Overview

FieldValue
ID1098
NameManage FlowSchemas (API Server DoS/Manipulation)
Risk CategoryDenial of Service
Risk LevelCritical
Role TypeClusterRole
API Groupsflowcontrol.apiserver.k8s.io
Resourcesflowschemas
Verbscreate, update, patch, delete
TagsAPIServerDoS ControlPlaneDisruption DenialOfService Tampering

Description

Allows managing FlowSchema objects cluster-wide. FlowSchemas are part of API Priority and Fairness, controlling how API requests are categorized and prioritized. Misconfiguration can lead to denial of service against the API server for critical components or allow certain requests to bypass throttling, potentially overwhelming the server.