Compliance Run (06-23-2025) 
        
            Diki Version:  v0.17.0Glossary 
            
                🟢 Passed: Rule check has been fulfilled. 
                🔵 Skipped: Rule check has been considered irrelevant for the specific scenario and will not be run. 
                🔵 Accepted: Rule check may or may not have been run, but it was decided by the user that the check is not a finding. 
                🟠 Warning: Rule check has encountered an ambiguous condition or configuration preventing the ability to determine if the check is fulfilled or not. 
                🔴 Failed: Rule check has been unfulfilled, can be considered a finding. 
                🔴 Errored: Rule check has errored during runtime. It cannot be determined whether the check is fulfilled or not. 
                🟠 Not Implemented: Rule check has not been implemented yet. 
             
                Provider Garden 
                Evaluated targets 
                
                    aws  (gardenerVersion: v1.121.1, projectName: diki-comp, time: 06-23-2025 00:22:41)azure  (gardenerVersion: v1.121.1, projectName: diki-comp, time: 06-23-2025 00:24:13)gcp  (gardenerVersion: v1.121.1, projectName: diki-comp, time: 06-23-2025 00:25:57)openstack  (gardenerVersion: v1.121.1, projectName: diki-comp, time: 06-23-2025 00:28:18) 
                
                    
                        v0.2.1 Security Hardened Shoot Cluster  (11x Passed 🟢)
                            
                                🟢 Passed 
                                
                                    
                                        1000 (Medium) - Shoot clusters should enable required extensions. 
                                        
                                            
                                                Extension shoot-lakom-service is enabled for the shoot cluster. 
                                                
                                             
                                         
                                     
                                    
                                        1001 (Medium) - Shoot clusters should use a supported version of Kubernetes. 
                                        
                                            
                                                Shoot uses a Kubernetes version with an allowed classification. 
                                                
                                                    
                                                        aws 
                                                        
                                                            classification: supported version: 1.31.8  
                                                         
                                                     
                                                    
                                                        azure 
                                                        
                                                            classification: supported version: 1.31.8  
                                                         
                                                     
                                                    
                                                        gcp 
                                                        
                                                            classification: supported version: 1.31.8  
                                                         
                                                     
                                                    
                                                        openstack 
                                                        
                                                            classification: supported version: 1.31.8  
                                                         
                                                     
                                                 
                                             
                                         
                                     
                                    
                                        1002 (Medium) - Shoot clusters should use supported versions for their Workers' images. 
                                        
                                            
                                                Worker group uses allowed classification of machine image. 
                                                
                                                    
                                                        aws 
                                                        
                                                            classification: supported image: gardenlinux version: 1592.10.0 worker: worker-kkfk1  
                                                         
                                                     
                                                    
                                                        azure 
                                                        
                                                            classification: supported image: gardenlinux version: 1592.10.0 worker: worker-g7p4p  
                                                         
                                                     
                                                    
                                                        gcp 
                                                        
                                                            classification: supported image: gardenlinux version: 1592.10.0 worker: worker-bex82  
                                                         
                                                     
                                                    
                                                        openstack 
                                                        
                                                            classification: supported image: gardenlinux version: 1592.10.0 worker: worker-dqty2  
                                                         
                                                     
                                                 
                                             
                                         
                                     
                                    
                                        1003 (High) - Shoot clusters must have the Lakom extension configured. 
                                        
                                            
                                                Extension shoot-lakom-service configured correctly for the shoot cluster. 
                                                
                                             
                                         
                                     
                                    
                                        2000 (High) - Shoot clusters must have anonymous authentication disabled for the Kubernetes API server. 
                                        
                                            
                                                Anonymous authentication is not enabled. 
                                                
                                             
                                         
                                     
                                    
                                        2001 (Medium) - Shoot clusters must disable ssh access to worker nodes. 
                                        
                                            
                                                SSH access is disabled for worker nodes. 
                                                
                                             
                                         
                                     
                                    
                                        2002 (Medium) - Shoot clusters must not have Alpha APIs enabled for any Kubernetes component. 
                                        
                                            
                                                AllAlpha featureGate is not enabled for the kube-apiserver. 
                                                
                                             
                                            
                                                AllAlpha featureGate is not enabled for the kube-controller-manager. 
                                                
                                             
                                            
                                                AllAlpha featureGate is not enabled for the kube-scheduler. 
                                                
                                             
                                            
                                                AllAlpha featureGate is not enabled for the kube-proxy. 
                                                
                                             
                                            
                                                AllAlpha featureGate is not enabled for the kubelet. 
                                                
                                             
                                         
                                     
                                    
                                        2003 (High) - Shoot clusters must enable kernel protection for Kubelets. 
                                        
                                            
                                                Default kubelet config does not disable kernel protection. 
                                                
                                             
                                            
                                                Worker kubelet config does not disable kernel protection. 
                                                
                                             
                                         
                                     
                                    
                                        2004 (High) - Shoot clusters must have ValidatingAdmissionWebhook admission plugin enabled. 
                                        
                                            
                                                The ValidatingAdmissionWebhook admission plugin is not disabled. 
                                                
                                             
                                         
                                     
                                    
                                        2005 (Medium) - Shoot clusters must not disable timeouts for Kubelet. 
                                        
                                            
                                                The connection timeout is not set and therefore will be defaulted to the recommended value (5m). 
                                                
                                             
                                         
                                     
                                    
                                        2007 (High) - Shoot clusters must have a PodSecurity admission plugin configured. 
                                        
                                            
                                                PodSecurity admission plugin is configured correctly. 
                                                
                                             
                                         
                                     
                                 
                             
                         
                     
                 
             
            
                Provider Gardener 
                Evaluated targets 
                
                    aws  (gardenVirtualCloudProvider: gcp, gardenerVersion: v1.121.1, projectName: diki-comp, seedCloudProvider: aws, seedKubernetesVersion: v1.32.4, shootCloudProvider: aws, shootKubernetesVersion: v1.31.8, time: 06-23-2025 00:22:41)azure  (gardenVirtualCloudProvider: gcp, gardenerVersion: v1.121.1, projectName: diki-comp, seedCloudProvider: azure, seedKubernetesVersion: v1.32.4, shootCloudProvider: azure, shootKubernetesVersion: v1.31.8, time: 06-23-2025 00:24:13)gcp  (gardenVirtualCloudProvider: gcp, gardenerVersion: v1.121.1, projectName: diki-comp, seedCloudProvider: gcp, seedKubernetesVersion: v1.32.4, shootCloudProvider: gcp, shootKubernetesVersion: v1.31.8, time: 06-23-2025 00:25:57)openstack  (gardenVirtualCloudProvider: gcp, gardenerVersion: v1.121.1, projectName: diki-comp, seedCloudProvider: openstack, seedKubernetesVersion: v1.32.4, shootCloudProvider: openstack, shootKubernetesVersion: v1.31.8, time: 06-23-2025 00:28:18) 
                
                    
                        v2r3 DISA Kubernetes Security Technical Implementation Guide  (61x Passed 🟢, 24x Skipped 🔵, 7x Accepted 🔵)
                            
                                🟢 Passed 
                                
                                    
                                        242376 (Medium) - The Kubernetes Controller Manager must use TLS 1.2, at a minimum, to protect the confidentiality of sensitive data during electronic dissemination. 
                                        
                                            
                                                Option tls-min-version has not been set. 
                                                
                                                    
                                                        aws 
                                                        
                                                            kind: deployment name: kube-controller-manager namespace: shoot--diki-comp--aws  
                                                         
                                                     
                                                    
                                                        azure 
                                                        
                                                            kind: deployment name: kube-controller-manager namespace: shoot--diki-comp--azure  
                                                         
                                                     
                                                    
                                                        gcp 
                                                        
                                                            kind: deployment name: kube-controller-manager namespace: shoot--diki-comp--gcp  
                                                         
                                                     
                                                    
                                                        openstack 
                                                        
                                                            kind: deployment name: kube-controller-manager namespace: shoot--diki-comp--openstack  
                                                         
                                                     
                                                 
                                             
                                         
                                     
                                    
                                        242377 (Medium) - Kubernetes Scheduler must use TLS 1.2, at a minimum, to protect the confidentiality of sensitive data during electronic dissemination. 
                                        
                                            
                                                Option tls-min-version has not been set. 
                                                
                                                    
                                                        aws 
                                                        
                                                            cluster: seed kind: deployment name: kube-scheduler namespace: shoot--diki-comp--aws  
                                                         
                                                     
                                                    
                                                        azure 
                                                        
                                                            cluster: seed kind: deployment name: kube-scheduler namespace: shoot--diki-comp--azure  
                                                         
                                                     
                                                    
                                                        gcp 
                                                        
                                                            cluster: seed kind: deployment name: kube-scheduler namespace: shoot--diki-comp--gcp  
                                                         
                                                     
                                                    
                                                        openstack 
                                                        
                                                            cluster: seed kind: deployment name: kube-scheduler namespace: shoot--diki-comp--openstack  
                                                         
                                                     
                                                 
                                             
                                         
                                     
                                    
                                        242378 (Medium) - The Kubernetes API Server must use TLS 1.2, at a minimum, to protect the confidentiality of sensitive data during electronic dissemination. 
                                        
                                            
                                                Option tls-min-version has not been set. 
                                                
                                                    
                                                        aws 
                                                        
                                                            kind: deployment name: kube-apiserver namespace: shoot--diki-comp--aws  
                                                         
                                                     
                                                    
                                                        azure 
                                                        
                                                            kind: deployment name: kube-apiserver namespace: shoot--diki-comp--azure  
                                                         
                                                     
                                                    
                                                        gcp 
                                                        
                                                            kind: deployment name: kube-apiserver namespace: shoot--diki-comp--gcp  
                                                         
                                                     
                                                    
                                                        openstack 
                                                        
                                                            kind: deployment name: kube-apiserver namespace: shoot--diki-comp--openstack  
                                                         
                                                     
                                                 
                                             
                                         
                                     
                                    
                                        242379 (Medium) - The Kubernetes etcd must use TLS to protect the confidentiality of sensitive data during electronic dissemination. 
                                        
                                            
                                                Option client-transport-security.auto-tls set to allowed value. 
                                                
                                                    
                                                        aws 
                                                        
                                                            kind: statefulSet name: etcd-main namespace: shoot--diki-comp--aws  
                                                            kind: statefulSet name: etcd-events namespace: shoot--diki-comp--aws  
                                                         
                                                     
                                                    
                                                        azure 
                                                        
                                                            kind: statefulSet name: etcd-main namespace: shoot--diki-comp--azure  
                                                            kind: statefulSet name: etcd-events namespace: shoot--diki-comp--azure  
                                                         
                                                     
                                                    
                                                        gcp 
                                                        
                                                            kind: statefulSet name: etcd-main namespace: shoot--diki-comp--gcp  
                                                            kind: statefulSet name: etcd-events namespace: shoot--diki-comp--gcp  
                                                         
                                                     
                                                    
                                                        openstack 
                                                        
                                                            kind: statefulSet name: etcd-main namespace: shoot--diki-comp--openstack  
                                                            kind: statefulSet name: etcd-events namespace: shoot--diki-comp--openstack  
                                                         
                                                     
                                                 
                                             
                                         
                                     
                                    
                                        242381 (High) - The Kubernetes Controller Manager must create unique service accounts for each work payload. 
                                        
                                            
                                                Option use-service-account-credentials set to allowed value. 
                                                
                                                    
                                                        aws 
                                                        
                                                            kind: deployment name: kube-controller-manager namespace: shoot--diki-comp--aws  
                                                         
                                                     
                                                    
                                                        azure 
                                                        
                                                            kind: deployment name: kube-controller-manager namespace: shoot--diki-comp--azure  
                                                         
                                                     
                                                    
                                                        gcp 
                                                        
                                                            kind: deployment name: kube-controller-manager namespace: shoot--diki-comp--gcp  
                                                         
                                                     
                                                    
                                                        openstack 
                                                        
                                                            kind: deployment name: kube-controller-manager namespace: shoot--diki-comp--openstack  
                                                         
                                                     
                                                 
                                             
                                         
                                     
                                    
                                        242382 (Medium) - The Kubernetes API Server must enable Node,RBAC as the authorization mode. 
                                        
                                            
                                                AuthorizationConfiguration has expected start mode types set. 
                                                
                                                    
                                                        aws 
                                                        
                                                            kind: AuthorizationConfiguration  
                                                         
                                                     
                                                    
                                                        azure 
                                                        
                                                            kind: AuthorizationConfiguration  
                                                         
                                                     
                                                    
                                                        gcp 
                                                        
                                                            kind: AuthorizationConfiguration  
                                                         
                                                     
                                                    
                                                        openstack 
                                                        
                                                            kind: AuthorizationConfiguration  
                                                         
                                                     
                                                 
                                             
                                         
                                     
                                    
                                        242383 (Medium) - Kubernetes must separate user functionality. 
                                        
                                            
                                                System resource in system namespaces. 
                                                
                                                    
                                                        aws 
                                                        
                                                            kind: Service name: kubernetes namespace: default  
                                                         
                                                     
                                                    
                                                        azure 
                                                        
                                                            kind: Service name: kubernetes namespace: default  
                                                         
                                                     
                                                    
                                                        gcp 
                                                        
                                                            kind: Service name: kubernetes namespace: default  
                                                         
                                                     
                                                    
                                                        openstack 
                                                        
                                                            kind: Service name: kubernetes namespace: default  
                                                         
                                                     
                                                 
                                             
                                         
                                     
                                    
                                        242386 (High) - The Kubernetes API server must have the insecure port flag disabled. 
                                        
                                            
                                                Option insecure-port not set. 
                                                
                                                    
                                                        aws 
                                                        
                                                            kind: deployment name: kube-apiserver namespace: shoot--diki-comp--aws  
                                                         
                                                     
                                                    
                                                        azure 
                                                        
                                                            kind: deployment name: kube-apiserver namespace: shoot--diki-comp--azure  
                                                         
                                                     
                                                    
                                                        gcp 
                                                        
                                                            kind: deployment name: kube-apiserver namespace: shoot--diki-comp--gcp  
                                                         
                                                     
                                                    
                                                        openstack 
                                                        
                                                            kind: deployment name: kube-apiserver namespace: shoot--diki-comp--openstack  
                                                         
                                                     
                                                 
                                             
                                         
                                     
                                    
                                        242387 (High) - The Kubernetes Kubelet must have the "readOnlyPort" flag disabled. 
                                        
                                            
                                                Option readOnlyPort not set. 
                                                
                                                    
                                                        aws 
                                                        
                                                            kind: node name: ip-IP-Address.eu-west-1.compute.internal  
                                                            kind: node name: ip-IP-Address.eu-west-1.compute.internal  
                                                         
                                                     
                                                    
                                                        azure 
                                                        
                                                            kind: node name: shoot--diki-comp--azure-worker-g7p4p-z3-66467-k6q5n  
                                                            kind: node name: shoot--diki-comp--azure-worker-g7p4p-z3-66467-xzlbf  
                                                         
                                                     
                                                    
                                                        gcp 
                                                        
                                                            kind: node name: shoot--diki-comp--gcp-worker-bex82-z1-5d9b4-8fp7q  
                                                            kind: node name: shoot--diki-comp--gcp-worker-bex82-z1-5d9b4-xjxdz  
                                                         
                                                     
                                                    
                                                        openstack 
                                                        
                                                            kind: node name: shoot--diki-comp--openstack-worker-dqty2-z1-64f7d-jllmm  
                                                            kind: node name: shoot--diki-comp--openstack-worker-dqty2-z1-64f7d-wmcjr  
                                                         
                                                     
                                                 
                                             
                                         
                                     
                                    
                                        242388 (High) - The Kubernetes API server must have the insecure bind address not set. 
                                        
                                            
                                                Option insecure-bind-address not set. 
                                                
                                                    
                                                        aws 
                                                        
                                                            kind: deployment name: kube-apiserver namespace: shoot--diki-comp--aws  
                                                         
                                                     
                                                    
                                                        azure 
                                                        
                                                            kind: deployment name: kube-apiserver namespace: shoot--diki-comp--azure  
                                                         
                                                     
                                                    
                                                        gcp 
                                                        
                                                            kind: deployment name: kube-apiserver namespace: shoot--diki-comp--gcp  
                                                         
                                                     
                                                    
                                                        openstack 
                                                        
                                                            kind: deployment name: kube-apiserver namespace: shoot--diki-comp--openstack  
                                                         
                                                     
                                                 
                                             
                                         
                                     
                                    
                                        242389 (Medium) - The Kubernetes API server must have the secure port set. 
                                        
                                            
                                                Option secure-port set to allowed value. 
                                                
                                                    
                                                        aws 
                                                        
                                                            kind: deployment name: kube-apiserver namespace: shoot--diki-comp--aws  
                                                         
                                                     
                                                    
                                                        azure 
                                                        
                                                            kind: deployment name: kube-apiserver namespace: shoot--diki-comp--azure  
                                                         
                                                     
                                                    
                                                        gcp 
                                                        
                                                            kind: deployment name: kube-apiserver namespace: shoot--diki-comp--gcp  
                                                         
                                                     
                                                    
                                                        openstack 
                                                        
                                                            kind: deployment name: kube-apiserver namespace: shoot--diki-comp--openstack  
                                                         
                                                     
                                                 
                                             
                                         
                                     
                                    
                                        242390 (High) - The Kubernetes API server must have anonymous authentication disabled. 
                                        
                                            
                                                Option anonymous-auth set to allowed value. 
                                                
                                                    
                                                        aws 
                                                        
                                                            kind: deployment name: kube-apiserver namespace: shoot--diki-comp--aws  
                                                         
                                                     
                                                    
                                                        azure 
                                                        
                                                            kind: deployment name: kube-apiserver namespace: shoot--diki-comp--azure  
                                                         
                                                     
                                                    
                                                        gcp 
                                                        
                                                            kind: deployment name: kube-apiserver namespace: shoot--diki-comp--gcp  
                                                         
                                                     
                                                    
                                                        openstack 
                                                        
                                                            kind: deployment name: kube-apiserver namespace: shoot--diki-comp--openstack  
                                                         
                                                     
                                                 
                                             
                                         
                                     
                                    
                                        242391 (High) - The Kubernetes Kubelet must have anonymous authentication disabled. 
                                        
                                            
                                                Option authentication.anonymous.enabled set to allowed value. 
                                                
                                                    
                                                        aws 
                                                        
                                                            kind: node name: ip-IP-Address.eu-west-1.compute.internal  
                                                            kind: node name: ip-IP-Address.eu-west-1.compute.internal  
                                                         
                                                     
                                                    
                                                        azure 
                                                        
                                                            kind: node name: shoot--diki-comp--azure-worker-g7p4p-z3-66467-k6q5n  
                                                            kind: node name: shoot--diki-comp--azure-worker-g7p4p-z3-66467-xzlbf  
                                                         
                                                     
                                                    
                                                        gcp 
                                                        
                                                            kind: node name: shoot--diki-comp--gcp-worker-bex82-z1-5d9b4-8fp7q  
                                                            kind: node name: shoot--diki-comp--gcp-worker-bex82-z1-5d9b4-xjxdz  
                                                         
                                                     
                                                    
                                                        openstack 
                                                        
                                                            kind: node name: shoot--diki-comp--openstack-worker-dqty2-z1-64f7d-jllmm  
                                                            kind: node name: shoot--diki-comp--openstack-worker-dqty2-z1-64f7d-wmcjr  
                                                         
                                                     
                                                 
                                             
                                         
                                     
                                    
                                        242392 (High) - The Kubernetes kubelet must enable explicit authorization. 
                                        
                                            
                                                Option authorization.mode set to allowed value. 
                                                
                                                    
                                                        aws 
                                                        
                                                            kind: node name: ip-IP-Address.eu-west-1.compute.internal  
                                                            kind: node name: ip-IP-Address.eu-west-1.compute.internal  
                                                         
                                                     
                                                    
                                                        azure 
                                                        
                                                            kind: node name: shoot--diki-comp--azure-worker-g7p4p-z3-66467-k6q5n  
                                                            kind: node name: shoot--diki-comp--azure-worker-g7p4p-z3-66467-xzlbf  
                                                         
                                                     
                                                    
                                                        gcp 
                                                        
                                                            kind: node name: shoot--diki-comp--gcp-worker-bex82-z1-5d9b4-8fp7q  
                                                            kind: node name: shoot--diki-comp--gcp-worker-bex82-z1-5d9b4-xjxdz  
                                                         
                                                     
                                                    
                                                        openstack 
                                                        
                                                            kind: node name: shoot--diki-comp--openstack-worker-dqty2-z1-64f7d-jllmm  
                                                            kind: node name: shoot--diki-comp--openstack-worker-dqty2-z1-64f7d-wmcjr  
                                                         
                                                     
                                                 
                                             
                                         
                                     
                                    
                                        242393 (Medium) - Kubernetes Worker Nodes must not have sshd service running. 
                                        
                                            
                                                SSH daemon service not installed 
                                                
                                                    
                                                        aws 
                                                        
                                                            kind: node name: ip-IP-Address.eu-west-1.compute.internal  
                                                         
                                                     
                                                    
                                                        azure 
                                                        
                                                            kind: node name: shoot--diki-comp--azure-worker-g7p4p-z3-66467-k6q5n  
                                                         
                                                     
                                                    
                                                        gcp 
                                                        
                                                            kind: node name: shoot--diki-comp--gcp-worker-bex82-z1-5d9b4-8fp7q  
                                                         
                                                     
                                                    
                                                        openstack 
                                                        
                                                            kind: node name: shoot--diki-comp--openstack-worker-dqty2-z1-64f7d-jllmm  
                                                         
                                                     
                                                 
                                             
                                         
                                     
                                    
                                        242394 (Medium) - Kubernetes Worker Nodes must not have the sshd service enabled. 
                                        
                                            
                                                SSH daemon disabled (or could not be probed) 
                                                
                                                    
                                                        aws 
                                                        
                                                            kind: node name: ip-IP-Address.eu-west-1.compute.internal  
                                                         
                                                     
                                                    
                                                        azure 
                                                        
                                                            kind: node name: shoot--diki-comp--azure-worker-g7p4p-z3-66467-k6q5n  
                                                         
                                                     
                                                    
                                                        gcp 
                                                        
                                                            kind: node name: shoot--diki-comp--gcp-worker-bex82-z1-5d9b4-8fp7q  
                                                         
                                                     
                                                    
                                                        openstack 
                                                        
                                                            kind: node name: shoot--diki-comp--openstack-worker-dqty2-z1-64f7d-jllmm  
                                                         
                                                     
                                                 
                                             
                                         
                                     
                                    
                                        242395 (Medium) - Kubernetes dashboard must not be enabled. 
                                        
                                            
                                                Kubernetes dashboard not installed 
                                                
                                             
                                         
                                     
                                    
                                        242397 (High) - The Kubernetes kubelet staticPodPath must not enable static pods. 
                                        
                                            
                                                Option staticPodPath not set. 
                                                
                                                    
                                                        aws 
                                                        
                                                            kind: node name: ip-IP-Address.eu-west-1.compute.internal  
                                                            kind: node name: ip-IP-Address.eu-west-1.compute.internal  
                                                         
                                                     
                                                    
                                                        azure 
                                                        
                                                            kind: node name: shoot--diki-comp--azure-worker-g7p4p-z3-66467-k6q5n  
                                                            kind: node name: shoot--diki-comp--azure-worker-g7p4p-z3-66467-xzlbf  
                                                         
                                                     
                                                    
                                                        gcp 
                                                        
                                                            kind: node name: shoot--diki-comp--gcp-worker-bex82-z1-5d9b4-8fp7q  
                                                            kind: node name: shoot--diki-comp--gcp-worker-bex82-z1-5d9b4-xjxdz  
                                                         
                                                     
                                                    
                                                        openstack 
                                                        
                                                            kind: node name: shoot--diki-comp--openstack-worker-dqty2-z1-64f7d-jllmm  
                                                            kind: node name: shoot--diki-comp--openstack-worker-dqty2-z1-64f7d-wmcjr  
                                                         
                                                     
                                                 
                                             
                                         
                                     
                                    
                                        242400 (Medium) - The Kubernetes API server must have Alpha APIs disabled. 
                                        
                                            
                                                Option featureGates.AllAlpha not set. 
                                                
                                                    
                                                        aws 
                                                        
                                                            cluster: seed kind: deployment name: kube-apiserver namespace: shoot--diki-comp--aws  
                                                            cluster: seed kind: deployment name: kube-controller-manager namespace: shoot--diki-comp--aws  
                                                            cluster: seed kind: deployment name: kube-scheduler namespace: shoot--diki-comp--aws  
                                                            cluster: shoot kind: node name: ip-IP-Address.eu-west-1.compute.internal  
                                                            cluster: shoot kind: node name: ip-IP-Address.eu-west-1.compute.internal  
                                                            cluster: shoot kind: pod name: kube-proxy-worker-kkfk1-v1.31.8-8bvtn namespace: kube-system  
                                                         
                                                     
                                                    
                                                        azure 
                                                        
                                                            cluster: seed kind: deployment name: kube-apiserver namespace: shoot--diki-comp--azure  
                                                            cluster: seed kind: deployment name: kube-controller-manager namespace: shoot--diki-comp--azure  
                                                            cluster: seed kind: deployment name: kube-scheduler namespace: shoot--diki-comp--azure  
                                                            cluster: shoot kind: node name: shoot--diki-comp--azure-worker-g7p4p-z3-66467-k6q5n  
                                                            cluster: shoot kind: node name: shoot--diki-comp--azure-worker-g7p4p-z3-66467-xzlbf  
                                                            cluster: shoot kind: pod name: kube-proxy-worker-g7p4p-v1.31.8-7dnc5 namespace: kube-system  
                                                         
                                                     
                                                    
                                                        gcp 
                                                        
                                                            cluster: seed kind: deployment name: kube-apiserver namespace: shoot--diki-comp--gcp  
                                                            cluster: seed kind: deployment name: kube-controller-manager namespace: shoot--diki-comp--gcp  
                                                            cluster: seed kind: deployment name: kube-scheduler namespace: shoot--diki-comp--gcp  
                                                            cluster: shoot kind: node name: shoot--diki-comp--gcp-worker-bex82-z1-5d9b4-8fp7q  
                                                            cluster: shoot kind: node name: shoot--diki-comp--gcp-worker-bex82-z1-5d9b4-xjxdz  
                                                            cluster: shoot kind: pod name: kube-proxy-worker-bex82-v1.31.8-x9kg4 namespace: kube-system  
                                                         
                                                     
                                                    
                                                        openstack 
                                                        
                                                            cluster: seed kind: deployment name: kube-apiserver namespace: shoot--diki-comp--openstack  
                                                            cluster: seed kind: deployment name: kube-controller-manager namespace: shoot--diki-comp--openstack  
                                                            cluster: seed kind: deployment name: kube-scheduler namespace: shoot--diki-comp--openstack  
                                                            cluster: shoot kind: node name: shoot--diki-comp--openstack-worker-dqty2-z1-64f7d-jllmm  
                                                            cluster: shoot kind: node name: shoot--diki-comp--openstack-worker-dqty2-z1-64f7d-wmcjr  
                                                            cluster: shoot kind: pod name: kube-proxy-worker-dqty2-v1.31.8-9sx78 namespace: kube-system  
                                                         
                                                     
                                                 
                                             
                                         
                                     
                                    
                                        242404 (Medium) - Kubernetes Kubelet must deny hostname override. 
                                        
                                            
                                                Flag hostname-override not set. 
                                                
                                                    
                                                        aws 
                                                        
                                                            kind: node name: ip-IP-Address.eu-west-1.compute.internal  
                                                         
                                                     
                                                    
                                                        azure 
                                                        
                                                            kind: node name: shoot--diki-comp--azure-worker-g7p4p-z3-66467-k6q5n  
                                                         
                                                     
                                                    
                                                        gcp 
                                                        
                                                            kind: node name: shoot--diki-comp--gcp-worker-bex82-z1-5d9b4-8fp7q  
                                                         
                                                     
                                                    
                                                        openstack 
                                                        
                                                            kind: node name: shoot--diki-comp--openstack-worker-dqty2-z1-64f7d-jllmm  
                                                         
                                                     
                                                 
                                             
                                         
                                     
                                    
                                        242406 (Medium) - The Kubernetes kubelet configuration file must be owned by root. 
                                        
                                            
                                                File has expected owners 
                                                
                                                    
                                                        aws 
                                                        
                                                            details: fileName: /etc/systemd/system/kubelet.service, ownerUser: 0, ownerGroup: 0 kind: node name: ip-IP-Address.eu-west-1.compute.internal  
                                                         
                                                     
                                                    
                                                        azure 
                                                        
                                                            details: fileName: /etc/systemd/system/kubelet.service, ownerUser: 0, ownerGroup: 0 kind: node name: shoot--diki-comp--azure-worker-g7p4p-z3-66467-k6q5n  
                                                         
                                                     
                                                    
                                                        gcp 
                                                        
                                                            details: fileName: /etc/systemd/system/kubelet.service, ownerUser: 0, ownerGroup: 0 kind: node name: shoot--diki-comp--gcp-worker-bex82-z1-5d9b4-8fp7q  
                                                         
                                                     
                                                    
                                                        openstack 
                                                        
                                                            details: fileName: /etc/systemd/system/kubelet.service, ownerUser: 0, ownerGroup: 0 kind: node name: shoot--diki-comp--openstack-worker-dqty2-z1-64f7d-jllmm  
                                                         
                                                     
                                                 
                                             
                                         
                                     
                                    
                                        242407 (Medium) - The Kubernetes kubelet configuration files must have file permissions set to 644 or more restrictive. 
                                        
                                            
                                                File has expected permissions 
                                                
                                                    
                                                        aws 
                                                        
                                                            details: fileName: /etc/systemd/system/kubelet.service, permissions: 600 kind: node name: ip-IP-Address.eu-west-1.compute.internal  
                                                         
                                                     
                                                    
                                                        azure 
                                                        
                                                            details: fileName: /etc/systemd/system/kubelet.service, permissions: 600 kind: node name: shoot--diki-comp--azure-worker-g7p4p-z3-66467-k6q5n  
                                                         
                                                     
                                                    
                                                        gcp 
                                                        
                                                            details: fileName: /etc/systemd/system/kubelet.service, permissions: 600 kind: node name: shoot--diki-comp--gcp-worker-bex82-z1-5d9b4-8fp7q  
                                                         
                                                     
                                                    
                                                        openstack 
                                                        
                                                            details: fileName: /etc/systemd/system/kubelet.service, permissions: 600 kind: node name: shoot--diki-comp--openstack-worker-dqty2-z1-64f7d-jllmm  
                                                         
                                                     
                                                 
                                             
                                         
                                     
                                    
                                        242409 (Medium) - Kubernetes Controller Manager must disable profiling. 
                                        
                                            
                                                Option profiling set to allowed value. 
                                                
                                                    
                                                        aws 
                                                        
                                                            kind: deployment name: kube-controller-manager namespace: shoot--diki-comp--aws  
                                                         
                                                     
                                                    
                                                        azure 
                                                        
                                                            kind: deployment name: kube-controller-manager namespace: shoot--diki-comp--azure  
                                                         
                                                     
                                                    
                                                        gcp 
                                                        
                                                            kind: deployment name: kube-controller-manager namespace: shoot--diki-comp--gcp  
                                                         
                                                     
                                                    
                                                        openstack 
                                                        
                                                            kind: deployment name: kube-controller-manager namespace: shoot--diki-comp--openstack  
                                                         
                                                     
                                                 
                                             
                                         
                                     
                                    
                                        242414 (Medium) - The Kubernetes cluster must use non-privileged host ports for user pods. 
                                        
                                            
                                                Pod does not have container using hostPort < 1024. 
                                                
                                                    
                                                        aws 
                                                        
                                                            cluster: seed kind: pod name: aws-custom-route-controller-6c7db9d6c8-hqpn5 namespace: shoot--diki-comp--aws  
                                                            cluster: seed kind: pod name: blackbox-exporter-7c4f5c968f-4cpfs namespace: shoot--diki-comp--aws  
                                                            cluster: seed kind: pod name: blackbox-exporter-7c4f5c968f-jcd6l namespace: shoot--diki-comp--aws  
                                                            cluster: seed kind: pod name: cert-controller-manager-9b9d9ddd6-65z6d namespace: shoot--diki-comp--aws  
                                                            cluster: seed kind: pod name: cloud-controller-manager-6777588465-j47t6 namespace: shoot--diki-comp--aws  
                                                            cluster: seed kind: pod name: csi-driver-controller-85d7b45468-76ckf namespace: shoot--diki-comp--aws  
                                                            cluster: seed kind: pod name: csi-snapshot-controller-75c6cb47dd-4spkm namespace: shoot--diki-comp--aws  
                                                            cluster: seed kind: pod name: etcd-events-0 namespace: shoot--diki-comp--aws  
                                                            cluster: seed kind: pod name: etcd-main-0 namespace: shoot--diki-comp--aws  
                                                            cluster: seed kind: pod name: event-logger-869cc5447-tdzmt namespace: shoot--diki-comp--aws  
                                                            cluster: seed kind: pod name: extension-shoot-lakom-service-547f76b5cf-bfm9d namespace: shoot--diki-comp--aws  
                                                            cluster: seed kind: pod name: extension-shoot-lakom-service-547f76b5cf-m79s6 namespace: shoot--diki-comp--aws  
                                                            cluster: seed kind: pod name: gardener-resource-manager-7b846bcdd7-hrvs9 namespace: shoot--diki-comp--aws  
                                                            cluster: seed kind: pod name: gardener-resource-manager-7b846bcdd7-sld9w namespace: shoot--diki-comp--aws  
                                                            cluster: seed kind: pod name: kube-apiserver-6d847f96d4-82qpt namespace: shoot--diki-comp--aws  
                                                            cluster: seed kind: pod name: kube-apiserver-6d847f96d4-bb8nj namespace: shoot--diki-comp--aws  
                                                            cluster: seed kind: pod name: kube-controller-manager-7c9bc75987-cqgs4 namespace: shoot--diki-comp--aws  
                                                            cluster: seed kind: pod name: kube-scheduler-5854d54c7c-2b7mv namespace: shoot--diki-comp--aws  
                                                            cluster: seed kind: pod name: kube-state-metrics-5cf988645d-xkcbh namespace: shoot--diki-comp--aws  
                                                            cluster: seed kind: pod name: machine-controller-manager-755b6bc74b-kk5tw namespace: shoot--diki-comp--aws  
                                                            cluster: seed kind: pod name: network-problem-detector-controller-645dbbb7b-k6lwf namespace: shoot--diki-comp--aws  
                                                            cluster: seed kind: pod name: plutono-6ff99f98c5-cfsxm namespace: shoot--diki-comp--aws  
                                                            cluster: seed kind: pod name: prometheus-shoot-0 namespace: shoot--diki-comp--aws  
                                                            cluster: seed kind: pod name: shoot-dns-service-7dd6475bdb-cnrj7 namespace: shoot--diki-comp--aws  
                                                            cluster: seed kind: pod name: vali-0 namespace: shoot--diki-comp--aws  
                                                            cluster: seed kind: pod name: vpa-admission-controller-896db4f49-7pnjh namespace: shoot--diki-comp--aws  
                                                            cluster: seed kind: pod name: vpa-admission-controller-896db4f49-nvbtc namespace: shoot--diki-comp--aws  
                                                            cluster: seed kind: pod name: vpa-recommender-57f6f96445-6949p namespace: shoot--diki-comp--aws  
                                                            cluster: seed kind: pod name: vpa-updater-f489b559f-mrbpw namespace: shoot--diki-comp--aws  
                                                            cluster: seed kind: pod name: vpn-seed-server-5cc798467c-szg2w namespace: shoot--diki-comp--aws  
                                                            cluster: shoot kind: pod name: apiserver-proxy-4dqc8 namespace: kube-system  
                                                            cluster: shoot kind: pod name: apiserver-proxy-qmw5c namespace: kube-system  
                                                            cluster: shoot kind: pod name: blackbox-exporter-54d6476f57-9r7pm namespace: kube-system  
                                                            cluster: shoot kind: pod name: blackbox-exporter-54d6476f57-s87tl namespace: kube-system  
                                                            cluster: shoot kind: pod name: calico-node-ftrmj namespace: kube-system  
                                                            cluster: shoot kind: pod name: calico-node-vertical-autoscaler-75c94f77bb-d8kc9 namespace: kube-system  
                                                            cluster: shoot kind: pod name: calico-node-znq6v namespace: kube-system  
                                                            cluster: shoot kind: pod name: calico-typha-deploy-6c94dc645b-hmjtm namespace: kube-system  
                                                            cluster: shoot kind: pod name: calico-typha-deploy-6c94dc645b-pmv7f namespace: kube-system  
                                                            cluster: shoot kind: pod name: calico-typha-horizontal-autoscaler-745ff89c8f-55hfh namespace: kube-system  
                                                            cluster: shoot kind: pod name: calico-typha-vertical-autoscaler-59b9756658-jfws7 namespace: kube-system  
                                                            cluster: shoot kind: pod name: coredns-7dc94444b8-9vvfv namespace: kube-system  
                                                            cluster: shoot kind: pod name: coredns-7dc94444b8-zg7b7 namespace: kube-system  
                                                            cluster: shoot kind: pod name: csi-driver-node-jcrqk namespace: kube-system  
                                                            cluster: shoot kind: pod name: csi-driver-node-r2wkr namespace: kube-system  
                                                            cluster: shoot kind: pod name: egress-filter-applier-5t7l2 namespace: kube-system  
                                                            cluster: shoot kind: pod name: egress-filter-applier-z2bgp namespace: kube-system  
                                                            cluster: shoot kind: pod name: kube-proxy-worker-kkfk1-v1.31.8-8bvtn namespace: kube-system  
                                                            cluster: shoot kind: pod name: kube-proxy-worker-kkfk1-v1.31.8-fdssd namespace: kube-system  
                                                            cluster: shoot kind: pod name: metrics-server-6bf765d77d-djkfx namespace: kube-system  
                                                            cluster: shoot kind: pod name: metrics-server-6bf765d77d-fsgdq namespace: kube-system  
                                                            cluster: shoot kind: pod name: network-problem-detector-host-2cvlq namespace: kube-system  
                                                            cluster: shoot kind: pod name: network-problem-detector-host-7xff6 namespace: kube-system  
                                                            cluster: shoot kind: pod name: network-problem-detector-pod-9t5fl namespace: kube-system  
                                                            cluster: shoot kind: pod name: network-problem-detector-pod-v89js namespace: kube-system  
                                                            cluster: shoot kind: pod name: node-exporter-45s48 namespace: kube-system  
                                                            cluster: shoot kind: pod name: node-exporter-fb7c7 namespace: kube-system  
                                                            cluster: shoot kind: pod name: node-problem-detector-gtfpl namespace: kube-system  
                                                            cluster: shoot kind: pod name: node-problem-detector-kpczj namespace: kube-system  
                                                            cluster: shoot kind: pod name: vpn-shoot-b79bb6f9-7vnr4 namespace: kube-system  
                                                         
                                                     
                                                    
                                                        azure 
                                                        
                                                            cluster: seed kind: pod name: blackbox-exporter-8547775d9-n22dh namespace: shoot--diki-comp--azure  
                                                            cluster: seed kind: pod name: blackbox-exporter-8547775d9-qrm6v namespace: shoot--diki-comp--azure  
                                                            cluster: seed kind: pod name: cert-controller-manager-65bf58bc55-wk5xc namespace: shoot--diki-comp--azure  
                                                            cluster: seed kind: pod name: cloud-controller-manager-6c69fb65f5-kp7m8 namespace: shoot--diki-comp--azure  
                                                            cluster: seed kind: pod name: csi-driver-controller-disk-97dc65bcb-xxzss namespace: shoot--diki-comp--azure  
                                                            cluster: seed kind: pod name: csi-driver-controller-file-6568c4895c-5rvjp namespace: shoot--diki-comp--azure  
                                                            cluster: seed kind: pod name: csi-snapshot-controller-57f9c4f647-hnrlc namespace: shoot--diki-comp--azure  
                                                            cluster: seed kind: pod name: etcd-events-0 namespace: shoot--diki-comp--azure  
                                                            cluster: seed kind: pod name: etcd-main-0 namespace: shoot--diki-comp--azure  
                                                            cluster: seed kind: pod name: event-logger-69fb646bc6-7skhd namespace: shoot--diki-comp--azure  
                                                            cluster: seed kind: pod name: extension-shoot-lakom-service-545fb5d9c-nngpv namespace: shoot--diki-comp--azure  
                                                            cluster: seed kind: pod name: extension-shoot-lakom-service-545fb5d9c-znf28 namespace: shoot--diki-comp--azure  
                                                            cluster: seed kind: pod name: gardener-resource-manager-8cc67bf67-sjtbd namespace: shoot--diki-comp--azure  
                                                            cluster: seed kind: pod name: gardener-resource-manager-8cc67bf67-ss947 namespace: shoot--diki-comp--azure  
                                                            cluster: seed kind: pod name: kube-apiserver-d66f4d44f-sdt88 namespace: shoot--diki-comp--azure  
                                                            cluster: seed kind: pod name: kube-apiserver-d66f4d44f-tm4cs namespace: shoot--diki-comp--azure  
                                                            cluster: seed kind: pod name: kube-controller-manager-7d869c84b8-kz7dm namespace: shoot--diki-comp--azure  
                                                            cluster: seed kind: pod name: kube-scheduler-67fdbc4569-h6j7v namespace: shoot--diki-comp--azure  
                                                            cluster: seed kind: pod name: kube-state-metrics-75858b45d5-nmbtl namespace: shoot--diki-comp--azure  
                                                            cluster: seed kind: pod name: machine-controller-manager-744cfd9b8b-nzwv7 namespace: shoot--diki-comp--azure  
                                                            cluster: seed kind: pod name: network-problem-detector-controller-787fdc7897-z7v7j namespace: shoot--diki-comp--azure  
                                                            cluster: seed kind: pod name: plutono-7b9d579b8-6k8lh namespace: shoot--diki-comp--azure  
                                                            cluster: seed kind: pod name: prometheus-shoot-0 namespace: shoot--diki-comp--azure  
                                                            cluster: seed kind: pod name: remedy-controller-azure-58f9c9758c-jg854 namespace: shoot--diki-comp--azure  
                                                            cluster: seed kind: pod name: shoot-dns-service-794d698b6b-t2xrc namespace: shoot--diki-comp--azure  
                                                            cluster: seed kind: pod name: vali-0 namespace: shoot--diki-comp--azure  
                                                            cluster: seed kind: pod name: vpa-admission-controller-5ff6f989b-7rrsg namespace: shoot--diki-comp--azure  
                                                            cluster: seed kind: pod name: vpa-admission-controller-5ff6f989b-g662j namespace: shoot--diki-comp--azure  
                                                            cluster: seed kind: pod name: vpa-recommender-5fdbffd4f8-jnj9d namespace: shoot--diki-comp--azure  
                                                            cluster: seed kind: pod name: vpa-updater-78cd7c7dfb-n9rth namespace: shoot--diki-comp--azure  
                                                            cluster: seed kind: pod name: vpn-seed-server-9f4b575f5-hjwb6 namespace: shoot--diki-comp--azure  
                                                            cluster: shoot kind: pod name: apiserver-proxy-8r626 namespace: kube-system  
                                                            cluster: shoot kind: pod name: apiserver-proxy-l8lgd namespace: kube-system  
                                                            cluster: shoot kind: pod name: blackbox-exporter-54d6476f57-bsw76 namespace: kube-system  
                                                            cluster: shoot kind: pod name: blackbox-exporter-54d6476f57-c7wc2 namespace: kube-system  
                                                            cluster: shoot kind: pod name: calico-node-6j4zv namespace: kube-system  
                                                            cluster: shoot kind: pod name: calico-node-cbmrk namespace: kube-system  
                                                            cluster: shoot kind: pod name: calico-node-vertical-autoscaler-75c94f77bb-44czk namespace: kube-system  
                                                            cluster: shoot kind: pod name: calico-typha-deploy-6c94dc645b-cn7v8 namespace: kube-system  
                                                            cluster: shoot kind: pod name: calico-typha-deploy-6c94dc645b-vgg9l namespace: kube-system  
                                                            cluster: shoot kind: pod name: calico-typha-horizontal-autoscaler-745ff89c8f-2rpxc namespace: kube-system  
                                                            cluster: shoot kind: pod name: calico-typha-vertical-autoscaler-59b9756658-p8mzz namespace: kube-system  
                                                            cluster: shoot kind: pod name: cloud-node-manager-p7tm2 namespace: kube-system  
                                                            cluster: shoot kind: pod name: cloud-node-manager-ps8pw namespace: kube-system  
                                                            cluster: shoot kind: pod name: coredns-556cd47d78-g9h8v namespace: kube-system  
                                                            cluster: shoot kind: pod name: coredns-556cd47d78-ql2rp namespace: kube-system  
                                                            cluster: shoot kind: pod name: csi-driver-node-disk-ch2pm namespace: kube-system  
                                                            cluster: shoot kind: pod name: csi-driver-node-disk-jfxtn namespace: kube-system  
                                                            cluster: shoot kind: pod name: csi-driver-node-file-6dn4x namespace: kube-system  
                                                            cluster: shoot kind: pod name: csi-driver-node-file-kjgcg namespace: kube-system  
                                                            cluster: shoot kind: pod name: egress-filter-applier-2bmgq namespace: kube-system  
                                                            cluster: shoot kind: pod name: egress-filter-applier-tssl5 namespace: kube-system  
                                                            cluster: shoot kind: pod name: kube-proxy-worker-g7p4p-v1.31.8-7dnc5 namespace: kube-system  
                                                            cluster: shoot kind: pod name: kube-proxy-worker-g7p4p-v1.31.8-th5l5 namespace: kube-system  
                                                            cluster: shoot kind: pod name: metrics-server-d94c5968-fbmdw namespace: kube-system  
                                                            cluster: shoot kind: pod name: metrics-server-d94c5968-m2x7r namespace: kube-system  
                                                            cluster: shoot kind: pod name: network-problem-detector-host-cprp9 namespace: kube-system  
                                                            cluster: shoot kind: pod name: network-problem-detector-host-xvzkb namespace: kube-system  
                                                            cluster: shoot kind: pod name: network-problem-detector-pod-ck849 namespace: kube-system  
                                                            cluster: shoot kind: pod name: network-problem-detector-pod-jgf7j namespace: kube-system  
                                                            cluster: shoot kind: pod name: node-exporter-8nn24 namespace: kube-system  
                                                            cluster: shoot kind: pod name: node-exporter-lzf7z namespace: kube-system  
                                                            cluster: shoot kind: pod name: node-problem-detector-ddmx4 namespace: kube-system  
                                                            cluster: shoot kind: pod name: node-problem-detector-qxs5g namespace: kube-system  
                                                            cluster: shoot kind: pod name: vpn-shoot-84954fb6df-sqkt9 namespace: kube-system  
                                                         
                                                     
                                                    
                                                        gcp 
                                                        
                                                            cluster: seed kind: pod name: blackbox-exporter-7c9f64946b-858zc namespace: shoot--diki-comp--gcp  
                                                            cluster: seed kind: pod name: blackbox-exporter-7c9f64946b-frzzn namespace: shoot--diki-comp--gcp  
                                                            cluster: seed kind: pod name: cert-controller-manager-58c4dd69b-22cv5 namespace: shoot--diki-comp--gcp  
                                                            cluster: seed kind: pod name: cloud-controller-manager-6fd7f65f47-tjwc8 namespace: shoot--diki-comp--gcp  
                                                            cluster: seed kind: pod name: csi-driver-controller-86674c874d-sbj8h namespace: shoot--diki-comp--gcp  
                                                            cluster: seed kind: pod name: csi-snapshot-controller-78c4fb7fff-qzjtg namespace: shoot--diki-comp--gcp  
                                                            cluster: seed kind: pod name: etcd-events-0 namespace: shoot--diki-comp--gcp  
                                                            cluster: seed kind: pod name: etcd-main-0 namespace: shoot--diki-comp--gcp  
                                                            cluster: seed kind: pod name: event-logger-5d755c84b-gfrlg namespace: shoot--diki-comp--gcp  
                                                            cluster: seed kind: pod name: extension-shoot-lakom-service-549d957ff4-8d9q2 namespace: shoot--diki-comp--gcp  
                                                            cluster: seed kind: pod name: extension-shoot-lakom-service-549d957ff4-mfkj4 namespace: shoot--diki-comp--gcp  
                                                            cluster: seed kind: pod name: gardener-resource-manager-784c7f9d6-jtq64 namespace: shoot--diki-comp--gcp  
                                                            cluster: seed kind: pod name: gardener-resource-manager-784c7f9d6-n547r namespace: shoot--diki-comp--gcp  
                                                            cluster: seed kind: pod name: kube-apiserver-789b87d9bc-m288k namespace: shoot--diki-comp--gcp  
                                                            cluster: seed kind: pod name: kube-apiserver-789b87d9bc-njgk5 namespace: shoot--diki-comp--gcp  
                                                            cluster: seed kind: pod name: kube-controller-manager-65cdccf875-lhhzw namespace: shoot--diki-comp--gcp  
                                                            cluster: seed kind: pod name: kube-scheduler-7d978d746c-2vbm4 namespace: shoot--diki-comp--gcp  
                                                            cluster: seed kind: pod name: kube-state-metrics-f58599957-qzsv4 namespace: shoot--diki-comp--gcp  
                                                            cluster: seed kind: pod name: machine-controller-manager-5bffb86d4b-9xst4 namespace: shoot--diki-comp--gcp  
                                                            cluster: seed kind: pod name: network-problem-detector-controller-697769fd46-fb5tp namespace: shoot--diki-comp--gcp  
                                                            cluster: seed kind: pod name: plutono-6dbd8c4b8f-glqxk namespace: shoot--diki-comp--gcp  
                                                            cluster: seed kind: pod name: prometheus-shoot-0 namespace: shoot--diki-comp--gcp  
                                                            cluster: seed kind: pod name: shoot-dns-service-5c9fb456b4-dgt5h namespace: shoot--diki-comp--gcp  
                                                            cluster: seed kind: pod name: vali-0 namespace: shoot--diki-comp--gcp  
                                                            cluster: seed kind: pod name: vpa-admission-controller-64d74d58bc-4gwbg namespace: shoot--diki-comp--gcp  
                                                            cluster: seed kind: pod name: vpa-admission-controller-64d74d58bc-kgdms namespace: shoot--diki-comp--gcp  
                                                            cluster: seed kind: pod name: vpa-recommender-868d4768f5-gtmrq namespace: shoot--diki-comp--gcp  
                                                            cluster: seed kind: pod name: vpa-updater-6d54b866dc-zmztr namespace: shoot--diki-comp--gcp  
                                                            cluster: seed kind: pod name: vpn-seed-server-5885f686b9-tdz5n namespace: shoot--diki-comp--gcp  
                                                            cluster: shoot kind: pod name: apiserver-proxy-dxk6r namespace: kube-system  
                                                            cluster: shoot kind: pod name: apiserver-proxy-wdccl namespace: kube-system  
                                                            cluster: shoot kind: pod name: blackbox-exporter-54d6476f57-8wfq2 namespace: kube-system  
                                                            cluster: shoot kind: pod name: blackbox-exporter-54d6476f57-vvg7r namespace: kube-system  
                                                            cluster: shoot kind: pod name: calico-node-pbp5x namespace: kube-system  
                                                            cluster: shoot kind: pod name: calico-node-vertical-autoscaler-75c94f77bb-7sxbj namespace: kube-system  
                                                            cluster: shoot kind: pod name: calico-node-xjxgs namespace: kube-system  
                                                            cluster: shoot kind: pod name: calico-typha-deploy-6c94dc645b-hxc9n namespace: kube-system  
                                                            cluster: shoot kind: pod name: calico-typha-deploy-6c94dc645b-jx2gb namespace: kube-system  
                                                            cluster: shoot kind: pod name: calico-typha-horizontal-autoscaler-745ff89c8f-wfsgm namespace: kube-system  
                                                            cluster: shoot kind: pod name: calico-typha-vertical-autoscaler-59b9756658-zn42c namespace: kube-system  
                                                            cluster: shoot kind: pod name: coredns-f68b78c49-8xjpl namespace: kube-system  
                                                            cluster: shoot kind: pod name: coredns-f68b78c49-zkfxf namespace: kube-system  
                                                            cluster: shoot kind: pod name: csi-driver-node-4mx2n namespace: kube-system  
                                                            cluster: shoot kind: pod name: csi-driver-node-j8pfg namespace: kube-system  
                                                            cluster: shoot kind: pod name: egress-filter-applier-b9b5x namespace: kube-system  
                                                            cluster: shoot kind: pod name: egress-filter-applier-pkr9q namespace: kube-system  
                                                            cluster: shoot kind: pod name: kube-proxy-worker-bex82-v1.31.8-krn64 namespace: kube-system  
                                                            cluster: shoot kind: pod name: kube-proxy-worker-bex82-v1.31.8-x9kg4 namespace: kube-system  
                                                            cluster: shoot kind: pod name: metrics-server-5df6676dbf-kbm29 namespace: kube-system  
                                                            cluster: shoot kind: pod name: metrics-server-5df6676dbf-tkhb2 namespace: kube-system  
                                                            cluster: shoot kind: pod name: network-problem-detector-host-8ltzf namespace: kube-system  
                                                            cluster: shoot kind: pod name: network-problem-detector-host-hd4cf namespace: kube-system  
                                                            cluster: shoot kind: pod name: network-problem-detector-pod-gz2ph namespace: kube-system  
                                                            cluster: shoot kind: pod name: network-problem-detector-pod-q8tj6 namespace: kube-system  
                                                            cluster: shoot kind: pod name: node-exporter-5jtvr namespace: kube-system  
                                                            cluster: shoot kind: pod name: node-exporter-s5t8x namespace: kube-system  
                                                            cluster: shoot kind: pod name: node-problem-detector-2jzhw namespace: kube-system  
                                                            cluster: shoot kind: pod name: node-problem-detector-5qmlk namespace: kube-system  
                                                            cluster: shoot kind: pod name: vpn-shoot-5b6c54bdc9-dh49n namespace: kube-system  
                                                         
                                                     
                                                    
                                                        openstack 
                                                        
                                                            cluster: seed kind: pod name: blackbox-exporter-84c755d78c-nldvh namespace: shoot--diki-comp--openstack  
                                                            cluster: seed kind: pod name: blackbox-exporter-84c755d78c-vggh4 namespace: shoot--diki-comp--openstack  
                                                            cluster: seed kind: pod name: cert-controller-manager-5b89798597-x6s57 namespace: shoot--diki-comp--openstack  
                                                            cluster: seed kind: pod name: cloud-controller-manager-6f6d9778c4-bwkhl namespace: shoot--diki-comp--openstack  
                                                            cluster: seed kind: pod name: csi-driver-controller-54f9569bb4-k5hpc namespace: shoot--diki-comp--openstack  
                                                            cluster: seed kind: pod name: csi-snapshot-controller-66759ffb58-966h2 namespace: shoot--diki-comp--openstack  
                                                            cluster: seed kind: pod name: etcd-events-0 namespace: shoot--diki-comp--openstack  
                                                            cluster: seed kind: pod name: etcd-main-0 namespace: shoot--diki-comp--openstack  
                                                            cluster: seed kind: pod name: event-logger-74476766b9-2zk56 namespace: shoot--diki-comp--openstack  
                                                            cluster: seed kind: pod name: extension-shoot-lakom-service-5f65bd7cfb-2xvtj namespace: shoot--diki-comp--openstack  
                                                            cluster: seed kind: pod name: extension-shoot-lakom-service-5f65bd7cfb-m9wxz namespace: shoot--diki-comp--openstack  
                                                            cluster: seed kind: pod name: gardener-resource-manager-5659d9595c-8p2rn namespace: shoot--diki-comp--openstack  
                                                            cluster: seed kind: pod name: gardener-resource-manager-5659d9595c-dt6vh namespace: shoot--diki-comp--openstack  
                                                            cluster: seed kind: pod name: kube-apiserver-5ffd79587b-574wj namespace: shoot--diki-comp--openstack  
                                                            cluster: seed kind: pod name: kube-apiserver-5ffd79587b-pnscp namespace: shoot--diki-comp--openstack  
                                                            cluster: seed kind: pod name: kube-controller-manager-76f68f67cf-z8lm4 namespace: shoot--diki-comp--openstack  
                                                            cluster: seed kind: pod name: kube-scheduler-785644b95f-fzldg namespace: shoot--diki-comp--openstack  
                                                            cluster: seed kind: pod name: kube-state-metrics-5568d5676-xl69n namespace: shoot--diki-comp--openstack  
                                                            cluster: seed kind: pod name: machine-controller-manager-7b6ff66dd9-t5289 namespace: shoot--diki-comp--openstack  
                                                            cluster: seed kind: pod name: network-problem-detector-controller-5b7cddb9cf-2bqbs namespace: shoot--diki-comp--openstack  
                                                            cluster: seed kind: pod name: plutono-76d8d5c9c9-5x6sj namespace: shoot--diki-comp--openstack  
                                                            cluster: seed kind: pod name: prometheus-shoot-0 namespace: shoot--diki-comp--openstack  
                                                            cluster: seed kind: pod name: shoot-dns-service-5cf487c477-vhl8t namespace: shoot--diki-comp--openstack  
                                                            cluster: seed kind: pod name: vali-0 namespace: shoot--diki-comp--openstack  
                                                            cluster: seed kind: pod name: vpa-admission-controller-5764cd858f-pl4rr namespace: shoot--diki-comp--openstack  
                                                            cluster: seed kind: pod name: vpa-admission-controller-5764cd858f-wfptd namespace: shoot--diki-comp--openstack  
                                                            cluster: seed kind: pod name: vpa-recommender-798985c98b-t95x5 namespace: shoot--diki-comp--openstack  
                                                            cluster: seed kind: pod name: vpa-updater-766d88bd9b-zz89l namespace: shoot--diki-comp--openstack  
                                                            cluster: seed kind: pod name: vpn-seed-server-5666f97d54-ghztk namespace: shoot--diki-comp--openstack  
                                                            cluster: shoot kind: pod name: apiserver-proxy-mjfl5 namespace: kube-system  
                                                            cluster: shoot kind: pod name: apiserver-proxy-zp6mh namespace: kube-system  
                                                            cluster: shoot kind: pod name: blackbox-exporter-54d6476f57-4jfn4 namespace: kube-system  
                                                            cluster: shoot kind: pod name: blackbox-exporter-54d6476f57-vprcp namespace: kube-system  
                                                            cluster: shoot kind: pod name: calico-kube-controllers-5f4cb8d889-mcgpq namespace: kube-system  
                                                            cluster: shoot kind: pod name: calico-node-rsrv5 namespace: kube-system  
                                                            cluster: shoot kind: pod name: calico-node-vertical-autoscaler-75c94f77bb-zjc72 namespace: kube-system  
                                                            cluster: shoot kind: pod name: calico-node-wdnsn namespace: kube-system  
                                                            cluster: shoot kind: pod name: calico-typha-deploy-6c94dc645b-fzc8v namespace: kube-system  
                                                            cluster: shoot kind: pod name: calico-typha-deploy-6c94dc645b-jvpdv namespace: kube-system  
                                                            cluster: shoot kind: pod name: calico-typha-horizontal-autoscaler-745ff89c8f-jwh2r namespace: kube-system  
                                                            cluster: shoot kind: pod name: calico-typha-vertical-autoscaler-59b9756658-qx9sd namespace: kube-system  
                                                            cluster: shoot kind: pod name: coredns-5464fd5895-gzjzz namespace: kube-system  
                                                            cluster: shoot kind: pod name: coredns-5464fd5895-mgtdc namespace: kube-system  
                                                            cluster: shoot kind: pod name: csi-driver-node-46dm2 namespace: kube-system  
                                                            cluster: shoot kind: pod name: csi-driver-node-pwcl7 namespace: kube-system  
                                                            cluster: shoot kind: pod name: egress-filter-applier-b5z8f namespace: kube-system  
                                                            cluster: shoot kind: pod name: egress-filter-applier-b6786 namespace: kube-system  
                                                            cluster: shoot kind: pod name: kube-proxy-worker-dqty2-v1.31.8-9sx78 namespace: kube-system  
                                                            cluster: shoot kind: pod name: kube-proxy-worker-dqty2-v1.31.8-fwp8d namespace: kube-system  
                                                            cluster: shoot kind: pod name: metrics-server-7c7946c76-gsxtg namespace: kube-system  
                                                            cluster: shoot kind: pod name: metrics-server-7c7946c76-szr7s namespace: kube-system  
                                                            cluster: shoot kind: pod name: network-problem-detector-host-75kzx namespace: kube-system  
                                                            cluster: shoot kind: pod name: network-problem-detector-host-xhqzr namespace: kube-system  
                                                            cluster: shoot kind: pod name: network-problem-detector-pod-7kj5v namespace: kube-system  
                                                            cluster: shoot kind: pod name: network-problem-detector-pod-bb6zl namespace: kube-system  
                                                            cluster: shoot kind: pod name: node-exporter-4cp5g namespace: kube-system  
                                                            cluster: shoot kind: pod name: node-exporter-rshd2 namespace: kube-system  
                                                            cluster: shoot kind: pod name: node-problem-detector-2dxfn namespace: kube-system  
                                                            cluster: shoot kind: pod name: node-problem-detector-5mv98 namespace: kube-system  
                                                            cluster: shoot kind: pod name: vpn-shoot-54dfc94bd-jlgl9 namespace: kube-system  
                                                         
                                                     
                                                 
                                             
                                         
                                     
                                    
                                        242415 (High) - Secrets in Kubernetes must not be stored as environment variables. 
                                        
                                            
                                                Pod does not use environment to inject secret. 
                                                
                                                    
                                                        aws 
                                                        
                                                            cluster: seed kind: pod name: aws-custom-route-controller-6c7db9d6c8-hqpn5 namespace: shoot--diki-comp--aws  
                                                            cluster: seed kind: pod name: blackbox-exporter-7c4f5c968f-4cpfs namespace: shoot--diki-comp--aws  
                                                            cluster: seed kind: pod name: blackbox-exporter-7c4f5c968f-jcd6l namespace: shoot--diki-comp--aws  
                                                            cluster: seed kind: pod name: cert-controller-manager-9b9d9ddd6-65z6d namespace: shoot--diki-comp--aws  
                                                            cluster: seed kind: pod name: cloud-controller-manager-6777588465-j47t6 namespace: shoot--diki-comp--aws  
                                                            cluster: seed kind: pod name: csi-driver-controller-85d7b45468-76ckf namespace: shoot--diki-comp--aws  
                                                            cluster: seed kind: pod name: csi-snapshot-controller-75c6cb47dd-4spkm namespace: shoot--diki-comp--aws  
                                                            cluster: seed kind: pod name: etcd-events-0 namespace: shoot--diki-comp--aws  
                                                            cluster: seed kind: pod name: etcd-main-0 namespace: shoot--diki-comp--aws  
                                                            cluster: seed kind: pod name: event-logger-869cc5447-tdzmt namespace: shoot--diki-comp--aws  
                                                            cluster: seed kind: pod name: extension-shoot-lakom-service-547f76b5cf-bfm9d namespace: shoot--diki-comp--aws  
                                                            cluster: seed kind: pod name: extension-shoot-lakom-service-547f76b5cf-m79s6 namespace: shoot--diki-comp--aws  
                                                            cluster: seed kind: pod name: gardener-resource-manager-7b846bcdd7-hrvs9 namespace: shoot--diki-comp--aws  
                                                            cluster: seed kind: pod name: gardener-resource-manager-7b846bcdd7-sld9w namespace: shoot--diki-comp--aws  
                                                            cluster: seed kind: pod name: kube-apiserver-6d847f96d4-82qpt namespace: shoot--diki-comp--aws  
                                                            cluster: seed kind: pod name: kube-apiserver-6d847f96d4-bb8nj namespace: shoot--diki-comp--aws  
                                                            cluster: seed kind: pod name: kube-controller-manager-7c9bc75987-cqgs4 namespace: shoot--diki-comp--aws  
                                                            cluster: seed kind: pod name: kube-scheduler-5854d54c7c-2b7mv namespace: shoot--diki-comp--aws  
                                                            cluster: seed kind: pod name: kube-state-metrics-5cf988645d-xkcbh namespace: shoot--diki-comp--aws  
                                                            cluster: seed kind: pod name: machine-controller-manager-755b6bc74b-kk5tw namespace: shoot--diki-comp--aws  
                                                            cluster: seed kind: pod name: network-problem-detector-controller-645dbbb7b-k6lwf namespace: shoot--diki-comp--aws  
                                                            cluster: seed kind: pod name: plutono-6ff99f98c5-cfsxm namespace: shoot--diki-comp--aws  
                                                            cluster: seed kind: pod name: prometheus-shoot-0 namespace: shoot--diki-comp--aws  
                                                            cluster: seed kind: pod name: shoot-dns-service-7dd6475bdb-cnrj7 namespace: shoot--diki-comp--aws  
                                                            cluster: seed kind: pod name: vali-0 namespace: shoot--diki-comp--aws  
                                                            cluster: seed kind: pod name: vpa-admission-controller-896db4f49-7pnjh namespace: shoot--diki-comp--aws  
                                                            cluster: seed kind: pod name: vpa-admission-controller-896db4f49-nvbtc namespace: shoot--diki-comp--aws  
                                                            cluster: seed kind: pod name: vpa-recommender-57f6f96445-6949p namespace: shoot--diki-comp--aws  
                                                            cluster: seed kind: pod name: vpa-updater-f489b559f-mrbpw namespace: shoot--diki-comp--aws  
                                                            cluster: seed kind: pod name: vpn-seed-server-5cc798467c-szg2w namespace: shoot--diki-comp--aws  
                                                            cluster: shoot kind: pod name: apiserver-proxy-4dqc8 namespace: kube-system  
                                                            cluster: shoot kind: pod name: apiserver-proxy-qmw5c namespace: kube-system  
                                                            cluster: shoot kind: pod name: blackbox-exporter-54d6476f57-9r7pm namespace: kube-system  
                                                            cluster: shoot kind: pod name: blackbox-exporter-54d6476f57-s87tl namespace: kube-system  
                                                            cluster: shoot kind: pod name: calico-node-ftrmj namespace: kube-system  
                                                            cluster: shoot kind: pod name: calico-node-vertical-autoscaler-75c94f77bb-d8kc9 namespace: kube-system  
                                                            cluster: shoot kind: pod name: calico-node-znq6v namespace: kube-system  
                                                            cluster: shoot kind: pod name: calico-typha-deploy-6c94dc645b-hmjtm namespace: kube-system  
                                                            cluster: shoot kind: pod name: calico-typha-deploy-6c94dc645b-pmv7f namespace: kube-system  
                                                            cluster: shoot kind: pod name: calico-typha-horizontal-autoscaler-745ff89c8f-55hfh namespace: kube-system  
                                                            cluster: shoot kind: pod name: calico-typha-vertical-autoscaler-59b9756658-jfws7 namespace: kube-system  
                                                            cluster: shoot kind: pod name: coredns-7dc94444b8-9vvfv namespace: kube-system  
                                                            cluster: shoot kind: pod name: coredns-7dc94444b8-zg7b7 namespace: kube-system  
                                                            cluster: shoot kind: pod name: csi-driver-node-jcrqk namespace: kube-system  
                                                            cluster: shoot kind: pod name: csi-driver-node-r2wkr namespace: kube-system  
                                                            cluster: shoot kind: pod name: egress-filter-applier-5t7l2 namespace: kube-system  
                                                            cluster: shoot kind: pod name: egress-filter-applier-z2bgp namespace: kube-system  
                                                            cluster: shoot kind: pod name: kube-proxy-worker-kkfk1-v1.31.8-8bvtn namespace: kube-system  
                                                            cluster: shoot kind: pod name: kube-proxy-worker-kkfk1-v1.31.8-fdssd namespace: kube-system  
                                                            cluster: shoot kind: pod name: metrics-server-6bf765d77d-djkfx namespace: kube-system  
                                                            cluster: shoot kind: pod name: metrics-server-6bf765d77d-fsgdq namespace: kube-system  
                                                            cluster: shoot kind: pod name: network-problem-detector-host-2cvlq namespace: kube-system  
                                                            cluster: shoot kind: pod name: network-problem-detector-host-7xff6 namespace: kube-system  
                                                            cluster: shoot kind: pod name: network-problem-detector-pod-9t5fl namespace: kube-system  
                                                            cluster: shoot kind: pod name: network-problem-detector-pod-v89js namespace: kube-system  
                                                            cluster: shoot kind: pod name: node-exporter-45s48 namespace: kube-system  
                                                            cluster: shoot kind: pod name: node-exporter-fb7c7 namespace: kube-system  
                                                            cluster: shoot kind: pod name: node-local-dns-mnx5f namespace: kube-system  
                                                            cluster: shoot kind: pod name: node-local-dns-pjrjg namespace: kube-system  
                                                            cluster: shoot kind: pod name: node-problem-detector-gtfpl namespace: kube-system  
                                                            cluster: shoot kind: pod name: node-problem-detector-kpczj namespace: kube-system  
                                                            cluster: shoot kind: pod name: vpn-shoot-b79bb6f9-7vnr4 namespace: kube-system  
                                                         
                                                     
                                                    
                                                        azure 
                                                        
                                                            cluster: seed kind: pod name: blackbox-exporter-8547775d9-n22dh namespace: shoot--diki-comp--azure  
                                                            cluster: seed kind: pod name: blackbox-exporter-8547775d9-qrm6v namespace: shoot--diki-comp--azure  
                                                            cluster: seed kind: pod name: cert-controller-manager-65bf58bc55-wk5xc namespace: shoot--diki-comp--azure  
                                                            cluster: seed kind: pod name: cloud-controller-manager-6c69fb65f5-kp7m8 namespace: shoot--diki-comp--azure  
                                                            cluster: seed kind: pod name: csi-driver-controller-disk-97dc65bcb-xxzss namespace: shoot--diki-comp--azure  
                                                            cluster: seed kind: pod name: csi-driver-controller-file-6568c4895c-5rvjp namespace: shoot--diki-comp--azure  
                                                            cluster: seed kind: pod name: csi-snapshot-controller-57f9c4f647-hnrlc namespace: shoot--diki-comp--azure  
                                                            cluster: seed kind: pod name: etcd-events-0 namespace: shoot--diki-comp--azure  
                                                            cluster: seed kind: pod name: etcd-main-0 namespace: shoot--diki-comp--azure  
                                                            cluster: seed kind: pod name: event-logger-69fb646bc6-7skhd namespace: shoot--diki-comp--azure  
                                                            cluster: seed kind: pod name: extension-shoot-lakom-service-545fb5d9c-nngpv namespace: shoot--diki-comp--azure  
                                                            cluster: seed kind: pod name: extension-shoot-lakom-service-545fb5d9c-znf28 namespace: shoot--diki-comp--azure  
                                                            cluster: seed kind: pod name: gardener-resource-manager-8cc67bf67-sjtbd namespace: shoot--diki-comp--azure  
                                                            cluster: seed kind: pod name: gardener-resource-manager-8cc67bf67-ss947 namespace: shoot--diki-comp--azure  
                                                            cluster: seed kind: pod name: kube-apiserver-d66f4d44f-sdt88 namespace: shoot--diki-comp--azure  
                                                            cluster: seed kind: pod name: kube-apiserver-d66f4d44f-tm4cs namespace: shoot--diki-comp--azure  
                                                            cluster: seed kind: pod name: kube-controller-manager-7d869c84b8-kz7dm namespace: shoot--diki-comp--azure  
                                                            cluster: seed kind: pod name: kube-scheduler-67fdbc4569-h6j7v namespace: shoot--diki-comp--azure  
                                                            cluster: seed kind: pod name: kube-state-metrics-75858b45d5-nmbtl namespace: shoot--diki-comp--azure  
                                                            cluster: seed kind: pod name: machine-controller-manager-744cfd9b8b-nzwv7 namespace: shoot--diki-comp--azure  
                                                            cluster: seed kind: pod name: network-problem-detector-controller-787fdc7897-z7v7j namespace: shoot--diki-comp--azure  
                                                            cluster: seed kind: pod name: plutono-7b9d579b8-6k8lh namespace: shoot--diki-comp--azure  
                                                            cluster: seed kind: pod name: prometheus-shoot-0 namespace: shoot--diki-comp--azure  
                                                            cluster: seed kind: pod name: remedy-controller-azure-58f9c9758c-jg854 namespace: shoot--diki-comp--azure  
                                                            cluster: seed kind: pod name: shoot-dns-service-794d698b6b-t2xrc namespace: shoot--diki-comp--azure  
                                                            cluster: seed kind: pod name: vali-0 namespace: shoot--diki-comp--azure  
                                                            cluster: seed kind: pod name: vpa-admission-controller-5ff6f989b-7rrsg namespace: shoot--diki-comp--azure  
                                                            cluster: seed kind: pod name: vpa-admission-controller-5ff6f989b-g662j namespace: shoot--diki-comp--azure  
                                                            cluster: seed kind: pod name: vpa-recommender-5fdbffd4f8-jnj9d namespace: shoot--diki-comp--azure  
                                                            cluster: seed kind: pod name: vpa-updater-78cd7c7dfb-n9rth namespace: shoot--diki-comp--azure  
                                                            cluster: seed kind: pod name: vpn-seed-server-9f4b575f5-hjwb6 namespace: shoot--diki-comp--azure  
                                                            cluster: shoot kind: pod name: apiserver-proxy-8r626 namespace: kube-system  
                                                            cluster: shoot kind: pod name: apiserver-proxy-l8lgd namespace: kube-system  
                                                            cluster: shoot kind: pod name: blackbox-exporter-54d6476f57-bsw76 namespace: kube-system  
                                                            cluster: shoot kind: pod name: blackbox-exporter-54d6476f57-c7wc2 namespace: kube-system  
                                                            cluster: shoot kind: pod name: calico-node-6j4zv namespace: kube-system  
                                                            cluster: shoot kind: pod name: calico-node-cbmrk namespace: kube-system  
                                                            cluster: shoot kind: pod name: calico-node-vertical-autoscaler-75c94f77bb-44czk namespace: kube-system  
                                                            cluster: shoot kind: pod name: calico-typha-deploy-6c94dc645b-cn7v8 namespace: kube-system  
                                                            cluster: shoot kind: pod name: calico-typha-deploy-6c94dc645b-vgg9l namespace: kube-system  
                                                            cluster: shoot kind: pod name: calico-typha-horizontal-autoscaler-745ff89c8f-2rpxc namespace: kube-system  
                                                            cluster: shoot kind: pod name: calico-typha-vertical-autoscaler-59b9756658-p8mzz namespace: kube-system  
                                                            cluster: shoot kind: pod name: cloud-node-manager-p7tm2 namespace: kube-system  
                                                            cluster: shoot kind: pod name: cloud-node-manager-ps8pw namespace: kube-system  
                                                            cluster: shoot kind: pod name: coredns-556cd47d78-g9h8v namespace: kube-system  
                                                            cluster: shoot kind: pod name: coredns-556cd47d78-ql2rp namespace: kube-system  
                                                            cluster: shoot kind: pod name: csi-driver-node-disk-ch2pm namespace: kube-system  
                                                            cluster: shoot kind: pod name: csi-driver-node-disk-jfxtn namespace: kube-system  
                                                            cluster: shoot kind: pod name: csi-driver-node-file-6dn4x namespace: kube-system  
                                                            cluster: shoot kind: pod name: csi-driver-node-file-kjgcg namespace: kube-system  
                                                            cluster: shoot kind: pod name: egress-filter-applier-2bmgq namespace: kube-system  
                                                            cluster: shoot kind: pod name: egress-filter-applier-tssl5 namespace: kube-system  
                                                            cluster: shoot kind: pod name: kube-proxy-worker-g7p4p-v1.31.8-7dnc5 namespace: kube-system  
                                                            cluster: shoot kind: pod name: kube-proxy-worker-g7p4p-v1.31.8-th5l5 namespace: kube-system  
                                                            cluster: shoot kind: pod name: metrics-server-d94c5968-fbmdw namespace: kube-system  
                                                            cluster: shoot kind: pod name: metrics-server-d94c5968-m2x7r namespace: kube-system  
                                                            cluster: shoot kind: pod name: network-problem-detector-host-cprp9 namespace: kube-system  
                                                            cluster: shoot kind: pod name: network-problem-detector-host-xvzkb namespace: kube-system  
                                                            cluster: shoot kind: pod name: network-problem-detector-pod-ck849 namespace: kube-system  
                                                            cluster: shoot kind: pod name: network-problem-detector-pod-jgf7j namespace: kube-system  
                                                            cluster: shoot kind: pod name: node-exporter-8nn24 namespace: kube-system  
                                                            cluster: shoot kind: pod name: node-exporter-lzf7z namespace: kube-system  
                                                            cluster: shoot kind: pod name: node-local-dns-d6lgp namespace: kube-system  
                                                            cluster: shoot kind: pod name: node-local-dns-r6zzr namespace: kube-system  
                                                            cluster: shoot kind: pod name: node-problem-detector-ddmx4 namespace: kube-system  
                                                            cluster: shoot kind: pod name: node-problem-detector-qxs5g namespace: kube-system  
                                                            cluster: shoot kind: pod name: vpn-shoot-84954fb6df-sqkt9 namespace: kube-system  
                                                         
                                                     
                                                    
                                                        gcp 
                                                        
                                                            cluster: seed kind: pod name: blackbox-exporter-7c9f64946b-858zc namespace: shoot--diki-comp--gcp  
                                                            cluster: seed kind: pod name: blackbox-exporter-7c9f64946b-frzzn namespace: shoot--diki-comp--gcp  
                                                            cluster: seed kind: pod name: cert-controller-manager-58c4dd69b-22cv5 namespace: shoot--diki-comp--gcp  
                                                            cluster: seed kind: pod name: cloud-controller-manager-6fd7f65f47-tjwc8 namespace: shoot--diki-comp--gcp  
                                                            cluster: seed kind: pod name: csi-driver-controller-86674c874d-sbj8h namespace: shoot--diki-comp--gcp  
                                                            cluster: seed kind: pod name: csi-snapshot-controller-78c4fb7fff-qzjtg namespace: shoot--diki-comp--gcp  
                                                            cluster: seed kind: pod name: etcd-events-0 namespace: shoot--diki-comp--gcp  
                                                            cluster: seed kind: pod name: etcd-main-0 namespace: shoot--diki-comp--gcp  
                                                            cluster: seed kind: pod name: event-logger-5d755c84b-gfrlg namespace: shoot--diki-comp--gcp  
                                                            cluster: seed kind: pod name: extension-shoot-lakom-service-549d957ff4-8d9q2 namespace: shoot--diki-comp--gcp  
                                                            cluster: seed kind: pod name: extension-shoot-lakom-service-549d957ff4-mfkj4 namespace: shoot--diki-comp--gcp  
                                                            cluster: seed kind: pod name: gardener-resource-manager-784c7f9d6-jtq64 namespace: shoot--diki-comp--gcp  
                                                            cluster: seed kind: pod name: gardener-resource-manager-784c7f9d6-n547r namespace: shoot--diki-comp--gcp  
                                                            cluster: seed kind: pod name: kube-apiserver-789b87d9bc-m288k namespace: shoot--diki-comp--gcp  
                                                            cluster: seed kind: pod name: kube-apiserver-789b87d9bc-njgk5 namespace: shoot--diki-comp--gcp  
                                                            cluster: seed kind: pod name: kube-controller-manager-65cdccf875-lhhzw namespace: shoot--diki-comp--gcp  
                                                            cluster: seed kind: pod name: kube-scheduler-7d978d746c-2vbm4 namespace: shoot--diki-comp--gcp  
                                                            cluster: seed kind: pod name: kube-state-metrics-f58599957-qzsv4 namespace: shoot--diki-comp--gcp  
                                                            cluster: seed kind: pod name: machine-controller-manager-5bffb86d4b-9xst4 namespace: shoot--diki-comp--gcp  
                                                            cluster: seed kind: pod name: network-problem-detector-controller-697769fd46-fb5tp namespace: shoot--diki-comp--gcp  
                                                            cluster: seed kind: pod name: plutono-6dbd8c4b8f-glqxk namespace: shoot--diki-comp--gcp  
                                                            cluster: seed kind: pod name: prometheus-shoot-0 namespace: shoot--diki-comp--gcp  
                                                            cluster: seed kind: pod name: shoot-dns-service-5c9fb456b4-dgt5h namespace: shoot--diki-comp--gcp  
                                                            cluster: seed kind: pod name: vali-0 namespace: shoot--diki-comp--gcp  
                                                            cluster: seed kind: pod name: vpa-admission-controller-64d74d58bc-4gwbg namespace: shoot--diki-comp--gcp  
                                                            cluster: seed kind: pod name: vpa-admission-controller-64d74d58bc-kgdms namespace: shoot--diki-comp--gcp  
                                                            cluster: seed kind: pod name: vpa-recommender-868d4768f5-gtmrq namespace: shoot--diki-comp--gcp  
                                                            cluster: seed kind: pod name: vpa-updater-6d54b866dc-zmztr namespace: shoot--diki-comp--gcp  
                                                            cluster: seed kind: pod name: vpn-seed-server-5885f686b9-tdz5n namespace: shoot--diki-comp--gcp  
                                                            cluster: shoot kind: pod name: apiserver-proxy-dxk6r namespace: kube-system  
                                                            cluster: shoot kind: pod name: apiserver-proxy-wdccl namespace: kube-system  
                                                            cluster: shoot kind: pod name: blackbox-exporter-54d6476f57-8wfq2 namespace: kube-system  
                                                            cluster: shoot kind: pod name: blackbox-exporter-54d6476f57-vvg7r namespace: kube-system  
                                                            cluster: shoot kind: pod name: calico-node-pbp5x namespace: kube-system  
                                                            cluster: shoot kind: pod name: calico-node-vertical-autoscaler-75c94f77bb-7sxbj namespace: kube-system  
                                                            cluster: shoot kind: pod name: calico-node-xjxgs namespace: kube-system  
                                                            cluster: shoot kind: pod name: calico-typha-deploy-6c94dc645b-hxc9n namespace: kube-system  
                                                            cluster: shoot kind: pod name: calico-typha-deploy-6c94dc645b-jx2gb namespace: kube-system  
                                                            cluster: shoot kind: pod name: calico-typha-horizontal-autoscaler-745ff89c8f-wfsgm namespace: kube-system  
                                                            cluster: shoot kind: pod name: calico-typha-vertical-autoscaler-59b9756658-zn42c namespace: kube-system  
                                                            cluster: shoot kind: pod name: coredns-f68b78c49-8xjpl namespace: kube-system  
                                                            cluster: shoot kind: pod name: coredns-f68b78c49-zkfxf namespace: kube-system  
                                                            cluster: shoot kind: pod name: csi-driver-node-4mx2n namespace: kube-system  
                                                            cluster: shoot kind: pod name: csi-driver-node-j8pfg namespace: kube-system  
                                                            cluster: shoot kind: pod name: egress-filter-applier-b9b5x namespace: kube-system  
                                                            cluster: shoot kind: pod name: egress-filter-applier-pkr9q namespace: kube-system  
                                                            cluster: shoot kind: pod name: kube-proxy-worker-bex82-v1.31.8-krn64 namespace: kube-system  
                                                            cluster: shoot kind: pod name: kube-proxy-worker-bex82-v1.31.8-x9kg4 namespace: kube-system  
                                                            cluster: shoot kind: pod name: metrics-server-5df6676dbf-kbm29 namespace: kube-system  
                                                            cluster: shoot kind: pod name: metrics-server-5df6676dbf-tkhb2 namespace: kube-system  
                                                            cluster: shoot kind: pod name: network-problem-detector-host-8ltzf namespace: kube-system  
                                                            cluster: shoot kind: pod name: network-problem-detector-host-hd4cf namespace: kube-system  
                                                            cluster: shoot kind: pod name: network-problem-detector-pod-gz2ph namespace: kube-system  
                                                            cluster: shoot kind: pod name: network-problem-detector-pod-q8tj6 namespace: kube-system  
                                                            cluster: shoot kind: pod name: node-exporter-5jtvr namespace: kube-system  
                                                            cluster: shoot kind: pod name: node-exporter-s5t8x namespace: kube-system  
                                                            cluster: shoot kind: pod name: node-local-dns-f29m2 namespace: kube-system  
                                                            cluster: shoot kind: pod name: node-local-dns-srwg9 namespace: kube-system  
                                                            cluster: shoot kind: pod name: node-problem-detector-2jzhw namespace: kube-system  
                                                            cluster: shoot kind: pod name: node-problem-detector-5qmlk namespace: kube-system  
                                                            cluster: shoot kind: pod name: vpn-shoot-5b6c54bdc9-dh49n namespace: kube-system  
                                                         
