Lineage
read-only · v1.0
static mock demo — no cluster connection, no oc, no credentials
Static mock demo. This page uses a small bundled sample dataset. It does not connect to a cluster, run oc, or read local credentials.

SCC restricted-v2

Configuration

priority
allowPrivilegedContainerFalse
allowPrivilegeEscalationFalse
allowHostNetworkFalse
allowHostPIDFalse
allowHostIPCFalse
readOnlyRootFilesystem
runAsUser.typeMustRunAsRange

Granted to

Users (0)

none

Groups (1)

Pods admitted under this SCC (1)

Expandable summaries below show namespaces, images, and every pod admitted with this SCC. Click a summary row to open the table.

By namespace (1)

NamespacePods
openshift-authentication 1

By image (1)

ImageRegistryContainers
quay.io/openshift-release-dev/ocp-release@sha256:fake quay.io 1

All admitted pods (1)

ServiceAccountPodNamespacePhaseOwnerCreated
default oauth-server openshift-authentication Running 1y

Subjects that can use this SCC (1 of 6)

Direct SCC grants and RBAC use grants. Ghost ServiceAccounts here are potential admissions: recreating the same SA name reactivates the SCC grant.

SubjectCreatedStateGranted viaScope / note
User alice 1y user present ClusterRoleBinding/platform-admins-cluster-admin (via platform-admins) (RBAC use grant) can use this SCC now if authenticated