Lineage
read-only · v1.0
static mock demo — no cluster connection, no oc, no credentials
Static mock demo. This page uses a small bundled sample dataset. It does not connect to a cluster, run oc, or read local credentials.

SCC privileged privileged

Configuration

priority10
allowPrivilegedContainerTrue
allowPrivilegeEscalationTrue
allowHostNetworkTrue
allowHostPIDTrue
allowHostIPCTrue
readOnlyRootFilesystem
runAsUser.typeRunAsAny

Granted to

Users (2)

Groups (1)

Resurrectable ServiceAccount grants (1)

These entries in scc.users address a ServiceAccount that no longer exists. SCC admission matches by name string, so recreating the SA reactivates this SCC's posture for any pod the SA admits. Because this SCC allows privileged containers, the surviving grant is critical.

PrincipalCreatedNamespaceState
system:serviceaccount:legacy-pipelines:runner 1y legacy-pipelines namespace deleted recreating ns + SA reactivates

Pods admitted under this SCC (1)

Expandable summaries below show namespaces, images, and every pod admitted with this SCC. Click a summary row to open the table.

By namespace (1)

NamespacePods
mine-platform 1

By image (1)

ImageRegistryContainers
registry.redhat.io/rhel8/support-tools:latest registry.redhat.io 1

All admitted pods (1)

ServiceAccountPodNamespacePhaseOwnerCreated
builder privileged-debug mine-platform Running 1y

Subjects that can use this SCC (3 of 9)

Direct SCC grants and RBAC use grants. Ghost ServiceAccounts here are potential admissions: recreating the same SA name reactivates the SCC grant.

SubjectCreatedStateGranted viaScope / note
User alice 1y user present ClusterRoleBinding/platform-admins-cluster-admin (via platform-admins) (RBAC use grant) can use this SCC now if authenticated
User alice 1y user present scc.groups/platform-admins (SCC group list) can use this SCC now if authenticated
User system:admin baseline 1y virtual/system user scc.users (SCC user list) platform identity