Description

Installs the Tigera operator for Calico

Overview

IdentityNamespaceAutomountSecretsPermissionsWorkloadsRisk
tigera-operatordefault642Critical

Numbers in the last two columns indicate how many bindings or workloads involve each ServiceAccount.


Identities

🤖 tigera-operator

Namespace: default  |  Automount:

🔑 Permissions (64)

RoleResourceVerbsRiskTags
ClusterRole tigera-operatorrbac.authorization.k8s.io/clusterrolesbind · create · delete · escalate · get · list · update · watchCriticalBindingToPrivilegedRole ClusterAdminAccess InformationDisclosure PrivilegeEscalation RBACManipulation (+2 more)
ClusterRole tigera-operatorapps/daemonsetscreate · delete · get · list · patch · update · watchCriticalNodeAccess Persistence PrivilegeEscalation Tampering WorkloadLifecycle
ClusterRole tigera-operatorapps/deploymentscreate · delete · get · list · patch · update · watchCriticalPersistence PotentialPrivilegeEscalation PrivilegeEscalation Tampering WorkloadLifecycle
ClusterRole tigera-operatorcore/podscreate · delete · get · list · update · watchCriticalLateralMovement Persistence PotentialPrivilegeEscalation PrivilegeEscalation WorkloadExecution
ClusterRole tigera-operatorpolicy/podsecuritypoliciescreate · delete · get · list · update · use · watchCriticalDeprecatedFeature NodeAccess PodSecurityPolicy PrivilegeEscalation
ClusterRole tigera-operatorcore/secretsget · list · watchCriticalClusterWideSecretAccess CredentialAccess DataExposure InformationDisclosure SecretAccess
ClusterRole tigera-operatorapps/statefulsetscreate · delete · get · list · patch · update · watchCriticalPersistence PotentialPrivilegeEscalation PrivilegeEscalation Tampering WorkloadLifecycle
ClusterRole tigera-operatorcore/configmapscreate · delete · get · list · update · watchHighConfigMapAccess DataExposure InformationDisclosure
ClusterRole tigera-operatorcore/namespacescreate · delete · get · list · update · watchHighClusterStructure DenialOfService InformationDisclosure NamespaceLifecycle Reconnaissance (+1 more)
ClusterRole tigera-operatorrbac.authorization.k8s.io/clusterrolebindingsbind · create · delete · escalate · get · list · update · watchMediumInformationDisclosure RBACQuery Reconnaissance
ClusterRole tigera-operatorcore/eventscreate · delete · get · list · update · watchMediumInformationDisclosure OperationalData Reconnaissance
ClusterRole tigera-operatorcore/resourcequotascreate · delete · get · list · update · watchMediumInformationDisclosure QuotaTampering Reconnaissance ResourceConfiguration
ClusterRole tigera-operatorrbac.authorization.k8s.io/rolebindingsbind · create · delete · escalate · get · list · update · watchMediumInformationDisclosure RBACQuery Reconnaissance
ClusterRole tigera-operatorrbac.authorization.k8s.io/rolesbind · create · delete · escalate · get · list · update · watchMediumInformationDisclosure RBACQuery Reconnaissance
ClusterRole tigera-operatoroperator.tigera.io/apiserversdelete · get · list · patch · update · watchLow
ClusterRole tigera-operatoroperator.tigera.io/apiservers/finalizersget · list · patch · update · watchLow
ClusterRole tigera-operatoroperator.tigera.io/apiservers/statusget · list · patch · update · watchLow
ClusterRole tigera-operatorapiregistration.k8s.io/apiservicescreate · list · update · watchLow
ClusterRole tigera-operatorcrd.projectcalico.org/bgpconfigurationsget · list · watchLow
ClusterRole tigera-operatorcertificates.k8s.io/certificatesigningrequestslist · watchLow
ClusterRole tigera-operatorcrd.projectcalico.org/clusterinformationsget · list · watchLow
ClusterRole tigera-operatorstorage.k8s.io/csidriverscreate · delete · get · list · update · watchLow
ClusterRole tigera-operatorapiextensions.k8s.io/customresourcedefinitionscreate · get · list · update · watchLow
ClusterRole tigera-operatorapps/deployments/finalizersupdateLow
ClusterRole tigera-operatorcore/endpointscreate · delete · get · list · update · watchLow
ClusterRole tigera-operatorgateway.envoyproxy.io/envoyproxiescreate · delete · get · list · update · watchLow
ClusterRole tigera-operatorcrd.projectcalico.org/felixconfigurationscreate · get · list · patch · watchLow
