Resurrectable ServiceAccount identities (2)
Critical / high-severity grants whose subject ServiceAccount is gone but the binding is not. Recreating the SA name reactivates the privilege. All severities →
| Principal | Severity | Created | Namespace state | Surviving grants |
|---|---|---|---|---|
| system:serviceaccount:legacy-pipelines:runner resurrectable cluster-admin privileged SCC | critical | 1y | ns deleted recreate ns + SA reactivates | |
| system:serviceaccount:ci:pipeline resurrectable cluster-admin | critical | 1y | ns present SA missing |
Role grants
Every role bound to a non-baseline subject — users, groups, your service accounts. Newest first. The audit view of what was granted to whom, when.
1 grants
| Created | Role | Tier | Subject | Scope | Binding |
|---|---|---|---|---|---|
| 1y | system:openshift:scc:anyuid (ClusterRole) | admin | ServiceAccount builder (mine-platform) | mine-platform | RoleBinding/mine-builder-use-anyuid |