Resurrectable ServiceAccount identities (2)
Critical / high-severity grants whose subject ServiceAccount is gone but the binding is not. Recreating the SA name reactivates the privilege. All severities →
| Principal | Severity | Created | Namespace state | Surviving grants |
|---|---|---|---|---|
| system:serviceaccount:legacy-pipelines:runner resurrectable cluster-admin privileged SCC | critical | 1y | ns deleted recreate ns + SA reactivates | |
| system:serviceaccount:ci:pipeline resurrectable cluster-admin | critical | 1y | ns present SA missing |
Role grants
Every role bound to a non-baseline subject — users, groups, your service accounts. Newest first. The audit view of what was granted to whom, when.
1 grants
| Created | Role | Tier | Subject | Scope | Binding |
|---|---|---|---|---|---|
| 1y | system:image-builder (ClusterRole) | custom | ServiceAccount builder (ci) | shared-images | RoleBinding/ci-builder-pushes-shared |