Resurrectable ServiceAccount identities (2)
Critical / high-severity grants — RBAC bindings or SCC user lists — addressed at system:serviceaccount:<ns>:<name> for which the SA is gone. Recreating the name reactivates the privilege. All severities →
| Principal | Severity | Created | Namespace state | Surviving grants |
|---|---|---|---|---|
| system:serviceaccount:legacy-pipelines:runner resurrectable cluster-admin privileged SCC | critical | 1y | ns deleted recreate ns + SA reactivates | |
| system:serviceaccount:ci:pipeline resurrectable cluster-admin | critical | 1y | ns present SA missing |
Privileged subjects
Subjects bound to a privileged ClusterRole (cluster-admin, admin, system:masters) or a high-risk SCC use grant. Missing subjects here deserve review because the grant can become usable if the subject is later created or recreated.
1 bindings
| Role | Subject | Binding | Scope | Created |
|---|---|---|---|---|
| cluster-admin | Group system:masters | ClusterRoleBinding/cluster-admin | cluster-wide | 1y |