Resurrectable ServiceAccount identities (2)
Critical / high-severity grants whose subject ServiceAccount is gone but the binding is not. Recreating the SA name reactivates the privilege. All severities →
| Principal | Severity | Created | Namespace state | Surviving grants |
|---|---|---|---|---|
| system:serviceaccount:legacy-pipelines:runner resurrectable cluster-admin privileged SCC | critical | 1y | ns deleted recreate ns + SA reactivates | |
| system:serviceaccount:ci:pipeline resurrectable cluster-admin | critical | 1y | ns present SA missing |
Role grants
Every role bound to a non-baseline subject — users, groups, your service accounts. Newest first. The audit view of what was granted to whom, when.
3 grants
| Created | Role | Tier | Subject | Scope | Binding |
|---|---|---|---|---|---|
| 1y | admin (ClusterRole) | admin | Group engineers | mine-platform | RoleBinding/admin-rb-copy |
| 1y | admin (ClusterRole) | admin | Group engineers | mine-platform | RoleBinding/admin-rb |
| 1y | admin (ClusterRole) | admin | User future-hire@company.com ghost | cluster-wide | ClusterRoleBinding/ghost-future-employee |