                                                     
                                                    
                                                        openstack 
                                                        
                                                            cluster: seed kind: pod name: blackbox-exporter-84c755d78c-nldvh namespace: shoot--diki-comp--openstack  
                                                            cluster: seed kind: pod name: blackbox-exporter-84c755d78c-vggh4 namespace: shoot--diki-comp--openstack  
                                                            cluster: seed kind: pod name: cert-controller-manager-5b89798597-x6s57 namespace: shoot--diki-comp--openstack  
                                                            cluster: seed kind: pod name: cloud-controller-manager-6f6d9778c4-bwkhl namespace: shoot--diki-comp--openstack  
                                                            cluster: seed kind: pod name: csi-driver-controller-54f9569bb4-k5hpc namespace: shoot--diki-comp--openstack  
                                                            cluster: seed kind: pod name: csi-snapshot-controller-66759ffb58-966h2 namespace: shoot--diki-comp--openstack  
                                                            cluster: seed kind: pod name: etcd-events-0 namespace: shoot--diki-comp--openstack  
                                                            cluster: seed kind: pod name: etcd-main-0 namespace: shoot--diki-comp--openstack  
                                                            cluster: seed kind: pod name: event-logger-74476766b9-2zk56 namespace: shoot--diki-comp--openstack  
                                                            cluster: seed kind: pod name: extension-shoot-lakom-service-5f65bd7cfb-2xvtj namespace: shoot--diki-comp--openstack  
                                                            cluster: seed kind: pod name: extension-shoot-lakom-service-5f65bd7cfb-m9wxz namespace: shoot--diki-comp--openstack  
                                                            cluster: seed kind: pod name: gardener-resource-manager-5659d9595c-8p2rn namespace: shoot--diki-comp--openstack  
                                                            cluster: seed kind: pod name: gardener-resource-manager-5659d9595c-dt6vh namespace: shoot--diki-comp--openstack  
                                                            cluster: seed kind: pod name: kube-apiserver-5ffd79587b-574wj namespace: shoot--diki-comp--openstack  
                                                            cluster: seed kind: pod name: kube-apiserver-5ffd79587b-pnscp namespace: shoot--diki-comp--openstack  
                                                            cluster: seed kind: pod name: kube-controller-manager-76f68f67cf-z8lm4 namespace: shoot--diki-comp--openstack  
                                                            cluster: seed kind: pod name: kube-scheduler-785644b95f-fzldg namespace: shoot--diki-comp--openstack  
                                                            cluster: seed kind: pod name: kube-state-metrics-5568d5676-xl69n namespace: shoot--diki-comp--openstack  
                                                            cluster: seed kind: pod name: machine-controller-manager-7b6ff66dd9-t5289 namespace: shoot--diki-comp--openstack  
                                                            cluster: seed kind: pod name: network-problem-detector-controller-5b7cddb9cf-2bqbs namespace: shoot--diki-comp--openstack  
                                                            cluster: seed kind: pod name: plutono-76d8d5c9c9-5x6sj namespace: shoot--diki-comp--openstack  
                                                            cluster: seed kind: pod name: prometheus-shoot-0 namespace: shoot--diki-comp--openstack  
                                                            cluster: seed kind: pod name: shoot-dns-service-5cf487c477-vhl8t namespace: shoot--diki-comp--openstack  
                                                            cluster: seed kind: pod name: vali-0 namespace: shoot--diki-comp--openstack  
                                                            cluster: seed kind: pod name: vpa-admission-controller-5764cd858f-pl4rr namespace: shoot--diki-comp--openstack  
                                                            cluster: seed kind: pod name: vpa-admission-controller-5764cd858f-wfptd namespace: shoot--diki-comp--openstack  
                                                            cluster: seed kind: pod name: vpa-recommender-798985c98b-t95x5 namespace: shoot--diki-comp--openstack  
                                                            cluster: seed kind: pod name: vpa-updater-766d88bd9b-zz89l namespace: shoot--diki-comp--openstack  
                                                            cluster: seed kind: pod name: vpn-seed-server-5666f97d54-ghztk namespace: shoot--diki-comp--openstack  
                                                            cluster: shoot kind: pod name: apiserver-proxy-mjfl5 namespace: kube-system  
                                                            cluster: shoot kind: pod name: apiserver-proxy-zp6mh namespace: kube-system  
                                                            cluster: shoot kind: pod name: blackbox-exporter-54d6476f57-4jfn4 namespace: kube-system  
                                                            cluster: shoot kind: pod name: blackbox-exporter-54d6476f57-vprcp namespace: kube-system  
                                                            cluster: shoot kind: pod name: calico-kube-controllers-5f4cb8d889-mcgpq namespace: kube-system  
                                                            cluster: shoot kind: pod name: calico-node-rsrv5 namespace: kube-system  
                                                            cluster: shoot kind: pod name: calico-node-vertical-autoscaler-75c94f77bb-zjc72 namespace: kube-system  
                                                            cluster: shoot kind: pod name: calico-node-wdnsn namespace: kube-system  
                                                            cluster: shoot kind: pod name: calico-typha-deploy-6c94dc645b-fzc8v namespace: kube-system  
                                                            cluster: shoot kind: pod name: calico-typha-deploy-6c94dc645b-jvpdv namespace: kube-system  
                                                            cluster: shoot kind: pod name: calico-typha-horizontal-autoscaler-745ff89c8f-jwh2r namespace: kube-system  
                                                            cluster: shoot kind: pod name: calico-typha-vertical-autoscaler-59b9756658-qx9sd namespace: kube-system  
                                                            cluster: shoot kind: pod name: coredns-5464fd5895-gzjzz namespace: kube-system  
                                                            cluster: shoot kind: pod name: coredns-5464fd5895-mgtdc namespace: kube-system  
                                                            cluster: shoot kind: pod name: csi-driver-node-46dm2 namespace: kube-system  
                                                            cluster: shoot kind: pod name: csi-driver-node-pwcl7 namespace: kube-system  
                                                            cluster: shoot kind: pod name: egress-filter-applier-b5z8f namespace: kube-system  
                                                            cluster: shoot kind: pod name: egress-filter-applier-b6786 namespace: kube-system  
                                                            cluster: shoot kind: pod name: kube-proxy-worker-dqty2-v1.31.8-9sx78 namespace: kube-system  
                                                            cluster: shoot kind: pod name: kube-proxy-worker-dqty2-v1.31.8-fwp8d namespace: kube-system  
                                                            cluster: shoot kind: pod name: metrics-server-7c7946c76-gsxtg namespace: kube-system  
                                                            cluster: shoot kind: pod name: metrics-server-7c7946c76-szr7s namespace: kube-system  
                                                            cluster: shoot kind: pod name: network-problem-detector-host-75kzx namespace: kube-system  
                                                            cluster: shoot kind: pod name: network-problem-detector-host-xhqzr namespace: kube-system  
                                                            cluster: shoot kind: pod name: network-problem-detector-pod-7kj5v namespace: kube-system  
                                                            cluster: shoot kind: pod name: network-problem-detector-pod-bb6zl namespace: kube-system  
                                                            cluster: shoot kind: pod name: node-exporter-4cp5g namespace: kube-system  
                                                            cluster: shoot kind: pod name: node-exporter-rshd2 namespace: kube-system  
                                                            cluster: shoot kind: pod name: node-local-dns-57bpm namespace: kube-system  
                                                            cluster: shoot kind: pod name: node-local-dns-8b6dg namespace: kube-system  
                                                            cluster: shoot kind: pod name: node-problem-detector-2dxfn namespace: kube-system  
                                                            cluster: shoot kind: pod name: node-problem-detector-5mv98 namespace: kube-system  
                                                            cluster: shoot kind: pod name: vpn-shoot-54dfc94bd-jlgl9 namespace: kube-system  
                                                         
                                                     
                                                 
                                             
                                         
                                     
                                    
                                        242417 (Medium) - Kubernetes must separate user functionality. 
                                        
                                            
                                                Gardener managed pods are not user pods 
                                                
                                                    
                                                        aws 
                                                        
                                                            kind: pod name: apiserver-proxy-4dqc8 namespace: kube-system  
                                                            kind: pod name: apiserver-proxy-qmw5c namespace: kube-system  
                                                            kind: pod name: blackbox-exporter-54d6476f57-9r7pm namespace: kube-system  
                                                            kind: pod name: blackbox-exporter-54d6476f57-s87tl namespace: kube-system  
                                                            kind: pod name: calico-node-ftrmj namespace: kube-system  
                                                            kind: pod name: calico-node-vertical-autoscaler-75c94f77bb-d8kc9 namespace: kube-system  
                                                            kind: pod name: calico-node-znq6v namespace: kube-system  
                                                            kind: pod name: calico-typha-deploy-6c94dc645b-hmjtm namespace: kube-system  
                                                            kind: pod name: calico-typha-deploy-6c94dc645b-pmv7f namespace: kube-system  
                                                            kind: pod name: calico-typha-horizontal-autoscaler-745ff89c8f-55hfh namespace: kube-system  
                                                            kind: pod name: calico-typha-vertical-autoscaler-59b9756658-jfws7 namespace: kube-system  
                                                            kind: pod name: coredns-7dc94444b8-9vvfv namespace: kube-system  
                                                            kind: pod name: coredns-7dc94444b8-zg7b7 namespace: kube-system  
                                                            kind: pod name: csi-driver-node-jcrqk namespace: kube-system  
                                                            kind: pod name: csi-driver-node-r2wkr namespace: kube-system  
                                                            kind: pod name: egress-filter-applier-5t7l2 namespace: kube-system  
                                                            kind: pod name: egress-filter-applier-z2bgp namespace: kube-system  
                                                            kind: pod name: kube-proxy-worker-kkfk1-v1.31.8-8bvtn namespace: kube-system  
                                                            kind: pod name: kube-proxy-worker-kkfk1-v1.31.8-fdssd namespace: kube-system  
                                                            kind: pod name: metrics-server-6bf765d77d-djkfx namespace: kube-system  
                                                            kind: pod name: metrics-server-6bf765d77d-fsgdq namespace: kube-system  
                                                            kind: pod name: network-problem-detector-host-2cvlq namespace: kube-system  
                                                            kind: pod name: network-problem-detector-host-7xff6 namespace: kube-system  
                                                            kind: pod name: network-problem-detector-pod-9t5fl namespace: kube-system  
                                                            kind: pod name: network-problem-detector-pod-v89js namespace: kube-system  
                                                            kind: pod name: node-exporter-45s48 namespace: kube-system  
                                                            kind: pod name: node-exporter-fb7c7 namespace: kube-system  
                                                            kind: pod name: node-local-dns-mnx5f namespace: kube-system  
                                                            kind: pod name: node-local-dns-pjrjg namespace: kube-system  
                                                            kind: pod name: node-problem-detector-gtfpl namespace: kube-system  
                                                            kind: pod name: node-problem-detector-kpczj namespace: kube-system  
                                                            kind: pod name: vpn-shoot-b79bb6f9-7vnr4 namespace: kube-system  
                                                         
                                                     
                                                    
                                                        azure 
                                                        
                                                            kind: pod name: apiserver-proxy-8r626 namespace: kube-system  
                                                            kind: pod name: apiserver-proxy-l8lgd namespace: kube-system  
                                                            kind: pod name: blackbox-exporter-54d6476f57-bsw76 namespace: kube-system  
                                                            kind: pod name: blackbox-exporter-54d6476f57-c7wc2 namespace: kube-system  
                                                            kind: pod name: calico-node-6j4zv namespace: kube-system  
                                                            kind: pod name: calico-node-cbmrk namespace: kube-system  
                                                            kind: pod name: calico-node-vertical-autoscaler-75c94f77bb-44czk namespace: kube-system  
                                                            kind: pod name: calico-typha-deploy-6c94dc645b-cn7v8 namespace: kube-system  
                                                            kind: pod name: calico-typha-deploy-6c94dc645b-vgg9l namespace: kube-system  
                                                            kind: pod name: calico-typha-horizontal-autoscaler-745ff89c8f-2rpxc namespace: kube-system  
                                                            kind: pod name: calico-typha-vertical-autoscaler-59b9756658-p8mzz namespace: kube-system  
                                                            kind: pod name: cloud-node-manager-p7tm2 namespace: kube-system  
                                                            kind: pod name: cloud-node-manager-ps8pw namespace: kube-system  
                                                            kind: pod name: coredns-556cd47d78-g9h8v namespace: kube-system  
                                                            kind: pod name: coredns-556cd47d78-ql2rp namespace: kube-system  
                                                            kind: pod name: csi-driver-node-disk-ch2pm namespace: kube-system  
                                                            kind: pod name: csi-driver-node-disk-jfxtn namespace: kube-system  
                                                            kind: pod name: csi-driver-node-file-6dn4x namespace: kube-system  
                                                            kind: pod name: csi-driver-node-file-kjgcg namespace: kube-system  
                                                            kind: pod name: egress-filter-applier-2bmgq namespace: kube-system  
                                                            kind: pod name: egress-filter-applier-tssl5 namespace: kube-system  
                                                            kind: pod name: kube-proxy-worker-g7p4p-v1.31.8-7dnc5 namespace: kube-system  
                                                            kind: pod name: kube-proxy-worker-g7p4p-v1.31.8-th5l5 namespace: kube-system  
                                                            kind: pod name: metrics-server-d94c5968-fbmdw namespace: kube-system  
                                                            kind: pod name: metrics-server-d94c5968-m2x7r namespace: kube-system  
                                                            kind: pod name: network-problem-detector-host-cprp9 namespace: kube-system  
                                                            kind: pod name: network-problem-detector-host-xvzkb namespace: kube-system  
                                                            kind: pod name: network-problem-detector-pod-ck849 namespace: kube-system  
                                                            kind: pod name: network-problem-detector-pod-jgf7j namespace: kube-system  
                                                            kind: pod name: node-exporter-8nn24 namespace: kube-system  
                                                            kind: pod name: node-exporter-lzf7z namespace: kube-system  
                                                            kind: pod name: node-local-dns-d6lgp namespace: kube-system  
                                                            kind: pod name: node-local-dns-r6zzr namespace: kube-system  
                                                            kind: pod name: node-problem-detector-ddmx4 namespace: kube-system  
                                                            kind: pod name: node-problem-detector-qxs5g namespace: kube-system  
                                                            kind: pod name: vpn-shoot-84954fb6df-sqkt9 namespace: kube-system  
                                                         
                                                     
                                                    
                                                        gcp 
                                                        
                                                            kind: pod name: apiserver-proxy-dxk6r namespace: kube-system  
                                                            kind: pod name: apiserver-proxy-wdccl namespace: kube-system  
                                                            kind: pod name: blackbox-exporter-54d6476f57-8wfq2 namespace: kube-system  
                                                            kind: pod name: blackbox-exporter-54d6476f57-vvg7r namespace: kube-system  
                                                            kind: pod name: calico-node-pbp5x namespace: kube-system  
                                                            kind: pod name: calico-node-vertical-autoscaler-75c94f77bb-7sxbj namespace: kube-system  
                                                            kind: pod name: calico-node-xjxgs namespace: kube-system  
                                                            kind: pod name: calico-typha-deploy-6c94dc645b-hxc9n namespace: kube-system  
                                                            kind: pod name: calico-typha-deploy-6c94dc645b-jx2gb namespace: kube-system  
                                                            kind: pod name: calico-typha-horizontal-autoscaler-745ff89c8f-wfsgm namespace: kube-system  
                                                            kind: pod name: calico-typha-vertical-autoscaler-59b9756658-zn42c namespace: kube-system  
                                                            kind: pod name: coredns-f68b78c49-8xjpl namespace: kube-system  
                                                            kind: pod name: coredns-f68b78c49-zkfxf namespace: kube-system  
                                                            kind: pod name: csi-driver-node-4mx2n namespace: kube-system  
                                                            kind: pod name: csi-driver-node-j8pfg namespace: kube-system  
                                                            kind: pod name: egress-filter-applier-b9b5x namespace: kube-system  
                                                            kind: pod name: egress-filter-applier-pkr9q namespace: kube-system  
                                                            kind: pod name: kube-proxy-worker-bex82-v1.31.8-krn64 namespace: kube-system  
                                                            kind: pod name: kube-proxy-worker-bex82-v1.31.8-x9kg4 namespace: kube-system  
                                                            kind: pod name: metrics-server-5df6676dbf-kbm29 namespace: kube-system  
                                                            kind: pod name: metrics-server-5df6676dbf-tkhb2 namespace: kube-system  
                                                            kind: pod name: network-problem-detector-host-8ltzf namespace: kube-system  
                                                            kind: pod name: network-problem-detector-host-hd4cf namespace: kube-system  
                                                            kind: pod name: network-problem-detector-pod-gz2ph namespace: kube-system  
                                                            kind: pod name: network-problem-detector-pod-q8tj6 namespace: kube-system  
                                                            kind: pod name: node-exporter-5jtvr namespace: kube-system  
                                                            kind: pod name: node-exporter-s5t8x namespace: kube-system  
                                                            kind: pod name: node-local-dns-f29m2 namespace: kube-system  
                                                            kind: pod name: node-local-dns-srwg9 namespace: kube-system  
                                                            kind: pod name: node-problem-detector-2jzhw namespace: kube-system  
                                                            kind: pod name: node-problem-detector-5qmlk namespace: kube-system  
                                                            kind: pod name: vpn-shoot-5b6c54bdc9-dh49n namespace: kube-system  
                                                         
                                                     
                                                    
                                                        openstack 
                                                        
                                                            kind: pod name: apiserver-proxy-mjfl5 namespace: kube-system  
                                                            kind: pod name: apiserver-proxy-zp6mh namespace: kube-system  
                                                            kind: pod name: blackbox-exporter-54d6476f57-4jfn4 namespace: kube-system  
                                                            kind: pod name: blackbox-exporter-54d6476f57-vprcp namespace: kube-system  
                                                            kind: pod name: calico-kube-controllers-5f4cb8d889-mcgpq namespace: kube-system  
                                                            kind: pod name: calico-node-rsrv5 namespace: kube-system  
                                                            kind: pod name: calico-node-vertical-autoscaler-75c94f77bb-zjc72 namespace: kube-system  
                                                            kind: pod name: calico-node-wdnsn namespace: kube-system  
                                                            kind: pod name: calico-typha-deploy-6c94dc645b-fzc8v namespace: kube-system  
                                                            kind: pod name: calico-typha-deploy-6c94dc645b-jvpdv namespace: kube-system  
                                                            kind: pod name: calico-typha-horizontal-autoscaler-745ff89c8f-jwh2r namespace: kube-system  
                                                            kind: pod name: calico-typha-vertical-autoscaler-59b9756658-qx9sd namespace: kube-system  
                                                            kind: pod name: coredns-5464fd5895-gzjzz namespace: kube-system  
                                                            kind: pod name: coredns-5464fd5895-mgtdc namespace: kube-system  
                                                            kind: pod name: csi-driver-node-46dm2 namespace: kube-system  
                                                            kind: pod name: csi-driver-node-pwcl7 namespace: kube-system  
                                                            kind: pod name: egress-filter-applier-b5z8f namespace: kube-system  
                                                            kind: pod name: egress-filter-applier-b6786 namespace: kube-system  
                                                            kind: pod name: kube-proxy-worker-dqty2-v1.31.8-9sx78 namespace: kube-system  
                                                            kind: pod name: kube-proxy-worker-dqty2-v1.31.8-fwp8d namespace: kube-system  
                                                            kind: pod name: metrics-server-7c7946c76-gsxtg namespace: kube-system  
                                                            kind: pod name: metrics-server-7c7946c76-szr7s namespace: kube-system  
                                                            kind: pod name: network-problem-detector-host-75kzx namespace: kube-system  
                                                            kind: pod name: network-problem-detector-host-xhqzr namespace: kube-system  
                                                            kind: pod name: network-problem-detector-pod-7kj5v namespace: kube-system  
                                                            kind: pod name: network-problem-detector-pod-bb6zl namespace: kube-system  
                                                            kind: pod name: node-exporter-4cp5g namespace: kube-system  
                                                            kind: pod name: node-exporter-rshd2 namespace: kube-system  
                                                            kind: pod name: node-local-dns-57bpm namespace: kube-system  
                                                            kind: pod name: node-local-dns-8b6dg namespace: kube-system  
                                                            kind: pod name: node-problem-detector-2dxfn namespace: kube-system  
                                                            kind: pod name: node-problem-detector-5mv98 namespace: kube-system  
                                                            kind: pod name: vpn-shoot-54dfc94bd-jlgl9 namespace: kube-system  
                                                         
                                                     
                                                 
                                             
                                         
                                     
                                    
                                        242418 (Medium) - The Kubernetes API server must use approved cipher suites. 
                                        
                                            
                                                Option tls-cipher-suites set to allowed values. 
                                                
                                                    
                                                        aws 
                                                        
                                                            kind: deployment name: kube-apiserver namespace: shoot--diki-comp--aws  
                                                         
                                                     
                                                    
                                                        azure 
                                                        
                                                            kind: deployment name: kube-apiserver namespace: shoot--diki-comp--azure  
                                                         
                                                     
                                                    
                                                        gcp 
                                                        
                                                            kind: deployment name: kube-apiserver namespace: shoot--diki-comp--gcp  
                                                         
                                                     
                                                    
                                                        openstack 
                                                        
                                                            kind: deployment name: kube-apiserver namespace: shoot--diki-comp--openstack  
                                                         
                                                     
                                                 
                                             
                                         
                                     
                                    
                                        242419 (Medium) - Kubernetes API Server must have the SSL Certificate Authority set. 
                                        
                                            
                                                Option client-ca-file set. 
                                                
                                                    
                                                        aws 
                                                        
                                                            kind: deployment name: kube-apiserver namespace: shoot--diki-comp--aws  
                                                         
                                                     
                                                    
                                                        azure 
                                                        
                                                            kind: deployment name: kube-apiserver namespace: shoot--diki-comp--azure  
                                                         
                                                     
                                                    
                                                        gcp 
                                                        
                                                            kind: deployment name: kube-apiserver namespace: shoot--diki-comp--gcp  
                                                         
                                                     
                                                    
                                                        openstack 
                                                        
                                                            kind: deployment name: kube-apiserver namespace: shoot--diki-comp--openstack  
                                                         
                                                     
                                                 
                                             
                                         
                                     
                                    
                                        242420 (Medium) - Kubernetes Kubelet must have the SSL Certificate Authority set. 
                                        
                                            
                                                Option authentication.x509.clientCAFile set. 
                                                
                                                    
                                                        aws 
                                                        
                                                            kind: node name: ip-IP-Address.eu-west-1.compute.internal  
                                                            kind: node name: ip-IP-Address.eu-west-1.compute.internal  
                                                         
                                                     
                                                    
                                                        azure 
                                                        
                                                            kind: node name: shoot--diki-comp--azure-worker-g7p4p-z3-66467-k6q5n  
                                                            kind: node name: shoot--diki-comp--azure-worker-g7p4p-z3-66467-xzlbf  
                                                         
                                                     
                                                    
                                                        gcp 
                                                        
                                                            kind: node name: shoot--diki-comp--gcp-worker-bex82-z1-5d9b4-8fp7q  
                                                            kind: node name: shoot--diki-comp--gcp-worker-bex82-z1-5d9b4-xjxdz  
                                                         
                                                     
                                                    
                                                        openstack 
                                                        
                                                            kind: node name: shoot--diki-comp--openstack-worker-dqty2-z1-64f7d-jllmm  
                                                            kind: node name: shoot--diki-comp--openstack-worker-dqty2-z1-64f7d-wmcjr  
                                                         
                                                     
                                                 
                                             
                                         
                                     
                                    
                                        242421 (Medium) - Kubernetes Controller Manager must have the SSL Certificate Authority set. 
                                        
                                            
                                                Option root-ca-file set. 
                                                
                                                    
                                                        aws 
                                                        
                                                            kind: deployment name: kube-controller-manager namespace: shoot--diki-comp--aws  
                                                         
                                                     
                                                    
                                                        azure 
                                                        
                                                            kind: deployment name: kube-controller-manager namespace: shoot--diki-comp--azure  
                                                         
                                                     
                                                    
                                                        gcp 
                                                        
                                                            kind: deployment name: kube-controller-manager namespace: shoot--diki-comp--gcp  
                                                         
                                                     
                                                    
                                                        openstack 
                                                        
                                                            kind: deployment name: kube-controller-manager namespace: shoot--diki-comp--openstack  
                                                         
                                                     
                                                 
                                             
                                         
                                     
                                    
                                        242422 (Medium) - Kubernetes API Server must have a certificate for communication. 
                                        
                                            
                                                Option tls-cert-file set. 
                                                
                                                    
                                                        aws 
                                                        
                                                            kind: deployment name: kube-apiserver namespace: shoot--diki-comp--aws  
                                                         
                                                     
                                                    
                                                        azure 
                                                        
                                                            kind: deployment name: kube-apiserver namespace: shoot--diki-comp--azure  
                                                         
                                                     
                                                    
                                                        gcp 
                                                        
                                                            kind: deployment name: kube-apiserver namespace: shoot--diki-comp--gcp  
                                                         
                                                     
                                                    
                                                        openstack 
                                                        
                                                            kind: deployment name: kube-apiserver namespace: shoot--diki-comp--openstack  
                                                         
                                                     
                                                 
                                             
                                            
                                                Option tls-private-key-file set. 
                                                
                                                    
                                                        aws 
                                                        
                                                            kind: deployment name: kube-apiserver namespace: shoot--diki-comp--aws  
                                                         
                                                     
                                                    
                                                        azure 
                                                        
                                                            kind: deployment name: kube-apiserver namespace: shoot--diki-comp--azure  
                                                         
                                                     
                                                    
                                                        gcp 
                                                        
                                                            kind: deployment name: kube-apiserver namespace: shoot--diki-comp--gcp  
                                                         
                                                     
                                                    
                                                        openstack 
                                                        
                                                            kind: deployment name: kube-apiserver namespace: shoot--diki-comp--openstack  
                                                         
                                                     
                                                 
                                             
                                         
                                     
                                    
                                        242423 (Medium) - Kubernetes etcd must enable client authentication to secure service. 
                                        
                                            
                                                Option client-transport-security.client-cert-auth set to allowed value. 
                                                
                                                    
                                                        aws 
                                                        
                                                            kind: statefulSet name: etcd-main namespace: shoot--diki-comp--aws  
                                                            kind: statefulSet name: etcd-events namespace: shoot--diki-comp--aws  
                                                         
                                                     
                                                    
                                                        azure 
                                                        
                                                            kind: statefulSet name: etcd-main namespace: shoot--diki-comp--azure  
                                                            kind: statefulSet name: etcd-events namespace: shoot--diki-comp--azure  
                                                         
                                                     
                                                    
                                                        gcp 
                                                        
                                                            kind: statefulSet name: etcd-main namespace: shoot--diki-comp--gcp  
                                                            kind: statefulSet name: etcd-events namespace: shoot--diki-comp--gcp  
                                                         
                                                     
                                                    
                                                        openstack 
                                                        
                                                            kind: statefulSet name: etcd-main namespace: shoot--diki-comp--openstack  
                                                            kind: statefulSet name: etcd-events namespace: shoot--diki-comp--openstack  
                                                         
                                                     
                                                 
                                             
                                         
                                     
                                    
                                        242424 (Medium) - Kubernetes Kubelet must enable tlsPrivateKeyFile for client authentication to secure service. 
                                        
                                            
                                                Kubelet rotates server certificates automatically itself. 
                                                
                                                    
                                                        aws 
                                                        
                                                            kind: node name: ip-IP-Address.eu-west-1.compute.internal  
                                                            kind: node name: ip-IP-Address.eu-west-1.compute.internal  
                                                         
                                                     
                                                    
                                                        azure 
                                                        
                                                            kind: node name: shoot--diki-comp--azure-worker-g7p4p-z3-66467-k6q5n  
                                                            kind: node name: shoot--diki-comp--azure-worker-g7p4p-z3-66467-xzlbf  
                                                         
                                                     
                                                    
                                                        gcp 
                                                        
                                                            kind: node name: shoot--diki-comp--gcp-worker-bex82-z1-5d9b4-8fp7q  
                                                            kind: node name: shoot--diki-comp--gcp-worker-bex82-z1-5d9b4-xjxdz  
                                                         
                                                     
                                                    
                                                        openstack 
                                                        
                                                            kind: node name: shoot--diki-comp--openstack-worker-dqty2-z1-64f7d-jllmm  
                                                            kind: node name: shoot--diki-comp--openstack-worker-dqty2-z1-64f7d-wmcjr  
                                                         
                                                     
                                                 
                                             
                                         
                                     
                                    
                                        242425 (Medium) - Kubernetes Kubelet must enable tlsCertFile for client authentication to secure service. 
                                        
                                            
                                                Kubelet rotates server certificates automatically itself. 
                                                
                                                    
                                                        aws 
                                                        
                                                            kind: node name: ip-IP-Address.eu-west-1.compute.internal  
                                                            kind: node name: ip-IP-Address.eu-west-1.compute.internal  
                                                         
                                                     
                                                    
                                                        azure 
                                                        
                                                            kind: node name: shoot--diki-comp--azure-worker-g7p4p-z3-66467-k6q5n  
                                                            kind: node name: shoot--diki-comp--azure-worker-g7p4p-z3-66467-xzlbf  
                                                         
                                                     
                                                    
                                                        gcp 
                                                        
                                                            kind: node name: shoot--diki-comp--gcp-worker-bex82-z1-5d9b4-8fp7q  
                                                            kind: node name: shoot--diki-comp--gcp-worker-bex82-z1-5d9b4-xjxdz  
                                                         
                                                     
                                                    
                                                        openstack 
                                                        
                                                            kind: node name: shoot--diki-comp--openstack-worker-dqty2-z1-64f7d-jllmm  
                                                            kind: node name: shoot--diki-comp--openstack-worker-dqty2-z1-64f7d-wmcjr  
                                                         
                                                     
                                                 
                                             
                                         
                                     
                                    
                                        242427 (Medium) - Kubernetes etcd must have a key file for secure communication. 
                                        
                                            
                                                Option client-transport-security.key-file set to allowed value. 
                                                
                                                    
                                                        aws 
                                                        
                                                            kind: statefulSet name: etcd-main namespace: shoot--diki-comp--aws  
                                                            kind: statefulSet name: etcd-events namespace: shoot--diki-comp--aws  
                                                         
                                                     
                                                    
                                                        azure 
                                                        
                                                            kind: statefulSet name: etcd-main namespace: shoot--diki-comp--azure  
                                                            kind: statefulSet name: etcd-events namespace: shoot--diki-comp--azure  
                                                         
                                                     
                                                    
                                                        gcp 
                                                        
                                                            kind: statefulSet name: etcd-main namespace: shoot--diki-comp--gcp  
                                                            kind: statefulSet name: etcd-events namespace: shoot--diki-comp--gcp  
                                                         
                                                     
                                                    
                                                        openstack 
                                                        
                                                            kind: statefulSet name: etcd-main namespace: shoot--diki-comp--openstack  
                                                            kind: statefulSet name: etcd-events namespace: shoot--diki-comp--openstack  
                                                         
                                                     
                                                 
                                             
                                         
                                     
                                    
                                        242428 (Medium) - Kubernetes etcd must have a certificate for communication. 
                                        
                                            
                                                Option client-transport-security.cert-file set to allowed value. 
                                                
                                                    
                                                        aws 
                                                        
                                                            kind: statefulSet name: etcd-main namespace: shoot--diki-comp--aws  
                                                            kind: statefulSet name: etcd-events namespace: shoot--diki-comp--aws  
                                                         
                                                     
                                                    
                                                        azure 
                                                        
                                                            kind: statefulSet name: etcd-main namespace: shoot--diki-comp--azure  
                                                            kind: statefulSet name: etcd-events namespace: shoot--diki-comp--azure  
                                                         
                                                     
                                                    
                                                        gcp 
                                                        
                                                            kind: statefulSet name: etcd-main namespace: shoot--diki-comp--gcp  
                                                            kind: statefulSet name: etcd-events namespace: shoot--diki-comp--gcp  
                                                         
                                                     
                                                    
                                                        openstack 
                                                        
                                                            kind: statefulSet name: etcd-main namespace: shoot--diki-comp--openstack  
                                                            kind: statefulSet name: etcd-events namespace: shoot--diki-comp--openstack  
                                                         
                                                     
                                                 
                                             
                                         
                                     
                                    
                                        242429 (Medium) - Kubernetes etcd must have the SSL Certificate Authority set. 
                                        
                                            
                                                Option etcd-cafile set. 
                                                
                                                    
                                                        aws 
                                                        
                                                            kind: deployment name: kube-apiserver namespace: shoot--diki-comp--aws  
                                                         
                                                     
                                                    
                                                        azure 
                                                        
                                                            kind: deployment name: kube-apiserver namespace: shoot--diki-comp--azure  
                                                         
                                                     
                                                    
                                                        gcp 
                                                        
                                                            kind: deployment name: kube-apiserver namespace: shoot--diki-comp--gcp  
                                                         
                                                     
                                                    
                                                        openstack 
                                                        
                                                            kind: deployment name: kube-apiserver namespace: shoot--diki-comp--openstack  
                                                         
                                                     
                                                 
                                             
                                         
                                     
                                    
                                        242430 (Medium) - Kubernetes etcd must have a certificate for communication. 
                                        
                                            
                                                Option etcd-certfile set. 
                                                
                                                    
                                                        aws 
                                                        
                                                            kind: deployment name: kube-apiserver namespace: shoot--diki-comp--aws  
                                                         
                                                     
                                                    
                                                        azure 
                                                        
                                                            kind: deployment name: kube-apiserver namespace: shoot--diki-comp--azure  
                                                         
                                                     
                                                    
                                                        gcp 
                                                        
                                                            kind: deployment name: kube-apiserver namespace: shoot--diki-comp--gcp  
                                                         
                                                     
                                                    
                                                        openstack 
                                                        
                                                            kind: deployment name: kube-apiserver namespace: shoot--diki-comp--openstack  
                                                         
                                                     
                                                 
                                             
                                         
                                     
                                    
                                        242431 (Medium) - Kubernetes etcd must have a key file for secure communication. 
                                        
                                            
                                                Option etcd-keyfile set. 
                                                
                                                    
                                                        aws 
                                                        
                                                            kind: deployment name: kube-apiserver namespace: shoot--diki-comp--aws  
                                                         
                                                     
                                                    
                                                        azure 
                                                        
                                                            kind: deployment name: kube-apiserver namespace: shoot--diki-comp--azure  
                                                         
                                                     
                                                    
                                                        gcp 
                                                        
                                                            kind: deployment name: kube-apiserver namespace: shoot--diki-comp--gcp  
                                                         
                                                     
                                                    
                                                        openstack 
                                                        
                                                            kind: deployment name: kube-apiserver namespace: shoot--diki-comp--openstack  
                                                         
                                                     
                                                 
                                             
                                         
                                     
                                    
                                        242434 (High) - Kubernetes Kubelet must enable kernel protection. 
                                        
                                            
                                                Option protectKernelDefaults set to allowed value. 
                                                
                                                    
                                                        aws 
                                                        
                                                            kind: node name: ip-IP-Address.eu-west-1.compute.internal  
                                                            kind: node name: ip-IP-Address.eu-west-1.compute.internal  
                                                         
                                                     
                                                    
                                                        azure 
                                                        
                                                            kind: node name: shoot--diki-comp--azure-worker-g7p4p-z3-66467-k6q5n  
                                                            kind: node name: shoot--diki-comp--azure-worker-g7p4p-z3-66467-xzlbf  
                                                         
                                                     
                                                    
                                                        gcp 
                                                        
                                                            kind: node name: shoot--diki-comp--gcp-worker-bex82-z1-5d9b4-8fp7q  
                                                            kind: node name: shoot--diki-comp--gcp-worker-bex82-z1-5d9b4-xjxdz  
                                                         
                                                     
                                                    
                                                        openstack 
                                                        
                                                            kind: node name: shoot--diki-comp--openstack-worker-dqty2-z1-64f7d-jllmm  
                                                            kind: node name: shoot--diki-comp--openstack-worker-dqty2-z1-64f7d-wmcjr  
                                                         
                                                     
                                                 
                                             
                                         
                                     
                                    
                                        242436 (High) - The Kubernetes API server must have the ValidatingAdmissionWebhook enabled. 
                                        
                                            
                                                Option enable-admission-plugins defaults to allowed value. 
                                                
                                                    
                                                        aws 
                                                        
                                                            kind: deployment name: kube-apiserver namespace: shoot--diki-comp--aws  
                                                         
                                                     
                                                    
                                                        azure 
                                                        
                                                            kind: deployment name: kube-apiserver namespace: shoot--diki-comp--azure  
                                                         
                                                     
                                                    
                                                        gcp 
                                                        
                                                            kind: deployment name: kube-apiserver namespace: shoot--diki-comp--gcp  
                                                         
                                                     
                                                    
                                                        openstack 
                                                        
                                                            kind: deployment name: kube-apiserver namespace: shoot--diki-comp--openstack  
                                                         
                                                     
                                                 
                                             
                                         
                                     
                                    
                                        242438 (Medium) - Kubernetes API Server must configure timeouts to limit attack surface. 
                                        
                                            
                                                Option request-timeout has not been set. 
                                                
                                                    
                                                        aws 
                                                        
                                                            details: defaults to 1m0s kind: deployment name: kube-apiserver namespace: shoot--diki-comp--aws  
                                                         
                                                     
                                                    
                                                        azure 
                                                        
                                                            details: defaults to 1m0s kind: deployment name: kube-apiserver namespace: shoot--diki-comp--azure  
                                                         
                                                     
                                                    
                                                        gcp 
                                                        
                                                            details: defaults to 1m0s kind: deployment name: kube-apiserver namespace: shoot--diki-comp--gcp  
                                                         
                                                     
                                                    
                                                        openstack 
                                                        
                                                            details: defaults to 1m0s kind: deployment name: kube-apiserver namespace: shoot--diki-comp--openstack  
                                                         
                                                     
                                                 
                                             
                                         
                                     
                                    
                                        242442 (Medium) - Kubernetes must remove old components after updated versions have been installed. 
                                        
                                            
                                                All found images use current versions. 
                                                
                                             
                                         
                                     
                                    
                                        242445 (Medium) - The Kubernetes component etcd must be owned by etcd. 
                                        
                                            
                                                File has expected owners 
                                                
                                                    
                                                        aws 
                                                        
                                                            containerName: etcd details: fileName: /var/lib/kubelet/pods/e9a97103-bea9-4174-9f2f-d11c7dee0b81/volumes/kubernetes.io~csi/pv-shoot--garden--aws-ha-eu2-e91404ef-48a3-4fd4-adad-1722b56c23ab/mount/safe_guard, ownerUser: 65532, ownerGroup: 65532 kind: pod name: etcd-main-0 namespace: shoot--diki-comp--aws  
                                                            containerName: etcd details: fileName: /var/lib/kubelet/pods/e9a97103-bea9-4174-9f2f-d11c7dee0b81/volumes/kubernetes.io~csi/pv-shoot--garden--aws-ha-eu2-e91404ef-48a3-4fd4-adad-1722b56c23ab/mount/new.etcd/member/wal/0.tmp, ownerUser: 65532, ownerGroup: 65532 kind: pod name: etcd-main-0 namespace: shoot--diki-comp--aws  
                                                            containerName: etcd details: fileName: /var/lib/kubelet/pods/e9a97103-bea9-4174-9f2f-d11c7dee0b81/volumes/kubernetes.io~csi/pv-shoot--garden--aws-ha-eu2-e91404ef-48a3-4fd4-adad-1722b56c23ab/mount/new.etcd/member/wal/0000000000000000-0000000000000000.wal, ownerUser: 65532, ownerGroup: 65532 kind: pod name: etcd-main-0 namespace: shoot--diki-comp--aws  
                                                            containerName: etcd details: fileName: /var/lib/kubelet/pods/e9a97103-bea9-4174-9f2f-d11c7dee0b81/volumes/kubernetes.io~csi/pv-shoot--garden--aws-ha-eu2-e91404ef-48a3-4fd4-adad-1722b56c23ab/mount/new.etcd/member/snap/db, ownerUser: 65532, ownerGroup: 65532 kind: pod name: etcd-main-0 namespace: shoot--diki-comp--aws  
                                                            containerName: etcd details: fileName: /var/lib/kubelet/pods/e9a97103-bea9-4174-9f2f-d11c7dee0b81/volumes/kubernetes.io~secret/etcd-ca/..2025_06_23_00_02_28.70977455/bundle.crt, ownerUser: 0, ownerGroup: 65532 kind: pod name: etcd-main-0 namespace: shoot--diki-comp--aws  
                                                            containerName: etcd details: fileName: /var/lib/kubelet/pods/e9a97103-bea9-4174-9f2f-d11c7dee0b81/volumes/kubernetes.io~secret/etcd-server-tls/..2025_06_23_00_02_28.941742504/tls.crt, ownerUser: 0, ownerGroup: 65532 kind: pod name: etcd-main-0 namespace: shoot--diki-comp--aws  
                                                            containerName: etcd details: fileName: /var/lib/kubelet/pods/e9a97103-bea9-4174-9f2f-d11c7dee0b81/volumes/kubernetes.io~secret/etcd-server-tls/..2025_06_23_00_02_28.941742504/tls.key, ownerUser: 0, ownerGroup: 65532 kind: pod name: etcd-main-0 namespace: shoot--diki-comp--aws  
                                                            containerName: etcd details: fileName: /var/lib/kubelet/pods/e9a97103-bea9-4174-9f2f-d11c7dee0b81/volumes/kubernetes.io~secret/etcd-client-tls/..2025_06_23_00_02_28.581061777/tls.key, ownerUser: 0, ownerGroup: 65532 kind: pod name: etcd-main-0 namespace: shoot--diki-comp--aws  
                                                            containerName: etcd details: fileName: /var/lib/kubelet/pods/e9a97103-bea9-4174-9f2f-d11c7dee0b81/volumes/kubernetes.io~secret/etcd-client-tls/..2025_06_23_00_02_28.581061777/tls.crt, ownerUser: 0, ownerGroup: 65532 kind: pod name: etcd-main-0 namespace: shoot--diki-comp--aws  
                                                            containerName: etcd details: fileName: /var/lib/kubelet/pods/e9a97103-bea9-4174-9f2f-d11c7dee0b81/volumes/kubernetes.io~secret/backup-restore-ca/..2025_06_23_00_02_28.3789989883/bundle.crt, ownerUser: 0, ownerGroup: 65532 kind: pod name: etcd-main-0 namespace: shoot--diki-comp--aws  
                                                            containerName: etcd details: fileName: /var/lib/kubelet/pods/e9a97103-bea9-4174-9f2f-d11c7dee0b81/volumes/kubernetes.io~projected/kube-api-access-gardener/..2025_06_23_00_02_28.4232825321/namespace, ownerUser: 0, ownerGroup: 65532 kind: pod name: etcd-main-0 namespace: shoot--diki-comp--aws  
                                                            containerName: etcd details: fileName: /var/lib/kubelet/pods/e9a97103-bea9-4174-9f2f-d11c7dee0b81/volumes/kubernetes.io~projected/kube-api-access-gardener/..2025_06_23_00_02_28.4232825321/ca.crt, ownerUser: 0, ownerGroup: 65532 kind: pod name: etcd-main-0 namespace: shoot--diki-comp--aws  
                                                            containerName: etcd details: fileName: /var/lib/kubelet/pods/e9a97103-bea9-4174-9f2f-d11c7dee0b81/volumes/kubernetes.io~projected/kube-api-access-gardener/..2025_06_23_00_02_28.4232825321/token, ownerUser: 65532, ownerGroup: 65532 kind: pod name: etcd-main-0 namespace: shoot--diki-comp--aws  
                                                            containerName: backup-restore details: fileName: /var/lib/kubelet/pods/e9a97103-bea9-4174-9f2f-d11c7dee0b81/volumes/kubernetes.io~secret/etcd-backup-secret/..2025_06_23_00_02_28.166720885/secretAccessKey, ownerUser: 0, ownerGroup: 65532 kind: pod name: etcd-main-0 namespace: shoot--diki-comp--aws  
                                                            containerName: backup-restore details: fileName: /var/lib/kubelet/pods/e9a97103-bea9-4174-9f2f-d11c7dee0b81/volumes/kubernetes.io~secret/etcd-backup-secret/..2025_06_23_00_02_28.166720885/region, ownerUser: 0, ownerGroup: 65532 kind: pod name: etcd-main-0 namespace: shoot--diki-comp--aws  
                                                            containerName: backup-restore details: fileName: /var/lib/kubelet/pods/e9a97103-bea9-4174-9f2f-d11c7dee0b81/volumes/kubernetes.io~secret/etcd-backup-secret/..2025_06_23_00_02_28.166720885/bucketName, ownerUser: 0, ownerGroup: 65532 kind: pod name: etcd-main-0 namespace: shoot--diki-comp--aws  
                                                            containerName: backup-restore details: fileName: /var/lib/kubelet/pods/e9a97103-bea9-4174-9f2f-d11c7dee0b81/volumes/kubernetes.io~secret/etcd-backup-secret/..2025_06_23_00_02_28.166720885/accessKeyID, ownerUser: 0, ownerGroup: 65532 kind: pod name: etcd-main-0 namespace: shoot--diki-comp--aws  
                                                            containerName: backup-restore details: fileName: /var/lib/kubelet/pods/e9a97103-bea9-4174-9f2f-d11c7dee0b81/volumes/kubernetes.io~csi/pv-shoot--garden--aws-ha-eu2-e91404ef-48a3-4fd4-adad-1722b56c23ab/mount/safe_guard, ownerUser: 65532, ownerGroup: 65532 kind: pod name: etcd-main-0 namespace: shoot--diki-comp--aws  
                                                            containerName: backup-restore details: fileName: /var/lib/kubelet/pods/e9a97103-bea9-4174-9f2f-d11c7dee0b81/volumes/kubernetes.io~csi/pv-shoot--garden--aws-ha-eu2-e91404ef-48a3-4fd4-adad-1722b56c23ab/mount/new.etcd/member/wal/0.tmp, ownerUser: 65532, ownerGroup: 65532 kind: pod name: etcd-main-0 namespace: shoot--diki-comp--aws  
                                                            containerName: backup-restore details: fileName: /var/lib/kubelet/pods/e9a97103-bea9-4174-9f2f-d11c7dee0b81/volumes/kubernetes.io~csi/pv-shoot--garden--aws-ha-eu2-e91404ef-48a3-4fd4-adad-1722b56c23ab/mount/new.etcd/member/wal/0000000000000000-0000000000000000.wal, ownerUser: 65532, ownerGroup: 65532 kind: pod name: etcd-main-0 namespace: shoot--diki-comp--aws  
                                                            containerName: backup-restore details: fileName: /var/lib/kubelet/pods/e9a97103-bea9-4174-9f2f-d11c7dee0b81/volumes/kubernetes.io~csi/pv-shoot--garden--aws-ha-eu2-e91404ef-48a3-4fd4-adad-1722b56c23ab/mount/new.etcd/member/snap/db, ownerUser: 65532, ownerGroup: 65532 kind: pod name: etcd-main-0 namespace: shoot--diki-comp--aws  
                                                            containerName: backup-restore details: fileName: /var/lib/kubelet/pods/e9a97103-bea9-4174-9f2f-d11c7dee0b81/volumes/kubernetes.io~configmap/etcd-config-file/..2025_06_23_00_02_28.1273412141/etcd.conf.yaml, ownerUser: 0, ownerGroup: 65532 kind: pod name: etcd-main-0 namespace: shoot--diki-comp--aws  
                                                            containerName: backup-restore details: fileName: /var/lib/kubelet/pods/e9a97103-bea9-4174-9f2f-d11c7dee0b81/volumes/kubernetes.io~secret/backup-restore-server-tls/..2025_06_23_00_02_28.137193825/tls.key, ownerUser: 0, ownerGroup: 65532 kind: pod name: etcd-main-0 namespace: shoot--diki-comp--aws  
                                                            containerName: backup-restore details: fileName: /var/lib/kubelet/pods/e9a97103-bea9-4174-9f2f-d11c7dee0b81/volumes/kubernetes.io~secret/backup-restore-server-tls/..2025_06_23_00_02_28.137193825/tls.crt, ownerUser: 0, ownerGroup: 65532 kind: pod name: etcd-main-0 namespace: shoot--diki-comp--aws  
                                                            containerName: backup-restore details: fileName: /var/lib/kubelet/pods/e9a97103-bea9-4174-9f2f-d11c7dee0b81/volumes/kubernetes.io~secret/etcd-ca/..2025_06_23_00_02_28.70977455/bundle.crt, ownerUser: 0, ownerGroup: 65532 kind: pod name: etcd-main-0 namespace: shoot--diki-comp--aws  
                                                            containerName: backup-restore details: fileName: /var/lib/kubelet/pods/e9a97103-bea9-4174-9f2f-d11c7dee0b81/volumes/kubernetes.io~secret/etcd-client-tls/..2025_06_23_00_02_28.581061777/tls.key, ownerUser: 0, ownerGroup: 65532 kind: pod name: etcd-main-0 namespace: shoot--diki-comp--aws  
                                                            containerName: backup-restore details: fileName: /var/lib/kubelet/pods/e9a97103-bea9-4174-9f2f-d11c7dee0b81/volumes/kubernetes.io~secret/etcd-client-tls/..2025_06_23_00_02_28.581061777/tls.crt, ownerUser: 0, ownerGroup: 65532 kind: pod name: etcd-main-0 namespace: shoot--diki-comp--aws  
                                                            containerName: backup-restore details: fileName: /var/lib/kubelet/pods/e9a97103-bea9-4174-9f2f-d11c7dee0b81/volumes/kubernetes.io~projected/kube-api-access-gardener/..2025_06_23_00_02_28.4232825321/namespace, ownerUser: 0, ownerGroup: 65532 kind: pod name: etcd-main-0 namespace: shoot--diki-comp--aws  
                                                            containerName: backup-restore details: fileName: /var/lib/kubelet/pods/e9a97103-bea9-4174-9f2f-d11c7dee0b81/volumes/kubernetes.io~projected/kube-api-access-gardener/..2025_06_23_00_02_28.4232825321/ca.crt, ownerUser: 0, ownerGroup: 65532 kind: pod name: etcd-main-0 namespace: shoot--diki-comp--aws  
                                                            containerName: backup-restore details: fileName: /var/lib/kubelet/pods/e9a97103-bea9-4174-9f2f-d11c7dee0b81/volumes/kubernetes.io~projected/kube-api-access-gardener/..2025_06_23_00_02_28.4232825321/token, ownerUser: 65532, ownerGroup: 65532 kind: pod name: etcd-main-0 namespace: shoot--diki-comp--aws  
                                                            containerName: etcd details: fileName: /var/lib/kubelet/pods/8500de88-870c-4453-a9d3-673fe2e83591/volumes/kubernetes.io~csi/pv-shoot--garden--aws-ha-eu2-93a075b4-8ed7-415f-b925-72cc610120fd/mount/safe_guard, ownerUser: 65532, ownerGroup: 65532 kind: pod name: etcd-events-0 namespace: shoot--diki-comp--aws  
                                                            containerName: etcd details: fileName: /var/lib/kubelet/pods/8500de88-870c-4453-a9d3-673fe2e83591/volumes/kubernetes.io~csi/pv-shoot--garden--aws-ha-eu2-93a075b4-8ed7-415f-b925-72cc610120fd/mount/new.etcd/member/snap/db, ownerUser: 65532, ownerGroup: 65532 kind: pod name: etcd-events-0 namespace: shoot--diki-comp--aws  
                                                            containerName: etcd details: fileName: /var/lib/kubelet/pods/8500de88-870c-4453-a9d3-673fe2e83591/volumes/kubernetes.io~csi/pv-shoot--garden--aws-ha-eu2-93a075b4-8ed7-415f-b925-72cc610120fd/mount/new.etcd/member/wal/0000000000000000-0000000000000000.wal, ownerUser: 65532, ownerGroup: 65532 kind: pod name: etcd-events-0 namespace: shoot--diki-comp--aws  
                                                            containerName: etcd details: fileName: /var/lib/kubelet/pods/8500de88-870c-4453-a9d3-673fe2e83591/volumes/kubernetes.io~csi/pv-shoot--garden--aws-ha-eu2-93a075b4-8ed7-415f-b925-72cc610120fd/mount/new.etcd/member/wal/0.tmp, ownerUser: 65532, ownerGroup: 65532 kind: pod name: etcd-events-0 namespace: shoot--diki-comp--aws  
                                                            containerName: etcd details: fileName: /var/lib/kubelet/pods/8500de88-870c-4453-a9d3-673fe2e83591/volumes/kubernetes.io~secret/etcd-ca/..2025_06_23_00_02_28.1460198907/bundle.crt, ownerUser: 0, ownerGroup: 65532 kind: pod name: etcd-events-0 namespace: shoot--diki-comp--aws  
                                                            containerName: etcd details: fileName: /var/lib/kubelet/pods/8500de88-870c-4453-a9d3-673fe2e83591/volumes/kubernetes.io~secret/etcd-server-tls/..2025_06_23_00_02_28.1081429868/tls.key, ownerUser: 0, ownerGroup: 65532 kind: pod name: etcd-events-0 namespace: shoot--diki-comp--aws  
                                                            containerName: etcd details: fileName: /var/lib/kubelet/pods/8500de88-870c-4453-a9d3-673fe2e83591/volumes/kubernetes.io~secret/etcd-server-tls/..2025_06_23_00_02_28.1081429868/tls.crt, ownerUser: 0, ownerGroup: 65532 kind: pod name: etcd-events-0 namespace: shoot--diki-comp--aws  
                                                            containerName: etcd details: fileName: /var/lib/kubelet/pods/8500de88-870c-4453-a9d3-673fe2e83591/volumes/kubernetes.io~secret/etcd-client-tls/..2025_06_23_00_02_28.830733358/tls.key, ownerUser: 0, ownerGroup: 65532 kind: pod name: etcd-events-0 namespace: shoot--diki-comp--aws  
                                                            containerName: etcd details: fileName: /var/lib/kubelet/pods/8500de88-870c-4453-a9d3-673fe2e83591/volumes/kubernetes.io~secret/etcd-client-tls/..2025_06_23_00_02_28.830733358/tls.crt, ownerUser: 0, ownerGroup: 65532 kind: pod name: etcd-events-0 namespace: shoot--diki-comp--aws  
                                                            containerName: etcd details: fileName: /var/lib/kubelet/pods/8500de88-870c-4453-a9d3-673fe2e83591/volumes/kubernetes.io~secret/backup-restore-ca/..2025_06_23_00_02_28.402585131/bundle.crt, ownerUser: 0, ownerGroup: 65532 kind: pod name: etcd-events-0 namespace: shoot--diki-comp--aws  
                                                            containerName: etcd details: fileName: /var/lib/kubelet/pods/8500de88-870c-4453-a9d3-673fe2e83591/volumes/kubernetes.io~projected/kube-api-access-gardener/..2025_06_23_00_02_28.124882621/ca.crt, ownerUser: 0, ownerGroup: 65532 kind: pod name: etcd-events-0 namespace: shoot--diki-comp--aws  
                                                            containerName: etcd details: fileName: /var/lib/kubelet/pods/8500de88-870c-4453-a9d3-673fe2e83591/volumes/kubernetes.io~projected/kube-api-access-gardener/..2025_06_23_00_02_28.124882621/token, ownerUser: 65532, ownerGroup: 65532 kind: pod name: etcd-events-0 namespace: shoot--diki-comp--aws  
                                                            containerName: etcd details: fileName: /var/lib/kubelet/pods/8500de88-870c-4453-a9d3-673fe2e83591/volumes/kubernetes.io~projected/kube-api-access-gardener/..2025_06_23_00_02_28.124882621/namespace, ownerUser: 0, ownerGroup: 65532 kind: pod name: etcd-events-0 namespace: shoot--diki-comp--aws  
                                                            containerName: backup-restore details: fileName: /var/lib/kubelet/pods/8500de88-870c-4453-a9d3-673fe2e83591/volumes/kubernetes.io~csi/pv-shoot--garden--aws-ha-eu2-93a075b4-8ed7-415f-b925-72cc610120fd/mount/safe_guard, ownerUser: 65532, ownerGroup: 65532 kind: pod name: etcd-events-0 namespace: shoot--diki-comp--aws  
                                                            containerName: backup-restore details: fileName: /var/lib/kubelet/pods/8500de88-870c-4453-a9d3-673fe2e83591/volumes/kubernetes.io~csi/pv-shoot--garden--aws-ha-eu2-93a075b4-8ed7-415f-b925-72cc610120fd/mount/new.etcd/member/snap/db, ownerUser: 65532, ownerGroup: 65532 kind: pod name: etcd-events-0 namespace: shoot--diki-comp--aws  
                                                            containerName: backup-restore details: fileName: /var/lib/kubelet/pods/8500de88-870c-4453-a9d3-673fe2e83591/volumes/kubernetes.io~csi/pv-shoot--garden--aws-ha-eu2-93a075b4-8ed7-415f-b925-72cc610120fd/mount/new.etcd/member/wal/0000000000000000-0000000000000000.wal, ownerUser: 65532, ownerGroup: 65532 kind: pod name: etcd-events-0 namespace: shoot--diki-comp--aws  
                                                            containerName: backup-restore details: fileName: /var/lib/kubelet/pods/8500de88-870c-4453-a9d3-673fe2e83591/volumes/kubernetes.io~csi/pv-shoot--garden--aws-ha-eu2-93a075b4-8ed7-415f-b925-72cc610120fd/mount/new.etcd/member/wal/0.tmp, ownerUser: 65532, ownerGroup: 65532 kind: pod name: etcd-events-0 namespace: shoot--diki-comp--aws  
                                                            containerName: backup-restore details: fileName: /var/lib/kubelet/pods/8500de88-870c-4453-a9d3-673fe2e83591/volumes/kubernetes.io~configmap/etcd-config-file/..2025_06_23_00_02_28.1474259460/etcd.conf.yaml, ownerUser: 0, ownerGroup: 65532 kind: pod name: etcd-events-0 namespace: shoot--diki-comp--aws  
                                                            containerName: backup-restore details: fileName: /var/lib/kubelet/pods/8500de88-870c-4453-a9d3-673fe2e83591/volumes/kubernetes.io~secret/backup-restore-server-tls/..2025_06_23_00_02_28.1357612372/tls.key, ownerUser: 0, ownerGroup: 65532 kind: pod name: etcd-events-0 namespace: shoot--diki-comp--aws  
                                                            containerName: backup-restore details: fileName: /var/lib/kubelet/pods/8500de88-870c-4453-a9d3-673fe2e83591/volumes/kubernetes.io~secret/backup-restore-server-tls/..2025_06_23_00_02_28.1357612372/tls.crt, ownerUser: 0, ownerGroup: 65532 kind: pod name: etcd-events-0 namespace: shoot--diki-comp--aws  
                                                            containerName: backup-restore details: fileName: /var/lib/kubelet/pods/8500de88-870c-4453-a9d3-673fe2e83591/volumes/kubernetes.io~secret/etcd-ca/..2025_06_23_00_02_28.1460198907/bundle.crt, ownerUser: 0, ownerGroup: 65532 kind: pod name: etcd-events-0 namespace: shoot--diki-comp--aws  
                                                            containerName: backup-restore details: fileName: /var/lib/kubelet/pods/8500de88-870c-4453-a9d3-673fe2e83591/volumes/kubernetes.io~secret/etcd-client-tls/..2025_06_23_00_02_28.830733358/tls.key, ownerUser: 0, ownerGroup: 65532 kind: pod name: etcd-events-0 namespace: shoot--diki-comp--aws  
                                                            containerName: backup-restore details: fileName: /var/lib/kubelet/pods/8500de88-870c-4453-a9d3-673fe2e83591/volumes/kubernetes.io~secret/etcd-client-tls/..2025_06_23_00_02_28.830733358/tls.crt, ownerUser: 0, ownerGroup: 65532 kind: pod name: etcd-events-0 namespace: shoot--diki-comp--aws  
                                                            containerName: backup-restore details: fileName: /var/lib/kubelet/pods/8500de88-870c-4453-a9d3-673fe2e83591/volumes/kubernetes.io~projected/kube-api-access-gardener/..2025_06_23_00_02_28.124882621/ca.crt, ownerUser: 0, ownerGroup: 65532 kind: pod name: etcd-events-0 namespace: shoot--diki-comp--aws  
                                                            containerName: backup-restore details: fileName: /var/lib/kubelet/pods/8500de88-870c-4453-a9d3-673fe2e83591/volumes/kubernetes.io~projected/kube-api-access-gardener/..2025_06_23_00_02_28.124882621/token, ownerUser: 65532, ownerGroup: 65532 kind: pod name: etcd-events-0 namespace: shoot--diki-comp--aws  
                                                            containerName: backup-restore details: fileName: /var/lib/kubelet/pods/8500de88-870c-4453-a9d3-673fe2e83591/volumes/kubernetes.io~projected/kube-api-access-gardener/..2025_06_23_00_02_28.124882621/namespace, ownerUser: 0, ownerGroup: 65532 kind: pod name: etcd-events-0 namespace: shoot--diki-comp--aws  
                                                         
                                                     
                                                    
                                                        azure 
                                                        
                                                            containerName: etcd details: fileName: /var/lib/kubelet/pods/d86b08b7-3d10-49ae-a4d6-4fe9fa757c93/volumes/kubernetes.io~csi/pv-shoot--garden--az-ha-eu1-08c488c5-a3a5-4c50-8a35-ef557f341224/mount/safe_guard, ownerUser: 65532, ownerGroup: 65532 kind: pod name: etcd-main-0 namespace: shoot--diki-comp--azure  
                                                            containerName: etcd details: fileName: /var/lib/kubelet/pods/d86b08b7-3d10-49ae-a4d6-4fe9fa757c93/volumes/kubernetes.io~csi/pv-shoot--garden--az-ha-eu1-08c488c5-a3a5-4c50-8a35-ef557f341224/mount/new.etcd/member/snap/db, ownerUser: 65532, ownerGroup: 65532 kind: pod name: etcd-main-0 namespace: shoot--diki-comp--azure  
                                                            containerName: etcd details: fileName: /var/lib/kubelet/pods/d86b08b7-3d10-49ae-a4d6-4fe9fa757c93/volumes/kubernetes.io~csi/pv-shoot--garden--az-ha-eu1-08c488c5-a3a5-4c50-8a35-ef557f341224/mount/new.etcd/member/wal/0.tmp, ownerUser: 65532, ownerGroup: 65532 kind: pod name: etcd-main-0 namespace: shoot--diki-comp--azure  
                                                            containerName: etcd details: fileName: /var/lib/kubelet/pods/d86b08b7-3d10-49ae-a4d6-4fe9fa757c93/volumes/kubernetes.io~csi/pv-shoot--garden--az-ha-eu1-08c488c5-a3a5-4c50-8a35-ef557f341224/mount/new.etcd/member/wal/0000000000000000-0000000000000000.wal, ownerUser: 65532, ownerGroup: 65532 kind: pod name: etcd-main-0 namespace: shoot--diki-comp--azure  
                                                            containerName: etcd details: fileName: /var/lib/kubelet/pods/d86b08b7-3d10-49ae-a4d6-4fe9fa757c93/volumes/kubernetes.io~secret/etcd-ca/..2025_06_23_00_02_37.231883813/bundle.crt, ownerUser: 0, ownerGroup: 65532 kind: pod name: etcd-main-0 namespace: shoot--diki-comp--azure  
                                                            containerName: etcd details: fileName: /var/lib/kubelet/pods/d86b08b7-3d10-49ae-a4d6-4fe9fa757c93/volumes/kubernetes.io~secret/etcd-server-tls/..2025_06_23_00_02_37.4111409223/tls.key, ownerUser: 0, ownerGroup: 65532 kind: pod name: etcd-main-0 namespace: shoot--diki-comp--azure  
                                                            containerName: etcd details: fileName: /var/lib/kubelet/pods/d86b08b7-3d10-49ae-a4d6-4fe9fa757c93/volumes/kubernetes.io~secret/etcd-server-tls/..2025_06_23_00_02_37.4111409223/tls.crt, ownerUser: 0, ownerGroup: 65532 kind: pod name: etcd-main-0 namespace: shoot--diki-comp--azure  
                                                            containerName: etcd details: fileName: /var/lib/kubelet/pods/d86b08b7-3d10-49ae-a4d6-4fe9fa757c93/volumes/kubernetes.io~secret/etcd-client-tls/..2025_06_23_00_02_37.256397641/tls.key, ownerUser: 0, ownerGroup: 65532 kind: pod name: etcd-main-0 namespace: shoot--diki-comp--azure  
                                                            containerName: etcd details: fileName: /var/lib/kubelet/pods/d86b08b7-3d10-49ae-a4d6-4fe9fa757c93/volumes/kubernetes.io~secret/etcd-client-tls/..2025_06_23_00_02_37.256397641/tls.crt, ownerUser: 0, ownerGroup: 65532 kind: pod name: etcd-main-0 namespace: shoot--diki-comp--azure  
                                                            containerName: etcd details: fileName: /var/lib/kubelet/pods/d86b08b7-3d10-49ae-a4d6-4fe9fa757c93/volumes/kubernetes.io~secret/backup-restore-ca/..2025_06_23_00_02_37.1332383038/bundle.crt, ownerUser: 0, ownerGroup: 65532 kind: pod name: etcd-main-0 namespace: shoot--diki-comp--azure  
                                                            containerName: etcd details: fileName: /var/lib/kubelet/pods/d86b08b7-3d10-49ae-a4d6-4fe9fa757c93/volumes/kubernetes.io~projected/kube-api-access-gardener/..2025_06_23_00_02_37.3272012549/namespace, ownerUser: 0, ownerGroup: 65532 kind: pod name: etcd-main-0 namespace: shoot--diki-comp--azure  
                                                            containerName: etcd details: fileName: /var/lib/kubelet/pods/d86b08b7-3d10-49ae-a4d6-4fe9fa757c93/volumes/kubernetes.io~projected/kube-api-access-gardener/..2025_06_23_00_02_37.3272012549/ca.crt, ownerUser: 0, ownerGroup: 65532 kind: pod name: etcd-main-0 namespace: shoot--diki-comp--azure  
                                                            containerName: etcd details: fileName: /var/lib/kubelet/pods/d86b08b7-3d10-49ae-a4d6-4fe9fa757c93/volumes/kubernetes.io~projected/kube-api-access-gardener/..2025_06_23_00_02_37.3272012549/token, ownerUser: 65532, ownerGroup: 65532 kind: pod name: etcd-main-0 namespace: shoot--diki-comp--azure  
                                                            containerName: backup-restore details: fileName: /var/lib/kubelet/pods/d86b08b7-3d10-49ae-a4d6-4fe9fa757c93/volumes/kubernetes.io~secret/etcd-backup-secret/..2025_06_23_00_02_37.2496710629/domain, ownerUser: 0, ownerGroup: 65532 kind: pod name: etcd-main-0 namespace: shoot--diki-comp--azure  
                                                            containerName: backup-restore details: fileName: /var/lib/kubelet/pods/d86b08b7-3d10-49ae-a4d6-4fe9fa757c93/volumes/kubernetes.io~secret/etcd-backup-secret/..2025_06_23_00_02_37.2496710629/bucketName, ownerUser: 0, ownerGroup: 65532 kind: pod name: etcd-main-0 namespace: shoot--diki-comp--azure  
                                                            containerName: backup-restore details: fileName: /var/lib/kubelet/pods/d86b08b7-3d10-49ae-a4d6-4fe9fa757c93/volumes/kubernetes.io~secret/etcd-backup-secret/..2025_06_23_00_02_37.2496710629/storageKey, ownerUser: 0, ownerGroup: 65532 kind: pod name: etcd-main-0 namespace: shoot--diki-comp--azure  
                                                            containerName: backup-restore details: fileName: /var/lib/kubelet/pods/d86b08b7-3d10-49ae-a4d6-4fe9fa757c93/volumes/kubernetes.io~secret/etcd-backup-secret/..2025_06_23_00_02_37.2496710629/storageAccount, ownerUser: 0, ownerGroup: 65532 kind: pod name: etcd-main-0 namespace: shoot--diki-comp--azure  
                                                            containerName: backup-restore details: fileName: /var/lib/kubelet/pods/d86b08b7-3d10-49ae-a4d6-4fe9fa757c93/volumes/kubernetes.io~csi/pv-shoot--garden--az-ha-eu1-08c488c5-a3a5-4c50-8a35-ef557f341224/mount/safe_guard, ownerUser: 65532, ownerGroup: 65532 kind: pod name: etcd-main-0 namespace: shoot--diki-comp--azure  
                                                            containerName: backup-restore details: fileName: /var/lib/kubelet/pods/d86b08b7-3d10-49ae-a4d6-4fe9fa757c93/volumes/kubernetes.io~csi/pv-shoot--garden--az-ha-eu1-08c488c5-a3a5-4c50-8a35-ef557f341224/mount/new.etcd/member/snap/db, ownerUser: 65532, ownerGroup: 65532 kind: pod name: etcd-main-0 namespace: shoot--diki-comp--azure  
                                                            containerName: backup-restore details: fileName: /var/lib/kubelet/pods/d86b08b7-3d10-49ae-a4d6-4fe9fa757c93/volumes/kubernetes.io~csi/pv-shoot--garden--az-ha-eu1-08c488c5-a3a5-4c50-8a35-ef557f341224/mount/new.etcd/member/wal/0.tmp, ownerUser: 65532, ownerGroup: 65532 kind: pod name: etcd-main-0 namespace: shoot--diki-comp--azure  
                                                            containerName: backup-restore details: fileName: /var/lib/kubelet/pods/d86b08b7-3d10-49ae-a4d6-4fe9fa757c93/volumes/kubernetes.io~csi/pv-shoot--garden--az-ha-eu1-08c488c5-a3a5-4c50-8a35-ef557f341224/mount/new.etcd/member/wal/0000000000000000-0000000000000000.wal, ownerUser: 65532, ownerGroup: 65532 kind: pod name: etcd-main-0 namespace: shoot--diki-comp--azure  
                                                            containerName: backup-restore details: fileName: /var/lib/kubelet/pods/d86b08b7-3d10-49ae-a4d6-4fe9fa757c93/volumes/kubernetes.io~configmap/etcd-config-file/..2025_06_23_00_02_37.3175801511/etcd.conf.yaml, ownerUser: 0, ownerGroup: 65532 kind: pod name: etcd-main-0 namespace: shoot--diki-comp--azure  
                                                            containerName: backup-restore details: fileName: /var/lib/kubelet/pods/d86b08b7-3d10-49ae-a4d6-4fe9fa757c93/volumes/kubernetes.io~secret/backup-restore-server-tls/..2025_06_23_00_02_37.2487232432/tls.key, ownerUser: 0, ownerGroup: 65532 kind: pod name: etcd-main-0 namespace: shoot--diki-comp--azure  
                                                            containerName: backup-restore details: fileName: /var/lib/kubelet/pods/d86b08b7-3d10-49ae-a4d6-4fe9fa757c93/volumes/kubernetes.io~secret/backup-restore-server-tls/..2025_06_23_00_02_37.2487232432/tls.crt, ownerUser: 0, ownerGroup: 65532 kind: pod name: etcd-main-0 namespace: shoot--diki-comp--azure  
                                                            containerName: backup-restore details: fileName: /var/lib/kubelet/pods/d86b08b7-3d10-49ae-a4d6-4fe9fa757c93/volumes/kubernetes.io~secret/etcd-ca/..2025_06_23_00_02_37.231883813/bundle.crt, ownerUser: 0, ownerGroup: 65532 kind: pod name: etcd-main-0 namespace: shoot--diki-comp--azure  
                                                            containerName: backup-restore details: fileName: /var/lib/kubelet/pods/d86b08b7-3d10-49ae-a4d6-4fe9fa757c93/volumes/kubernetes.io~secret/etcd-client-tls/..2025_06_23_00_02_37.256397641/tls.key, ownerUser: 0, ownerGroup: 65532 kind: pod name: etcd-main-0 namespace: shoot--diki-comp--azure  
                                                            containerName: backup-restore details: fileName: /var/lib/kubelet/pods/d86b08b7-3d10-49ae-a4d6-4fe9fa757c93/volumes/kubernetes.io~secret/etcd-client-tls/..2025_06_23_00_02_37.256397641/tls.crt, ownerUser: 0, ownerGroup: 65532 kind: pod name: etcd-main-0 namespace: shoot--diki-comp--azure  
                                                            containerName: backup-restore details: fileName: /var/lib/kubelet/pods/d86b08b7-3d10-49ae-a4d6-4fe9fa757c93/volumes/kubernetes.io~projected/kube-api-access-gardener/..2025_06_23_00_02_37.3272012549/namespace, ownerUser: 0, ownerGroup: 65532 kind: pod name: etcd-main-0 namespace: shoot--diki-comp--azure  
                                                            containerName: backup-restore details: fileName: /var/lib/kubelet/pods/d86b08b7-3d10-49ae-a4d6-4fe9fa757c93/volumes/kubernetes.io~projected/kube-api-access-gardener/..2025_06_23_00_02_37.3272012549/ca.crt, ownerUser: 0, ownerGroup: 65532 kind: pod name: etcd-main-0 namespace: shoot--diki-comp--azure  
                                                            containerName: backup-restore details: fileName: /var/lib/kubelet/pods/d86b08b7-3d10-49ae-a4d6-4fe9fa757c93/volumes/kubernetes.io~projected/kube-api-access-gardener/..2025_06_23_00_02_37.3272012549/token, ownerUser: 65532, ownerGroup: 65532 kind: pod name: etcd-main-0 namespace: shoot--diki-comp--azure  
                                                            containerName: etcd details: fileName: /var/lib/kubelet/pods/74f71030-9c73-40a7-b50e-fb1bb70cb9a5/volumes/kubernetes.io~csi/pv-shoot--garden--az-ha-eu1-e6a899bf-0a4c-4913-94ca-1434f1bee164/mount/new.etcd/member/wal/0.tmp, ownerUser: 65532, ownerGroup: 65532 kind: pod name: etcd-events-0 namespace: shoot--diki-comp--azure  
                                                            containerName: etcd details: fileName: /var/lib/kubelet/pods/74f71030-9c73-40a7-b50e-fb1bb70cb9a5/volumes/kubernetes.io~csi/pv-shoot--garden--az-ha-eu1-e6a899bf-0a4c-4913-94ca-1434f1bee164/mount/new.etcd/member/wal/0000000000000000-0000000000000000.wal, ownerUser: 65532, ownerGroup: 65532 kind: pod name: etcd-events-0 namespace: shoot--diki-comp--azure  
                                                            containerName: etcd details: fileName: /var/lib/kubelet/pods/74f71030-9c73-40a7-b50e-fb1bb70cb9a5/volumes/kubernetes.io~csi/pv-shoot--garden--az-ha-eu1-e6a899bf-0a4c-4913-94ca-1434f1bee164/mount/new.etcd/member/snap/db, ownerUser: 65532, ownerGroup: 65532 kind: pod name: etcd-events-0 namespace: shoot--diki-comp--azure  
                                                            containerName: etcd details: fileName: /var/lib/kubelet/pods/74f71030-9c73-40a7-b50e-fb1bb70cb9a5/volumes/kubernetes.io~csi/pv-shoot--garden--az-ha-eu1-e6a899bf-0a4c-4913-94ca-1434f1bee164/mount/safe_guard, ownerUser: 65532, ownerGroup: 65532 kind: pod name: etcd-events-0 namespace: shoot--diki-comp--azure  
                                                            containerName: etcd details: fileName: /var/lib/kubelet/pods/74f71030-9c73-40a7-b50e-fb1bb70cb9a5/volumes/kubernetes.io~secret/etcd-ca/..2025_06_23_00_02_36.1146945202/bundle.crt, ownerUser: 0, ownerGroup: 65532 kind: pod name: etcd-events-0 namespace: shoot--diki-comp--azure  
                                                            containerName: etcd details: fileName: /var/lib/kubelet/pods/74f71030-9c73-40a7-b50e-fb1bb70cb9a5/volumes/kubernetes.io~secret/etcd-server-tls/..2025_06_23_00_02_36.3673560748/tls.key, ownerUser: 0, ownerGroup: 65532 kind: pod name: etcd-events-0 namespace: shoot--diki-comp--azure  
                                                            containerName: etcd details: fileName: /var/lib/kubelet/pods/74f71030-9c73-40a7-b50e-fb1bb70cb9a5/volumes/kubernetes.io~secret/etcd-server-tls/..2025_06_23_00_02_36.3673560748/tls.crt, ownerUser: 0, ownerGroup: 65532 kind: pod name: etcd-events-0 namespace: shoot--diki-comp--azure  
                                                            containerName: etcd details: fileName: /var/lib/kubelet/pods/74f71030-9c73-40a7-b50e-fb1bb70cb9a5/volumes/kubernetes.io~secret/etcd-client-tls/..2025_06_23_00_02_36.3852713643/tls.crt, ownerUser: 0, ownerGroup: 65532 kind: pod name: etcd-events-0 namespace: shoot--diki-comp--azure  
                                                            containerName: etcd details: fileName: /var/lib/kubelet/pods/74f71030-9c73-40a7-b50e-fb1bb70cb9a5/volumes/kubernetes.io~secret/etcd-client-tls/..2025_06_23_00_02_36.3852713643/tls.key, ownerUser: 0, ownerGroup: 65532 kind: pod name: etcd-events-0 namespace: shoot--diki-comp--azure  
                                                            containerName: etcd details: fileName: /var/lib/kubelet/pods/74f71030-9c73-40a7-b50e-fb1bb70cb9a5/volumes/kubernetes.io~secret/backup-restore-ca/..2025_06_23_00_02_36.3194705379/bundle.crt, ownerUser: 0, ownerGroup: 65532 kind: pod name: etcd-events-0 namespace: shoot--diki-comp--azure  
                                                            containerName: etcd details: fileName: /var/lib/kubelet/pods/74f71030-9c73-40a7-b50e-fb1bb70cb9a5/volumes/kubernetes.io~projected/kube-api-access-gardener/..2025_06_23_00_02_36.662581379/ca.crt, ownerUser: 0, ownerGroup: 65532 kind: pod name: etcd-events-0 namespace: shoot--diki-comp--azure  
                                                            containerName: etcd details: fileName: /var/lib/kubelet/pods/74f71030-9c73-40a7-b50e-fb1bb70cb9a5/volumes/kubernetes.io~projected/kube-api-access-gardener/..2025_06_23_00_02_36.662581379/token, ownerUser: 65532, ownerGroup: 65532 kind: pod name: etcd-events-0 namespace: shoot--diki-comp--azure  
                                                            containerName: etcd details: fileName: /var/lib/kubelet/pods/74f71030-9c73-40a7-b50e-fb1bb70cb9a5/volumes/kubernetes.io~projected/kube-api-access-gardener/..2025_06_23_00_02_36.662581379/namespace, ownerUser: 0, ownerGroup: 65532 kind: pod name: etcd-events-0 namespace: shoot--diki-comp--azure  
                                                            containerName: backup-restore details: fileName: /var/lib/kubelet/pods/74f71030-9c73-40a7-b50e-fb1bb70cb9a5/volumes/kubernetes.io~csi/pv-shoot--garden--az-ha-eu1-e6a899bf-0a4c-4913-94ca-1434f1bee164/mount/new.etcd/member/wal/0.tmp, ownerUser: 65532, ownerGroup: 65532 kind: pod name: etcd-events-0 namespace: shoot--diki-comp--azure  
                                                            containerName: backup-restore details: fileName: /var/lib/kubelet/pods/74f71030-9c73-40a7-b50e-fb1bb70cb9a5/volumes/kubernetes.io~csi/pv-shoot--garden--az-ha-eu1-e6a899bf-0a4c-4913-94ca-1434f1bee164/mount/new.etcd/member/wal/0000000000000000-0000000000000000.wal, ownerUser: 65532, ownerGroup: 65532 kind: pod name: etcd-events-0 namespace: shoot--diki-comp--azure  
                                                            containerName: backup-restore details: fileName: /var/lib/kubelet/pods/74f71030-9c73-40a7-b50e-fb1bb70cb9a5/volumes/kubernetes.io~csi/pv-shoot--garden--az-ha-eu1-e6a899bf-0a4c-4913-94ca-1434f1bee164/mount/new.etcd/member/snap/db, ownerUser: 65532, ownerGroup: 65532 kind: pod name: etcd-events-0 namespace: shoot--diki-comp--azure  
                                                            containerName: backup-restore details: fileName: /var/lib/kubelet/pods/74f71030-9c73-40a7-b50e-fb1bb70cb9a5/volumes/kubernetes.io~csi/pv-shoot--garden--az-ha-eu1-e6a899bf-0a4c-4913-94ca-1434f1bee164/mount/safe_guard, ownerUser: 65532, ownerGroup: 65532 kind: pod name: etcd-events-0 namespace: shoot--diki-comp--azure  
                                                            containerName: backup-restore details: fileName: /var/lib/kubelet/pods/74f71030-9c73-40a7-b50e-fb1bb70cb9a5/volumes/kubernetes.io~configmap/etcd-config-file/..2025_06_23_00_02_36.261068025/etcd.conf.yaml, ownerUser: 0, ownerGroup: 65532 kind: pod name: etcd-events-0 namespace: shoot--diki-comp--azure  
                                                            containerName: backup-restore details: fileName: /var/lib/kubelet/pods/74f71030-9c73-40a7-b50e-fb1bb70cb9a5/volumes/kubernetes.io~secret/backup-restore-server-tls/..2025_06_23_00_02_36.327312203/tls.key, ownerUser: 0, ownerGroup: 65532 kind: pod name: etcd-events-0 namespace: shoot--diki-comp--azure  
                                                            containerName: backup-restore details: fileName: /var/lib/kubelet/pods/74f71030-9c73-40a7-b50e-fb1bb70cb9a5/volumes/kubernetes.io~secret/backup-restore-server-tls/..2025_06_23_00_02_36.327312203/tls.crt, ownerUser: 0, ownerGroup: 65532 kind: pod name: etcd-events-0 namespace: shoot--diki-comp--azure  
                                                            containerName: backup-restore details: fileName: /var/lib/kubelet/pods/74f71030-9c73-40a7-b50e-fb1bb70cb9a5/volumes/kubernetes.io~secret/etcd-ca/..2025_06_23_00_02_36.1146945202/bundle.crt, ownerUser: 0, ownerGroup: 65532 kind: pod name: etcd-events-0 namespace: shoot--diki-comp--azure  
                                                            containerName: backup-restore details: fileName: /var/lib/kubelet/pods/74f71030-9c73-40a7-b50e-fb1bb70cb9a5/volumes/kubernetes.io~secret/etcd-client-tls/..2025_06_23_00_02_36.3852713643/tls.crt, ownerUser: 0, ownerGroup: 65532 kind: pod name: etcd-events-0 namespace: shoot--diki-comp--azure  
                                                            containerName: backup-restore details: fileName: /var/lib/kubelet/pods/74f71030-9c73-40a7-b50e-fb1bb70cb9a5/volumes/kubernetes.io~secret/etcd-client-tls/..2025_06_23_00_02_36.3852713643/tls.key, ownerUser: 0, ownerGroup: 65532 kind: pod name: etcd-events-0 namespace: shoot--diki-comp--azure  
                                                            containerName: backup-restore details: fileName: /var/lib/kubelet/pods/74f71030-9c73-40a7-b50e-fb1bb70cb9a5/volumes/kubernetes.io~projected/kube-api-access-gardener/..2025_06_23_00_02_36.662581379/ca.crt, ownerUser: 0, ownerGroup: 65532 kind: pod name: etcd-events-0 namespace: shoot--diki-comp--azure  
                                                            containerName: backup-restore details: fileName: /var/lib/kubelet/pods/74f71030-9c73-40a7-b50e-fb1bb70cb9a5/volumes/kubernetes.io~projected/kube-api-access-gardener/..2025_06_23_00_02_36.662581379/token, ownerUser: 65532, ownerGroup: 65532 kind: pod name: etcd-events-0 namespace: shoot--diki-comp--azure  
                                                            containerName: backup-restore details: fileName: /var/lib/kubelet/pods/74f71030-9c73-40a7-b50e-fb1bb70cb9a5/volumes/kubernetes.io~projected/kube-api-access-gardener/..2025_06_23_00_02_36.662581379/namespace, ownerUser: 0, ownerGroup: 65532 kind: pod name: etcd-events-0 namespace: shoot--diki-comp--azure  
                                                         
