonitoring.coreos.com/alertmanagers/finalizers*HighClusterWideAccess WildcardPermission
ClusterRole stackgres-operator-prometh-operatormonitoring.coreos.com/podmonitors*HighClusterWideAccess WildcardPermission
ClusterRole stackgres-operator-prometh-operatormonitoring.coreos.com/prometheuses*HighClusterWideAccess WildcardPermission
ClusterRole stackgres-operator-prometh-operatormonitoring.coreos.com/prometheuses/finalizers*HighClusterWideAccess WildcardPermission
ClusterRole stackgres-operator-prometh-operatormonitoring.coreos.com/prometheusrules*HighClusterWideAccess WildcardPermission
ClusterRole stackgres-operator-prometh-operatormonitoring.coreos.com/servicemonitors*HighClusterWideAccess WildcardPermission
ClusterRole stackgres-operator-prometh-operatormonitoring.coreos.com/thanosrulers*HighClusterWideAccess WildcardPermission
ClusterRole stackgres-operator-prometh-operatormonitoring.coreos.com/thanosrulers/finalizers*HighClusterWideAccess WildcardPermission
ClusterRole stackgres-operator-prometh-operatorcore/endpointscreate · delete · get · updateLow
ClusterRole stackgres-operator-prometh-operatorcore/namespacesget · list · watchLowClusterStructure InformationDisclosure Reconnaissance
ClusterRole stackgres-operator-prometh-operatorcore/nodeslist · watchLow
ClusterRole stackgres-operator-prometh-operatorcore/podsdelete · listLow
ClusterRole stackgres-operator-prometh-operatorcore/servicescreate · delete · get · updateLow
ClusterRole stackgres-operator-prometh-operatorcore/services/finalizerscreate · delete · get · updateLow
ClusterRole stackgres-operator-prometh-operator-psppolicy/podsecuritypolicies (restricted to: stackgres-operator-prometh-operator)useLowDeprecatedFeature NodeAccess PodSecurityPolicy PrivilegeEscalation ResourceNameRestricted

⚠️ Potential Abuse (15)

The following security risks were found based on the above permissions:

📦 Workloads (2)

KindNameContainerImage
Deploymentstackgres-operator-prometh-operatorprometheus-operatorquay.io/coreos/prometheus-operator:v0.38.1
Deploymentstackgres-operator-prometh-operatortls-proxysquareup/ghostunnel:v1.5.2

🤖 stackgres-operator-prometh-prometheus

Namespace: default  |  Automount:

🔑 Permissions (9)

RoleResourceVerbsRiskTags
ClusterRole stackgres-operator-prometh-prometheuscore/nodes/proxyget · list · watchCriticalAuthorizationBypass ClusterAdminAccess CodeExecution ElevationOfPrivilege LateralMovement (+1 more)
ClusterRole stackgres-operator-prometh-prometheuscore/endpointsget · list · watchLow
ClusterRole stackgres-operator-prometh-prometheusextensions/ingressesget · list · watchLow
ClusterRole stackgres-operator-prometh-prometheusnetworking.k8s.io/ingressesget · list · watchLow
ClusterRole stackgres-operator-prometh-prometheuscore/nodesget · list · watchLow
ClusterRole stackgres-operator-prometh-prometheuscore/nodes/metricsget · list · watchLow
ClusterRole stackgres-operator-prometh-prometheuscore/podsget · list · watchLow
ClusterRole stackgres-operator-prometh-prometheuscore/servicesget · list · watchLow
ClusterRole stackgres-operator-prometh-prometheus-psppolicy/podsecuritypolicies (restricted to: stackgres-operator-prometh-prometheus)useLowDeprecatedFeature NodeAccess PodSecurityPolicy PrivilegeEscalation ResourceNameRestricted

⚠️ Potential Abuse (3)

The following security risks were found based on the above permissions:

📦 Workloads (0)

No workloads use this ServiceAccount.


🤖 stackgres-restapi

Namespace: default  |  Automount:

🔑 Permissions (5)

RoleResourceVerbsRiskTags
ClusterRole stackgres-restapicore/groupsimpersonateCriticalClusterAdminAccess Impersonation PrivilegeEscalation Spoofing
ClusterRole stackgres-restapicore/usersimpersonateCriticalClusterAdminAccess Impersonation PrivilegeEscalation Spoofing
ClusterRole stackgres-restapiauthorization.k8s.io/subjectaccessreviewscreateMediumInformationDisclosure RBACQuery
ClusterRole stackgres-restapicore/secretsget · listLow
ClusterRole stackgres-restapicore/serviceaccountimpersonateLow

⚠️ Potential Abuse (3)

The following security risks were found based on the above permissions:

