Open this resource#

Console route: /serviceaccounts. This is a namespaced resource; choose the namespace before making a change.

  1. Select the correct cluster in the sidebar.
  2. Open ServiceAccounts and narrow the list using the available namespace/search controls.
  3. Select the exact object by name. Verify its scope and identity at the top of the detail page.
Service accounts are Kubernetes workload identities. Use the namespace context to find the identity used by your workload.
Service accounts are Kubernetes workload identities. Use the namespace context to find the identity used by your workload. View full size ↗

What to inspect#

ServiceAccount name, namespace, annotations and referenced configuration.

Refresh the resource when you need the latest observation. Overview fields summarize the object; YAML exposes the complete returned document. A placeholder or missing status field should not be read as a successful or zero-valued result.

Use the available features#

Open Service Accounts in the workload namespace. Compare the workload’s serviceAccountName with this object. Follow relevant RoleBindings/ClusterRoleBindings to understand granted permissions.

Describe, Clone, YAML editing and Delete are shared resource actions where the page and your permissions allow them. Read Create, edit, clone and delete resources before applying a change.

A practical investigation#

Creating a ServiceAccount alone does not grant arbitrary resource access. Orkiva user accounts and Kubernetes ServiceAccounts are different identities.

  1. Establish the current state and the symptom you want to resolve.
  2. Identify whether a controller, Helm release or Delivery project owns the object.
  3. Make the smallest authorized change through that owner when possible.
  4. Refresh and verify the resulting resource state. Inspect related objects rather than stopping at a successful save message.

Permissions and unavailable data#

Listing this kind does not automatically grant every subresource action. The console checks operation access, and Kubernetes still checks the connected identity. If this API is not served by the cluster, fix the installation/version capability rather than treating an empty or unavailable page as an authorization grant.