                                                     
                                                    
                                                        gcp 
                                                        
                                                            containerName: etcd details: fileName: /var/lib/kubelet/pods/5b8aebf9-d079-4ec9-a1dc-f2e2adadf242/volumes/kubernetes.io~csi/pv--54a8efde-85c8-4138-af3a-952bd7394924/mount/safe_guard, ownerUser: 65532, ownerGroup: 65532 kind: pod name: etcd-main-0 namespace: shoot--diki-comp--gcp  
                                                            containerName: etcd details: fileName: /var/lib/kubelet/pods/5b8aebf9-d079-4ec9-a1dc-f2e2adadf242/volumes/kubernetes.io~csi/pv--54a8efde-85c8-4138-af3a-952bd7394924/mount/new.etcd/member/wal/0000000000000000-0000000000000000.wal, ownerUser: 65532, ownerGroup: 65532 kind: pod name: etcd-main-0 namespace: shoot--diki-comp--gcp  
                                                            containerName: etcd details: fileName: /var/lib/kubelet/pods/5b8aebf9-d079-4ec9-a1dc-f2e2adadf242/volumes/kubernetes.io~csi/pv--54a8efde-85c8-4138-af3a-952bd7394924/mount/new.etcd/member/wal/0.tmp, ownerUser: 65532, ownerGroup: 65532 kind: pod name: etcd-main-0 namespace: shoot--diki-comp--gcp  
                                                            containerName: etcd details: fileName: /var/lib/kubelet/pods/5b8aebf9-d079-4ec9-a1dc-f2e2adadf242/volumes/kubernetes.io~csi/pv--54a8efde-85c8-4138-af3a-952bd7394924/mount/new.etcd/member/snap/db, ownerUser: 65532, ownerGroup: 65532 kind: pod name: etcd-main-0 namespace: shoot--diki-comp--gcp  
                                                            containerName: etcd details: fileName: /var/lib/kubelet/pods/5b8aebf9-d079-4ec9-a1dc-f2e2adadf242/volumes/kubernetes.io~secret/etcd-ca/..2025_06_23_00_02_35.359863374/bundle.crt, ownerUser: 0, ownerGroup: 65532 kind: pod name: etcd-main-0 namespace: shoot--diki-comp--gcp  
                                                            containerName: etcd details: fileName: /var/lib/kubelet/pods/5b8aebf9-d079-4ec9-a1dc-f2e2adadf242/volumes/kubernetes.io~secret/etcd-server-tls/..2025_06_23_00_02_35.761653683/tls.crt, ownerUser: 0, ownerGroup: 65532 kind: pod name: etcd-main-0 namespace: shoot--diki-comp--gcp  
                                                            containerName: etcd details: fileName: /var/lib/kubelet/pods/5b8aebf9-d079-4ec9-a1dc-f2e2adadf242/volumes/kubernetes.io~secret/etcd-server-tls/..2025_06_23_00_02_35.761653683/tls.key, ownerUser: 0, ownerGroup: 65532 kind: pod name: etcd-main-0 namespace: shoot--diki-comp--gcp  
                                                            containerName: etcd details: fileName: /var/lib/kubelet/pods/5b8aebf9-d079-4ec9-a1dc-f2e2adadf242/volumes/kubernetes.io~secret/etcd-client-tls/..2025_06_23_00_02_35.270682216/tls.crt, ownerUser: 0, ownerGroup: 65532 kind: pod name: etcd-main-0 namespace: shoot--diki-comp--gcp  
                                                            containerName: etcd details: fileName: /var/lib/kubelet/pods/5b8aebf9-d079-4ec9-a1dc-f2e2adadf242/volumes/kubernetes.io~secret/etcd-client-tls/..2025_06_23_00_02_35.270682216/tls.key, ownerUser: 0, ownerGroup: 65532 kind: pod name: etcd-main-0 namespace: shoot--diki-comp--gcp  
                                                            containerName: etcd details: fileName: /var/lib/kubelet/pods/5b8aebf9-d079-4ec9-a1dc-f2e2adadf242/volumes/kubernetes.io~secret/backup-restore-ca/..2025_06_23_00_02_35.2072965808/bundle.crt, ownerUser: 0, ownerGroup: 65532 kind: pod name: etcd-main-0 namespace: shoot--diki-comp--gcp  
                                                            containerName: etcd details: fileName: /var/lib/kubelet/pods/5b8aebf9-d079-4ec9-a1dc-f2e2adadf242/volumes/kubernetes.io~projected/kube-api-access-gardener/..2025_06_23_00_02_35.3521445574/ca.crt, ownerUser: 0, ownerGroup: 65532 kind: pod name: etcd-main-0 namespace: shoot--diki-comp--gcp  
                                                            containerName: etcd details: fileName: /var/lib/kubelet/pods/5b8aebf9-d079-4ec9-a1dc-f2e2adadf242/volumes/kubernetes.io~projected/kube-api-access-gardener/..2025_06_23_00_02_35.3521445574/token, ownerUser: 65532, ownerGroup: 65532 kind: pod name: etcd-main-0 namespace: shoot--diki-comp--gcp  
                                                            containerName: etcd details: fileName: /var/lib/kubelet/pods/5b8aebf9-d079-4ec9-a1dc-f2e2adadf242/volumes/kubernetes.io~projected/kube-api-access-gardener/..2025_06_23_00_02_35.3521445574/namespace, ownerUser: 0, ownerGroup: 65532 kind: pod name: etcd-main-0 namespace: shoot--diki-comp--gcp  
                                                            containerName: backup-restore details: fileName: /var/lib/kubelet/pods/5b8aebf9-d079-4ec9-a1dc-f2e2adadf242/volumes/kubernetes.io~secret/etcd-backup-secret/..2025_06_23_00_02_35.4034996191/serviceaccount.json, ownerUser: 0, ownerGroup: 65532 kind: pod name: etcd-main-0 namespace: shoot--diki-comp--gcp  
                                                            containerName: backup-restore details: fileName: /var/lib/kubelet/pods/5b8aebf9-d079-4ec9-a1dc-f2e2adadf242/volumes/kubernetes.io~secret/etcd-backup-secret/..2025_06_23_00_02_35.4034996191/bucketName, ownerUser: 0, ownerGroup: 65532 kind: pod name: etcd-main-0 namespace: shoot--diki-comp--gcp  
                                                            containerName: backup-restore details: fileName: /var/lib/kubelet/pods/5b8aebf9-d079-4ec9-a1dc-f2e2adadf242/volumes/kubernetes.io~csi/pv--54a8efde-85c8-4138-af3a-952bd7394924/mount/safe_guard, ownerUser: 65532, ownerGroup: 65532 kind: pod name: etcd-main-0 namespace: shoot--diki-comp--gcp  
                                                            containerName: backup-restore details: fileName: /var/lib/kubelet/pods/5b8aebf9-d079-4ec9-a1dc-f2e2adadf242/volumes/kubernetes.io~csi/pv--54a8efde-85c8-4138-af3a-952bd7394924/mount/new.etcd/member/wal/0000000000000000-0000000000000000.wal, ownerUser: 65532, ownerGroup: 65532 kind: pod name: etcd-main-0 namespace: shoot--diki-comp--gcp  
                                                            containerName: backup-restore details: fileName: /var/lib/kubelet/pods/5b8aebf9-d079-4ec9-a1dc-f2e2adadf242/volumes/kubernetes.io~csi/pv--54a8efde-85c8-4138-af3a-952bd7394924/mount/new.etcd/member/wal/0.tmp, ownerUser: 65532, ownerGroup: 65532 kind: pod name: etcd-main-0 namespace: shoot--diki-comp--gcp  
                                                            containerName: backup-restore details: fileName: /var/lib/kubelet/pods/5b8aebf9-d079-4ec9-a1dc-f2e2adadf242/volumes/kubernetes.io~csi/pv--54a8efde-85c8-4138-af3a-952bd7394924/mount/new.etcd/member/snap/db, ownerUser: 65532, ownerGroup: 65532 kind: pod name: etcd-main-0 namespace: shoot--diki-comp--gcp  
                                                            containerName: backup-restore details: fileName: /var/lib/kubelet/pods/5b8aebf9-d079-4ec9-a1dc-f2e2adadf242/volumes/kubernetes.io~configmap/etcd-config-file/..2025_06_23_00_02_35.1894821196/etcd.conf.yaml, ownerUser: 0, ownerGroup: 65532 kind: pod name: etcd-main-0 namespace: shoot--diki-comp--gcp  
                                                            containerName: backup-restore details: fileName: /var/lib/kubelet/pods/5b8aebf9-d079-4ec9-a1dc-f2e2adadf242/volumes/kubernetes.io~secret/backup-restore-server-tls/..2025_06_23_00_02_35.1035566417/tls.key, ownerUser: 0, ownerGroup: 65532 kind: pod name: etcd-main-0 namespace: shoot--diki-comp--gcp  
                                                            containerName: backup-restore details: fileName: /var/lib/kubelet/pods/5b8aebf9-d079-4ec9-a1dc-f2e2adadf242/volumes/kubernetes.io~secret/backup-restore-server-tls/..2025_06_23_00_02_35.1035566417/tls.crt, ownerUser: 0, ownerGroup: 65532 kind: pod name: etcd-main-0 namespace: shoot--diki-comp--gcp  
                                                            containerName: backup-restore details: fileName: /var/lib/kubelet/pods/5b8aebf9-d079-4ec9-a1dc-f2e2adadf242/volumes/kubernetes.io~secret/etcd-ca/..2025_06_23_00_02_35.359863374/bundle.crt, ownerUser: 0, ownerGroup: 65532 kind: pod name: etcd-main-0 namespace: shoot--diki-comp--gcp  
                                                            containerName: backup-restore details: fileName: /var/lib/kubelet/pods/5b8aebf9-d079-4ec9-a1dc-f2e2adadf242/volumes/kubernetes.io~secret/etcd-client-tls/..2025_06_23_00_02_35.270682216/tls.crt, ownerUser: 0, ownerGroup: 65532 kind: pod name: etcd-main-0 namespace: shoot--diki-comp--gcp  
                                                            containerName: backup-restore details: fileName: /var/lib/kubelet/pods/5b8aebf9-d079-4ec9-a1dc-f2e2adadf242/volumes/kubernetes.io~secret/etcd-client-tls/..2025_06_23_00_02_35.270682216/tls.key, ownerUser: 0, ownerGroup: 65532 kind: pod name: etcd-main-0 namespace: shoot--diki-comp--gcp  
                                                            containerName: backup-restore details: fileName: /var/lib/kubelet/pods/5b8aebf9-d079-4ec9-a1dc-f2e2adadf242/volumes/kubernetes.io~projected/kube-api-access-gardener/..2025_06_23_00_02_35.3521445574/ca.crt, ownerUser: 0, ownerGroup: 65532 kind: pod name: etcd-main-0 namespace: shoot--diki-comp--gcp  
                                                            containerName: backup-restore details: fileName: /var/lib/kubelet/pods/5b8aebf9-d079-4ec9-a1dc-f2e2adadf242/volumes/kubernetes.io~projected/kube-api-access-gardener/..2025_06_23_00_02_35.3521445574/token, ownerUser: 65532, ownerGroup: 65532 kind: pod name: etcd-main-0 namespace: shoot--diki-comp--gcp  
                                                            containerName: backup-restore details: fileName: /var/lib/kubelet/pods/5b8aebf9-d079-4ec9-a1dc-f2e2adadf242/volumes/kubernetes.io~projected/kube-api-access-gardener/..2025_06_23_00_02_35.3521445574/namespace, ownerUser: 0, ownerGroup: 65532 kind: pod name: etcd-main-0 namespace: shoot--diki-comp--gcp  
                                                            containerName: etcd details: fileName: /var/lib/kubelet/pods/56b8ee4f-315f-4054-af24-a9fd2f484963/volumes/kubernetes.io~csi/pv--2a07e1f1-b1e9-46ed-a639-a3b1fd1434b4/mount/new.etcd/member/wal/0000000000000000-0000000000000000.wal, ownerUser: 65532, ownerGroup: 65532 kind: pod name: etcd-events-0 namespace: shoot--diki-comp--gcp  
                                                            containerName: etcd details: fileName: /var/lib/kubelet/pods/56b8ee4f-315f-4054-af24-a9fd2f484963/volumes/kubernetes.io~csi/pv--2a07e1f1-b1e9-46ed-a639-a3b1fd1434b4/mount/new.etcd/member/wal/0.tmp, ownerUser: 65532, ownerGroup: 65532 kind: pod name: etcd-events-0 namespace: shoot--diki-comp--gcp  
                                                            containerName: etcd details: fileName: /var/lib/kubelet/pods/56b8ee4f-315f-4054-af24-a9fd2f484963/volumes/kubernetes.io~csi/pv--2a07e1f1-b1e9-46ed-a639-a3b1fd1434b4/mount/new.etcd/member/snap/db, ownerUser: 65532, ownerGroup: 65532 kind: pod name: etcd-events-0 namespace: shoot--diki-comp--gcp  
                                                            containerName: etcd details: fileName: /var/lib/kubelet/pods/56b8ee4f-315f-4054-af24-a9fd2f484963/volumes/kubernetes.io~csi/pv--2a07e1f1-b1e9-46ed-a639-a3b1fd1434b4/mount/safe_guard, ownerUser: 65532, ownerGroup: 65532 kind: pod name: etcd-events-0 namespace: shoot--diki-comp--gcp  
                                                            containerName: etcd details: fileName: /var/lib/kubelet/pods/56b8ee4f-315f-4054-af24-a9fd2f484963/volumes/kubernetes.io~secret/etcd-ca/..2025_06_23_00_02_35.3098522537/bundle.crt, ownerUser: 0, ownerGroup: 65532 kind: pod name: etcd-events-0 namespace: shoot--diki-comp--gcp  
                                                            containerName: etcd details: fileName: /var/lib/kubelet/pods/56b8ee4f-315f-4054-af24-a9fd2f484963/volumes/kubernetes.io~secret/etcd-server-tls/..2025_06_23_00_02_35.3565116838/tls.key, ownerUser: 0, ownerGroup: 65532 kind: pod name: etcd-events-0 namespace: shoot--diki-comp--gcp  
                                                            containerName: etcd details: fileName: /var/lib/kubelet/pods/56b8ee4f-315f-4054-af24-a9fd2f484963/volumes/kubernetes.io~secret/etcd-server-tls/..2025_06_23_00_02_35.3565116838/tls.crt, ownerUser: 0, ownerGroup: 65532 kind: pod name: etcd-events-0 namespace: shoot--diki-comp--gcp  
                                                            containerName: etcd details: fileName: /var/lib/kubelet/pods/56b8ee4f-315f-4054-af24-a9fd2f484963/volumes/kubernetes.io~secret/etcd-client-tls/..2025_06_23_00_02_35.3308771745/tls.key, ownerUser: 0, ownerGroup: 65532 kind: pod name: etcd-events-0 namespace: shoot--diki-comp--gcp  
                                                            containerName: etcd details: fileName: /var/lib/kubelet/pods/56b8ee4f-315f-4054-af24-a9fd2f484963/volumes/kubernetes.io~secret/etcd-client-tls/..2025_06_23_00_02_35.3308771745/tls.crt, ownerUser: 0, ownerGroup: 65532 kind: pod name: etcd-events-0 namespace: shoot--diki-comp--gcp  
                                                            containerName: etcd details: fileName: /var/lib/kubelet/pods/56b8ee4f-315f-4054-af24-a9fd2f484963/volumes/kubernetes.io~secret/backup-restore-ca/..2025_06_23_00_02_35.4083445152/bundle.crt, ownerUser: 0, ownerGroup: 65532 kind: pod name: etcd-events-0 namespace: shoot--diki-comp--gcp  
                                                            containerName: etcd details: fileName: /var/lib/kubelet/pods/56b8ee4f-315f-4054-af24-a9fd2f484963/volumes/kubernetes.io~projected/kube-api-access-gardener/..2025_06_23_00_02_35.4217059112/namespace, ownerUser: 0, ownerGroup: 65532 kind: pod name: etcd-events-0 namespace: shoot--diki-comp--gcp  
                                                            containerName: etcd details: fileName: /var/lib/kubelet/pods/56b8ee4f-315f-4054-af24-a9fd2f484963/volumes/kubernetes.io~projected/kube-api-access-gardener/..2025_06_23_00_02_35.4217059112/ca.crt, ownerUser: 0, ownerGroup: 65532 kind: pod name: etcd-events-0 namespace: shoot--diki-comp--gcp  
                                                            containerName: etcd details: fileName: /var/lib/kubelet/pods/56b8ee4f-315f-4054-af24-a9fd2f484963/volumes/kubernetes.io~projected/kube-api-access-gardener/..2025_06_23_00_02_35.4217059112/token, ownerUser: 65532, ownerGroup: 65532 kind: pod name: etcd-events-0 namespace: shoot--diki-comp--gcp  
                                                            containerName: backup-restore details: fileName: /var/lib/kubelet/pods/56b8ee4f-315f-4054-af24-a9fd2f484963/volumes/kubernetes.io~csi/pv--2a07e1f1-b1e9-46ed-a639-a3b1fd1434b4/mount/new.etcd/member/wal/0000000000000000-0000000000000000.wal, ownerUser: 65532, ownerGroup: 65532 kind: pod name: etcd-events-0 namespace: shoot--diki-comp--gcp  
                                                            containerName: backup-restore details: fileName: /var/lib/kubelet/pods/56b8ee4f-315f-4054-af24-a9fd2f484963/volumes/kubernetes.io~csi/pv--2a07e1f1-b1e9-46ed-a639-a3b1fd1434b4/mount/new.etcd/member/wal/0.tmp, ownerUser: 65532, ownerGroup: 65532 kind: pod name: etcd-events-0 namespace: shoot--diki-comp--gcp  
                                                            containerName: backup-restore details: fileName: /var/lib/kubelet/pods/56b8ee4f-315f-4054-af24-a9fd2f484963/volumes/kubernetes.io~csi/pv--2a07e1f1-b1e9-46ed-a639-a3b1fd1434b4/mount/new.etcd/member/snap/db, ownerUser: 65532, ownerGroup: 65532 kind: pod name: etcd-events-0 namespace: shoot--diki-comp--gcp  
                                                            containerName: backup-restore details: fileName: /var/lib/kubelet/pods/56b8ee4f-315f-4054-af24-a9fd2f484963/volumes/kubernetes.io~csi/pv--2a07e1f1-b1e9-46ed-a639-a3b1fd1434b4/mount/safe_guard, ownerUser: 65532, ownerGroup: 65532 kind: pod name: etcd-events-0 namespace: shoot--diki-comp--gcp  
                                                            containerName: backup-restore details: fileName: /var/lib/kubelet/pods/56b8ee4f-315f-4054-af24-a9fd2f484963/volumes/kubernetes.io~configmap/etcd-config-file/..2025_06_23_00_02_35.261387052/etcd.conf.yaml, ownerUser: 0, ownerGroup: 65532 kind: pod name: etcd-events-0 namespace: shoot--diki-comp--gcp  
                                                            containerName: backup-restore details: fileName: /var/lib/kubelet/pods/56b8ee4f-315f-4054-af24-a9fd2f484963/volumes/kubernetes.io~secret/backup-restore-server-tls/..2025_06_23_00_02_35.375113374/tls.crt, ownerUser: 0, ownerGroup: 65532 kind: pod name: etcd-events-0 namespace: shoot--diki-comp--gcp  
                                                            containerName: backup-restore details: fileName: /var/lib/kubelet/pods/56b8ee4f-315f-4054-af24-a9fd2f484963/volumes/kubernetes.io~secret/backup-restore-server-tls/..2025_06_23_00_02_35.375113374/tls.key, ownerUser: 0, ownerGroup: 65532 kind: pod name: etcd-events-0 namespace: shoot--diki-comp--gcp  
                                                            containerName: backup-restore details: fileName: /var/lib/kubelet/pods/56b8ee4f-315f-4054-af24-a9fd2f484963/volumes/kubernetes.io~secret/etcd-ca/..2025_06_23_00_02_35.3098522537/bundle.crt, ownerUser: 0, ownerGroup: 65532 kind: pod name: etcd-events-0 namespace: shoot--diki-comp--gcp  
                                                            containerName: backup-restore details: fileName: /var/lib/kubelet/pods/56b8ee4f-315f-4054-af24-a9fd2f484963/volumes/kubernetes.io~secret/etcd-client-tls/..2025_06_23_00_02_35.3308771745/tls.key, ownerUser: 0, ownerGroup: 65532 kind: pod name: etcd-events-0 namespace: shoot--diki-comp--gcp  
                                                            containerName: backup-restore details: fileName: /var/lib/kubelet/pods/56b8ee4f-315f-4054-af24-a9fd2f484963/volumes/kubernetes.io~secret/etcd-client-tls/..2025_06_23_00_02_35.3308771745/tls.crt, ownerUser: 0, ownerGroup: 65532 kind: pod name: etcd-events-0 namespace: shoot--diki-comp--gcp  
                                                            containerName: backup-restore details: fileName: /var/lib/kubelet/pods/56b8ee4f-315f-4054-af24-a9fd2f484963/volumes/kubernetes.io~projected/kube-api-access-gardener/..2025_06_23_00_02_35.4217059112/namespace, ownerUser: 0, ownerGroup: 65532 kind: pod name: etcd-events-0 namespace: shoot--diki-comp--gcp  
                                                            containerName: backup-restore details: fileName: /var/lib/kubelet/pods/56b8ee4f-315f-4054-af24-a9fd2f484963/volumes/kubernetes.io~projected/kube-api-access-gardener/..2025_06_23_00_02_35.4217059112/ca.crt, ownerUser: 0, ownerGroup: 65532 kind: pod name: etcd-events-0 namespace: shoot--diki-comp--gcp  
                                                            containerName: backup-restore details: fileName: /var/lib/kubelet/pods/56b8ee4f-315f-4054-af24-a9fd2f484963/volumes/kubernetes.io~projected/kube-api-access-gardener/..2025_06_23_00_02_35.4217059112/token, ownerUser: 65532, ownerGroup: 65532 kind: pod name: etcd-events-0 namespace: shoot--diki-comp--gcp  
                                                         
                                                     
                                                    
                                                        openstack 
                                                        
                                                            containerName: etcd details: fileName: /var/lib/kubelet/pods/7d71941f-a963-401d-b0e0-28ed7592fe7d/volumes/kubernetes.io~csi/pv-shoot--garden--cc-ha-eu1-dade4d52-dcc4-4f13-9aa3-6ca013d1bc55/mount/new.etcd/member/snap/db, ownerUser: 65532, ownerGroup: 65532 kind: pod name: etcd-main-0 namespace: shoot--diki-comp--openstack  
                                                            containerName: etcd details: fileName: /var/lib/kubelet/pods/7d71941f-a963-401d-b0e0-28ed7592fe7d/volumes/kubernetes.io~csi/pv-shoot--garden--cc-ha-eu1-dade4d52-dcc4-4f13-9aa3-6ca013d1bc55/mount/new.etcd/member/wal/0.tmp, ownerUser: 65532, ownerGroup: 65532 kind: pod name: etcd-main-0 namespace: shoot--diki-comp--openstack  
                                                            containerName: etcd details: fileName: /var/lib/kubelet/pods/7d71941f-a963-401d-b0e0-28ed7592fe7d/volumes/kubernetes.io~csi/pv-shoot--garden--cc-ha-eu1-dade4d52-dcc4-4f13-9aa3-6ca013d1bc55/mount/new.etcd/member/wal/0000000000000000-0000000000000000.wal, ownerUser: 65532, ownerGroup: 65532 kind: pod name: etcd-main-0 namespace: shoot--diki-comp--openstack  
                                                            containerName: etcd details: fileName: /var/lib/kubelet/pods/7d71941f-a963-401d-b0e0-28ed7592fe7d/volumes/kubernetes.io~csi/pv-shoot--garden--cc-ha-eu1-dade4d52-dcc4-4f13-9aa3-6ca013d1bc55/mount/safe_guard, ownerUser: 65532, ownerGroup: 65532 kind: pod name: etcd-main-0 namespace: shoot--diki-comp--openstack  
                                                            containerName: etcd details: fileName: /var/lib/kubelet/pods/7d71941f-a963-401d-b0e0-28ed7592fe7d/volumes/kubernetes.io~secret/etcd-ca/..2025_06_23_00_02_39.4052105237/bundle.crt, ownerUser: 0, ownerGroup: 65532 kind: pod name: etcd-main-0 namespace: shoot--diki-comp--openstack  
                                                            containerName: etcd details: fileName: /var/lib/kubelet/pods/7d71941f-a963-401d-b0e0-28ed7592fe7d/volumes/kubernetes.io~secret/etcd-server-tls/..2025_06_23_00_02_39.149437060/tls.key, ownerUser: 0, ownerGroup: 65532 kind: pod name: etcd-main-0 namespace: shoot--diki-comp--openstack  
                                                            containerName: etcd details: fileName: /var/lib/kubelet/pods/7d71941f-a963-401d-b0e0-28ed7592fe7d/volumes/kubernetes.io~secret/etcd-server-tls/..2025_06_23_00_02_39.149437060/tls.crt, ownerUser: 0, ownerGroup: 65532 kind: pod name: etcd-main-0 namespace: shoot--diki-comp--openstack  
                                                            containerName: etcd details: fileName: /var/lib/kubelet/pods/7d71941f-a963-401d-b0e0-28ed7592fe7d/volumes/kubernetes.io~secret/etcd-client-tls/..2025_06_23_00_02_39.296248316/tls.crt, ownerUser: 0, ownerGroup: 65532 kind: pod name: etcd-main-0 namespace: shoot--diki-comp--openstack  
                                                            containerName: etcd details: fileName: /var/lib/kubelet/pods/7d71941f-a963-401d-b0e0-28ed7592fe7d/volumes/kubernetes.io~secret/etcd-client-tls/..2025_06_23_00_02_39.296248316/tls.key, ownerUser: 0, ownerGroup: 65532 kind: pod name: etcd-main-0 namespace: shoot--diki-comp--openstack  
                                                            containerName: etcd details: fileName: /var/lib/kubelet/pods/7d71941f-a963-401d-b0e0-28ed7592fe7d/volumes/kubernetes.io~secret/backup-restore-ca/..2025_06_23_00_02_39.2679800161/bundle.crt, ownerUser: 0, ownerGroup: 65532 kind: pod name: etcd-main-0 namespace: shoot--diki-comp--openstack  
                                                            containerName: etcd details: fileName: /var/lib/kubelet/pods/7d71941f-a963-401d-b0e0-28ed7592fe7d/volumes/kubernetes.io~projected/kube-api-access-gardener/..2025_06_23_00_02_39.1703787134/ca.crt, ownerUser: 0, ownerGroup: 65532 kind: pod name: etcd-main-0 namespace: shoot--diki-comp--openstack  
                                                            containerName: etcd details: fileName: /var/lib/kubelet/pods/7d71941f-a963-401d-b0e0-28ed7592fe7d/volumes/kubernetes.io~projected/kube-api-access-gardener/..2025_06_23_00_02_39.1703787134/token, ownerUser: 65532, ownerGroup: 65532 kind: pod name: etcd-main-0 namespace: shoot--diki-comp--openstack  
                                                            containerName: etcd details: fileName: /var/lib/kubelet/pods/7d71941f-a963-401d-b0e0-28ed7592fe7d/volumes/kubernetes.io~projected/kube-api-access-gardener/..2025_06_23_00_02_39.1703787134/namespace, ownerUser: 0, ownerGroup: 65532 kind: pod name: etcd-main-0 namespace: shoot--diki-comp--openstack  
                                                            containerName: backup-restore details: fileName: /var/lib/kubelet/pods/7d71941f-a963-401d-b0e0-28ed7592fe7d/volumes/kubernetes.io~secret/etcd-backup-secret/..2025_06_23_00_02_39.2738667413/applicationCredentialName, ownerUser: 0, ownerGroup: 65532 kind: pod name: etcd-main-0 namespace: shoot--diki-comp--openstack  
                                                            containerName: backup-restore details: fileName: /var/lib/kubelet/pods/7d71941f-a963-401d-b0e0-28ed7592fe7d/volumes/kubernetes.io~secret/etcd-backup-secret/..2025_06_23_00_02_39.2738667413/applicationCredentialID, ownerUser: 0, ownerGroup: 65532 kind: pod name: etcd-main-0 namespace: shoot--diki-comp--openstack  
                                                            containerName: backup-restore details: fileName: /var/lib/kubelet/pods/7d71941f-a963-401d-b0e0-28ed7592fe7d/volumes/kubernetes.io~secret/etcd-backup-secret/..2025_06_23_00_02_39.2738667413/tenantName, ownerUser: 0, ownerGroup: 65532 kind: pod name: etcd-main-0 namespace: shoot--diki-comp--openstack  
                                                            containerName: backup-restore details: fileName: /var/lib/kubelet/pods/7d71941f-a963-401d-b0e0-28ed7592fe7d/volumes/kubernetes.io~secret/etcd-backup-secret/..2025_06_23_00_02_39.2738667413/region, ownerUser: 0, ownerGroup: 65532 kind: pod name: etcd-main-0 namespace: shoot--diki-comp--openstack  
                                                            containerName: backup-restore details: fileName: /var/lib/kubelet/pods/7d71941f-a963-401d-b0e0-28ed7592fe7d/volumes/kubernetes.io~secret/etcd-backup-secret/..2025_06_23_00_02_39.2738667413/domainName, ownerUser: 0, ownerGroup: 65532 kind: pod name: etcd-main-0 namespace: shoot--diki-comp--openstack  
                                                            containerName: backup-restore details: fileName: /var/lib/kubelet/pods/7d71941f-a963-401d-b0e0-28ed7592fe7d/volumes/kubernetes.io~secret/etcd-backup-secret/..2025_06_23_00_02_39.2738667413/bucketName, ownerUser: 0, ownerGroup: 65532 kind: pod name: etcd-main-0 namespace: shoot--diki-comp--openstack  
                                                            containerName: backup-restore details: fileName: /var/lib/kubelet/pods/7d71941f-a963-401d-b0e0-28ed7592fe7d/volumes/kubernetes.io~secret/etcd-backup-secret/..2025_06_23_00_02_39.2738667413/authURL, ownerUser: 0, ownerGroup: 65532 kind: pod name: etcd-main-0 namespace: shoot--diki-comp--openstack  
                                                            containerName: backup-restore details: fileName: /var/lib/kubelet/pods/7d71941f-a963-401d-b0e0-28ed7592fe7d/volumes/kubernetes.io~secret/etcd-backup-secret/..2025_06_23_00_02_39.2738667413/applicationCredentialSecret, ownerUser: 0, ownerGroup: 65532 kind: pod name: etcd-main-0 namespace: shoot--diki-comp--openstack  
                                                            containerName: backup-restore details: fileName: /var/lib/kubelet/pods/7d71941f-a963-401d-b0e0-28ed7592fe7d/volumes/kubernetes.io~csi/pv-shoot--garden--cc-ha-eu1-dade4d52-dcc4-4f13-9aa3-6ca013d1bc55/mount/new.etcd/member/snap/db, ownerUser: 65532, ownerGroup: 65532 kind: pod name: etcd-main-0 namespace: shoot--diki-comp--openstack  
                                                            containerName: backup-restore details: fileName: /var/lib/kubelet/pods/7d71941f-a963-401d-b0e0-28ed7592fe7d/volumes/kubernetes.io~csi/pv-shoot--garden--cc-ha-eu1-dade4d52-dcc4-4f13-9aa3-6ca013d1bc55/mount/new.etcd/member/wal/0.tmp, ownerUser: 65532, ownerGroup: 65532 kind: pod name: etcd-main-0 namespace: shoot--diki-comp--openstack  
                                                            containerName: backup-restore details: fileName: /var/lib/kubelet/pods/7d71941f-a963-401d-b0e0-28ed7592fe7d/volumes/kubernetes.io~csi/pv-shoot--garden--cc-ha-eu1-dade4d52-dcc4-4f13-9aa3-6ca013d1bc55/mount/new.etcd/member/wal/0000000000000000-0000000000000000.wal, ownerUser: 65532, ownerGroup: 65532 kind: pod name: etcd-main-0 namespace: shoot--diki-comp--openstack  
                                                            containerName: backup-restore details: fileName: /var/lib/kubelet/pods/7d71941f-a963-401d-b0e0-28ed7592fe7d/volumes/kubernetes.io~csi/pv-shoot--garden--cc-ha-eu1-dade4d52-dcc4-4f13-9aa3-6ca013d1bc55/mount/safe_guard, ownerUser: 65532, ownerGroup: 65532 kind: pod name: etcd-main-0 namespace: shoot--diki-comp--openstack  
                                                            containerName: backup-restore details: fileName: /var/lib/kubelet/pods/7d71941f-a963-401d-b0e0-28ed7592fe7d/volumes/kubernetes.io~configmap/etcd-config-file/..2025_06_23_00_02_39.532503070/etcd.conf.yaml, ownerUser: 0, ownerGroup: 65532 kind: pod name: etcd-main-0 namespace: shoot--diki-comp--openstack  
                                                            containerName: backup-restore details: fileName: /var/lib/kubelet/pods/7d71941f-a963-401d-b0e0-28ed7592fe7d/volumes/kubernetes.io~secret/backup-restore-server-tls/..2025_06_23_00_02_39.456523922/tls.key, ownerUser: 0, ownerGroup: 65532 kind: pod name: etcd-main-0 namespace: shoot--diki-comp--openstack  
                                                            containerName: backup-restore details: fileName: /var/lib/kubelet/pods/7d71941f-a963-401d-b0e0-28ed7592fe7d/volumes/kubernetes.io~secret/backup-restore-server-tls/..2025_06_23_00_02_39.456523922/tls.crt, ownerUser: 0, ownerGroup: 65532 kind: pod name: etcd-main-0 namespace: shoot--diki-comp--openstack  
                                                            containerName: backup-restore details: fileName: /var/lib/kubelet/pods/7d71941f-a963-401d-b0e0-28ed7592fe7d/volumes/kubernetes.io~secret/etcd-ca/..2025_06_23_00_02_39.4052105237/bundle.crt, ownerUser: 0, ownerGroup: 65532 kind: pod name: etcd-main-0 namespace: shoot--diki-comp--openstack  
                                                            containerName: backup-restore details: fileName: /var/lib/kubelet/pods/7d71941f-a963-401d-b0e0-28ed7592fe7d/volumes/kubernetes.io~secret/etcd-client-tls/..2025_06_23_00_02_39.296248316/tls.crt, ownerUser: 0, ownerGroup: 65532 kind: pod name: etcd-main-0 namespace: shoot--diki-comp--openstack  
                                                            containerName: backup-restore details: fileName: /var/lib/kubelet/pods/7d71941f-a963-401d-b0e0-28ed7592fe7d/volumes/kubernetes.io~secret/etcd-client-tls/..2025_06_23_00_02_39.296248316/tls.key, ownerUser: 0, ownerGroup: 65532 kind: pod name: etcd-main-0 namespace: shoot--diki-comp--openstack  
                                                            containerName: backup-restore details: fileName: /var/lib/kubelet/pods/7d71941f-a963-401d-b0e0-28ed7592fe7d/volumes/kubernetes.io~projected/kube-api-access-gardener/..2025_06_23_00_02_39.1703787134/ca.crt, ownerUser: 0, ownerGroup: 65532 kind: pod name: etcd-main-0 namespace: shoot--diki-comp--openstack  
                                                            containerName: backup-restore details: fileName: /var/lib/kubelet/pods/7d71941f-a963-401d-b0e0-28ed7592fe7d/volumes/kubernetes.io~projected/kube-api-access-gardener/..2025_06_23_00_02_39.1703787134/token, ownerUser: 65532, ownerGroup: 65532 kind: pod name: etcd-main-0 namespace: shoot--diki-comp--openstack  
                                                            containerName: backup-restore details: fileName: /var/lib/kubelet/pods/7d71941f-a963-401d-b0e0-28ed7592fe7d/volumes/kubernetes.io~projected/kube-api-access-gardener/..2025_06_23_00_02_39.1703787134/namespace, ownerUser: 0, ownerGroup: 65532 kind: pod name: etcd-main-0 namespace: shoot--diki-comp--openstack  
                                                            containerName: backup-restore details: fileName: /var/lib/kubelet/pods/9c7e7507-c95f-4034-bb45-54d9a5a0061e/volumes/kubernetes.io~csi/pv-shoot--garden--cc-ha-eu1-c71d53d4-69ee-460e-8ef0-1d320b26975c/mount/safe_guard, ownerUser: 65532, ownerGroup: 65532 kind: pod name: etcd-events-0 namespace: shoot--diki-comp--openstack  
                                                            containerName: backup-restore details: fileName: /var/lib/kubelet/pods/9c7e7507-c95f-4034-bb45-54d9a5a0061e/volumes/kubernetes.io~csi/pv-shoot--garden--cc-ha-eu1-c71d53d4-69ee-460e-8ef0-1d320b26975c/mount/new.etcd/member/wal/0000000000000000-0000000000000000.wal, ownerUser: 65532, ownerGroup: 65532 kind: pod name: etcd-events-0 namespace: shoot--diki-comp--openstack  
                                                            containerName: backup-restore details: fileName: /var/lib/kubelet/pods/9c7e7507-c95f-4034-bb45-54d9a5a0061e/volumes/kubernetes.io~csi/pv-shoot--garden--cc-ha-eu1-c71d53d4-69ee-460e-8ef0-1d320b26975c/mount/new.etcd/member/wal/0.tmp, ownerUser: 65532, ownerGroup: 65532 kind: pod name: etcd-events-0 namespace: shoot--diki-comp--openstack  
                                                            containerName: backup-restore details: fileName: /var/lib/kubelet/pods/9c7e7507-c95f-4034-bb45-54d9a5a0061e/volumes/kubernetes.io~csi/pv-shoot--garden--cc-ha-eu1-c71d53d4-69ee-460e-8ef0-1d320b26975c/mount/new.etcd/member/snap/db, ownerUser: 65532, ownerGroup: 65532 kind: pod name: etcd-events-0 namespace: shoot--diki-comp--openstack  
                                                            containerName: backup-restore details: fileName: /var/lib/kubelet/pods/9c7e7507-c95f-4034-bb45-54d9a5a0061e/volumes/kubernetes.io~configmap/etcd-config-file/..2025_06_23_00_02_39.1412208420/etcd.conf.yaml, ownerUser: 0, ownerGroup: 65532 kind: pod name: etcd-events-0 namespace: shoot--diki-comp--openstack  
                                                            containerName: backup-restore details: fileName: /var/lib/kubelet/pods/9c7e7507-c95f-4034-bb45-54d9a5a0061e/volumes/kubernetes.io~secret/backup-restore-server-tls/..2025_06_23_00_02_39.705338586/tls.crt, ownerUser: 0, ownerGroup: 65532 kind: pod name: etcd-events-0 namespace: shoot--diki-comp--openstack  
                                                            containerName: backup-restore details: fileName: /var/lib/kubelet/pods/9c7e7507-c95f-4034-bb45-54d9a5a0061e/volumes/kubernetes.io~secret/backup-restore-server-tls/..2025_06_23_00_02_39.705338586/tls.key, ownerUser: 0, ownerGroup: 65532 kind: pod name: etcd-events-0 namespace: shoot--diki-comp--openstack  
                                                            containerName: backup-restore details: fileName: /var/lib/kubelet/pods/9c7e7507-c95f-4034-bb45-54d9a5a0061e/volumes/kubernetes.io~secret/etcd-ca/..2025_06_23_00_02_39.2818779423/bundle.crt, ownerUser: 0, ownerGroup: 65532 kind: pod name: etcd-events-0 namespace: shoot--diki-comp--openstack  
                                                            containerName: backup-restore details: fileName: /var/lib/kubelet/pods/9c7e7507-c95f-4034-bb45-54d9a5a0061e/volumes/kubernetes.io~secret/etcd-client-tls/..2025_06_23_00_02_39.2589051175/tls.key, ownerUser: 0, ownerGroup: 65532 kind: pod name: etcd-events-0 namespace: shoot--diki-comp--openstack  
                                                            containerName: backup-restore details: fileName: /var/lib/kubelet/pods/9c7e7507-c95f-4034-bb45-54d9a5a0061e/volumes/kubernetes.io~secret/etcd-client-tls/..2025_06_23_00_02_39.2589051175/tls.crt, ownerUser: 0, ownerGroup: 65532 kind: pod name: etcd-events-0 namespace: shoot--diki-comp--openstack  
                                                            containerName: backup-restore details: fileName: /var/lib/kubelet/pods/9c7e7507-c95f-4034-bb45-54d9a5a0061e/volumes/kubernetes.io~projected/kube-api-access-gardener/..2025_06_23_00_02_39.3883414360/namespace, ownerUser: 0, ownerGroup: 65532 kind: pod name: etcd-events-0 namespace: shoot--diki-comp--openstack  
                                                            containerName: backup-restore details: fileName: /var/lib/kubelet/pods/9c7e7507-c95f-4034-bb45-54d9a5a0061e/volumes/kubernetes.io~projected/kube-api-access-gardener/..2025_06_23_00_02_39.3883414360/ca.crt, ownerUser: 0, ownerGroup: 65532 kind: pod name: etcd-events-0 namespace: shoot--diki-comp--openstack  
                                                            containerName: backup-restore details: fileName: /var/lib/kubelet/pods/9c7e7507-c95f-4034-bb45-54d9a5a0061e/volumes/kubernetes.io~projected/kube-api-access-gardener/..2025_06_23_00_02_39.3883414360/token, ownerUser: 65532, ownerGroup: 65532 kind: pod name: etcd-events-0 namespace: shoot--diki-comp--openstack  
                                                            containerName: etcd details: fileName: /var/lib/kubelet/pods/9c7e7507-c95f-4034-bb45-54d9a5a0061e/volumes/kubernetes.io~csi/pv-shoot--garden--cc-ha-eu1-c71d53d4-69ee-460e-8ef0-1d320b26975c/mount/safe_guard, ownerUser: 65532, ownerGroup: 65532 kind: pod name: etcd-events-0 namespace: shoot--diki-comp--openstack  
                                                            containerName: etcd details: fileName: /var/lib/kubelet/pods/9c7e7507-c95f-4034-bb45-54d9a5a0061e/volumes/kubernetes.io~csi/pv-shoot--garden--cc-ha-eu1-c71d53d4-69ee-460e-8ef0-1d320b26975c/mount/new.etcd/member/wal/0000000000000000-0000000000000000.wal, ownerUser: 65532, ownerGroup: 65532 kind: pod name: etcd-events-0 namespace: shoot--diki-comp--openstack  
                                                            containerName: etcd details: fileName: /var/lib/kubelet/pods/9c7e7507-c95f-4034-bb45-54d9a5a0061e/volumes/kubernetes.io~csi/pv-shoot--garden--cc-ha-eu1-c71d53d4-69ee-460e-8ef0-1d320b26975c/mount/new.etcd/member/wal/0.tmp, ownerUser: 65532, ownerGroup: 65532 kind: pod name: etcd-events-0 namespace: shoot--diki-comp--openstack  
                                                            containerName: etcd details: fileName: /var/lib/kubelet/pods/9c7e7507-c95f-4034-bb45-54d9a5a0061e/volumes/kubernetes.io~csi/pv-shoot--garden--cc-ha-eu1-c71d53d4-69ee-460e-8ef0-1d320b26975c/mount/new.etcd/member/snap/db, ownerUser: 65532, ownerGroup: 65532 kind: pod name: etcd-events-0 namespace: shoot--diki-comp--openstack  
                                                            containerName: etcd details: fileName: /var/lib/kubelet/pods/9c7e7507-c95f-4034-bb45-54d9a5a0061e/volumes/kubernetes.io~secret/etcd-ca/..2025_06_23_00_02_39.2818779423/bundle.crt, ownerUser: 0, ownerGroup: 65532 kind: pod name: etcd-events-0 namespace: shoot--diki-comp--openstack  
                                                            containerName: etcd details: fileName: /var/lib/kubelet/pods/9c7e7507-c95f-4034-bb45-54d9a5a0061e/volumes/kubernetes.io~secret/etcd-server-tls/..2025_06_23_00_02_39.1241938029/tls.key, ownerUser: 0, ownerGroup: 65532 kind: pod name: etcd-events-0 namespace: shoot--diki-comp--openstack  
                                                            containerName: etcd details: fileName: /var/lib/kubelet/pods/9c7e7507-c95f-4034-bb45-54d9a5a0061e/volumes/kubernetes.io~secret/etcd-server-tls/..2025_06_23_00_02_39.1241938029/tls.crt, ownerUser: 0, ownerGroup: 65532 kind: pod name: etcd-events-0 namespace: shoot--diki-comp--openstack  
                                                            containerName: etcd details: fileName: /var/lib/kubelet/pods/9c7e7507-c95f-4034-bb45-54d9a5a0061e/volumes/kubernetes.io~secret/etcd-client-tls/..2025_06_23_00_02_39.2589051175/tls.key, ownerUser: 0, ownerGroup: 65532 kind: pod name: etcd-events-0 namespace: shoot--diki-comp--openstack  
                                                            containerName: etcd details: fileName: /var/lib/kubelet/pods/9c7e7507-c95f-4034-bb45-54d9a5a0061e/volumes/kubernetes.io~secret/etcd-client-tls/..2025_06_23_00_02_39.2589051175/tls.crt, ownerUser: 0, ownerGroup: 65532 kind: pod name: etcd-events-0 namespace: shoot--diki-comp--openstack  
                                                            containerName: etcd details: fileName: /var/lib/kubelet/pods/9c7e7507-c95f-4034-bb45-54d9a5a0061e/volumes/kubernetes.io~secret/backup-restore-ca/..2025_06_23_00_02_39.735587336/bundle.crt, ownerUser: 0, ownerGroup: 65532 kind: pod name: etcd-events-0 namespace: shoot--diki-comp--openstack  
                                                            containerName: etcd details: fileName: /var/lib/kubelet/pods/9c7e7507-c95f-4034-bb45-54d9a5a0061e/volumes/kubernetes.io~projected/kube-api-access-gardener/..2025_06_23_00_02_39.3883414360/namespace, ownerUser: 0, ownerGroup: 65532 kind: pod name: etcd-events-0 namespace: shoot--diki-comp--openstack  
                                                            containerName: etcd details: fileName: /var/lib/kubelet/pods/9c7e7507-c95f-4034-bb45-54d9a5a0061e/volumes/kubernetes.io~projected/kube-api-access-gardener/..2025_06_23_00_02_39.3883414360/ca.crt, ownerUser: 0, ownerGroup: 65532 kind: pod name: etcd-events-0 namespace: shoot--diki-comp--openstack  
                                                            containerName: etcd details: fileName: /var/lib/kubelet/pods/9c7e7507-c95f-4034-bb45-54d9a5a0061e/volumes/kubernetes.io~projected/kube-api-access-gardener/..2025_06_23_00_02_39.3883414360/token, ownerUser: 65532, ownerGroup: 65532 kind: pod name: etcd-events-0 namespace: shoot--diki-comp--openstack  
                                                         
                                                     
                                                 
                                             
                                         
                                     
                                    
                                        242446 (Medium) - The Kubernetes conf files must be owned by root. 
                                        
                                            
                                                File has expected owners 
                                                
                                                    
                                                        aws 
                                                        
                                                            containerName: kube-controller-manager details: fileName: /var/lib/kubelet/pods/c423b64c-cb58-46fa-a956-022b9b1664c6/volumes/kubernetes.io~secret/ca/..2025_06_23_00_16_39.892891764/bundle.crt, ownerUser: 0, ownerGroup: 65532 kind: pod name: kube-controller-manager-7c9bc75987-cqgs4 namespace: shoot--diki-comp--aws  
                                                            containerName: kube-controller-manager details: fileName: /var/lib/kubelet/pods/c423b64c-cb58-46fa-a956-022b9b1664c6/volumes/kubernetes.io~secret/ca-client/..2025_06_23_00_16_39.4293646224/ca.key, ownerUser: 0, ownerGroup: 65532 kind: pod name: kube-controller-manager-7c9bc75987-cqgs4 namespace: shoot--diki-comp--aws  
                                                            containerName: kube-controller-manager details: fileName: /var/lib/kubelet/pods/c423b64c-cb58-46fa-a956-022b9b1664c6/volumes/kubernetes.io~secret/ca-client/..2025_06_23_00_16_39.4293646224/ca.crt, ownerUser: 0, ownerGroup: 65532 kind: pod name: kube-controller-manager-7c9bc75987-cqgs4 namespace: shoot--diki-comp--aws  
                                                            containerName: kube-controller-manager details: fileName: /var/lib/kubelet/pods/c423b64c-cb58-46fa-a956-022b9b1664c6/volumes/kubernetes.io~secret/service-account-key/..2025_06_23_00_16_39.1494491013/id_rsa, ownerUser: 0, ownerGroup: 65532 kind: pod name: kube-controller-manager-7c9bc75987-cqgs4 namespace: shoot--diki-comp--aws  
                                                            containerName: kube-controller-manager details: fileName: /var/lib/kubelet/pods/c423b64c-cb58-46fa-a956-022b9b1664c6/volumes/kubernetes.io~secret/server/..2025_06_23_00_16_39.867879351/tls.key, ownerUser: 0, ownerGroup: 65532 kind: pod name: kube-controller-manager-7c9bc75987-cqgs4 namespace: shoot--diki-comp--aws  
                                                            containerName: kube-controller-manager details: fileName: /var/lib/kubelet/pods/c423b64c-cb58-46fa-a956-022b9b1664c6/volumes/kubernetes.io~secret/server/..2025_06_23_00_16_39.867879351/tls.crt, ownerUser: 0, ownerGroup: 65532 kind: pod name: kube-controller-manager-7c9bc75987-cqgs4 namespace: shoot--diki-comp--aws  
                                                            containerName: kube-controller-manager details: fileName: /var/lib/kubelet/pods/c423b64c-cb58-46fa-a956-022b9b1664c6/volumes/kubernetes.io~secret/ca-kubelet/..2025_06_23_00_16_39.254040933/ca.key, ownerUser: 0, ownerGroup: 65532 kind: pod name: kube-controller-manager-7c9bc75987-cqgs4 namespace: shoot--diki-comp--aws  
                                                            containerName: kube-controller-manager details: fileName: /var/lib/kubelet/pods/c423b64c-cb58-46fa-a956-022b9b1664c6/volumes/kubernetes.io~secret/ca-kubelet/..2025_06_23_00_16_39.254040933/ca.crt, ownerUser: 0, ownerGroup: 65532 kind: pod name: kube-controller-manager-7c9bc75987-cqgs4 namespace: shoot--diki-comp--aws  
                                                            containerName: kube-controller-manager details: fileName: /var/lib/kubelet/pods/c423b64c-cb58-46fa-a956-022b9b1664c6/volumes/kubernetes.io~projected/kubeconfig/..2025_06_23_00_16_39.1696466279/token, ownerUser: 0, ownerGroup: 65532 kind: pod name: kube-controller-manager-7c9bc75987-cqgs4 namespace: shoot--diki-comp--aws  
                                                            containerName: kube-controller-manager details: fileName: /var/lib/kubelet/pods/c423b64c-cb58-46fa-a956-022b9b1664c6/volumes/kubernetes.io~projected/kubeconfig/..2025_06_23_00_16_39.1696466279/kubeconfig, ownerUser: 0, ownerGroup: 65532 kind: pod name: kube-controller-manager-7c9bc75987-cqgs4 namespace: shoot--diki-comp--aws  
                                                            containerName: kube-scheduler details: fileName: /var/lib/kubelet/pods/06134fb6-0360-493d-adc6-38d710393b11/volumes/kubernetes.io~projected/client-ca/..2025_06_23_00_10_38.120749235/bundle.crt, ownerUser: 0, ownerGroup: 65532 kind: pod name: kube-scheduler-5854d54c7c-2b7mv namespace: shoot--diki-comp--aws  
                                                            containerName: kube-scheduler details: fileName: /var/lib/kubelet/pods/06134fb6-0360-493d-adc6-38d710393b11/volumes/kubernetes.io~secret/kube-scheduler-server/..2025_06_23_00_10_38.1273189684/tls.key, ownerUser: 0, ownerGroup: 65532 kind: pod name: kube-scheduler-5854d54c7c-2b7mv namespace: shoot--diki-comp--aws  
                                                            containerName: kube-scheduler details: fileName: /var/lib/kubelet/pods/06134fb6-0360-493d-adc6-38d710393b11/volumes/kubernetes.io~secret/kube-scheduler-server/..2025_06_23_00_10_38.1273189684/tls.crt, ownerUser: 0, ownerGroup: 65532 kind: pod name: kube-scheduler-5854d54c7c-2b7mv namespace: shoot--diki-comp--aws  
                                                            containerName: kube-scheduler details: fileName: /var/lib/kubelet/pods/06134fb6-0360-493d-adc6-38d710393b11/volumes/kubernetes.io~configmap/kube-scheduler-config/..2025_06_23_00_10_38.2951232700/config.yaml, ownerUser: 0, ownerGroup: 65532 kind: pod name: kube-scheduler-5854d54c7c-2b7mv namespace: shoot--diki-comp--aws  
                                                            containerName: kube-scheduler details: fileName: /var/lib/kubelet/pods/06134fb6-0360-493d-adc6-38d710393b11/volumes/kubernetes.io~projected/kubeconfig/..2025_06_23_00_10_38.297818258/token, ownerUser: 0, ownerGroup: 65532 kind: pod name: kube-scheduler-5854d54c7c-2b7mv namespace: shoot--diki-comp--aws  
                                                            containerName: kube-scheduler details: fileName: /var/lib/kubelet/pods/06134fb6-0360-493d-adc6-38d710393b11/volumes/kubernetes.io~projected/kubeconfig/..2025_06_23_00_10_38.297818258/kubeconfig, ownerUser: 0, ownerGroup: 65532 kind: pod name: kube-scheduler-5854d54c7c-2b7mv namespace: shoot--diki-comp--aws  
                                                            containerName: kube-apiserver details: fileName: /var/lib/kubelet/pods/42db629f-9d43-492e-92df-f2a0ac97d2b6/volumes/kubernetes.io~secret/ca/..2025_06_23_00_09_39.1820813547/bundle.crt, ownerUser: 0, ownerGroup: 65532 kind: pod name: kube-apiserver-6d847f96d4-82qpt namespace: shoot--diki-comp--aws  
                                                            containerName: kube-apiserver details: fileName: /var/lib/kubelet/pods/42db629f-9d43-492e-92df-f2a0ac97d2b6/volumes/kubernetes.io~secret/ca-client/..2025_06_23_00_09_39.3911158577/bundle.crt, ownerUser: 0, ownerGroup: 65532 kind: pod name: kube-apiserver-6d847f96d4-82qpt namespace: shoot--diki-comp--aws  
                                                            containerName: kube-apiserver details: fileName: /var/lib/kubelet/pods/42db629f-9d43-492e-92df-f2a0ac97d2b6/volumes/kubernetes.io~secret/ca-front-proxy/..2025_06_23_00_09_39.1216619138/bundle.crt, ownerUser: 0, ownerGroup: 65532 kind: pod name: kube-apiserver-6d847f96d4-82qpt namespace: shoot--diki-comp--aws  
                                                            containerName: kube-apiserver details: fileName: /var/lib/kubelet/pods/42db629f-9d43-492e-92df-f2a0ac97d2b6/volumes/kubernetes.io~secret/service-account-key/..2025_06_23_00_09_39.2803718542/id_rsa, ownerUser: 0, ownerGroup: 65532 kind: pod name: kube-apiserver-6d847f96d4-82qpt namespace: shoot--diki-comp--aws  
                                                            containerName: kube-apiserver details: fileName: /var/lib/kubelet/pods/42db629f-9d43-492e-92df-f2a0ac97d2b6/volumes/kubernetes.io~secret/service-account-key-bundle/..2025_06_23_00_09_39.1536096673/bundle.key, ownerUser: 0, ownerGroup: 65532 kind: pod name: kube-apiserver-6d847f96d4-82qpt namespace: shoot--diki-comp--aws  
                                                            containerName: kube-apiserver details: fileName: /var/lib/kubelet/pods/42db629f-9d43-492e-92df-f2a0ac97d2b6/volumes/kubernetes.io~secret/static-token/..2025_06_23_00_09_39.3305149993/static_tokens.csv, ownerUser: 0, ownerGroup: 65532 kind: pod name: kube-apiserver-6d847f96d4-82qpt namespace: shoot--diki-comp--aws  
                                                            containerName: kube-apiserver details: fileName: /var/lib/kubelet/pods/42db629f-9d43-492e-92df-f2a0ac97d2b6/volumes/kubernetes.io~secret/kube-aggregator/..2025_06_23_00_09_39.3585741192/tls.key, ownerUser: 0, ownerGroup: 65532 kind: pod name: kube-apiserver-6d847f96d4-82qpt namespace: shoot--diki-comp--aws  
                                                            containerName: kube-apiserver details: fileName: /var/lib/kubelet/pods/42db629f-9d43-492e-92df-f2a0ac97d2b6/volumes/kubernetes.io~secret/kube-aggregator/..2025_06_23_00_09_39.3585741192/tls.crt, ownerUser: 0, ownerGroup: 65532 kind: pod name: kube-apiserver-6d847f96d4-82qpt namespace: shoot--diki-comp--aws  
                                                            containerName: kube-apiserver details: fileName: /var/lib/kubelet/pods/42db629f-9d43-492e-92df-f2a0ac97d2b6/volumes/kubernetes.io~secret/server/..2025_06_23_00_09_39.2101876528/tls.key, ownerUser: 0, ownerGroup: 65532 kind: pod name: kube-apiserver-6d847f96d4-82qpt namespace: shoot--diki-comp--aws  
                                                            containerName: kube-apiserver details: fileName: /var/lib/kubelet/pods/42db629f-9d43-492e-92df-f2a0ac97d2b6/volumes/kubernetes.io~secret/server/..2025_06_23_00_09_39.2101876528/tls.crt, ownerUser: 0, ownerGroup: 65532 kind: pod name: kube-apiserver-6d847f96d4-82qpt namespace: shoot--diki-comp--aws  
                                                            containerName: kube-apiserver details: fileName: /var/lib/kubelet/pods/42db629f-9d43-492e-92df-f2a0ac97d2b6/volumes/kubernetes.io~configmap/audit-policy-config/..2025_06_23_00_09_39.2329166342/audit-policy.yaml, ownerUser: 0, ownerGroup: 65532 kind: pod name: kube-apiserver-6d847f96d4-82qpt namespace: shoot--diki-comp--aws  
                                                            containerName: kube-apiserver details: fileName: /var/lib/kubelet/pods/42db629f-9d43-492e-92df-f2a0ac97d2b6/volumes/kubernetes.io~configmap/admission-config/..2025_06_23_00_09_39.1330272162/podsecurity.yaml, ownerUser: 0, ownerGroup: 65532 kind: pod name: kube-apiserver-6d847f96d4-82qpt namespace: shoot--diki-comp--aws  
                                                            containerName: kube-apiserver details: fileName: /var/lib/kubelet/pods/42db629f-9d43-492e-92df-f2a0ac97d2b6/volumes/kubernetes.io~configmap/admission-config/..2025_06_23_00_09_39.1330272162/admission-configuration.yaml, ownerUser: 0, ownerGroup: 65532 kind: pod name: kube-apiserver-6d847f96d4-82qpt namespace: shoot--diki-comp--aws  
                                                            containerName: kube-apiserver details: fileName: /var/lib/kubelet/pods/42db629f-9d43-492e-92df-f2a0ac97d2b6/volumes/kubernetes.io~secret/etcd-encryption-secret/..2025_06_23_00_09_39.2708327898/encryption-configuration.yaml, ownerUser: 0, ownerGroup: 65532 kind: pod name: kube-apiserver-6d847f96d4-82qpt namespace: shoot--diki-comp--aws  
                                                            containerName: kube-apiserver details: fileName: /var/lib/kubelet/pods/42db629f-9d43-492e-92df-f2a0ac97d2b6/volumes/kubernetes.io~secret/ca-vpn/..2025_06_23_00_09_39.1345136145/bundle.crt, ownerUser: 0, ownerGroup: 65532 kind: pod name: kube-apiserver-6d847f96d4-82qpt namespace: shoot--diki-comp--aws  
                                                            containerName: kube-apiserver details: fileName: /var/lib/kubelet/pods/42db629f-9d43-492e-92df-f2a0ac97d2b6/volumes/kubernetes.io~configmap/egress-selection-config/..2025_06_23_00_09_39.2143964349/egress-selector-configuration.yaml, ownerUser: 0, ownerGroup: 65532 kind: pod name: kube-apiserver-6d847f96d4-82qpt namespace: shoot--diki-comp--aws  
                                                            containerName: kube-apiserver details: fileName: /var/lib/kubelet/pods/42db629f-9d43-492e-92df-f2a0ac97d2b6/volumes/kubernetes.io~secret/ca-kubelet/..2025_06_23_00_09_39.2968989444/bundle.crt, ownerUser: 0, ownerGroup: 65532 kind: pod name: kube-apiserver-6d847f96d4-82qpt namespace: shoot--diki-comp--aws  
                                                            containerName: kube-apiserver details: fileName: /var/lib/kubelet/pods/42db629f-9d43-492e-92df-f2a0ac97d2b6/volumes/kubernetes.io~secret/kubelet-client/..2025_06_23_00_09_39.2120918226/tls.key, ownerUser: 0, ownerGroup: 65532 kind: pod name: kube-apiserver-6d847f96d4-82qpt namespace: shoot--diki-comp--aws  
                                                            containerName: kube-apiserver details: fileName: /var/lib/kubelet/pods/42db629f-9d43-492e-92df-f2a0ac97d2b6/volumes/kubernetes.io~secret/kubelet-client/..2025_06_23_00_09_39.2120918226/tls.crt, ownerUser: 0, ownerGroup: 65532 kind: pod name: kube-apiserver-6d847f96d4-82qpt namespace: shoot--diki-comp--aws  
                                                            containerName: kube-apiserver details: fileName: /var/lib/kubelet/pods/42db629f-9d43-492e-92df-f2a0ac97d2b6/volumes/kubernetes.io~secret/ca-etcd/..2025_06_23_00_09_39.86038190/bundle.crt, ownerUser: 0, ownerGroup: 65532 kind: pod name: kube-apiserver-6d847f96d4-82qpt namespace: shoot--diki-comp--aws  
                                                            containerName: kube-apiserver details: fileName: /var/lib/kubelet/pods/42db629f-9d43-492e-92df-f2a0ac97d2b6/volumes/kubernetes.io~secret/etcd-client/..2025_06_23_00_09_39.3841361014/tls.crt, ownerUser: 0, ownerGroup: 65532 kind: pod name: kube-apiserver-6d847f96d4-82qpt namespace: shoot--diki-comp--aws  
                                                            containerName: kube-apiserver details: fileName: /var/lib/kubelet/pods/42db629f-9d43-492e-92df-f2a0ac97d2b6/volumes/kubernetes.io~secret/etcd-client/..2025_06_23_00_09_39.3841361014/tls.key, ownerUser: 0, ownerGroup: 65532 kind: pod name: kube-apiserver-6d847f96d4-82qpt namespace: shoot--diki-comp--aws  
                                                            containerName: kube-apiserver details: fileName: /var/lib/kubelet/pods/42db629f-9d43-492e-92df-f2a0ac97d2b6/volumes/kubernetes.io~secret/tls-sni-0/..2025_06_23_00_09_39.1534744055/tls.key, ownerUser: 0, ownerGroup: 65532 kind: pod name: kube-apiserver-6d847f96d4-82qpt namespace: shoot--diki-comp--aws  
                                                            containerName: kube-apiserver details: fileName: /var/lib/kubelet/pods/42db629f-9d43-492e-92df-f2a0ac97d2b6/volumes/kubernetes.io~secret/tls-sni-0/..2025_06_23_00_09_39.1534744055/tls.crt, ownerUser: 0, ownerGroup: 65532 kind: pod name: kube-apiserver-6d847f96d4-82qpt namespace: shoot--diki-comp--aws  
                                                            containerName: kube-apiserver details: fileName: /var/lib/kubelet/pods/42db629f-9d43-492e-92df-f2a0ac97d2b6/volumes/kubernetes.io~secret/tls-sni-0/..2025_06_23_00_09_39.1534744055/ca.crt, ownerUser: 0, ownerGroup: 65532 kind: pod name: kube-apiserver-6d847f96d4-82qpt namespace: shoot--diki-comp--aws  
                                                            containerName: kube-apiserver details: fileName: /var/lib/kubelet/pods/42db629f-9d43-492e-92df-f2a0ac97d2b6/volumes/kubernetes.io~configmap/authorization-config/..2025_06_23_00_09_39.233957482/config.yaml, ownerUser: 0, ownerGroup: 65532 kind: pod name: kube-apiserver-6d847f96d4-82qpt namespace: shoot--diki-comp--aws  
                                                            containerName: kube-apiserver details: fileName: /var/lib/kubelet/pods/42db629f-9d43-492e-92df-f2a0ac97d2b6/volumes/kubernetes.io~secret/authorization-kubeconfigs/..2025_06_23_00_09_39.3354464403/node-agent-authorizer-kubeconfig.yaml, ownerUser: 0, ownerGroup: 65532 kind: pod name: kube-apiserver-6d847f96d4-82qpt namespace: shoot--diki-comp--aws  
                                                            containerName: kube-apiserver details: fileName: /var/lib/kubelet/pods/42db629f-9d43-492e-92df-f2a0ac97d2b6/volumes/kubernetes.io~secret/http-proxy/..2025_06_23_00_09_39.1635279459/tls.key, ownerUser: 0, ownerGroup: 65532 kind: pod name: kube-apiserver-6d847f96d4-82qpt namespace: shoot--diki-comp--aws  
                                                            containerName: kube-apiserver details: fileName: /var/lib/kubelet/pods/42db629f-9d43-492e-92df-f2a0ac97d2b6/volumes/kubernetes.io~secret/http-proxy/..2025_06_23_00_09_39.1635279459/tls.crt, ownerUser: 0, ownerGroup: 65532 kind: pod name: kube-apiserver-6d847f96d4-82qpt namespace: shoot--diki-comp--aws  
                                                         
                                                     
                                                    
                                                        azure 
                                                        
                                                            containerName: kube-apiserver details: fileName: /var/lib/kubelet/pods/19e8d0fb-e648-458d-9824-7002ba098bce/volumes/kubernetes.io~secret/ca/..2025_06_23_00_14_46.3142548715/bundle.crt, ownerUser: 0, ownerGroup: 65532 kind: pod name: kube-apiserver-d66f4d44f-tm4cs namespace: shoot--diki-comp--azure  
                                                            containerName: kube-apiserver details: fileName: /var/lib/kubelet/pods/19e8d0fb-e648-458d-9824-7002ba098bce/volumes/kubernetes.io~secret/ca-client/..2025_06_23_00_14_46.1427032518/bundle.crt, ownerUser: 0, ownerGroup: 65532 kind: pod name: kube-apiserver-d66f4d44f-tm4cs namespace: shoot--diki-comp--azure  
                                                            containerName: kube-apiserver details: fileName: /var/lib/kubelet/pods/19e8d0fb-e648-458d-9824-7002ba098bce/volumes/kubernetes.io~secret/ca-front-proxy/..2025_06_23_00_14_46.1493427643/bundle.crt, ownerUser: 0, ownerGroup: 65532 kind: pod name: kube-apiserver-d66f4d44f-tm4cs namespace: shoot--diki-comp--azure  
                                                            containerName: kube-apiserver details: fileName: /var/lib/kubelet/pods/19e8d0fb-e648-458d-9824-7002ba098bce/volumes/kubernetes.io~secret/service-account-key/..2025_06_23_00_14_46.325050636/id_rsa, ownerUser: 0, ownerGroup: 65532 kind: pod name: kube-apiserver-d66f4d44f-tm4cs namespace: shoot--diki-comp--azure  
                                                            containerName: kube-apiserver details: fileName: /var/lib/kubelet/pods/19e8d0fb-e648-458d-9824-7002ba098bce/volumes/kubernetes.io~secret/service-account-key-bundle/..2025_06_23_00_14_46.504056214/bundle.key, ownerUser: 0, ownerGroup: 65532 kind: pod name: kube-apiserver-d66f4d44f-tm4cs namespace: shoot--diki-comp--azure  
                                                            containerName: kube-apiserver details: fileName: /var/lib/kubelet/pods/19e8d0fb-e648-458d-9824-7002ba098bce/volumes/kubernetes.io~secret/static-token/..2025_06_23_00_14_46.4214259902/static_tokens.csv, ownerUser: 0, ownerGroup: 65532 kind: pod name: kube-apiserver-d66f4d44f-tm4cs namespace: shoot--diki-comp--azure  
                                                            containerName: kube-apiserver details: fileName: /var/lib/kubelet/pods/19e8d0fb-e648-458d-9824-7002ba098bce/volumes/kubernetes.io~secret/kube-aggregator/..2025_06_23_00_14_46.2139614939/tls.key, ownerUser: 0, ownerGroup: 65532 kind: pod name: kube-apiserver-d66f4d44f-tm4cs namespace: shoot--diki-comp--azure  
                                                            containerName: kube-apiserver details: fileName: /var/lib/kubelet/pods/19e8d0fb-e648-458d-9824-7002ba098bce/volumes/kubernetes.io~secret/kube-aggregator/..2025_06_23_00_14_46.2139614939/tls.crt, ownerUser: 0, ownerGroup: 65532 kind: pod name: kube-apiserver-d66f4d44f-tm4cs namespace: shoot--diki-comp--azure  
                                                            containerName: kube-apiserver details: fileName: /var/lib/kubelet/pods/19e8d0fb-e648-458d-9824-7002ba098bce/volumes/kubernetes.io~secret/server/..2025_06_23_00_14_46.2186093174/tls.key, ownerUser: 0, ownerGroup: 65532 kind: pod name: kube-apiserver-d66f4d44f-tm4cs namespace: shoot--diki-comp--azure  
                                                            containerName: kube-apiserver details: fileName: /var/lib/kubelet/pods/19e8d0fb-e648-458d-9824-7002ba098bce/volumes/kubernetes.io~secret/server/..2025_06_23_00_14_46.2186093174/tls.crt, ownerUser: 0, ownerGroup: 65532 kind: pod name: kube-apiserver-d66f4d44f-tm4cs namespace: shoot--diki-comp--azure  
                                                            containerName: kube-apiserver details: fileName: /var/lib/kubelet/pods/19e8d0fb-e648-458d-9824-7002ba098bce/volumes/kubernetes.io~configmap/audit-policy-config/..2025_06_23_00_14_46.1584132699/audit-policy.yaml, ownerUser: 0, ownerGroup: 65532 kind: pod name: kube-apiserver-d66f4d44f-tm4cs namespace: shoot--diki-comp--azure  
                                                            containerName: kube-apiserver details: fileName: /var/lib/kubelet/pods/19e8d0fb-e648-458d-9824-7002ba098bce/volumes/kubernetes.io~configmap/admission-config/..2025_06_23_00_14_46.4294471397/podsecurity.yaml, ownerUser: 0, ownerGroup: 65532 kind: pod name: kube-apiserver-d66f4d44f-tm4cs namespace: shoot--diki-comp--azure  
                                                            containerName: kube-apiserver details: fileName: /var/lib/kubelet/pods/19e8d0fb-e648-458d-9824-7002ba098bce/volumes/kubernetes.io~configmap/admission-config/..2025_06_23_00_14_46.4294471397/admission-configuration.yaml, ownerUser: 0, ownerGroup: 65532 kind: pod name: kube-apiserver-d66f4d44f-tm4cs namespace: shoot--diki-comp--azure  
                                                            containerName: kube-apiserver details: fileName: /var/lib/kubelet/pods/19e8d0fb-e648-458d-9824-7002ba098bce/volumes/kubernetes.io~secret/etcd-encryption-secret/..2025_06_23_00_14_46.439791232/encryption-configuration.yaml, ownerUser: 0, ownerGroup: 65532 kind: pod name: kube-apiserver-d66f4d44f-tm4cs namespace: shoot--diki-comp--azure  
                                                            containerName: kube-apiserver details: fileName: /var/lib/kubelet/pods/19e8d0fb-e648-458d-9824-7002ba098bce/volumes/kubernetes.io~secret/ca-vpn/..2025_06_23_00_14_46.3412290611/bundle.crt, ownerUser: 0, ownerGroup: 65532 kind: pod name: kube-apiserver-d66f4d44f-tm4cs namespace: shoot--diki-comp--azure  
                                                            containerName: kube-apiserver details: fileName: /var/lib/kubelet/pods/19e8d0fb-e648-458d-9824-7002ba098bce/volumes/kubernetes.io~configmap/egress-selection-config/..2025_06_23_00_14_46.4108663986/egress-selector-configuration.yaml, ownerUser: 0, ownerGroup: 65532 kind: pod name: kube-apiserver-d66f4d44f-tm4cs namespace: shoot--diki-comp--azure  
                                                            containerName: kube-apiserver details: fileName: /var/lib/kubelet/pods/19e8d0fb-e648-458d-9824-7002ba098bce/volumes/kubernetes.io~secret/ca-kubelet/..2025_06_23_00_14_46.3112199018/bundle.crt, ownerUser: 0, ownerGroup: 65532 kind: pod name: kube-apiserver-d66f4d44f-tm4cs namespace: shoot--diki-comp--azure  
                                                            containerName: kube-apiserver details: fileName: /var/lib/kubelet/pods/19e8d0fb-e648-458d-9824-7002ba098bce/volumes/kubernetes.io~secret/kubelet-client/..2025_06_23_00_14_46.2446316166/tls.crt, ownerUser: 0, ownerGroup: 65532 kind: pod name: kube-apiserver-d66f4d44f-tm4cs namespace: shoot--diki-comp--azure  
                                                            containerName: kube-apiserver details: fileName: /var/lib/kubelet/pods/19e8d0fb-e648-458d-9824-7002ba098bce/volumes/kubernetes.io~secret/kubelet-client/..2025_06_23_00_14_46.2446316166/tls.key, ownerUser: 0, ownerGroup: 65532 kind: pod name: kube-apiserver-d66f4d44f-tm4cs namespace: shoot--diki-comp--azure  
                                                            containerName: kube-apiserver details: fileName: /var/lib/kubelet/pods/19e8d0fb-e648-458d-9824-7002ba098bce/volumes/kubernetes.io~secret/ca-etcd/..2025_06_23_00_14_46.3219727173/bundle.crt, ownerUser: 0, ownerGroup: 65532 kind: pod name: kube-apiserver-d66f4d44f-tm4cs namespace: shoot--diki-comp--azure  
                                                            containerName: kube-apiserver details: fileName: /var/lib/kubelet/pods/19e8d0fb-e648-458d-9824-7002ba098bce/volumes/kubernetes.io~secret/etcd-client/..2025_06_23_00_14_46.1466414181/tls.key, ownerUser: 0, ownerGroup: 65532 kind: pod name: kube-apiserver-d66f4d44f-tm4cs namespace: shoot--diki-comp--azure  
                                                            containerName: kube-apiserver details: fileName: /var/lib/kubelet/pods/19e8d0fb-e648-458d-9824-7002ba098bce/volumes/kubernetes.io~secret/etcd-client/..2025_06_23_00_14_46.1466414181/tls.crt, ownerUser: 0, ownerGroup: 65532 kind: pod name: kube-apiserver-d66f4d44f-tm4cs namespace: shoot--diki-comp--azure  
                                                            containerName: kube-apiserver details: fileName: /var/lib/kubelet/pods/19e8d0fb-e648-458d-9824-7002ba098bce/volumes/kubernetes.io~secret/tls-sni-0/..2025_06_23_00_14_46.1021198322/tls.key, ownerUser: 0, ownerGroup: 65532 kind: pod name: kube-apiserver-d66f4d44f-tm4cs namespace: shoot--diki-comp--azure  
                                                            containerName: kube-apiserver details: fileName: /var/lib/kubelet/pods/19e8d0fb-e648-458d-9824-7002ba098bce/volumes/kubernetes.io~secret/tls-sni-0/..2025_06_23_00_14_46.1021198322/tls.crt, ownerUser: 0, ownerGroup: 65532 kind: pod name: kube-apiserver-d66f4d44f-tm4cs namespace: shoot--diki-comp--azure  
                                                            containerName: kube-apiserver details: fileName: /var/lib/kubelet/pods/19e8d0fb-e648-458d-9824-7002ba098bce/volumes/kubernetes.io~secret/tls-sni-0/..2025_06_23_00_14_46.1021198322/ca.crt, ownerUser: 0, ownerGroup: 65532 kind: pod name: kube-apiserver-d66f4d44f-tm4cs namespace: shoot--diki-comp--azure  
                                                            containerName: kube-apiserver details: fileName: /var/lib/kubelet/pods/19e8d0fb-e648-458d-9824-7002ba098bce/volumes/kubernetes.io~configmap/authorization-config/..2025_06_23_00_14_46.2637053043/config.yaml, ownerUser: 0, ownerGroup: 65532 kind: pod name: kube-apiserver-d66f4d44f-tm4cs namespace: shoot--diki-comp--azure  
                                                            containerName: kube-apiserver details: fileName: /var/lib/kubelet/pods/19e8d0fb-e648-458d-9824-7002ba098bce/volumes/kubernetes.io~secret/authorization-kubeconfigs/..2025_06_23_00_14_46.2011429030/node-agent-authorizer-kubeconfig.yaml, ownerUser: 0, ownerGroup: 65532 kind: pod name: kube-apiserver-d66f4d44f-tm4cs namespace: shoot--diki-comp--azure  
                                                            containerName: kube-apiserver details: fileName: /var/lib/kubelet/pods/19e8d0fb-e648-458d-9824-7002ba098bce/volumes/kubernetes.io~secret/http-proxy/..2025_06_23_00_14_46.234968055/tls.key, ownerUser: 0, ownerGroup: 65532 kind: pod name: kube-apiserver-d66f4d44f-tm4cs namespace: shoot--diki-comp--azure  
                                                            containerName: kube-apiserver details: fileName: /var/lib/kubelet/pods/19e8d0fb-e648-458d-9824-7002ba098bce/volumes/kubernetes.io~secret/http-proxy/..2025_06_23_00_14_46.234968055/tls.crt, ownerUser: 0, ownerGroup: 65532 kind: pod name: kube-apiserver-d66f4d44f-tm4cs namespace: shoot--diki-comp--azure  
                                                            containerName: kube-controller-manager details: fileName: /var/lib/kubelet/pods/8a5510fe-a88b-42cc-b90a-1d8f9487d887/volumes/kubernetes.io~secret/ca/..2025_06_23_00_19_46.2289618773/bundle.crt, ownerUser: 0, ownerGroup: 65532 kind: pod name: kube-controller-manager-7d869c84b8-kz7dm namespace: shoot--diki-comp--azure  
                                                            containerName: kube-controller-manager details: fileName: /var/lib/kubelet/pods/8a5510fe-a88b-42cc-b90a-1d8f9487d887/volumes/kubernetes.io~secret/ca-client/..2025_06_23_00_19_46.1556017874/ca.crt, ownerUser: 0, ownerGroup: 65532 kind: pod name: kube-controller-manager-7d869c84b8-kz7dm namespace: shoot--diki-comp--azure  
                                                            containerName: kube-controller-manager details: fileName: /var/lib/kubelet/pods/8a5510fe-a88b-42cc-b90a-1d8f9487d887/volumes/kubernetes.io~secret/ca-client/..2025_06_23_00_19_46.1556017874/ca.key, ownerUser: 0, ownerGroup: 65532 kind: pod name: kube-controller-manager-7d869c84b8-kz7dm namespace: shoot--diki-comp--azure  
                                                            containerName: kube-controller-manager details: fileName: /var/lib/kubelet/pods/8a5510fe-a88b-42cc-b90a-1d8f9487d887/volumes/kubernetes.io~secret/service-account-key/..2025_06_23_00_19_46.2680073418/id_rsa, ownerUser: 0, ownerGroup: 65532 kind: pod name: kube-controller-manager-7d869c84b8-kz7dm namespace: shoot--diki-comp--azure  
                                                            containerName: kube-controller-manager details: fileName: /var/lib/kubelet/pods/8a5510fe-a88b-42cc-b90a-1d8f9487d887/volumes/kubernetes.io~secret/server/..2025_06_23_00_19_46.3137963724/tls.key, ownerUser: 0, ownerGroup: 65532 kind: pod name: kube-controller-manager-7d869c84b8-kz7dm namespace: shoot--diki-comp--azure  
                                                            containerName: kube-controller-manager details: fileName: /var/lib/kubelet/pods/8a5510fe-a88b-42cc-b90a-1d8f9487d887/volumes/kubernetes.io~secret/server/..2025_06_23_00_19_46.3137963724/tls.crt, ownerUser: 0, ownerGroup: 65532 kind: pod name: kube-controller-manager-7d869c84b8-kz7dm namespace: shoot--diki-comp--azure  
                                                            containerName: kube-controller-manager details: fileName: /var/lib/kubelet/pods/8a5510fe-a88b-42cc-b90a-1d8f9487d887/volumes/kubernetes.io~secret/ca-kubelet/..2025_06_23_00_19_46.2139875717/ca.crt, ownerUser: 0, ownerGroup: 65532 kind: pod name: kube-controller-manager-7d869c84b8-kz7dm namespace: shoot--diki-comp--azure  
                                                            containerName: kube-controller-manager details: fileName: /var/lib/kubelet/pods/8a5510fe-a88b-42cc-b90a-1d8f9487d887/volumes/kubernetes.io~secret/ca-kubelet/..2025_06_23_00_19_46.2139875717/ca.key, ownerUser: 0, ownerGroup: 65532 kind: pod name: kube-controller-manager-7d869c84b8-kz7dm namespace: shoot--diki-comp--azure  
                                                            containerName: kube-controller-manager details: fileName: /var/lib/kubelet/pods/8a5510fe-a88b-42cc-b90a-1d8f9487d887/volumes/kubernetes.io~projected/kubeconfig/..2025_06_23_00_19_46.3968766951/token, ownerUser: 0, ownerGroup: 65532 kind: pod name: kube-controller-manager-7d869c84b8-kz7dm namespace: shoot--diki-comp--azure  
                                                            containerName: kube-controller-manager details: fileName: /var/lib/kubelet/pods/8a5510fe-a88b-42cc-b90a-1d8f9487d887/volumes/kubernetes.io~projected/kubeconfig/..2025_06_23_00_19_46.3968766951/kubeconfig, ownerUser: 0, ownerGroup: 65532 kind: pod name: kube-controller-manager-7d869c84b8-kz7dm namespace: shoot--diki-comp--azure  
                                                            containerName: kube-scheduler details: fileName: /var/lib/kubelet/pods/8afdd891-92eb-4c6a-aac5-9a324987f6ad/volumes/kubernetes.io~projected/client-ca/..2025_06_23_00_14_46.3397349168/bundle.crt, ownerUser: 0, ownerGroup: 65532 kind: pod name: kube-scheduler-67fdbc4569-h6j7v namespace: shoot--diki-comp--azure  
                                                            containerName: kube-scheduler details: fileName: /var/lib/kubelet/pods/8afdd891-92eb-4c6a-aac5-9a324987f6ad/volumes/kubernetes.io~secret/kube-scheduler-server/..2025_06_23_00_14_46.366944806/tls.key, ownerUser: 0, ownerGroup: 65532 kind: pod name: kube-scheduler-67fdbc4569-h6j7v namespace: shoot--diki-comp--azure  
                                                            containerName: kube-scheduler details: fileName: /var/lib/kubelet/pods/8afdd891-92eb-4c6a-aac5-9a324987f6ad/volumes/kubernetes.io~secret/kube-scheduler-server/..2025_06_23_00_14_46.366944806/tls.crt, ownerUser: 0, ownerGroup: 65532 kind: pod name: kube-scheduler-67fdbc4569-h6j7v namespace: shoot--diki-comp--azure  
                                                            containerName: kube-scheduler details: fileName: /var/lib/kubelet/pods/8afdd891-92eb-4c6a-aac5-9a324987f6ad/volumes/kubernetes.io~configmap/kube-scheduler-config/..2025_06_23_00_14_46.962074830/config.yaml, ownerUser: 0, ownerGroup: 65532 kind: pod name: kube-scheduler-67fdbc4569-h6j7v namespace: shoot--diki-comp--azure  
                                                            containerName: kube-scheduler details: fileName: /var/lib/kubelet/pods/8afdd891-92eb-4c6a-aac5-9a324987f6ad/volumes/kubernetes.io~projected/kubeconfig/..2025_06_23_00_14_46.877888443/token, ownerUser: 0, ownerGroup: 65532 kind: pod name: kube-scheduler-67fdbc4569-h6j7v namespace: shoot--diki-comp--azure  
                                                            containerName: kube-scheduler details: fileName: /var/lib/kubelet/pods/8afdd891-92eb-4c6a-aac5-9a324987f6ad/volumes/kubernetes.io~projected/kubeconfig/..2025_06_23_00_14_46.877888443/kubeconfig, ownerUser: 0, ownerGroup: 65532 kind: pod name: kube-scheduler-67fdbc4569-h6j7v namespace: shoot--diki-comp--azure  
                                                         
