Kubernetes Operators: The Overlooked Backdoor in Cloud Automation
Kubernetes operators are automated tools that reduce manual work by acting like site reliability engineers, managing applications without human intervention. However, they typically rely on highly privileged service accounts to function, and this privilege often goes unchecked. Unit 42 has released a free tool called OperTraitor, which analyses the access permissions of these operators and compares them to what the operator actually needs to do its job.
Using this tool, researchers found that many operators, including ones listed in the popular OperatorHub catalog, are configured with broad, wildcard-style permissions that go far beyond what is necessary. Some of these components are abandoned or poorly maintained, yet still carry sweeping access rights. If an attacker compromises such an operator, whether through a supply chain attack, a software vulnerability, or a hijacked server, the level of damage they can cause is defined entirely by those excessive permissions.
The researchers also note that as the industry moves toward AI-driven, agentic operators, these previously passive misconfigurations could become active attack pathways. This makes reviewing and tightening operator permissions an increasingly urgent task for organisations running Kubernetes infrastructure.