📦 Workloads (2)

KindNameContainerImage
Deploymentstackgres-restapistackgres-adminuistackgres/admin-ui:0.9.3
Deploymentstackgres-restapistackgres-restapistackgres/restapi:0.9.3-jvm

🤖 stackgres-operator-grafana

Namespace: default  |  Automount:

🔑 Permissions (3)

RoleResourceVerbsRiskTags
ClusterRole stackgres-operator-grafana-clusterrolecore/secretsget · list · watchCriticalClusterWideSecretAccess CredentialAccess DataExposure InformationDisclosure SecretAccess
ClusterRole stackgres-operator-grafana-clusterrolecore/configmapsget · list · watchHighConfigMapAccess DataExposure InformationDisclosure
Role stackgres-operator-grafanaextensions/podsecuritypolicies (restricted to: stackgres-operator-grafana)useLowResourceNameRestricted

⚠️ Potential Abuse (5)

The following security risks were found based on the above permissions:

📦 Workloads (2)

KindNameContainerImage
Deploymentstackgres-operator-grafanagrafanagrafana/grafana:6.7.3
Deploymentstackgres-operator-grafanagrafana-sc-dashboardkiwigrid/k8s-sidecar:0.1.99

🤖 stackgres-operator-prometh-admission

Namespace: default  |  Automount:

🔑 Permissions (4)

RoleResourceVerbsRiskTags
ClusterRole stackgres-operator-prometh-admissionadmissionregistration.k8s.io/mutatingwebhookconfigurationsget · updateLow
Role stackgres-operator-prometh-admissioncore/secretscreate · getLow
ClusterRole stackgres-operator-prometh-admissionadmissionregistration.k8s.io/validatingwebhookconfigurationsget · updateLow
ClusterRole stackgres-operator-prometh-admissionpolicy/podsecuritypolicies (restricted to: stackgres-operator-prometh-admission)useLowDeprecatedFeature NodeAccess PodSecurityPolicy PrivilegeEscalation ResourceNameRestricted

⚠️ Potential Abuse (2)

The following security risks were found based on the above permissions:

📦 Workloads (2)

KindNameContainerImage
Jobstackgres-operator-prometh-admission-createcreatejettech/kube-webhook-certgen:v1.2.0
Jobstackgres-operator-prometh-admission-patchpatchjettech/kube-webhook-certgen:v1.2.0

🤖 stackgres-operator-grafana-test

Namespace: default  |  Automount:

🔑 Permissions (1)

RoleResourceVerbsRiskTags
Role stackgres-operator-grafana-testpolicy/podsecuritypolicies (restricted to: stackgres-operator-grafana-test)useLowResourceNameRestricted

⚠️ Potential Abuse (1)

The following security risks were found based on the above permissions:

📦 Workloads (1)

KindNameContainerImage
Podstackgres-operator-grafana-teststackgres-operator-testbats/bats:v1.1.0

🤖 stackgres-operator-prometh-alertmanager

Namespace: default  |  Automount:

🔑 Permissions (1)

RoleResourceVerbsRiskTags
Role stackgres-operator-prometh-alertmanagerpolicy/podsecuritypolicies (restricted to: stackgres-operator-prometh-alertmanager)useLowResourceNameRestricted

⚠️ Potential Abuse (1)

The following security risks were found based on the above permissions:

📦 Workloads (0)

No workloads use this ServiceAccount.


🤖 stackgres-operator-prometheus-node-exporter

Namespace: default  |  Automount:

🔑 Permissions (1)

RoleResourceVerbsRiskTags
ClusterRole psp-stackgres-operator-prometheus-node-exporterextensions/podsecuritypolicies (restricted to: stackgres-operator-prometheus-node-exporter)useLowDeprecatedFeature NodeAccess PodSecurityPolicy PrivilegeEscalation ResourceNameRestricted

⚠️ Potential Abuse (2)

The following security risks were found based on the above permissions:

📦 Workloads (1)

KindNameContainerImage
DaemonSetstackgres-operator-prometheus-node-exporternode-exporterquay.io/prometheus/node-exporter:v0.18.1

🤖 stackgres-operator-init

Namespace: default  |  Automount:

🔑 Permissions (0)

No explicit RBAC bindings.

📦 Workloads (4)

KindNameContainerImage
Jobstackgres-operator-bootstrapstackgres-operator-bootstrapbitnami/kubectl:1.18.3
Jobstackgres-operator-create-certificatestackgres-operator-create-certificatebitnami/kubectl:1.18.3
Jobstackgres-operator-upgradestackgres-operator-upgradebitnami/kubectl:1.18.3
Jobstackgres-operator-waitstackgres-operator-waitbitnami/kubectl:1.18.3