                                                     
                                                    
                                                        gcp 
                                                        
                                                            containerName: kube-apiserver details: fileName: /var/lib/kubelet/pods/bcae6617-9cf5-48c4-a654-323e2fd06c94/volumes/kubernetes.io~secret/ca/..2025_06_23_00_05_00.1635859179/bundle.crt, ownerUser: 0, ownerGroup: 65532 kind: pod name: kube-apiserver-789b87d9bc-m288k namespace: shoot--diki-comp--gcp  
                                                            containerName: kube-apiserver details: fileName: /var/lib/kubelet/pods/bcae6617-9cf5-48c4-a654-323e2fd06c94/volumes/kubernetes.io~secret/ca-client/..2025_06_23_00_05_00.3123507849/bundle.crt, ownerUser: 0, ownerGroup: 65532 kind: pod name: kube-apiserver-789b87d9bc-m288k namespace: shoot--diki-comp--gcp  
                                                            containerName: kube-apiserver details: fileName: /var/lib/kubelet/pods/bcae6617-9cf5-48c4-a654-323e2fd06c94/volumes/kubernetes.io~secret/ca-front-proxy/..2025_06_23_00_05_00.3311897769/bundle.crt, ownerUser: 0, ownerGroup: 65532 kind: pod name: kube-apiserver-789b87d9bc-m288k namespace: shoot--diki-comp--gcp  
                                                            containerName: kube-apiserver details: fileName: /var/lib/kubelet/pods/bcae6617-9cf5-48c4-a654-323e2fd06c94/volumes/kubernetes.io~secret/service-account-key/..2025_06_23_00_05_00.213839922/id_rsa, ownerUser: 0, ownerGroup: 65532 kind: pod name: kube-apiserver-789b87d9bc-m288k namespace: shoot--diki-comp--gcp  
                                                            containerName: kube-apiserver details: fileName: /var/lib/kubelet/pods/bcae6617-9cf5-48c4-a654-323e2fd06c94/volumes/kubernetes.io~secret/service-account-key-bundle/..2025_06_23_00_05_00.527676273/bundle.key, ownerUser: 0, ownerGroup: 65532 kind: pod name: kube-apiserver-789b87d9bc-m288k namespace: shoot--diki-comp--gcp  
                                                            containerName: kube-apiserver details: fileName: /var/lib/kubelet/pods/bcae6617-9cf5-48c4-a654-323e2fd06c94/volumes/kubernetes.io~secret/static-token/..2025_06_23_00_05_00.3972387062/static_tokens.csv, ownerUser: 0, ownerGroup: 65532 kind: pod name: kube-apiserver-789b87d9bc-m288k namespace: shoot--diki-comp--gcp  
                                                            containerName: kube-apiserver details: fileName: /var/lib/kubelet/pods/bcae6617-9cf5-48c4-a654-323e2fd06c94/volumes/kubernetes.io~secret/kube-aggregator/..2025_06_23_00_05_00.8440286/tls.crt, ownerUser: 0, ownerGroup: 65532 kind: pod name: kube-apiserver-789b87d9bc-m288k namespace: shoot--diki-comp--gcp  
                                                            containerName: kube-apiserver details: fileName: /var/lib/kubelet/pods/bcae6617-9cf5-48c4-a654-323e2fd06c94/volumes/kubernetes.io~secret/kube-aggregator/..2025_06_23_00_05_00.8440286/tls.key, ownerUser: 0, ownerGroup: 65532 kind: pod name: kube-apiserver-789b87d9bc-m288k namespace: shoot--diki-comp--gcp  
                                                            containerName: kube-apiserver details: fileName: /var/lib/kubelet/pods/bcae6617-9cf5-48c4-a654-323e2fd06c94/volumes/kubernetes.io~secret/server/..2025_06_23_00_05_00.2211691282/tls.key, ownerUser: 0, ownerGroup: 65532 kind: pod name: kube-apiserver-789b87d9bc-m288k namespace: shoot--diki-comp--gcp  
                                                            containerName: kube-apiserver details: fileName: /var/lib/kubelet/pods/bcae6617-9cf5-48c4-a654-323e2fd06c94/volumes/kubernetes.io~secret/server/..2025_06_23_00_05_00.2211691282/tls.crt, ownerUser: 0, ownerGroup: 65532 kind: pod name: kube-apiserver-789b87d9bc-m288k namespace: shoot--diki-comp--gcp  
                                                            containerName: kube-apiserver details: fileName: /var/lib/kubelet/pods/bcae6617-9cf5-48c4-a654-323e2fd06c94/volumes/kubernetes.io~configmap/audit-policy-config/..2025_06_23_00_05_00.518575439/audit-policy.yaml, ownerUser: 0, ownerGroup: 65532 kind: pod name: kube-apiserver-789b87d9bc-m288k namespace: shoot--diki-comp--gcp  
                                                            containerName: kube-apiserver details: fileName: /var/lib/kubelet/pods/bcae6617-9cf5-48c4-a654-323e2fd06c94/volumes/kubernetes.io~configmap/admission-config/..2025_06_23_00_05_00.2157622198/podsecurity.yaml, ownerUser: 0, ownerGroup: 65532 kind: pod name: kube-apiserver-789b87d9bc-m288k namespace: shoot--diki-comp--gcp  
                                                            containerName: kube-apiserver details: fileName: /var/lib/kubelet/pods/bcae6617-9cf5-48c4-a654-323e2fd06c94/volumes/kubernetes.io~configmap/admission-config/..2025_06_23_00_05_00.2157622198/admission-configuration.yaml, ownerUser: 0, ownerGroup: 65532 kind: pod name: kube-apiserver-789b87d9bc-m288k namespace: shoot--diki-comp--gcp  
                                                            containerName: kube-apiserver details: fileName: /var/lib/kubelet/pods/bcae6617-9cf5-48c4-a654-323e2fd06c94/volumes/kubernetes.io~secret/etcd-encryption-secret/..2025_06_23_00_05_00.1089428079/encryption-configuration.yaml, ownerUser: 0, ownerGroup: 65532 kind: pod name: kube-apiserver-789b87d9bc-m288k namespace: shoot--diki-comp--gcp  
                                                            containerName: kube-apiserver details: fileName: /var/lib/kubelet/pods/bcae6617-9cf5-48c4-a654-323e2fd06c94/volumes/kubernetes.io~secret/ca-vpn/..2025_06_23_00_05_00.3200529218/bundle.crt, ownerUser: 0, ownerGroup: 65532 kind: pod name: kube-apiserver-789b87d9bc-m288k namespace: shoot--diki-comp--gcp  
                                                            containerName: kube-apiserver details: fileName: /var/lib/kubelet/pods/bcae6617-9cf5-48c4-a654-323e2fd06c94/volumes/kubernetes.io~configmap/egress-selection-config/..2025_06_23_00_05_00.1397569347/egress-selector-configuration.yaml, ownerUser: 0, ownerGroup: 65532 kind: pod name: kube-apiserver-789b87d9bc-m288k namespace: shoot--diki-comp--gcp  
                                                            containerName: kube-apiserver details: fileName: /var/lib/kubelet/pods/bcae6617-9cf5-48c4-a654-323e2fd06c94/volumes/kubernetes.io~secret/ca-kubelet/..2025_06_23_00_05_00.1340282604/bundle.crt, ownerUser: 0, ownerGroup: 65532 kind: pod name: kube-apiserver-789b87d9bc-m288k namespace: shoot--diki-comp--gcp  
                                                            containerName: kube-apiserver details: fileName: /var/lib/kubelet/pods/bcae6617-9cf5-48c4-a654-323e2fd06c94/volumes/kubernetes.io~secret/kubelet-client/..2025_06_23_00_05_00.3066470044/tls.crt, ownerUser: 0, ownerGroup: 65532 kind: pod name: kube-apiserver-789b87d9bc-m288k namespace: shoot--diki-comp--gcp  
                                                            containerName: kube-apiserver details: fileName: /var/lib/kubelet/pods/bcae6617-9cf5-48c4-a654-323e2fd06c94/volumes/kubernetes.io~secret/kubelet-client/..2025_06_23_00_05_00.3066470044/tls.key, ownerUser: 0, ownerGroup: 65532 kind: pod name: kube-apiserver-789b87d9bc-m288k namespace: shoot--diki-comp--gcp  
                                                            containerName: kube-apiserver details: fileName: /var/lib/kubelet/pods/bcae6617-9cf5-48c4-a654-323e2fd06c94/volumes/kubernetes.io~secret/ca-etcd/..2025_06_23_00_05_00.599344253/bundle.crt, ownerUser: 0, ownerGroup: 65532 kind: pod name: kube-apiserver-789b87d9bc-m288k namespace: shoot--diki-comp--gcp  
                                                            containerName: kube-apiserver details: fileName: /var/lib/kubelet/pods/bcae6617-9cf5-48c4-a654-323e2fd06c94/volumes/kubernetes.io~secret/etcd-client/..2025_06_23_00_05_00.3665142686/tls.key, ownerUser: 0, ownerGroup: 65532 kind: pod name: kube-apiserver-789b87d9bc-m288k namespace: shoot--diki-comp--gcp  
                                                            containerName: kube-apiserver details: fileName: /var/lib/kubelet/pods/bcae6617-9cf5-48c4-a654-323e2fd06c94/volumes/kubernetes.io~secret/etcd-client/..2025_06_23_00_05_00.3665142686/tls.crt, ownerUser: 0, ownerGroup: 65532 kind: pod name: kube-apiserver-789b87d9bc-m288k namespace: shoot--diki-comp--gcp  
                                                            containerName: kube-apiserver details: fileName: /var/lib/kubelet/pods/bcae6617-9cf5-48c4-a654-323e2fd06c94/volumes/kubernetes.io~secret/tls-sni-0/..2025_06_23_00_05_00.1355552674/tls.key, ownerUser: 0, ownerGroup: 65532 kind: pod name: kube-apiserver-789b87d9bc-m288k namespace: shoot--diki-comp--gcp  
                                                            containerName: kube-apiserver details: fileName: /var/lib/kubelet/pods/bcae6617-9cf5-48c4-a654-323e2fd06c94/volumes/kubernetes.io~secret/tls-sni-0/..2025_06_23_00_05_00.1355552674/tls.crt, ownerUser: 0, ownerGroup: 65532 kind: pod name: kube-apiserver-789b87d9bc-m288k namespace: shoot--diki-comp--gcp  
                                                            containerName: kube-apiserver details: fileName: /var/lib/kubelet/pods/bcae6617-9cf5-48c4-a654-323e2fd06c94/volumes/kubernetes.io~secret/tls-sni-0/..2025_06_23_00_05_00.1355552674/ca.crt, ownerUser: 0, ownerGroup: 65532 kind: pod name: kube-apiserver-789b87d9bc-m288k namespace: shoot--diki-comp--gcp  
                                                            containerName: kube-apiserver details: fileName: /var/lib/kubelet/pods/bcae6617-9cf5-48c4-a654-323e2fd06c94/volumes/kubernetes.io~configmap/authorization-config/..2025_06_23_00_05_00.165428170/config.yaml, ownerUser: 0, ownerGroup: 65532 kind: pod name: kube-apiserver-789b87d9bc-m288k namespace: shoot--diki-comp--gcp  
                                                            containerName: kube-apiserver details: fileName: /var/lib/kubelet/pods/bcae6617-9cf5-48c4-a654-323e2fd06c94/volumes/kubernetes.io~secret/authorization-kubeconfigs/..2025_06_23_00_05_00.985374819/node-agent-authorizer-kubeconfig.yaml, ownerUser: 0, ownerGroup: 65532 kind: pod name: kube-apiserver-789b87d9bc-m288k namespace: shoot--diki-comp--gcp  
                                                            containerName: kube-apiserver details: fileName: /var/lib/kubelet/pods/bcae6617-9cf5-48c4-a654-323e2fd06c94/volumes/kubernetes.io~secret/http-proxy/..2025_06_23_00_05_00.2267541296/tls.key, ownerUser: 0, ownerGroup: 65532 kind: pod name: kube-apiserver-789b87d9bc-m288k namespace: shoot--diki-comp--gcp  
                                                            containerName: kube-apiserver details: fileName: /var/lib/kubelet/pods/bcae6617-9cf5-48c4-a654-323e2fd06c94/volumes/kubernetes.io~secret/http-proxy/..2025_06_23_00_05_00.2267541296/tls.crt, ownerUser: 0, ownerGroup: 65532 kind: pod name: kube-apiserver-789b87d9bc-m288k namespace: shoot--diki-comp--gcp  
                                                            containerName: kube-controller-manager details: fileName: /var/lib/kubelet/pods/7207bfe7-1315-42f2-8383-7b79afa8437d/volumes/kubernetes.io~secret/ca/..2025_06_23_00_10_41.4029468750/bundle.crt, ownerUser: 0, ownerGroup: 65532 kind: pod name: kube-controller-manager-65cdccf875-lhhzw namespace: shoot--diki-comp--gcp  
                                                            containerName: kube-controller-manager details: fileName: /var/lib/kubelet/pods/7207bfe7-1315-42f2-8383-7b79afa8437d/volumes/kubernetes.io~secret/ca-client/..2025_06_23_00_10_41.2990537503/ca.crt, ownerUser: 0, ownerGroup: 65532 kind: pod name: kube-controller-manager-65cdccf875-lhhzw namespace: shoot--diki-comp--gcp  
                                                            containerName: kube-controller-manager details: fileName: /var/lib/kubelet/pods/7207bfe7-1315-42f2-8383-7b79afa8437d/volumes/kubernetes.io~secret/ca-client/..2025_06_23_00_10_41.2990537503/ca.key, ownerUser: 0, ownerGroup: 65532 kind: pod name: kube-controller-manager-65cdccf875-lhhzw namespace: shoot--diki-comp--gcp  
                                                            containerName: kube-controller-manager details: fileName: /var/lib/kubelet/pods/7207bfe7-1315-42f2-8383-7b79afa8437d/volumes/kubernetes.io~secret/service-account-key/..2025_06_23_00_10_41.2563485830/id_rsa, ownerUser: 0, ownerGroup: 65532 kind: pod name: kube-controller-manager-65cdccf875-lhhzw namespace: shoot--diki-comp--gcp  
                                                            containerName: kube-controller-manager details: fileName: /var/lib/kubelet/pods/7207bfe7-1315-42f2-8383-7b79afa8437d/volumes/kubernetes.io~secret/server/..2025_06_23_00_10_41.2206626934/tls.crt, ownerUser: 0, ownerGroup: 65532 kind: pod name: kube-controller-manager-65cdccf875-lhhzw namespace: shoot--diki-comp--gcp  
                                                            containerName: kube-controller-manager details: fileName: /var/lib/kubelet/pods/7207bfe7-1315-42f2-8383-7b79afa8437d/volumes/kubernetes.io~secret/server/..2025_06_23_00_10_41.2206626934/tls.key, ownerUser: 0, ownerGroup: 65532 kind: pod name: kube-controller-manager-65cdccf875-lhhzw namespace: shoot--diki-comp--gcp  
                                                            containerName: kube-controller-manager details: fileName: /var/lib/kubelet/pods/7207bfe7-1315-42f2-8383-7b79afa8437d/volumes/kubernetes.io~secret/ca-kubelet/..2025_06_23_00_10_41.1244180931/ca.crt, ownerUser: 0, ownerGroup: 65532 kind: pod name: kube-controller-manager-65cdccf875-lhhzw namespace: shoot--diki-comp--gcp  
                                                            containerName: kube-controller-manager details: fileName: /var/lib/kubelet/pods/7207bfe7-1315-42f2-8383-7b79afa8437d/volumes/kubernetes.io~secret/ca-kubelet/..2025_06_23_00_10_41.1244180931/ca.key, ownerUser: 0, ownerGroup: 65532 kind: pod name: kube-controller-manager-65cdccf875-lhhzw namespace: shoot--diki-comp--gcp  
                                                            containerName: kube-controller-manager details: fileName: /var/lib/kubelet/pods/7207bfe7-1315-42f2-8383-7b79afa8437d/volumes/kubernetes.io~projected/kubeconfig/..2025_06_23_00_10_41.1252315107/kubeconfig, ownerUser: 0, ownerGroup: 65532 kind: pod name: kube-controller-manager-65cdccf875-lhhzw namespace: shoot--diki-comp--gcp  
                                                            containerName: kube-controller-manager details: fileName: /var/lib/kubelet/pods/7207bfe7-1315-42f2-8383-7b79afa8437d/volumes/kubernetes.io~projected/kubeconfig/..2025_06_23_00_10_41.1252315107/token, ownerUser: 0, ownerGroup: 65532 kind: pod name: kube-controller-manager-65cdccf875-lhhzw namespace: shoot--diki-comp--gcp  
                                                            containerName: kube-scheduler details: fileName: /var/lib/kubelet/pods/d1968ae3-bf95-4709-b100-13709ba484c9/volumes/kubernetes.io~projected/client-ca/..2025_06_23_00_22_41.2638774521/bundle.crt, ownerUser: 0, ownerGroup: 65532 kind: pod name: kube-scheduler-7d978d746c-2vbm4 namespace: shoot--diki-comp--gcp  
                                                            containerName: kube-scheduler details: fileName: /var/lib/kubelet/pods/d1968ae3-bf95-4709-b100-13709ba484c9/volumes/kubernetes.io~secret/kube-scheduler-server/..2025_06_23_00_22_41.3181132458/tls.crt, ownerUser: 0, ownerGroup: 65532 kind: pod name: kube-scheduler-7d978d746c-2vbm4 namespace: shoot--diki-comp--gcp  
                                                            containerName: kube-scheduler details: fileName: /var/lib/kubelet/pods/d1968ae3-bf95-4709-b100-13709ba484c9/volumes/kubernetes.io~secret/kube-scheduler-server/..2025_06_23_00_22_41.3181132458/tls.key, ownerUser: 0, ownerGroup: 65532 kind: pod name: kube-scheduler-7d978d746c-2vbm4 namespace: shoot--diki-comp--gcp  
                                                            containerName: kube-scheduler details: fileName: /var/lib/kubelet/pods/d1968ae3-bf95-4709-b100-13709ba484c9/volumes/kubernetes.io~configmap/kube-scheduler-config/..2025_06_23_00_22_41.3002091610/config.yaml, ownerUser: 0, ownerGroup: 65532 kind: pod name: kube-scheduler-7d978d746c-2vbm4 namespace: shoot--diki-comp--gcp  
                                                            containerName: kube-scheduler details: fileName: /var/lib/kubelet/pods/d1968ae3-bf95-4709-b100-13709ba484c9/volumes/kubernetes.io~projected/kubeconfig/..2025_06_23_00_22_41.335601454/token, ownerUser: 0, ownerGroup: 65532 kind: pod name: kube-scheduler-7d978d746c-2vbm4 namespace: shoot--diki-comp--gcp  
                                                            containerName: kube-scheduler details: fileName: /var/lib/kubelet/pods/d1968ae3-bf95-4709-b100-13709ba484c9/volumes/kubernetes.io~projected/kubeconfig/..2025_06_23_00_22_41.335601454/kubeconfig, ownerUser: 0, ownerGroup: 65532 kind: pod name: kube-scheduler-7d978d746c-2vbm4 namespace: shoot--diki-comp--gcp  
                                                         
                                                     
                                                    
                                                        openstack 
                                                        
                                                            containerName: kube-controller-manager details: fileName: /var/lib/kubelet/pods/0b27d4d8-1580-4d41-8c12-a56ef49072dc/volumes/kubernetes.io~secret/ca/..2025_06_23_00_12_57.3765708577/bundle.crt, ownerUser: 0, ownerGroup: 65532 kind: pod name: kube-controller-manager-76f68f67cf-z8lm4 namespace: shoot--diki-comp--openstack  
                                                            containerName: kube-controller-manager details: fileName: /var/lib/kubelet/pods/0b27d4d8-1580-4d41-8c12-a56ef49072dc/volumes/kubernetes.io~secret/ca-client/..2025_06_23_00_12_57.3596785791/ca.crt, ownerUser: 0, ownerGroup: 65532 kind: pod name: kube-controller-manager-76f68f67cf-z8lm4 namespace: shoot--diki-comp--openstack  
                                                            containerName: kube-controller-manager details: fileName: /var/lib/kubelet/pods/0b27d4d8-1580-4d41-8c12-a56ef49072dc/volumes/kubernetes.io~secret/ca-client/..2025_06_23_00_12_57.3596785791/ca.key, ownerUser: 0, ownerGroup: 65532 kind: pod name: kube-controller-manager-76f68f67cf-z8lm4 namespace: shoot--diki-comp--openstack  
                                                            containerName: kube-controller-manager details: fileName: /var/lib/kubelet/pods/0b27d4d8-1580-4d41-8c12-a56ef49072dc/volumes/kubernetes.io~secret/service-account-key/..2025_06_23_00_12_57.136774851/id_rsa, ownerUser: 0, ownerGroup: 65532 kind: pod name: kube-controller-manager-76f68f67cf-z8lm4 namespace: shoot--diki-comp--openstack  
                                                            containerName: kube-controller-manager details: fileName: /var/lib/kubelet/pods/0b27d4d8-1580-4d41-8c12-a56ef49072dc/volumes/kubernetes.io~secret/server/..2025_06_23_00_12_57.4281910611/tls.key, ownerUser: 0, ownerGroup: 65532 kind: pod name: kube-controller-manager-76f68f67cf-z8lm4 namespace: shoot--diki-comp--openstack  
                                                            containerName: kube-controller-manager details: fileName: /var/lib/kubelet/pods/0b27d4d8-1580-4d41-8c12-a56ef49072dc/volumes/kubernetes.io~secret/server/..2025_06_23_00_12_57.4281910611/tls.crt, ownerUser: 0, ownerGroup: 65532 kind: pod name: kube-controller-manager-76f68f67cf-z8lm4 namespace: shoot--diki-comp--openstack  
                                                            containerName: kube-controller-manager details: fileName: /var/lib/kubelet/pods/0b27d4d8-1580-4d41-8c12-a56ef49072dc/volumes/kubernetes.io~secret/ca-kubelet/..2025_06_23_00_12_57.775870841/ca.key, ownerUser: 0, ownerGroup: 65532 kind: pod name: kube-controller-manager-76f68f67cf-z8lm4 namespace: shoot--diki-comp--openstack  
                                                            containerName: kube-controller-manager details: fileName: /var/lib/kubelet/pods/0b27d4d8-1580-4d41-8c12-a56ef49072dc/volumes/kubernetes.io~secret/ca-kubelet/..2025_06_23_00_12_57.775870841/ca.crt, ownerUser: 0, ownerGroup: 65532 kind: pod name: kube-controller-manager-76f68f67cf-z8lm4 namespace: shoot--diki-comp--openstack  
                                                            containerName: kube-controller-manager details: fileName: /var/lib/kubelet/pods/0b27d4d8-1580-4d41-8c12-a56ef49072dc/volumes/kubernetes.io~projected/kubeconfig/..2025_06_23_00_12_57.1210378879/token, ownerUser: 0, ownerGroup: 65532 kind: pod name: kube-controller-manager-76f68f67cf-z8lm4 namespace: shoot--diki-comp--openstack  
                                                            containerName: kube-controller-manager details: fileName: /var/lib/kubelet/pods/0b27d4d8-1580-4d41-8c12-a56ef49072dc/volumes/kubernetes.io~projected/kubeconfig/..2025_06_23_00_12_57.1210378879/kubeconfig, ownerUser: 0, ownerGroup: 65532 kind: pod name: kube-controller-manager-76f68f67cf-z8lm4 namespace: shoot--diki-comp--openstack  
                                                            containerName: kube-scheduler details: fileName: /var/lib/kubelet/pods/b2afa8e5-74e9-4932-af53-bf0fcfd84066/volumes/kubernetes.io~projected/client-ca/..2025_06_23_00_11_57.2527488857/bundle.crt, ownerUser: 0, ownerGroup: 65532 kind: pod name: kube-scheduler-785644b95f-fzldg namespace: shoot--diki-comp--openstack  
                                                            containerName: kube-scheduler details: fileName: /var/lib/kubelet/pods/b2afa8e5-74e9-4932-af53-bf0fcfd84066/volumes/kubernetes.io~secret/kube-scheduler-server/..2025_06_23_00_11_57.748288227/tls.crt, ownerUser: 0, ownerGroup: 65532 kind: pod name: kube-scheduler-785644b95f-fzldg namespace: shoot--diki-comp--openstack  
                                                            containerName: kube-scheduler details: fileName: /var/lib/kubelet/pods/b2afa8e5-74e9-4932-af53-bf0fcfd84066/volumes/kubernetes.io~secret/kube-scheduler-server/..2025_06_23_00_11_57.748288227/tls.key, ownerUser: 0, ownerGroup: 65532 kind: pod name: kube-scheduler-785644b95f-fzldg namespace: shoot--diki-comp--openstack  
                                                            containerName: kube-scheduler details: fileName: /var/lib/kubelet/pods/b2afa8e5-74e9-4932-af53-bf0fcfd84066/volumes/kubernetes.io~configmap/kube-scheduler-config/..2025_06_23_00_11_57.964913296/config.yaml, ownerUser: 0, ownerGroup: 65532 kind: pod name: kube-scheduler-785644b95f-fzldg namespace: shoot--diki-comp--openstack  
                                                            containerName: kube-scheduler details: fileName: /var/lib/kubelet/pods/b2afa8e5-74e9-4932-af53-bf0fcfd84066/volumes/kubernetes.io~projected/kubeconfig/..2025_06_23_00_11_57.558571866/token, ownerUser: 0, ownerGroup: 65532 kind: pod name: kube-scheduler-785644b95f-fzldg namespace: shoot--diki-comp--openstack  
                                                            containerName: kube-scheduler details: fileName: /var/lib/kubelet/pods/b2afa8e5-74e9-4932-af53-bf0fcfd84066/volumes/kubernetes.io~projected/kubeconfig/..2025_06_23_00_11_57.558571866/kubeconfig, ownerUser: 0, ownerGroup: 65532 kind: pod name: kube-scheduler-785644b95f-fzldg namespace: shoot--diki-comp--openstack  
                                                            containerName: kube-apiserver details: fileName: /var/lib/kubelet/pods/4a414212-471d-49e1-ba69-657ac6fd352a/volumes/kubernetes.io~secret/ca/..2025_06_23_00_05_31.3801277659/bundle.crt, ownerUser: 0, ownerGroup: 65532 kind: pod name: kube-apiserver-5ffd79587b-574wj namespace: shoot--diki-comp--openstack  
                                                            containerName: kube-apiserver details: fileName: /var/lib/kubelet/pods/4a414212-471d-49e1-ba69-657ac6fd352a/volumes/kubernetes.io~secret/ca-client/..2025_06_23_00_05_31.316180318/bundle.crt, ownerUser: 0, ownerGroup: 65532 kind: pod name: kube-apiserver-5ffd79587b-574wj namespace: shoot--diki-comp--openstack  
                                                            containerName: kube-apiserver details: fileName: /var/lib/kubelet/pods/4a414212-471d-49e1-ba69-657ac6fd352a/volumes/kubernetes.io~secret/ca-front-proxy/..2025_06_23_00_05_31.1046019673/bundle.crt, ownerUser: 0, ownerGroup: 65532 kind: pod name: kube-apiserver-5ffd79587b-574wj namespace: shoot--diki-comp--openstack  
                                                            containerName: kube-apiserver details: fileName: /var/lib/kubelet/pods/4a414212-471d-49e1-ba69-657ac6fd352a/volumes/kubernetes.io~secret/service-account-key/..2025_06_23_00_05_31.235664194/id_rsa, ownerUser: 0, ownerGroup: 65532 kind: pod name: kube-apiserver-5ffd79587b-574wj namespace: shoot--diki-comp--openstack  
                                                            containerName: kube-apiserver details: fileName: /var/lib/kubelet/pods/4a414212-471d-49e1-ba69-657ac6fd352a/volumes/kubernetes.io~secret/service-account-key-bundle/..2025_06_23_00_05_31.2877576203/bundle.key, ownerUser: 0, ownerGroup: 65532 kind: pod name: kube-apiserver-5ffd79587b-574wj namespace: shoot--diki-comp--openstack  
                                                            containerName: kube-apiserver details: fileName: /var/lib/kubelet/pods/4a414212-471d-49e1-ba69-657ac6fd352a/volumes/kubernetes.io~secret/static-token/..2025_06_23_00_05_31.1058278656/static_tokens.csv, ownerUser: 0, ownerGroup: 65532 kind: pod name: kube-apiserver-5ffd79587b-574wj namespace: shoot--diki-comp--openstack  
                                                            containerName: kube-apiserver details: fileName: /var/lib/kubelet/pods/4a414212-471d-49e1-ba69-657ac6fd352a/volumes/kubernetes.io~secret/kube-aggregator/..2025_06_23_00_05_31.974579027/tls.crt, ownerUser: 0, ownerGroup: 65532 kind: pod name: kube-apiserver-5ffd79587b-574wj namespace: shoot--diki-comp--openstack  
                                                            containerName: kube-apiserver details: fileName: /var/lib/kubelet/pods/4a414212-471d-49e1-ba69-657ac6fd352a/volumes/kubernetes.io~secret/kube-aggregator/..2025_06_23_00_05_31.974579027/tls.key, ownerUser: 0, ownerGroup: 65532 kind: pod name: kube-apiserver-5ffd79587b-574wj namespace: shoot--diki-comp--openstack  
                                                            containerName: kube-apiserver details: fileName: /var/lib/kubelet/pods/4a414212-471d-49e1-ba69-657ac6fd352a/volumes/kubernetes.io~secret/server/..2025_06_23_00_05_31.110607305/tls.key, ownerUser: 0, ownerGroup: 65532 kind: pod name: kube-apiserver-5ffd79587b-574wj namespace: shoot--diki-comp--openstack  
                                                            containerName: kube-apiserver details: fileName: /var/lib/kubelet/pods/4a414212-471d-49e1-ba69-657ac6fd352a/volumes/kubernetes.io~secret/server/..2025_06_23_00_05_31.110607305/tls.crt, ownerUser: 0, ownerGroup: 65532 kind: pod name: kube-apiserver-5ffd79587b-574wj namespace: shoot--diki-comp--openstack  
                                                            containerName: kube-apiserver details: fileName: /var/lib/kubelet/pods/4a414212-471d-49e1-ba69-657ac6fd352a/volumes/kubernetes.io~configmap/audit-policy-config/..2025_06_23_00_05_31.3259083047/audit-policy.yaml, ownerUser: 0, ownerGroup: 65532 kind: pod name: kube-apiserver-5ffd79587b-574wj namespace: shoot--diki-comp--openstack  
                                                            containerName: kube-apiserver details: fileName: /var/lib/kubelet/pods/4a414212-471d-49e1-ba69-657ac6fd352a/volumes/kubernetes.io~configmap/admission-config/..2025_06_23_00_05_31.3719270629/podsecurity.yaml, ownerUser: 0, ownerGroup: 65532 kind: pod name: kube-apiserver-5ffd79587b-574wj namespace: shoot--diki-comp--openstack  
                                                            containerName: kube-apiserver details: fileName: /var/lib/kubelet/pods/4a414212-471d-49e1-ba69-657ac6fd352a/volumes/kubernetes.io~configmap/admission-config/..2025_06_23_00_05_31.3719270629/admission-configuration.yaml, ownerUser: 0, ownerGroup: 65532 kind: pod name: kube-apiserver-5ffd79587b-574wj namespace: shoot--diki-comp--openstack  
                                                            containerName: kube-apiserver details: fileName: /var/lib/kubelet/pods/4a414212-471d-49e1-ba69-657ac6fd352a/volumes/kubernetes.io~secret/etcd-encryption-secret/..2025_06_23_00_05_31.2859207702/encryption-configuration.yaml, ownerUser: 0, ownerGroup: 65532 kind: pod name: kube-apiserver-5ffd79587b-574wj namespace: shoot--diki-comp--openstack  
                                                            containerName: kube-apiserver details: fileName: /var/lib/kubelet/pods/4a414212-471d-49e1-ba69-657ac6fd352a/volumes/kubernetes.io~secret/ca-vpn/..2025_06_23_00_05_31.1571181539/bundle.crt, ownerUser: 0, ownerGroup: 65532 kind: pod name: kube-apiserver-5ffd79587b-574wj namespace: shoot--diki-comp--openstack  
                                                            containerName: kube-apiserver details: fileName: /var/lib/kubelet/pods/4a414212-471d-49e1-ba69-657ac6fd352a/volumes/kubernetes.io~configmap/egress-selection-config/..2025_06_23_00_05_31.2734610207/egress-selector-configuration.yaml, ownerUser: 0, ownerGroup: 65532 kind: pod name: kube-apiserver-5ffd79587b-574wj namespace: shoot--diki-comp--openstack  
                                                            containerName: kube-apiserver details: fileName: /var/lib/kubelet/pods/4a414212-471d-49e1-ba69-657ac6fd352a/volumes/kubernetes.io~secret/ca-kubelet/..2025_06_23_00_05_31.1055204524/bundle.crt, ownerUser: 0, ownerGroup: 65532 kind: pod name: kube-apiserver-5ffd79587b-574wj namespace: shoot--diki-comp--openstack  
                                                            containerName: kube-apiserver details: fileName: /var/lib/kubelet/pods/4a414212-471d-49e1-ba69-657ac6fd352a/volumes/kubernetes.io~secret/kubelet-client/..2025_06_23_00_05_31.529535444/tls.crt, ownerUser: 0, ownerGroup: 65532 kind: pod name: kube-apiserver-5ffd79587b-574wj namespace: shoot--diki-comp--openstack  
                                                            containerName: kube-apiserver details: fileName: /var/lib/kubelet/pods/4a414212-471d-49e1-ba69-657ac6fd352a/volumes/kubernetes.io~secret/kubelet-client/..2025_06_23_00_05_31.529535444/tls.key, ownerUser: 0, ownerGroup: 65532 kind: pod name: kube-apiserver-5ffd79587b-574wj namespace: shoot--diki-comp--openstack  
                                                            containerName: kube-apiserver details: fileName: /var/lib/kubelet/pods/4a414212-471d-49e1-ba69-657ac6fd352a/volumes/kubernetes.io~secret/ca-etcd/..2025_06_23_00_05_31.3135557557/bundle.crt, ownerUser: 0, ownerGroup: 65532 kind: pod name: kube-apiserver-5ffd79587b-574wj namespace: shoot--diki-comp--openstack  
                                                            containerName: kube-apiserver details: fileName: /var/lib/kubelet/pods/4a414212-471d-49e1-ba69-657ac6fd352a/volumes/kubernetes.io~secret/etcd-client/..2025_06_23_00_05_31.3982193628/tls.key, ownerUser: 0, ownerGroup: 65532 kind: pod name: kube-apiserver-5ffd79587b-574wj namespace: shoot--diki-comp--openstack  
                                                            containerName: kube-apiserver details: fileName: /var/lib/kubelet/pods/4a414212-471d-49e1-ba69-657ac6fd352a/volumes/kubernetes.io~secret/etcd-client/..2025_06_23_00_05_31.3982193628/tls.crt, ownerUser: 0, ownerGroup: 65532 kind: pod name: kube-apiserver-5ffd79587b-574wj namespace: shoot--diki-comp--openstack  
                                                            containerName: kube-apiserver details: fileName: /var/lib/kubelet/pods/4a414212-471d-49e1-ba69-657ac6fd352a/volumes/kubernetes.io~secret/tls-sni-0/..2025_06_23_00_05_31.1069974019/tls.key, ownerUser: 0, ownerGroup: 65532 kind: pod name: kube-apiserver-5ffd79587b-574wj namespace: shoot--diki-comp--openstack  
                                                            containerName: kube-apiserver details: fileName: /var/lib/kubelet/pods/4a414212-471d-49e1-ba69-657ac6fd352a/volumes/kubernetes.io~secret/tls-sni-0/..2025_06_23_00_05_31.1069974019/tls.crt, ownerUser: 0, ownerGroup: 65532 kind: pod name: kube-apiserver-5ffd79587b-574wj namespace: shoot--diki-comp--openstack  
                                                            containerName: kube-apiserver details: fileName: /var/lib/kubelet/pods/4a414212-471d-49e1-ba69-657ac6fd352a/volumes/kubernetes.io~secret/tls-sni-0/..2025_06_23_00_05_31.1069974019/ca.crt, ownerUser: 0, ownerGroup: 65532 kind: pod name: kube-apiserver-5ffd79587b-574wj namespace: shoot--diki-comp--openstack  
                                                            containerName: kube-apiserver details: fileName: /var/lib/kubelet/pods/4a414212-471d-49e1-ba69-657ac6fd352a/volumes/kubernetes.io~configmap/authorization-config/..2025_06_23_00_05_31.2392426714/config.yaml, ownerUser: 0, ownerGroup: 65532 kind: pod name: kube-apiserver-5ffd79587b-574wj namespace: shoot--diki-comp--openstack  
                                                            containerName: kube-apiserver details: fileName: /var/lib/kubelet/pods/4a414212-471d-49e1-ba69-657ac6fd352a/volumes/kubernetes.io~secret/authorization-kubeconfigs/..2025_06_23_00_05_31.3381187726/node-agent-authorizer-kubeconfig.yaml, ownerUser: 0, ownerGroup: 65532 kind: pod name: kube-apiserver-5ffd79587b-574wj namespace: shoot--diki-comp--openstack  
                                                            containerName: kube-apiserver details: fileName: /var/lib/kubelet/pods/4a414212-471d-49e1-ba69-657ac6fd352a/volumes/kubernetes.io~secret/http-proxy/..2025_06_23_00_05_31.3012580451/tls.key, ownerUser: 0, ownerGroup: 65532 kind: pod name: kube-apiserver-5ffd79587b-574wj namespace: shoot--diki-comp--openstack  
                                                            containerName: kube-apiserver details: fileName: /var/lib/kubelet/pods/4a414212-471d-49e1-ba69-657ac6fd352a/volumes/kubernetes.io~secret/http-proxy/..2025_06_23_00_05_31.3012580451/tls.crt, ownerUser: 0, ownerGroup: 65532 kind: pod name: kube-apiserver-5ffd79587b-574wj namespace: shoot--diki-comp--openstack  
                                                         
                                                     
                                                 
                                             
                                         
                                     
                                    
                                        242447 (Medium) - The Kubernetes Kube Proxy kubeconfig must have file permissions set to 644 or more restrictive. 
                                        
                                            
                                                File has expected permissions 
                                                
                                                    
                                                        aws 
                                                        
                                                            details: fileName: /var/lib/kubelet/pods/d0c8ecde-b8ca-4e6b-bb08-1cbc0775438d/volumes/kubernetes.io~configmap/kube-proxy-config/config.yaml, permissions: 644 kind: pod name: kube-proxy-worker-kkfk1-v1.31.8-8bvtn namespace: kube-system  
                                                            details: fileName: /var/lib/kubelet/pods/d0c8ecde-b8ca-4e6b-bb08-1cbc0775438d/volumes/kubernetes.io~secret/kubeconfig/kubeconfig, permissions: 644 kind: pod name: kube-proxy-worker-kkfk1-v1.31.8-8bvtn namespace: kube-system  
                                                         
                                                     
                                                    
                                                        azure 
                                                        
                                                            details: fileName: /var/lib/kubelet/pods/7f34a064-2a9b-48d4-a97f-57ed2fc7a389/volumes/kubernetes.io~configmap/kube-proxy-config/config.yaml, permissions: 644 kind: pod name: kube-proxy-worker-g7p4p-v1.31.8-7dnc5 namespace: kube-system  
                                                            details: fileName: /var/lib/kubelet/pods/7f34a064-2a9b-48d4-a97f-57ed2fc7a389/volumes/kubernetes.io~secret/kubeconfig/kubeconfig, permissions: 644 kind: pod name: kube-proxy-worker-g7p4p-v1.31.8-7dnc5 namespace: kube-system  
                                                         
                                                     
                                                    
                                                        gcp 
                                                        
                                                            details: fileName: /var/lib/kubelet/pods/4933cf73-66c0-4f8e-b07d-54a68fc93917/volumes/kubernetes.io~configmap/kube-proxy-config/config.yaml, permissions: 644 kind: pod name: kube-proxy-worker-bex82-v1.31.8-x9kg4 namespace: kube-system  
                                                            details: fileName: /var/lib/kubelet/pods/4933cf73-66c0-4f8e-b07d-54a68fc93917/volumes/kubernetes.io~secret/kubeconfig/kubeconfig, permissions: 644 kind: pod name: kube-proxy-worker-bex82-v1.31.8-x9kg4 namespace: kube-system  
                                                         
                                                     
                                                    
                                                        openstack 
                                                        
                                                            details: fileName: /var/lib/kubelet/pods/c1afd1ba-2ab9-43f3-a306-c810e02cd47d/volumes/kubernetes.io~configmap/kube-proxy-config/config.yaml, permissions: 644 kind: pod name: kube-proxy-worker-dqty2-v1.31.8-9sx78 namespace: kube-system  
                                                            details: fileName: /var/lib/kubelet/pods/c1afd1ba-2ab9-43f3-a306-c810e02cd47d/volumes/kubernetes.io~secret/kubeconfig/kubeconfig, permissions: 644 kind: pod name: kube-proxy-worker-dqty2-v1.31.8-9sx78 namespace: kube-system  
                                                         
                                                     
                                                 
                                             
                                         
                                     
                                    
                                        242448 (Medium) - The Kubernetes Kube Proxy kubeconfig must be owned by root. 
                                        
                                            
                                                File has expected owners 
                                                
                                                    
                                                        aws 
                                                        
                                                            details: fileName: /var/lib/kubelet/pods/d0c8ecde-b8ca-4e6b-bb08-1cbc0775438d/volumes/kubernetes.io~configmap/kube-proxy-config/config.yaml, ownerUser: 0, ownerGroup: 0 kind: pod name: kube-proxy-worker-kkfk1-v1.31.8-8bvtn namespace: kube-system  
                                                            details: fileName: /var/lib/kubelet/pods/d0c8ecde-b8ca-4e6b-bb08-1cbc0775438d/volumes/kubernetes.io~secret/kubeconfig/kubeconfig, ownerUser: 0, ownerGroup: 0 kind: pod name: kube-proxy-worker-kkfk1-v1.31.8-8bvtn namespace: kube-system  
                                                         
                                                     
                                                    
                                                        azure 
                                                        
                                                            details: fileName: /var/lib/kubelet/pods/7f34a064-2a9b-48d4-a97f-57ed2fc7a389/volumes/kubernetes.io~configmap/kube-proxy-config/config.yaml, ownerUser: 0, ownerGroup: 0 kind: pod name: kube-proxy-worker-g7p4p-v1.31.8-7dnc5 namespace: kube-system  
                                                            details: fileName: /var/lib/kubelet/pods/7f34a064-2a9b-48d4-a97f-57ed2fc7a389/volumes/kubernetes.io~secret/kubeconfig/kubeconfig, ownerUser: 0, ownerGroup: 0 kind: pod name: kube-proxy-worker-g7p4p-v1.31.8-7dnc5 namespace: kube-system  
                                                         
                                                     
                                                    
                                                        gcp 
                                                        
                                                            details: fileName: /var/lib/kubelet/pods/4933cf73-66c0-4f8e-b07d-54a68fc93917/volumes/kubernetes.io~configmap/kube-proxy-config/config.yaml, ownerUser: 0, ownerGroup: 0 kind: pod name: kube-proxy-worker-bex82-v1.31.8-x9kg4 namespace: kube-system  
                                                            details: fileName: /var/lib/kubelet/pods/4933cf73-66c0-4f8e-b07d-54a68fc93917/volumes/kubernetes.io~secret/kubeconfig/kubeconfig, ownerUser: 0, ownerGroup: 0 kind: pod name: kube-proxy-worker-bex82-v1.31.8-x9kg4 namespace: kube-system  
                                                         
                                                     
                                                    
                                                        openstack 
                                                        
                                                            details: fileName: /var/lib/kubelet/pods/c1afd1ba-2ab9-43f3-a306-c810e02cd47d/volumes/kubernetes.io~configmap/kube-proxy-config/config.yaml, ownerUser: 0, ownerGroup: 0 kind: pod name: kube-proxy-worker-dqty2-v1.31.8-9sx78 namespace: kube-system  
                                                            details: fileName: /var/lib/kubelet/pods/c1afd1ba-2ab9-43f3-a306-c810e02cd47d/volumes/kubernetes.io~secret/kubeconfig/kubeconfig, ownerUser: 0, ownerGroup: 0 kind: pod name: kube-proxy-worker-dqty2-v1.31.8-9sx78 namespace: kube-system  
                                                         
                                                     
                                                 
                                             
                                         
                                     
                                    
                                        242449 (Medium) - The Kubernetes Kubelet certificate authority file must have file permissions set to 644 or more restrictive. 
                                        
                                            
                                                File has expected permissions 
                                                
                                                    
                                                        aws 
                                                        
                                                            details: fileName: /var/lib/kubelet/ca.crt, permissions: 644 kind: node name: ip-IP-Address.eu-west-1.compute.internal  
                                                         
                                                     
                                                    
                                                        azure 
                                                        
                                                            details: fileName: /var/lib/kubelet/ca.crt, permissions: 644 kind: node name: shoot--diki-comp--azure-worker-g7p4p-z3-66467-k6q5n  
                                                         
                                                     
                                                    
                                                        gcp 
                                                        
                                                            details: fileName: /var/lib/kubelet/ca.crt, permissions: 644 kind: node name: shoot--diki-comp--gcp-worker-bex82-z1-5d9b4-8fp7q  
                                                         
                                                     
                                                    
                                                        openstack 
                                                        
                                                            details: fileName: /var/lib/kubelet/ca.crt, permissions: 644 kind: node name: shoot--diki-comp--openstack-worker-dqty2-z1-64f7d-jllmm  
                                                         
                                                     
                                                 
                                             
                                         
                                     
                                    
                                        242450 (Medium) - The Kubernetes Kubelet certificate authority must be owned by root. 
                                        
                                            
                                                File has expected owners 
                                                
                                                    
                                                        aws 
                                                        
                                                            details: fileName: /var/lib/kubelet/ca.crt, ownerUser: 0, ownerGroup: 0 kind: node name: ip-IP-Address.eu-west-1.compute.internal  
                                                         
                                                     
                                                    
                                                        azure 
                                                        
                                                            details: fileName: /var/lib/kubelet/ca.crt, ownerUser: 0, ownerGroup: 0 kind: node name: shoot--diki-comp--azure-worker-g7p4p-z3-66467-k6q5n  
                                                         
                                                     
                                                    
                                                        gcp 
                                                        
                                                            details: fileName: /var/lib/kubelet/ca.crt, ownerUser: 0, ownerGroup: 0 kind: node name: shoot--diki-comp--gcp-worker-bex82-z1-5d9b4-8fp7q  
                                                         
                                                     
                                                    
                                                        openstack 
                                                        
                                                            details: fileName: /var/lib/kubelet/ca.crt, ownerUser: 0, ownerGroup: 0 kind: node name: shoot--diki-comp--openstack-worker-dqty2-z1-64f7d-jllmm  
                                                         
                                                     
                                                 
                                             
                                         
                                     
                                    
                                        242451 (Medium) - The Kubernetes component PKI must be owned by root. 
                                        
                                            
                                                File has expected owners 
                                                
                                                    
                                                        aws 
                                                        
                                                            cluster: seed containerName: etcd details: fileName: /var/lib/kubelet/pods/8500de88-870c-4453-a9d3-673fe2e83591/volumes/kubernetes.io~secret/etcd-ca/..2025_06_23_00_02_28.1460198907/bundle.crt, ownerUser: 0, ownerGroup: 65532 kind: pod name: etcd-events-0 namespace: shoot--diki-comp--aws  
                                                            cluster: seed containerName: etcd details: fileName: /var/lib/kubelet/pods/8500de88-870c-4453-a9d3-673fe2e83591/volumes/kubernetes.io~secret/etcd-server-tls/..2025_06_23_00_02_28.1081429868/tls.key, ownerUser: 0, ownerGroup: 65532 kind: pod name: etcd-events-0 namespace: shoot--diki-comp--aws  
                                                            cluster: seed containerName: etcd details: fileName: /var/lib/kubelet/pods/8500de88-870c-4453-a9d3-673fe2e83591/volumes/kubernetes.io~secret/etcd-server-tls/..2025_06_23_00_02_28.1081429868/tls.crt, ownerUser: 0, ownerGroup: 65532 kind: pod name: etcd-events-0 namespace: shoot--diki-comp--aws  
                                                            cluster: seed containerName: etcd details: fileName: /var/lib/kubelet/pods/8500de88-870c-4453-a9d3-673fe2e83591/volumes/kubernetes.io~secret/etcd-client-tls/..2025_06_23_00_02_28.830733358/tls.key, ownerUser: 0, ownerGroup: 65532 kind: pod name: etcd-events-0 namespace: shoot--diki-comp--aws  
                                                            cluster: seed containerName: etcd details: fileName: /var/lib/kubelet/pods/8500de88-870c-4453-a9d3-673fe2e83591/volumes/kubernetes.io~secret/etcd-client-tls/..2025_06_23_00_02_28.830733358/tls.crt, ownerUser: 0, ownerGroup: 65532 kind: pod name: etcd-events-0 namespace: shoot--diki-comp--aws  
                                                            cluster: seed containerName: etcd details: fileName: /var/lib/kubelet/pods/8500de88-870c-4453-a9d3-673fe2e83591/volumes/kubernetes.io~secret/backup-restore-ca/..2025_06_23_00_02_28.402585131/bundle.crt, ownerUser: 0, ownerGroup: 65532 kind: pod name: etcd-events-0 namespace: shoot--diki-comp--aws  
                                                            cluster: seed containerName: etcd details: fileName: /var/lib/kubelet/pods/8500de88-870c-4453-a9d3-673fe2e83591/volumes/kubernetes.io~projected/kube-api-access-gardener/..2025_06_23_00_02_28.124882621/ca.crt, ownerUser: 0, ownerGroup: 65532 kind: pod name: etcd-events-0 namespace: shoot--diki-comp--aws  
                                                            cluster: seed containerName: etcd details: fileName: /var/lib/kubelet/pods/8500de88-870c-4453-a9d3-673fe2e83591/volumes/kubernetes.io~secret/etcd-ca/..2025_06_23_00_02_28.1460198907, ownerUser: 0, ownerGroup: 65532 kind: pod name: etcd-events-0 namespace: shoot--diki-comp--aws  
                                                            cluster: seed containerName: etcd details: fileName: /var/lib/kubelet/pods/8500de88-870c-4453-a9d3-673fe2e83591/volumes/kubernetes.io~secret/etcd-server-tls/..2025_06_23_00_02_28.1081429868, ownerUser: 0, ownerGroup: 65532 kind: pod name: etcd-events-0 namespace: shoot--diki-comp--aws  
                                                            cluster: seed containerName: etcd details: fileName: /var/lib/kubelet/pods/8500de88-870c-4453-a9d3-673fe2e83591/volumes/kubernetes.io~secret/etcd-client-tls/..2025_06_23_00_02_28.830733358, ownerUser: 0, ownerGroup: 65532 kind: pod name: etcd-events-0 namespace: shoot--diki-comp--aws  
                                                            cluster: seed containerName: etcd details: fileName: /var/lib/kubelet/pods/8500de88-870c-4453-a9d3-673fe2e83591/volumes/kubernetes.io~secret/backup-restore-ca/..2025_06_23_00_02_28.402585131, ownerUser: 0, ownerGroup: 65532 kind: pod name: etcd-events-0 namespace: shoot--diki-comp--aws  
                                                            cluster: seed containerName: etcd details: fileName: /var/lib/kubelet/pods/8500de88-870c-4453-a9d3-673fe2e83591/volumes/kubernetes.io~projected/kube-api-access-gardener/..2025_06_23_00_02_28.124882621, ownerUser: 0, ownerGroup: 65532 kind: pod name: etcd-events-0 namespace: shoot--diki-comp--aws  
                                                            cluster: seed containerName: backup-restore details: fileName: /var/lib/kubelet/pods/8500de88-870c-4453-a9d3-673fe2e83591/volumes/kubernetes.io~secret/backup-restore-server-tls/..2025_06_23_00_02_28.1357612372/tls.key, ownerUser: 0, ownerGroup: 65532 kind: pod name: etcd-events-0 namespace: shoot--diki-comp--aws  
                                                            cluster: seed containerName: backup-restore details: fileName: /var/lib/kubelet/pods/8500de88-870c-4453-a9d3-673fe2e83591/volumes/kubernetes.io~secret/backup-restore-server-tls/..2025_06_23_00_02_28.1357612372/tls.crt, ownerUser: 0, ownerGroup: 65532 kind: pod name: etcd-events-0 namespace: shoot--diki-comp--aws  
                                                            cluster: seed containerName: backup-restore details: fileName: /var/lib/kubelet/pods/8500de88-870c-4453-a9d3-673fe2e83591/volumes/kubernetes.io~secret/etcd-ca/..2025_06_23_00_02_28.1460198907/bundle.crt, ownerUser: 0, ownerGroup: 65532 kind: pod name: etcd-events-0 namespace: shoot--diki-comp--aws  
                                                            cluster: seed containerName: backup-restore details: fileName: /var/lib/kubelet/pods/8500de88-870c-4453-a9d3-673fe2e83591/volumes/kubernetes.io~secret/etcd-client-tls/..2025_06_23_00_02_28.830733358/tls.key, ownerUser: 0, ownerGroup: 65532 kind: pod name: etcd-events-0 namespace: shoot--diki-comp--aws  
                                                            cluster: seed containerName: backup-restore details: fileName: /var/lib/kubelet/pods/8500de88-870c-4453-a9d3-673fe2e83591/volumes/kubernetes.io~secret/etcd-client-tls/..2025_06_23_00_02_28.830733358/tls.crt, ownerUser: 0, ownerGroup: 65532 kind: pod name: etcd-events-0 namespace: shoot--diki-comp--aws  
                                                            cluster: seed containerName: backup-restore details: fileName: /var/lib/kubelet/pods/8500de88-870c-4453-a9d3-673fe2e83591/volumes/kubernetes.io~projected/kube-api-access-gardener/..2025_06_23_00_02_28.124882621/ca.crt, ownerUser: 0, ownerGroup: 65532 kind: pod name: etcd-events-0 namespace: shoot--diki-comp--aws  
                                                            cluster: seed containerName: backup-restore details: fileName: /var/lib/kubelet/pods/8500de88-870c-4453-a9d3-673fe2e83591/volumes/kubernetes.io~secret/backup-restore-server-tls/..2025_06_23_00_02_28.1357612372, ownerUser: 0, ownerGroup: 65532 kind: pod name: etcd-events-0 namespace: shoot--diki-comp--aws  
                                                            cluster: seed containerName: backup-restore details: fileName: /var/lib/kubelet/pods/8500de88-870c-4453-a9d3-673fe2e83591/volumes/kubernetes.io~secret/etcd-ca/..2025_06_23_00_02_28.1460198907, ownerUser: 0, ownerGroup: 65532 kind: pod name: etcd-events-0 namespace: shoot--diki-comp--aws  
                                                            cluster: seed containerName: backup-restore details: fileName: /var/lib/kubelet/pods/8500de88-870c-4453-a9d3-673fe2e83591/volumes/kubernetes.io~secret/etcd-client-tls/..2025_06_23_00_02_28.830733358, ownerUser: 0, ownerGroup: 65532 kind: pod name: etcd-events-0 namespace: shoot--diki-comp--aws  
                                                            cluster: seed containerName: backup-restore details: fileName: /var/lib/kubelet/pods/8500de88-870c-4453-a9d3-673fe2e83591/volumes/kubernetes.io~projected/kube-api-access-gardener/..2025_06_23_00_02_28.124882621, ownerUser: 0, ownerGroup: 65532 kind: pod name: etcd-events-0 namespace: shoot--diki-comp--aws  
                                                            cluster: seed containerName: kube-scheduler details: fileName: /var/lib/kubelet/pods/06134fb6-0360-493d-adc6-38d710393b11/volumes/kubernetes.io~projected/client-ca/..2025_06_23_00_10_38.120749235/bundle.crt, ownerUser: 0, ownerGroup: 65532 kind: pod name: kube-scheduler-5854d54c7c-2b7mv namespace: shoot--diki-comp--aws  
                                                            cluster: seed containerName: kube-scheduler details: fileName: /var/lib/kubelet/pods/06134fb6-0360-493d-adc6-38d710393b11/volumes/kubernetes.io~secret/kube-scheduler-server/..2025_06_23_00_10_38.1273189684/tls.key, ownerUser: 0, ownerGroup: 65532 kind: pod name: kube-scheduler-5854d54c7c-2b7mv namespace: shoot--diki-comp--aws  
                                                            cluster: seed containerName: kube-scheduler details: fileName: /var/lib/kubelet/pods/06134fb6-0360-493d-adc6-38d710393b11/volumes/kubernetes.io~secret/kube-scheduler-server/..2025_06_23_00_10_38.1273189684/tls.crt, ownerUser: 0, ownerGroup: 65532 kind: pod name: kube-scheduler-5854d54c7c-2b7mv namespace: shoot--diki-comp--aws  
                                                            cluster: seed containerName: kube-scheduler details: fileName: /var/lib/kubelet/pods/06134fb6-0360-493d-adc6-38d710393b11/volumes/kubernetes.io~projected/client-ca/..2025_06_23_00_10_38.120749235, ownerUser: 0, ownerGroup: 65532 kind: pod name: kube-scheduler-5854d54c7c-2b7mv namespace: shoot--diki-comp--aws  
                                                            cluster: seed containerName: kube-scheduler details: fileName: /var/lib/kubelet/pods/06134fb6-0360-493d-adc6-38d710393b11/volumes/kubernetes.io~secret/kube-scheduler-server/..2025_06_23_00_10_38.1273189684, ownerUser: 0, ownerGroup: 65532 kind: pod name: kube-scheduler-5854d54c7c-2b7mv namespace: shoot--diki-comp--aws  
                                                            cluster: seed containerName: kube-controller-manager details: fileName: /var/lib/kubelet/pods/c423b64c-cb58-46fa-a956-022b9b1664c6/volumes/kubernetes.io~secret/ca/..2025_06_23_00_16_39.892891764/bundle.crt, ownerUser: 0, ownerGroup: 65532 kind: pod name: kube-controller-manager-7c9bc75987-cqgs4 namespace: shoot--diki-comp--aws  
                                                            cluster: seed containerName: kube-controller-manager details: fileName: /var/lib/kubelet/pods/c423b64c-cb58-46fa-a956-022b9b1664c6/volumes/kubernetes.io~secret/ca-client/..2025_06_23_00_16_39.4293646224/ca.key, ownerUser: 0, ownerGroup: 65532 kind: pod name: kube-controller-manager-7c9bc75987-cqgs4 namespace: shoot--diki-comp--aws  
                                                            cluster: seed containerName: kube-controller-manager details: fileName: /var/lib/kubelet/pods/c423b64c-cb58-46fa-a956-022b9b1664c6/volumes/kubernetes.io~secret/ca-client/..2025_06_23_00_16_39.4293646224/ca.crt, ownerUser: 0, ownerGroup: 65532 kind: pod name: kube-controller-manager-7c9bc75987-cqgs4 namespace: shoot--diki-comp--aws  
                                                            cluster: seed containerName: kube-controller-manager details: fileName: /var/lib/kubelet/pods/c423b64c-cb58-46fa-a956-022b9b1664c6/volumes/kubernetes.io~secret/server/..2025_06_23_00_16_39.867879351/tls.key, ownerUser: 0, ownerGroup: 65532 kind: pod name: kube-controller-manager-7c9bc75987-cqgs4 namespace: shoot--diki-comp--aws  
                                                            cluster: seed containerName: kube-controller-manager details: fileName: /var/lib/kubelet/pods/c423b64c-cb58-46fa-a956-022b9b1664c6/volumes/kubernetes.io~secret/server/..2025_06_23_00_16_39.867879351/tls.crt, ownerUser: 0, ownerGroup: 65532 kind: pod name: kube-controller-manager-7c9bc75987-cqgs4 namespace: shoot--diki-comp--aws  
                                                            cluster: seed containerName: kube-controller-manager details: fileName: /var/lib/kubelet/pods/c423b64c-cb58-46fa-a956-022b9b1664c6/volumes/kubernetes.io~secret/ca-kubelet/..2025_06_23_00_16_39.254040933/ca.key, ownerUser: 0, ownerGroup: 65532 kind: pod name: kube-controller-manager-7c9bc75987-cqgs4 namespace: shoot--diki-comp--aws  
                                                            cluster: seed containerName: kube-controller-manager details: fileName: /var/lib/kubelet/pods/c423b64c-cb58-46fa-a956-022b9b1664c6/volumes/kubernetes.io~secret/ca-kubelet/..2025_06_23_00_16_39.254040933/ca.crt, ownerUser: 0, ownerGroup: 65532 kind: pod name: kube-controller-manager-7c9bc75987-cqgs4 namespace: shoot--diki-comp--aws  
                                                            cluster: seed containerName: kube-controller-manager details: fileName: /var/lib/kubelet/pods/c423b64c-cb58-46fa-a956-022b9b1664c6/volumes/kubernetes.io~secret/ca-client/..2025_06_23_00_16_39.4293646224, ownerUser: 0, ownerGroup: 65532 kind: pod name: kube-controller-manager-7c9bc75987-cqgs4 namespace: shoot--diki-comp--aws  
                                                            cluster: seed containerName: kube-controller-manager details: fileName: /var/lib/kubelet/pods/c423b64c-cb58-46fa-a956-022b9b1664c6/volumes/kubernetes.io~secret/server/..2025_06_23_00_16_39.867879351, ownerUser: 0, ownerGroup: 65532 kind: pod name: kube-controller-manager-7c9bc75987-cqgs4 namespace: shoot--diki-comp--aws  
                                                            cluster: seed containerName: kube-controller-manager details: fileName: /var/lib/kubelet/pods/c423b64c-cb58-46fa-a956-022b9b1664c6/volumes/kubernetes.io~secret/ca-kubelet/..2025_06_23_00_16_39.254040933, ownerUser: 0, ownerGroup: 65532 kind: pod name: kube-controller-manager-7c9bc75987-cqgs4 namespace: shoot--diki-comp--aws  
                                                            cluster: seed containerName: kube-controller-manager details: fileName: /var/lib/kubelet/pods/c423b64c-cb58-46fa-a956-022b9b1664c6/volumes/kubernetes.io~secret/ca/..2025_06_23_00_16_39.892891764, ownerUser: 0, ownerGroup: 65532 kind: pod name: kube-controller-manager-7c9bc75987-cqgs4 namespace: shoot--diki-comp--aws  
                                                            cluster: seed containerName: etcd details: fileName: /var/lib/kubelet/pods/e9a97103-bea9-4174-9f2f-d11c7dee0b81/volumes/kubernetes.io~secret/etcd-ca/..2025_06_23_00_02_28.70977455/bundle.crt, ownerUser: 0, ownerGroup: 65532 kind: pod name: etcd-main-0 namespace: shoot--diki-comp--aws  
                                                            cluster: seed containerName: etcd details: fileName: /var/lib/kubelet/pods/e9a97103-bea9-4174-9f2f-d11c7dee0b81/volumes/kubernetes.io~secret/etcd-server-tls/..2025_06_23_00_02_28.941742504/tls.crt, ownerUser: 0, ownerGroup: 65532 kind: pod name: etcd-main-0 namespace: shoot--diki-comp--aws  
                                                            cluster: seed containerName: etcd details: fileName: /var/lib/kubelet/pods/e9a97103-bea9-4174-9f2f-d11c7dee0b81/volumes/kubernetes.io~secret/etcd-server-tls/..2025_06_23_00_02_28.941742504/tls.key, ownerUser: 0, ownerGroup: 65532 kind: pod name: etcd-main-0 namespace: shoot--diki-comp--aws  
                                                            cluster: seed containerName: etcd details: fileName: /var/lib/kubelet/pods/e9a97103-bea9-4174-9f2f-d11c7dee0b81/volumes/kubernetes.io~secret/etcd-client-tls/..2025_06_23_00_02_28.581061777/tls.key, ownerUser: 0, ownerGroup: 65532 kind: pod name: etcd-main-0 namespace: shoot--diki-comp--aws  
                                                            cluster: seed containerName: etcd details: fileName: /var/lib/kubelet/pods/e9a97103-bea9-4174-9f2f-d11c7dee0b81/volumes/kubernetes.io~secret/etcd-client-tls/..2025_06_23_00_02_28.581061777/tls.crt, ownerUser: 0, ownerGroup: 65532 kind: pod name: etcd-main-0 namespace: shoot--diki-comp--aws  
                                                            cluster: seed containerName: etcd details: fileName: /var/lib/kubelet/pods/e9a97103-bea9-4174-9f2f-d11c7dee0b81/volumes/kubernetes.io~secret/backup-restore-ca/..2025_06_23_00_02_28.3789989883/bundle.crt, ownerUser: 0, ownerGroup: 65532 kind: pod name: etcd-main-0 namespace: shoot--diki-comp--aws  
                                                            cluster: seed containerName: etcd details: fileName: /var/lib/kubelet/pods/e9a97103-bea9-4174-9f2f-d11c7dee0b81/volumes/kubernetes.io~projected/kube-api-access-gardener/..2025_06_23_00_02_28.4232825321/ca.crt, ownerUser: 0, ownerGroup: 65532 kind: pod name: etcd-main-0 namespace: shoot--diki-comp--aws  
                                                            cluster: seed containerName: etcd details: fileName: /var/lib/kubelet/pods/e9a97103-bea9-4174-9f2f-d11c7dee0b81/volumes/kubernetes.io~secret/backup-restore-ca/..2025_06_23_00_02_28.3789989883, ownerUser: 0, ownerGroup: 65532 kind: pod name: etcd-main-0 namespace: shoot--diki-comp--aws  
                                                            cluster: seed containerName: etcd details: fileName: /var/lib/kubelet/pods/e9a97103-bea9-4174-9f2f-d11c7dee0b81/volumes/kubernetes.io~projected/kube-api-access-gardener/..2025_06_23_00_02_28.4232825321, ownerUser: 0, ownerGroup: 65532 kind: pod name: etcd-main-0 namespace: shoot--diki-comp--aws  
                                                            cluster: seed containerName: etcd details: fileName: /var/lib/kubelet/pods/e9a97103-bea9-4174-9f2f-d11c7dee0b81/volumes/kubernetes.io~secret/etcd-ca/..2025_06_23_00_02_28.70977455, ownerUser: 0, ownerGroup: 65532 kind: pod name: etcd-main-0 namespace: shoot--diki-comp--aws  
                                                            cluster: seed containerName: etcd details: fileName: /var/lib/kubelet/pods/e9a97103-bea9-4174-9f2f-d11c7dee0b81/volumes/kubernetes.io~secret/etcd-server-tls/..2025_06_23_00_02_28.941742504, ownerUser: 0, ownerGroup: 65532 kind: pod name: etcd-main-0 namespace: shoot--diki-comp--aws  
                                                            cluster: seed containerName: etcd details: fileName: /var/lib/kubelet/pods/e9a97103-bea9-4174-9f2f-d11c7dee0b81/volumes/kubernetes.io~secret/etcd-client-tls/..2025_06_23_00_02_28.581061777, ownerUser: 0, ownerGroup: 65532 kind: pod name: etcd-main-0 namespace: shoot--diki-comp--aws  
                                                            cluster: seed containerName: backup-restore details: fileName: /var/lib/kubelet/pods/e9a97103-bea9-4174-9f2f-d11c7dee0b81/volumes/kubernetes.io~secret/backup-restore-server-tls/..2025_06_23_00_02_28.137193825/tls.key, ownerUser: 0, ownerGroup: 65532 kind: pod name: etcd-main-0 namespace: shoot--diki-comp--aws  
                                                            cluster: seed containerName: backup-restore details: fileName: /var/lib/kubelet/pods/e9a97103-bea9-4174-9f2f-d11c7dee0b81/volumes/kubernetes.io~secret/backup-restore-server-tls/..2025_06_23_00_02_28.137193825/tls.crt, ownerUser: 0, ownerGroup: 65532 kind: pod name: etcd-main-0 namespace: shoot--diki-comp--aws  
                                                            cluster: seed containerName: backup-restore details: fileName: /var/lib/kubelet/pods/e9a97103-bea9-4174-9f2f-d11c7dee0b81/volumes/kubernetes.io~secret/etcd-ca/..2025_06_23_00_02_28.70977455/bundle.crt, ownerUser: 0, ownerGroup: 65532 kind: pod name: etcd-main-0 namespace: shoot--diki-comp--aws  
                                                            cluster: seed containerName: backup-restore details: fileName: /var/lib/kubelet/pods/e9a97103-bea9-4174-9f2f-d11c7dee0b81/volumes/kubernetes.io~secret/etcd-client-tls/..2025_06_23_00_02_28.581061777/tls.key, ownerUser: 0, ownerGroup: 65532 kind: pod name: etcd-main-0 namespace: shoot--diki-comp--aws  
                                                            cluster: seed containerName: backup-restore details: fileName: /var/lib/kubelet/pods/e9a97103-bea9-4174-9f2f-d11c7dee0b81/volumes/kubernetes.io~secret/etcd-client-tls/..2025_06_23_00_02_28.581061777/tls.crt, ownerUser: 0, ownerGroup: 65532 kind: pod name: etcd-main-0 namespace: shoot--diki-comp--aws  
                                                            cluster: seed containerName: backup-restore details: fileName: /var/lib/kubelet/pods/e9a97103-bea9-4174-9f2f-d11c7dee0b81/volumes/kubernetes.io~projected/kube-api-access-gardener/..2025_06_23_00_02_28.4232825321/ca.crt, ownerUser: 0, ownerGroup: 65532 kind: pod name: etcd-main-0 namespace: shoot--diki-comp--aws  
                                                            cluster: seed containerName: backup-restore details: fileName: /var/lib/kubelet/pods/e9a97103-bea9-4174-9f2f-d11c7dee0b81/volumes/kubernetes.io~secret/backup-restore-server-tls/..2025_06_23_00_02_28.137193825, ownerUser: 0, ownerGroup: 65532 kind: pod name: etcd-main-0 namespace: shoot--diki-comp--aws  
                                                            cluster: seed containerName: backup-restore details: fileName: /var/lib/kubelet/pods/e9a97103-bea9-4174-9f2f-d11c7dee0b81/volumes/kubernetes.io~secret/etcd-ca/..2025_06_23_00_02_28.70977455, ownerUser: 0, ownerGroup: 65532 kind: pod name: etcd-main-0 namespace: shoot--diki-comp--aws  
                                                            cluster: seed containerName: backup-restore details: fileName: /var/lib/kubelet/pods/e9a97103-bea9-4174-9f2f-d11c7dee0b81/volumes/kubernetes.io~secret/etcd-client-tls/..2025_06_23_00_02_28.581061777, ownerUser: 0, ownerGroup: 65532 kind: pod name: etcd-main-0 namespace: shoot--diki-comp--aws  
                                                            cluster: seed containerName: backup-restore details: fileName: /var/lib/kubelet/pods/e9a97103-bea9-4174-9f2f-d11c7dee0b81/volumes/kubernetes.io~projected/kube-api-access-gardener/..2025_06_23_00_02_28.4232825321, ownerUser: 0, ownerGroup: 65532 kind: pod name: etcd-main-0 namespace: shoot--diki-comp--aws  
                                                            cluster: seed containerName: kube-apiserver details: fileName: /var/lib/kubelet/pods/42db629f-9d43-492e-92df-f2a0ac97d2b6/volumes/kubernetes.io~secret/ca/..2025_06_23_00_09_39.1820813547/bundle.crt, ownerUser: 0, ownerGroup: 65532 kind: pod name: kube-apiserver-6d847f96d4-82qpt namespace: shoot--diki-comp--aws  
                                                            cluster: seed containerName: kube-apiserver details: fileName: /var/lib/kubelet/pods/42db629f-9d43-492e-92df-f2a0ac97d2b6/volumes/kubernetes.io~secret/ca-client/..2025_06_23_00_09_39.3911158577/bundle.crt, ownerUser: 0, ownerGroup: 65532 kind: pod name: kube-apiserver-6d847f96d4-82qpt namespace: shoot--diki-comp--aws  
                                                            cluster: seed containerName: kube-apiserver details: fileName: /var/lib/kubelet/pods/42db629f-9d43-492e-92df-f2a0ac97d2b6/volumes/kubernetes.io~secret/ca-front-proxy/..2025_06_23_00_09_39.1216619138/bundle.crt, ownerUser: 0, ownerGroup: 65532 kind: pod name: kube-apiserver-6d847f96d4-82qpt namespace: shoot--diki-comp--aws  
                                                            cluster: seed containerName: kube-apiserver details: fileName: /var/lib/kubelet/pods/42db629f-9d43-492e-92df-f2a0ac97d2b6/volumes/kubernetes.io~secret/service-account-key-bundle/..2025_06_23_00_09_39.1536096673/bundle.key, ownerUser: 0, ownerGroup: 65532 kind: pod name: kube-apiserver-6d847f96d4-82qpt namespace: shoot--diki-comp--aws  
                                                            cluster: seed containerName: kube-apiserver details: fileName: /var/lib/kubelet/pods/42db629f-9d43-492e-92df-f2a0ac97d2b6/volumes/kubernetes.io~secret/kube-aggregator/..2025_06_23_00_09_39.3585741192/tls.key, ownerUser: 0, ownerGroup: 65532 kind: pod name: kube-apiserver-6d847f96d4-82qpt namespace: shoot--diki-comp--aws  
                                                            cluster: seed containerName: kube-apiserver details: fileName: /var/lib/kubelet/pods/42db629f-9d43-492e-92df-f2a0ac97d2b6/volumes/kubernetes.io~secret/kube-aggregator/..2025_06_23_00_09_39.3585741192/tls.crt, ownerUser: 0, ownerGroup: 65532 kind: pod name: kube-apiserver-6d847f96d4-82qpt namespace: shoot--diki-comp--aws  
                                                            cluster: seed containerName: kube-apiserver details: fileName: /var/lib/kubelet/pods/42db629f-9d43-492e-92df-f2a0ac97d2b6/volumes/kubernetes.io~secret/server/..2025_06_23_00_09_39.2101876528/tls.key, ownerUser: 0, ownerGroup: 65532 kind: pod name: kube-apiserver-6d847f96d4-82qpt namespace: shoot--diki-comp--aws  
                                                            cluster: seed containerName: kube-apiserver details: fileName: /var/lib/kubelet/pods/42db629f-9d43-492e-92df-f2a0ac97d2b6/volumes/kubernetes.io~secret/server/..2025_06_23_00_09_39.2101876528/tls.crt, ownerUser: 0, ownerGroup: 65532 kind: pod name: kube-apiserver-6d847f96d4-82qpt namespace: shoot--diki-comp--aws  
                                                            cluster: seed containerName: kube-apiserver details: fileName: /var/lib/kubelet/pods/42db629f-9d43-492e-92df-f2a0ac97d2b6/volumes/kubernetes.io~secret/ca-vpn/..2025_06_23_00_09_39.1345136145/bundle.crt, ownerUser: 0, ownerGroup: 65532 kind: pod name: kube-apiserver-6d847f96d4-82qpt namespace: shoot--diki-comp--aws  
                                                            cluster: seed containerName: kube-apiserver details: fileName: /var/lib/kubelet/pods/42db629f-9d43-492e-92df-f2a0ac97d2b6/volumes/kubernetes.io~secret/ca-kubelet/..2025_06_23_00_09_39.2968989444/bundle.crt, ownerUser: 0, ownerGroup: 65532 kind: pod name: kube-apiserver-6d847f96d4-82qpt namespace: shoot--diki-comp--aws  
                                                            cluster: seed containerName: kube-apiserver details: fileName: /var/lib/kubelet/pods/42db629f-9d43-492e-92df-f2a0ac97d2b6/volumes/kubernetes.io~secret/kubelet-client/..2025_06_23_00_09_39.2120918226/tls.key, ownerUser: 0, ownerGroup: 65532 kind: pod name: kube-apiserver-6d847f96d4-82qpt namespace: shoot--diki-comp--aws  
                                                            cluster: seed containerName: kube-apiserver details: fileName: /var/lib/kubelet/pods/42db629f-9d43-492e-92df-f2a0ac97d2b6/volumes/kubernetes.io~secret/kubelet-client/..2025_06_23_00_09_39.2120918226/tls.crt, ownerUser: 0, ownerGroup: 65532 kind: pod name: kube-apiserver-6d847f96d4-82qpt namespace: shoot--diki-comp--aws  
                                                            cluster: seed containerName: kube-apiserver details: fileName: /var/lib/kubelet/pods/42db629f-9d43-492e-92df-f2a0ac97d2b6/volumes/kubernetes.io~secret/ca-etcd/..2025_06_23_00_09_39.86038190/bundle.crt, ownerUser: 0, ownerGroup: 65532 kind: pod name: kube-apiserver-6d847f96d4-82qpt namespace: shoot--diki-comp--aws  
                                                            cluster: seed containerName: kube-apiserver details: fileName: /var/lib/kubelet/pods/42db629f-9d43-492e-92df-f2a0ac97d2b6/volumes/kubernetes.io~secret/etcd-client/..2025_06_23_00_09_39.3841361014/tls.crt, ownerUser: 0, ownerGroup: 65532 kind: pod name: kube-apiserver-6d847f96d4-82qpt namespace: shoot--diki-comp--aws  
                                                            cluster: seed containerName: kube-apiserver details: fileName: /var/lib/kubelet/pods/42db629f-9d43-492e-92df-f2a0ac97d2b6/volumes/kubernetes.io~secret/etcd-client/..2025_06_23_00_09_39.3841361014/tls.key, ownerUser: 0, ownerGroup: 65532 kind: pod name: kube-apiserver-6d847f96d4-82qpt namespace: shoot--diki-comp--aws  
                                                            cluster: seed containerName: kube-apiserver details: fileName: /var/lib/kubelet/pods/42db629f-9d43-492e-92df-f2a0ac97d2b6/volumes/kubernetes.io~secret/tls-sni-0/..2025_06_23_00_09_39.1534744055/tls.key, ownerUser: 0, ownerGroup: 65532 kind: pod name: kube-apiserver-6d847f96d4-82qpt namespace: shoot--diki-comp--aws  
                                                            cluster: seed containerName: kube-apiserver details: fileName: /var/lib/kubelet/pods/42db629f-9d43-492e-92df-f2a0ac97d2b6/volumes/kubernetes.io~secret/tls-sni-0/..2025_06_23_00_09_39.1534744055/tls.crt, ownerUser: 0, ownerGroup: 65532 kind: pod name: kube-apiserver-6d847f96d4-82qpt namespace: shoot--diki-comp--aws  
                                                            cluster: seed containerName: kube-apiserver details: fileName: /var/lib/kubelet/pods/42db629f-9d43-492e-92df-f2a0ac97d2b6/volumes/kubernetes.io~secret/tls-sni-0/..2025_06_23_00_09_39.1534744055/ca.crt, ownerUser: 0, ownerGroup: 65532 kind: pod name: kube-apiserver-6d847f96d4-82qpt namespace: shoot--diki-comp--aws  
                                                            cluster: seed containerName: kube-apiserver details: fileName: /var/lib/kubelet/pods/42db629f-9d43-492e-92df-f2a0ac97d2b6/volumes/kubernetes.io~secret/http-proxy/..2025_06_23_00_09_39.1635279459/tls.key, ownerUser: 0, ownerGroup: 65532 kind: pod name: kube-apiserver-6d847f96d4-82qpt namespace: shoot--diki-comp--aws  
                                                            cluster: seed containerName: kube-apiserver details: fileName: /var/lib/kubelet/pods/42db629f-9d43-492e-92df-f2a0ac97d2b6/volumes/kubernetes.io~secret/http-proxy/..2025_06_23_00_09_39.1635279459/tls.crt, ownerUser: 0, ownerGroup: 65532 kind: pod name: kube-apiserver-6d847f96d4-82qpt namespace: shoot--diki-comp--aws  
                                                            cluster: seed containerName: kube-apiserver details: fileName: /var/lib/kubelet/pods/42db629f-9d43-492e-92df-f2a0ac97d2b6/volumes/kubernetes.io~secret/ca/..2025_06_23_00_09_39.1820813547, ownerUser: 0, ownerGroup: 65532 kind: pod name: kube-apiserver-6d847f96d4-82qpt namespace: shoot--diki-comp--aws  
                                                            cluster: seed containerName: kube-apiserver details: fileName: /var/lib/kubelet/pods/42db629f-9d43-492e-92df-f2a0ac97d2b6/volumes/kubernetes.io~secret/ca-client/..2025_06_23_00_09_39.3911158577, ownerUser: 0, ownerGroup: 65532 kind: pod name: kube-apiserver-6d847f96d4-82qpt namespace: shoot--diki-comp--aws  
                                                            cluster: seed containerName: kube-apiserver details: fileName: /var/lib/kubelet/pods/42db629f-9d43-492e-92df-f2a0ac97d2b6/volumes/kubernetes.io~secret/ca-front-proxy/..2025_06_23_00_09_39.1216619138, ownerUser: 0, ownerGroup: 65532 kind: pod name: kube-apiserver-6d847f96d4-82qpt namespace: shoot--diki-comp--aws  
                                                            cluster: seed containerName: kube-apiserver details: fileName: /var/lib/kubelet/pods/42db629f-9d43-492e-92df-f2a0ac97d2b6/volumes/kubernetes.io~secret/kube-aggregator/..2025_06_23_00_09_39.3585741192, ownerUser: 0, ownerGroup: 65532 kind: pod name: kube-apiserver-6d847f96d4-82qpt namespace: shoot--diki-comp--aws  
                                                            cluster: seed containerName: kube-apiserver details: fileName: /var/lib/kubelet/pods/42db629f-9d43-492e-92df-f2a0ac97d2b6/volumes/kubernetes.io~secret/server/..2025_06_23_00_09_39.2101876528, ownerUser: 0, ownerGroup: 65532 kind: pod name: kube-apiserver-6d847f96d4-82qpt namespace: shoot--diki-comp--aws  
                                                            cluster: seed containerName: kube-apiserver details: fileName: /var/lib/kubelet/pods/42db629f-9d43-492e-92df-f2a0ac97d2b6/volumes/kubernetes.io~secret/ca-kubelet/..2025_06_23_00_09_39.2968989444, ownerUser: 0, ownerGroup: 65532 kind: pod name: kube-apiserver-6d847f96d4-82qpt namespace: shoot--diki-comp--aws  
                                                            cluster: seed containerName: kube-apiserver details: fileName: /var/lib/kubelet/pods/42db629f-9d43-492e-92df-f2a0ac97d2b6/volumes/kubernetes.io~secret/kubelet-client/..2025_06_23_00_09_39.2120918226, ownerUser: 0, ownerGroup: 65532 kind: pod name: kube-apiserver-6d847f96d4-82qpt namespace: shoot--diki-comp--aws  
                                                            cluster: seed containerName: kube-apiserver details: fileName: /var/lib/kubelet/pods/42db629f-9d43-492e-92df-f2a0ac97d2b6/volumes/kubernetes.io~secret/tls-sni-0/..2025_06_23_00_09_39.1534744055, ownerUser: 0, ownerGroup: 65532 kind: pod name: kube-apiserver-6d847f96d4-82qpt namespace: shoot--diki-comp--aws  
                                                            cluster: seed containerName: kube-apiserver details: fileName: /var/lib/kubelet/pods/42db629f-9d43-492e-92df-f2a0ac97d2b6/volumes/kubernetes.io~secret/service-account-key-bundle/..2025_06_23_00_09_39.1536096673, ownerUser: 0, ownerGroup: 65532 kind: pod name: kube-apiserver-6d847f96d4-82qpt namespace: shoot--diki-comp--aws  
                                                            cluster: seed containerName: kube-apiserver details: fileName: /var/lib/kubelet/pods/42db629f-9d43-492e-92df-f2a0ac97d2b6/volumes/kubernetes.io~secret/ca-vpn/..2025_06_23_00_09_39.1345136145, ownerUser: 0, ownerGroup: 65532 kind: pod name: kube-apiserver-6d847f96d4-82qpt namespace: shoot--diki-comp--aws  
                                                            cluster: seed containerName: kube-apiserver details: fileName: /var/lib/kubelet/pods/42db629f-9d43-492e-92df-f2a0ac97d2b6/volumes/kubernetes.io~secret/ca-etcd/..2025_06_23_00_09_39.86038190, ownerUser: 0, ownerGroup: 65532 kind: pod name: kube-apiserver-6d847f96d4-82qpt namespace: shoot--diki-comp--aws  
                                                            cluster: seed containerName: kube-apiserver details: fileName: /var/lib/kubelet/pods/42db629f-9d43-492e-92df-f2a0ac97d2b6/volumes/kubernetes.io~secret/etcd-client/..2025_06_23_00_09_39.3841361014, ownerUser: 0, ownerGroup: 65532 kind: pod name: kube-apiserver-6d847f96d4-82qpt namespace: shoot--diki-comp--aws  
                                                            cluster: seed containerName: kube-apiserver details: fileName: /var/lib/kubelet/pods/42db629f-9d43-492e-92df-f2a0ac97d2b6/volumes/kubernetes.io~secret/http-proxy/..2025_06_23_00_09_39.1635279459, ownerUser: 0, ownerGroup: 65532 kind: pod name: kube-apiserver-6d847f96d4-82qpt namespace: shoot--diki-comp--aws  
                                                            cluster: shoot details: fileName: /var/lib/kubelet/pki/kubelet-client-2025-06-23-00-08-33.pem, ownerUser: 0, ownerGroup: 0 kind: node name: ip-IP-Address.eu-west-1.compute.internal  
                                                            cluster: shoot details: fileName: /var/lib/kubelet/pki/kubelet-server-2025-06-23-00-08-57.pem, ownerUser: 0, ownerGroup: 0 kind: node name: ip-IP-Address.eu-west-1.compute.internal  
                                                            cluster: shoot details: fileName: /var/lib/kubelet/pki, ownerUser: 0, ownerGroup: 0 kind: node name: ip-IP-Address.eu-west-1.compute.internal  
                                                            cluster: shoot containerName: kube-proxy details: fileName: /var/lib/kubelet/pods/d0c8ecde-b8ca-4e6b-bb08-1cbc0775438d/volumes/kubernetes.io~projected/kube-api-access-gardener/..2025_06_23_00_08_35.3746123174/ca.crt, ownerUser: 0, ownerGroup: 0 kind: pod name: kube-proxy-worker-kkfk1-v1.31.8-8bvtn namespace: kube-system  
                                                            cluster: shoot containerName: kube-proxy details: fileName: /var/lib/kubelet/pods/d0c8ecde-b8ca-4e6b-bb08-1cbc0775438d/volumes/kubernetes.io~projected/kube-api-access-gardener/..2025_06_23_00_08_35.3746123174, ownerUser: 0, ownerGroup: 0 kind: pod name: kube-proxy-worker-kkfk1-v1.31.8-8bvtn namespace: kube-system  
                                                            cluster: shoot containerName: conntrack-fix details: fileName: /var/lib/kubelet/pods/d0c8ecde-b8ca-4e6b-bb08-1cbc0775438d/volumes/kubernetes.io~projected/kube-api-access-gardener/..2025_06_23_00_08_35.3746123174/ca.crt, ownerUser: 0, ownerGroup: 0 kind: pod name: kube-proxy-worker-kkfk1-v1.31.8-8bvtn namespace: kube-system  
                                                            cluster: shoot containerName: conntrack-fix details: fileName: /var/lib/kubelet/pods/d0c8ecde-b8ca-4e6b-bb08-1cbc0775438d/volumes/kubernetes.io~projected/kube-api-access-gardener/..2025_06_23_00_08_35.3746123174, ownerUser: 0, ownerGroup: 0 kind: pod name: kube-proxy-worker-kkfk1-v1.31.8-8bvtn namespace: kube-system  
                                                            cluster: shoot containerName: cleanup details: fileName: /var/lib/kubelet/pods/d0c8ecde-b8ca-4e6b-bb08-1cbc0775438d/volumes/kubernetes.io~projected/kube-api-access-gardener/..2025_06_23_00_08_35.3746123174/ca.crt, ownerUser: 0, ownerGroup: 0 kind: pod name: kube-proxy-worker-kkfk1-v1.31.8-8bvtn namespace: kube-system  
                                                            cluster: shoot containerName: cleanup details: fileName: /var/lib/kubelet/pods/d0c8ecde-b8ca-4e6b-bb08-1cbc0775438d/volumes/kubernetes.io~projected/kube-api-access-gardener/..2025_06_23_00_08_35.3746123174, ownerUser: 0, ownerGroup: 0 kind: pod name: kube-proxy-worker-kkfk1-v1.31.8-8bvtn namespace: kube-system  
                                                            cluster: shoot containerName: kube-proxy-init details: fileName: /var/lib/kubelet/pods/d0c8ecde-b8ca-4e6b-bb08-1cbc0775438d/volumes/kubernetes.io~projected/kube-api-access-gardener/..2025_06_23_00_08_35.3746123174/ca.crt, ownerUser: 0, ownerGroup: 0 kind: pod name: kube-proxy-worker-kkfk1-v1.31.8-8bvtn namespace: kube-system  
                                                            cluster: shoot containerName: kube-proxy-init details: fileName: /var/lib/kubelet/pods/d0c8ecde-b8ca-4e6b-bb08-1cbc0775438d/volumes/kubernetes.io~projected/kube-api-access-gardener/..2025_06_23_00_08_35.3746123174, ownerUser: 0, ownerGroup: 0 kind: pod name: kube-proxy-worker-kkfk1-v1.31.8-8bvtn namespace: kube-system  
                                                         
