Description

YugabyteDB Anywhere provides deployment, orchestration, and monitoring for managing YugabyteDB clusters. YugabyteDB Anywhere can create a YugabyteDB cluster with multiple pods provided by Kubernetes or OpenShift and logically grouped together to form one logical distributed database.

Overview

IdentityNamespaceAutomountSecretsPermissionsWorkloadsRisk
yugawaredefault193Critical

Numbers in the last two columns indicate how many bindings or workloads involve each ServiceAccount.


Identities

🤖 yugaware

Namespace: default  |  Automount:

🔑 Permissions (19)

RoleResourceVerbsRiskTags
ClusterRole yugawarecore/configmapscreate · delete · get · list · patch · update · watchCriticalConfigMapAccess DataExposure InformationDisclosure PotentialPrivilegeEscalation Tampering
ClusterRole yugawarecore/nodes/proxygetCriticalAuthorizationBypass ClusterAdminAccess CodeExecution ElevationOfPrivilege LateralMovement (+1 more)
ClusterRole yugawarecore/pods/execcreateCriticalClusterWidePodExec CodeExecution ElevationOfPrivilege LateralMovement PodExec (+1 more)
ClusterRole yugawarecore/secretscreate · delete · get · list · patch · updateCriticalClusterWideSecretAccess Persistence PotentialPrivilegeEscalation PrivilegeEscalation SecretAccess (+1 more)
ClusterRole yugawareoperator.yugabyte.io/*create · delete · get · list · patch · update · watchHighClusterWideAccess WildcardPermission
ClusterRole yugawarecore/namespacescreate · delete · get · list · patchHighDenialOfService NamespaceLifecycle ResourceDeletion
ClusterRole yugawarecore/eventscreate · delete · get · list · patch · update · watchMediumInformationDisclosure OperationalData Reconnaissance
ClusterRole yugawarecert-manager.io/certificatescreate · delete · get · patchLow
ClusterRole yugawarecert-manager.io/clusterissuersgetLow
ClusterRole yugawarecert-manager.io/issuersgetLow
ClusterRole yugawarecore/nodesget · list · watchLow
ClusterRole yugawareopentelemetry.io/opentelemetrycollectorscreate · delete · get · patchLow
ClusterRole yugawarecore/persistentvolumeclaimsdelete · get · list · patchLow
ClusterRole yugawarepolicy/poddisruptionbudgetscreate · delete · get · patchLow
ClusterRole yugawarecore/podsdelete · get · list · watchLow
ClusterRole yugawarecore/servicescreate · delete · get · list · patchLow
ClusterRole yugawareapps/statefulsetscreate · delete · get · list · patchLow
ClusterRole yugawareapps/statefulsets/scalepatchLow
ClusterRole yugawarestorage.k8s.io/storageclassesgetLow

⚠️ Potential Abuse (13)

The following security risks were found based on the above permissions:

📦 Workloads (3)

KindNameContainerImage
StatefulSetyugaware-yugawarepostgrespostgres:14.19
StatefulSetyugaware-yugawareprometheusprom/prometheus:v3.5.0
StatefulSetyugaware-yugawareyugawarequay.io/yugabyte/yugaware:2025.2.0.1-b1