Description

Victoria Metrics Operator

Overview

IdentityNamespaceAutomountSecretsPermissionsWorkloadsRisk
victoria-metrics-operatordefault521Critical

Numbers in the last two columns indicate how many bindings or workloads involve each ServiceAccount.


Identities

🤖 victoria-metrics-operator

Namespace: default  |  Automount:

🔑 Permissions (52)

RoleResourceVerbsRiskTags
ClusterRole victoria-metrics-operatorcore/configmaps* · get · list · watchCriticalClusterWideAccess ConfigMapAccess DataExposure InformationDisclosure PotentialPrivilegeEscalation (+2 more)
ClusterRole victoria-metrics-operatorapps/deployments*CriticalClusterWideAccess Persistence PotentialPrivilegeEscalation PrivilegeEscalation Tampering (+2 more)
ClusterRole victoria-metrics-operatorcore/endpoints* · get · list · watchCriticalClusterWideAccess DenialOfService ManInTheMiddle NetworkManipulation Tampering (+2 more)
ClusterRole victoria-metrics-operatorcore/nodes/proxyget · list · watchCriticalAuthorizationBypass ClusterAdminAccess CodeExecution ElevationOfPrivilege LateralMovement (+1 more)
ClusterRole victoria-metrics-operatorcore/pods* · get · list · watchCriticalClusterWideAccess LateralMovement Persistence PotentialPrivilegeEscalation PrivilegeEscalation (+3 more)
ClusterRole victoria-metrics-operatorpolicy/podsecuritypoliciescreate · get · list · patch · update · use · watchCriticalDeprecatedFeature NodeAccess PodSecurityPolicy PrivilegeEscalation
ClusterRole victoria-metrics-operatorcore/secrets*CriticalClusterWideAccess ClusterWideSecretAccess CredentialAccess DataExposure InformationDisclosure (+6 more)
ClusterRole victoria-metrics-operatorcore/services* · get · list · watchCriticalClusterWideAccess DenialOfService NetworkManipulation ServiceExposure Tampering (+1 more)
ClusterRole victoria-metrics-operatorapps/statefulsets*CriticalClusterWideAccess Persistence PotentialPrivilegeEscalation PrivilegeEscalation Tampering (+2 more)
ClusterRole victoria-metrics-operatormonitoring.coreos.com/**HighClusterWideAccess WildcardPermission
Role victoria-metrics-operatorcore/configmapscreate · delete · get · list · patch · update · watchHighConfigMapAccess DataExposure InformationDisclosure PotentialPrivilegeEscalation Tampering
ClusterRole victoria-metrics-operatorcore/persistentvolumeclaims*HighClusterWideAccess WildcardPermission
ClusterRole victoria-metrics-operatorapps/replicasets*HighClusterWideAccess WildcardPermission
ClusterRole victoria-metrics-operatorcore/services/finalizers*HighClusterWideAccess WildcardPermission
ClusterRole victoria-metrics-operatorrbac.authorization.k8s.io/clusterrolebindingscreate · get · list · patch · update · watchMediumInformationDisclosure RBACQuery Reconnaissance
ClusterRole victoria-metrics-operatorrbac.authorization.k8s.io/clusterrolescreate · get · list · patch · update · watchMediumInformationDisclosure RBACQuery Reconnaissance
ClusterRole victoria-metrics-operatorcore/events*MediumClusterWideAccess InformationDisclosure OperationalData Reconnaissance WildcardPermission
Role victoria-metrics-operatorcore/configmaps/statusget · patch · updateLow
ClusterRole victoria-metrics-operatorcore/endpointslicesget · list · watchLow
Role victoria-metrics-operatorcore/eventscreate · patchLow
ClusterRole victoria-metrics-operatorextensions/ingressesget · list · watchLow
ClusterRole victoria-metrics-operatornetworking.k8s.io/ingressesget · list · watchLow
ClusterRole victoria-metrics-operatorcore/namespacesget · list · watchLowClusterStructure InformationDisclosure Reconnaissance
ClusterRole victoria-metrics-operatorcore/nodesget · list · watchLow
ClusterRole victoria-metrics-operatorcore/serviceaccountscreate · get · list · watchLow