                                                     
                                                    
                                                        azure 
                                                        
                                                            cluster: seed containerName: kube-apiserver details: fileName: /var/lib/kubelet/pods/19e8d0fb-e648-458d-9824-7002ba098bce/volumes/kubernetes.io~secret/ca/..2025_06_23_00_14_46.3142548715/bundle.crt, ownerUser: 0, ownerGroup: 65532 kind: pod name: kube-apiserver-d66f4d44f-tm4cs namespace: shoot--diki-comp--azure  
                                                            cluster: seed containerName: kube-apiserver details: fileName: /var/lib/kubelet/pods/19e8d0fb-e648-458d-9824-7002ba098bce/volumes/kubernetes.io~secret/ca-client/..2025_06_23_00_14_46.1427032518/bundle.crt, ownerUser: 0, ownerGroup: 65532 kind: pod name: kube-apiserver-d66f4d44f-tm4cs namespace: shoot--diki-comp--azure  
                                                            cluster: seed containerName: kube-apiserver details: fileName: /var/lib/kubelet/pods/19e8d0fb-e648-458d-9824-7002ba098bce/volumes/kubernetes.io~secret/ca-front-proxy/..2025_06_23_00_14_46.1493427643/bundle.crt, ownerUser: 0, ownerGroup: 65532 kind: pod name: kube-apiserver-d66f4d44f-tm4cs namespace: shoot--diki-comp--azure  
                                                            cluster: seed containerName: kube-apiserver details: fileName: /var/lib/kubelet/pods/19e8d0fb-e648-458d-9824-7002ba098bce/volumes/kubernetes.io~secret/service-account-key-bundle/..2025_06_23_00_14_46.504056214/bundle.key, ownerUser: 0, ownerGroup: 65532 kind: pod name: kube-apiserver-d66f4d44f-tm4cs namespace: shoot--diki-comp--azure  
                                                            cluster: seed containerName: kube-apiserver details: fileName: /var/lib/kubelet/pods/19e8d0fb-e648-458d-9824-7002ba098bce/volumes/kubernetes.io~secret/kube-aggregator/..2025_06_23_00_14_46.2139614939/tls.key, ownerUser: 0, ownerGroup: 65532 kind: pod name: kube-apiserver-d66f4d44f-tm4cs namespace: shoot--diki-comp--azure  
                                                            cluster: seed containerName: kube-apiserver details: fileName: /var/lib/kubelet/pods/19e8d0fb-e648-458d-9824-7002ba098bce/volumes/kubernetes.io~secret/kube-aggregator/..2025_06_23_00_14_46.2139614939/tls.crt, ownerUser: 0, ownerGroup: 65532 kind: pod name: kube-apiserver-d66f4d44f-tm4cs namespace: shoot--diki-comp--azure  
                                                            cluster: seed containerName: kube-apiserver details: fileName: /var/lib/kubelet/pods/19e8d0fb-e648-458d-9824-7002ba098bce/volumes/kubernetes.io~secret/server/..2025_06_23_00_14_46.2186093174/tls.key, ownerUser: 0, ownerGroup: 65532 kind: pod name: kube-apiserver-d66f4d44f-tm4cs namespace: shoot--diki-comp--azure  
                                                            cluster: seed containerName: kube-apiserver details: fileName: /var/lib/kubelet/pods/19e8d0fb-e648-458d-9824-7002ba098bce/volumes/kubernetes.io~secret/server/..2025_06_23_00_14_46.2186093174/tls.crt, ownerUser: 0, ownerGroup: 65532 kind: pod name: kube-apiserver-d66f4d44f-tm4cs namespace: shoot--diki-comp--azure  
                                                            cluster: seed containerName: kube-apiserver details: fileName: /var/lib/kubelet/pods/19e8d0fb-e648-458d-9824-7002ba098bce/volumes/kubernetes.io~secret/ca-vpn/..2025_06_23_00_14_46.3412290611/bundle.crt, ownerUser: 0, ownerGroup: 65532 kind: pod name: kube-apiserver-d66f4d44f-tm4cs namespace: shoot--diki-comp--azure  
                                                            cluster: seed containerName: kube-apiserver details: fileName: /var/lib/kubelet/pods/19e8d0fb-e648-458d-9824-7002ba098bce/volumes/kubernetes.io~secret/ca-kubelet/..2025_06_23_00_14_46.3112199018/bundle.crt, ownerUser: 0, ownerGroup: 65532 kind: pod name: kube-apiserver-d66f4d44f-tm4cs namespace: shoot--diki-comp--azure  
                                                            cluster: seed containerName: kube-apiserver details: fileName: /var/lib/kubelet/pods/19e8d0fb-e648-458d-9824-7002ba098bce/volumes/kubernetes.io~secret/kubelet-client/..2025_06_23_00_14_46.2446316166/tls.crt, ownerUser: 0, ownerGroup: 65532 kind: pod name: kube-apiserver-d66f4d44f-tm4cs namespace: shoot--diki-comp--azure  
                                                            cluster: seed containerName: kube-apiserver details: fileName: /var/lib/kubelet/pods/19e8d0fb-e648-458d-9824-7002ba098bce/volumes/kubernetes.io~secret/kubelet-client/..2025_06_23_00_14_46.2446316166/tls.key, ownerUser: 0, ownerGroup: 65532 kind: pod name: kube-apiserver-d66f4d44f-tm4cs namespace: shoot--diki-comp--azure  
                                                            cluster: seed containerName: kube-apiserver details: fileName: /var/lib/kubelet/pods/19e8d0fb-e648-458d-9824-7002ba098bce/volumes/kubernetes.io~secret/ca-etcd/..2025_06_23_00_14_46.3219727173/bundle.crt, ownerUser: 0, ownerGroup: 65532 kind: pod name: kube-apiserver-d66f4d44f-tm4cs namespace: shoot--diki-comp--azure  
                                                            cluster: seed containerName: kube-apiserver details: fileName: /var/lib/kubelet/pods/19e8d0fb-e648-458d-9824-7002ba098bce/volumes/kubernetes.io~secret/etcd-client/..2025_06_23_00_14_46.1466414181/tls.key, ownerUser: 0, ownerGroup: 65532 kind: pod name: kube-apiserver-d66f4d44f-tm4cs namespace: shoot--diki-comp--azure  
                                                            cluster: seed containerName: kube-apiserver details: fileName: /var/lib/kubelet/pods/19e8d0fb-e648-458d-9824-7002ba098bce/volumes/kubernetes.io~secret/etcd-client/..2025_06_23_00_14_46.1466414181/tls.crt, ownerUser: 0, ownerGroup: 65532 kind: pod name: kube-apiserver-d66f4d44f-tm4cs namespace: shoot--diki-comp--azure  
                                                            cluster: seed containerName: kube-apiserver details: fileName: /var/lib/kubelet/pods/19e8d0fb-e648-458d-9824-7002ba098bce/volumes/kubernetes.io~secret/tls-sni-0/..2025_06_23_00_14_46.1021198322/tls.key, ownerUser: 0, ownerGroup: 65532 kind: pod name: kube-apiserver-d66f4d44f-tm4cs namespace: shoot--diki-comp--azure  
                                                            cluster: seed containerName: kube-apiserver details: fileName: /var/lib/kubelet/pods/19e8d0fb-e648-458d-9824-7002ba098bce/volumes/kubernetes.io~secret/tls-sni-0/..2025_06_23_00_14_46.1021198322/tls.crt, ownerUser: 0, ownerGroup: 65532 kind: pod name: kube-apiserver-d66f4d44f-tm4cs namespace: shoot--diki-comp--azure  
                                                            cluster: seed containerName: kube-apiserver details: fileName: /var/lib/kubelet/pods/19e8d0fb-e648-458d-9824-7002ba098bce/volumes/kubernetes.io~secret/tls-sni-0/..2025_06_23_00_14_46.1021198322/ca.crt, ownerUser: 0, ownerGroup: 65532 kind: pod name: kube-apiserver-d66f4d44f-tm4cs namespace: shoot--diki-comp--azure  
                                                            cluster: seed containerName: kube-apiserver details: fileName: /var/lib/kubelet/pods/19e8d0fb-e648-458d-9824-7002ba098bce/volumes/kubernetes.io~secret/http-proxy/..2025_06_23_00_14_46.234968055/tls.key, ownerUser: 0, ownerGroup: 65532 kind: pod name: kube-apiserver-d66f4d44f-tm4cs namespace: shoot--diki-comp--azure  
                                                            cluster: seed containerName: kube-apiserver details: fileName: /var/lib/kubelet/pods/19e8d0fb-e648-458d-9824-7002ba098bce/volumes/kubernetes.io~secret/http-proxy/..2025_06_23_00_14_46.234968055/tls.crt, ownerUser: 0, ownerGroup: 65532 kind: pod name: kube-apiserver-d66f4d44f-tm4cs namespace: shoot--diki-comp--azure  
                                                            cluster: seed containerName: kube-apiserver details: fileName: /var/lib/kubelet/pods/19e8d0fb-e648-458d-9824-7002ba098bce/volumes/kubernetes.io~secret/ca/..2025_06_23_00_14_46.3142548715, ownerUser: 0, ownerGroup: 65532 kind: pod name: kube-apiserver-d66f4d44f-tm4cs namespace: shoot--diki-comp--azure  
                                                            cluster: seed containerName: kube-apiserver details: fileName: /var/lib/kubelet/pods/19e8d0fb-e648-458d-9824-7002ba098bce/volumes/kubernetes.io~secret/ca-client/..2025_06_23_00_14_46.1427032518, ownerUser: 0, ownerGroup: 65532 kind: pod name: kube-apiserver-d66f4d44f-tm4cs namespace: shoot--diki-comp--azure  
                                                            cluster: seed containerName: kube-apiserver details: fileName: /var/lib/kubelet/pods/19e8d0fb-e648-458d-9824-7002ba098bce/volumes/kubernetes.io~secret/ca-front-proxy/..2025_06_23_00_14_46.1493427643, ownerUser: 0, ownerGroup: 65532 kind: pod name: kube-apiserver-d66f4d44f-tm4cs namespace: shoot--diki-comp--azure  
                                                            cluster: seed containerName: kube-apiserver details: fileName: /var/lib/kubelet/pods/19e8d0fb-e648-458d-9824-7002ba098bce/volumes/kubernetes.io~secret/service-account-key-bundle/..2025_06_23_00_14_46.504056214, ownerUser: 0, ownerGroup: 65532 kind: pod name: kube-apiserver-d66f4d44f-tm4cs namespace: shoot--diki-comp--azure  
                                                            cluster: seed containerName: kube-apiserver details: fileName: /var/lib/kubelet/pods/19e8d0fb-e648-458d-9824-7002ba098bce/volumes/kubernetes.io~secret/server/..2025_06_23_00_14_46.2186093174, ownerUser: 0, ownerGroup: 65532 kind: pod name: kube-apiserver-d66f4d44f-tm4cs namespace: shoot--diki-comp--azure  
                                                            cluster: seed containerName: kube-apiserver details: fileName: /var/lib/kubelet/pods/19e8d0fb-e648-458d-9824-7002ba098bce/volumes/kubernetes.io~secret/ca-kubelet/..2025_06_23_00_14_46.3112199018, ownerUser: 0, ownerGroup: 65532 kind: pod name: kube-apiserver-d66f4d44f-tm4cs namespace: shoot--diki-comp--azure  
                                                            cluster: seed containerName: kube-apiserver details: fileName: /var/lib/kubelet/pods/19e8d0fb-e648-458d-9824-7002ba098bce/volumes/kubernetes.io~secret/kubelet-client/..2025_06_23_00_14_46.2446316166, ownerUser: 0, ownerGroup: 65532 kind: pod name: kube-apiserver-d66f4d44f-tm4cs namespace: shoot--diki-comp--azure  
                                                            cluster: seed containerName: kube-apiserver details: fileName: /var/lib/kubelet/pods/19e8d0fb-e648-458d-9824-7002ba098bce/volumes/kubernetes.io~secret/ca-etcd/..2025_06_23_00_14_46.3219727173, ownerUser: 0, ownerGroup: 65532 kind: pod name: kube-apiserver-d66f4d44f-tm4cs namespace: shoot--diki-comp--azure  
                                                            cluster: seed containerName: kube-apiserver details: fileName: /var/lib/kubelet/pods/19e8d0fb-e648-458d-9824-7002ba098bce/volumes/kubernetes.io~secret/kube-aggregator/..2025_06_23_00_14_46.2139614939, ownerUser: 0, ownerGroup: 65532 kind: pod name: kube-apiserver-d66f4d44f-tm4cs namespace: shoot--diki-comp--azure  
                                                            cluster: seed containerName: kube-apiserver details: fileName: /var/lib/kubelet/pods/19e8d0fb-e648-458d-9824-7002ba098bce/volumes/kubernetes.io~secret/ca-vpn/..2025_06_23_00_14_46.3412290611, ownerUser: 0, ownerGroup: 65532 kind: pod name: kube-apiserver-d66f4d44f-tm4cs namespace: shoot--diki-comp--azure  
                                                            cluster: seed containerName: kube-apiserver details: fileName: /var/lib/kubelet/pods/19e8d0fb-e648-458d-9824-7002ba098bce/volumes/kubernetes.io~secret/etcd-client/..2025_06_23_00_14_46.1466414181, ownerUser: 0, ownerGroup: 65532 kind: pod name: kube-apiserver-d66f4d44f-tm4cs namespace: shoot--diki-comp--azure  
                                                            cluster: seed containerName: kube-apiserver details: fileName: /var/lib/kubelet/pods/19e8d0fb-e648-458d-9824-7002ba098bce/volumes/kubernetes.io~secret/tls-sni-0/..2025_06_23_00_14_46.1021198322, ownerUser: 0, ownerGroup: 65532 kind: pod name: kube-apiserver-d66f4d44f-tm4cs namespace: shoot--diki-comp--azure  
                                                            cluster: seed containerName: kube-apiserver details: fileName: /var/lib/kubelet/pods/19e8d0fb-e648-458d-9824-7002ba098bce/volumes/kubernetes.io~secret/http-proxy/..2025_06_23_00_14_46.234968055, ownerUser: 0, ownerGroup: 65532 kind: pod name: kube-apiserver-d66f4d44f-tm4cs namespace: shoot--diki-comp--azure  
                                                            cluster: seed containerName: kube-controller-manager details: fileName: /var/lib/kubelet/pods/8a5510fe-a88b-42cc-b90a-1d8f9487d887/volumes/kubernetes.io~secret/ca/..2025_06_23_00_19_46.2289618773/bundle.crt, ownerUser: 0, ownerGroup: 65532 kind: pod name: kube-controller-manager-7d869c84b8-kz7dm namespace: shoot--diki-comp--azure  
                                                            cluster: seed containerName: kube-controller-manager details: fileName: /var/lib/kubelet/pods/8a5510fe-a88b-42cc-b90a-1d8f9487d887/volumes/kubernetes.io~secret/ca-client/..2025_06_23_00_19_46.1556017874/ca.crt, ownerUser: 0, ownerGroup: 65532 kind: pod name: kube-controller-manager-7d869c84b8-kz7dm namespace: shoot--diki-comp--azure  
                                                            cluster: seed containerName: kube-controller-manager details: fileName: /var/lib/kubelet/pods/8a5510fe-a88b-42cc-b90a-1d8f9487d887/volumes/kubernetes.io~secret/ca-client/..2025_06_23_00_19_46.1556017874/ca.key, ownerUser: 0, ownerGroup: 65532 kind: pod name: kube-controller-manager-7d869c84b8-kz7dm namespace: shoot--diki-comp--azure  
                                                            cluster: seed containerName: kube-controller-manager details: fileName: /var/lib/kubelet/pods/8a5510fe-a88b-42cc-b90a-1d8f9487d887/volumes/kubernetes.io~secret/server/..2025_06_23_00_19_46.3137963724/tls.key, ownerUser: 0, ownerGroup: 65532 kind: pod name: kube-controller-manager-7d869c84b8-kz7dm namespace: shoot--diki-comp--azure  
                                                            cluster: seed containerName: kube-controller-manager details: fileName: /var/lib/kubelet/pods/8a5510fe-a88b-42cc-b90a-1d8f9487d887/volumes/kubernetes.io~secret/server/..2025_06_23_00_19_46.3137963724/tls.crt, ownerUser: 0, ownerGroup: 65532 kind: pod name: kube-controller-manager-7d869c84b8-kz7dm namespace: shoot--diki-comp--azure  
                                                            cluster: seed containerName: kube-controller-manager details: fileName: /var/lib/kubelet/pods/8a5510fe-a88b-42cc-b90a-1d8f9487d887/volumes/kubernetes.io~secret/ca-kubelet/..2025_06_23_00_19_46.2139875717/ca.crt, ownerUser: 0, ownerGroup: 65532 kind: pod name: kube-controller-manager-7d869c84b8-kz7dm namespace: shoot--diki-comp--azure  
                                                            cluster: seed containerName: kube-controller-manager details: fileName: /var/lib/kubelet/pods/8a5510fe-a88b-42cc-b90a-1d8f9487d887/volumes/kubernetes.io~secret/ca-kubelet/..2025_06_23_00_19_46.2139875717/ca.key, ownerUser: 0, ownerGroup: 65532 kind: pod name: kube-controller-manager-7d869c84b8-kz7dm namespace: shoot--diki-comp--azure  
                                                            cluster: seed containerName: kube-controller-manager details: fileName: /var/lib/kubelet/pods/8a5510fe-a88b-42cc-b90a-1d8f9487d887/volumes/kubernetes.io~secret/ca/..2025_06_23_00_19_46.2289618773, ownerUser: 0, ownerGroup: 65532 kind: pod name: kube-controller-manager-7d869c84b8-kz7dm namespace: shoot--diki-comp--azure  
                                                            cluster: seed containerName: kube-controller-manager details: fileName: /var/lib/kubelet/pods/8a5510fe-a88b-42cc-b90a-1d8f9487d887/volumes/kubernetes.io~secret/ca-client/..2025_06_23_00_19_46.1556017874, ownerUser: 0, ownerGroup: 65532 kind: pod name: kube-controller-manager-7d869c84b8-kz7dm namespace: shoot--diki-comp--azure  
                                                            cluster: seed containerName: kube-controller-manager details: fileName: /var/lib/kubelet/pods/8a5510fe-a88b-42cc-b90a-1d8f9487d887/volumes/kubernetes.io~secret/server/..2025_06_23_00_19_46.3137963724, ownerUser: 0, ownerGroup: 65532 kind: pod name: kube-controller-manager-7d869c84b8-kz7dm namespace: shoot--diki-comp--azure  
                                                            cluster: seed containerName: kube-controller-manager details: fileName: /var/lib/kubelet/pods/8a5510fe-a88b-42cc-b90a-1d8f9487d887/volumes/kubernetes.io~secret/ca-kubelet/..2025_06_23_00_19_46.2139875717, ownerUser: 0, ownerGroup: 65532 kind: pod name: kube-controller-manager-7d869c84b8-kz7dm namespace: shoot--diki-comp--azure  
                                                            cluster: seed containerName: kube-scheduler details: fileName: /var/lib/kubelet/pods/8afdd891-92eb-4c6a-aac5-9a324987f6ad/volumes/kubernetes.io~projected/client-ca/..2025_06_23_00_14_46.3397349168/bundle.crt, ownerUser: 0, ownerGroup: 65532 kind: pod name: kube-scheduler-67fdbc4569-h6j7v namespace: shoot--diki-comp--azure  
                                                            cluster: seed containerName: kube-scheduler details: fileName: /var/lib/kubelet/pods/8afdd891-92eb-4c6a-aac5-9a324987f6ad/volumes/kubernetes.io~secret/kube-scheduler-server/..2025_06_23_00_14_46.366944806/tls.key, ownerUser: 0, ownerGroup: 65532 kind: pod name: kube-scheduler-67fdbc4569-h6j7v namespace: shoot--diki-comp--azure  
                                                            cluster: seed containerName: kube-scheduler details: fileName: /var/lib/kubelet/pods/8afdd891-92eb-4c6a-aac5-9a324987f6ad/volumes/kubernetes.io~secret/kube-scheduler-server/..2025_06_23_00_14_46.366944806/tls.crt, ownerUser: 0, ownerGroup: 65532 kind: pod name: kube-scheduler-67fdbc4569-h6j7v namespace: shoot--diki-comp--azure  
                                                            cluster: seed containerName: kube-scheduler details: fileName: /var/lib/kubelet/pods/8afdd891-92eb-4c6a-aac5-9a324987f6ad/volumes/kubernetes.io~projected/client-ca/..2025_06_23_00_14_46.3397349168, ownerUser: 0, ownerGroup: 65532 kind: pod name: kube-scheduler-67fdbc4569-h6j7v namespace: shoot--diki-comp--azure  
                                                            cluster: seed containerName: kube-scheduler details: fileName: /var/lib/kubelet/pods/8afdd891-92eb-4c6a-aac5-9a324987f6ad/volumes/kubernetes.io~secret/kube-scheduler-server/..2025_06_23_00_14_46.366944806, ownerUser: 0, ownerGroup: 65532 kind: pod name: kube-scheduler-67fdbc4569-h6j7v namespace: shoot--diki-comp--azure  
                                                            cluster: seed containerName: etcd details: fileName: /var/lib/kubelet/pods/d86b08b7-3d10-49ae-a4d6-4fe9fa757c93/volumes/kubernetes.io~secret/etcd-ca/..2025_06_23_00_02_37.231883813/bundle.crt, ownerUser: 0, ownerGroup: 65532 kind: pod name: etcd-main-0 namespace: shoot--diki-comp--azure  
                                                            cluster: seed containerName: etcd details: fileName: /var/lib/kubelet/pods/d86b08b7-3d10-49ae-a4d6-4fe9fa757c93/volumes/kubernetes.io~secret/etcd-server-tls/..2025_06_23_00_02_37.4111409223/tls.key, ownerUser: 0, ownerGroup: 65532 kind: pod name: etcd-main-0 namespace: shoot--diki-comp--azure  
                                                            cluster: seed containerName: etcd details: fileName: /var/lib/kubelet/pods/d86b08b7-3d10-49ae-a4d6-4fe9fa757c93/volumes/kubernetes.io~secret/etcd-server-tls/..2025_06_23_00_02_37.4111409223/tls.crt, ownerUser: 0, ownerGroup: 65532 kind: pod name: etcd-main-0 namespace: shoot--diki-comp--azure  
                                                            cluster: seed containerName: etcd details: fileName: /var/lib/kubelet/pods/d86b08b7-3d10-49ae-a4d6-4fe9fa757c93/volumes/kubernetes.io~secret/etcd-client-tls/..2025_06_23_00_02_37.256397641/tls.key, ownerUser: 0, ownerGroup: 65532 kind: pod name: etcd-main-0 namespace: shoot--diki-comp--azure  
                                                            cluster: seed containerName: etcd details: fileName: /var/lib/kubelet/pods/d86b08b7-3d10-49ae-a4d6-4fe9fa757c93/volumes/kubernetes.io~secret/etcd-client-tls/..2025_06_23_00_02_37.256397641/tls.crt, ownerUser: 0, ownerGroup: 65532 kind: pod name: etcd-main-0 namespace: shoot--diki-comp--azure  
                                                            cluster: seed containerName: etcd details: fileName: /var/lib/kubelet/pods/d86b08b7-3d10-49ae-a4d6-4fe9fa757c93/volumes/kubernetes.io~secret/backup-restore-ca/..2025_06_23_00_02_37.1332383038/bundle.crt, ownerUser: 0, ownerGroup: 65532 kind: pod name: etcd-main-0 namespace: shoot--diki-comp--azure  
                                                            cluster: seed containerName: etcd details: fileName: /var/lib/kubelet/pods/d86b08b7-3d10-49ae-a4d6-4fe9fa757c93/volumes/kubernetes.io~projected/kube-api-access-gardener/..2025_06_23_00_02_37.3272012549/ca.crt, ownerUser: 0, ownerGroup: 65532 kind: pod name: etcd-main-0 namespace: shoot--diki-comp--azure  
                                                            cluster: seed containerName: etcd details: fileName: /var/lib/kubelet/pods/d86b08b7-3d10-49ae-a4d6-4fe9fa757c93/volumes/kubernetes.io~secret/etcd-ca/..2025_06_23_00_02_37.231883813, ownerUser: 0, ownerGroup: 65532 kind: pod name: etcd-main-0 namespace: shoot--diki-comp--azure  
                                                            cluster: seed containerName: etcd details: fileName: /var/lib/kubelet/pods/d86b08b7-3d10-49ae-a4d6-4fe9fa757c93/volumes/kubernetes.io~secret/etcd-server-tls/..2025_06_23_00_02_37.4111409223, ownerUser: 0, ownerGroup: 65532 kind: pod name: etcd-main-0 namespace: shoot--diki-comp--azure  
                                                            cluster: seed containerName: etcd details: fileName: /var/lib/kubelet/pods/d86b08b7-3d10-49ae-a4d6-4fe9fa757c93/volumes/kubernetes.io~secret/etcd-client-tls/..2025_06_23_00_02_37.256397641, ownerUser: 0, ownerGroup: 65532 kind: pod name: etcd-main-0 namespace: shoot--diki-comp--azure  
                                                            cluster: seed containerName: etcd details: fileName: /var/lib/kubelet/pods/d86b08b7-3d10-49ae-a4d6-4fe9fa757c93/volumes/kubernetes.io~secret/backup-restore-ca/..2025_06_23_00_02_37.1332383038, ownerUser: 0, ownerGroup: 65532 kind: pod name: etcd-main-0 namespace: shoot--diki-comp--azure  
                                                            cluster: seed containerName: etcd details: fileName: /var/lib/kubelet/pods/d86b08b7-3d10-49ae-a4d6-4fe9fa757c93/volumes/kubernetes.io~projected/kube-api-access-gardener/..2025_06_23_00_02_37.3272012549, ownerUser: 0, ownerGroup: 65532 kind: pod name: etcd-main-0 namespace: shoot--diki-comp--azure  
                                                            cluster: seed containerName: backup-restore details: fileName: /var/lib/kubelet/pods/d86b08b7-3d10-49ae-a4d6-4fe9fa757c93/volumes/kubernetes.io~secret/backup-restore-server-tls/..2025_06_23_00_02_37.2487232432/tls.key, ownerUser: 0, ownerGroup: 65532 kind: pod name: etcd-main-0 namespace: shoot--diki-comp--azure  
                                                            cluster: seed containerName: backup-restore details: fileName: /var/lib/kubelet/pods/d86b08b7-3d10-49ae-a4d6-4fe9fa757c93/volumes/kubernetes.io~secret/backup-restore-server-tls/..2025_06_23_00_02_37.2487232432/tls.crt, ownerUser: 0, ownerGroup: 65532 kind: pod name: etcd-main-0 namespace: shoot--diki-comp--azure  
                                                            cluster: seed containerName: backup-restore details: fileName: /var/lib/kubelet/pods/d86b08b7-3d10-49ae-a4d6-4fe9fa757c93/volumes/kubernetes.io~secret/etcd-ca/..2025_06_23_00_02_37.231883813/bundle.crt, ownerUser: 0, ownerGroup: 65532 kind: pod name: etcd-main-0 namespace: shoot--diki-comp--azure  
                                                            cluster: seed containerName: backup-restore details: fileName: /var/lib/kubelet/pods/d86b08b7-3d10-49ae-a4d6-4fe9fa757c93/volumes/kubernetes.io~secret/etcd-client-tls/..2025_06_23_00_02_37.256397641/tls.key, ownerUser: 0, ownerGroup: 65532 kind: pod name: etcd-main-0 namespace: shoot--diki-comp--azure  
                                                            cluster: seed containerName: backup-restore details: fileName: /var/lib/kubelet/pods/d86b08b7-3d10-49ae-a4d6-4fe9fa757c93/volumes/kubernetes.io~secret/etcd-client-tls/..2025_06_23_00_02_37.256397641/tls.crt, ownerUser: 0, ownerGroup: 65532 kind: pod name: etcd-main-0 namespace: shoot--diki-comp--azure  
                                                            cluster: seed containerName: backup-restore details: fileName: /var/lib/kubelet/pods/d86b08b7-3d10-49ae-a4d6-4fe9fa757c93/volumes/kubernetes.io~projected/kube-api-access-gardener/..2025_06_23_00_02_37.3272012549/ca.crt, ownerUser: 0, ownerGroup: 65532 kind: pod name: etcd-main-0 namespace: shoot--diki-comp--azure  
                                                            cluster: seed containerName: backup-restore details: fileName: /var/lib/kubelet/pods/d86b08b7-3d10-49ae-a4d6-4fe9fa757c93/volumes/kubernetes.io~projected/kube-api-access-gardener/..2025_06_23_00_02_37.3272012549, ownerUser: 0, ownerGroup: 65532 kind: pod name: etcd-main-0 namespace: shoot--diki-comp--azure  
                                                            cluster: seed containerName: backup-restore details: fileName: /var/lib/kubelet/pods/d86b08b7-3d10-49ae-a4d6-4fe9fa757c93/volumes/kubernetes.io~secret/backup-restore-server-tls/..2025_06_23_00_02_37.2487232432, ownerUser: 0, ownerGroup: 65532 kind: pod name: etcd-main-0 namespace: shoot--diki-comp--azure  
                                                            cluster: seed containerName: backup-restore details: fileName: /var/lib/kubelet/pods/d86b08b7-3d10-49ae-a4d6-4fe9fa757c93/volumes/kubernetes.io~secret/etcd-ca/..2025_06_23_00_02_37.231883813, ownerUser: 0, ownerGroup: 65532 kind: pod name: etcd-main-0 namespace: shoot--diki-comp--azure  
                                                            cluster: seed containerName: backup-restore details: fileName: /var/lib/kubelet/pods/d86b08b7-3d10-49ae-a4d6-4fe9fa757c93/volumes/kubernetes.io~secret/etcd-client-tls/..2025_06_23_00_02_37.256397641, ownerUser: 0, ownerGroup: 65532 kind: pod name: etcd-main-0 namespace: shoot--diki-comp--azure  
                                                            cluster: seed containerName: etcd details: fileName: /var/lib/kubelet/pods/74f71030-9c73-40a7-b50e-fb1bb70cb9a5/volumes/kubernetes.io~secret/etcd-ca/..2025_06_23_00_02_36.1146945202/bundle.crt, ownerUser: 0, ownerGroup: 65532 kind: pod name: etcd-events-0 namespace: shoot--diki-comp--azure  
                                                            cluster: seed containerName: etcd details: fileName: /var/lib/kubelet/pods/74f71030-9c73-40a7-b50e-fb1bb70cb9a5/volumes/kubernetes.io~secret/etcd-server-tls/..2025_06_23_00_02_36.3673560748/tls.key, ownerUser: 0, ownerGroup: 65532 kind: pod name: etcd-events-0 namespace: shoot--diki-comp--azure  
                                                            cluster: seed containerName: etcd details: fileName: /var/lib/kubelet/pods/74f71030-9c73-40a7-b50e-fb1bb70cb9a5/volumes/kubernetes.io~secret/etcd-server-tls/..2025_06_23_00_02_36.3673560748/tls.crt, ownerUser: 0, ownerGroup: 65532 kind: pod name: etcd-events-0 namespace: shoot--diki-comp--azure  
                                                            cluster: seed containerName: etcd details: fileName: /var/lib/kubelet/pods/74f71030-9c73-40a7-b50e-fb1bb70cb9a5/volumes/kubernetes.io~secret/etcd-client-tls/..2025_06_23_00_02_36.3852713643/tls.crt, ownerUser: 0, ownerGroup: 65532 kind: pod name: etcd-events-0 namespace: shoot--diki-comp--azure  
                                                            cluster: seed containerName: etcd details: fileName: /var/lib/kubelet/pods/74f71030-9c73-40a7-b50e-fb1bb70cb9a5/volumes/kubernetes.io~secret/etcd-client-tls/..2025_06_23_00_02_36.3852713643/tls.key, ownerUser: 0, ownerGroup: 65532 kind: pod name: etcd-events-0 namespace: shoot--diki-comp--azure  
                                                            cluster: seed containerName: etcd details: fileName: /var/lib/kubelet/pods/74f71030-9c73-40a7-b50e-fb1bb70cb9a5/volumes/kubernetes.io~secret/backup-restore-ca/..2025_06_23_00_02_36.3194705379/bundle.crt, ownerUser: 0, ownerGroup: 65532 kind: pod name: etcd-events-0 namespace: shoot--diki-comp--azure  
                                                            cluster: seed containerName: etcd details: fileName: /var/lib/kubelet/pods/74f71030-9c73-40a7-b50e-fb1bb70cb9a5/volumes/kubernetes.io~projected/kube-api-access-gardener/..2025_06_23_00_02_36.662581379/ca.crt, ownerUser: 0, ownerGroup: 65532 kind: pod name: etcd-events-0 namespace: shoot--diki-comp--azure  
                                                            cluster: seed containerName: etcd details: fileName: /var/lib/kubelet/pods/74f71030-9c73-40a7-b50e-fb1bb70cb9a5/volumes/kubernetes.io~secret/etcd-server-tls/..2025_06_23_00_02_36.3673560748, ownerUser: 0, ownerGroup: 65532 kind: pod name: etcd-events-0 namespace: shoot--diki-comp--azure  
                                                            cluster: seed containerName: etcd details: fileName: /var/lib/kubelet/pods/74f71030-9c73-40a7-b50e-fb1bb70cb9a5/volumes/kubernetes.io~secret/etcd-client-tls/..2025_06_23_00_02_36.3852713643, ownerUser: 0, ownerGroup: 65532 kind: pod name: etcd-events-0 namespace: shoot--diki-comp--azure  
                                                            cluster: seed containerName: etcd details: fileName: /var/lib/kubelet/pods/74f71030-9c73-40a7-b50e-fb1bb70cb9a5/volumes/kubernetes.io~secret/backup-restore-ca/..2025_06_23_00_02_36.3194705379, ownerUser: 0, ownerGroup: 65532 kind: pod name: etcd-events-0 namespace: shoot--diki-comp--azure  
                                                            cluster: seed containerName: etcd details: fileName: /var/lib/kubelet/pods/74f71030-9c73-40a7-b50e-fb1bb70cb9a5/volumes/kubernetes.io~projected/kube-api-access-gardener/..2025_06_23_00_02_36.662581379, ownerUser: 0, ownerGroup: 65532 kind: pod name: etcd-events-0 namespace: shoot--diki-comp--azure  
                                                            cluster: seed containerName: etcd details: fileName: /var/lib/kubelet/pods/74f71030-9c73-40a7-b50e-fb1bb70cb9a5/volumes/kubernetes.io~secret/etcd-ca/..2025_06_23_00_02_36.1146945202, ownerUser: 0, ownerGroup: 65532 kind: pod name: etcd-events-0 namespace: shoot--diki-comp--azure  
                                                            cluster: seed containerName: backup-restore details: fileName: /var/lib/kubelet/pods/74f71030-9c73-40a7-b50e-fb1bb70cb9a5/volumes/kubernetes.io~secret/backup-restore-server-tls/..2025_06_23_00_02_36.327312203/tls.key, ownerUser: 0, ownerGroup: 65532 kind: pod name: etcd-events-0 namespace: shoot--diki-comp--azure  
                                                            cluster: seed containerName: backup-restore details: fileName: /var/lib/kubelet/pods/74f71030-9c73-40a7-b50e-fb1bb70cb9a5/volumes/kubernetes.io~secret/backup-restore-server-tls/..2025_06_23_00_02_36.327312203/tls.crt, ownerUser: 0, ownerGroup: 65532 kind: pod name: etcd-events-0 namespace: shoot--diki-comp--azure  
                                                            cluster: seed containerName: backup-restore details: fileName: /var/lib/kubelet/pods/74f71030-9c73-40a7-b50e-fb1bb70cb9a5/volumes/kubernetes.io~secret/etcd-ca/..2025_06_23_00_02_36.1146945202/bundle.crt, ownerUser: 0, ownerGroup: 65532 kind: pod name: etcd-events-0 namespace: shoot--diki-comp--azure  
                                                            cluster: seed containerName: backup-restore details: fileName: /var/lib/kubelet/pods/74f71030-9c73-40a7-b50e-fb1bb70cb9a5/volumes/kubernetes.io~secret/etcd-client-tls/..2025_06_23_00_02_36.3852713643/tls.crt, ownerUser: 0, ownerGroup: 65532 kind: pod name: etcd-events-0 namespace: shoot--diki-comp--azure  
                                                            cluster: seed containerName: backup-restore details: fileName: /var/lib/kubelet/pods/74f71030-9c73-40a7-b50e-fb1bb70cb9a5/volumes/kubernetes.io~secret/etcd-client-tls/..2025_06_23_00_02_36.3852713643/tls.key, ownerUser: 0, ownerGroup: 65532 kind: pod name: etcd-events-0 namespace: shoot--diki-comp--azure  
                                                            cluster: seed containerName: backup-restore details: fileName: /var/lib/kubelet/pods/74f71030-9c73-40a7-b50e-fb1bb70cb9a5/volumes/kubernetes.io~projected/kube-api-access-gardener/..2025_06_23_00_02_36.662581379/ca.crt, ownerUser: 0, ownerGroup: 65532 kind: pod name: etcd-events-0 namespace: shoot--diki-comp--azure  
                                                            cluster: seed containerName: backup-restore details: fileName: /var/lib/kubelet/pods/74f71030-9c73-40a7-b50e-fb1bb70cb9a5/volumes/kubernetes.io~secret/backup-restore-server-tls/..2025_06_23_00_02_36.327312203, ownerUser: 0, ownerGroup: 65532 kind: pod name: etcd-events-0 namespace: shoot--diki-comp--azure  
                                                            cluster: seed containerName: backup-restore details: fileName: /var/lib/kubelet/pods/74f71030-9c73-40a7-b50e-fb1bb70cb9a5/volumes/kubernetes.io~secret/etcd-ca/..2025_06_23_00_02_36.1146945202, ownerUser: 0, ownerGroup: 65532 kind: pod name: etcd-events-0 namespace: shoot--diki-comp--azure  
                                                            cluster: seed containerName: backup-restore details: fileName: /var/lib/kubelet/pods/74f71030-9c73-40a7-b50e-fb1bb70cb9a5/volumes/kubernetes.io~secret/etcd-client-tls/..2025_06_23_00_02_36.3852713643, ownerUser: 0, ownerGroup: 65532 kind: pod name: etcd-events-0 namespace: shoot--diki-comp--azure  
                                                            cluster: seed containerName: backup-restore details: fileName: /var/lib/kubelet/pods/74f71030-9c73-40a7-b50e-fb1bb70cb9a5/volumes/kubernetes.io~projected/kube-api-access-gardener/..2025_06_23_00_02_36.662581379, ownerUser: 0, ownerGroup: 65532 kind: pod name: etcd-events-0 namespace: shoot--diki-comp--azure  
                                                            cluster: shoot details: fileName: /var/lib/kubelet/pki/kubelet-client-2025-06-23-00-09-20.pem, ownerUser: 0, ownerGroup: 0 kind: node name: shoot--diki-comp--azure-worker-g7p4p-z3-66467-k6q5n  
                                                            cluster: shoot details: fileName: /var/lib/kubelet/pki/kubelet-server-2025-06-23-00-10-22.pem, ownerUser: 0, ownerGroup: 0 kind: node name: shoot--diki-comp--azure-worker-g7p4p-z3-66467-k6q5n  
                                                            cluster: shoot details: fileName: /var/lib/kubelet/pki, ownerUser: 0, ownerGroup: 0 kind: node name: shoot--diki-comp--azure-worker-g7p4p-z3-66467-k6q5n  
                                                            cluster: shoot containerName: kube-proxy details: fileName: /var/lib/kubelet/pods/7f34a064-2a9b-48d4-a97f-57ed2fc7a389/volumes/kubernetes.io~projected/kube-api-access-gardener/..2025_06_23_00_09_26.3322732681/ca.crt, ownerUser: 0, ownerGroup: 0 kind: pod name: kube-proxy-worker-g7p4p-v1.31.8-7dnc5 namespace: kube-system  
                                                            cluster: shoot containerName: kube-proxy details: fileName: /var/lib/kubelet/pods/7f34a064-2a9b-48d4-a97f-57ed2fc7a389/volumes/kubernetes.io~projected/kube-api-access-gardener/..2025_06_23_00_09_26.3322732681, ownerUser: 0, ownerGroup: 0 kind: pod name: kube-proxy-worker-g7p4p-v1.31.8-7dnc5 namespace: kube-system  
                                                            cluster: shoot containerName: conntrack-fix details: fileName: /var/lib/kubelet/pods/7f34a064-2a9b-48d4-a97f-57ed2fc7a389/volumes/kubernetes.io~projected/kube-api-access-gardener/..2025_06_23_00_09_26.3322732681/ca.crt, ownerUser: 0, ownerGroup: 0 kind: pod name: kube-proxy-worker-g7p4p-v1.31.8-7dnc5 namespace: kube-system  
                                                            cluster: shoot containerName: conntrack-fix details: fileName: /var/lib/kubelet/pods/7f34a064-2a9b-48d4-a97f-57ed2fc7a389/volumes/kubernetes.io~projected/kube-api-access-gardener/..2025_06_23_00_09_26.3322732681, ownerUser: 0, ownerGroup: 0 kind: pod name: kube-proxy-worker-g7p4p-v1.31.8-7dnc5 namespace: kube-system  
                                                            cluster: shoot containerName: cleanup details: fileName: /var/lib/kubelet/pods/7f34a064-2a9b-48d4-a97f-57ed2fc7a389/volumes/kubernetes.io~projected/kube-api-access-gardener/..2025_06_23_00_09_26.3322732681/ca.crt, ownerUser: 0, ownerGroup: 0 kind: pod name: kube-proxy-worker-g7p4p-v1.31.8-7dnc5 namespace: kube-system  
                                                            cluster: shoot containerName: cleanup details: fileName: /var/lib/kubelet/pods/7f34a064-2a9b-48d4-a97f-57ed2fc7a389/volumes/kubernetes.io~projected/kube-api-access-gardener/..2025_06_23_00_09_26.3322732681, ownerUser: 0, ownerGroup: 0 kind: pod name: kube-proxy-worker-g7p4p-v1.31.8-7dnc5 namespace: kube-system  
                                                            cluster: shoot containerName: kube-proxy-init details: fileName: /var/lib/kubelet/pods/7f34a064-2a9b-48d4-a97f-57ed2fc7a389/volumes/kubernetes.io~projected/kube-api-access-gardener/..2025_06_23_00_09_26.3322732681/ca.crt, ownerUser: 0, ownerGroup: 0 kind: pod name: kube-proxy-worker-g7p4p-v1.31.8-7dnc5 namespace: kube-system  
                                                            cluster: shoot containerName: kube-proxy-init details: fileName: /var/lib/kubelet/pods/7f34a064-2a9b-48d4-a97f-57ed2fc7a389/volumes/kubernetes.io~projected/kube-api-access-gardener/..2025_06_23_00_09_26.3322732681, ownerUser: 0, ownerGroup: 0 kind: pod name: kube-proxy-worker-g7p4p-v1.31.8-7dnc5 namespace: kube-system  
                                                         
                                                     
                                                    
                                                        gcp 
                                                        
                                                            cluster: seed containerName: etcd details: fileName: /var/lib/kubelet/pods/56b8ee4f-315f-4054-af24-a9fd2f484963/volumes/kubernetes.io~secret/etcd-ca/..2025_06_23_00_02_35.3098522537/bundle.crt, ownerUser: 0, ownerGroup: 65532 kind: pod name: etcd-events-0 namespace: shoot--diki-comp--gcp  
                                                            cluster: seed containerName: etcd details: fileName: /var/lib/kubelet/pods/56b8ee4f-315f-4054-af24-a9fd2f484963/volumes/kubernetes.io~secret/etcd-server-tls/..2025_06_23_00_02_35.3565116838/tls.key, ownerUser: 0, ownerGroup: 65532 kind: pod name: etcd-events-0 namespace: shoot--diki-comp--gcp  
                                                            cluster: seed containerName: etcd details: fileName: /var/lib/kubelet/pods/56b8ee4f-315f-4054-af24-a9fd2f484963/volumes/kubernetes.io~secret/etcd-server-tls/..2025_06_23_00_02_35.3565116838/tls.crt, ownerUser: 0, ownerGroup: 65532 kind: pod name: etcd-events-0 namespace: shoot--diki-comp--gcp  
                                                            cluster: seed containerName: etcd details: fileName: /var/lib/kubelet/pods/56b8ee4f-315f-4054-af24-a9fd2f484963/volumes/kubernetes.io~secret/etcd-client-tls/..2025_06_23_00_02_35.3308771745/tls.key, ownerUser: 0, ownerGroup: 65532 kind: pod name: etcd-events-0 namespace: shoot--diki-comp--gcp  
                                                            cluster: seed containerName: etcd details: fileName: /var/lib/kubelet/pods/56b8ee4f-315f-4054-af24-a9fd2f484963/volumes/kubernetes.io~secret/etcd-client-tls/..2025_06_23_00_02_35.3308771745/tls.crt, ownerUser: 0, ownerGroup: 65532 kind: pod name: etcd-events-0 namespace: shoot--diki-comp--gcp  
                                                            cluster: seed containerName: etcd details: fileName: /var/lib/kubelet/pods/56b8ee4f-315f-4054-af24-a9fd2f484963/volumes/kubernetes.io~secret/backup-restore-ca/..2025_06_23_00_02_35.4083445152/bundle.crt, ownerUser: 0, ownerGroup: 65532 kind: pod name: etcd-events-0 namespace: shoot--diki-comp--gcp  
                                                            cluster: seed containerName: etcd details: fileName: /var/lib/kubelet/pods/56b8ee4f-315f-4054-af24-a9fd2f484963/volumes/kubernetes.io~projected/kube-api-access-gardener/..2025_06_23_00_02_35.4217059112/ca.crt, ownerUser: 0, ownerGroup: 65532 kind: pod name: etcd-events-0 namespace: shoot--diki-comp--gcp  
                                                            cluster: seed containerName: etcd details: fileName: /var/lib/kubelet/pods/56b8ee4f-315f-4054-af24-a9fd2f484963/volumes/kubernetes.io~secret/etcd-server-tls/..2025_06_23_00_02_35.3565116838, ownerUser: 0, ownerGroup: 65532 kind: pod name: etcd-events-0 namespace: shoot--diki-comp--gcp  
                                                            cluster: seed containerName: etcd details: fileName: /var/lib/kubelet/pods/56b8ee4f-315f-4054-af24-a9fd2f484963/volumes/kubernetes.io~secret/etcd-client-tls/..2025_06_23_00_02_35.3308771745, ownerUser: 0, ownerGroup: 65532 kind: pod name: etcd-events-0 namespace: shoot--diki-comp--gcp  
                                                            cluster: seed containerName: etcd details: fileName: /var/lib/kubelet/pods/56b8ee4f-315f-4054-af24-a9fd2f484963/volumes/kubernetes.io~secret/backup-restore-ca/..2025_06_23_00_02_35.4083445152, ownerUser: 0, ownerGroup: 65532 kind: pod name: etcd-events-0 namespace: shoot--diki-comp--gcp  
                                                            cluster: seed containerName: etcd details: fileName: /var/lib/kubelet/pods/56b8ee4f-315f-4054-af24-a9fd2f484963/volumes/kubernetes.io~projected/kube-api-access-gardener/..2025_06_23_00_02_35.4217059112, ownerUser: 0, ownerGroup: 65532 kind: pod name: etcd-events-0 namespace: shoot--diki-comp--gcp  
                                                            cluster: seed containerName: etcd details: fileName: /var/lib/kubelet/pods/56b8ee4f-315f-4054-af24-a9fd2f484963/volumes/kubernetes.io~secret/etcd-ca/..2025_06_23_00_02_35.3098522537, ownerUser: 0, ownerGroup: 65532 kind: pod name: etcd-events-0 namespace: shoot--diki-comp--gcp  
                                                            cluster: seed containerName: backup-restore details: fileName: /var/lib/kubelet/pods/56b8ee4f-315f-4054-af24-a9fd2f484963/volumes/kubernetes.io~secret/backup-restore-server-tls/..2025_06_23_00_02_35.375113374/tls.crt, ownerUser: 0, ownerGroup: 65532 kind: pod name: etcd-events-0 namespace: shoot--diki-comp--gcp  
                                                            cluster: seed containerName: backup-restore details: fileName: /var/lib/kubelet/pods/56b8ee4f-315f-4054-af24-a9fd2f484963/volumes/kubernetes.io~secret/backup-restore-server-tls/..2025_06_23_00_02_35.375113374/tls.key, ownerUser: 0, ownerGroup: 65532 kind: pod name: etcd-events-0 namespace: shoot--diki-comp--gcp  
                                                            cluster: seed containerName: backup-restore details: fileName: /var/lib/kubelet/pods/56b8ee4f-315f-4054-af24-a9fd2f484963/volumes/kubernetes.io~secret/etcd-ca/..2025_06_23_00_02_35.3098522537/bundle.crt, ownerUser: 0, ownerGroup: 65532 kind: pod name: etcd-events-0 namespace: shoot--diki-comp--gcp  
                                                            cluster: seed containerName: backup-restore details: fileName: /var/lib/kubelet/pods/56b8ee4f-315f-4054-af24-a9fd2f484963/volumes/kubernetes.io~secret/etcd-client-tls/..2025_06_23_00_02_35.3308771745/tls.key, ownerUser: 0, ownerGroup: 65532 kind: pod name: etcd-events-0 namespace: shoot--diki-comp--gcp  
                                                            cluster: seed containerName: backup-restore details: fileName: /var/lib/kubelet/pods/56b8ee4f-315f-4054-af24-a9fd2f484963/volumes/kubernetes.io~secret/etcd-client-tls/..2025_06_23_00_02_35.3308771745/tls.crt, ownerUser: 0, ownerGroup: 65532 kind: pod name: etcd-events-0 namespace: shoot--diki-comp--gcp  
                                                            cluster: seed containerName: backup-restore details: fileName: /var/lib/kubelet/pods/56b8ee4f-315f-4054-af24-a9fd2f484963/volumes/kubernetes.io~projected/kube-api-access-gardener/..2025_06_23_00_02_35.4217059112/ca.crt, ownerUser: 0, ownerGroup: 65532 kind: pod name: etcd-events-0 namespace: shoot--diki-comp--gcp  
                                                            cluster: seed containerName: backup-restore details: fileName: /var/lib/kubelet/pods/56b8ee4f-315f-4054-af24-a9fd2f484963/volumes/kubernetes.io~secret/backup-restore-server-tls/..2025_06_23_00_02_35.375113374, ownerUser: 0, ownerGroup: 65532 kind: pod name: etcd-events-0 namespace: shoot--diki-comp--gcp  
                                                            cluster: seed containerName: backup-restore details: fileName: /var/lib/kubelet/pods/56b8ee4f-315f-4054-af24-a9fd2f484963/volumes/kubernetes.io~secret/etcd-ca/..2025_06_23_00_02_35.3098522537, ownerUser: 0, ownerGroup: 65532 kind: pod name: etcd-events-0 namespace: shoot--diki-comp--gcp  
                                                            cluster: seed containerName: backup-restore details: fileName: /var/lib/kubelet/pods/56b8ee4f-315f-4054-af24-a9fd2f484963/volumes/kubernetes.io~secret/etcd-client-tls/..2025_06_23_00_02_35.3308771745, ownerUser: 0, ownerGroup: 65532 kind: pod name: etcd-events-0 namespace: shoot--diki-comp--gcp  
                                                            cluster: seed containerName: backup-restore details: fileName: /var/lib/kubelet/pods/56b8ee4f-315f-4054-af24-a9fd2f484963/volumes/kubernetes.io~projected/kube-api-access-gardener/..2025_06_23_00_02_35.4217059112, ownerUser: 0, ownerGroup: 65532 kind: pod name: etcd-events-0 namespace: shoot--diki-comp--gcp  
                                                            cluster: seed containerName: kube-scheduler details: fileName: /var/lib/kubelet/pods/d1968ae3-bf95-4709-b100-13709ba484c9/volumes/kubernetes.io~projected/client-ca/..2025_06_23_00_22_41.2638774521/bundle.crt, ownerUser: 0, ownerGroup: 65532 kind: pod name: kube-scheduler-7d978d746c-2vbm4 namespace: shoot--diki-comp--gcp  
                                                            cluster: seed containerName: kube-scheduler details: fileName: /var/lib/kubelet/pods/d1968ae3-bf95-4709-b100-13709ba484c9/volumes/kubernetes.io~secret/kube-scheduler-server/..2025_06_23_00_22_41.3181132458/tls.crt, ownerUser: 0, ownerGroup: 65532 kind: pod name: kube-scheduler-7d978d746c-2vbm4 namespace: shoot--diki-comp--gcp  
                                                            cluster: seed containerName: kube-scheduler details: fileName: /var/lib/kubelet/pods/d1968ae3-bf95-4709-b100-13709ba484c9/volumes/kubernetes.io~secret/kube-scheduler-server/..2025_06_23_00_22_41.3181132458/tls.key, ownerUser: 0, ownerGroup: 65532 kind: pod name: kube-scheduler-7d978d746c-2vbm4 namespace: shoot--diki-comp--gcp  
                                                            cluster: seed containerName: kube-scheduler details: fileName: /var/lib/kubelet/pods/d1968ae3-bf95-4709-b100-13709ba484c9/volumes/kubernetes.io~projected/client-ca/..2025_06_23_00_22_41.2638774521, ownerUser: 0, ownerGroup: 65532 kind: pod name: kube-scheduler-7d978d746c-2vbm4 namespace: shoot--diki-comp--gcp  
                                                            cluster: seed containerName: kube-scheduler details: fileName: /var/lib/kubelet/pods/d1968ae3-bf95-4709-b100-13709ba484c9/volumes/kubernetes.io~secret/kube-scheduler-server/..2025_06_23_00_22_41.3181132458, ownerUser: 0, ownerGroup: 65532 kind: pod name: kube-scheduler-7d978d746c-2vbm4 namespace: shoot--diki-comp--gcp  
                                                            cluster: seed containerName: kube-apiserver details: fileName: /var/lib/kubelet/pods/bcae6617-9cf5-48c4-a654-323e2fd06c94/volumes/kubernetes.io~secret/ca/..2025_06_23_00_05_00.1635859179/bundle.crt, ownerUser: 0, ownerGroup: 65532 kind: pod name: kube-apiserver-789b87d9bc-m288k namespace: shoot--diki-comp--gcp  
                                                            cluster: seed containerName: kube-apiserver details: fileName: /var/lib/kubelet/pods/bcae6617-9cf5-48c4-a654-323e2fd06c94/volumes/kubernetes.io~secret/ca-client/..2025_06_23_00_05_00.3123507849/bundle.crt, ownerUser: 0, ownerGroup: 65532 kind: pod name: kube-apiserver-789b87d9bc-m288k namespace: shoot--diki-comp--gcp  
                                                            cluster: seed containerName: kube-apiserver details: fileName: /var/lib/kubelet/pods/bcae6617-9cf5-48c4-a654-323e2fd06c94/volumes/kubernetes.io~secret/ca-front-proxy/..2025_06_23_00_05_00.3311897769/bundle.crt, ownerUser: 0, ownerGroup: 65532 kind: pod name: kube-apiserver-789b87d9bc-m288k namespace: shoot--diki-comp--gcp  
                                                            cluster: seed containerName: kube-apiserver details: fileName: /var/lib/kubelet/pods/bcae6617-9cf5-48c4-a654-323e2fd06c94/volumes/kubernetes.io~secret/service-account-key-bundle/..2025_06_23_00_05_00.527676273/bundle.key, ownerUser: 0, ownerGroup: 65532 kind: pod name: kube-apiserver-789b87d9bc-m288k namespace: shoot--diki-comp--gcp  
                                                            cluster: seed containerName: kube-apiserver details: fileName: /var/lib/kubelet/pods/bcae6617-9cf5-48c4-a654-323e2fd06c94/volumes/kubernetes.io~secret/kube-aggregator/..2025_06_23_00_05_00.8440286/tls.crt, ownerUser: 0, ownerGroup: 65532 kind: pod name: kube-apiserver-789b87d9bc-m288k namespace: shoot--diki-comp--gcp  
                                                            cluster: seed containerName: kube-apiserver details: fileName: /var/lib/kubelet/pods/bcae6617-9cf5-48c4-a654-323e2fd06c94/volumes/kubernetes.io~secret/kube-aggregator/..2025_06_23_00_05_00.8440286/tls.key, ownerUser: 0, ownerGroup: 65532 kind: pod name: kube-apiserver-789b87d9bc-m288k namespace: shoot--diki-comp--gcp  
                                                            cluster: seed containerName: kube-apiserver details: fileName: /var/lib/kubelet/pods/bcae6617-9cf5-48c4-a654-323e2fd06c94/volumes/kubernetes.io~secret/server/..2025_06_23_00_05_00.2211691282/tls.key, ownerUser: 0, ownerGroup: 65532 kind: pod name: kube-apiserver-789b87d9bc-m288k namespace: shoot--diki-comp--gcp  
                                                            cluster: seed containerName: kube-apiserver details: fileName: /var/lib/kubelet/pods/bcae6617-9cf5-48c4-a654-323e2fd06c94/volumes/kubernetes.io~secret/server/..2025_06_23_00_05_00.2211691282/tls.crt, ownerUser: 0, ownerGroup: 65532 kind: pod name: kube-apiserver-789b87d9bc-m288k namespace: shoot--diki-comp--gcp  
                                                            cluster: seed containerName: kube-apiserver details: fileName: /var/lib/kubelet/pods/bcae6617-9cf5-48c4-a654-323e2fd06c94/volumes/kubernetes.io~secret/ca-vpn/..2025_06_23_00_05_00.3200529218/bundle.crt, ownerUser: 0, ownerGroup: 65532 kind: pod name: kube-apiserver-789b87d9bc-m288k namespace: shoot--diki-comp--gcp  
                                                            cluster: seed containerName: kube-apiserver details: fileName: /var/lib/kubelet/pods/bcae6617-9cf5-48c4-a654-323e2fd06c94/volumes/kubernetes.io~secret/ca-kubelet/..2025_06_23_00_05_00.1340282604/bundle.crt, ownerUser: 0, ownerGroup: 65532 kind: pod name: kube-apiserver-789b87d9bc-m288k namespace: shoot--diki-comp--gcp  
                                                            cluster: seed containerName: kube-apiserver details: fileName: /var/lib/kubelet/pods/bcae6617-9cf5-48c4-a654-323e2fd06c94/volumes/kubernetes.io~secret/kubelet-client/..2025_06_23_00_05_00.3066470044/tls.crt, ownerUser: 0, ownerGroup: 65532 kind: pod name: kube-apiserver-789b87d9bc-m288k namespace: shoot--diki-comp--gcp  
                                                            cluster: seed containerName: kube-apiserver details: fileName: /var/lib/kubelet/pods/bcae6617-9cf5-48c4-a654-323e2fd06c94/volumes/kubernetes.io~secret/kubelet-client/..2025_06_23_00_05_00.3066470044/tls.key, ownerUser: 0, ownerGroup: 65532 kind: pod name: kube-apiserver-789b87d9bc-m288k namespace: shoot--diki-comp--gcp  
                                                            cluster: seed containerName: kube-apiserver details: fileName: /var/lib/kubelet/pods/bcae6617-9cf5-48c4-a654-323e2fd06c94/volumes/kubernetes.io~secret/ca-etcd/..2025_06_23_00_05_00.599344253/bundle.crt, ownerUser: 0, ownerGroup: 65532 kind: pod name: kube-apiserver-789b87d9bc-m288k namespace: shoot--diki-comp--gcp  
                                                            cluster: seed containerName: kube-apiserver details: fileName: /var/lib/kubelet/pods/bcae6617-9cf5-48c4-a654-323e2fd06c94/volumes/kubernetes.io~secret/etcd-client/..2025_06_23_00_05_00.3665142686/tls.key, ownerUser: 0, ownerGroup: 65532 kind: pod name: kube-apiserver-789b87d9bc-m288k namespace: shoot--diki-comp--gcp  
                                                            cluster: seed containerName: kube-apiserver details: fileName: /var/lib/kubelet/pods/bcae6617-9cf5-48c4-a654-323e2fd06c94/volumes/kubernetes.io~secret/etcd-client/..2025_06_23_00_05_00.3665142686/tls.crt, ownerUser: 0, ownerGroup: 65532 kind: pod name: kube-apiserver-789b87d9bc-m288k namespace: shoot--diki-comp--gcp  
                                                            cluster: seed containerName: kube-apiserver details: fileName: /var/lib/kubelet/pods/bcae6617-9cf5-48c4-a654-323e2fd06c94/volumes/kubernetes.io~secret/tls-sni-0/..2025_06_23_00_05_00.1355552674/tls.key, ownerUser: 0, ownerGroup: 65532 kind: pod name: kube-apiserver-789b87d9bc-m288k namespace: shoot--diki-comp--gcp  
                                                            cluster: seed containerName: kube-apiserver details: fileName: /var/lib/kubelet/pods/bcae6617-9cf5-48c4-a654-323e2fd06c94/volumes/kubernetes.io~secret/tls-sni-0/..2025_06_23_00_05_00.1355552674/tls.crt, ownerUser: 0, ownerGroup: 65532 kind: pod name: kube-apiserver-789b87d9bc-m288k namespace: shoot--diki-comp--gcp  
                                                            cluster: seed containerName: kube-apiserver details: fileName: /var/lib/kubelet/pods/bcae6617-9cf5-48c4-a654-323e2fd06c94/volumes/kubernetes.io~secret/tls-sni-0/..2025_06_23_00_05_00.1355552674/ca.crt, ownerUser: 0, ownerGroup: 65532 kind: pod name: kube-apiserver-789b87d9bc-m288k namespace: shoot--diki-comp--gcp  
                                                            cluster: seed containerName: kube-apiserver details: fileName: /var/lib/kubelet/pods/bcae6617-9cf5-48c4-a654-323e2fd06c94/volumes/kubernetes.io~secret/http-proxy/..2025_06_23_00_05_00.2267541296/tls.key, ownerUser: 0, ownerGroup: 65532 kind: pod name: kube-apiserver-789b87d9bc-m288k namespace: shoot--diki-comp--gcp  
                                                            cluster: seed containerName: kube-apiserver details: fileName: /var/lib/kubelet/pods/bcae6617-9cf5-48c4-a654-323e2fd06c94/volumes/kubernetes.io~secret/http-proxy/..2025_06_23_00_05_00.2267541296/tls.crt, ownerUser: 0, ownerGroup: 65532 kind: pod name: kube-apiserver-789b87d9bc-m288k namespace: shoot--diki-comp--gcp  
                                                            cluster: seed containerName: kube-apiserver details: fileName: /var/lib/kubelet/pods/bcae6617-9cf5-48c4-a654-323e2fd06c94/volumes/kubernetes.io~secret/ca-client/..2025_06_23_00_05_00.3123507849, ownerUser: 0, ownerGroup: 65532 kind: pod name: kube-apiserver-789b87d9bc-m288k namespace: shoot--diki-comp--gcp  
                                                            cluster: seed containerName: kube-apiserver details: fileName: /var/lib/kubelet/pods/bcae6617-9cf5-48c4-a654-323e2fd06c94/volumes/kubernetes.io~secret/ca-front-proxy/..2025_06_23_00_05_00.3311897769, ownerUser: 0, ownerGroup: 65532 kind: pod name: kube-apiserver-789b87d9bc-m288k namespace: shoot--diki-comp--gcp  
                                                            cluster: seed containerName: kube-apiserver details: fileName: /var/lib/kubelet/pods/bcae6617-9cf5-48c4-a654-323e2fd06c94/volumes/kubernetes.io~secret/server/..2025_06_23_00_05_00.2211691282, ownerUser: 0, ownerGroup: 65532 kind: pod name: kube-apiserver-789b87d9bc-m288k namespace: shoot--diki-comp--gcp  
                                                            cluster: seed containerName: kube-apiserver details: fileName: /var/lib/kubelet/pods/bcae6617-9cf5-48c4-a654-323e2fd06c94/volumes/kubernetes.io~secret/ca-vpn/..2025_06_23_00_05_00.3200529218, ownerUser: 0, ownerGroup: 65532 kind: pod name: kube-apiserver-789b87d9bc-m288k namespace: shoot--diki-comp--gcp  
                                                            cluster: seed containerName: kube-apiserver details: fileName: /var/lib/kubelet/pods/bcae6617-9cf5-48c4-a654-323e2fd06c94/volumes/kubernetes.io~secret/ca-kubelet/..2025_06_23_00_05_00.1340282604, ownerUser: 0, ownerGroup: 65532 kind: pod name: kube-apiserver-789b87d9bc-m288k namespace: shoot--diki-comp--gcp  
                                                            cluster: seed containerName: kube-apiserver details: fileName: /var/lib/kubelet/pods/bcae6617-9cf5-48c4-a654-323e2fd06c94/volumes/kubernetes.io~secret/kubelet-client/..2025_06_23_00_05_00.3066470044, ownerUser: 0, ownerGroup: 65532 kind: pod name: kube-apiserver-789b87d9bc-m288k namespace: shoot--diki-comp--gcp  
                                                            cluster: seed containerName: kube-apiserver details: fileName: /var/lib/kubelet/pods/bcae6617-9cf5-48c4-a654-323e2fd06c94/volumes/kubernetes.io~secret/ca-etcd/..2025_06_23_00_05_00.599344253, ownerUser: 0, ownerGroup: 65532 kind: pod name: kube-apiserver-789b87d9bc-m288k namespace: shoot--diki-comp--gcp  
                                                            cluster: seed containerName: kube-apiserver details: fileName: /var/lib/kubelet/pods/bcae6617-9cf5-48c4-a654-323e2fd06c94/volumes/kubernetes.io~secret/etcd-client/..2025_06_23_00_05_00.3665142686, ownerUser: 0, ownerGroup: 65532 kind: pod name: kube-apiserver-789b87d9bc-m288k namespace: shoot--diki-comp--gcp  
                                                            cluster: seed containerName: kube-apiserver details: fileName: /var/lib/kubelet/pods/bcae6617-9cf5-48c4-a654-323e2fd06c94/volumes/kubernetes.io~secret/ca/..2025_06_23_00_05_00.1635859179, ownerUser: 0, ownerGroup: 65532 kind: pod name: kube-apiserver-789b87d9bc-m288k namespace: shoot--diki-comp--gcp  
                                                            cluster: seed containerName: kube-apiserver details: fileName: /var/lib/kubelet/pods/bcae6617-9cf5-48c4-a654-323e2fd06c94/volumes/kubernetes.io~secret/service-account-key-bundle/..2025_06_23_00_05_00.527676273, ownerUser: 0, ownerGroup: 65532 kind: pod name: kube-apiserver-789b87d9bc-m288k namespace: shoot--diki-comp--gcp  
                                                            cluster: seed containerName: kube-apiserver details: fileName: /var/lib/kubelet/pods/bcae6617-9cf5-48c4-a654-323e2fd06c94/volumes/kubernetes.io~secret/kube-aggregator/..2025_06_23_00_05_00.8440286, ownerUser: 0, ownerGroup: 65532 kind: pod name: kube-apiserver-789b87d9bc-m288k namespace: shoot--diki-comp--gcp  
                                                            cluster: seed containerName: kube-apiserver details: fileName: /var/lib/kubelet/pods/bcae6617-9cf5-48c4-a654-323e2fd06c94/volumes/kubernetes.io~secret/tls-sni-0/..2025_06_23_00_05_00.1355552674, ownerUser: 0, ownerGroup: 65532 kind: pod name: kube-apiserver-789b87d9bc-m288k namespace: shoot--diki-comp--gcp  
                                                            cluster: seed containerName: kube-apiserver details: fileName: /var/lib/kubelet/pods/bcae6617-9cf5-48c4-a654-323e2fd06c94/volumes/kubernetes.io~secret/http-proxy/..2025_06_23_00_05_00.2267541296, ownerUser: 0, ownerGroup: 65532 kind: pod name: kube-apiserver-789b87d9bc-m288k namespace: shoot--diki-comp--gcp  
                                                            cluster: seed containerName: kube-controller-manager details: fileName: /var/lib/kubelet/pods/7207bfe7-1315-42f2-8383-7b79afa8437d/volumes/kubernetes.io~secret/ca/..2025_06_23_00_10_41.4029468750/bundle.crt, ownerUser: 0, ownerGroup: 65532 kind: pod name: kube-controller-manager-65cdccf875-lhhzw namespace: shoot--diki-comp--gcp  
                                                            cluster: seed containerName: kube-controller-manager details: fileName: /var/lib/kubelet/pods/7207bfe7-1315-42f2-8383-7b79afa8437d/volumes/kubernetes.io~secret/ca-client/..2025_06_23_00_10_41.2990537503/ca.crt, ownerUser: 0, ownerGroup: 65532 kind: pod name: kube-controller-manager-65cdccf875-lhhzw namespace: shoot--diki-comp--gcp  
                                                            cluster: seed containerName: kube-controller-manager details: fileName: /var/lib/kubelet/pods/7207bfe7-1315-42f2-8383-7b79afa8437d/volumes/kubernetes.io~secret/ca-client/..2025_06_23_00_10_41.2990537503/ca.key, ownerUser: 0, ownerGroup: 65532 kind: pod name: kube-controller-manager-65cdccf875-lhhzw namespace: shoot--diki-comp--gcp  
                                                            cluster: seed containerName: kube-controller-manager details: fileName: /var/lib/kubelet/pods/7207bfe7-1315-42f2-8383-7b79afa8437d/volumes/kubernetes.io~secret/server/..2025_06_23_00_10_41.2206626934/tls.crt, ownerUser: 0, ownerGroup: 65532 kind: pod name: kube-controller-manager-65cdccf875-lhhzw namespace: shoot--diki-comp--gcp  
                                                            cluster: seed containerName: kube-controller-manager details: fileName: /var/lib/kubelet/pods/7207bfe7-1315-42f2-8383-7b79afa8437d/volumes/kubernetes.io~secret/server/..2025_06_23_00_10_41.2206626934/tls.key, ownerUser: 0, ownerGroup: 65532 kind: pod name: kube-controller-manager-65cdccf875-lhhzw namespace: shoot--diki-comp--gcp  
                                                            cluster: seed containerName: kube-controller-manager details: fileName: /var/lib/kubelet/pods/7207bfe7-1315-42f2-8383-7b79afa8437d/volumes/kubernetes.io~secret/ca-kubelet/..2025_06_23_00_10_41.1244180931/ca.crt, ownerUser: 0, ownerGroup: 65532 kind: pod name: kube-controller-manager-65cdccf875-lhhzw namespace: shoot--diki-comp--gcp  
                                                            cluster: seed containerName: kube-controller-manager details: fileName: /var/lib/kubelet/pods/7207bfe7-1315-42f2-8383-7b79afa8437d/volumes/kubernetes.io~secret/ca-kubelet/..2025_06_23_00_10_41.1244180931/ca.key, ownerUser: 0, ownerGroup: 65532 kind: pod name: kube-controller-manager-65cdccf875-lhhzw namespace: shoot--diki-comp--gcp  
                                                            cluster: seed containerName: kube-controller-manager details: fileName: /var/lib/kubelet/pods/7207bfe7-1315-42f2-8383-7b79afa8437d/volumes/kubernetes.io~secret/ca/..2025_06_23_00_10_41.4029468750, ownerUser: 0, ownerGroup: 65532 kind: pod name: kube-controller-manager-65cdccf875-lhhzw namespace: shoot--diki-comp--gcp  
                                                            cluster: seed containerName: kube-controller-manager details: fileName: /var/lib/kubelet/pods/7207bfe7-1315-42f2-8383-7b79afa8437d/volumes/kubernetes.io~secret/ca-client/..2025_06_23_00_10_41.2990537503, ownerUser: 0, ownerGroup: 65532 kind: pod name: kube-controller-manager-65cdccf875-lhhzw namespace: shoot--diki-comp--gcp  
                                                            cluster: seed containerName: kube-controller-manager details: fileName: /var/lib/kubelet/pods/7207bfe7-1315-42f2-8383-7b79afa8437d/volumes/kubernetes.io~secret/server/..2025_06_23_00_10_41.2206626934, ownerUser: 0, ownerGroup: 65532 kind: pod name: kube-controller-manager-65cdccf875-lhhzw namespace: shoot--diki-comp--gcp  
                                                            cluster: seed containerName: kube-controller-manager details: fileName: /var/lib/kubelet/pods/7207bfe7-1315-42f2-8383-7b79afa8437d/volumes/kubernetes.io~secret/ca-kubelet/..2025_06_23_00_10_41.1244180931, ownerUser: 0, ownerGroup: 65532 kind: pod name: kube-controller-manager-65cdccf875-lhhzw namespace: shoot--diki-comp--gcp  
                                                            cluster: seed containerName: etcd details: fileName: /var/lib/kubelet/pods/5b8aebf9-d079-4ec9-a1dc-f2e2adadf242/volumes/kubernetes.io~secret/etcd-ca/..2025_06_23_00_02_35.359863374/bundle.crt, ownerUser: 0, ownerGroup: 65532 kind: pod name: etcd-main-0 namespace: shoot--diki-comp--gcp  
                                                            cluster: seed containerName: etcd details: fileName: /var/lib/kubelet/pods/5b8aebf9-d079-4ec9-a1dc-f2e2adadf242/volumes/kubernetes.io~secret/etcd-server-tls/..2025_06_23_00_02_35.761653683/tls.crt, ownerUser: 0, ownerGroup: 65532 kind: pod name: etcd-main-0 namespace: shoot--diki-comp--gcp  
                                                            cluster: seed containerName: etcd details: fileName: /var/lib/kubelet/pods/5b8aebf9-d079-4ec9-a1dc-f2e2adadf242/volumes/kubernetes.io~secret/etcd-server-tls/..2025_06_23_00_02_35.761653683/tls.key, ownerUser: 0, ownerGroup: 65532 kind: pod name: etcd-main-0 namespace: shoot--diki-comp--gcp  
                                                            cluster: seed containerName: etcd details: fileName: /var/lib/kubelet/pods/5b8aebf9-d079-4ec9-a1dc-f2e2adadf242/volumes/kubernetes.io~secret/etcd-client-tls/..2025_06_23_00_02_35.270682216/tls.crt, ownerUser: 0, ownerGroup: 65532 kind: pod name: etcd-main-0 namespace: shoot--diki-comp--gcp  
                                                            cluster: seed containerName: etcd details: fileName: /var/lib/kubelet/pods/5b8aebf9-d079-4ec9-a1dc-f2e2adadf242/volumes/kubernetes.io~secret/etcd-client-tls/..2025_06_23_00_02_35.270682216/tls.key, ownerUser: 0, ownerGroup: 65532 kind: pod name: etcd-main-0 namespace: shoot--diki-comp--gcp  
                                                            cluster: seed containerName: etcd details: fileName: /var/lib/kubelet/pods/5b8aebf9-d079-4ec9-a1dc-f2e2adadf242/volumes/kubernetes.io~secret/backup-restore-ca/..2025_06_23_00_02_35.2072965808/bundle.crt, ownerUser: 0, ownerGroup: 65532 kind: pod name: etcd-main-0 namespace: shoot--diki-comp--gcp  
                                                            cluster: seed containerName: etcd details: fileName: /var/lib/kubelet/pods/5b8aebf9-d079-4ec9-a1dc-f2e2adadf242/volumes/kubernetes.io~projected/kube-api-access-gardener/..2025_06_23_00_02_35.3521445574/ca.crt, ownerUser: 0, ownerGroup: 65532 kind: pod name: etcd-main-0 namespace: shoot--diki-comp--gcp  
                                                            cluster: seed containerName: etcd details: fileName: /var/lib/kubelet/pods/5b8aebf9-d079-4ec9-a1dc-f2e2adadf242/volumes/kubernetes.io~secret/etcd-ca/..2025_06_23_00_02_35.359863374, ownerUser: 0, ownerGroup: 65532 kind: pod name: etcd-main-0 namespace: shoot--diki-comp--gcp  
                                                            cluster: seed containerName: etcd details: fileName: /var/lib/kubelet/pods/5b8aebf9-d079-4ec9-a1dc-f2e2adadf242/volumes/kubernetes.io~secret/etcd-server-tls/..2025_06_23_00_02_35.761653683, ownerUser: 0, ownerGroup: 65532 kind: pod name: etcd-main-0 namespace: shoot--diki-comp--gcp  
                                                            cluster: seed containerName: etcd details: fileName: /var/lib/kubelet/pods/5b8aebf9-d079-4ec9-a1dc-f2e2adadf242/volumes/kubernetes.io~secret/etcd-client-tls/..2025_06_23_00_02_35.270682216, ownerUser: 0, ownerGroup: 65532 kind: pod name: etcd-main-0 namespace: shoot--diki-comp--gcp  
                                                            cluster: seed containerName: etcd details: fileName: /var/lib/kubelet/pods/5b8aebf9-d079-4ec9-a1dc-f2e2adadf242/volumes/kubernetes.io~secret/backup-restore-ca/..2025_06_23_00_02_35.2072965808, ownerUser: 0, ownerGroup: 65532 kind: pod name: etcd-main-0 namespace: shoot--diki-comp--gcp  
                                                            cluster: seed containerName: etcd details: fileName: /var/lib/kubelet/pods/5b8aebf9-d079-4ec9-a1dc-f2e2adadf242/volumes/kubernetes.io~projected/kube-api-access-gardener/..2025_06_23_00_02_35.3521445574, ownerUser: 0, ownerGroup: 65532 kind: pod name: etcd-main-0 namespace: shoot--diki-comp--gcp  
                                                            cluster: seed containerName: backup-restore details: fileName: /var/lib/kubelet/pods/5b8aebf9-d079-4ec9-a1dc-f2e2adadf242/volumes/kubernetes.io~secret/backup-restore-server-tls/..2025_06_23_00_02_35.1035566417/tls.key, ownerUser: 0, ownerGroup: 65532 kind: pod name: etcd-main-0 namespace: shoot--diki-comp--gcp  
                                                            cluster: seed containerName: backup-restore details: fileName: /var/lib/kubelet/pods/5b8aebf9-d079-4ec9-a1dc-f2e2adadf242/volumes/kubernetes.io~secret/backup-restore-server-tls/..2025_06_23_00_02_35.1035566417/tls.crt, ownerUser: 0, ownerGroup: 65532 kind: pod name: etcd-main-0 namespace: shoot--diki-comp--gcp  
                                                            cluster: seed containerName: backup-restore details: fileName: /var/lib/kubelet/pods/5b8aebf9-d079-4ec9-a1dc-f2e2adadf242/volumes/kubernetes.io~secret/etcd-ca/..2025_06_23_00_02_35.359863374/bundle.crt, ownerUser: 0, ownerGroup: 65532 kind: pod name: etcd-main-0 namespace: shoot--diki-comp--gcp  
                                                            cluster: seed containerName: backup-restore details: fileName: /var/lib/kubelet/pods/5b8aebf9-d079-4ec9-a1dc-f2e2adadf242/volumes/kubernetes.io~secret/etcd-client-tls/..2025_06_23_00_02_35.270682216/tls.crt, ownerUser: 0, ownerGroup: 65532 kind: pod name: etcd-main-0 namespace: shoot--diki-comp--gcp  
                                                            cluster: seed containerName: backup-restore details: fileName: /var/lib/kubelet/pods/5b8aebf9-d079-4ec9-a1dc-f2e2adadf242/volumes/kubernetes.io~secret/etcd-client-tls/..2025_06_23_00_02_35.270682216/tls.key, ownerUser: 0, ownerGroup: 65532 kind: pod name: etcd-main-0 namespace: shoot--diki-comp--gcp  
                                                            cluster: seed containerName: backup-restore details: fileName: /var/lib/kubelet/pods/5b8aebf9-d079-4ec9-a1dc-f2e2adadf242/volumes/kubernetes.io~projected/kube-api-access-gardener/..2025_06_23_00_02_35.3521445574/ca.crt, ownerUser: 0, ownerGroup: 65532 kind: pod name: etcd-main-0 namespace: shoot--diki-comp--gcp  
                                                            cluster: seed containerName: backup-restore details: fileName: /var/lib/kubelet/pods/5b8aebf9-d079-4ec9-a1dc-f2e2adadf242/volumes/kubernetes.io~projected/kube-api-access-gardener/..2025_06_23_00_02_35.3521445574, ownerUser: 0, ownerGroup: 65532 kind: pod name: etcd-main-0 namespace: shoot--diki-comp--gcp  
                                                            cluster: seed containerName: backup-restore details: fileName: /var/lib/kubelet/pods/5b8aebf9-d079-4ec9-a1dc-f2e2adadf242/volumes/kubernetes.io~secret/backup-restore-server-tls/..2025_06_23_00_02_35.1035566417, ownerUser: 0, ownerGroup: 65532 kind: pod name: etcd-main-0 namespace: shoot--diki-comp--gcp  
                                                            cluster: seed containerName: backup-restore details: fileName: /var/lib/kubelet/pods/5b8aebf9-d079-4ec9-a1dc-f2e2adadf242/volumes/kubernetes.io~secret/etcd-ca/..2025_06_23_00_02_35.359863374, ownerUser: 0, ownerGroup: 65532 kind: pod name: etcd-main-0 namespace: shoot--diki-comp--gcp  
                                                            cluster: seed containerName: backup-restore details: fileName: /var/lib/kubelet/pods/5b8aebf9-d079-4ec9-a1dc-f2e2adadf242/volumes/kubernetes.io~secret/etcd-client-tls/..2025_06_23_00_02_35.270682216, ownerUser: 0, ownerGroup: 65532 kind: pod name: etcd-main-0 namespace: shoot--diki-comp--gcp  
                                                            cluster: shoot details: fileName: /var/lib/kubelet/pki/kubelet-client-2025-06-23-00-07-48.pem, ownerUser: 0, ownerGroup: 0 kind: node name: shoot--diki-comp--gcp-worker-bex82-z1-5d9b4-8fp7q  
                                                            cluster: shoot details: fileName: /var/lib/kubelet/pki/kubelet-server-2025-06-23-00-08-19.pem, ownerUser: 0, ownerGroup: 0 kind: node name: shoot--diki-comp--gcp-worker-bex82-z1-5d9b4-8fp7q  
                                                            cluster: shoot details: fileName: /var/lib/kubelet/pki, ownerUser: 0, ownerGroup: 0 kind: node name: shoot--diki-comp--gcp-worker-bex82-z1-5d9b4-8fp7q  
                                                            cluster: shoot containerName: kube-proxy details: fileName: /var/lib/kubelet/pods/4933cf73-66c0-4f8e-b07d-54a68fc93917/volumes/kubernetes.io~projected/kube-api-access-gardener/..2025_06_23_00_07_50.3593682193/ca.crt, ownerUser: 0, ownerGroup: 0 kind: pod name: kube-proxy-worker-bex82-v1.31.8-x9kg4 namespace: kube-system  
                                                            cluster: shoot containerName: kube-proxy details: fileName: /var/lib/kubelet/pods/4933cf73-66c0-4f8e-b07d-54a68fc93917/volumes/kubernetes.io~projected/kube-api-access-gardener/..2025_06_23_00_07_50.3593682193, ownerUser: 0, ownerGroup: 0 kind: pod name: kube-proxy-worker-bex82-v1.31.8-x9kg4 namespace: kube-system  
                                                            cluster: shoot containerName: conntrack-fix details: fileName: /var/lib/kubelet/pods/4933cf73-66c0-4f8e-b07d-54a68fc93917/volumes/kubernetes.io~projected/kube-api-access-gardener/..2025_06_23_00_07_50.3593682193/ca.crt, ownerUser: 0, ownerGroup: 0 kind: pod name: kube-proxy-worker-bex82-v1.31.8-x9kg4 namespace: kube-system  
                                                            cluster: shoot containerName: conntrack-fix details: fileName: /var/lib/kubelet/pods/4933cf73-66c0-4f8e-b07d-54a68fc93917/volumes/kubernetes.io~projected/kube-api-access-gardener/..2025_06_23_00_07_50.3593682193, ownerUser: 0, ownerGroup: 0 kind: pod name: kube-proxy-worker-bex82-v1.31.8-x9kg4 namespace: kube-system  
                                                            cluster: shoot containerName: cleanup details: fileName: /var/lib/kubelet/pods/4933cf73-66c0-4f8e-b07d-54a68fc93917/volumes/kubernetes.io~projected/kube-api-access-gardener/..2025_06_23_00_07_50.3593682193/ca.crt, ownerUser: 0, ownerGroup: 0 kind: pod name: kube-proxy-worker-bex82-v1.31.8-x9kg4 namespace: kube-system  
                                                            cluster: shoot containerName: cleanup details: fileName: /var/lib/kubelet/pods/4933cf73-66c0-4f8e-b07d-54a68fc93917/volumes/kubernetes.io~projected/kube-api-access-gardener/..2025_06_23_00_07_50.3593682193, ownerUser: 0, ownerGroup: 0 kind: pod name: kube-proxy-worker-bex82-v1.31.8-x9kg4 namespace: kube-system  
                                                            cluster: shoot containerName: kube-proxy-init details: fileName: /var/lib/kubelet/pods/4933cf73-66c0-4f8e-b07d-54a68fc93917/volumes/kubernetes.io~projected/kube-api-access-gardener/..2025_06_23_00_07_50.3593682193/ca.crt, ownerUser: 0, ownerGroup: 0 kind: pod name: kube-proxy-worker-bex82-v1.31.8-x9kg4 namespace: kube-system  
                                                            cluster: shoot containerName: kube-proxy-init details: fileName: /var/lib/kubelet/pods/4933cf73-66c0-4f8e-b07d-54a68fc93917/volumes/kubernetes.io~projected/kube-api-access-gardener/..2025_06_23_00_07_50.3593682193, ownerUser: 0, ownerGroup: 0 kind: pod name: kube-proxy-worker-bex82-v1.31.8-x9kg4 namespace: kube-system  
                                                         
