bind a resource to a resource
RBAC Atlas is a curated database of identities and the Role Based Access Control (RBAC) policies associated with them in popular Kubernetes open-source projects. Each entry includes security annotations that highlight granted permissions, potential risks, and possible abuse scenarios.
Why is RBAC important? RBAC is the final layer of defense in Kubernetes security. If workloads are compromised and an identity is stolen, a misconfigured or overly permissive RBAC policy (common with Operators) can enable attackers to move laterally within your cluster, potentially leading to a complete Kubernetes cluster takeover.
RBAC Atlas is a collaborative project created by Lenin Alevski, and contributions of additional RBAC rules are welcome. Check out the source on GitHub: rbac-scope (the CLI tool) and rbac-atlas (this website).
🚀 Top Risks
📦 Top Categories
monitoring operator prometheus kubernetes metric database cluster alerting gitops argoproj kube-prometheus observability argocd storage sql gitlab metrics http php web See All →
📜 All Projects
istiod
v1.29.1Helm chart for istio control plane
jaeger
v4.5.0A Jaeger Helm chart for Kubernetes
jaeger-operator
v2.57.0jaeger-operator Helm chart for Kubernetes
jaeger-operator
v2.57.0jaeger-operator Helm chart for Kubernetes
jenkins
v5.9.8Jenkins - Build great things at any scale! As the leading open source automation server, Jenkins provides over 2000 plugins to support building, deploying and automating any project.
jira
v2.0.9A chart for installing Jira Data Center on Kubernetes
k10
v8.5.4Kasten’s K10 Data Management Platform
k8gb
v0.18.1A Helm chart for Kubernetes Global Balancer
k8s-watcher
v1.18.17Watches and sends kubernetes resource-related events
k8sgpt-operator
v0.2.25Automatic SRE Superpowers within your Kubernetes cluster
k8up
v4.8.6Kubernetes and OpenShift Backup Operator based on restic
kafka
v32.4.3Apache Kafka is a distributed streaming platform designed to build real-time pipelines and can be used as a message broker or as a replacement for a log aggregation solution for big data applications.
kafka-operator
v0.3.0The Kubedoop operator for Apache Kafka
kamaji-etcd
v0.15.0Helm chart for deploying a multi-tenant etcd cluster.
keda
v2.19.0Event-based autoscaler for workloads on Kubernetes
keptn
v0.11.0A Helm chart for Keptn, a set of tools to enable cloud-native application lifecycle management
keptn-cert-manager
v0.3.0A Helm chart for Keptn Certificate Manager, a subproject of Keptn
keptn-lifecycle-operator
v0.6.0A Helm chart for Keptn Lifecycle Operator, a subproject of Keptn
keptn-metrics-operator
v0.5.0A Helm chart for Keptn Metrics Operator, a subproject of Keptn
keycloak
v25.2.0Keycloak is a high performance Java-based identity and access management solution. It lets developers add an authentication layer to their applications with minimum effort.
keycloak-operator
v1.11.2Deploy Keycloak Operator and Keycloak
keycloak-operator
v1.32.0A Helm chart for KubeRocketCI Keycloak Operator
keycloak-operator
v1.33.0-SNAPSHOT.11A Helm chart for KubeRocketCI Keycloak Operator
keycloak-operator
v0.1.2Keycloak is an open source software product to allow single sign-on with identity and access management
kibana
v8.5.1Official Elastic helm chart for Kibana
komodor-agent
v2.16.1-RC1Watches and sends kubernetes resource-related events
kong
v3.1.0The Cloud-Native Ingress and API-management
kuadrant-operator
v1.4.2The Operator to install and manage the lifecycle of the Kuadrant components deployments.
kube-prometheus-stack
v62.7.0kube-prometheus-stack collects Kubernetes manifests, Grafana dashboards, and Prometheus rules combined with documentation and scripts to provide easy to operate end-to-end Kubernetes cluster monitoring with Prometheus using the Prometheus Operator.
kube-prometheus-stack
v82.10.3kube-prometheus-stack collects Kubernetes manifests, Grafana dashboards, and Prometheus rules combined with documentation and scripts to provide easy to operate end-to-end Kubernetes cluster monitoring with Prometheus using the Prometheus Operator.
kube-state-metrics
v7.2.0Install kube-state-metrics to generate and expose cluster-level metrics
kubernetes-dashboard
v7.14.0General-purpose web UI for Kubernetes clusters
kubestash-operator
v0.26.0KubeStash, Kubernetes native backup operator by AppsCode
kubevault-operator
v0.24.0-rc.0KubeVault Operator by AppsCode - HashiCorp Vault operator for Kubernetes
kubevious
v1.2.2A Helm chart for Kubevious
kured
v5.11.0A Helm chart for kured
kyverno
v3.7.1-rc.1Kubernetes Native Policy Management
lightrun-k8s-operator
v0.3.18A Helm chart for Lightrun k8s operator
limitador-operator
v0.18.0-dev01Kubernetes operator for managing Limitador instances, a rate limiting service to protect your APIs.
linkerd-control-plane
v2026.3.2Linkerd gives you observability, reliability, and security for your microservices — with no code change required.
linkerd-viz
v30.12.11The Linkerd-Viz extension contains observability and visualization components for Linkerd.
linkerd-viz
v2026.3.2The Linkerd-Viz extension contains observability and visualization components for Linkerd.
linkerd2
v2.11.5DEPRECATED: Use linkerd-crds and linkerd-control-plane for Linkerd 2.12.0 and later (see https://linkerd.io/2.12/tasks/upgrade/#upgrading-to-2-12-0-using-helm) - Linkerd gives you observability, reliability, and security for your microservices — with no code change required.
listener-operator
v0.3.0The Kubedoop Listener Operator
logstash
v8.5.1Official Elastic helm chart for Logstash
loki
v6.55.0Helm chart for Grafana Loki and Grafana Enterprise Logs supporting monolithic, simple scalable, and microservices modes.
loki-simple-scalable
v1.8.11Helm chart for Grafana Loki in simple, scalable mode
longhorn
v1.11.0Longhorn is a distributed block storage system for Kubernetes.
mariadb
v25.0.1MariaDB is an open source, community-developed SQL database server that is widely in use around the world due to its enterprise features, flexibility, and collaboration with leading tech firms.