ClusterRole victoria-metrics-operatoroperator.victoriametrics.com/vmagentscreate · delete · get · list · patch · update · watchLow
ClusterRole victoria-metrics-operatoroperator.victoriametrics.com/vmagents/finalizerscreate · delete · get · list · patch · update · watchLow
ClusterRole victoria-metrics-operatoroperator.victoriametrics.com/vmagents/statusget · patch · updateLow
ClusterRole victoria-metrics-operatoroperator.victoriametrics.com/vmalertmanagerscreate · delete · get · list · patch · update · watchLow
ClusterRole victoria-metrics-operatoroperator.victoriametrics.com/vmalertmanagers/finalizerscreate · delete · get · list · patch · update · watchLow
ClusterRole victoria-metrics-operatoroperator.victoriametrics.com/vmalertmanagers/statusget · patch · updateLow
ClusterRole victoria-metrics-operatoroperator.victoriametrics.com/vmalertscreate · delete · get · list · patch · update · watchLow
ClusterRole victoria-metrics-operatoroperator.victoriametrics.com/vmalerts/finalizerscreate · delete · get · list · patch · update · watchLow
ClusterRole victoria-metrics-operatoroperator.victoriametrics.com/vmalerts/statusget · patch · updateLow
ClusterRole victoria-metrics-operatoroperator.victoriametrics.com/vmclusterscreate · delete · get · list · patch · update · watchLow
ClusterRole victoria-metrics-operatoroperator.victoriametrics.com/vmclusters/finalizerscreate · delete · get · list · patch · update · watchLow
ClusterRole victoria-metrics-operatoroperator.victoriametrics.com/vmclusters/statusget · patch · updateLow
ClusterRole victoria-metrics-operatoroperator.victoriametrics.com/vmpodscrapescreate · delete · get · list · patch · update · watchLow
ClusterRole victoria-metrics-operatoroperator.victoriametrics.com/vmpodscrapes/statusget · patch · updateLow
ClusterRole victoria-metrics-operatoroperator.victoriametrics.com/vmprobescreate · delete · get · list · patch · update · watchLow
ClusterRole victoria-metrics-operatoroperator.victoriametrics.com/vmprobes/statusget · patch · updateLow
ClusterRole victoria-metrics-operatoroperator.victoriametrics.com/vmprobscrapes/finalizerscreate · delete · get · list · patch · update · watchLow
ClusterRole victoria-metrics-operatoroperator.victoriametrics.com/vmrulescreate · delete · get · list · patch · update · watchLow
ClusterRole victoria-metrics-operatoroperator.victoriametrics.com/vmrules/finalizerscreate · delete · get · list · patch · update · watchLow
ClusterRole victoria-metrics-operatoroperator.victoriametrics.com/vmrules/statusget · patch · updateLow
ClusterRole victoria-metrics-operatoroperator.victoriametrics.com/vmservicescrapescreate · delete · get · list · patch · update · watchLow
ClusterRole victoria-metrics-operatoroperator.victoriametrics.com/vmservicescrapes/finalizerscreate · delete · get · list · patch · update · watchLow
ClusterRole victoria-metrics-operatoroperator.victoriametrics.com/vmservicescrapes/statusget · patch · updateLow
ClusterRole victoria-metrics-operatoroperator.victoriametrics.com/vmsinglescreate · delete · get · list · patch · update · watchLow
ClusterRole victoria-metrics-operatoroperator.victoriametrics.com/vmsingles/finalizerscreate · delete · get · list · patch · update · watchLow
ClusterRole victoria-metrics-operatoroperator.victoriametrics.com/vmsingles/statusget · patch · updateLow
ClusterRole victoria-metrics-operator-psppolicy/podsecuritypolicies (restricted to: victoria-metrics-operator)useLowDeprecatedFeature NodeAccess PodSecurityPolicy PrivilegeEscalation ResourceNameRestricted

⚠️ Potential Abuse (27)

The following security risks were found based on the above permissions:

📦 Workloads (1)

KindNameContainerImage
Deploymentvictoria-metrics-operatorvictoria-metrics-operatorvictoriametrics/operator:v0.5.0