                                                     
                                                    
                                                        openstack 
                                                        
                                                            cluster: seed containerName: etcd details: fileName: /var/lib/kubelet/pods/9c7e7507-c95f-4034-bb45-54d9a5a0061e/volumes/kubernetes.io~secret/etcd-ca/..2025_06_23_00_02_39.2818779423/bundle.crt, ownerUser: 0, ownerGroup: 65532 kind: pod name: etcd-events-0 namespace: shoot--diki-comp--openstack  
                                                            cluster: seed containerName: etcd details: fileName: /var/lib/kubelet/pods/9c7e7507-c95f-4034-bb45-54d9a5a0061e/volumes/kubernetes.io~secret/etcd-server-tls/..2025_06_23_00_02_39.1241938029/tls.key, ownerUser: 0, ownerGroup: 65532 kind: pod name: etcd-events-0 namespace: shoot--diki-comp--openstack  
                                                            cluster: seed containerName: etcd details: fileName: /var/lib/kubelet/pods/9c7e7507-c95f-4034-bb45-54d9a5a0061e/volumes/kubernetes.io~secret/etcd-server-tls/..2025_06_23_00_02_39.1241938029/tls.crt, ownerUser: 0, ownerGroup: 65532 kind: pod name: etcd-events-0 namespace: shoot--diki-comp--openstack  
                                                            cluster: seed containerName: etcd details: fileName: /var/lib/kubelet/pods/9c7e7507-c95f-4034-bb45-54d9a5a0061e/volumes/kubernetes.io~secret/etcd-client-tls/..2025_06_23_00_02_39.2589051175/tls.key, ownerUser: 0, ownerGroup: 65532 kind: pod name: etcd-events-0 namespace: shoot--diki-comp--openstack  
                                                            cluster: seed containerName: etcd details: fileName: /var/lib/kubelet/pods/9c7e7507-c95f-4034-bb45-54d9a5a0061e/volumes/kubernetes.io~secret/etcd-client-tls/..2025_06_23_00_02_39.2589051175/tls.crt, ownerUser: 0, ownerGroup: 65532 kind: pod name: etcd-events-0 namespace: shoot--diki-comp--openstack  
                                                            cluster: seed containerName: etcd details: fileName: /var/lib/kubelet/pods/9c7e7507-c95f-4034-bb45-54d9a5a0061e/volumes/kubernetes.io~secret/backup-restore-ca/..2025_06_23_00_02_39.735587336/bundle.crt, ownerUser: 0, ownerGroup: 65532 kind: pod name: etcd-events-0 namespace: shoot--diki-comp--openstack  
                                                            cluster: seed containerName: etcd details: fileName: /var/lib/kubelet/pods/9c7e7507-c95f-4034-bb45-54d9a5a0061e/volumes/kubernetes.io~projected/kube-api-access-gardener/..2025_06_23_00_02_39.3883414360/ca.crt, ownerUser: 0, ownerGroup: 65532 kind: pod name: etcd-events-0 namespace: shoot--diki-comp--openstack  
                                                            cluster: seed containerName: etcd details: fileName: /var/lib/kubelet/pods/9c7e7507-c95f-4034-bb45-54d9a5a0061e/volumes/kubernetes.io~secret/etcd-server-tls/..2025_06_23_00_02_39.1241938029, ownerUser: 0, ownerGroup: 65532 kind: pod name: etcd-events-0 namespace: shoot--diki-comp--openstack  
                                                            cluster: seed containerName: etcd details: fileName: /var/lib/kubelet/pods/9c7e7507-c95f-4034-bb45-54d9a5a0061e/volumes/kubernetes.io~secret/etcd-client-tls/..2025_06_23_00_02_39.2589051175, ownerUser: 0, ownerGroup: 65532 kind: pod name: etcd-events-0 namespace: shoot--diki-comp--openstack  
                                                            cluster: seed containerName: etcd details: fileName: /var/lib/kubelet/pods/9c7e7507-c95f-4034-bb45-54d9a5a0061e/volumes/kubernetes.io~secret/backup-restore-ca/..2025_06_23_00_02_39.735587336, ownerUser: 0, ownerGroup: 65532 kind: pod name: etcd-events-0 namespace: shoot--diki-comp--openstack  
                                                            cluster: seed containerName: etcd details: fileName: /var/lib/kubelet/pods/9c7e7507-c95f-4034-bb45-54d9a5a0061e/volumes/kubernetes.io~projected/kube-api-access-gardener/..2025_06_23_00_02_39.3883414360, ownerUser: 0, ownerGroup: 65532 kind: pod name: etcd-events-0 namespace: shoot--diki-comp--openstack  
                                                            cluster: seed containerName: etcd details: fileName: /var/lib/kubelet/pods/9c7e7507-c95f-4034-bb45-54d9a5a0061e/volumes/kubernetes.io~secret/etcd-ca/..2025_06_23_00_02_39.2818779423, ownerUser: 0, ownerGroup: 65532 kind: pod name: etcd-events-0 namespace: shoot--diki-comp--openstack  
                                                            cluster: seed containerName: backup-restore details: fileName: /var/lib/kubelet/pods/9c7e7507-c95f-4034-bb45-54d9a5a0061e/volumes/kubernetes.io~secret/backup-restore-server-tls/..2025_06_23_00_02_39.705338586/tls.crt, ownerUser: 0, ownerGroup: 65532 kind: pod name: etcd-events-0 namespace: shoot--diki-comp--openstack  
                                                            cluster: seed containerName: backup-restore details: fileName: /var/lib/kubelet/pods/9c7e7507-c95f-4034-bb45-54d9a5a0061e/volumes/kubernetes.io~secret/backup-restore-server-tls/..2025_06_23_00_02_39.705338586/tls.key, ownerUser: 0, ownerGroup: 65532 kind: pod name: etcd-events-0 namespace: shoot--diki-comp--openstack  
                                                            cluster: seed containerName: backup-restore details: fileName: /var/lib/kubelet/pods/9c7e7507-c95f-4034-bb45-54d9a5a0061e/volumes/kubernetes.io~secret/etcd-ca/..2025_06_23_00_02_39.2818779423/bundle.crt, ownerUser: 0, ownerGroup: 65532 kind: pod name: etcd-events-0 namespace: shoot--diki-comp--openstack  
                                                            cluster: seed containerName: backup-restore details: fileName: /var/lib/kubelet/pods/9c7e7507-c95f-4034-bb45-54d9a5a0061e/volumes/kubernetes.io~secret/etcd-client-tls/..2025_06_23_00_02_39.2589051175/tls.key, ownerUser: 0, ownerGroup: 65532 kind: pod name: etcd-events-0 namespace: shoot--diki-comp--openstack  
                                                            cluster: seed containerName: backup-restore details: fileName: /var/lib/kubelet/pods/9c7e7507-c95f-4034-bb45-54d9a5a0061e/volumes/kubernetes.io~secret/etcd-client-tls/..2025_06_23_00_02_39.2589051175/tls.crt, ownerUser: 0, ownerGroup: 65532 kind: pod name: etcd-events-0 namespace: shoot--diki-comp--openstack  
                                                            cluster: seed containerName: backup-restore details: fileName: /var/lib/kubelet/pods/9c7e7507-c95f-4034-bb45-54d9a5a0061e/volumes/kubernetes.io~projected/kube-api-access-gardener/..2025_06_23_00_02_39.3883414360/ca.crt, ownerUser: 0, ownerGroup: 65532 kind: pod name: etcd-events-0 namespace: shoot--diki-comp--openstack  
                                                            cluster: seed containerName: backup-restore details: fileName: /var/lib/kubelet/pods/9c7e7507-c95f-4034-bb45-54d9a5a0061e/volumes/kubernetes.io~secret/backup-restore-server-tls/..2025_06_23_00_02_39.705338586, ownerUser: 0, ownerGroup: 65532 kind: pod name: etcd-events-0 namespace: shoot--diki-comp--openstack  
                                                            cluster: seed containerName: backup-restore details: fileName: /var/lib/kubelet/pods/9c7e7507-c95f-4034-bb45-54d9a5a0061e/volumes/kubernetes.io~secret/etcd-ca/..2025_06_23_00_02_39.2818779423, ownerUser: 0, ownerGroup: 65532 kind: pod name: etcd-events-0 namespace: shoot--diki-comp--openstack  
                                                            cluster: seed containerName: backup-restore details: fileName: /var/lib/kubelet/pods/9c7e7507-c95f-4034-bb45-54d9a5a0061e/volumes/kubernetes.io~secret/etcd-client-tls/..2025_06_23_00_02_39.2589051175, ownerUser: 0, ownerGroup: 65532 kind: pod name: etcd-events-0 namespace: shoot--diki-comp--openstack  
                                                            cluster: seed containerName: backup-restore details: fileName: /var/lib/kubelet/pods/9c7e7507-c95f-4034-bb45-54d9a5a0061e/volumes/kubernetes.io~projected/kube-api-access-gardener/..2025_06_23_00_02_39.3883414360, ownerUser: 0, ownerGroup: 65532 kind: pod name: etcd-events-0 namespace: shoot--diki-comp--openstack  
                                                            cluster: seed containerName: kube-controller-manager details: fileName: /var/lib/kubelet/pods/0b27d4d8-1580-4d41-8c12-a56ef49072dc/volumes/kubernetes.io~secret/ca/..2025_06_23_00_12_57.3765708577/bundle.crt, ownerUser: 0, ownerGroup: 65532 kind: pod name: kube-controller-manager-76f68f67cf-z8lm4 namespace: shoot--diki-comp--openstack  
                                                            cluster: seed containerName: kube-controller-manager details: fileName: /var/lib/kubelet/pods/0b27d4d8-1580-4d41-8c12-a56ef49072dc/volumes/kubernetes.io~secret/ca-client/..2025_06_23_00_12_57.3596785791/ca.crt, ownerUser: 0, ownerGroup: 65532 kind: pod name: kube-controller-manager-76f68f67cf-z8lm4 namespace: shoot--diki-comp--openstack  
                                                            cluster: seed containerName: kube-controller-manager details: fileName: /var/lib/kubelet/pods/0b27d4d8-1580-4d41-8c12-a56ef49072dc/volumes/kubernetes.io~secret/ca-client/..2025_06_23_00_12_57.3596785791/ca.key, ownerUser: 0, ownerGroup: 65532 kind: pod name: kube-controller-manager-76f68f67cf-z8lm4 namespace: shoot--diki-comp--openstack  
                                                            cluster: seed containerName: kube-controller-manager details: fileName: /var/lib/kubelet/pods/0b27d4d8-1580-4d41-8c12-a56ef49072dc/volumes/kubernetes.io~secret/server/..2025_06_23_00_12_57.4281910611/tls.key, ownerUser: 0, ownerGroup: 65532 kind: pod name: kube-controller-manager-76f68f67cf-z8lm4 namespace: shoot--diki-comp--openstack  
                                                            cluster: seed containerName: kube-controller-manager details: fileName: /var/lib/kubelet/pods/0b27d4d8-1580-4d41-8c12-a56ef49072dc/volumes/kubernetes.io~secret/server/..2025_06_23_00_12_57.4281910611/tls.crt, ownerUser: 0, ownerGroup: 65532 kind: pod name: kube-controller-manager-76f68f67cf-z8lm4 namespace: shoot--diki-comp--openstack  
                                                            cluster: seed containerName: kube-controller-manager details: fileName: /var/lib/kubelet/pods/0b27d4d8-1580-4d41-8c12-a56ef49072dc/volumes/kubernetes.io~secret/ca-kubelet/..2025_06_23_00_12_57.775870841/ca.key, ownerUser: 0, ownerGroup: 65532 kind: pod name: kube-controller-manager-76f68f67cf-z8lm4 namespace: shoot--diki-comp--openstack  
                                                            cluster: seed containerName: kube-controller-manager details: fileName: /var/lib/kubelet/pods/0b27d4d8-1580-4d41-8c12-a56ef49072dc/volumes/kubernetes.io~secret/ca-kubelet/..2025_06_23_00_12_57.775870841/ca.crt, ownerUser: 0, ownerGroup: 65532 kind: pod name: kube-controller-manager-76f68f67cf-z8lm4 namespace: shoot--diki-comp--openstack  
                                                            cluster: seed containerName: kube-controller-manager details: fileName: /var/lib/kubelet/pods/0b27d4d8-1580-4d41-8c12-a56ef49072dc/volumes/kubernetes.io~secret/ca/..2025_06_23_00_12_57.3765708577, ownerUser: 0, ownerGroup: 65532 kind: pod name: kube-controller-manager-76f68f67cf-z8lm4 namespace: shoot--diki-comp--openstack  
                                                            cluster: seed containerName: kube-controller-manager details: fileName: /var/lib/kubelet/pods/0b27d4d8-1580-4d41-8c12-a56ef49072dc/volumes/kubernetes.io~secret/ca-client/..2025_06_23_00_12_57.3596785791, ownerUser: 0, ownerGroup: 65532 kind: pod name: kube-controller-manager-76f68f67cf-z8lm4 namespace: shoot--diki-comp--openstack  
                                                            cluster: seed containerName: kube-controller-manager details: fileName: /var/lib/kubelet/pods/0b27d4d8-1580-4d41-8c12-a56ef49072dc/volumes/kubernetes.io~secret/server/..2025_06_23_00_12_57.4281910611, ownerUser: 0, ownerGroup: 65532 kind: pod name: kube-controller-manager-76f68f67cf-z8lm4 namespace: shoot--diki-comp--openstack  
                                                            cluster: seed containerName: kube-controller-manager details: fileName: /var/lib/kubelet/pods/0b27d4d8-1580-4d41-8c12-a56ef49072dc/volumes/kubernetes.io~secret/ca-kubelet/..2025_06_23_00_12_57.775870841, ownerUser: 0, ownerGroup: 65532 kind: pod name: kube-controller-manager-76f68f67cf-z8lm4 namespace: shoot--diki-comp--openstack  
                                                            cluster: seed containerName: kube-scheduler details: fileName: /var/lib/kubelet/pods/b2afa8e5-74e9-4932-af53-bf0fcfd84066/volumes/kubernetes.io~projected/client-ca/..2025_06_23_00_11_57.2527488857/bundle.crt, ownerUser: 0, ownerGroup: 65532 kind: pod name: kube-scheduler-785644b95f-fzldg namespace: shoot--diki-comp--openstack  
                                                            cluster: seed containerName: kube-scheduler details: fileName: /var/lib/kubelet/pods/b2afa8e5-74e9-4932-af53-bf0fcfd84066/volumes/kubernetes.io~secret/kube-scheduler-server/..2025_06_23_00_11_57.748288227/tls.crt, ownerUser: 0, ownerGroup: 65532 kind: pod name: kube-scheduler-785644b95f-fzldg namespace: shoot--diki-comp--openstack  
                                                            cluster: seed containerName: kube-scheduler details: fileName: /var/lib/kubelet/pods/b2afa8e5-74e9-4932-af53-bf0fcfd84066/volumes/kubernetes.io~secret/kube-scheduler-server/..2025_06_23_00_11_57.748288227/tls.key, ownerUser: 0, ownerGroup: 65532 kind: pod name: kube-scheduler-785644b95f-fzldg namespace: shoot--diki-comp--openstack  
                                                            cluster: seed containerName: kube-scheduler details: fileName: /var/lib/kubelet/pods/b2afa8e5-74e9-4932-af53-bf0fcfd84066/volumes/kubernetes.io~projected/client-ca/..2025_06_23_00_11_57.2527488857, ownerUser: 0, ownerGroup: 65532 kind: pod name: kube-scheduler-785644b95f-fzldg namespace: shoot--diki-comp--openstack  
                                                            cluster: seed containerName: kube-scheduler details: fileName: /var/lib/kubelet/pods/b2afa8e5-74e9-4932-af53-bf0fcfd84066/volumes/kubernetes.io~secret/kube-scheduler-server/..2025_06_23_00_11_57.748288227, ownerUser: 0, ownerGroup: 65532 kind: pod name: kube-scheduler-785644b95f-fzldg namespace: shoot--diki-comp--openstack  
                                                            cluster: seed containerName: etcd details: fileName: /var/lib/kubelet/pods/7d71941f-a963-401d-b0e0-28ed7592fe7d/volumes/kubernetes.io~secret/etcd-ca/..2025_06_23_00_02_39.4052105237/bundle.crt, ownerUser: 0, ownerGroup: 65532 kind: pod name: etcd-main-0 namespace: shoot--diki-comp--openstack  
                                                            cluster: seed containerName: etcd details: fileName: /var/lib/kubelet/pods/7d71941f-a963-401d-b0e0-28ed7592fe7d/volumes/kubernetes.io~secret/etcd-server-tls/..2025_06_23_00_02_39.149437060/tls.key, ownerUser: 0, ownerGroup: 65532 kind: pod name: etcd-main-0 namespace: shoot--diki-comp--openstack  
                                                            cluster: seed containerName: etcd details: fileName: /var/lib/kubelet/pods/7d71941f-a963-401d-b0e0-28ed7592fe7d/volumes/kubernetes.io~secret/etcd-server-tls/..2025_06_23_00_02_39.149437060/tls.crt, ownerUser: 0, ownerGroup: 65532 kind: pod name: etcd-main-0 namespace: shoot--diki-comp--openstack  
                                                            cluster: seed containerName: etcd details: fileName: /var/lib/kubelet/pods/7d71941f-a963-401d-b0e0-28ed7592fe7d/volumes/kubernetes.io~secret/etcd-client-tls/..2025_06_23_00_02_39.296248316/tls.crt, ownerUser: 0, ownerGroup: 65532 kind: pod name: etcd-main-0 namespace: shoot--diki-comp--openstack  
                                                            cluster: seed containerName: etcd details: fileName: /var/lib/kubelet/pods/7d71941f-a963-401d-b0e0-28ed7592fe7d/volumes/kubernetes.io~secret/etcd-client-tls/..2025_06_23_00_02_39.296248316/tls.key, ownerUser: 0, ownerGroup: 65532 kind: pod name: etcd-main-0 namespace: shoot--diki-comp--openstack  
                                                            cluster: seed containerName: etcd details: fileName: /var/lib/kubelet/pods/7d71941f-a963-401d-b0e0-28ed7592fe7d/volumes/kubernetes.io~secret/backup-restore-ca/..2025_06_23_00_02_39.2679800161/bundle.crt, ownerUser: 0, ownerGroup: 65532 kind: pod name: etcd-main-0 namespace: shoot--diki-comp--openstack  
                                                            cluster: seed containerName: etcd details: fileName: /var/lib/kubelet/pods/7d71941f-a963-401d-b0e0-28ed7592fe7d/volumes/kubernetes.io~projected/kube-api-access-gardener/..2025_06_23_00_02_39.1703787134/ca.crt, ownerUser: 0, ownerGroup: 65532 kind: pod name: etcd-main-0 namespace: shoot--diki-comp--openstack  
                                                            cluster: seed containerName: etcd details: fileName: /var/lib/kubelet/pods/7d71941f-a963-401d-b0e0-28ed7592fe7d/volumes/kubernetes.io~secret/etcd-ca/..2025_06_23_00_02_39.4052105237, ownerUser: 0, ownerGroup: 65532 kind: pod name: etcd-main-0 namespace: shoot--diki-comp--openstack  
                                                            cluster: seed containerName: etcd details: fileName: /var/lib/kubelet/pods/7d71941f-a963-401d-b0e0-28ed7592fe7d/volumes/kubernetes.io~secret/etcd-server-tls/..2025_06_23_00_02_39.149437060, ownerUser: 0, ownerGroup: 65532 kind: pod name: etcd-main-0 namespace: shoot--diki-comp--openstack  
                                                            cluster: seed containerName: etcd details: fileName: /var/lib/kubelet/pods/7d71941f-a963-401d-b0e0-28ed7592fe7d/volumes/kubernetes.io~secret/etcd-client-tls/..2025_06_23_00_02_39.296248316, ownerUser: 0, ownerGroup: 65532 kind: pod name: etcd-main-0 namespace: shoot--diki-comp--openstack  
                                                            cluster: seed containerName: etcd details: fileName: /var/lib/kubelet/pods/7d71941f-a963-401d-b0e0-28ed7592fe7d/volumes/kubernetes.io~secret/backup-restore-ca/..2025_06_23_00_02_39.2679800161, ownerUser: 0, ownerGroup: 65532 kind: pod name: etcd-main-0 namespace: shoot--diki-comp--openstack  
                                                            cluster: seed containerName: etcd details: fileName: /var/lib/kubelet/pods/7d71941f-a963-401d-b0e0-28ed7592fe7d/volumes/kubernetes.io~projected/kube-api-access-gardener/..2025_06_23_00_02_39.1703787134, ownerUser: 0, ownerGroup: 65532 kind: pod name: etcd-main-0 namespace: shoot--diki-comp--openstack  
                                                            cluster: seed containerName: backup-restore details: fileName: /var/lib/kubelet/pods/7d71941f-a963-401d-b0e0-28ed7592fe7d/volumes/kubernetes.io~secret/backup-restore-server-tls/..2025_06_23_00_02_39.456523922/tls.key, ownerUser: 0, ownerGroup: 65532 kind: pod name: etcd-main-0 namespace: shoot--diki-comp--openstack  
                                                            cluster: seed containerName: backup-restore details: fileName: /var/lib/kubelet/pods/7d71941f-a963-401d-b0e0-28ed7592fe7d/volumes/kubernetes.io~secret/backup-restore-server-tls/..2025_06_23_00_02_39.456523922/tls.crt, ownerUser: 0, ownerGroup: 65532 kind: pod name: etcd-main-0 namespace: shoot--diki-comp--openstack  
                                                            cluster: seed containerName: backup-restore details: fileName: /var/lib/kubelet/pods/7d71941f-a963-401d-b0e0-28ed7592fe7d/volumes/kubernetes.io~secret/etcd-ca/..2025_06_23_00_02_39.4052105237/bundle.crt, ownerUser: 0, ownerGroup: 65532 kind: pod name: etcd-main-0 namespace: shoot--diki-comp--openstack  
                                                            cluster: seed containerName: backup-restore details: fileName: /var/lib/kubelet/pods/7d71941f-a963-401d-b0e0-28ed7592fe7d/volumes/kubernetes.io~secret/etcd-client-tls/..2025_06_23_00_02_39.296248316/tls.crt, ownerUser: 0, ownerGroup: 65532 kind: pod name: etcd-main-0 namespace: shoot--diki-comp--openstack  
                                                            cluster: seed containerName: backup-restore details: fileName: /var/lib/kubelet/pods/7d71941f-a963-401d-b0e0-28ed7592fe7d/volumes/kubernetes.io~secret/etcd-client-tls/..2025_06_23_00_02_39.296248316/tls.key, ownerUser: 0, ownerGroup: 65532 kind: pod name: etcd-main-0 namespace: shoot--diki-comp--openstack  
                                                            cluster: seed containerName: backup-restore details: fileName: /var/lib/kubelet/pods/7d71941f-a963-401d-b0e0-28ed7592fe7d/volumes/kubernetes.io~projected/kube-api-access-gardener/..2025_06_23_00_02_39.1703787134/ca.crt, ownerUser: 0, ownerGroup: 65532 kind: pod name: etcd-main-0 namespace: shoot--diki-comp--openstack  
                                                            cluster: seed containerName: backup-restore details: fileName: /var/lib/kubelet/pods/7d71941f-a963-401d-b0e0-28ed7592fe7d/volumes/kubernetes.io~secret/backup-restore-server-tls/..2025_06_23_00_02_39.456523922, ownerUser: 0, ownerGroup: 65532 kind: pod name: etcd-main-0 namespace: shoot--diki-comp--openstack  
                                                            cluster: seed containerName: backup-restore details: fileName: /var/lib/kubelet/pods/7d71941f-a963-401d-b0e0-28ed7592fe7d/volumes/kubernetes.io~secret/etcd-ca/..2025_06_23_00_02_39.4052105237, ownerUser: 0, ownerGroup: 65532 kind: pod name: etcd-main-0 namespace: shoot--diki-comp--openstack  
                                                            cluster: seed containerName: backup-restore details: fileName: /var/lib/kubelet/pods/7d71941f-a963-401d-b0e0-28ed7592fe7d/volumes/kubernetes.io~secret/etcd-client-tls/..2025_06_23_00_02_39.296248316, ownerUser: 0, ownerGroup: 65532 kind: pod name: etcd-main-0 namespace: shoot--diki-comp--openstack  
                                                            cluster: seed containerName: backup-restore details: fileName: /var/lib/kubelet/pods/7d71941f-a963-401d-b0e0-28ed7592fe7d/volumes/kubernetes.io~projected/kube-api-access-gardener/..2025_06_23_00_02_39.1703787134, ownerUser: 0, ownerGroup: 65532 kind: pod name: etcd-main-0 namespace: shoot--diki-comp--openstack  
                                                            cluster: seed containerName: kube-apiserver details: fileName: /var/lib/kubelet/pods/4a414212-471d-49e1-ba69-657ac6fd352a/volumes/kubernetes.io~secret/ca/..2025_06_23_00_05_31.3801277659/bundle.crt, ownerUser: 0, ownerGroup: 65532 kind: pod name: kube-apiserver-5ffd79587b-574wj namespace: shoot--diki-comp--openstack  
                                                            cluster: seed containerName: kube-apiserver details: fileName: /var/lib/kubelet/pods/4a414212-471d-49e1-ba69-657ac6fd352a/volumes/kubernetes.io~secret/ca-client/..2025_06_23_00_05_31.316180318/bundle.crt, ownerUser: 0, ownerGroup: 65532 kind: pod name: kube-apiserver-5ffd79587b-574wj namespace: shoot--diki-comp--openstack  
                                                            cluster: seed containerName: kube-apiserver details: fileName: /var/lib/kubelet/pods/4a414212-471d-49e1-ba69-657ac6fd352a/volumes/kubernetes.io~secret/ca-front-proxy/..2025_06_23_00_05_31.1046019673/bundle.crt, ownerUser: 0, ownerGroup: 65532 kind: pod name: kube-apiserver-5ffd79587b-574wj namespace: shoot--diki-comp--openstack  
                                                            cluster: seed containerName: kube-apiserver details: fileName: /var/lib/kubelet/pods/4a414212-471d-49e1-ba69-657ac6fd352a/volumes/kubernetes.io~secret/service-account-key-bundle/..2025_06_23_00_05_31.2877576203/bundle.key, ownerUser: 0, ownerGroup: 65532 kind: pod name: kube-apiserver-5ffd79587b-574wj namespace: shoot--diki-comp--openstack  
                                                            cluster: seed containerName: kube-apiserver details: fileName: /var/lib/kubelet/pods/4a414212-471d-49e1-ba69-657ac6fd352a/volumes/kubernetes.io~secret/kube-aggregator/..2025_06_23_00_05_31.974579027/tls.crt, ownerUser: 0, ownerGroup: 65532 kind: pod name: kube-apiserver-5ffd79587b-574wj namespace: shoot--diki-comp--openstack  
                                                            cluster: seed containerName: kube-apiserver details: fileName: /var/lib/kubelet/pods/4a414212-471d-49e1-ba69-657ac6fd352a/volumes/kubernetes.io~secret/kube-aggregator/..2025_06_23_00_05_31.974579027/tls.key, ownerUser: 0, ownerGroup: 65532 kind: pod name: kube-apiserver-5ffd79587b-574wj namespace: shoot--diki-comp--openstack  
                                                            cluster: seed containerName: kube-apiserver details: fileName: /var/lib/kubelet/pods/4a414212-471d-49e1-ba69-657ac6fd352a/volumes/kubernetes.io~secret/server/..2025_06_23_00_05_31.110607305/tls.key, ownerUser: 0, ownerGroup: 65532 kind: pod name: kube-apiserver-5ffd79587b-574wj namespace: shoot--diki-comp--openstack  
                                                            cluster: seed containerName: kube-apiserver details: fileName: /var/lib/kubelet/pods/4a414212-471d-49e1-ba69-657ac6fd352a/volumes/kubernetes.io~secret/server/..2025_06_23_00_05_31.110607305/tls.crt, ownerUser: 0, ownerGroup: 65532 kind: pod name: kube-apiserver-5ffd79587b-574wj namespace: shoot--diki-comp--openstack  
                                                            cluster: seed containerName: kube-apiserver details: fileName: /var/lib/kubelet/pods/4a414212-471d-49e1-ba69-657ac6fd352a/volumes/kubernetes.io~secret/ca-vpn/..2025_06_23_00_05_31.1571181539/bundle.crt, ownerUser: 0, ownerGroup: 65532 kind: pod name: kube-apiserver-5ffd79587b-574wj namespace: shoot--diki-comp--openstack  
                                                            cluster: seed containerName: kube-apiserver details: fileName: /var/lib/kubelet/pods/4a414212-471d-49e1-ba69-657ac6fd352a/volumes/kubernetes.io~secret/ca-kubelet/..2025_06_23_00_05_31.1055204524/bundle.crt, ownerUser: 0, ownerGroup: 65532 kind: pod name: kube-apiserver-5ffd79587b-574wj namespace: shoot--diki-comp--openstack  
                                                            cluster: seed containerName: kube-apiserver details: fileName: /var/lib/kubelet/pods/4a414212-471d-49e1-ba69-657ac6fd352a/volumes/kubernetes.io~secret/kubelet-client/..2025_06_23_00_05_31.529535444/tls.crt, ownerUser: 0, ownerGroup: 65532 kind: pod name: kube-apiserver-5ffd79587b-574wj namespace: shoot--diki-comp--openstack  
                                                            cluster: seed containerName: kube-apiserver details: fileName: /var/lib/kubelet/pods/4a414212-471d-49e1-ba69-657ac6fd352a/volumes/kubernetes.io~secret/kubelet-client/..2025_06_23_00_05_31.529535444/tls.key, ownerUser: 0, ownerGroup: 65532 kind: pod name: kube-apiserver-5ffd79587b-574wj namespace: shoot--diki-comp--openstack  
                                                            cluster: seed containerName: kube-apiserver details: fileName: /var/lib/kubelet/pods/4a414212-471d-49e1-ba69-657ac6fd352a/volumes/kubernetes.io~secret/ca-etcd/..2025_06_23_00_05_31.3135557557/bundle.crt, ownerUser: 0, ownerGroup: 65532 kind: pod name: kube-apiserver-5ffd79587b-574wj namespace: shoot--diki-comp--openstack  
                                                            cluster: seed containerName: kube-apiserver details: fileName: /var/lib/kubelet/pods/4a414212-471d-49e1-ba69-657ac6fd352a/volumes/kubernetes.io~secret/etcd-client/..2025_06_23_00_05_31.3982193628/tls.key, ownerUser: 0, ownerGroup: 65532 kind: pod name: kube-apiserver-5ffd79587b-574wj namespace: shoot--diki-comp--openstack  
                                                            cluster: seed containerName: kube-apiserver details: fileName: /var/lib/kubelet/pods/4a414212-471d-49e1-ba69-657ac6fd352a/volumes/kubernetes.io~secret/etcd-client/..2025_06_23_00_05_31.3982193628/tls.crt, ownerUser: 0, ownerGroup: 65532 kind: pod name: kube-apiserver-5ffd79587b-574wj namespace: shoot--diki-comp--openstack  
                                                            cluster: seed containerName: kube-apiserver details: fileName: /var/lib/kubelet/pods/4a414212-471d-49e1-ba69-657ac6fd352a/volumes/kubernetes.io~secret/tls-sni-0/..2025_06_23_00_05_31.1069974019/tls.key, ownerUser: 0, ownerGroup: 65532 kind: pod name: kube-apiserver-5ffd79587b-574wj namespace: shoot--diki-comp--openstack  
                                                            cluster: seed containerName: kube-apiserver details: fileName: /var/lib/kubelet/pods/4a414212-471d-49e1-ba69-657ac6fd352a/volumes/kubernetes.io~secret/tls-sni-0/..2025_06_23_00_05_31.1069974019/tls.crt, ownerUser: 0, ownerGroup: 65532 kind: pod name: kube-apiserver-5ffd79587b-574wj namespace: shoot--diki-comp--openstack  
                                                            cluster: seed containerName: kube-apiserver details: fileName: /var/lib/kubelet/pods/4a414212-471d-49e1-ba69-657ac6fd352a/volumes/kubernetes.io~secret/tls-sni-0/..2025_06_23_00_05_31.1069974019/ca.crt, ownerUser: 0, ownerGroup: 65532 kind: pod name: kube-apiserver-5ffd79587b-574wj namespace: shoot--diki-comp--openstack  
                                                            cluster: seed containerName: kube-apiserver details: fileName: /var/lib/kubelet/pods/4a414212-471d-49e1-ba69-657ac6fd352a/volumes/kubernetes.io~secret/http-proxy/..2025_06_23_00_05_31.3012580451/tls.key, ownerUser: 0, ownerGroup: 65532 kind: pod name: kube-apiserver-5ffd79587b-574wj namespace: shoot--diki-comp--openstack  
                                                            cluster: seed containerName: kube-apiserver details: fileName: /var/lib/kubelet/pods/4a414212-471d-49e1-ba69-657ac6fd352a/volumes/kubernetes.io~secret/http-proxy/..2025_06_23_00_05_31.3012580451/tls.crt, ownerUser: 0, ownerGroup: 65532 kind: pod name: kube-apiserver-5ffd79587b-574wj namespace: shoot--diki-comp--openstack  
                                                            cluster: seed containerName: kube-apiserver details: fileName: /var/lib/kubelet/pods/4a414212-471d-49e1-ba69-657ac6fd352a/volumes/kubernetes.io~secret/ca-client/..2025_06_23_00_05_31.316180318, ownerUser: 0, ownerGroup: 65532 kind: pod name: kube-apiserver-5ffd79587b-574wj namespace: shoot--diki-comp--openstack  
                                                            cluster: seed containerName: kube-apiserver details: fileName: /var/lib/kubelet/pods/4a414212-471d-49e1-ba69-657ac6fd352a/volumes/kubernetes.io~secret/ca-front-proxy/..2025_06_23_00_05_31.1046019673, ownerUser: 0, ownerGroup: 65532 kind: pod name: kube-apiserver-5ffd79587b-574wj namespace: shoot--diki-comp--openstack  
                                                            cluster: seed containerName: kube-apiserver details: fileName: /var/lib/kubelet/pods/4a414212-471d-49e1-ba69-657ac6fd352a/volumes/kubernetes.io~secret/kube-aggregator/..2025_06_23_00_05_31.974579027, ownerUser: 0, ownerGroup: 65532 kind: pod name: kube-apiserver-5ffd79587b-574wj namespace: shoot--diki-comp--openstack  
                                                            cluster: seed containerName: kube-apiserver details: fileName: /var/lib/kubelet/pods/4a414212-471d-49e1-ba69-657ac6fd352a/volumes/kubernetes.io~secret/server/..2025_06_23_00_05_31.110607305, ownerUser: 0, ownerGroup: 65532 kind: pod name: kube-apiserver-5ffd79587b-574wj namespace: shoot--diki-comp--openstack  
                                                            cluster: seed containerName: kube-apiserver details: fileName: /var/lib/kubelet/pods/4a414212-471d-49e1-ba69-657ac6fd352a/volumes/kubernetes.io~secret/ca-kubelet/..2025_06_23_00_05_31.1055204524, ownerUser: 0, ownerGroup: 65532 kind: pod name: kube-apiserver-5ffd79587b-574wj namespace: shoot--diki-comp--openstack  
                                                            cluster: seed containerName: kube-apiserver details: fileName: /var/lib/kubelet/pods/4a414212-471d-49e1-ba69-657ac6fd352a/volumes/kubernetes.io~secret/ca-etcd/..2025_06_23_00_05_31.3135557557, ownerUser: 0, ownerGroup: 65532 kind: pod name: kube-apiserver-5ffd79587b-574wj namespace: shoot--diki-comp--openstack  
                                                            cluster: seed containerName: kube-apiserver details: fileName: /var/lib/kubelet/pods/4a414212-471d-49e1-ba69-657ac6fd352a/volumes/kubernetes.io~secret/etcd-client/..2025_06_23_00_05_31.3982193628, ownerUser: 0, ownerGroup: 65532 kind: pod name: kube-apiserver-5ffd79587b-574wj namespace: shoot--diki-comp--openstack  
                                                            cluster: seed containerName: kube-apiserver details: fileName: /var/lib/kubelet/pods/4a414212-471d-49e1-ba69-657ac6fd352a/volumes/kubernetes.io~secret/tls-sni-0/..2025_06_23_00_05_31.1069974019, ownerUser: 0, ownerGroup: 65532 kind: pod name: kube-apiserver-5ffd79587b-574wj namespace: shoot--diki-comp--openstack  
                                                            cluster: seed containerName: kube-apiserver details: fileName: /var/lib/kubelet/pods/4a414212-471d-49e1-ba69-657ac6fd352a/volumes/kubernetes.io~secret/ca/..2025_06_23_00_05_31.3801277659, ownerUser: 0, ownerGroup: 65532 kind: pod name: kube-apiserver-5ffd79587b-574wj namespace: shoot--diki-comp--openstack  
                                                            cluster: seed containerName: kube-apiserver details: fileName: /var/lib/kubelet/pods/4a414212-471d-49e1-ba69-657ac6fd352a/volumes/kubernetes.io~secret/service-account-key-bundle/..2025_06_23_00_05_31.2877576203, ownerUser: 0, ownerGroup: 65532 kind: pod name: kube-apiserver-5ffd79587b-574wj namespace: shoot--diki-comp--openstack  
                                                            cluster: seed containerName: kube-apiserver details: fileName: /var/lib/kubelet/pods/4a414212-471d-49e1-ba69-657ac6fd352a/volumes/kubernetes.io~secret/ca-vpn/..2025_06_23_00_05_31.1571181539, ownerUser: 0, ownerGroup: 65532 kind: pod name: kube-apiserver-5ffd79587b-574wj namespace: shoot--diki-comp--openstack  
                                                            cluster: seed containerName: kube-apiserver details: fileName: /var/lib/kubelet/pods/4a414212-471d-49e1-ba69-657ac6fd352a/volumes/kubernetes.io~secret/kubelet-client/..2025_06_23_00_05_31.529535444, ownerUser: 0, ownerGroup: 65532 kind: pod name: kube-apiserver-5ffd79587b-574wj namespace: shoot--diki-comp--openstack  
                                                            cluster: seed containerName: kube-apiserver details: fileName: /var/lib/kubelet/pods/4a414212-471d-49e1-ba69-657ac6fd352a/volumes/kubernetes.io~secret/http-proxy/..2025_06_23_00_05_31.3012580451, ownerUser: 0, ownerGroup: 65532 kind: pod name: kube-apiserver-5ffd79587b-574wj namespace: shoot--diki-comp--openstack  
                                                            cluster: shoot details: fileName: /var/lib/kubelet/pki/kubelet-client-2025-06-23-00-10-31.pem, ownerUser: 0, ownerGroup: 0 kind: node name: shoot--diki-comp--openstack-worker-dqty2-z1-64f7d-jllmm  
                                                            cluster: shoot details: fileName: /var/lib/kubelet/pki/kubelet-server-2025-06-23-00-10-38.pem, ownerUser: 0, ownerGroup: 0 kind: node name: shoot--diki-comp--openstack-worker-dqty2-z1-64f7d-jllmm  
                                                            cluster: shoot details: fileName: /var/lib/kubelet/pki, ownerUser: 0, ownerGroup: 0 kind: node name: shoot--diki-comp--openstack-worker-dqty2-z1-64f7d-jllmm  
                                                            cluster: shoot containerName: kube-proxy details: fileName: /var/lib/kubelet/pods/c1afd1ba-2ab9-43f3-a306-c810e02cd47d/volumes/kubernetes.io~projected/kube-api-access-gardener/..2025_06_23_00_10_32.3842156420/ca.crt, ownerUser: 0, ownerGroup: 0 kind: pod name: kube-proxy-worker-dqty2-v1.31.8-9sx78 namespace: kube-system  
                                                            cluster: shoot containerName: kube-proxy details: fileName: /var/lib/kubelet/pods/c1afd1ba-2ab9-43f3-a306-c810e02cd47d/volumes/kubernetes.io~projected/kube-api-access-gardener/..2025_06_23_00_10_32.3842156420, ownerUser: 0, ownerGroup: 0 kind: pod name: kube-proxy-worker-dqty2-v1.31.8-9sx78 namespace: kube-system  
                                                            cluster: shoot containerName: conntrack-fix details: fileName: /var/lib/kubelet/pods/c1afd1ba-2ab9-43f3-a306-c810e02cd47d/volumes/kubernetes.io~projected/kube-api-access-gardener/..2025_06_23_00_10_32.3842156420/ca.crt, ownerUser: 0, ownerGroup: 0 kind: pod name: kube-proxy-worker-dqty2-v1.31.8-9sx78 namespace: kube-system  
                                                            cluster: shoot containerName: conntrack-fix details: fileName: /var/lib/kubelet/pods/c1afd1ba-2ab9-43f3-a306-c810e02cd47d/volumes/kubernetes.io~projected/kube-api-access-gardener/..2025_06_23_00_10_32.3842156420, ownerUser: 0, ownerGroup: 0 kind: pod name: kube-proxy-worker-dqty2-v1.31.8-9sx78 namespace: kube-system  
                                                            cluster: shoot containerName: cleanup details: fileName: /var/lib/kubelet/pods/c1afd1ba-2ab9-43f3-a306-c810e02cd47d/volumes/kubernetes.io~projected/kube-api-access-gardener/..2025_06_23_00_10_32.3842156420/ca.crt, ownerUser: 0, ownerGroup: 0 kind: pod name: kube-proxy-worker-dqty2-v1.31.8-9sx78 namespace: kube-system  
                                                            cluster: shoot containerName: cleanup details: fileName: /var/lib/kubelet/pods/c1afd1ba-2ab9-43f3-a306-c810e02cd47d/volumes/kubernetes.io~projected/kube-api-access-gardener/..2025_06_23_00_10_32.3842156420, ownerUser: 0, ownerGroup: 0 kind: pod name: kube-proxy-worker-dqty2-v1.31.8-9sx78 namespace: kube-system  
                                                            cluster: shoot containerName: kube-proxy-init details: fileName: /var/lib/kubelet/pods/c1afd1ba-2ab9-43f3-a306-c810e02cd47d/volumes/kubernetes.io~projected/kube-api-access-gardener/..2025_06_23_00_10_32.3842156420/ca.crt, ownerUser: 0, ownerGroup: 0 kind: pod name: kube-proxy-worker-dqty2-v1.31.8-9sx78 namespace: kube-system  
                                                            cluster: shoot containerName: kube-proxy-init details: fileName: /var/lib/kubelet/pods/c1afd1ba-2ab9-43f3-a306-c810e02cd47d/volumes/kubernetes.io~projected/kube-api-access-gardener/..2025_06_23_00_10_32.3842156420, ownerUser: 0, ownerGroup: 0 kind: pod name: kube-proxy-worker-dqty2-v1.31.8-9sx78 namespace: kube-system  
                                                         
                                                     
                                                 
                                             
                                         
                                     
                                    
                                        242452 (Medium) - The Kubernetes kubelet KubeConfig must have file permissions set to 644 or more restrictive. 
                                        
                                            
                                                File has expected permissions 
                                                
                                                    
                                                        aws 
                                                        
                                                            details: fileName: /var/lib/kubelet/kubeconfig-real, permissions: 600 kind: node name: ip-IP-Address.eu-west-1.compute.internal  
                                                            details: fileName: /var/lib/kubelet/config/kubelet, permissions: 600 kind: node name: ip-IP-Address.eu-west-1.compute.internal  
                                                         
                                                     
                                                    
                                                        azure 
                                                        
                                                            details: fileName: /var/lib/kubelet/kubeconfig-real, permissions: 600 kind: node name: shoot--diki-comp--azure-worker-g7p4p-z3-66467-k6q5n  
                                                            details: fileName: /var/lib/kubelet/config/kubelet, permissions: 600 kind: node name: shoot--diki-comp--azure-worker-g7p4p-z3-66467-k6q5n  
                                                         
                                                     
                                                    
                                                        gcp 
                                                        
                                                            details: fileName: /var/lib/kubelet/kubeconfig-real, permissions: 600 kind: node name: shoot--diki-comp--gcp-worker-bex82-z1-5d9b4-8fp7q  
                                                            details: fileName: /var/lib/kubelet/config/kubelet, permissions: 600 kind: node name: shoot--diki-comp--gcp-worker-bex82-z1-5d9b4-8fp7q  
                                                         
                                                     
                                                    
                                                        openstack 
                                                        
                                                            details: fileName: /var/lib/kubelet/kubeconfig-real, permissions: 600 kind: node name: shoot--diki-comp--openstack-worker-dqty2-z1-64f7d-jllmm  
                                                            details: fileName: /var/lib/kubelet/config/kubelet, permissions: 600 kind: node name: shoot--diki-comp--openstack-worker-dqty2-z1-64f7d-jllmm  
                                                         
                                                     
                                                 
                                             
                                         
                                     
                                    
                                        242453 (Medium) - The Kubernetes kubelet KubeConfig file must be owned by root. 
                                        
                                            
                                                File has expected owners 
                                                
                                                    
                                                        aws 
                                                        
                                                            details: fileName: /var/lib/kubelet/kubeconfig-real, ownerUser: 0, ownerGroup: 0 kind: node name: ip-IP-Address.eu-west-1.compute.internal  
                                                            details: fileName: /var/lib/kubelet/config/kubelet, ownerUser: 0, ownerGroup: 0 kind: node name: ip-IP-Address.eu-west-1.compute.internal  
                                                         
                                                     
                                                    
                                                        azure 
                                                        
                                                            details: fileName: /var/lib/kubelet/kubeconfig-real, ownerUser: 0, ownerGroup: 0 kind: node name: shoot--diki-comp--azure-worker-g7p4p-z3-66467-k6q5n  
                                                            details: fileName: /var/lib/kubelet/config/kubelet, ownerUser: 0, ownerGroup: 0 kind: node name: shoot--diki-comp--azure-worker-g7p4p-z3-66467-k6q5n  
                                                         
                                                     
                                                    
                                                        gcp 
                                                        
                                                            details: fileName: /var/lib/kubelet/kubeconfig-real, ownerUser: 0, ownerGroup: 0 kind: node name: shoot--diki-comp--gcp-worker-bex82-z1-5d9b4-8fp7q  
                                                            details: fileName: /var/lib/kubelet/config/kubelet, ownerUser: 0, ownerGroup: 0 kind: node name: shoot--diki-comp--gcp-worker-bex82-z1-5d9b4-8fp7q  
                                                         
                                                     
                                                    
                                                        openstack 
                                                        
                                                            details: fileName: /var/lib/kubelet/kubeconfig-real, ownerUser: 0, ownerGroup: 0 kind: node name: shoot--diki-comp--openstack-worker-dqty2-z1-64f7d-jllmm  
                                                            details: fileName: /var/lib/kubelet/config/kubelet, ownerUser: 0, ownerGroup: 0 kind: node name: shoot--diki-comp--openstack-worker-dqty2-z1-64f7d-jllmm  
                                                         
                                                     
                                                 
                                             
                                         
                                     
                                    
                                        242459 (Medium) - The Kubernetes etcd must have file permissions set to 644 or more restrictive. 
                                        
                                            
                                                File has expected permissions 
                                                
                                                    
                                                        aws 
                                                        
                                                            containerName: etcd details: fileName: /var/lib/kubelet/pods/e9a97103-bea9-4174-9f2f-d11c7dee0b81/volumes/kubernetes.io~csi/pv-shoot--garden--aws-ha-eu2-e91404ef-48a3-4fd4-adad-1722b56c23ab/mount/safe_guard, permissions: 600 kind: pod name: etcd-main-0 namespace: shoot--diki-comp--aws  
                                                            containerName: etcd details: fileName: /var/lib/kubelet/pods/e9a97103-bea9-4174-9f2f-d11c7dee0b81/volumes/kubernetes.io~csi/pv-shoot--garden--aws-ha-eu2-e91404ef-48a3-4fd4-adad-1722b56c23ab/mount/new.etcd/member/wal/0.tmp, permissions: 600 kind: pod name: etcd-main-0 namespace: shoot--diki-comp--aws  
                                                            containerName: etcd details: fileName: /var/lib/kubelet/pods/e9a97103-bea9-4174-9f2f-d11c7dee0b81/volumes/kubernetes.io~csi/pv-shoot--garden--aws-ha-eu2-e91404ef-48a3-4fd4-adad-1722b56c23ab/mount/new.etcd/member/wal/0000000000000000-0000000000000000.wal, permissions: 600 kind: pod name: etcd-main-0 namespace: shoot--diki-comp--aws  
                                                            containerName: etcd details: fileName: /var/lib/kubelet/pods/e9a97103-bea9-4174-9f2f-d11c7dee0b81/volumes/kubernetes.io~csi/pv-shoot--garden--aws-ha-eu2-e91404ef-48a3-4fd4-adad-1722b56c23ab/mount/new.etcd/member/snap/db, permissions: 600 kind: pod name: etcd-main-0 namespace: shoot--diki-comp--aws  
                                                            containerName: etcd details: fileName: /var/lib/kubelet/pods/e9a97103-bea9-4174-9f2f-d11c7dee0b81/volumes/kubernetes.io~secret/etcd-ca/..2025_06_23_00_02_28.70977455/bundle.crt, permissions: 640 kind: pod name: etcd-main-0 namespace: shoot--diki-comp--aws  
                                                            containerName: etcd details: fileName: /var/lib/kubelet/pods/e9a97103-bea9-4174-9f2f-d11c7dee0b81/volumes/kubernetes.io~secret/etcd-server-tls/..2025_06_23_00_02_28.941742504/tls.crt, permissions: 640 kind: pod name: etcd-main-0 namespace: shoot--diki-comp--aws  
                                                            containerName: etcd details: fileName: /var/lib/kubelet/pods/e9a97103-bea9-4174-9f2f-d11c7dee0b81/volumes/kubernetes.io~secret/etcd-server-tls/..2025_06_23_00_02_28.941742504/tls.key, permissions: 640 kind: pod name: etcd-main-0 namespace: shoot--diki-comp--aws  
                                                            containerName: etcd details: fileName: /var/lib/kubelet/pods/e9a97103-bea9-4174-9f2f-d11c7dee0b81/volumes/kubernetes.io~secret/etcd-client-tls/..2025_06_23_00_02_28.581061777/tls.key, permissions: 640 kind: pod name: etcd-main-0 namespace: shoot--diki-comp--aws  
                                                            containerName: etcd details: fileName: /var/lib/kubelet/pods/e9a97103-bea9-4174-9f2f-d11c7dee0b81/volumes/kubernetes.io~secret/etcd-client-tls/..2025_06_23_00_02_28.581061777/tls.crt, permissions: 640 kind: pod name: etcd-main-0 namespace: shoot--diki-comp--aws  
                                                            containerName: etcd details: fileName: /var/lib/kubelet/pods/e9a97103-bea9-4174-9f2f-d11c7dee0b81/volumes/kubernetes.io~secret/backup-restore-ca/..2025_06_23_00_02_28.3789989883/bundle.crt, permissions: 640 kind: pod name: etcd-main-0 namespace: shoot--diki-comp--aws  
                                                            containerName: etcd details: fileName: /var/lib/kubelet/pods/e9a97103-bea9-4174-9f2f-d11c7dee0b81/volumes/kubernetes.io~projected/kube-api-access-gardener/..2025_06_23_00_02_28.4232825321/namespace, permissions: 644 kind: pod name: etcd-main-0 namespace: shoot--diki-comp--aws  
                                                            containerName: etcd details: fileName: /var/lib/kubelet/pods/e9a97103-bea9-4174-9f2f-d11c7dee0b81/volumes/kubernetes.io~projected/kube-api-access-gardener/..2025_06_23_00_02_28.4232825321/ca.crt, permissions: 644 kind: pod name: etcd-main-0 namespace: shoot--diki-comp--aws  
                                                            containerName: etcd details: fileName: /var/lib/kubelet/pods/e9a97103-bea9-4174-9f2f-d11c7dee0b81/volumes/kubernetes.io~projected/kube-api-access-gardener/..2025_06_23_00_02_28.4232825321/token, permissions: 640 kind: pod name: etcd-main-0 namespace: shoot--diki-comp--aws  
                                                            containerName: backup-restore details: fileName: /var/lib/kubelet/pods/e9a97103-bea9-4174-9f2f-d11c7dee0b81/volumes/kubernetes.io~secret/etcd-backup-secret/..2025_06_23_00_02_28.166720885/secretAccessKey, permissions: 640 kind: pod name: etcd-main-0 namespace: shoot--diki-comp--aws  
                                                            containerName: backup-restore details: fileName: /var/lib/kubelet/pods/e9a97103-bea9-4174-9f2f-d11c7dee0b81/volumes/kubernetes.io~secret/etcd-backup-secret/..2025_06_23_00_02_28.166720885/region, permissions: 640 kind: pod name: etcd-main-0 namespace: shoot--diki-comp--aws  
                                                            containerName: backup-restore details: fileName: /var/lib/kubelet/pods/e9a97103-bea9-4174-9f2f-d11c7dee0b81/volumes/kubernetes.io~secret/etcd-backup-secret/..2025_06_23_00_02_28.166720885/bucketName, permissions: 640 kind: pod name: etcd-main-0 namespace: shoot--diki-comp--aws  
                                                            containerName: backup-restore details: fileName: /var/lib/kubelet/pods/e9a97103-bea9-4174-9f2f-d11c7dee0b81/volumes/kubernetes.io~secret/etcd-backup-secret/..2025_06_23_00_02_28.166720885/accessKeyID, permissions: 640 kind: pod name: etcd-main-0 namespace: shoot--diki-comp--aws  
                                                            containerName: backup-restore details: fileName: /var/lib/kubelet/pods/e9a97103-bea9-4174-9f2f-d11c7dee0b81/volumes/kubernetes.io~csi/pv-shoot--garden--aws-ha-eu2-e91404ef-48a3-4fd4-adad-1722b56c23ab/mount/safe_guard, permissions: 600 kind: pod name: etcd-main-0 namespace: shoot--diki-comp--aws  
                                                            containerName: backup-restore details: fileName: /var/lib/kubelet/pods/e9a97103-bea9-4174-9f2f-d11c7dee0b81/volumes/kubernetes.io~csi/pv-shoot--garden--aws-ha-eu2-e91404ef-48a3-4fd4-adad-1722b56c23ab/mount/new.etcd/member/wal/0.tmp, permissions: 600 kind: pod name: etcd-main-0 namespace: shoot--diki-comp--aws  
                                                            containerName: backup-restore details: fileName: /var/lib/kubelet/pods/e9a97103-bea9-4174-9f2f-d11c7dee0b81/volumes/kubernetes.io~csi/pv-shoot--garden--aws-ha-eu2-e91404ef-48a3-4fd4-adad-1722b56c23ab/mount/new.etcd/member/wal/0000000000000000-0000000000000000.wal, permissions: 600 kind: pod name: etcd-main-0 namespace: shoot--diki-comp--aws  
                                                            containerName: backup-restore details: fileName: /var/lib/kubelet/pods/e9a97103-bea9-4174-9f2f-d11c7dee0b81/volumes/kubernetes.io~csi/pv-shoot--garden--aws-ha-eu2-e91404ef-48a3-4fd4-adad-1722b56c23ab/mount/new.etcd/member/snap/db, permissions: 600 kind: pod name: etcd-main-0 namespace: shoot--diki-comp--aws  
                                                            containerName: backup-restore details: fileName: /var/lib/kubelet/pods/e9a97103-bea9-4174-9f2f-d11c7dee0b81/volumes/kubernetes.io~configmap/etcd-config-file/..2025_06_23_00_02_28.1273412141/etcd.conf.yaml, permissions: 640 kind: pod name: etcd-main-0 namespace: shoot--diki-comp--aws  
                                                            containerName: backup-restore details: fileName: /var/lib/kubelet/pods/e9a97103-bea9-4174-9f2f-d11c7dee0b81/volumes/kubernetes.io~secret/backup-restore-server-tls/..2025_06_23_00_02_28.137193825/tls.key, permissions: 640 kind: pod name: etcd-main-0 namespace: shoot--diki-comp--aws  
                                                            containerName: backup-restore details: fileName: /var/lib/kubelet/pods/e9a97103-bea9-4174-9f2f-d11c7dee0b81/volumes/kubernetes.io~secret/backup-restore-server-tls/..2025_06_23_00_02_28.137193825/tls.crt, permissions: 640 kind: pod name: etcd-main-0 namespace: shoot--diki-comp--aws  
                                                            containerName: backup-restore details: fileName: /var/lib/kubelet/pods/e9a97103-bea9-4174-9f2f-d11c7dee0b81/volumes/kubernetes.io~secret/etcd-ca/..2025_06_23_00_02_28.70977455/bundle.crt, permissions: 640 kind: pod name: etcd-main-0 namespace: shoot--diki-comp--aws  
                                                            containerName: backup-restore details: fileName: /var/lib/kubelet/pods/e9a97103-bea9-4174-9f2f-d11c7dee0b81/volumes/kubernetes.io~secret/etcd-client-tls/..2025_06_23_00_02_28.581061777/tls.key, permissions: 640 kind: pod name: etcd-main-0 namespace: shoot--diki-comp--aws  
                                                            containerName: backup-restore details: fileName: /var/lib/kubelet/pods/e9a97103-bea9-4174-9f2f-d11c7dee0b81/volumes/kubernetes.io~secret/etcd-client-tls/..2025_06_23_00_02_28.581061777/tls.crt, permissions: 640 kind: pod name: etcd-main-0 namespace: shoot--diki-comp--aws  
                                                            containerName: backup-restore details: fileName: /var/lib/kubelet/pods/e9a97103-bea9-4174-9f2f-d11c7dee0b81/volumes/kubernetes.io~projected/kube-api-access-gardener/..2025_06_23_00_02_28.4232825321/namespace, permissions: 644 kind: pod name: etcd-main-0 namespace: shoot--diki-comp--aws  
                                                            containerName: backup-restore details: fileName: /var/lib/kubelet/pods/e9a97103-bea9-4174-9f2f-d11c7dee0b81/volumes/kubernetes.io~projected/kube-api-access-gardener/..2025_06_23_00_02_28.4232825321/ca.crt, permissions: 644 kind: pod name: etcd-main-0 namespace: shoot--diki-comp--aws  
                                                            containerName: backup-restore details: fileName: /var/lib/kubelet/pods/e9a97103-bea9-4174-9f2f-d11c7dee0b81/volumes/kubernetes.io~projected/kube-api-access-gardener/..2025_06_23_00_02_28.4232825321/token, permissions: 640 kind: pod name: etcd-main-0 namespace: shoot--diki-comp--aws  
                                                            containerName: etcd details: fileName: /var/lib/kubelet/pods/8500de88-870c-4453-a9d3-673fe2e83591/volumes/kubernetes.io~csi/pv-shoot--garden--aws-ha-eu2-93a075b4-8ed7-415f-b925-72cc610120fd/mount/safe_guard, permissions: 600 kind: pod name: etcd-events-0 namespace: shoot--diki-comp--aws  
                                                            containerName: etcd details: fileName: /var/lib/kubelet/pods/8500de88-870c-4453-a9d3-673fe2e83591/volumes/kubernetes.io~csi/pv-shoot--garden--aws-ha-eu2-93a075b4-8ed7-415f-b925-72cc610120fd/mount/new.etcd/member/snap/db, permissions: 600 kind: pod name: etcd-events-0 namespace: shoot--diki-comp--aws  
                                                            containerName: etcd details: fileName: /var/lib/kubelet/pods/8500de88-870c-4453-a9d3-673fe2e83591/volumes/kubernetes.io~csi/pv-shoot--garden--aws-ha-eu2-93a075b4-8ed7-415f-b925-72cc610120fd/mount/new.etcd/member/wal/0000000000000000-0000000000000000.wal, permissions: 600 kind: pod name: etcd-events-0 namespace: shoot--diki-comp--aws  
                                                            containerName: etcd details: fileName: /var/lib/kubelet/pods/8500de88-870c-4453-a9d3-673fe2e83591/volumes/kubernetes.io~csi/pv-shoot--garden--aws-ha-eu2-93a075b4-8ed7-415f-b925-72cc610120fd/mount/new.etcd/member/wal/0.tmp, permissions: 600 kind: pod name: etcd-events-0 namespace: shoot--diki-comp--aws  
                                                            containerName: etcd details: fileName: /var/lib/kubelet/pods/8500de88-870c-4453-a9d3-673fe2e83591/volumes/kubernetes.io~secret/etcd-ca/..2025_06_23_00_02_28.1460198907/bundle.crt, permissions: 640 kind: pod name: etcd-events-0 namespace: shoot--diki-comp--aws  
                                                            containerName: etcd details: fileName: /var/lib/kubelet/pods/8500de88-870c-4453-a9d3-673fe2e83591/volumes/kubernetes.io~secret/etcd-server-tls/..2025_06_23_00_02_28.1081429868/tls.key, permissions: 640 kind: pod name: etcd-events-0 namespace: shoot--diki-comp--aws  
                                                            containerName: etcd details: fileName: /var/lib/kubelet/pods/8500de88-870c-4453-a9d3-673fe2e83591/volumes/kubernetes.io~secret/etcd-server-tls/..2025_06_23_00_02_28.1081429868/tls.crt, permissions: 640 kind: pod name: etcd-events-0 namespace: shoot--diki-comp--aws  
                                                            containerName: etcd details: fileName: /var/lib/kubelet/pods/8500de88-870c-4453-a9d3-673fe2e83591/volumes/kubernetes.io~secret/etcd-client-tls/..2025_06_23_00_02_28.830733358/tls.key, permissions: 640 kind: pod name: etcd-events-0 namespace: shoot--diki-comp--aws  
                                                            containerName: etcd details: fileName: /var/lib/kubelet/pods/8500de88-870c-4453-a9d3-673fe2e83591/volumes/kubernetes.io~secret/etcd-client-tls/..2025_06_23_00_02_28.830733358/tls.crt, permissions: 640 kind: pod name: etcd-events-0 namespace: shoot--diki-comp--aws  
                                                            containerName: etcd details: fileName: /var/lib/kubelet/pods/8500de88-870c-4453-a9d3-673fe2e83591/volumes/kubernetes.io~secret/backup-restore-ca/..2025_06_23_00_02_28.402585131/bundle.crt, permissions: 640 kind: pod name: etcd-events-0 namespace: shoot--diki-comp--aws  
                                                            containerName: etcd details: fileName: /var/lib/kubelet/pods/8500de88-870c-4453-a9d3-673fe2e83591/volumes/kubernetes.io~projected/kube-api-access-gardener/..2025_06_23_00_02_28.124882621/ca.crt, permissions: 644 kind: pod name: etcd-events-0 namespace: shoot--diki-comp--aws  
                                                            containerName: etcd details: fileName: /var/lib/kubelet/pods/8500de88-870c-4453-a9d3-673fe2e83591/volumes/kubernetes.io~projected/kube-api-access-gardener/..2025_06_23_00_02_28.124882621/token, permissions: 640 kind: pod name: etcd-events-0 namespace: shoot--diki-comp--aws  
                                                            containerName: etcd details: fileName: /var/lib/kubelet/pods/8500de88-870c-4453-a9d3-673fe2e83591/volumes/kubernetes.io~projected/kube-api-access-gardener/..2025_06_23_00_02_28.124882621/namespace, permissions: 644 kind: pod name: etcd-events-0 namespace: shoot--diki-comp--aws  
                                                            containerName: backup-restore details: fileName: /var/lib/kubelet/pods/8500de88-870c-4453-a9d3-673fe2e83591/volumes/kubernetes.io~csi/pv-shoot--garden--aws-ha-eu2-93a075b4-8ed7-415f-b925-72cc610120fd/mount/safe_guard, permissions: 600 kind: pod name: etcd-events-0 namespace: shoot--diki-comp--aws  
                                                            containerName: backup-restore details: fileName: /var/lib/kubelet/pods/8500de88-870c-4453-a9d3-673fe2e83591/volumes/kubernetes.io~csi/pv-shoot--garden--aws-ha-eu2-93a075b4-8ed7-415f-b925-72cc610120fd/mount/new.etcd/member/snap/db, permissions: 600 kind: pod name: etcd-events-0 namespace: shoot--diki-comp--aws  
                                                            containerName: backup-restore details: fileName: /var/lib/kubelet/pods/8500de88-870c-4453-a9d3-673fe2e83591/volumes/kubernetes.io~csi/pv-shoot--garden--aws-ha-eu2-93a075b4-8ed7-415f-b925-72cc610120fd/mount/new.etcd/member/wal/0000000000000000-0000000000000000.wal, permissions: 600 kind: pod name: etcd-events-0 namespace: shoot--diki-comp--aws  
                                                            containerName: backup-restore details: fileName: /var/lib/kubelet/pods/8500de88-870c-4453-a9d3-673fe2e83591/volumes/kubernetes.io~csi/pv-shoot--garden--aws-ha-eu2-93a075b4-8ed7-415f-b925-72cc610120fd/mount/new.etcd/member/wal/0.tmp, permissions: 600 kind: pod name: etcd-events-0 namespace: shoot--diki-comp--aws  
                                                            containerName: backup-restore details: fileName: /var/lib/kubelet/pods/8500de88-870c-4453-a9d3-673fe2e83591/volumes/kubernetes.io~configmap/etcd-config-file/..2025_06_23_00_02_28.1474259460/etcd.conf.yaml, permissions: 640 kind: pod name: etcd-events-0 namespace: shoot--diki-comp--aws  
                                                            containerName: backup-restore details: fileName: /var/lib/kubelet/pods/8500de88-870c-4453-a9d3-673fe2e83591/volumes/kubernetes.io~secret/backup-restore-server-tls/..2025_06_23_00_02_28.1357612372/tls.key, permissions: 640 kind: pod name: etcd-events-0 namespace: shoot--diki-comp--aws  
                                                            containerName: backup-restore details: fileName: /var/lib/kubelet/pods/8500de88-870c-4453-a9d3-673fe2e83591/volumes/kubernetes.io~secret/backup-restore-server-tls/..2025_06_23_00_02_28.1357612372/tls.crt, permissions: 640 kind: pod name: etcd-events-0 namespace: shoot--diki-comp--aws  
                                                            containerName: backup-restore details: fileName: /var/lib/kubelet/pods/8500de88-870c-4453-a9d3-673fe2e83591/volumes/kubernetes.io~secret/etcd-ca/..2025_06_23_00_02_28.1460198907/bundle.crt, permissions: 640 kind: pod name: etcd-events-0 namespace: shoot--diki-comp--aws  
                                                            containerName: backup-restore details: fileName: /var/lib/kubelet/pods/8500de88-870c-4453-a9d3-673fe2e83591/volumes/kubernetes.io~secret/etcd-client-tls/..2025_06_23_00_02_28.830733358/tls.key, permissions: 640 kind: pod name: etcd-events-0 namespace: shoot--diki-comp--aws  
                                                            containerName: backup-restore details: fileName: /var/lib/kubelet/pods/8500de88-870c-4453-a9d3-673fe2e83591/volumes/kubernetes.io~secret/etcd-client-tls/..2025_06_23_00_02_28.830733358/tls.crt, permissions: 640 kind: pod name: etcd-events-0 namespace: shoot--diki-comp--aws  
                                                            containerName: backup-restore details: fileName: /var/lib/kubelet/pods/8500de88-870c-4453-a9d3-673fe2e83591/volumes/kubernetes.io~projected/kube-api-access-gardener/..2025_06_23_00_02_28.124882621/ca.crt, permissions: 644 kind: pod name: etcd-events-0 namespace: shoot--diki-comp--aws  
                                                            containerName: backup-restore details: fileName: /var/lib/kubelet/pods/8500de88-870c-4453-a9d3-673fe2e83591/volumes/kubernetes.io~projected/kube-api-access-gardener/..2025_06_23_00_02_28.124882621/token, permissions: 640 kind: pod name: etcd-events-0 namespace: shoot--diki-comp--aws  
                                                            containerName: backup-restore details: fileName: /var/lib/kubelet/pods/8500de88-870c-4453-a9d3-673fe2e83591/volumes/kubernetes.io~projected/kube-api-access-gardener/..2025_06_23_00_02_28.124882621/namespace, permissions: 644 kind: pod name: etcd-events-0 namespace: shoot--diki-comp--aws  
                                                         
