Overview

FieldValue
ID1081
NameManage Leases in kube-system or kube-node-lease namespace
Risk CategoryTampering
Risk LevelCritical
Role TypeRole
API Groupscoordination.k8s.io
Resourcesleases
Verbscreate, update, patch, delete
TagsControlPlaneDisruption CriticalNamespace DenialOfService Tampering

Description

Allows managing Lease objects in critical namespaces like ‘kube-system’ or ‘kube-node-lease’. This is highly critical as it can disrupt core Kubernetes components, lead to node instability, or denial of service.