bind a resource to a resource
RBAC Atlas is a curated database of identities and the Role Based Access Control (RBAC) policies associated with them in popular Kubernetes open-source projects. Each entry includes security annotations that highlight granted permissions, potential risks, and possible abuse scenarios.
Why is RBAC important? RBAC is the final layer of defense in Kubernetes security. If workloads are compromised and an identity is stolen, a misconfigured or overly permissive RBAC policy (common with Operators) can enable attackers to move laterally within your cluster, potentially leading to a complete Kubernetes cluster takeover.
RBAC Atlas is a collaborative project created by Lenin Alevski, and contributions of additional RBAC rules are welcome. Check out the source on GitHub: rbac-scope (the CLI tool) and rbac-atlas (this website).
🚀 Top Risks
📦 Top Categories
monitoring operator kubernetes prometheus metric observability database edp alerting metrics timeseries metricsql tsdb victoriametrics ci kube-prometheus cluster argoproj gitops authentication See All →
📜 All Projects
rook-ceph
v1.19.0-beta-0File, Block, and Object Storage Services for your Cloud-Native Environment
runtime-sensors
v101.3.1Helm chart for the deployment of JFrog Runtime Security Agents within a Kubernetes environment.
sbom-operator
v0.41.0Catalogue all images of a Kubernetes cluster to multiple targets with Syft
secret-operator
v0.3.0The Kubedoop Secret Operator
sm-operator
v1.1.0A Helm chart to install the Bitwarden Secrets Manager operator.
snapscheduler
v3.5.0An operator to take scheduled snapshots of Kubernetes persistent volumes
solr-operator
v0.9.1The Solr Operator enables easy management of Solr resources within Kubernetes.
sonar-operator
v3.4.0-SNAPSHOT.12A Helm chart for KubeRocketCI Sonar Operator
sonar-operator
v3.3.0A Helm chart for KubeRocketCI Sonar Operator