                                                     
                                                    
                                                        azure 
                                                        
                                                            containerName: etcd details: fileName: /var/lib/kubelet/pods/d86b08b7-3d10-49ae-a4d6-4fe9fa757c93/volumes/kubernetes.io~csi/pv-shoot--garden--az-ha-eu1-08c488c5-a3a5-4c50-8a35-ef557f341224/mount/safe_guard, permissions: 600 kind: pod name: etcd-main-0 namespace: shoot--diki-comp--azure  
                                                            containerName: etcd details: fileName: /var/lib/kubelet/pods/d86b08b7-3d10-49ae-a4d6-4fe9fa757c93/volumes/kubernetes.io~csi/pv-shoot--garden--az-ha-eu1-08c488c5-a3a5-4c50-8a35-ef557f341224/mount/new.etcd/member/snap/db, permissions: 600 kind: pod name: etcd-main-0 namespace: shoot--diki-comp--azure  
                                                            containerName: etcd details: fileName: /var/lib/kubelet/pods/d86b08b7-3d10-49ae-a4d6-4fe9fa757c93/volumes/kubernetes.io~csi/pv-shoot--garden--az-ha-eu1-08c488c5-a3a5-4c50-8a35-ef557f341224/mount/new.etcd/member/wal/0.tmp, permissions: 600 kind: pod name: etcd-main-0 namespace: shoot--diki-comp--azure  
                                                            containerName: etcd details: fileName: /var/lib/kubelet/pods/d86b08b7-3d10-49ae-a4d6-4fe9fa757c93/volumes/kubernetes.io~csi/pv-shoot--garden--az-ha-eu1-08c488c5-a3a5-4c50-8a35-ef557f341224/mount/new.etcd/member/wal/0000000000000000-0000000000000000.wal, permissions: 600 kind: pod name: etcd-main-0 namespace: shoot--diki-comp--azure  
                                                            containerName: etcd details: fileName: /var/lib/kubelet/pods/d86b08b7-3d10-49ae-a4d6-4fe9fa757c93/volumes/kubernetes.io~secret/etcd-ca/..2025_06_23_00_02_37.231883813/bundle.crt, permissions: 640 kind: pod name: etcd-main-0 namespace: shoot--diki-comp--azure  
                                                            containerName: etcd details: fileName: /var/lib/kubelet/pods/d86b08b7-3d10-49ae-a4d6-4fe9fa757c93/volumes/kubernetes.io~secret/etcd-server-tls/..2025_06_23_00_02_37.4111409223/tls.key, permissions: 640 kind: pod name: etcd-main-0 namespace: shoot--diki-comp--azure  
                                                            containerName: etcd details: fileName: /var/lib/kubelet/pods/d86b08b7-3d10-49ae-a4d6-4fe9fa757c93/volumes/kubernetes.io~secret/etcd-server-tls/..2025_06_23_00_02_37.4111409223/tls.crt, permissions: 640 kind: pod name: etcd-main-0 namespace: shoot--diki-comp--azure  
                                                            containerName: etcd details: fileName: /var/lib/kubelet/pods/d86b08b7-3d10-49ae-a4d6-4fe9fa757c93/volumes/kubernetes.io~secret/etcd-client-tls/..2025_06_23_00_02_37.256397641/tls.key, permissions: 640 kind: pod name: etcd-main-0 namespace: shoot--diki-comp--azure  
                                                            containerName: etcd details: fileName: /var/lib/kubelet/pods/d86b08b7-3d10-49ae-a4d6-4fe9fa757c93/volumes/kubernetes.io~secret/etcd-client-tls/..2025_06_23_00_02_37.256397641/tls.crt, permissions: 640 kind: pod name: etcd-main-0 namespace: shoot--diki-comp--azure  
                                                            containerName: etcd details: fileName: /var/lib/kubelet/pods/d86b08b7-3d10-49ae-a4d6-4fe9fa757c93/volumes/kubernetes.io~secret/backup-restore-ca/..2025_06_23_00_02_37.1332383038/bundle.crt, permissions: 640 kind: pod name: etcd-main-0 namespace: shoot--diki-comp--azure  
                                                            containerName: etcd details: fileName: /var/lib/kubelet/pods/d86b08b7-3d10-49ae-a4d6-4fe9fa757c93/volumes/kubernetes.io~projected/kube-api-access-gardener/..2025_06_23_00_02_37.3272012549/namespace, permissions: 644 kind: pod name: etcd-main-0 namespace: shoot--diki-comp--azure  
                                                            containerName: etcd details: fileName: /var/lib/kubelet/pods/d86b08b7-3d10-49ae-a4d6-4fe9fa757c93/volumes/kubernetes.io~projected/kube-api-access-gardener/..2025_06_23_00_02_37.3272012549/ca.crt, permissions: 644 kind: pod name: etcd-main-0 namespace: shoot--diki-comp--azure  
                                                            containerName: etcd details: fileName: /var/lib/kubelet/pods/d86b08b7-3d10-49ae-a4d6-4fe9fa757c93/volumes/kubernetes.io~projected/kube-api-access-gardener/..2025_06_23_00_02_37.3272012549/token, permissions: 640 kind: pod name: etcd-main-0 namespace: shoot--diki-comp--azure  
                                                            containerName: backup-restore details: fileName: /var/lib/kubelet/pods/d86b08b7-3d10-49ae-a4d6-4fe9fa757c93/volumes/kubernetes.io~secret/etcd-backup-secret/..2025_06_23_00_02_37.2496710629/domain, permissions: 640 kind: pod name: etcd-main-0 namespace: shoot--diki-comp--azure  
                                                            containerName: backup-restore details: fileName: /var/lib/kubelet/pods/d86b08b7-3d10-49ae-a4d6-4fe9fa757c93/volumes/kubernetes.io~secret/etcd-backup-secret/..2025_06_23_00_02_37.2496710629/bucketName, permissions: 640 kind: pod name: etcd-main-0 namespace: shoot--diki-comp--azure  
                                                            containerName: backup-restore details: fileName: /var/lib/kubelet/pods/d86b08b7-3d10-49ae-a4d6-4fe9fa757c93/volumes/kubernetes.io~secret/etcd-backup-secret/..2025_06_23_00_02_37.2496710629/storageKey, permissions: 640 kind: pod name: etcd-main-0 namespace: shoot--diki-comp--azure  
                                                            containerName: backup-restore details: fileName: /var/lib/kubelet/pods/d86b08b7-3d10-49ae-a4d6-4fe9fa757c93/volumes/kubernetes.io~secret/etcd-backup-secret/..2025_06_23_00_02_37.2496710629/storageAccount, permissions: 640 kind: pod name: etcd-main-0 namespace: shoot--diki-comp--azure  
                                                            containerName: backup-restore details: fileName: /var/lib/kubelet/pods/d86b08b7-3d10-49ae-a4d6-4fe9fa757c93/volumes/kubernetes.io~csi/pv-shoot--garden--az-ha-eu1-08c488c5-a3a5-4c50-8a35-ef557f341224/mount/safe_guard, permissions: 600 kind: pod name: etcd-main-0 namespace: shoot--diki-comp--azure  
                                                            containerName: backup-restore details: fileName: /var/lib/kubelet/pods/d86b08b7-3d10-49ae-a4d6-4fe9fa757c93/volumes/kubernetes.io~csi/pv-shoot--garden--az-ha-eu1-08c488c5-a3a5-4c50-8a35-ef557f341224/mount/new.etcd/member/snap/db, permissions: 600 kind: pod name: etcd-main-0 namespace: shoot--diki-comp--azure  
                                                            containerName: backup-restore details: fileName: /var/lib/kubelet/pods/d86b08b7-3d10-49ae-a4d6-4fe9fa757c93/volumes/kubernetes.io~csi/pv-shoot--garden--az-ha-eu1-08c488c5-a3a5-4c50-8a35-ef557f341224/mount/new.etcd/member/wal/0.tmp, permissions: 600 kind: pod name: etcd-main-0 namespace: shoot--diki-comp--azure  
                                                            containerName: backup-restore details: fileName: /var/lib/kubelet/pods/d86b08b7-3d10-49ae-a4d6-4fe9fa757c93/volumes/kubernetes.io~csi/pv-shoot--garden--az-ha-eu1-08c488c5-a3a5-4c50-8a35-ef557f341224/mount/new.etcd/member/wal/0000000000000000-0000000000000000.wal, permissions: 600 kind: pod name: etcd-main-0 namespace: shoot--diki-comp--azure  
                                                            containerName: backup-restore details: fileName: /var/lib/kubelet/pods/d86b08b7-3d10-49ae-a4d6-4fe9fa757c93/volumes/kubernetes.io~configmap/etcd-config-file/..2025_06_23_00_02_37.3175801511/etcd.conf.yaml, permissions: 640 kind: pod name: etcd-main-0 namespace: shoot--diki-comp--azure  
                                                            containerName: backup-restore details: fileName: /var/lib/kubelet/pods/d86b08b7-3d10-49ae-a4d6-4fe9fa757c93/volumes/kubernetes.io~secret/backup-restore-server-tls/..2025_06_23_00_02_37.2487232432/tls.key, permissions: 640 kind: pod name: etcd-main-0 namespace: shoot--diki-comp--azure  
                                                            containerName: backup-restore details: fileName: /var/lib/kubelet/pods/d86b08b7-3d10-49ae-a4d6-4fe9fa757c93/volumes/kubernetes.io~secret/backup-restore-server-tls/..2025_06_23_00_02_37.2487232432/tls.crt, permissions: 640 kind: pod name: etcd-main-0 namespace: shoot--diki-comp--azure  
                                                            containerName: backup-restore details: fileName: /var/lib/kubelet/pods/d86b08b7-3d10-49ae-a4d6-4fe9fa757c93/volumes/kubernetes.io~secret/etcd-ca/..2025_06_23_00_02_37.231883813/bundle.crt, permissions: 640 kind: pod name: etcd-main-0 namespace: shoot--diki-comp--azure  
                                                            containerName: backup-restore details: fileName: /var/lib/kubelet/pods/d86b08b7-3d10-49ae-a4d6-4fe9fa757c93/volumes/kubernetes.io~secret/etcd-client-tls/..2025_06_23_00_02_37.256397641/tls.key, permissions: 640 kind: pod name: etcd-main-0 namespace: shoot--diki-comp--azure  
                                                            containerName: backup-restore details: fileName: /var/lib/kubelet/pods/d86b08b7-3d10-49ae-a4d6-4fe9fa757c93/volumes/kubernetes.io~secret/etcd-client-tls/..2025_06_23_00_02_37.256397641/tls.crt, permissions: 640 kind: pod name: etcd-main-0 namespace: shoot--diki-comp--azure  
                                                            containerName: backup-restore details: fileName: /var/lib/kubelet/pods/d86b08b7-3d10-49ae-a4d6-4fe9fa757c93/volumes/kubernetes.io~projected/kube-api-access-gardener/..2025_06_23_00_02_37.3272012549/namespace, permissions: 644 kind: pod name: etcd-main-0 namespace: shoot--diki-comp--azure  
                                                            containerName: backup-restore details: fileName: /var/lib/kubelet/pods/d86b08b7-3d10-49ae-a4d6-4fe9fa757c93/volumes/kubernetes.io~projected/kube-api-access-gardener/..2025_06_23_00_02_37.3272012549/ca.crt, permissions: 644 kind: pod name: etcd-main-0 namespace: shoot--diki-comp--azure  
                                                            containerName: backup-restore details: fileName: /var/lib/kubelet/pods/d86b08b7-3d10-49ae-a4d6-4fe9fa757c93/volumes/kubernetes.io~projected/kube-api-access-gardener/..2025_06_23_00_02_37.3272012549/token, permissions: 640 kind: pod name: etcd-main-0 namespace: shoot--diki-comp--azure  
                                                            containerName: etcd details: fileName: /var/lib/kubelet/pods/74f71030-9c73-40a7-b50e-fb1bb70cb9a5/volumes/kubernetes.io~csi/pv-shoot--garden--az-ha-eu1-e6a899bf-0a4c-4913-94ca-1434f1bee164/mount/new.etcd/member/wal/0.tmp, permissions: 600 kind: pod name: etcd-events-0 namespace: shoot--diki-comp--azure  
                                                            containerName: etcd details: fileName: /var/lib/kubelet/pods/74f71030-9c73-40a7-b50e-fb1bb70cb9a5/volumes/kubernetes.io~csi/pv-shoot--garden--az-ha-eu1-e6a899bf-0a4c-4913-94ca-1434f1bee164/mount/new.etcd/member/wal/0000000000000000-0000000000000000.wal, permissions: 600 kind: pod name: etcd-events-0 namespace: shoot--diki-comp--azure  
                                                            containerName: etcd details: fileName: /var/lib/kubelet/pods/74f71030-9c73-40a7-b50e-fb1bb70cb9a5/volumes/kubernetes.io~csi/pv-shoot--garden--az-ha-eu1-e6a899bf-0a4c-4913-94ca-1434f1bee164/mount/new.etcd/member/snap/db, permissions: 600 kind: pod name: etcd-events-0 namespace: shoot--diki-comp--azure  
                                                            containerName: etcd details: fileName: /var/lib/kubelet/pods/74f71030-9c73-40a7-b50e-fb1bb70cb9a5/volumes/kubernetes.io~csi/pv-shoot--garden--az-ha-eu1-e6a899bf-0a4c-4913-94ca-1434f1bee164/mount/safe_guard, permissions: 600 kind: pod name: etcd-events-0 namespace: shoot--diki-comp--azure  
                                                            containerName: etcd details: fileName: /var/lib/kubelet/pods/74f71030-9c73-40a7-b50e-fb1bb70cb9a5/volumes/kubernetes.io~secret/etcd-ca/..2025_06_23_00_02_36.1146945202/bundle.crt, permissions: 640 kind: pod name: etcd-events-0 namespace: shoot--diki-comp--azure  
                                                            containerName: etcd details: fileName: /var/lib/kubelet/pods/74f71030-9c73-40a7-b50e-fb1bb70cb9a5/volumes/kubernetes.io~secret/etcd-server-tls/..2025_06_23_00_02_36.3673560748/tls.key, permissions: 640 kind: pod name: etcd-events-0 namespace: shoot--diki-comp--azure  
                                                            containerName: etcd details: fileName: /var/lib/kubelet/pods/74f71030-9c73-40a7-b50e-fb1bb70cb9a5/volumes/kubernetes.io~secret/etcd-server-tls/..2025_06_23_00_02_36.3673560748/tls.crt, permissions: 640 kind: pod name: etcd-events-0 namespace: shoot--diki-comp--azure  
                                                            containerName: etcd details: fileName: /var/lib/kubelet/pods/74f71030-9c73-40a7-b50e-fb1bb70cb9a5/volumes/kubernetes.io~secret/etcd-client-tls/..2025_06_23_00_02_36.3852713643/tls.crt, permissions: 640 kind: pod name: etcd-events-0 namespace: shoot--diki-comp--azure  
                                                            containerName: etcd details: fileName: /var/lib/kubelet/pods/74f71030-9c73-40a7-b50e-fb1bb70cb9a5/volumes/kubernetes.io~secret/etcd-client-tls/..2025_06_23_00_02_36.3852713643/tls.key, permissions: 640 kind: pod name: etcd-events-0 namespace: shoot--diki-comp--azure  
                                                            containerName: etcd details: fileName: /var/lib/kubelet/pods/74f71030-9c73-40a7-b50e-fb1bb70cb9a5/volumes/kubernetes.io~secret/backup-restore-ca/..2025_06_23_00_02_36.3194705379/bundle.crt, permissions: 640 kind: pod name: etcd-events-0 namespace: shoot--diki-comp--azure  
                                                            containerName: etcd details: fileName: /var/lib/kubelet/pods/74f71030-9c73-40a7-b50e-fb1bb70cb9a5/volumes/kubernetes.io~projected/kube-api-access-gardener/..2025_06_23_00_02_36.662581379/ca.crt, permissions: 644 kind: pod name: etcd-events-0 namespace: shoot--diki-comp--azure  
                                                            containerName: etcd details: fileName: /var/lib/kubelet/pods/74f71030-9c73-40a7-b50e-fb1bb70cb9a5/volumes/kubernetes.io~projected/kube-api-access-gardener/..2025_06_23_00_02_36.662581379/token, permissions: 640 kind: pod name: etcd-events-0 namespace: shoot--diki-comp--azure  
                                                            containerName: etcd details: fileName: /var/lib/kubelet/pods/74f71030-9c73-40a7-b50e-fb1bb70cb9a5/volumes/kubernetes.io~projected/kube-api-access-gardener/..2025_06_23_00_02_36.662581379/namespace, permissions: 644 kind: pod name: etcd-events-0 namespace: shoot--diki-comp--azure  
                                                            containerName: backup-restore details: fileName: /var/lib/kubelet/pods/74f71030-9c73-40a7-b50e-fb1bb70cb9a5/volumes/kubernetes.io~csi/pv-shoot--garden--az-ha-eu1-e6a899bf-0a4c-4913-94ca-1434f1bee164/mount/new.etcd/member/wal/0.tmp, permissions: 600 kind: pod name: etcd-events-0 namespace: shoot--diki-comp--azure  
                                                            containerName: backup-restore details: fileName: /var/lib/kubelet/pods/74f71030-9c73-40a7-b50e-fb1bb70cb9a5/volumes/kubernetes.io~csi/pv-shoot--garden--az-ha-eu1-e6a899bf-0a4c-4913-94ca-1434f1bee164/mount/new.etcd/member/wal/0000000000000000-0000000000000000.wal, permissions: 600 kind: pod name: etcd-events-0 namespace: shoot--diki-comp--azure  
                                                            containerName: backup-restore details: fileName: /var/lib/kubelet/pods/74f71030-9c73-40a7-b50e-fb1bb70cb9a5/volumes/kubernetes.io~csi/pv-shoot--garden--az-ha-eu1-e6a899bf-0a4c-4913-94ca-1434f1bee164/mount/new.etcd/member/snap/db, permissions: 600 kind: pod name: etcd-events-0 namespace: shoot--diki-comp--azure  
                                                            containerName: backup-restore details: fileName: /var/lib/kubelet/pods/74f71030-9c73-40a7-b50e-fb1bb70cb9a5/volumes/kubernetes.io~csi/pv-shoot--garden--az-ha-eu1-e6a899bf-0a4c-4913-94ca-1434f1bee164/mount/safe_guard, permissions: 600 kind: pod name: etcd-events-0 namespace: shoot--diki-comp--azure  
                                                            containerName: backup-restore details: fileName: /var/lib/kubelet/pods/74f71030-9c73-40a7-b50e-fb1bb70cb9a5/volumes/kubernetes.io~configmap/etcd-config-file/..2025_06_23_00_02_36.261068025/etcd.conf.yaml, permissions: 640 kind: pod name: etcd-events-0 namespace: shoot--diki-comp--azure  
                                                            containerName: backup-restore details: fileName: /var/lib/kubelet/pods/74f71030-9c73-40a7-b50e-fb1bb70cb9a5/volumes/kubernetes.io~secret/backup-restore-server-tls/..2025_06_23_00_02_36.327312203/tls.key, permissions: 640 kind: pod name: etcd-events-0 namespace: shoot--diki-comp--azure  
                                                            containerName: backup-restore details: fileName: /var/lib/kubelet/pods/74f71030-9c73-40a7-b50e-fb1bb70cb9a5/volumes/kubernetes.io~secret/backup-restore-server-tls/..2025_06_23_00_02_36.327312203/tls.crt, permissions: 640 kind: pod name: etcd-events-0 namespace: shoot--diki-comp--azure  
                                                            containerName: backup-restore details: fileName: /var/lib/kubelet/pods/74f71030-9c73-40a7-b50e-fb1bb70cb9a5/volumes/kubernetes.io~secret/etcd-ca/..2025_06_23_00_02_36.1146945202/bundle.crt, permissions: 640 kind: pod name: etcd-events-0 namespace: shoot--diki-comp--azure  
                                                            containerName: backup-restore details: fileName: /var/lib/kubelet/pods/74f71030-9c73-40a7-b50e-fb1bb70cb9a5/volumes/kubernetes.io~secret/etcd-client-tls/..2025_06_23_00_02_36.3852713643/tls.crt, permissions: 640 kind: pod name: etcd-events-0 namespace: shoot--diki-comp--azure  
                                                            containerName: backup-restore details: fileName: /var/lib/kubelet/pods/74f71030-9c73-40a7-b50e-fb1bb70cb9a5/volumes/kubernetes.io~secret/etcd-client-tls/..2025_06_23_00_02_36.3852713643/tls.key, permissions: 640 kind: pod name: etcd-events-0 namespace: shoot--diki-comp--azure  
                                                            containerName: backup-restore details: fileName: /var/lib/kubelet/pods/74f71030-9c73-40a7-b50e-fb1bb70cb9a5/volumes/kubernetes.io~projected/kube-api-access-gardener/..2025_06_23_00_02_36.662581379/ca.crt, permissions: 644 kind: pod name: etcd-events-0 namespace: shoot--diki-comp--azure  
                                                            containerName: backup-restore details: fileName: /var/lib/kubelet/pods/74f71030-9c73-40a7-b50e-fb1bb70cb9a5/volumes/kubernetes.io~projected/kube-api-access-gardener/..2025_06_23_00_02_36.662581379/token, permissions: 640 kind: pod name: etcd-events-0 namespace: shoot--diki-comp--azure  
                                                            containerName: backup-restore details: fileName: /var/lib/kubelet/pods/74f71030-9c73-40a7-b50e-fb1bb70cb9a5/volumes/kubernetes.io~projected/kube-api-access-gardener/..2025_06_23_00_02_36.662581379/namespace, permissions: 644 kind: pod name: etcd-events-0 namespace: shoot--diki-comp--azure  
                                                         
                                                     
                                                    
                                                        gcp 
                                                        
                                                            containerName: etcd details: fileName: /var/lib/kubelet/pods/56b8ee4f-315f-4054-af24-a9fd2f484963/volumes/kubernetes.io~csi/pv--2a07e1f1-b1e9-46ed-a639-a3b1fd1434b4/mount/new.etcd/member/wal/0000000000000000-0000000000000000.wal, permissions: 600 kind: pod name: etcd-events-0 namespace: shoot--diki-comp--gcp  
                                                            containerName: etcd details: fileName: /var/lib/kubelet/pods/56b8ee4f-315f-4054-af24-a9fd2f484963/volumes/kubernetes.io~csi/pv--2a07e1f1-b1e9-46ed-a639-a3b1fd1434b4/mount/new.etcd/member/wal/0.tmp, permissions: 600 kind: pod name: etcd-events-0 namespace: shoot--diki-comp--gcp  
                                                            containerName: etcd details: fileName: /var/lib/kubelet/pods/56b8ee4f-315f-4054-af24-a9fd2f484963/volumes/kubernetes.io~csi/pv--2a07e1f1-b1e9-46ed-a639-a3b1fd1434b4/mount/new.etcd/member/snap/db, permissions: 600 kind: pod name: etcd-events-0 namespace: shoot--diki-comp--gcp  
                                                            containerName: etcd details: fileName: /var/lib/kubelet/pods/56b8ee4f-315f-4054-af24-a9fd2f484963/volumes/kubernetes.io~csi/pv--2a07e1f1-b1e9-46ed-a639-a3b1fd1434b4/mount/safe_guard, permissions: 600 kind: pod name: etcd-events-0 namespace: shoot--diki-comp--gcp  
                                                            containerName: etcd details: fileName: /var/lib/kubelet/pods/56b8ee4f-315f-4054-af24-a9fd2f484963/volumes/kubernetes.io~secret/etcd-ca/..2025_06_23_00_02_35.3098522537/bundle.crt, permissions: 640 kind: pod name: etcd-events-0 namespace: shoot--diki-comp--gcp  
                                                            containerName: etcd details: fileName: /var/lib/kubelet/pods/56b8ee4f-315f-4054-af24-a9fd2f484963/volumes/kubernetes.io~secret/etcd-server-tls/..2025_06_23_00_02_35.3565116838/tls.key, permissions: 640 kind: pod name: etcd-events-0 namespace: shoot--diki-comp--gcp  
                                                            containerName: etcd details: fileName: /var/lib/kubelet/pods/56b8ee4f-315f-4054-af24-a9fd2f484963/volumes/kubernetes.io~secret/etcd-server-tls/..2025_06_23_00_02_35.3565116838/tls.crt, permissions: 640 kind: pod name: etcd-events-0 namespace: shoot--diki-comp--gcp  
                                                            containerName: etcd details: fileName: /var/lib/kubelet/pods/56b8ee4f-315f-4054-af24-a9fd2f484963/volumes/kubernetes.io~secret/etcd-client-tls/..2025_06_23_00_02_35.3308771745/tls.key, permissions: 640 kind: pod name: etcd-events-0 namespace: shoot--diki-comp--gcp  
                                                            containerName: etcd details: fileName: /var/lib/kubelet/pods/56b8ee4f-315f-4054-af24-a9fd2f484963/volumes/kubernetes.io~secret/etcd-client-tls/..2025_06_23_00_02_35.3308771745/tls.crt, permissions: 640 kind: pod name: etcd-events-0 namespace: shoot--diki-comp--gcp  
                                                            containerName: etcd details: fileName: /var/lib/kubelet/pods/56b8ee4f-315f-4054-af24-a9fd2f484963/volumes/kubernetes.io~secret/backup-restore-ca/..2025_06_23_00_02_35.4083445152/bundle.crt, permissions: 640 kind: pod name: etcd-events-0 namespace: shoot--diki-comp--gcp  
                                                            containerName: etcd details: fileName: /var/lib/kubelet/pods/56b8ee4f-315f-4054-af24-a9fd2f484963/volumes/kubernetes.io~projected/kube-api-access-gardener/..2025_06_23_00_02_35.4217059112/namespace, permissions: 644 kind: pod name: etcd-events-0 namespace: shoot--diki-comp--gcp  
                                                            containerName: etcd details: fileName: /var/lib/kubelet/pods/56b8ee4f-315f-4054-af24-a9fd2f484963/volumes/kubernetes.io~projected/kube-api-access-gardener/..2025_06_23_00_02_35.4217059112/ca.crt, permissions: 644 kind: pod name: etcd-events-0 namespace: shoot--diki-comp--gcp  
                                                            containerName: etcd details: fileName: /var/lib/kubelet/pods/56b8ee4f-315f-4054-af24-a9fd2f484963/volumes/kubernetes.io~projected/kube-api-access-gardener/..2025_06_23_00_02_35.4217059112/token, permissions: 640 kind: pod name: etcd-events-0 namespace: shoot--diki-comp--gcp  
                                                            containerName: backup-restore details: fileName: /var/lib/kubelet/pods/56b8ee4f-315f-4054-af24-a9fd2f484963/volumes/kubernetes.io~csi/pv--2a07e1f1-b1e9-46ed-a639-a3b1fd1434b4/mount/new.etcd/member/wal/0000000000000000-0000000000000000.wal, permissions: 600 kind: pod name: etcd-events-0 namespace: shoot--diki-comp--gcp  
                                                            containerName: backup-restore details: fileName: /var/lib/kubelet/pods/56b8ee4f-315f-4054-af24-a9fd2f484963/volumes/kubernetes.io~csi/pv--2a07e1f1-b1e9-46ed-a639-a3b1fd1434b4/mount/new.etcd/member/wal/0.tmp, permissions: 600 kind: pod name: etcd-events-0 namespace: shoot--diki-comp--gcp  
                                                            containerName: backup-restore details: fileName: /var/lib/kubelet/pods/56b8ee4f-315f-4054-af24-a9fd2f484963/volumes/kubernetes.io~csi/pv--2a07e1f1-b1e9-46ed-a639-a3b1fd1434b4/mount/new.etcd/member/snap/db, permissions: 600 kind: pod name: etcd-events-0 namespace: shoot--diki-comp--gcp  
                                                            containerName: backup-restore details: fileName: /var/lib/kubelet/pods/56b8ee4f-315f-4054-af24-a9fd2f484963/volumes/kubernetes.io~csi/pv--2a07e1f1-b1e9-46ed-a639-a3b1fd1434b4/mount/safe_guard, permissions: 600 kind: pod name: etcd-events-0 namespace: shoot--diki-comp--gcp  
                                                            containerName: backup-restore details: fileName: /var/lib/kubelet/pods/56b8ee4f-315f-4054-af24-a9fd2f484963/volumes/kubernetes.io~configmap/etcd-config-file/..2025_06_23_00_02_35.261387052/etcd.conf.yaml, permissions: 640 kind: pod name: etcd-events-0 namespace: shoot--diki-comp--gcp  
                                                            containerName: backup-restore details: fileName: /var/lib/kubelet/pods/56b8ee4f-315f-4054-af24-a9fd2f484963/volumes/kubernetes.io~secret/backup-restore-server-tls/..2025_06_23_00_02_35.375113374/tls.crt, permissions: 640 kind: pod name: etcd-events-0 namespace: shoot--diki-comp--gcp  
                                                            containerName: backup-restore details: fileName: /var/lib/kubelet/pods/56b8ee4f-315f-4054-af24-a9fd2f484963/volumes/kubernetes.io~secret/backup-restore-server-tls/..2025_06_23_00_02_35.375113374/tls.key, permissions: 640 kind: pod name: etcd-events-0 namespace: shoot--diki-comp--gcp  
                                                            containerName: backup-restore details: fileName: /var/lib/kubelet/pods/56b8ee4f-315f-4054-af24-a9fd2f484963/volumes/kubernetes.io~secret/etcd-ca/..2025_06_23_00_02_35.3098522537/bundle.crt, permissions: 640 kind: pod name: etcd-events-0 namespace: shoot--diki-comp--gcp  
                                                            containerName: backup-restore details: fileName: /var/lib/kubelet/pods/56b8ee4f-315f-4054-af24-a9fd2f484963/volumes/kubernetes.io~secret/etcd-client-tls/..2025_06_23_00_02_35.3308771745/tls.key, permissions: 640 kind: pod name: etcd-events-0 namespace: shoot--diki-comp--gcp  
                                                            containerName: backup-restore details: fileName: /var/lib/kubelet/pods/56b8ee4f-315f-4054-af24-a9fd2f484963/volumes/kubernetes.io~secret/etcd-client-tls/..2025_06_23_00_02_35.3308771745/tls.crt, permissions: 640 kind: pod name: etcd-events-0 namespace: shoot--diki-comp--gcp  
                                                            containerName: backup-restore details: fileName: /var/lib/kubelet/pods/56b8ee4f-315f-4054-af24-a9fd2f484963/volumes/kubernetes.io~projected/kube-api-access-gardener/..2025_06_23_00_02_35.4217059112/namespace, permissions: 644 kind: pod name: etcd-events-0 namespace: shoot--diki-comp--gcp  
                                                            containerName: backup-restore details: fileName: /var/lib/kubelet/pods/56b8ee4f-315f-4054-af24-a9fd2f484963/volumes/kubernetes.io~projected/kube-api-access-gardener/..2025_06_23_00_02_35.4217059112/ca.crt, permissions: 644 kind: pod name: etcd-events-0 namespace: shoot--diki-comp--gcp  
                                                            containerName: backup-restore details: fileName: /var/lib/kubelet/pods/56b8ee4f-315f-4054-af24-a9fd2f484963/volumes/kubernetes.io~projected/kube-api-access-gardener/..2025_06_23_00_02_35.4217059112/token, permissions: 640 kind: pod name: etcd-events-0 namespace: shoot--diki-comp--gcp  
                                                            containerName: backup-restore details: fileName: /var/lib/kubelet/pods/5b8aebf9-d079-4ec9-a1dc-f2e2adadf242/volumes/kubernetes.io~secret/etcd-backup-secret/..2025_06_23_00_02_35.4034996191/serviceaccount.json, permissions: 640 kind: pod name: etcd-main-0 namespace: shoot--diki-comp--gcp  
                                                            containerName: backup-restore details: fileName: /var/lib/kubelet/pods/5b8aebf9-d079-4ec9-a1dc-f2e2adadf242/volumes/kubernetes.io~secret/etcd-backup-secret/..2025_06_23_00_02_35.4034996191/bucketName, permissions: 640 kind: pod name: etcd-main-0 namespace: shoot--diki-comp--gcp  
                                                            containerName: backup-restore details: fileName: /var/lib/kubelet/pods/5b8aebf9-d079-4ec9-a1dc-f2e2adadf242/volumes/kubernetes.io~csi/pv--54a8efde-85c8-4138-af3a-952bd7394924/mount/safe_guard, permissions: 600 kind: pod name: etcd-main-0 namespace: shoot--diki-comp--gcp  
                                                            containerName: backup-restore details: fileName: /var/lib/kubelet/pods/5b8aebf9-d079-4ec9-a1dc-f2e2adadf242/volumes/kubernetes.io~csi/pv--54a8efde-85c8-4138-af3a-952bd7394924/mount/new.etcd/member/wal/0000000000000000-0000000000000000.wal, permissions: 600 kind: pod name: etcd-main-0 namespace: shoot--diki-comp--gcp  
                                                            containerName: backup-restore details: fileName: /var/lib/kubelet/pods/5b8aebf9-d079-4ec9-a1dc-f2e2adadf242/volumes/kubernetes.io~csi/pv--54a8efde-85c8-4138-af3a-952bd7394924/mount/new.etcd/member/wal/0.tmp, permissions: 600 kind: pod name: etcd-main-0 namespace: shoot--diki-comp--gcp  
                                                            containerName: backup-restore details: fileName: /var/lib/kubelet/pods/5b8aebf9-d079-4ec9-a1dc-f2e2adadf242/volumes/kubernetes.io~csi/pv--54a8efde-85c8-4138-af3a-952bd7394924/mount/new.etcd/member/snap/db, permissions: 600 kind: pod name: etcd-main-0 namespace: shoot--diki-comp--gcp  
                                                            containerName: backup-restore details: fileName: /var/lib/kubelet/pods/5b8aebf9-d079-4ec9-a1dc-f2e2adadf242/volumes/kubernetes.io~configmap/etcd-config-file/..2025_06_23_00_02_35.1894821196/etcd.conf.yaml, permissions: 640 kind: pod name: etcd-main-0 namespace: shoot--diki-comp--gcp  
                                                            containerName: backup-restore details: fileName: /var/lib/kubelet/pods/5b8aebf9-d079-4ec9-a1dc-f2e2adadf242/volumes/kubernetes.io~secret/backup-restore-server-tls/..2025_06_23_00_02_35.1035566417/tls.key, permissions: 640 kind: pod name: etcd-main-0 namespace: shoot--diki-comp--gcp  
                                                            containerName: backup-restore details: fileName: /var/lib/kubelet/pods/5b8aebf9-d079-4ec9-a1dc-f2e2adadf242/volumes/kubernetes.io~secret/backup-restore-server-tls/..2025_06_23_00_02_35.1035566417/tls.crt, permissions: 640 kind: pod name: etcd-main-0 namespace: shoot--diki-comp--gcp  
                                                            containerName: backup-restore details: fileName: /var/lib/kubelet/pods/5b8aebf9-d079-4ec9-a1dc-f2e2adadf242/volumes/kubernetes.io~secret/etcd-ca/..2025_06_23_00_02_35.359863374/bundle.crt, permissions: 640 kind: pod name: etcd-main-0 namespace: shoot--diki-comp--gcp  
                                                            containerName: backup-restore details: fileName: /var/lib/kubelet/pods/5b8aebf9-d079-4ec9-a1dc-f2e2adadf242/volumes/kubernetes.io~secret/etcd-client-tls/..2025_06_23_00_02_35.270682216/tls.crt, permissions: 640 kind: pod name: etcd-main-0 namespace: shoot--diki-comp--gcp  
                                                            containerName: backup-restore details: fileName: /var/lib/kubelet/pods/5b8aebf9-d079-4ec9-a1dc-f2e2adadf242/volumes/kubernetes.io~secret/etcd-client-tls/..2025_06_23_00_02_35.270682216/tls.key, permissions: 640 kind: pod name: etcd-main-0 namespace: shoot--diki-comp--gcp  
                                                            containerName: backup-restore details: fileName: /var/lib/kubelet/pods/5b8aebf9-d079-4ec9-a1dc-f2e2adadf242/volumes/kubernetes.io~projected/kube-api-access-gardener/..2025_06_23_00_02_35.3521445574/ca.crt, permissions: 644 kind: pod name: etcd-main-0 namespace: shoot--diki-comp--gcp  
                                                            containerName: backup-restore details: fileName: /var/lib/kubelet/pods/5b8aebf9-d079-4ec9-a1dc-f2e2adadf242/volumes/kubernetes.io~projected/kube-api-access-gardener/..2025_06_23_00_02_35.3521445574/token, permissions: 640 kind: pod name: etcd-main-0 namespace: shoot--diki-comp--gcp  
                                                            containerName: backup-restore details: fileName: /var/lib/kubelet/pods/5b8aebf9-d079-4ec9-a1dc-f2e2adadf242/volumes/kubernetes.io~projected/kube-api-access-gardener/..2025_06_23_00_02_35.3521445574/namespace, permissions: 644 kind: pod name: etcd-main-0 namespace: shoot--diki-comp--gcp  
                                                            containerName: etcd details: fileName: /var/lib/kubelet/pods/5b8aebf9-d079-4ec9-a1dc-f2e2adadf242/volumes/kubernetes.io~csi/pv--54a8efde-85c8-4138-af3a-952bd7394924/mount/safe_guard, permissions: 600 kind: pod name: etcd-main-0 namespace: shoot--diki-comp--gcp  
                                                            containerName: etcd details: fileName: /var/lib/kubelet/pods/5b8aebf9-d079-4ec9-a1dc-f2e2adadf242/volumes/kubernetes.io~csi/pv--54a8efde-85c8-4138-af3a-952bd7394924/mount/new.etcd/member/wal/0000000000000000-0000000000000000.wal, permissions: 600 kind: pod name: etcd-main-0 namespace: shoot--diki-comp--gcp  
                                                            containerName: etcd details: fileName: /var/lib/kubelet/pods/5b8aebf9-d079-4ec9-a1dc-f2e2adadf242/volumes/kubernetes.io~csi/pv--54a8efde-85c8-4138-af3a-952bd7394924/mount/new.etcd/member/wal/0.tmp, permissions: 600 kind: pod name: etcd-main-0 namespace: shoot--diki-comp--gcp  
                                                            containerName: etcd details: fileName: /var/lib/kubelet/pods/5b8aebf9-d079-4ec9-a1dc-f2e2adadf242/volumes/kubernetes.io~csi/pv--54a8efde-85c8-4138-af3a-952bd7394924/mount/new.etcd/member/snap/db, permissions: 600 kind: pod name: etcd-main-0 namespace: shoot--diki-comp--gcp  
                                                            containerName: etcd details: fileName: /var/lib/kubelet/pods/5b8aebf9-d079-4ec9-a1dc-f2e2adadf242/volumes/kubernetes.io~secret/etcd-ca/..2025_06_23_00_02_35.359863374/bundle.crt, permissions: 640 kind: pod name: etcd-main-0 namespace: shoot--diki-comp--gcp  
                                                            containerName: etcd details: fileName: /var/lib/kubelet/pods/5b8aebf9-d079-4ec9-a1dc-f2e2adadf242/volumes/kubernetes.io~secret/etcd-server-tls/..2025_06_23_00_02_35.761653683/tls.crt, permissions: 640 kind: pod name: etcd-main-0 namespace: shoot--diki-comp--gcp  
                                                            containerName: etcd details: fileName: /var/lib/kubelet/pods/5b8aebf9-d079-4ec9-a1dc-f2e2adadf242/volumes/kubernetes.io~secret/etcd-server-tls/..2025_06_23_00_02_35.761653683/tls.key, permissions: 640 kind: pod name: etcd-main-0 namespace: shoot--diki-comp--gcp  
                                                            containerName: etcd details: fileName: /var/lib/kubelet/pods/5b8aebf9-d079-4ec9-a1dc-f2e2adadf242/volumes/kubernetes.io~secret/etcd-client-tls/..2025_06_23_00_02_35.270682216/tls.crt, permissions: 640 kind: pod name: etcd-main-0 namespace: shoot--diki-comp--gcp  
                                                            containerName: etcd details: fileName: /var/lib/kubelet/pods/5b8aebf9-d079-4ec9-a1dc-f2e2adadf242/volumes/kubernetes.io~secret/etcd-client-tls/..2025_06_23_00_02_35.270682216/tls.key, permissions: 640 kind: pod name: etcd-main-0 namespace: shoot--diki-comp--gcp  
                                                            containerName: etcd details: fileName: /var/lib/kubelet/pods/5b8aebf9-d079-4ec9-a1dc-f2e2adadf242/volumes/kubernetes.io~secret/backup-restore-ca/..2025_06_23_00_02_35.2072965808/bundle.crt, permissions: 640 kind: pod name: etcd-main-0 namespace: shoot--diki-comp--gcp  
                                                            containerName: etcd details: fileName: /var/lib/kubelet/pods/5b8aebf9-d079-4ec9-a1dc-f2e2adadf242/volumes/kubernetes.io~projected/kube-api-access-gardener/..2025_06_23_00_02_35.3521445574/ca.crt, permissions: 644 kind: pod name: etcd-main-0 namespace: shoot--diki-comp--gcp  
                                                            containerName: etcd details: fileName: /var/lib/kubelet/pods/5b8aebf9-d079-4ec9-a1dc-f2e2adadf242/volumes/kubernetes.io~projected/kube-api-access-gardener/..2025_06_23_00_02_35.3521445574/token, permissions: 640 kind: pod name: etcd-main-0 namespace: shoot--diki-comp--gcp  
                                                            containerName: etcd details: fileName: /var/lib/kubelet/pods/5b8aebf9-d079-4ec9-a1dc-f2e2adadf242/volumes/kubernetes.io~projected/kube-api-access-gardener/..2025_06_23_00_02_35.3521445574/namespace, permissions: 644 kind: pod name: etcd-main-0 namespace: shoot--diki-comp--gcp  
                                                         
                                                     
                                                    
                                                        openstack 
                                                        
                                                            containerName: etcd details: fileName: /var/lib/kubelet/pods/9c7e7507-c95f-4034-bb45-54d9a5a0061e/volumes/kubernetes.io~csi/pv-shoot--garden--cc-ha-eu1-c71d53d4-69ee-460e-8ef0-1d320b26975c/mount/safe_guard, permissions: 600 kind: pod name: etcd-events-0 namespace: shoot--diki-comp--openstack  
                                                            containerName: etcd details: fileName: /var/lib/kubelet/pods/9c7e7507-c95f-4034-bb45-54d9a5a0061e/volumes/kubernetes.io~csi/pv-shoot--garden--cc-ha-eu1-c71d53d4-69ee-460e-8ef0-1d320b26975c/mount/new.etcd/member/wal/0000000000000000-0000000000000000.wal, permissions: 600 kind: pod name: etcd-events-0 namespace: shoot--diki-comp--openstack  
                                                            containerName: etcd details: fileName: /var/lib/kubelet/pods/9c7e7507-c95f-4034-bb45-54d9a5a0061e/volumes/kubernetes.io~csi/pv-shoot--garden--cc-ha-eu1-c71d53d4-69ee-460e-8ef0-1d320b26975c/mount/new.etcd/member/wal/0.tmp, permissions: 600 kind: pod name: etcd-events-0 namespace: shoot--diki-comp--openstack  
                                                            containerName: etcd details: fileName: /var/lib/kubelet/pods/9c7e7507-c95f-4034-bb45-54d9a5a0061e/volumes/kubernetes.io~csi/pv-shoot--garden--cc-ha-eu1-c71d53d4-69ee-460e-8ef0-1d320b26975c/mount/new.etcd/member/snap/db, permissions: 600 kind: pod name: etcd-events-0 namespace: shoot--diki-comp--openstack  
                                                            containerName: etcd details: fileName: /var/lib/kubelet/pods/9c7e7507-c95f-4034-bb45-54d9a5a0061e/volumes/kubernetes.io~secret/etcd-ca/..2025_06_23_00_02_39.2818779423/bundle.crt, permissions: 640 kind: pod name: etcd-events-0 namespace: shoot--diki-comp--openstack  
                                                            containerName: etcd details: fileName: /var/lib/kubelet/pods/9c7e7507-c95f-4034-bb45-54d9a5a0061e/volumes/kubernetes.io~secret/etcd-server-tls/..2025_06_23_00_02_39.1241938029/tls.key, permissions: 640 kind: pod name: etcd-events-0 namespace: shoot--diki-comp--openstack  
                                                            containerName: etcd details: fileName: /var/lib/kubelet/pods/9c7e7507-c95f-4034-bb45-54d9a5a0061e/volumes/kubernetes.io~secret/etcd-server-tls/..2025_06_23_00_02_39.1241938029/tls.crt, permissions: 640 kind: pod name: etcd-events-0 namespace: shoot--diki-comp--openstack  
                                                            containerName: etcd details: fileName: /var/lib/kubelet/pods/9c7e7507-c95f-4034-bb45-54d9a5a0061e/volumes/kubernetes.io~secret/etcd-client-tls/..2025_06_23_00_02_39.2589051175/tls.key, permissions: 640 kind: pod name: etcd-events-0 namespace: shoot--diki-comp--openstack  
                                                            containerName: etcd details: fileName: /var/lib/kubelet/pods/9c7e7507-c95f-4034-bb45-54d9a5a0061e/volumes/kubernetes.io~secret/etcd-client-tls/..2025_06_23_00_02_39.2589051175/tls.crt, permissions: 640 kind: pod name: etcd-events-0 namespace: shoot--diki-comp--openstack  
                                                            containerName: etcd details: fileName: /var/lib/kubelet/pods/9c7e7507-c95f-4034-bb45-54d9a5a0061e/volumes/kubernetes.io~secret/backup-restore-ca/..2025_06_23_00_02_39.735587336/bundle.crt, permissions: 640 kind: pod name: etcd-events-0 namespace: shoot--diki-comp--openstack  
                                                            containerName: etcd details: fileName: /var/lib/kubelet/pods/9c7e7507-c95f-4034-bb45-54d9a5a0061e/volumes/kubernetes.io~projected/kube-api-access-gardener/..2025_06_23_00_02_39.3883414360/namespace, permissions: 644 kind: pod name: etcd-events-0 namespace: shoot--diki-comp--openstack  
                                                            containerName: etcd details: fileName: /var/lib/kubelet/pods/9c7e7507-c95f-4034-bb45-54d9a5a0061e/volumes/kubernetes.io~projected/kube-api-access-gardener/..2025_06_23_00_02_39.3883414360/ca.crt, permissions: 644 kind: pod name: etcd-events-0 namespace: shoot--diki-comp--openstack  
                                                            containerName: etcd details: fileName: /var/lib/kubelet/pods/9c7e7507-c95f-4034-bb45-54d9a5a0061e/volumes/kubernetes.io~projected/kube-api-access-gardener/..2025_06_23_00_02_39.3883414360/token, permissions: 640 kind: pod name: etcd-events-0 namespace: shoot--diki-comp--openstack  
                                                            containerName: backup-restore details: fileName: /var/lib/kubelet/pods/9c7e7507-c95f-4034-bb45-54d9a5a0061e/volumes/kubernetes.io~csi/pv-shoot--garden--cc-ha-eu1-c71d53d4-69ee-460e-8ef0-1d320b26975c/mount/safe_guard, permissions: 600 kind: pod name: etcd-events-0 namespace: shoot--diki-comp--openstack  
                                                            containerName: backup-restore details: fileName: /var/lib/kubelet/pods/9c7e7507-c95f-4034-bb45-54d9a5a0061e/volumes/kubernetes.io~csi/pv-shoot--garden--cc-ha-eu1-c71d53d4-69ee-460e-8ef0-1d320b26975c/mount/new.etcd/member/wal/0000000000000000-0000000000000000.wal, permissions: 600 kind: pod name: etcd-events-0 namespace: shoot--diki-comp--openstack  
                                                            containerName: backup-restore details: fileName: /var/lib/kubelet/pods/9c7e7507-c95f-4034-bb45-54d9a5a0061e/volumes/kubernetes.io~csi/pv-shoot--garden--cc-ha-eu1-c71d53d4-69ee-460e-8ef0-1d320b26975c/mount/new.etcd/member/wal/0.tmp, permissions: 600 kind: pod name: etcd-events-0 namespace: shoot--diki-comp--openstack  
                                                            containerName: backup-restore details: fileName: /var/lib/kubelet/pods/9c7e7507-c95f-4034-bb45-54d9a5a0061e/volumes/kubernetes.io~csi/pv-shoot--garden--cc-ha-eu1-c71d53d4-69ee-460e-8ef0-1d320b26975c/mount/new.etcd/member/snap/db, permissions: 600 kind: pod name: etcd-events-0 namespace: shoot--diki-comp--openstack  
                                                            containerName: backup-restore details: fileName: /var/lib/kubelet/pods/9c7e7507-c95f-4034-bb45-54d9a5a0061e/volumes/kubernetes.io~configmap/etcd-config-file/..2025_06_23_00_02_39.1412208420/etcd.conf.yaml, permissions: 640 kind: pod name: etcd-events-0 namespace: shoot--diki-comp--openstack  
                                                            containerName: backup-restore details: fileName: /var/lib/kubelet/pods/9c7e7507-c95f-4034-bb45-54d9a5a0061e/volumes/kubernetes.io~secret/backup-restore-server-tls/..2025_06_23_00_02_39.705338586/tls.crt, permissions: 640 kind: pod name: etcd-events-0 namespace: shoot--diki-comp--openstack  
                                                            containerName: backup-restore details: fileName: /var/lib/kubelet/pods/9c7e7507-c95f-4034-bb45-54d9a5a0061e/volumes/kubernetes.io~secret/backup-restore-server-tls/..2025_06_23_00_02_39.705338586/tls.key, permissions: 640 kind: pod name: etcd-events-0 namespace: shoot--diki-comp--openstack  
                                                            containerName: backup-restore details: fileName: /var/lib/kubelet/pods/9c7e7507-c95f-4034-bb45-54d9a5a0061e/volumes/kubernetes.io~secret/etcd-ca/..2025_06_23_00_02_39.2818779423/bundle.crt, permissions: 640 kind: pod name: etcd-events-0 namespace: shoot--diki-comp--openstack  
                                                            containerName: backup-restore details: fileName: /var/lib/kubelet/pods/9c7e7507-c95f-4034-bb45-54d9a5a0061e/volumes/kubernetes.io~secret/etcd-client-tls/..2025_06_23_00_02_39.2589051175/tls.key, permissions: 640 kind: pod name: etcd-events-0 namespace: shoot--diki-comp--openstack  
                                                            containerName: backup-restore details: fileName: /var/lib/kubelet/pods/9c7e7507-c95f-4034-bb45-54d9a5a0061e/volumes/kubernetes.io~secret/etcd-client-tls/..2025_06_23_00_02_39.2589051175/tls.crt, permissions: 640 kind: pod name: etcd-events-0 namespace: shoot--diki-comp--openstack  
                                                            containerName: backup-restore details: fileName: /var/lib/kubelet/pods/9c7e7507-c95f-4034-bb45-54d9a5a0061e/volumes/kubernetes.io~projected/kube-api-access-gardener/..2025_06_23_00_02_39.3883414360/namespace, permissions: 644 kind: pod name: etcd-events-0 namespace: shoot--diki-comp--openstack  
                                                            containerName: backup-restore details: fileName: /var/lib/kubelet/pods/9c7e7507-c95f-4034-bb45-54d9a5a0061e/volumes/kubernetes.io~projected/kube-api-access-gardener/..2025_06_23_00_02_39.3883414360/ca.crt, permissions: 644 kind: pod name: etcd-events-0 namespace: shoot--diki-comp--openstack  
                                                            containerName: backup-restore details: fileName: /var/lib/kubelet/pods/9c7e7507-c95f-4034-bb45-54d9a5a0061e/volumes/kubernetes.io~projected/kube-api-access-gardener/..2025_06_23_00_02_39.3883414360/token, permissions: 640 kind: pod name: etcd-events-0 namespace: shoot--diki-comp--openstack  
                                                            containerName: etcd details: fileName: /var/lib/kubelet/pods/7d71941f-a963-401d-b0e0-28ed7592fe7d/volumes/kubernetes.io~csi/pv-shoot--garden--cc-ha-eu1-dade4d52-dcc4-4f13-9aa3-6ca013d1bc55/mount/new.etcd/member/snap/db, permissions: 600 kind: pod name: etcd-main-0 namespace: shoot--diki-comp--openstack  
                                                            containerName: etcd details: fileName: /var/lib/kubelet/pods/7d71941f-a963-401d-b0e0-28ed7592fe7d/volumes/kubernetes.io~csi/pv-shoot--garden--cc-ha-eu1-dade4d52-dcc4-4f13-9aa3-6ca013d1bc55/mount/new.etcd/member/wal/0.tmp, permissions: 600 kind: pod name: etcd-main-0 namespace: shoot--diki-comp--openstack  
                                                            containerName: etcd details: fileName: /var/lib/kubelet/pods/7d71941f-a963-401d-b0e0-28ed7592fe7d/volumes/kubernetes.io~csi/pv-shoot--garden--cc-ha-eu1-dade4d52-dcc4-4f13-9aa3-6ca013d1bc55/mount/new.etcd/member/wal/0000000000000000-0000000000000000.wal, permissions: 600 kind: pod name: etcd-main-0 namespace: shoot--diki-comp--openstack  
                                                            containerName: etcd details: fileName: /var/lib/kubelet/pods/7d71941f-a963-401d-b0e0-28ed7592fe7d/volumes/kubernetes.io~csi/pv-shoot--garden--cc-ha-eu1-dade4d52-dcc4-4f13-9aa3-6ca013d1bc55/mount/safe_guard, permissions: 600 kind: pod name: etcd-main-0 namespace: shoot--diki-comp--openstack  
                                                            containerName: etcd details: fileName: /var/lib/kubelet/pods/7d71941f-a963-401d-b0e0-28ed7592fe7d/volumes/kubernetes.io~secret/etcd-ca/..2025_06_23_00_02_39.4052105237/bundle.crt, permissions: 640 kind: pod name: etcd-main-0 namespace: shoot--diki-comp--openstack  
                                                            containerName: etcd details: fileName: /var/lib/kubelet/pods/7d71941f-a963-401d-b0e0-28ed7592fe7d/volumes/kubernetes.io~secret/etcd-server-tls/..2025_06_23_00_02_39.149437060/tls.key, permissions: 640 kind: pod name: etcd-main-0 namespace: shoot--diki-comp--openstack  
                                                            containerName: etcd details: fileName: /var/lib/kubelet/pods/7d71941f-a963-401d-b0e0-28ed7592fe7d/volumes/kubernetes.io~secret/etcd-server-tls/..2025_06_23_00_02_39.149437060/tls.crt, permissions: 640 kind: pod name: etcd-main-0 namespace: shoot--diki-comp--openstack  
                                                            containerName: etcd details: fileName: /var/lib/kubelet/pods/7d71941f-a963-401d-b0e0-28ed7592fe7d/volumes/kubernetes.io~secret/etcd-client-tls/..2025_06_23_00_02_39.296248316/tls.crt, permissions: 640 kind: pod name: etcd-main-0 namespace: shoot--diki-comp--openstack  
                                                            containerName: etcd details: fileName: /var/lib/kubelet/pods/7d71941f-a963-401d-b0e0-28ed7592fe7d/volumes/kubernetes.io~secret/etcd-client-tls/..2025_06_23_00_02_39.296248316/tls.key, permissions: 640 kind: pod name: etcd-main-0 namespace: shoot--diki-comp--openstack  
                                                            containerName: etcd details: fileName: /var/lib/kubelet/pods/7d71941f-a963-401d-b0e0-28ed7592fe7d/volumes/kubernetes.io~secret/backup-restore-ca/..2025_06_23_00_02_39.2679800161/bundle.crt, permissions: 640 kind: pod name: etcd-main-0 namespace: shoot--diki-comp--openstack  
                                                            containerName: etcd details: fileName: /var/lib/kubelet/pods/7d71941f-a963-401d-b0e0-28ed7592fe7d/volumes/kubernetes.io~projected/kube-api-access-gardener/..2025_06_23_00_02_39.1703787134/ca.crt, permissions: 644 kind: pod name: etcd-main-0 namespace: shoot--diki-comp--openstack  
                                                            containerName: etcd details: fileName: /var/lib/kubelet/pods/7d71941f-a963-401d-b0e0-28ed7592fe7d/volumes/kubernetes.io~projected/kube-api-access-gardener/..2025_06_23_00_02_39.1703787134/token, permissions: 640 kind: pod name: etcd-main-0 namespace: shoot--diki-comp--openstack  
                                                            containerName: etcd details: fileName: /var/lib/kubelet/pods/7d71941f-a963-401d-b0e0-28ed7592fe7d/volumes/kubernetes.io~projected/kube-api-access-gardener/..2025_06_23_00_02_39.1703787134/namespace, permissions: 644 kind: pod name: etcd-main-0 namespace: shoot--diki-comp--openstack  
                                                            containerName: backup-restore details: fileName: /var/lib/kubelet/pods/7d71941f-a963-401d-b0e0-28ed7592fe7d/volumes/kubernetes.io~secret/etcd-backup-secret/..2025_06_23_00_02_39.2738667413/applicationCredentialName, permissions: 640 kind: pod name: etcd-main-0 namespace: shoot--diki-comp--openstack  
                                                            containerName: backup-restore details: fileName: /var/lib/kubelet/pods/7d71941f-a963-401d-b0e0-28ed7592fe7d/volumes/kubernetes.io~secret/etcd-backup-secret/..2025_06_23_00_02_39.2738667413/applicationCredentialID, permissions: 640 kind: pod name: etcd-main-0 namespace: shoot--diki-comp--openstack  
                                                            containerName: backup-restore details: fileName: /var/lib/kubelet/pods/7d71941f-a963-401d-b0e0-28ed7592fe7d/volumes/kubernetes.io~secret/etcd-backup-secret/..2025_06_23_00_02_39.2738667413/tenantName, permissions: 640 kind: pod name: etcd-main-0 namespace: shoot--diki-comp--openstack  
                                                            containerName: backup-restore details: fileName: /var/lib/kubelet/pods/7d71941f-a963-401d-b0e0-28ed7592fe7d/volumes/kubernetes.io~secret/etcd-backup-secret/..2025_06_23_00_02_39.2738667413/region, permissions: 640 kind: pod name: etcd-main-0 namespace: shoot--diki-comp--openstack  
                                                            containerName: backup-restore details: fileName: /var/lib/kubelet/pods/7d71941f-a963-401d-b0e0-28ed7592fe7d/volumes/kubernetes.io~secret/etcd-backup-secret/..2025_06_23_00_02_39.2738667413/domainName, permissions: 640 kind: pod name: etcd-main-0 namespace: shoot--diki-comp--openstack  
                                                            containerName: backup-restore details: fileName: /var/lib/kubelet/pods/7d71941f-a963-401d-b0e0-28ed7592fe7d/volumes/kubernetes.io~secret/etcd-backup-secret/..2025_06_23_00_02_39.2738667413/bucketName, permissions: 640 kind: pod name: etcd-main-0 namespace: shoot--diki-comp--openstack  
                                                            containerName: backup-restore details: fileName: /var/lib/kubelet/pods/7d71941f-a963-401d-b0e0-28ed7592fe7d/volumes/kubernetes.io~secret/etcd-backup-secret/..2025_06_23_00_02_39.2738667413/authURL, permissions: 640 kind: pod name: etcd-main-0 namespace: shoot--diki-comp--openstack  
                                                            containerName: backup-restore details: fileName: /var/lib/kubelet/pods/7d71941f-a963-401d-b0e0-28ed7592fe7d/volumes/kubernetes.io~secret/etcd-backup-secret/..2025_06_23_00_02_39.2738667413/applicationCredentialSecret, permissions: 640 kind: pod name: etcd-main-0 namespace: shoot--diki-comp--openstack  
                                                            containerName: backup-restore details: fileName: /var/lib/kubelet/pods/7d71941f-a963-401d-b0e0-28ed7592fe7d/volumes/kubernetes.io~csi/pv-shoot--garden--cc-ha-eu1-dade4d52-dcc4-4f13-9aa3-6ca013d1bc55/mount/new.etcd/member/snap/db, permissions: 600 kind: pod name: etcd-main-0 namespace: shoot--diki-comp--openstack  
                                                            containerName: backup-restore details: fileName: /var/lib/kubelet/pods/7d71941f-a963-401d-b0e0-28ed7592fe7d/volumes/kubernetes.io~csi/pv-shoot--garden--cc-ha-eu1-dade4d52-dcc4-4f13-9aa3-6ca013d1bc55/mount/new.etcd/member/wal/0.tmp, permissions: 600 kind: pod name: etcd-main-0 namespace: shoot--diki-comp--openstack  
                                                            containerName: backup-restore details: fileName: /var/lib/kubelet/pods/7d71941f-a963-401d-b0e0-28ed7592fe7d/volumes/kubernetes.io~csi/pv-shoot--garden--cc-ha-eu1-dade4d52-dcc4-4f13-9aa3-6ca013d1bc55/mount/new.etcd/member/wal/0000000000000000-0000000000000000.wal, permissions: 600 kind: pod name: etcd-main-0 namespace: shoot--diki-comp--openstack  
                                                            containerName: backup-restore details: fileName: /var/lib/kubelet/pods/7d71941f-a963-401d-b0e0-28ed7592fe7d/volumes/kubernetes.io~csi/pv-shoot--garden--cc-ha-eu1-dade4d52-dcc4-4f13-9aa3-6ca013d1bc55/mount/safe_guard, permissions: 600 kind: pod name: etcd-main-0 namespace: shoot--diki-comp--openstack  
                                                            containerName: backup-restore details: fileName: /var/lib/kubelet/pods/7d71941f-a963-401d-b0e0-28ed7592fe7d/volumes/kubernetes.io~configmap/etcd-config-file/..2025_06_23_00_02_39.532503070/etcd.conf.yaml, permissions: 640 kind: pod name: etcd-main-0 namespace: shoot--diki-comp--openstack  
                                                            containerName: backup-restore details: fileName: /var/lib/kubelet/pods/7d71941f-a963-401d-b0e0-28ed7592fe7d/volumes/kubernetes.io~secret/backup-restore-server-tls/..2025_06_23_00_02_39.456523922/tls.key, permissions: 640 kind: pod name: etcd-main-0 namespace: shoot--diki-comp--openstack  
                                                            containerName: backup-restore details: fileName: /var/lib/kubelet/pods/7d71941f-a963-401d-b0e0-28ed7592fe7d/volumes/kubernetes.io~secret/backup-restore-server-tls/..2025_06_23_00_02_39.456523922/tls.crt, permissions: 640 kind: pod name: etcd-main-0 namespace: shoot--diki-comp--openstack  
                                                            containerName: backup-restore details: fileName: /var/lib/kubelet/pods/7d71941f-a963-401d-b0e0-28ed7592fe7d/volumes/kubernetes.io~secret/etcd-ca/..2025_06_23_00_02_39.4052105237/bundle.crt, permissions: 640 kind: pod name: etcd-main-0 namespace: shoot--diki-comp--openstack  
                                                            containerName: backup-restore details: fileName: /var/lib/kubelet/pods/7d71941f-a963-401d-b0e0-28ed7592fe7d/volumes/kubernetes.io~secret/etcd-client-tls/..2025_06_23_00_02_39.296248316/tls.crt, permissions: 640 kind: pod name: etcd-main-0 namespace: shoot--diki-comp--openstack  
                                                            containerName: backup-restore details: fileName: /var/lib/kubelet/pods/7d71941f-a963-401d-b0e0-28ed7592fe7d/volumes/kubernetes.io~secret/etcd-client-tls/..2025_06_23_00_02_39.296248316/tls.key, permissions: 640 kind: pod name: etcd-main-0 namespace: shoot--diki-comp--openstack  
                                                            containerName: backup-restore details: fileName: /var/lib/kubelet/pods/7d71941f-a963-401d-b0e0-28ed7592fe7d/volumes/kubernetes.io~projected/kube-api-access-gardener/..2025_06_23_00_02_39.1703787134/ca.crt, permissions: 644 kind: pod name: etcd-main-0 namespace: shoot--diki-comp--openstack  
                                                            containerName: backup-restore details: fileName: /var/lib/kubelet/pods/7d71941f-a963-401d-b0e0-28ed7592fe7d/volumes/kubernetes.io~projected/kube-api-access-gardener/..2025_06_23_00_02_39.1703787134/token, permissions: 640 kind: pod name: etcd-main-0 namespace: shoot--diki-comp--openstack  
                                                            containerName: backup-restore details: fileName: /var/lib/kubelet/pods/7d71941f-a963-401d-b0e0-28ed7592fe7d/volumes/kubernetes.io~projected/kube-api-access-gardener/..2025_06_23_00_02_39.1703787134/namespace, permissions: 644 kind: pod name: etcd-main-0 namespace: shoot--diki-comp--openstack  
                                                         
                                                     
                                                 
                                             
                                         
                                     
                                    
                                        242460 (Medium) - The Kubernetes admin.conf must have file permissions set to 644 or more restrictive. 
                                        
                                            
                                                File has expected permissions 
                                                
                                                    
                                                        aws 
                                                        
                                                            containerName: kube-controller-manager details: fileName: /var/lib/kubelet/pods/c423b64c-cb58-46fa-a956-022b9b1664c6/volumes/kubernetes.io~secret/ca/..2025_06_23_00_16_39.892891764/bundle.crt, permissions: 644 kind: pod name: kube-controller-manager-7c9bc75987-cqgs4 namespace: shoot--diki-comp--aws  
                                                            containerName: kube-controller-manager details: fileName: /var/lib/kubelet/pods/c423b64c-cb58-46fa-a956-022b9b1664c6/volumes/kubernetes.io~secret/ca-client/..2025_06_23_00_16_39.4293646224/ca.key, permissions: 640 kind: pod name: kube-controller-manager-7c9bc75987-cqgs4 namespace: shoot--diki-comp--aws  
                                                            containerName: kube-controller-manager details: fileName: /var/lib/kubelet/pods/c423b64c-cb58-46fa-a956-022b9b1664c6/volumes/kubernetes.io~secret/ca-client/..2025_06_23_00_16_39.4293646224/ca.crt, permissions: 640 kind: pod name: kube-controller-manager-7c9bc75987-cqgs4 namespace: shoot--diki-comp--aws  
                                                            containerName: kube-controller-manager details: fileName: /var/lib/kubelet/pods/c423b64c-cb58-46fa-a956-022b9b1664c6/volumes/kubernetes.io~secret/service-account-key/..2025_06_23_00_16_39.1494491013/id_rsa, permissions: 640 kind: pod name: kube-controller-manager-7c9bc75987-cqgs4 namespace: shoot--diki-comp--aws  
                                                            containerName: kube-controller-manager details: fileName: /var/lib/kubelet/pods/c423b64c-cb58-46fa-a956-022b9b1664c6/volumes/kubernetes.io~secret/server/..2025_06_23_00_16_39.867879351/tls.key, permissions: 640 kind: pod name: kube-controller-manager-7c9bc75987-cqgs4 namespace: shoot--diki-comp--aws  
                                                            containerName: kube-controller-manager details: fileName: /var/lib/kubelet/pods/c423b64c-cb58-46fa-a956-022b9b1664c6/volumes/kubernetes.io~secret/server/..2025_06_23_00_16_39.867879351/tls.crt, permissions: 640 kind: pod name: kube-controller-manager-7c9bc75987-cqgs4 namespace: shoot--diki-comp--aws  
                                                            containerName: kube-controller-manager details: fileName: /var/lib/kubelet/pods/c423b64c-cb58-46fa-a956-022b9b1664c6/volumes/kubernetes.io~secret/ca-kubelet/..2025_06_23_00_16_39.254040933/ca.key, permissions: 640 kind: pod name: kube-controller-manager-7c9bc75987-cqgs4 namespace: shoot--diki-comp--aws  
                                                            containerName: kube-controller-manager details: fileName: /var/lib/kubelet/pods/c423b64c-cb58-46fa-a956-022b9b1664c6/volumes/kubernetes.io~secret/ca-kubelet/..2025_06_23_00_16_39.254040933/ca.crt, permissions: 640 kind: pod name: kube-controller-manager-7c9bc75987-cqgs4 namespace: shoot--diki-comp--aws  
                                                            containerName: kube-controller-manager details: fileName: /var/lib/kubelet/pods/c423b64c-cb58-46fa-a956-022b9b1664c6/volumes/kubernetes.io~projected/kubeconfig/..2025_06_23_00_16_39.1696466279/token, permissions: 644 kind: pod name: kube-controller-manager-7c9bc75987-cqgs4 namespace: shoot--diki-comp--aws  
                                                            containerName: kube-controller-manager details: fileName: /var/lib/kubelet/pods/c423b64c-cb58-46fa-a956-022b9b1664c6/volumes/kubernetes.io~projected/kubeconfig/..2025_06_23_00_16_39.1696466279/kubeconfig, permissions: 644 kind: pod name: kube-controller-manager-7c9bc75987-cqgs4 namespace: shoot--diki-comp--aws  
                                                            containerName: kube-scheduler details: fileName: /var/lib/kubelet/pods/06134fb6-0360-493d-adc6-38d710393b11/volumes/kubernetes.io~projected/client-ca/..2025_06_23_00_10_38.120749235/bundle.crt, permissions: 644 kind: pod name: kube-scheduler-5854d54c7c-2b7mv namespace: shoot--diki-comp--aws  
                                                            containerName: kube-scheduler details: fileName: /var/lib/kubelet/pods/06134fb6-0360-493d-adc6-38d710393b11/volumes/kubernetes.io~secret/kube-scheduler-server/..2025_06_23_00_10_38.1273189684/tls.key, permissions: 640 kind: pod name: kube-scheduler-5854d54c7c-2b7mv namespace: shoot--diki-comp--aws  
                                                            containerName: kube-scheduler details: fileName: /var/lib/kubelet/pods/06134fb6-0360-493d-adc6-38d710393b11/volumes/kubernetes.io~secret/kube-scheduler-server/..2025_06_23_00_10_38.1273189684/tls.crt, permissions: 640 kind: pod name: kube-scheduler-5854d54c7c-2b7mv namespace: shoot--diki-comp--aws  
                                                            containerName: kube-scheduler details: fileName: /var/lib/kubelet/pods/06134fb6-0360-493d-adc6-38d710393b11/volumes/kubernetes.io~configmap/kube-scheduler-config/..2025_06_23_00_10_38.2951232700/config.yaml, permissions: 644 kind: pod name: kube-scheduler-5854d54c7c-2b7mv namespace: shoot--diki-comp--aws  
                                                            containerName: kube-scheduler details: fileName: /var/lib/kubelet/pods/06134fb6-0360-493d-adc6-38d710393b11/volumes/kubernetes.io~projected/kubeconfig/..2025_06_23_00_10_38.297818258/token, permissions: 644 kind: pod name: kube-scheduler-5854d54c7c-2b7mv namespace: shoot--diki-comp--aws  
                                                            containerName: kube-scheduler details: fileName: /var/lib/kubelet/pods/06134fb6-0360-493d-adc6-38d710393b11/volumes/kubernetes.io~projected/kubeconfig/..2025_06_23_00_10_38.297818258/kubeconfig, permissions: 644 kind: pod name: kube-scheduler-5854d54c7c-2b7mv namespace: shoot--diki-comp--aws  
                                                            containerName: kube-apiserver details: fileName: /var/lib/kubelet/pods/42db629f-9d43-492e-92df-f2a0ac97d2b6/volumes/kubernetes.io~secret/ca/..2025_06_23_00_09_39.1820813547/bundle.crt, permissions: 644 kind: pod name: kube-apiserver-6d847f96d4-82qpt namespace: shoot--diki-comp--aws  
                                                            containerName: kube-apiserver details: fileName: /var/lib/kubelet/pods/42db629f-9d43-492e-92df-f2a0ac97d2b6/volumes/kubernetes.io~secret/ca-client/..2025_06_23_00_09_39.3911158577/bundle.crt, permissions: 644 kind: pod name: kube-apiserver-6d847f96d4-82qpt namespace: shoot--diki-comp--aws  
                                                            containerName: kube-apiserver details: fileName: /var/lib/kubelet/pods/42db629f-9d43-492e-92df-f2a0ac97d2b6/volumes/kubernetes.io~secret/ca-front-proxy/..2025_06_23_00_09_39.1216619138/bundle.crt, permissions: 644 kind: pod name: kube-apiserver-6d847f96d4-82qpt namespace: shoot--diki-comp--aws  
                                                            containerName: kube-apiserver details: fileName: /var/lib/kubelet/pods/42db629f-9d43-492e-92df-f2a0ac97d2b6/volumes/kubernetes.io~secret/service-account-key/..2025_06_23_00_09_39.2803718542/id_rsa, permissions: 640 kind: pod name: kube-apiserver-6d847f96d4-82qpt namespace: shoot--diki-comp--aws  
                                                            containerName: kube-apiserver details: fileName: /var/lib/kubelet/pods/42db629f-9d43-492e-92df-f2a0ac97d2b6/volumes/kubernetes.io~secret/service-account-key-bundle/..2025_06_23_00_09_39.1536096673/bundle.key, permissions: 640 kind: pod name: kube-apiserver-6d847f96d4-82qpt namespace: shoot--diki-comp--aws  
                                                            containerName: kube-apiserver details: fileName: /var/lib/kubelet/pods/42db629f-9d43-492e-92df-f2a0ac97d2b6/volumes/kubernetes.io~secret/static-token/..2025_06_23_00_09_39.3305149993/static_tokens.csv, permissions: 644 kind: pod name: kube-apiserver-6d847f96d4-82qpt namespace: shoot--diki-comp--aws  
                                                            containerName: kube-apiserver details: fileName: /var/lib/kubelet/pods/42db629f-9d43-492e-92df-f2a0ac97d2b6/volumes/kubernetes.io~secret/kube-aggregator/..2025_06_23_00_09_39.3585741192/tls.key, permissions: 640 kind: pod name: kube-apiserver-6d847f96d4-82qpt namespace: shoot--diki-comp--aws  
                                                            containerName: kube-apiserver details: fileName: /var/lib/kubelet/pods/42db629f-9d43-492e-92df-f2a0ac97d2b6/volumes/kubernetes.io~secret/kube-aggregator/..2025_06_23_00_09_39.3585741192/tls.crt, permissions: 640 kind: pod name: kube-apiserver-6d847f96d4-82qpt namespace: shoot--diki-comp--aws  
                                                            containerName: kube-apiserver details: fileName: /var/lib/kubelet/pods/42db629f-9d43-492e-92df-f2a0ac97d2b6/volumes/kubernetes.io~secret/server/..2025_06_23_00_09_39.2101876528/tls.key, permissions: 640 kind: pod name: kube-apiserver-6d847f96d4-82qpt namespace: shoot--diki-comp--aws  
                                                            containerName: kube-apiserver details: fileName: /var/lib/kubelet/pods/42db629f-9d43-492e-92df-f2a0ac97d2b6/volumes/kubernetes.io~secret/server/..2025_06_23_00_09_39.2101876528/tls.crt, permissions: 640 kind: pod name: kube-apiserver-6d847f96d4-82qpt namespace: shoot--diki-comp--aws  
                                                            containerName: kube-apiserver details: fileName: /var/lib/kubelet/pods/42db629f-9d43-492e-92df-f2a0ac97d2b6/volumes/kubernetes.io~configmap/audit-policy-config/..2025_06_23_00_09_39.2329166342/audit-policy.yaml, permissions: 644 kind: pod name: kube-apiserver-6d847f96d4-82qpt namespace: shoot--diki-comp--aws  
                                                            containerName: kube-apiserver details: fileName: /var/lib/kubelet/pods/42db629f-9d43-492e-92df-f2a0ac97d2b6/volumes/kubernetes.io~configmap/admission-config/..2025_06_23_00_09_39.1330272162/podsecurity.yaml, permissions: 644 kind: pod name: kube-apiserver-6d847f96d4-82qpt namespace: shoot--diki-comp--aws  
                                                            containerName: kube-apiserver details: fileName: /var/lib/kubelet/pods/42db629f-9d43-492e-92df-f2a0ac97d2b6/volumes/kubernetes.io~configmap/admission-config/..2025_06_23_00_09_39.1330272162/admission-configuration.yaml, permissions: 644 kind: pod name: kube-apiserver-6d847f96d4-82qpt namespace: shoot--diki-comp--aws  
                                                            containerName: kube-apiserver details: fileName: /var/lib/kubelet/pods/42db629f-9d43-492e-92df-f2a0ac97d2b6/volumes/kubernetes.io~secret/etcd-encryption-secret/..2025_06_23_00_09_39.2708327898/encryption-configuration.yaml, permissions: 640 kind: pod name: kube-apiserver-6d847f96d4-82qpt namespace: shoot--diki-comp--aws  
                                                            containerName: kube-apiserver details: fileName: /var/lib/kubelet/pods/42db629f-9d43-492e-92df-f2a0ac97d2b6/volumes/kubernetes.io~secret/ca-vpn/..2025_06_23_00_09_39.1345136145/bundle.crt, permissions: 644 kind: pod name: kube-apiserver-6d847f96d4-82qpt namespace: shoot--diki-comp--aws  
                                                            containerName: kube-apiserver details: fileName: /var/lib/kubelet/pods/42db629f-9d43-492e-92df-f2a0ac97d2b6/volumes/kubernetes.io~configmap/egress-selection-config/..2025_06_23_00_09_39.2143964349/egress-selector-configuration.yaml, permissions: 644 kind: pod name: kube-apiserver-6d847f96d4-82qpt namespace: shoot--diki-comp--aws  
                                                            containerName: kube-apiserver details: fileName: /var/lib/kubelet/pods/42db629f-9d43-492e-92df-f2a0ac97d2b6/volumes/kubernetes.io~secret/ca-kubelet/..2025_06_23_00_09_39.2968989444/bundle.crt, permissions: 644 kind: pod name: kube-apiserver-6d847f96d4-82qpt namespace: shoot--diki-comp--aws  
                                                            containerName: kube-apiserver details: fileName: /var/lib/kubelet/pods/42db629f-9d43-492e-92df-f2a0ac97d2b6/volumes/kubernetes.io~secret/kubelet-client/..2025_06_23_00_09_39.2120918226/tls.key, permissions: 640 kind: pod name: kube-apiserver-6d847f96d4-82qpt namespace: shoot--diki-comp--aws  
                                                            containerName: kube-apiserver details: fileName: /var/lib/kubelet/pods/42db629f-9d43-492e-92df-f2a0ac97d2b6/volumes/kubernetes.io~secret/kubelet-client/..2025_06_23_00_09_39.2120918226/tls.crt, permissions: 640 kind: pod name: kube-apiserver-6d847f96d4-82qpt namespace: shoot--diki-comp--aws  
                                                            containerName: kube-apiserver details: fileName: /var/lib/kubelet/pods/42db629f-9d43-492e-92df-f2a0ac97d2b6/volumes/kubernetes.io~secret/ca-etcd/..2025_06_23_00_09_39.86038190/bundle.crt, permissions: 644 kind: pod name: kube-apiserver-6d847f96d4-82qpt namespace: shoot--diki-comp--aws  
                                                            containerName: kube-apiserver details: fileName: /var/lib/kubelet/pods/42db629f-9d43-492e-92df-f2a0ac97d2b6/volumes/kubernetes.io~secret/etcd-client/..2025_06_23_00_09_39.3841361014/tls.crt, permissions: 640 kind: pod name: kube-apiserver-6d847f96d4-82qpt namespace: shoot--diki-comp--aws  
                                                            containerName: kube-apiserver details: fileName: /var/lib/kubelet/pods/42db629f-9d43-492e-92df-f2a0ac97d2b6/volumes/kubernetes.io~secret/etcd-client/..2025_06_23_00_09_39.3841361014/tls.key, permissions: 640 kind: pod name: kube-apiserver-6d847f96d4-82qpt namespace: shoot--diki-comp--aws  
                                                            containerName: kube-apiserver details: fileName: /var/lib/kubelet/pods/42db629f-9d43-492e-92df-f2a0ac97d2b6/volumes/kubernetes.io~secret/tls-sni-0/..2025_06_23_00_09_39.1534744055/tls.key, permissions: 640 kind: pod name: kube-apiserver-6d847f96d4-82qpt namespace: shoot--diki-comp--aws  
                                                            containerName: kube-apiserver details: fileName: /var/lib/kubelet/pods/42db629f-9d43-492e-92df-f2a0ac97d2b6/volumes/kubernetes.io~secret/tls-sni-0/..2025_06_23_00_09_39.1534744055/tls.crt, permissions: 640 kind: pod name: kube-apiserver-6d847f96d4-82qpt namespace: shoot--diki-comp--aws  
                                                            containerName: kube-apiserver details: fileName: /var/lib/kubelet/pods/42db629f-9d43-492e-92df-f2a0ac97d2b6/volumes/kubernetes.io~secret/tls-sni-0/..2025_06_23_00_09_39.1534744055/ca.crt, permissions: 640 kind: pod name: kube-apiserver-6d847f96d4-82qpt namespace: shoot--diki-comp--aws  
                                                            containerName: kube-apiserver details: fileName: /var/lib/kubelet/pods/42db629f-9d43-492e-92df-f2a0ac97d2b6/volumes/kubernetes.io~configmap/authorization-config/..2025_06_23_00_09_39.233957482/config.yaml, permissions: 644 kind: pod name: kube-apiserver-6d847f96d4-82qpt namespace: shoot--diki-comp--aws  
                                                            containerName: kube-apiserver details: fileName: /var/lib/kubelet/pods/42db629f-9d43-492e-92df-f2a0ac97d2b6/volumes/kubernetes.io~secret/authorization-kubeconfigs/..2025_06_23_00_09_39.3354464403/node-agent-authorizer-kubeconfig.yaml, permissions: 644 kind: pod name: kube-apiserver-6d847f96d4-82qpt namespace: shoot--diki-comp--aws  
                                                            containerName: kube-apiserver details: fileName: /var/lib/kubelet/pods/42db629f-9d43-492e-92df-f2a0ac97d2b6/volumes/kubernetes.io~secret/http-proxy/..2025_06_23_00_09_39.1635279459/tls.key, permissions: 640 kind: pod name: kube-apiserver-6d847f96d4-82qpt namespace: shoot--diki-comp--aws  
                                                            containerName: kube-apiserver details: fileName: /var/lib/kubelet/pods/42db629f-9d43-492e-92df-f2a0ac97d2b6/volumes/kubernetes.io~secret/http-proxy/..2025_06_23_00_09_39.1635279459/tls.crt, permissions: 640 kind: pod name: kube-apiserver-6d847f96d4-82qpt namespace: shoot--diki-comp--aws  
                                                         