ClusterRole tigera-operatoroperator.tigera.io/gatewayapisget · list · patch · update · watchLow
ClusterRole tigera-operatoroperator.tigera.io/gatewayapis/finalizersget · list · patch · update · watchLow
ClusterRole tigera-operatoroperator.tigera.io/gatewayapis/statusget · list · patch · update · watchLow
ClusterRole tigera-operatorgateway.networking.k8s.io/gatewayclassescreate · delete · get · list · update · watchLow
ClusterRole tigera-operatoroperator.tigera.io/goldmanesdelete · get · list · patch · update · watchLow
ClusterRole tigera-operatoroperator.tigera.io/goldmanes/finalizersget · list · patch · update · watchLow
ClusterRole tigera-operatoroperator.tigera.io/goldmanes/statusget · list · patch · update · watchLow
ClusterRole tigera-operatoroperator.tigera.io/imagesetsget · list · patch · update · watchLow
ClusterRole tigera-operatoroperator.tigera.io/installationsdelete · get · list · patch · update · watchLow
ClusterRole tigera-operatoroperator.tigera.io/installations/finalizersget · list · patch · update · watchLow
ClusterRole tigera-operatoroperator.tigera.io/installations/statusget · list · patch · update · watchLow
ClusterRole tigera-operatorprojectcalico.org/ipamconfigurationsget · list · watchLow
ClusterRole tigera-operatorcrd.projectcalico.org/ippoolscreate · get · list · patch · watchLow
ClusterRole tigera-operatorprojectcalico.org/ippoolscreate · delete · get · list · patch · update · watchLow
ClusterRole tigera-operatorbatch/jobscreate · list · update · watchLow
ClusterRole tigera-operatorcrd.projectcalico.org/kubecontrollersconfigurationsget · list · watchLow
ClusterRole tigera-operatorcoordination.k8s.io/leasescreate · delete · get · list · update · watchLow
ClusterRole tigera-operatoroperator.tigera.io/managementclusterconnectionsget · list · patch · update · watchLow
ClusterRole tigera-operatoroperator.tigera.io/managementclusterconnections/finalizersget · list · patch · update · watchLow
ClusterRole tigera-operatoroperator.tigera.io/managementclusterconnections/statusget · list · patch · update · watchLow
ClusterRole tigera-operatoradmissionregistration.k8s.io/mutatingwebhookconfigurationsdeleteLow
ClusterRole tigera-operatornetworking.k8s.io/networkpoliciescreate · delete · get · list · update · watchLow
ClusterRole tigera-operatorcore/nodesget · list · patch · watchLow
ClusterRole tigera-operatorpolicy/poddisruptionbudgetscreate · delete · get · list · update · watchLow
ClusterRole tigera-operatorcore/podtemplatescreate · delete · get · list · update · watchLow
ClusterRole tigera-operatorscheduling.k8s.io/priorityclassescreate · delete · get · list · update · watchLow
ClusterRole tigera-operatorcore/serviceaccountscreate · delete · get · list · update · watchLow
ClusterRole tigera-operatorcore/servicescreate · delete · get · list · update · watchLow
ClusterRole tigera-operatorprojectcalico.org/tier.globalnetworkpoliciescreate · delete · get · list · update · watchLow
ClusterRole tigera-operatorprojectcalico.org/tier.networkpoliciescreate · delete · get · list · update · watchLow
ClusterRole tigera-operatorprojectcalico.org/tierscreate · delete · get · list · update · watchLow
ClusterRole tigera-operatoroperator.tigera.io/tigerastatusescreate · delete · get · list · patch · update · watchLow
ClusterRole tigera-operatoroperator.tigera.io/tigerastatuses/finalizersget · list · patch · update · watchLow
ClusterRole tigera-operatoroperator.tigera.io/tigerastatuses/statusget · list · patch · update · watchLow
ClusterRole tigera-operatoroperator.tigera.io/whiskersdelete · get · list · patch · update · watchLow
ClusterRole tigera-operatoroperator.tigera.io/whiskers/finalizersget · list · patch · update · watchLow
ClusterRole tigera-operatoroperator.tigera.io/whiskers/statusget · list · patch · update · watchLow

⚠️ Potential Abuse (22)

The following security risks were found based on the above permissions:

📦 Workloads (2)

KindNameContainerImage
Deploymenttigera-operatortigera-operatorquay.io/tigera/operator:v1.38.1
Jobtigera-operator-uninstallcleanup-jobquay.io/tigera/operator:v1.38.1