Description

Victoria Metrics Operator

Overview

IdentityNamespaceAutomountSecretsPermissionsWorkloadsRisk
victoria-metrics-operatordefault311Critical

Numbers in the last two columns indicate how many bindings or workloads involve each ServiceAccount.


Identities

🤖 victoria-metrics-operator

Namespace: default  |  Automount:

🔑 Permissions (31)

RoleResourceVerbsRiskTags
ClusterRole victoria-metrics-operatorcore/configmaps*CriticalClusterWideAccess ConfigMapAccess DataExposure InformationDisclosure PotentialPrivilegeEscalation (+2 more)
ClusterRole victoria-metrics-operatorapps/deployments*CriticalClusterWideAccess Persistence PotentialPrivilegeEscalation PrivilegeEscalation Tampering (+2 more)
ClusterRole victoria-metrics-operatorcore/endpoints*CriticalClusterWideAccess DenialOfService ManInTheMiddle NetworkManipulation Tampering (+2 more)
ClusterRole victoria-metrics-operatorcore/pods*CriticalClusterWideAccess LateralMovement Persistence PotentialPrivilegeEscalation PrivilegeEscalation (+3 more)
ClusterRole victoria-metrics-operatorcore/secrets*CriticalClusterWideAccess ClusterWideSecretAccess CredentialAccess DataExposure InformationDisclosure (+6 more)
ClusterRole victoria-metrics-operatorcore/services*CriticalClusterWideAccess DenialOfService NetworkManipulation ServiceExposure Tampering (+1 more)
ClusterRole victoria-metrics-operatorapps/statefulsets*CriticalClusterWideAccess Persistence PotentialPrivilegeEscalation PrivilegeEscalation Tampering (+2 more)
ClusterRole victoria-metrics-operatormonitoring.coreos.com/**HighClusterWideAccess WildcardPermission
ClusterRole victoria-metrics-operatorcore/persistentvolumeclaims*HighClusterWideAccess WildcardPermission
ClusterRole victoria-metrics-operatorapps/replicasets*HighClusterWideAccess WildcardPermission
ClusterRole victoria-metrics-operatorcore/services/finalizers*HighClusterWideAccess WildcardPermission
ClusterRole victoria-metrics-operatorcore/events*MediumClusterWideAccess InformationDisclosure OperationalData Reconnaissance WildcardPermission
ClusterRole victoria-metrics-operatorcore/namespacesget · list · watchLowClusterStructure InformationDisclosure Reconnaissance
ClusterRole victoria-metrics-operatoroperator.victoriametrics.com/vmagentscreate · delete · get · list · patch · update · watchLow
ClusterRole victoria-metrics-operatoroperator.victoriametrics.com/vmagents/statusget · patch · updateLow
ClusterRole victoria-metrics-operatoroperator.victoriametrics.com/vmalertmanagerscreate · delete · get · list · patch · update · watchLow
ClusterRole victoria-metrics-operatoroperator.victoriametrics.com/vmalertmanagers/statusget · patch · updateLow
ClusterRole victoria-metrics-operatoroperator.victoriametrics.com/vmalertscreate · delete · get · list · patch · update · watchLow
ClusterRole victoria-metrics-operatoroperator.victoriametrics.com/vmalerts/statusget · patch · updateLow
ClusterRole victoria-metrics-operatoroperator.victoriametrics.com/vmclusterscreate · delete · get · list · patch · update · watchLow
ClusterRole victoria-metrics-operatoroperator.victoriametrics.com/vmclusters/statusget · patch · updateLow
ClusterRole victoria-metrics-operatoroperator.victoriametrics.com/vmpodscrapescreate · delete · get · list · patch · update · watchLow
ClusterRole victoria-metrics-operatoroperator.victoriametrics.com/vmpodscrapes/statusget · patch · updateLow
ClusterRole victoria-metrics-operatoroperator.victoriametrics.com/vmprobescreate · delete · get · list · patch · update · watchLow
ClusterRole victoria-metrics-operatoroperator.victoriametrics.com/vmprobes/statusget · patch · updateLow
ClusterRole victoria-metrics-operatoroperator.victoriametrics.com/vmrulescreate · delete · get · list · patch · update · watchLow
ClusterRole victoria-metrics-operatoroperator.victoriametrics.com/vmrules/statusget · patch · updateLow
ClusterRole victoria-metrics-operatoroperator.victoriametrics.com/vmservicescrapescreate · delete · get · list · patch · update · watchLow
ClusterRole victoria-metrics-operatoroperator.victoriametrics.com/vmservicescrapes/statusget · patch · updateLow
ClusterRole victoria-metrics-operatoroperator.victoriametrics.com/vmsinglescreate · delete · get · list · patch · update · watchLow
ClusterRole victoria-metrics-operatoroperator.victoriametrics.com/vmsingles/statusget · patch · updateLow

⚠️ Potential Abuse (24)

The following security risks were found based on the above permissions:

📦 Workloads (1)

KindNameContainerImage
Deploymentvictoria-metrics-operatorvictoria-metrics-operatorvictoriametrics/operator:v0.2.1