Fedora Account System
Red Hat Associate
Red Hat Customer
The submariner-k8s-broker-cluster Role — bound to the SA token distributed to every joined cluster — grants create,get,list,watch,patch,update,delete on submariner.io/clusters and submariner.io/endpoints across the entire broker namespace with no resourceNames restriction. Each cluster's gateway publishes an Endpoint CR containing its public IP, NAT IP, subnets, and cable-driver parameters; peer gateways read these to establish tunnels. A compromised spoke can therefore overwrite any other spoke's Endpoint CR to redirect tunnel traffic through an attacker-controlled IP, enabling IPsec MITM across the entire cluster mesh. Source: Project Glasswing AI-SAST audit of submariner-io/submariner-operator. Finding ID: FIND-001 Assurance: machine_verified (static analysis + code-level execution proof)