                                                     
                                                    
                                                        azure 
                                                        
                                                            containerName: kube-apiserver details: fileName: /var/lib/kubelet/pods/19e8d0fb-e648-458d-9824-7002ba098bce/volumes/kubernetes.io~secret/ca/..2025_06_23_00_14_46.3142548715/bundle.crt, permissions: 644 kind: pod name: kube-apiserver-d66f4d44f-tm4cs namespace: shoot--diki-comp--azure  
                                                            containerName: kube-apiserver details: fileName: /var/lib/kubelet/pods/19e8d0fb-e648-458d-9824-7002ba098bce/volumes/kubernetes.io~secret/ca-client/..2025_06_23_00_14_46.1427032518/bundle.crt, permissions: 644 kind: pod name: kube-apiserver-d66f4d44f-tm4cs namespace: shoot--diki-comp--azure  
                                                            containerName: kube-apiserver details: fileName: /var/lib/kubelet/pods/19e8d0fb-e648-458d-9824-7002ba098bce/volumes/kubernetes.io~secret/ca-front-proxy/..2025_06_23_00_14_46.1493427643/bundle.crt, permissions: 644 kind: pod name: kube-apiserver-d66f4d44f-tm4cs namespace: shoot--diki-comp--azure  
                                                            containerName: kube-apiserver details: fileName: /var/lib/kubelet/pods/19e8d0fb-e648-458d-9824-7002ba098bce/volumes/kubernetes.io~secret/service-account-key/..2025_06_23_00_14_46.325050636/id_rsa, permissions: 640 kind: pod name: kube-apiserver-d66f4d44f-tm4cs namespace: shoot--diki-comp--azure  
                                                            containerName: kube-apiserver details: fileName: /var/lib/kubelet/pods/19e8d0fb-e648-458d-9824-7002ba098bce/volumes/kubernetes.io~secret/service-account-key-bundle/..2025_06_23_00_14_46.504056214/bundle.key, permissions: 640 kind: pod name: kube-apiserver-d66f4d44f-tm4cs namespace: shoot--diki-comp--azure  
                                                            containerName: kube-apiserver details: fileName: /var/lib/kubelet/pods/19e8d0fb-e648-458d-9824-7002ba098bce/volumes/kubernetes.io~secret/static-token/..2025_06_23_00_14_46.4214259902/static_tokens.csv, permissions: 644 kind: pod name: kube-apiserver-d66f4d44f-tm4cs namespace: shoot--diki-comp--azure  
                                                            containerName: kube-apiserver details: fileName: /var/lib/kubelet/pods/19e8d0fb-e648-458d-9824-7002ba098bce/volumes/kubernetes.io~secret/kube-aggregator/..2025_06_23_00_14_46.2139614939/tls.key, permissions: 640 kind: pod name: kube-apiserver-d66f4d44f-tm4cs namespace: shoot--diki-comp--azure  
                                                            containerName: kube-apiserver details: fileName: /var/lib/kubelet/pods/19e8d0fb-e648-458d-9824-7002ba098bce/volumes/kubernetes.io~secret/kube-aggregator/..2025_06_23_00_14_46.2139614939/tls.crt, permissions: 640 kind: pod name: kube-apiserver-d66f4d44f-tm4cs namespace: shoot--diki-comp--azure  
                                                            containerName: kube-apiserver details: fileName: /var/lib/kubelet/pods/19e8d0fb-e648-458d-9824-7002ba098bce/volumes/kubernetes.io~secret/server/..2025_06_23_00_14_46.2186093174/tls.key, permissions: 640 kind: pod name: kube-apiserver-d66f4d44f-tm4cs namespace: shoot--diki-comp--azure  
                                                            containerName: kube-apiserver details: fileName: /var/lib/kubelet/pods/19e8d0fb-e648-458d-9824-7002ba098bce/volumes/kubernetes.io~secret/server/..2025_06_23_00_14_46.2186093174/tls.crt, permissions: 640 kind: pod name: kube-apiserver-d66f4d44f-tm4cs namespace: shoot--diki-comp--azure  
                                                            containerName: kube-apiserver details: fileName: /var/lib/kubelet/pods/19e8d0fb-e648-458d-9824-7002ba098bce/volumes/kubernetes.io~configmap/audit-policy-config/..2025_06_23_00_14_46.1584132699/audit-policy.yaml, permissions: 644 kind: pod name: kube-apiserver-d66f4d44f-tm4cs namespace: shoot--diki-comp--azure  
                                                            containerName: kube-apiserver details: fileName: /var/lib/kubelet/pods/19e8d0fb-e648-458d-9824-7002ba098bce/volumes/kubernetes.io~configmap/admission-config/..2025_06_23_00_14_46.4294471397/podsecurity.yaml, permissions: 644 kind: pod name: kube-apiserver-d66f4d44f-tm4cs namespace: shoot--diki-comp--azure  
                                                            containerName: kube-apiserver details: fileName: /var/lib/kubelet/pods/19e8d0fb-e648-458d-9824-7002ba098bce/volumes/kubernetes.io~configmap/admission-config/..2025_06_23_00_14_46.4294471397/admission-configuration.yaml, permissions: 644 kind: pod name: kube-apiserver-d66f4d44f-tm4cs namespace: shoot--diki-comp--azure  
                                                            containerName: kube-apiserver details: fileName: /var/lib/kubelet/pods/19e8d0fb-e648-458d-9824-7002ba098bce/volumes/kubernetes.io~secret/etcd-encryption-secret/..2025_06_23_00_14_46.439791232/encryption-configuration.yaml, permissions: 640 kind: pod name: kube-apiserver-d66f4d44f-tm4cs namespace: shoot--diki-comp--azure  
                                                            containerName: kube-apiserver details: fileName: /var/lib/kubelet/pods/19e8d0fb-e648-458d-9824-7002ba098bce/volumes/kubernetes.io~secret/ca-vpn/..2025_06_23_00_14_46.3412290611/bundle.crt, permissions: 644 kind: pod name: kube-apiserver-d66f4d44f-tm4cs namespace: shoot--diki-comp--azure  
                                                            containerName: kube-apiserver details: fileName: /var/lib/kubelet/pods/19e8d0fb-e648-458d-9824-7002ba098bce/volumes/kubernetes.io~configmap/egress-selection-config/..2025_06_23_00_14_46.4108663986/egress-selector-configuration.yaml, permissions: 644 kind: pod name: kube-apiserver-d66f4d44f-tm4cs namespace: shoot--diki-comp--azure  
                                                            containerName: kube-apiserver details: fileName: /var/lib/kubelet/pods/19e8d0fb-e648-458d-9824-7002ba098bce/volumes/kubernetes.io~secret/ca-kubelet/..2025_06_23_00_14_46.3112199018/bundle.crt, permissions: 644 kind: pod name: kube-apiserver-d66f4d44f-tm4cs namespace: shoot--diki-comp--azure  
                                                            containerName: kube-apiserver details: fileName: /var/lib/kubelet/pods/19e8d0fb-e648-458d-9824-7002ba098bce/volumes/kubernetes.io~secret/kubelet-client/..2025_06_23_00_14_46.2446316166/tls.crt, permissions: 640 kind: pod name: kube-apiserver-d66f4d44f-tm4cs namespace: shoot--diki-comp--azure  
                                                            containerName: kube-apiserver details: fileName: /var/lib/kubelet/pods/19e8d0fb-e648-458d-9824-7002ba098bce/volumes/kubernetes.io~secret/kubelet-client/..2025_06_23_00_14_46.2446316166/tls.key, permissions: 640 kind: pod name: kube-apiserver-d66f4d44f-tm4cs namespace: shoot--diki-comp--azure  
                                                            containerName: kube-apiserver details: fileName: /var/lib/kubelet/pods/19e8d0fb-e648-458d-9824-7002ba098bce/volumes/kubernetes.io~secret/ca-etcd/..2025_06_23_00_14_46.3219727173/bundle.crt, permissions: 644 kind: pod name: kube-apiserver-d66f4d44f-tm4cs namespace: shoot--diki-comp--azure  
                                                            containerName: kube-apiserver details: fileName: /var/lib/kubelet/pods/19e8d0fb-e648-458d-9824-7002ba098bce/volumes/kubernetes.io~secret/etcd-client/..2025_06_23_00_14_46.1466414181/tls.key, permissions: 640 kind: pod name: kube-apiserver-d66f4d44f-tm4cs namespace: shoot--diki-comp--azure  
                                                            containerName: kube-apiserver details: fileName: /var/lib/kubelet/pods/19e8d0fb-e648-458d-9824-7002ba098bce/volumes/kubernetes.io~secret/etcd-client/..2025_06_23_00_14_46.1466414181/tls.crt, permissions: 640 kind: pod name: kube-apiserver-d66f4d44f-tm4cs namespace: shoot--diki-comp--azure  
                                                            containerName: kube-apiserver details: fileName: /var/lib/kubelet/pods/19e8d0fb-e648-458d-9824-7002ba098bce/volumes/kubernetes.io~secret/tls-sni-0/..2025_06_23_00_14_46.1021198322/tls.key, permissions: 640 kind: pod name: kube-apiserver-d66f4d44f-tm4cs namespace: shoot--diki-comp--azure  
                                                            containerName: kube-apiserver details: fileName: /var/lib/kubelet/pods/19e8d0fb-e648-458d-9824-7002ba098bce/volumes/kubernetes.io~secret/tls-sni-0/..2025_06_23_00_14_46.1021198322/tls.crt, permissions: 640 kind: pod name: kube-apiserver-d66f4d44f-tm4cs namespace: shoot--diki-comp--azure  
                                                            containerName: kube-apiserver details: fileName: /var/lib/kubelet/pods/19e8d0fb-e648-458d-9824-7002ba098bce/volumes/kubernetes.io~secret/tls-sni-0/..2025_06_23_00_14_46.1021198322/ca.crt, permissions: 640 kind: pod name: kube-apiserver-d66f4d44f-tm4cs namespace: shoot--diki-comp--azure  
                                                            containerName: kube-apiserver details: fileName: /var/lib/kubelet/pods/19e8d0fb-e648-458d-9824-7002ba098bce/volumes/kubernetes.io~configmap/authorization-config/..2025_06_23_00_14_46.2637053043/config.yaml, permissions: 644 kind: pod name: kube-apiserver-d66f4d44f-tm4cs namespace: shoot--diki-comp--azure  
                                                            containerName: kube-apiserver details: fileName: /var/lib/kubelet/pods/19e8d0fb-e648-458d-9824-7002ba098bce/volumes/kubernetes.io~secret/authorization-kubeconfigs/..2025_06_23_00_14_46.2011429030/node-agent-authorizer-kubeconfig.yaml, permissions: 644 kind: pod name: kube-apiserver-d66f4d44f-tm4cs namespace: shoot--diki-comp--azure  
                                                            containerName: kube-apiserver details: fileName: /var/lib/kubelet/pods/19e8d0fb-e648-458d-9824-7002ba098bce/volumes/kubernetes.io~secret/http-proxy/..2025_06_23_00_14_46.234968055/tls.key, permissions: 640 kind: pod name: kube-apiserver-d66f4d44f-tm4cs namespace: shoot--diki-comp--azure  
                                                            containerName: kube-apiserver details: fileName: /var/lib/kubelet/pods/19e8d0fb-e648-458d-9824-7002ba098bce/volumes/kubernetes.io~secret/http-proxy/..2025_06_23_00_14_46.234968055/tls.crt, permissions: 640 kind: pod name: kube-apiserver-d66f4d44f-tm4cs namespace: shoot--diki-comp--azure  
                                                            containerName: kube-controller-manager details: fileName: /var/lib/kubelet/pods/8a5510fe-a88b-42cc-b90a-1d8f9487d887/volumes/kubernetes.io~secret/ca/..2025_06_23_00_19_46.2289618773/bundle.crt, permissions: 644 kind: pod name: kube-controller-manager-7d869c84b8-kz7dm namespace: shoot--diki-comp--azure  
                                                            containerName: kube-controller-manager details: fileName: /var/lib/kubelet/pods/8a5510fe-a88b-42cc-b90a-1d8f9487d887/volumes/kubernetes.io~secret/ca-client/..2025_06_23_00_19_46.1556017874/ca.crt, permissions: 640 kind: pod name: kube-controller-manager-7d869c84b8-kz7dm namespace: shoot--diki-comp--azure  
                                                            containerName: kube-controller-manager details: fileName: /var/lib/kubelet/pods/8a5510fe-a88b-42cc-b90a-1d8f9487d887/volumes/kubernetes.io~secret/ca-client/..2025_06_23_00_19_46.1556017874/ca.key, permissions: 640 kind: pod name: kube-controller-manager-7d869c84b8-kz7dm namespace: shoot--diki-comp--azure  
                                                            containerName: kube-controller-manager details: fileName: /var/lib/kubelet/pods/8a5510fe-a88b-42cc-b90a-1d8f9487d887/volumes/kubernetes.io~secret/service-account-key/..2025_06_23_00_19_46.2680073418/id_rsa, permissions: 640 kind: pod name: kube-controller-manager-7d869c84b8-kz7dm namespace: shoot--diki-comp--azure  
                                                            containerName: kube-controller-manager details: fileName: /var/lib/kubelet/pods/8a5510fe-a88b-42cc-b90a-1d8f9487d887/volumes/kubernetes.io~secret/server/..2025_06_23_00_19_46.3137963724/tls.key, permissions: 640 kind: pod name: kube-controller-manager-7d869c84b8-kz7dm namespace: shoot--diki-comp--azure  
                                                            containerName: kube-controller-manager details: fileName: /var/lib/kubelet/pods/8a5510fe-a88b-42cc-b90a-1d8f9487d887/volumes/kubernetes.io~secret/server/..2025_06_23_00_19_46.3137963724/tls.crt, permissions: 640 kind: pod name: kube-controller-manager-7d869c84b8-kz7dm namespace: shoot--diki-comp--azure  
                                                            containerName: kube-controller-manager details: fileName: /var/lib/kubelet/pods/8a5510fe-a88b-42cc-b90a-1d8f9487d887/volumes/kubernetes.io~secret/ca-kubelet/..2025_06_23_00_19_46.2139875717/ca.crt, permissions: 640 kind: pod name: kube-controller-manager-7d869c84b8-kz7dm namespace: shoot--diki-comp--azure  
                                                            containerName: kube-controller-manager details: fileName: /var/lib/kubelet/pods/8a5510fe-a88b-42cc-b90a-1d8f9487d887/volumes/kubernetes.io~secret/ca-kubelet/..2025_06_23_00_19_46.2139875717/ca.key, permissions: 640 kind: pod name: kube-controller-manager-7d869c84b8-kz7dm namespace: shoot--diki-comp--azure  
                                                            containerName: kube-controller-manager details: fileName: /var/lib/kubelet/pods/8a5510fe-a88b-42cc-b90a-1d8f9487d887/volumes/kubernetes.io~projected/kubeconfig/..2025_06_23_00_19_46.3968766951/token, permissions: 644 kind: pod name: kube-controller-manager-7d869c84b8-kz7dm namespace: shoot--diki-comp--azure  
                                                            containerName: kube-controller-manager details: fileName: /var/lib/kubelet/pods/8a5510fe-a88b-42cc-b90a-1d8f9487d887/volumes/kubernetes.io~projected/kubeconfig/..2025_06_23_00_19_46.3968766951/kubeconfig, permissions: 644 kind: pod name: kube-controller-manager-7d869c84b8-kz7dm namespace: shoot--diki-comp--azure  
                                                            containerName: kube-scheduler details: fileName: /var/lib/kubelet/pods/8afdd891-92eb-4c6a-aac5-9a324987f6ad/volumes/kubernetes.io~projected/client-ca/..2025_06_23_00_14_46.3397349168/bundle.crt, permissions: 644 kind: pod name: kube-scheduler-67fdbc4569-h6j7v namespace: shoot--diki-comp--azure  
                                                            containerName: kube-scheduler details: fileName: /var/lib/kubelet/pods/8afdd891-92eb-4c6a-aac5-9a324987f6ad/volumes/kubernetes.io~secret/kube-scheduler-server/..2025_06_23_00_14_46.366944806/tls.key, permissions: 640 kind: pod name: kube-scheduler-67fdbc4569-h6j7v namespace: shoot--diki-comp--azure  
                                                            containerName: kube-scheduler details: fileName: /var/lib/kubelet/pods/8afdd891-92eb-4c6a-aac5-9a324987f6ad/volumes/kubernetes.io~secret/kube-scheduler-server/..2025_06_23_00_14_46.366944806/tls.crt, permissions: 640 kind: pod name: kube-scheduler-67fdbc4569-h6j7v namespace: shoot--diki-comp--azure  
                                                            containerName: kube-scheduler details: fileName: /var/lib/kubelet/pods/8afdd891-92eb-4c6a-aac5-9a324987f6ad/volumes/kubernetes.io~configmap/kube-scheduler-config/..2025_06_23_00_14_46.962074830/config.yaml, permissions: 644 kind: pod name: kube-scheduler-67fdbc4569-h6j7v namespace: shoot--diki-comp--azure  
                                                            containerName: kube-scheduler details: fileName: /var/lib/kubelet/pods/8afdd891-92eb-4c6a-aac5-9a324987f6ad/volumes/kubernetes.io~projected/kubeconfig/..2025_06_23_00_14_46.877888443/token, permissions: 644 kind: pod name: kube-scheduler-67fdbc4569-h6j7v namespace: shoot--diki-comp--azure  
                                                            containerName: kube-scheduler details: fileName: /var/lib/kubelet/pods/8afdd891-92eb-4c6a-aac5-9a324987f6ad/volumes/kubernetes.io~projected/kubeconfig/..2025_06_23_00_14_46.877888443/kubeconfig, permissions: 644 kind: pod name: kube-scheduler-67fdbc4569-h6j7v namespace: shoot--diki-comp--azure  
                                                         
                                                     
                                                    
                                                        gcp 
                                                        
                                                            containerName: kube-apiserver details: fileName: /var/lib/kubelet/pods/bcae6617-9cf5-48c4-a654-323e2fd06c94/volumes/kubernetes.io~secret/ca/..2025_06_23_00_05_00.1635859179/bundle.crt, permissions: 644 kind: pod name: kube-apiserver-789b87d9bc-m288k namespace: shoot--diki-comp--gcp  
                                                            containerName: kube-apiserver details: fileName: /var/lib/kubelet/pods/bcae6617-9cf5-48c4-a654-323e2fd06c94/volumes/kubernetes.io~secret/ca-client/..2025_06_23_00_05_00.3123507849/bundle.crt, permissions: 644 kind: pod name: kube-apiserver-789b87d9bc-m288k namespace: shoot--diki-comp--gcp  
                                                            containerName: kube-apiserver details: fileName: /var/lib/kubelet/pods/bcae6617-9cf5-48c4-a654-323e2fd06c94/volumes/kubernetes.io~secret/ca-front-proxy/..2025_06_23_00_05_00.3311897769/bundle.crt, permissions: 644 kind: pod name: kube-apiserver-789b87d9bc-m288k namespace: shoot--diki-comp--gcp  
                                                            containerName: kube-apiserver details: fileName: /var/lib/kubelet/pods/bcae6617-9cf5-48c4-a654-323e2fd06c94/volumes/kubernetes.io~secret/service-account-key/..2025_06_23_00_05_00.213839922/id_rsa, permissions: 640 kind: pod name: kube-apiserver-789b87d9bc-m288k namespace: shoot--diki-comp--gcp  
                                                            containerName: kube-apiserver details: fileName: /var/lib/kubelet/pods/bcae6617-9cf5-48c4-a654-323e2fd06c94/volumes/kubernetes.io~secret/service-account-key-bundle/..2025_06_23_00_05_00.527676273/bundle.key, permissions: 640 kind: pod name: kube-apiserver-789b87d9bc-m288k namespace: shoot--diki-comp--gcp  
                                                            containerName: kube-apiserver details: fileName: /var/lib/kubelet/pods/bcae6617-9cf5-48c4-a654-323e2fd06c94/volumes/kubernetes.io~secret/static-token/..2025_06_23_00_05_00.3972387062/static_tokens.csv, permissions: 644 kind: pod name: kube-apiserver-789b87d9bc-m288k namespace: shoot--diki-comp--gcp  
                                                            containerName: kube-apiserver details: fileName: /var/lib/kubelet/pods/bcae6617-9cf5-48c4-a654-323e2fd06c94/volumes/kubernetes.io~secret/kube-aggregator/..2025_06_23_00_05_00.8440286/tls.crt, permissions: 640 kind: pod name: kube-apiserver-789b87d9bc-m288k namespace: shoot--diki-comp--gcp  
                                                            containerName: kube-apiserver details: fileName: /var/lib/kubelet/pods/bcae6617-9cf5-48c4-a654-323e2fd06c94/volumes/kubernetes.io~secret/kube-aggregator/..2025_06_23_00_05_00.8440286/tls.key, permissions: 640 kind: pod name: kube-apiserver-789b87d9bc-m288k namespace: shoot--diki-comp--gcp  
                                                            containerName: kube-apiserver details: fileName: /var/lib/kubelet/pods/bcae6617-9cf5-48c4-a654-323e2fd06c94/volumes/kubernetes.io~secret/server/..2025_06_23_00_05_00.2211691282/tls.key, permissions: 640 kind: pod name: kube-apiserver-789b87d9bc-m288k namespace: shoot--diki-comp--gcp  
                                                            containerName: kube-apiserver details: fileName: /var/lib/kubelet/pods/bcae6617-9cf5-48c4-a654-323e2fd06c94/volumes/kubernetes.io~secret/server/..2025_06_23_00_05_00.2211691282/tls.crt, permissions: 640 kind: pod name: kube-apiserver-789b87d9bc-m288k namespace: shoot--diki-comp--gcp  
                                                            containerName: kube-apiserver details: fileName: /var/lib/kubelet/pods/bcae6617-9cf5-48c4-a654-323e2fd06c94/volumes/kubernetes.io~configmap/audit-policy-config/..2025_06_23_00_05_00.518575439/audit-policy.yaml, permissions: 644 kind: pod name: kube-apiserver-789b87d9bc-m288k namespace: shoot--diki-comp--gcp  
                                                            containerName: kube-apiserver details: fileName: /var/lib/kubelet/pods/bcae6617-9cf5-48c4-a654-323e2fd06c94/volumes/kubernetes.io~configmap/admission-config/..2025_06_23_00_05_00.2157622198/podsecurity.yaml, permissions: 644 kind: pod name: kube-apiserver-789b87d9bc-m288k namespace: shoot--diki-comp--gcp  
                                                            containerName: kube-apiserver details: fileName: /var/lib/kubelet/pods/bcae6617-9cf5-48c4-a654-323e2fd06c94/volumes/kubernetes.io~configmap/admission-config/..2025_06_23_00_05_00.2157622198/admission-configuration.yaml, permissions: 644 kind: pod name: kube-apiserver-789b87d9bc-m288k namespace: shoot--diki-comp--gcp  
                                                            containerName: kube-apiserver details: fileName: /var/lib/kubelet/pods/bcae6617-9cf5-48c4-a654-323e2fd06c94/volumes/kubernetes.io~secret/etcd-encryption-secret/..2025_06_23_00_05_00.1089428079/encryption-configuration.yaml, permissions: 640 kind: pod name: kube-apiserver-789b87d9bc-m288k namespace: shoot--diki-comp--gcp  
                                                            containerName: kube-apiserver details: fileName: /var/lib/kubelet/pods/bcae6617-9cf5-48c4-a654-323e2fd06c94/volumes/kubernetes.io~secret/ca-vpn/..2025_06_23_00_05_00.3200529218/bundle.crt, permissions: 644 kind: pod name: kube-apiserver-789b87d9bc-m288k namespace: shoot--diki-comp--gcp  
                                                            containerName: kube-apiserver details: fileName: /var/lib/kubelet/pods/bcae6617-9cf5-48c4-a654-323e2fd06c94/volumes/kubernetes.io~configmap/egress-selection-config/..2025_06_23_00_05_00.1397569347/egress-selector-configuration.yaml, permissions: 644 kind: pod name: kube-apiserver-789b87d9bc-m288k namespace: shoot--diki-comp--gcp  
                                                            containerName: kube-apiserver details: fileName: /var/lib/kubelet/pods/bcae6617-9cf5-48c4-a654-323e2fd06c94/volumes/kubernetes.io~secret/ca-kubelet/..2025_06_23_00_05_00.1340282604/bundle.crt, permissions: 644 kind: pod name: kube-apiserver-789b87d9bc-m288k namespace: shoot--diki-comp--gcp  
                                                            containerName: kube-apiserver details: fileName: /var/lib/kubelet/pods/bcae6617-9cf5-48c4-a654-323e2fd06c94/volumes/kubernetes.io~secret/kubelet-client/..2025_06_23_00_05_00.3066470044/tls.crt, permissions: 640 kind: pod name: kube-apiserver-789b87d9bc-m288k namespace: shoot--diki-comp--gcp  
                                                            containerName: kube-apiserver details: fileName: /var/lib/kubelet/pods/bcae6617-9cf5-48c4-a654-323e2fd06c94/volumes/kubernetes.io~secret/kubelet-client/..2025_06_23_00_05_00.3066470044/tls.key, permissions: 640 kind: pod name: kube-apiserver-789b87d9bc-m288k namespace: shoot--diki-comp--gcp  
                                                            containerName: kube-apiserver details: fileName: /var/lib/kubelet/pods/bcae6617-9cf5-48c4-a654-323e2fd06c94/volumes/kubernetes.io~secret/ca-etcd/..2025_06_23_00_05_00.599344253/bundle.crt, permissions: 644 kind: pod name: kube-apiserver-789b87d9bc-m288k namespace: shoot--diki-comp--gcp  
                                                            containerName: kube-apiserver details: fileName: /var/lib/kubelet/pods/bcae6617-9cf5-48c4-a654-323e2fd06c94/volumes/kubernetes.io~secret/etcd-client/..2025_06_23_00_05_00.3665142686/tls.key, permissions: 640 kind: pod name: kube-apiserver-789b87d9bc-m288k namespace: shoot--diki-comp--gcp  
                                                            containerName: kube-apiserver details: fileName: /var/lib/kubelet/pods/bcae6617-9cf5-48c4-a654-323e2fd06c94/volumes/kubernetes.io~secret/etcd-client/..2025_06_23_00_05_00.3665142686/tls.crt, permissions: 640 kind: pod name: kube-apiserver-789b87d9bc-m288k namespace: shoot--diki-comp--gcp  
                                                            containerName: kube-apiserver details: fileName: /var/lib/kubelet/pods/bcae6617-9cf5-48c4-a654-323e2fd06c94/volumes/kubernetes.io~secret/tls-sni-0/..2025_06_23_00_05_00.1355552674/tls.key, permissions: 640 kind: pod name: kube-apiserver-789b87d9bc-m288k namespace: shoot--diki-comp--gcp  
                                                            containerName: kube-apiserver details: fileName: /var/lib/kubelet/pods/bcae6617-9cf5-48c4-a654-323e2fd06c94/volumes/kubernetes.io~secret/tls-sni-0/..2025_06_23_00_05_00.1355552674/tls.crt, permissions: 640 kind: pod name: kube-apiserver-789b87d9bc-m288k namespace: shoot--diki-comp--gcp  
                                                            containerName: kube-apiserver details: fileName: /var/lib/kubelet/pods/bcae6617-9cf5-48c4-a654-323e2fd06c94/volumes/kubernetes.io~secret/tls-sni-0/..2025_06_23_00_05_00.1355552674/ca.crt, permissions: 640 kind: pod name: kube-apiserver-789b87d9bc-m288k namespace: shoot--diki-comp--gcp  
                                                            containerName: kube-apiserver details: fileName: /var/lib/kubelet/pods/bcae6617-9cf5-48c4-a654-323e2fd06c94/volumes/kubernetes.io~configmap/authorization-config/..2025_06_23_00_05_00.165428170/config.yaml, permissions: 644 kind: pod name: kube-apiserver-789b87d9bc-m288k namespace: shoot--diki-comp--gcp  
                                                            containerName: kube-apiserver details: fileName: /var/lib/kubelet/pods/bcae6617-9cf5-48c4-a654-323e2fd06c94/volumes/kubernetes.io~secret/authorization-kubeconfigs/..2025_06_23_00_05_00.985374819/node-agent-authorizer-kubeconfig.yaml, permissions: 644 kind: pod name: kube-apiserver-789b87d9bc-m288k namespace: shoot--diki-comp--gcp  
                                                            containerName: kube-apiserver details: fileName: /var/lib/kubelet/pods/bcae6617-9cf5-48c4-a654-323e2fd06c94/volumes/kubernetes.io~secret/http-proxy/..2025_06_23_00_05_00.2267541296/tls.key, permissions: 640 kind: pod name: kube-apiserver-789b87d9bc-m288k namespace: shoot--diki-comp--gcp  
                                                            containerName: kube-apiserver details: fileName: /var/lib/kubelet/pods/bcae6617-9cf5-48c4-a654-323e2fd06c94/volumes/kubernetes.io~secret/http-proxy/..2025_06_23_00_05_00.2267541296/tls.crt, permissions: 640 kind: pod name: kube-apiserver-789b87d9bc-m288k namespace: shoot--diki-comp--gcp  
                                                            containerName: kube-controller-manager details: fileName: /var/lib/kubelet/pods/7207bfe7-1315-42f2-8383-7b79afa8437d/volumes/kubernetes.io~secret/ca/..2025_06_23_00_10_41.4029468750/bundle.crt, permissions: 644 kind: pod name: kube-controller-manager-65cdccf875-lhhzw namespace: shoot--diki-comp--gcp  
                                                            containerName: kube-controller-manager details: fileName: /var/lib/kubelet/pods/7207bfe7-1315-42f2-8383-7b79afa8437d/volumes/kubernetes.io~secret/ca-client/..2025_06_23_00_10_41.2990537503/ca.crt, permissions: 640 kind: pod name: kube-controller-manager-65cdccf875-lhhzw namespace: shoot--diki-comp--gcp  
                                                            containerName: kube-controller-manager details: fileName: /var/lib/kubelet/pods/7207bfe7-1315-42f2-8383-7b79afa8437d/volumes/kubernetes.io~secret/ca-client/..2025_06_23_00_10_41.2990537503/ca.key, permissions: 640 kind: pod name: kube-controller-manager-65cdccf875-lhhzw namespace: shoot--diki-comp--gcp  
                                                            containerName: kube-controller-manager details: fileName: /var/lib/kubelet/pods/7207bfe7-1315-42f2-8383-7b79afa8437d/volumes/kubernetes.io~secret/service-account-key/..2025_06_23_00_10_41.2563485830/id_rsa, permissions: 640 kind: pod name: kube-controller-manager-65cdccf875-lhhzw namespace: shoot--diki-comp--gcp  
                                                            containerName: kube-controller-manager details: fileName: /var/lib/kubelet/pods/7207bfe7-1315-42f2-8383-7b79afa8437d/volumes/kubernetes.io~secret/server/..2025_06_23_00_10_41.2206626934/tls.crt, permissions: 640 kind: pod name: kube-controller-manager-65cdccf875-lhhzw namespace: shoot--diki-comp--gcp  
                                                            containerName: kube-controller-manager details: fileName: /var/lib/kubelet/pods/7207bfe7-1315-42f2-8383-7b79afa8437d/volumes/kubernetes.io~secret/server/..2025_06_23_00_10_41.2206626934/tls.key, permissions: 640 kind: pod name: kube-controller-manager-65cdccf875-lhhzw namespace: shoot--diki-comp--gcp  
                                                            containerName: kube-controller-manager details: fileName: /var/lib/kubelet/pods/7207bfe7-1315-42f2-8383-7b79afa8437d/volumes/kubernetes.io~secret/ca-kubelet/..2025_06_23_00_10_41.1244180931/ca.crt, permissions: 640 kind: pod name: kube-controller-manager-65cdccf875-lhhzw namespace: shoot--diki-comp--gcp  
                                                            containerName: kube-controller-manager details: fileName: /var/lib/kubelet/pods/7207bfe7-1315-42f2-8383-7b79afa8437d/volumes/kubernetes.io~secret/ca-kubelet/..2025_06_23_00_10_41.1244180931/ca.key, permissions: 640 kind: pod name: kube-controller-manager-65cdccf875-lhhzw namespace: shoot--diki-comp--gcp  
                                                            containerName: kube-controller-manager details: fileName: /var/lib/kubelet/pods/7207bfe7-1315-42f2-8383-7b79afa8437d/volumes/kubernetes.io~projected/kubeconfig/..2025_06_23_00_10_41.1252315107/kubeconfig, permissions: 644 kind: pod name: kube-controller-manager-65cdccf875-lhhzw namespace: shoot--diki-comp--gcp  
                                                            containerName: kube-controller-manager details: fileName: /var/lib/kubelet/pods/7207bfe7-1315-42f2-8383-7b79afa8437d/volumes/kubernetes.io~projected/kubeconfig/..2025_06_23_00_10_41.1252315107/token, permissions: 644 kind: pod name: kube-controller-manager-65cdccf875-lhhzw namespace: shoot--diki-comp--gcp  
                                                            containerName: kube-scheduler details: fileName: /var/lib/kubelet/pods/d1968ae3-bf95-4709-b100-13709ba484c9/volumes/kubernetes.io~projected/client-ca/..2025_06_23_00_22_41.2638774521/bundle.crt, permissions: 644 kind: pod name: kube-scheduler-7d978d746c-2vbm4 namespace: shoot--diki-comp--gcp  
                                                            containerName: kube-scheduler details: fileName: /var/lib/kubelet/pods/d1968ae3-bf95-4709-b100-13709ba484c9/volumes/kubernetes.io~secret/kube-scheduler-server/..2025_06_23_00_22_41.3181132458/tls.crt, permissions: 640 kind: pod name: kube-scheduler-7d978d746c-2vbm4 namespace: shoot--diki-comp--gcp  
                                                            containerName: kube-scheduler details: fileName: /var/lib/kubelet/pods/d1968ae3-bf95-4709-b100-13709ba484c9/volumes/kubernetes.io~secret/kube-scheduler-server/..2025_06_23_00_22_41.3181132458/tls.key, permissions: 640 kind: pod name: kube-scheduler-7d978d746c-2vbm4 namespace: shoot--diki-comp--gcp  
                                                            containerName: kube-scheduler details: fileName: /var/lib/kubelet/pods/d1968ae3-bf95-4709-b100-13709ba484c9/volumes/kubernetes.io~configmap/kube-scheduler-config/..2025_06_23_00_22_41.3002091610/config.yaml, permissions: 644 kind: pod name: kube-scheduler-7d978d746c-2vbm4 namespace: shoot--diki-comp--gcp  
                                                            containerName: kube-scheduler details: fileName: /var/lib/kubelet/pods/d1968ae3-bf95-4709-b100-13709ba484c9/volumes/kubernetes.io~projected/kubeconfig/..2025_06_23_00_22_41.335601454/token, permissions: 644 kind: pod name: kube-scheduler-7d978d746c-2vbm4 namespace: shoot--diki-comp--gcp  
                                                            containerName: kube-scheduler details: fileName: /var/lib/kubelet/pods/d1968ae3-bf95-4709-b100-13709ba484c9/volumes/kubernetes.io~projected/kubeconfig/..2025_06_23_00_22_41.335601454/kubeconfig, permissions: 644 kind: pod name: kube-scheduler-7d978d746c-2vbm4 namespace: shoot--diki-comp--gcp  
                                                         
                                                     
                                                    
                                                        openstack 
                                                        
                                                            containerName: kube-controller-manager details: fileName: /var/lib/kubelet/pods/0b27d4d8-1580-4d41-8c12-a56ef49072dc/volumes/kubernetes.io~secret/ca/..2025_06_23_00_12_57.3765708577/bundle.crt, permissions: 644 kind: pod name: kube-controller-manager-76f68f67cf-z8lm4 namespace: shoot--diki-comp--openstack  
                                                            containerName: kube-controller-manager details: fileName: /var/lib/kubelet/pods/0b27d4d8-1580-4d41-8c12-a56ef49072dc/volumes/kubernetes.io~secret/ca-client/..2025_06_23_00_12_57.3596785791/ca.crt, permissions: 640 kind: pod name: kube-controller-manager-76f68f67cf-z8lm4 namespace: shoot--diki-comp--openstack  
                                                            containerName: kube-controller-manager details: fileName: /var/lib/kubelet/pods/0b27d4d8-1580-4d41-8c12-a56ef49072dc/volumes/kubernetes.io~secret/ca-client/..2025_06_23_00_12_57.3596785791/ca.key, permissions: 640 kind: pod name: kube-controller-manager-76f68f67cf-z8lm4 namespace: shoot--diki-comp--openstack  
                                                            containerName: kube-controller-manager details: fileName: /var/lib/kubelet/pods/0b27d4d8-1580-4d41-8c12-a56ef49072dc/volumes/kubernetes.io~secret/service-account-key/..2025_06_23_00_12_57.136774851/id_rsa, permissions: 640 kind: pod name: kube-controller-manager-76f68f67cf-z8lm4 namespace: shoot--diki-comp--openstack  
                                                            containerName: kube-controller-manager details: fileName: /var/lib/kubelet/pods/0b27d4d8-1580-4d41-8c12-a56ef49072dc/volumes/kubernetes.io~secret/server/..2025_06_23_00_12_57.4281910611/tls.key, permissions: 640 kind: pod name: kube-controller-manager-76f68f67cf-z8lm4 namespace: shoot--diki-comp--openstack  
                                                            containerName: kube-controller-manager details: fileName: /var/lib/kubelet/pods/0b27d4d8-1580-4d41-8c12-a56ef49072dc/volumes/kubernetes.io~secret/server/..2025_06_23_00_12_57.4281910611/tls.crt, permissions: 640 kind: pod name: kube-controller-manager-76f68f67cf-z8lm4 namespace: shoot--diki-comp--openstack  
                                                            containerName: kube-controller-manager details: fileName: /var/lib/kubelet/pods/0b27d4d8-1580-4d41-8c12-a56ef49072dc/volumes/kubernetes.io~secret/ca-kubelet/..2025_06_23_00_12_57.775870841/ca.key, permissions: 640 kind: pod name: kube-controller-manager-76f68f67cf-z8lm4 namespace: shoot--diki-comp--openstack  
                                                            containerName: kube-controller-manager details: fileName: /var/lib/kubelet/pods/0b27d4d8-1580-4d41-8c12-a56ef49072dc/volumes/kubernetes.io~secret/ca-kubelet/..2025_06_23_00_12_57.775870841/ca.crt, permissions: 640 kind: pod name: kube-controller-manager-76f68f67cf-z8lm4 namespace: shoot--diki-comp--openstack  
                                                            containerName: kube-controller-manager details: fileName: /var/lib/kubelet/pods/0b27d4d8-1580-4d41-8c12-a56ef49072dc/volumes/kubernetes.io~projected/kubeconfig/..2025_06_23_00_12_57.1210378879/token, permissions: 644 kind: pod name: kube-controller-manager-76f68f67cf-z8lm4 namespace: shoot--diki-comp--openstack  
                                                            containerName: kube-controller-manager details: fileName: /var/lib/kubelet/pods/0b27d4d8-1580-4d41-8c12-a56ef49072dc/volumes/kubernetes.io~projected/kubeconfig/..2025_06_23_00_12_57.1210378879/kubeconfig, permissions: 644 kind: pod name: kube-controller-manager-76f68f67cf-z8lm4 namespace: shoot--diki-comp--openstack  
                                                            containerName: kube-scheduler details: fileName: /var/lib/kubelet/pods/b2afa8e5-74e9-4932-af53-bf0fcfd84066/volumes/kubernetes.io~projected/client-ca/..2025_06_23_00_11_57.2527488857/bundle.crt, permissions: 644 kind: pod name: kube-scheduler-785644b95f-fzldg namespace: shoot--diki-comp--openstack  
                                                            containerName: kube-scheduler details: fileName: /var/lib/kubelet/pods/b2afa8e5-74e9-4932-af53-bf0fcfd84066/volumes/kubernetes.io~secret/kube-scheduler-server/..2025_06_23_00_11_57.748288227/tls.crt, permissions: 640 kind: pod name: kube-scheduler-785644b95f-fzldg namespace: shoot--diki-comp--openstack  
                                                            containerName: kube-scheduler details: fileName: /var/lib/kubelet/pods/b2afa8e5-74e9-4932-af53-bf0fcfd84066/volumes/kubernetes.io~secret/kube-scheduler-server/..2025_06_23_00_11_57.748288227/tls.key, permissions: 640 kind: pod name: kube-scheduler-785644b95f-fzldg namespace: shoot--diki-comp--openstack  
                                                            containerName: kube-scheduler details: fileName: /var/lib/kubelet/pods/b2afa8e5-74e9-4932-af53-bf0fcfd84066/volumes/kubernetes.io~configmap/kube-scheduler-config/..2025_06_23_00_11_57.964913296/config.yaml, permissions: 644 kind: pod name: kube-scheduler-785644b95f-fzldg namespace: shoot--diki-comp--openstack  
                                                            containerName: kube-scheduler details: fileName: /var/lib/kubelet/pods/b2afa8e5-74e9-4932-af53-bf0fcfd84066/volumes/kubernetes.io~projected/kubeconfig/..2025_06_23_00_11_57.558571866/token, permissions: 644 kind: pod name: kube-scheduler-785644b95f-fzldg namespace: shoot--diki-comp--openstack  
                                                            containerName: kube-scheduler details: fileName: /var/lib/kubelet/pods/b2afa8e5-74e9-4932-af53-bf0fcfd84066/volumes/kubernetes.io~projected/kubeconfig/..2025_06_23_00_11_57.558571866/kubeconfig, permissions: 644 kind: pod name: kube-scheduler-785644b95f-fzldg namespace: shoot--diki-comp--openstack  
                                                            containerName: kube-apiserver details: fileName: /var/lib/kubelet/pods/4a414212-471d-49e1-ba69-657ac6fd352a/volumes/kubernetes.io~secret/ca/..2025_06_23_00_05_31.3801277659/bundle.crt, permissions: 644 kind: pod name: kube-apiserver-5ffd79587b-574wj namespace: shoot--diki-comp--openstack  
                                                            containerName: kube-apiserver details: fileName: /var/lib/kubelet/pods/4a414212-471d-49e1-ba69-657ac6fd352a/volumes/kubernetes.io~secret/ca-client/..2025_06_23_00_05_31.316180318/bundle.crt, permissions: 644 kind: pod name: kube-apiserver-5ffd79587b-574wj namespace: shoot--diki-comp--openstack  
                                                            containerName: kube-apiserver details: fileName: /var/lib/kubelet/pods/4a414212-471d-49e1-ba69-657ac6fd352a/volumes/kubernetes.io~secret/ca-front-proxy/..2025_06_23_00_05_31.1046019673/bundle.crt, permissions: 644 kind: pod name: kube-apiserver-5ffd79587b-574wj namespace: shoot--diki-comp--openstack  
                                                            containerName: kube-apiserver details: fileName: /var/lib/kubelet/pods/4a414212-471d-49e1-ba69-657ac6fd352a/volumes/kubernetes.io~secret/service-account-key/..2025_06_23_00_05_31.235664194/id_rsa, permissions: 640 kind: pod name: kube-apiserver-5ffd79587b-574wj namespace: shoot--diki-comp--openstack  
                                                            containerName: kube-apiserver details: fileName: /var/lib/kubelet/pods/4a414212-471d-49e1-ba69-657ac6fd352a/volumes/kubernetes.io~secret/service-account-key-bundle/..2025_06_23_00_05_31.2877576203/bundle.key, permissions: 640 kind: pod name: kube-apiserver-5ffd79587b-574wj namespace: shoot--diki-comp--openstack  
                                                            containerName: kube-apiserver details: fileName: /var/lib/kubelet/pods/4a414212-471d-49e1-ba69-657ac6fd352a/volumes/kubernetes.io~secret/static-token/..2025_06_23_00_05_31.1058278656/static_tokens.csv, permissions: 644 kind: pod name: kube-apiserver-5ffd79587b-574wj namespace: shoot--diki-comp--openstack  
                                                            containerName: kube-apiserver details: fileName: /var/lib/kubelet/pods/4a414212-471d-49e1-ba69-657ac6fd352a/volumes/kubernetes.io~secret/kube-aggregator/..2025_06_23_00_05_31.974579027/tls.crt, permissions: 640 kind: pod name: kube-apiserver-5ffd79587b-574wj namespace: shoot--diki-comp--openstack  
                                                            containerName: kube-apiserver details: fileName: /var/lib/kubelet/pods/4a414212-471d-49e1-ba69-657ac6fd352a/volumes/kubernetes.io~secret/kube-aggregator/..2025_06_23_00_05_31.974579027/tls.key, permissions: 640 kind: pod name: kube-apiserver-5ffd79587b-574wj namespace: shoot--diki-comp--openstack  
                                                            containerName: kube-apiserver details: fileName: /var/lib/kubelet/pods/4a414212-471d-49e1-ba69-657ac6fd352a/volumes/kubernetes.io~secret/server/..2025_06_23_00_05_31.110607305/tls.key, permissions: 640 kind: pod name: kube-apiserver-5ffd79587b-574wj namespace: shoot--diki-comp--openstack  
                                                            containerName: kube-apiserver details: fileName: /var/lib/kubelet/pods/4a414212-471d-49e1-ba69-657ac6fd352a/volumes/kubernetes.io~secret/server/..2025_06_23_00_05_31.110607305/tls.crt, permissions: 640 kind: pod name: kube-apiserver-5ffd79587b-574wj namespace: shoot--diki-comp--openstack  
                                                            containerName: kube-apiserver details: fileName: /var/lib/kubelet/pods/4a414212-471d-49e1-ba69-657ac6fd352a/volumes/kubernetes.io~configmap/audit-policy-config/..2025_06_23_00_05_31.3259083047/audit-policy.yaml, permissions: 644 kind: pod name: kube-apiserver-5ffd79587b-574wj namespace: shoot--diki-comp--openstack  
                                                            containerName: kube-apiserver details: fileName: /var/lib/kubelet/pods/4a414212-471d-49e1-ba69-657ac6fd352a/volumes/kubernetes.io~configmap/admission-config/..2025_06_23_00_05_31.3719270629/podsecurity.yaml, permissions: 644 kind: pod name: kube-apiserver-5ffd79587b-574wj namespace: shoot--diki-comp--openstack  
                                                            containerName: kube-apiserver details: fileName: /var/lib/kubelet/pods/4a414212-471d-49e1-ba69-657ac6fd352a/volumes/kubernetes.io~configmap/admission-config/..2025_06_23_00_05_31.3719270629/admission-configuration.yaml, permissions: 644 kind: pod name: kube-apiserver-5ffd79587b-574wj namespace: shoot--diki-comp--openstack  
                                                            containerName: kube-apiserver details: fileName: /var/lib/kubelet/pods/4a414212-471d-49e1-ba69-657ac6fd352a/volumes/kubernetes.io~secret/etcd-encryption-secret/..2025_06_23_00_05_31.2859207702/encryption-configuration.yaml, permissions: 640 kind: pod name: kube-apiserver-5ffd79587b-574wj namespace: shoot--diki-comp--openstack  
                                                            containerName: kube-apiserver details: fileName: /var/lib/kubelet/pods/4a414212-471d-49e1-ba69-657ac6fd352a/volumes/kubernetes.io~secret/ca-vpn/..2025_06_23_00_05_31.1571181539/bundle.crt, permissions: 644 kind: pod name: kube-apiserver-5ffd79587b-574wj namespace: shoot--diki-comp--openstack  
                                                            containerName: kube-apiserver details: fileName: /var/lib/kubelet/pods/4a414212-471d-49e1-ba69-657ac6fd352a/volumes/kubernetes.io~configmap/egress-selection-config/..2025_06_23_00_05_31.2734610207/egress-selector-configuration.yaml, permissions: 644 kind: pod name: kube-apiserver-5ffd79587b-574wj namespace: shoot--diki-comp--openstack  
                                                            containerName: kube-apiserver details: fileName: /var/lib/kubelet/pods/4a414212-471d-49e1-ba69-657ac6fd352a/volumes/kubernetes.io~secret/ca-kubelet/..2025_06_23_00_05_31.1055204524/bundle.crt, permissions: 644 kind: pod name: kube-apiserver-5ffd79587b-574wj namespace: shoot--diki-comp--openstack  
                                                            containerName: kube-apiserver details: fileName: /var/lib/kubelet/pods/4a414212-471d-49e1-ba69-657ac6fd352a/volumes/kubernetes.io~secret/kubelet-client/..2025_06_23_00_05_31.529535444/tls.crt, permissions: 640 kind: pod name: kube-apiserver-5ffd79587b-574wj namespace: shoot--diki-comp--openstack  
                                                            containerName: kube-apiserver details: fileName: /var/lib/kubelet/pods/4a414212-471d-49e1-ba69-657ac6fd352a/volumes/kubernetes.io~secret/kubelet-client/..2025_06_23_00_05_31.529535444/tls.key, permissions: 640 kind: pod name: kube-apiserver-5ffd79587b-574wj namespace: shoot--diki-comp--openstack  
                                                            containerName: kube-apiserver details: fileName: /var/lib/kubelet/pods/4a414212-471d-49e1-ba69-657ac6fd352a/volumes/kubernetes.io~secret/ca-etcd/..2025_06_23_00_05_31.3135557557/bundle.crt, permissions: 644 kind: pod name: kube-apiserver-5ffd79587b-574wj namespace: shoot--diki-comp--openstack  
                                                            containerName: kube-apiserver details: fileName: /var/lib/kubelet/pods/4a414212-471d-49e1-ba69-657ac6fd352a/volumes/kubernetes.io~secret/etcd-client/..2025_06_23_00_05_31.3982193628/tls.key, permissions: 640 kind: pod name: kube-apiserver-5ffd79587b-574wj namespace: shoot--diki-comp--openstack  
                                                            containerName: kube-apiserver details: fileName: /var/lib/kubelet/pods/4a414212-471d-49e1-ba69-657ac6fd352a/volumes/kubernetes.io~secret/etcd-client/..2025_06_23_00_05_31.3982193628/tls.crt, permissions: 640 kind: pod name: kube-apiserver-5ffd79587b-574wj namespace: shoot--diki-comp--openstack  
                                                            containerName: kube-apiserver details: fileName: /var/lib/kubelet/pods/4a414212-471d-49e1-ba69-657ac6fd352a/volumes/kubernetes.io~secret/tls-sni-0/..2025_06_23_00_05_31.1069974019/tls.key, permissions: 640 kind: pod name: kube-apiserver-5ffd79587b-574wj namespace: shoot--diki-comp--openstack  
                                                            containerName: kube-apiserver details: fileName: /var/lib/kubelet/pods/4a414212-471d-49e1-ba69-657ac6fd352a/volumes/kubernetes.io~secret/tls-sni-0/..2025_06_23_00_05_31.1069974019/tls.crt, permissions: 640 kind: pod name: kube-apiserver-5ffd79587b-574wj namespace: shoot--diki-comp--openstack  
                                                            containerName: kube-apiserver details: fileName: /var/lib/kubelet/pods/4a414212-471d-49e1-ba69-657ac6fd352a/volumes/kubernetes.io~secret/tls-sni-0/..2025_06_23_00_05_31.1069974019/ca.crt, permissions: 640 kind: pod name: kube-apiserver-5ffd79587b-574wj namespace: shoot--diki-comp--openstack  
                                                            containerName: kube-apiserver details: fileName: /var/lib/kubelet/pods/4a414212-471d-49e1-ba69-657ac6fd352a/volumes/kubernetes.io~configmap/authorization-config/..2025_06_23_00_05_31.2392426714/config.yaml, permissions: 644 kind: pod name: kube-apiserver-5ffd79587b-574wj namespace: shoot--diki-comp--openstack  
                                                            containerName: kube-apiserver details: fileName: /var/lib/kubelet/pods/4a414212-471d-49e1-ba69-657ac6fd352a/volumes/kubernetes.io~secret/authorization-kubeconfigs/..2025_06_23_00_05_31.3381187726/node-agent-authorizer-kubeconfig.yaml, permissions: 644 kind: pod name: kube-apiserver-5ffd79587b-574wj namespace: shoot--diki-comp--openstack  
                                                            containerName: kube-apiserver details: fileName: /var/lib/kubelet/pods/4a414212-471d-49e1-ba69-657ac6fd352a/volumes/kubernetes.io~secret/http-proxy/..2025_06_23_00_05_31.3012580451/tls.key, permissions: 640 kind: pod name: kube-apiserver-5ffd79587b-574wj namespace: shoot--diki-comp--openstack  
                                                            containerName: kube-apiserver details: fileName: /var/lib/kubelet/pods/4a414212-471d-49e1-ba69-657ac6fd352a/volumes/kubernetes.io~secret/http-proxy/..2025_06_23_00_05_31.3012580451/tls.crt, permissions: 640 kind: pod name: kube-apiserver-5ffd79587b-574wj namespace: shoot--diki-comp--openstack  
                                                         
                                                     
                                                 
                                             
                                         
                                     
                                    
                                        242461 (Medium) - The Kubernetes API Server audit logs must be enabled. 
                                        
                                            
                                                Option audit-policy-file set. 
                                                
                                                    
                                                        aws 
                                                        
                                                            kind: deployment name: kube-apiserver namespace: shoot--diki-comp--aws  
                                                         
                                                     
                                                    
                                                        azure 
                                                        
                                                            kind: deployment name: kube-apiserver namespace: shoot--diki-comp--azure  
                                                         
                                                     
                                                    
                                                        gcp 
                                                        
                                                            kind: deployment name: kube-apiserver namespace: shoot--diki-comp--gcp  
                                                         
                                                     
                                                    
                                                        openstack 
                                                        
                                                            kind: deployment name: kube-apiserver namespace: shoot--diki-comp--openstack  
                                                         
                                                     
                                                 
                                             
                                         
                                     
                                    
                                        242466 (Medium) - The Kubernetes PKI CRT must have file permissions set to 644 or more restrictive. 
                                        
                                            
                                                File has expected permissions 
                                                
                                                    
                                                        aws 
                                                        
                                                            cluster: seed containerName: kube-controller-manager details: fileName: /var/lib/kubelet/pods/c423b64c-cb58-46fa-a956-022b9b1664c6/volumes/kubernetes.io~secret/ca/..2025_06_23_00_16_39.892891764/bundle.crt, permissions: 644 kind: pod name: kube-controller-manager-7c9bc75987-cqgs4 namespace: shoot--diki-comp--aws  
                                                            cluster: seed containerName: kube-controller-manager details: fileName: /var/lib/kubelet/pods/c423b64c-cb58-46fa-a956-022b9b1664c6/volumes/kubernetes.io~secret/ca-client/..2025_06_23_00_16_39.4293646224/ca.crt, permissions: 640 kind: pod name: kube-controller-manager-7c9bc75987-cqgs4 namespace: shoot--diki-comp--aws  
                                                            cluster: seed containerName: kube-controller-manager details: fileName: /var/lib/kubelet/pods/c423b64c-cb58-46fa-a956-022b9b1664c6/volumes/kubernetes.io~secret/server/..2025_06_23_00_16_39.867879351/tls.crt, permissions: 640 kind: pod name: kube-controller-manager-7c9bc75987-cqgs4 namespace: shoot--diki-comp--aws  
                                                            cluster: seed containerName: kube-controller-manager details: fileName: /var/lib/kubelet/pods/c423b64c-cb58-46fa-a956-022b9b1664c6/volumes/kubernetes.io~secret/ca-kubelet/..2025_06_23_00_16_39.254040933/ca.crt, permissions: 640 kind: pod name: kube-controller-manager-7c9bc75987-cqgs4 namespace: shoot--diki-comp--aws  
                                                            cluster: seed containerName: etcd details: fileName: /var/lib/kubelet/pods/8500de88-870c-4453-a9d3-673fe2e83591/volumes/kubernetes.io~secret/etcd-ca/..2025_06_23_00_02_28.1460198907/bundle.crt, permissions: 640 kind: pod name: etcd-events-0 namespace: shoot--diki-comp--aws  
                                                            cluster: seed containerName: etcd details: fileName: /var/lib/kubelet/pods/8500de88-870c-4453-a9d3-673fe2e83591/volumes/kubernetes.io~secret/etcd-server-tls/..2025_06_23_00_02_28.1081429868/tls.crt, permissions: 640 kind: pod name: etcd-events-0 namespace: shoot--diki-comp--aws  
                                                            cluster: seed containerName: etcd details: fileName: /var/lib/kubelet/pods/8500de88-870c-4453-a9d3-673fe2e83591/volumes/kubernetes.io~secret/etcd-client-tls/..2025_06_23_00_02_28.830733358/tls.crt, permissions: 640 kind: pod name: etcd-events-0 namespace: shoot--diki-comp--aws  
                                                            cluster: seed containerName: etcd details: fileName: /var/lib/kubelet/pods/8500de88-870c-4453-a9d3-673fe2e83591/volumes/kubernetes.io~secret/backup-restore-ca/..2025_06_23_00_02_28.402585131/bundle.crt, permissions: 640 kind: pod name: etcd-events-0 namespace: shoot--diki-comp--aws  
                                                            cluster: seed containerName: etcd details: fileName: /var/lib/kubelet/pods/8500de88-870c-4453-a9d3-673fe2e83591/volumes/kubernetes.io~projected/kube-api-access-gardener/..2025_06_23_00_02_28.124882621/ca.crt, permissions: 644 kind: pod name: etcd-events-0 namespace: shoot--diki-comp--aws  
                                                            cluster: seed containerName: backup-restore details: fileName: /var/lib/kubelet/pods/8500de88-870c-4453-a9d3-673fe2e83591/volumes/kubernetes.io~secret/backup-restore-server-tls/..2025_06_23_00_02_28.1357612372/tls.crt, permissions: 640 kind: pod name: etcd-events-0 namespace: shoot--diki-comp--aws  
                                                            cluster: seed containerName: backup-restore details: fileName: /var/lib/kubelet/pods/8500de88-870c-4453-a9d3-673fe2e83591/volumes/kubernetes.io~secret/etcd-ca/..2025_06_23_00_02_28.1460198907/bundle.crt, permissions: 640 kind: pod name: etcd-events-0 namespace: shoot--diki-comp--aws  
                                                            cluster: seed containerName: backup-restore details: fileName: /var/lib/kubelet/pods/8500de88-870c-4453-a9d3-673fe2e83591/volumes/kubernetes.io~secret/etcd-client-tls/..2025_06_23_00_02_28.830733358/tls.crt, permissions: 640 kind: pod name: etcd-events-0 namespace: shoot--diki-comp--aws  
                                                            cluster: seed containerName: backup-restore details: fileName: /var/lib/kubelet/pods/8500de88-870c-4453-a9d3-673fe2e83591/volumes/kubernetes.io~projected/kube-api-access-gardener/..2025_06_23_00_02_28.124882621/ca.crt, permissions: 644 kind: pod name: etcd-events-0 namespace: shoot--diki-comp--aws  
                                                            cluster: seed containerName: kube-scheduler details: fileName: /var/lib/kubelet/pods/06134fb6-0360-493d-adc6-38d710393b11/volumes/kubernetes.io~projected/client-ca/..2025_06_23_00_10_38.120749235/bundle.crt, permissions: 644 kind: pod name: kube-scheduler-5854d54c7c-2b7mv namespace: shoot--diki-comp--aws  
                                                            cluster: seed containerName: kube-scheduler details: fileName: /var/lib/kubelet/pods/06134fb6-0360-493d-adc6-38d710393b11/volumes/kubernetes.io~secret/kube-scheduler-server/..2025_06_23_00_10_38.1273189684/tls.crt, permissions: 640 kind: pod name: kube-scheduler-5854d54c7c-2b7mv namespace: shoot--diki-comp--aws  
                                                            cluster: seed containerName: etcd details: fileName: /var/lib/kubelet/pods/e9a97103-bea9-4174-9f2f-d11c7dee0b81/volumes/kubernetes.io~secret/etcd-ca/..2025_06_23_00_02_28.70977455/bundle.crt, permissions: 640 kind: pod name: etcd-main-0 namespace: shoot--diki-comp--aws  
                                                            cluster: seed containerName: etcd details: fileName: /var/lib/kubelet/pods/e9a97103-bea9-4174-9f2f-d11c7dee0b81/volumes/kubernetes.io~secret/etcd-server-tls/..2025_06_23_00_02_28.941742504/tls.crt, permissions: 640 kind: pod name: etcd-main-0 namespace: shoot--diki-comp--aws  
                                                            cluster: seed containerName: etcd details: fileName: /var/lib/kubelet/pods/e9a97103-bea9-4174-9f2f-d11c7dee0b81/volumes/kubernetes.io~secret/etcd-client-tls/..2025_06_23_00_02_28.581061777/tls.crt, permissions: 640 kind: pod name: etcd-main-0 namespace: shoot--diki-comp--aws  
                                                            cluster: seed containerName: etcd details: fileName: /var/lib/kubelet/pods/e9a97103-bea9-4174-9f2f-d11c7dee0b81/volumes/kubernetes.io~secret/backup-restore-ca/..2025_06_23_00_02_28.3789989883/bundle.crt, permissions: 640 kind: pod name: etcd-main-0 namespace: shoot--diki-comp--aws  
                                                            cluster: seed containerName: etcd details: fileName: /var/lib/kubelet/pods/e9a97103-bea9-4174-9f2f-d11c7dee0b81/volumes/kubernetes.io~projected/kube-api-access-gardener/..2025_06_23_00_02_28.4232825321/ca.crt, permissions: 644 kind: pod name: etcd-main-0 namespace: shoot--diki-comp--aws  
                                                            cluster: seed containerName: backup-restore details: fileName: /var/lib/kubelet/pods/e9a97103-bea9-4174-9f2f-d11c7dee0b81/volumes/kubernetes.io~secret/backup-restore-server-tls/..2025_06_23_00_02_28.137193825/tls.crt, permissions: 640 kind: pod name: etcd-main-0 namespace: shoot--diki-comp--aws  
                                                            cluster: seed containerName: backup-restore details: fileName: /var/lib/kubelet/pods/e9a97103-bea9-4174-9f2f-d11c7dee0b81/volumes/kubernetes.io~secret/etcd-ca/..2025_06_23_00_02_28.70977455/bundle.crt, permissions: 640 kind: pod name: etcd-main-0 namespace: shoot--diki-comp--aws  
                                                            cluster: seed containerName: backup-restore details: fileName: /var/lib/kubelet/pods/e9a97103-bea9-4174-9f2f-d11c7dee0b81/volumes/kubernetes.io~secret/etcd-client-tls/..2025_06_23_00_02_28.581061777/tls.crt, permissions: 640 kind: pod name: etcd-main-0 namespace: shoot--diki-comp--aws  
                                                            cluster: seed containerName: backup-restore details: fileName: /var/lib/kubelet/pods/e9a97103-bea9-4174-9f2f-d11c7dee0b81/volumes/kubernetes.io~projected/kube-api-access-gardener/..2025_06_23_00_02_28.4232825321/ca.crt, permissions: 644 kind: pod name: etcd-main-0 namespace: shoot--diki-comp--aws  
                                                            cluster: seed containerName: kube-apiserver details: fileName: /var/lib/kubelet/pods/42db629f-9d43-492e-92df-f2a0ac97d2b6/volumes/kubernetes.io~secret/ca/..2025_06_23_00_09_39.1820813547/bundle.crt, permissions: 644 kind: pod name: kube-apiserver-6d847f96d4-82qpt namespace: shoot--diki-comp--aws  
                                                            cluster: seed containerName: kube-apiserver details: fileName: /var/lib/kubelet/pods/42db629f-9d43-492e-92df-f2a0ac97d2b6/volumes/kubernetes.io~secret/ca-client/..2025_06_23_00_09_39.3911158577/bundle.crt, permissions: 644 kind: pod name: kube-apiserver-6d847f96d4-82qpt namespace: shoot--diki-comp--aws  
                                                            cluster: seed containerName: kube-apiserver details: fileName: /var/lib/kubelet/pods/42db629f-9d43-492e-92df-f2a0ac97d2b6/volumes/kubernetes.io~secret/ca-front-proxy/..2025_06_23_00_09_39.1216619138/bundle.crt, permissions: 644 kind: pod name: kube-apiserver-6d847f96d4-82qpt namespace: shoot--diki-comp--aws  
                                                            cluster: seed containerName: kube-apiserver details: fileName: /var/lib/kubelet/pods/42db629f-9d43-492e-92df-f2a0ac97d2b6/volumes/kubernetes.io~secret/kube-aggregator/..2025_06_23_00_09_39.3585741192/tls.crt, permissions: 640 kind: pod name: kube-apiserver-6d847f96d4-82qpt namespace: shoot--diki-comp--aws  
                                                            cluster: seed containerName: kube-apiserver details: fileName: /var/lib/kubelet/pods/42db629f-9d43-492e-92df-f2a0ac97d2b6/volumes/kubernetes.io~secret/server/..2025_06_23_00_09_39.2101876528/tls.crt, permissions: 640 kind: pod name: kube-apiserver-6d847f96d4-82qpt namespace: shoot--diki-comp--aws  
                                                            cluster: seed containerName: kube-apiserver details: fileName: /var/lib/kubelet/pods/42db629f-9d43-492e-92df-f2a0ac97d2b6/volumes/kubernetes.io~secret/ca-vpn/..2025_06_23_00_09_39.1345136145/bundle.crt, permissions: 644 kind: pod name: kube-apiserver-6d847f96d4-82qpt namespace: shoot--diki-comp--aws  
                                                            cluster: seed containerName: kube-apiserver details: fileName: /var/lib/kubelet/pods/42db629f-9d43-492e-92df-f2a0ac97d2b6/volumes/kubernetes.io~secret/ca-kubelet/..2025_06_23_00_09_39.2968989444/bundle.crt, permissions: 644 kind: pod name: kube-apiserver-6d847f96d4-82qpt namespace: shoot--diki-comp--aws  
                                                            cluster: seed containerName: kube-apiserver details: fileName: /var/lib/kubelet/pods/42db629f-9d43-492e-92df-f2a0ac97d2b6/volumes/kubernetes.io~secret/kubelet-client/..2025_06_23_00_09_39.2120918226/tls.crt, permissions: 640 kind: pod name: kube-apiserver-6d847f96d4-82qpt namespace: shoot--diki-comp--aws  
                                                            cluster: seed containerName: kube-apiserver details: fileName: /var/lib/kubelet/pods/42db629f-9d43-492e-92df-f2a0ac97d2b6/volumes/kubernetes.io~secret/ca-etcd/..2025_06_23_00_09_39.86038190/bundle.crt, permissions: 644 kind: pod name: kube-apiserver-6d847f96d4-82qpt namespace: shoot--diki-comp--aws  
                                                            cluster: seed containerName: kube-apiserver details: fileName: /var/lib/kubelet/pods/42db629f-9d43-492e-92df-f2a0ac97d2b6/volumes/kubernetes.io~secret/etcd-client/..2025_06_23_00_09_39.3841361014/tls.crt, permissions: 640 kind: pod name: kube-apiserver-6d847f96d4-82qpt namespace: shoot--diki-comp--aws  
                                                            cluster: seed containerName: kube-apiserver details: fileName: /var/lib/kubelet/pods/42db629f-9d43-492e-92df-f2a0ac97d2b6/volumes/kubernetes.io~secret/tls-sni-0/..2025_06_23_00_09_39.1534744055/tls.crt, permissions: 640 kind: pod name: kube-apiserver-6d847f96d4-82qpt namespace: shoot--diki-comp--aws  
                                                            cluster: seed containerName: kube-apiserver details: fileName: /var/lib/kubelet/pods/42db629f-9d43-492e-92df-f2a0ac97d2b6/volumes/kubernetes.io~secret/tls-sni-0/..2025_06_23_00_09_39.1534744055/ca.crt, permissions: 640 kind: pod name: kube-apiserver-6d847f96d4-82qpt namespace: shoot--diki-comp--aws  
                                                            cluster: seed containerName: kube-apiserver details: fileName: /var/lib/kubelet/pods/42db629f-9d43-492e-92df-f2a0ac97d2b6/volumes/kubernetes.io~secret/http-proxy/..2025_06_23_00_09_39.1635279459/tls.crt, permissions: 640 kind: pod name: kube-apiserver-6d847f96d4-82qpt namespace: shoot--diki-comp--aws  
                                                            cluster: shoot details: fileName: /var/lib/kubelet/pki/kubelet-client-2025-06-23-00-08-33.pem, permissions: 600 kind: node name: ip-IP-Address.eu-west-1.compute.internal  
                                                            cluster: shoot details: fileName: /var/lib/kubelet/pki/kubelet-server-2025-06-23-00-08-57.pem, permissions: 600 kind: node name: ip-IP-Address.eu-west-1.compute.internal  
                                                            cluster: shoot containerName: cleanup details: fileName: /var/lib/kubelet/pods/d0c8ecde-b8ca-4e6b-bb08-1cbc0775438d/volumes/kubernetes.io~projected/kube-api-access-gardener/..2025_06_23_00_08_35.3746123174/ca.crt, permissions: 644 kind: pod name: kube-proxy-worker-kkfk1-v1.31.8-8bvtn namespace: kube-system  
                                                            cluster: shoot containerName: kube-proxy-init details: fileName: /var/lib/kubelet/pods/d0c8ecde-b8ca-4e6b-bb08-1cbc0775438d/volumes/kubernetes.io~projected/kube-api-access-gardener/..2025_06_23_00_08_35.3746123174/ca.crt, permissions: 644 kind: pod name: kube-proxy-worker-kkfk1-v1.31.8-8bvtn namespace: kube-system  
                                                            cluster: shoot containerName: kube-proxy details: fileName: /var/lib/kubelet/pods/d0c8ecde-b8ca-4e6b-bb08-1cbc0775438d/volumes/kubernetes.io~projected/kube-api-access-gardener/..2025_06_23_00_08_35.3746123174/ca.crt, permissions: 644 kind: pod name: kube-proxy-worker-kkfk1-v1.31.8-8bvtn namespace: kube-system  
                                                            cluster: shoot containerName: conntrack-fix details: fileName: /var/lib/kubelet/pods/d0c8ecde-b8ca-4e6b-bb08-1cbc0775438d/volumes/kubernetes.io~projected/kube-api-access-gardener/..2025_06_23_00_08_35.3746123174/ca.crt, permissions: 644 kind: pod name: kube-proxy-worker-kkfk1-v1.31.8-8bvtn namespace: kube-system  
                                                         
                                                     
                                                    
                                                        azure 
                                                        
                                                            cluster: seed containerName: kube-apiserver details: fileName: /var/lib/kubelet/pods/19e8d0fb-e648-458d-9824-7002ba098bce/volumes/kubernetes.io~secret/ca/..2025_06_23_00_14_46.3142548715/bundle.crt, permissions: 644 kind: pod name: kube-apiserver-d66f4d44f-tm4cs namespace: shoot--diki-comp--azure  
                                                            cluster: seed containerName: kube-apiserver details: fileName: /var/lib/kubelet/pods/19e8d0fb-e648-458d-9824-7002ba098bce/volumes/kubernetes.io~secret/ca-client/..2025_06_23_00_14_46.1427032518/bundle.crt, permissions: 644 kind: pod name: kube-apiserver-d66f4d44f-tm4cs namespace: shoot--diki-comp--azure  
                                                            cluster: seed containerName: kube-apiserver details: fileName: /var/lib/kubelet/pods/19e8d0fb-e648-458d-9824-7002ba098bce/volumes/kubernetes.io~secret/ca-front-proxy/..2025_06_23_00_14_46.1493427643/bundle.crt, permissions: 644 kind: pod name: kube-apiserver-d66f4d44f-tm4cs namespace: shoot--diki-comp--azure  
                                                            cluster: seed containerName: kube-apiserver details: fileName: /var/lib/kubelet/pods/19e8d0fb-e648-458d-9824-7002ba098bce/volumes/kubernetes.io~secret/kube-aggregator/..2025_06_23_00_14_46.2139614939/tls.crt, permissions: 640 kind: pod name: kube-apiserver-d66f4d44f-tm4cs namespace: shoot--diki-comp--azure  
                                                            cluster: seed containerName: kube-apiserver details: fileName: /var/lib/kubelet/pods/19e8d0fb-e648-458d-9824-7002ba098bce/volumes/kubernetes.io~secret/server/..2025_06_23_00_14_46.2186093174/tls.crt, permissions: 640 kind: pod name: kube-apiserver-d66f4d44f-tm4cs namespace: shoot--diki-comp--azure  
                                                            cluster: seed containerName: kube-apiserver details: fileName: /var/lib/kubelet/pods/19e8d0fb-e648-458d-9824-7002ba098bce/volumes/kubernetes.io~secret/ca-vpn/..2025_06_23_00_14_46.3412290611/bundle.crt, permissions: 644 kind: pod name: kube-apiserver-d66f4d44f-tm4cs namespace: shoot--diki-comp--azure  
                                                            cluster: seed containerName: kube-apiserver details: fileName: /var/lib/kubelet/pods/19e8d0fb-e648-458d-9824-7002ba098bce/volumes/kubernetes.io~secret/ca-kubelet/..2025_06_23_00_14_46.3112199018/bundle.crt, permissions: 644 kind: pod name: kube-apiserver-d66f4d44f-tm4cs namespace: shoot--diki-comp--azure  
                                                            cluster: seed containerName: kube-apiserver details: fileName: /var/lib/kubelet/pods/19e8d0fb-e648-458d-9824-7002ba098bce/volumes/kubernetes.io~secret/kubelet-client/..2025_06_23_00_14_46.2446316166/tls.crt, permissions: 640 kind: pod name: kube-apiserver-d66f4d44f-tm4cs namespace: shoot--diki-comp--azure  
                                                            cluster: seed containerName: kube-apiserver details: fileName: /var/lib/kubelet/pods/19e8d0fb-e648-458d-9824-7002ba098bce/volumes/kubernetes.io~secret/ca-etcd/..2025_06_23_00_14_46.3219727173/bundle.crt, permissions: 644 kind: pod name: kube-apiserver-d66f4d44f-tm4cs namespace: shoot--diki-comp--azure  
                                                            cluster: seed containerName: kube-apiserver details: fileName: /var/lib/kubelet/pods/19e8d0fb-e648-458d-9824-7002ba098bce/volumes/kubernetes.io~secret/etcd-client/..2025_06_23_00_14_46.1466414181/tls.crt, permissions: 640 kind: pod name: kube-apiserver-d66f4d44f-tm4cs namespace: shoot--diki-comp--azure  
                                                            cluster: seed containerName: kube-apiserver details: fileName: /var/lib/kubelet/pods/19e8d0fb-e648-458d-9824-7002ba098bce/volumes/kubernetes.io~secret/tls-sni-0/..2025_06_23_00_14_46.1021198322/tls.crt, permissions: 640 kind: pod name: kube-apiserver-d66f4d44f-tm4cs namespace: shoot--diki-comp--azure  
                                                            cluster: seed containerName: kube-apiserver details: fileName: /var/lib/kubelet/pods/19e8d0fb-e648-458d-9824-7002ba098bce/volumes/kubernetes.io~secret/tls-sni-0/..2025_06_23_00_14_46.1021198322/ca.crt, permissions: 640 kind: pod name: kube-apiserver-d66f4d44f-tm4cs namespace: shoot--diki-comp--azure  
                                                            cluster: seed containerName: kube-apiserver details: fileName: /var/lib/kubelet/pods/19e8d0fb-e648-458d-9824-7002ba098bce/volumes/kubernetes.io~secret/http-proxy/..2025_06_23_00_14_46.234968055/tls.crt, permissions: 640 kind: pod name: kube-apiserver-d66f4d44f-tm4cs namespace: shoot--diki-comp--azure  
                                                            cluster: seed containerName: kube-controller-manager details: fileName: /var/lib/kubelet/pods/8a5510fe-a88b-42cc-b90a-1d8f9487d887/volumes/kubernetes.io~secret/ca/..2025_06_23_00_19_46.2289618773/bundle.crt, permissions: 644 kind: pod name: kube-controller-manager-7d869c84b8-kz7dm namespace: shoot--diki-comp--azure  
                                                            cluster: seed containerName: kube-controller-manager details: fileName: /var/lib/kubelet/pods/8a5510fe-a88b-42cc-b90a-1d8f9487d887/volumes/kubernetes.io~secret/ca-client/..2025_06_23_00_19_46.1556017874/ca.crt, permissions: 640 kind: pod name: kube-controller-manager-7d869c84b8-kz7dm namespace: shoot--diki-comp--azure  
                                                            cluster: seed containerName: kube-controller-manager details: fileName: /var/lib/kubelet/pods/8a5510fe-a88b-42cc-b90a-1d8f9487d887/volumes/kubernetes.io~secret/server/..2025_06_23_00_19_46.3137963724/tls.crt, permissions: 640 kind: pod name: kube-controller-manager-7d869c84b8-kz7dm namespace: shoot--diki-comp--azure  
                                                            cluster: seed containerName: kube-controller-manager details: fileName: /var/lib/kubelet/pods/8a5510fe-a88b-42cc-b90a-1d8f9487d887/volumes/kubernetes.io~secret/ca-kubelet/..2025_06_23_00_19_46.2139875717/ca.crt, permissions: 640 kind: pod name: kube-controller-manager-7d869c84b8-kz7dm namespace: shoot--diki-comp--azure  
                                                            cluster: seed containerName: kube-scheduler details: fileName: /var/lib/kubelet/pods/8afdd891-92eb-4c6a-aac5-9a324987f6ad/volumes/kubernetes.io~projected/client-ca/..2025_06_23_00_14_46.3397349168/bundle.crt, permissions: 644 kind: pod name: kube-scheduler-67fdbc4569-h6j7v namespace: shoot--diki-comp--azure  
                                                            cluster: seed containerName: kube-scheduler details: fileName: /var/lib/kubelet/pods/8afdd891-92eb-4c6a-aac5-9a324987f6ad/volumes/kubernetes.io~secret/kube-scheduler-server/..2025_06_23_00_14_46.366944806/tls.crt, permissions: 640 kind: pod name: kube-scheduler-67fdbc4569-h6j7v namespace: shoot--diki-comp--azure  
                                                            cluster: seed containerName: etcd details: fileName: /var/lib/kubelet/pods/d86b08b7-3d10-49ae-a4d6-4fe9fa757c93/volumes/kubernetes.io~secret/etcd-ca/..2025_06_23_00_02_37.231883813/bundle.crt, permissions: 640 kind: pod name: etcd-main-0 namespace: shoot--diki-comp--azure  
                                                            cluster: seed containerName: etcd details: fileName: /var/lib/kubelet/pods/d86b08b7-3d10-49ae-a4d6-4fe9fa757c93/volumes/kubernetes.io~secret/etcd-server-tls/..2025_06_23_00_02_37.4111409223/tls.crt, permissions: 640 kind: pod name: etcd-main-0 namespace: shoot--diki-comp--azure  
                                                            cluster: seed containerName: etcd details: fileName: /var/lib/kubelet/pods/d86b08b7-3d10-49ae-a4d6-4fe9fa757c93/volumes/kubernetes.io~secret/etcd-client-tls/..2025_06_23_00_02_37.256397641/tls.crt, permissions: 640 kind: pod name: etcd-main-0 namespace: shoot--diki-comp--azure  
                                                            cluster: seed containerName: etcd details: fileName: /var/lib/kubelet/pods/d86b08b7-3d10-49ae-a4d6-4fe9fa757c93/volumes/kubernetes.io~secret/backup-restore-ca/..2025_06_23_00_02_37.1332383038/bundle.crt, permissions: 640 kind: pod name: etcd-main-0 namespace: shoot--diki-comp--azure  
                                                            cluster: seed containerName: etcd details: fileName: /var/lib/kubelet/pods/d86b08b7-3d10-49ae-a4d6-4fe9fa757c93/volumes/kubernetes.io~projected/kube-api-access-gardener/..2025_06_23_00_02_37.3272012549/ca.crt, permissions: 644 kind: pod name: etcd-main-0 namespace: shoot--diki-comp--azure  
                                                            cluster: seed containerName: backup-restore details: fileName: /var/lib/kubelet/pods/d86b08b7-3d10-49ae-a4d6-4fe9fa757c93/volumes/kubernetes.io~secret/backup-restore-server-tls/..2025_06_23_00_02_37.2487232432/tls.crt, permissions: 640 kind: pod name: etcd-main-0 namespace: shoot--diki-comp--azure  
                                                            cluster: seed containerName: backup-restore details: fileName: /var/lib/kubelet/pods/d86b08b7-3d10-49ae-a4d6-4fe9fa757c93/volumes/kubernetes.io~secret/etcd-ca/..2025_06_23_00_02_37.231883813/bundle.crt, permissions: 640 kind: pod name: etcd-main-0 namespace: shoot--diki-comp--azure  
                                                            cluster: seed containerName: backup-restore details: fileName: /var/lib/kubelet/pods/d86b08b7-3d10-49ae-a4d6-4fe9fa757c93/volumes/kubernetes.io~secret/etcd-client-tls/..2025_06_23_00_02_37.256397641/tls.crt, permissions: 640 kind: pod name: etcd-main-0 namespace: shoot--diki-comp--azure  
                                                            cluster: seed containerName: backup-restore details: fileName: /var/lib/kubelet/pods/d86b08b7-3d10-49ae-a4d6-4fe9fa757c93/volumes/kubernetes.io~projected/kube-api-access-gardener/..2025_06_23_00_02_37.3272012549/ca.crt, permissions: 644 kind: pod name: etcd-main-0 namespace: shoot--diki-comp--azure  
                                                            cluster: seed containerName: etcd details: fileName: /var/lib/kubelet/pods/74f71030-9c73-40a7-b50e-fb1bb70cb9a5/volumes/kubernetes.io~secret/etcd-ca/..2025_06_23_00_02_36.1146945202/bundle.crt, permissions: 640 kind: pod name: etcd-events-0 namespace: shoot--diki-comp--azure  
                                                            cluster: seed containerName: etcd details: fileName: /var/lib/kubelet/pods/74f71030-9c73-40a7-b50e-fb1bb70cb9a5/volumes/kubernetes.io~secret/etcd-server-tls/..2025_06_23_00_02_36.3673560748/tls.crt, permissions: 640 kind: pod name: etcd-events-0 namespace: shoot--diki-comp--azure  
                                                            cluster: seed containerName: etcd details: fileName: /var/lib/kubelet/pods/74f71030-9c73-40a7-b50e-fb1bb70cb9a5/volumes/kubernetes.io~secret/etcd-client-tls/..2025_06_23_00_02_36.3852713643/tls.crt, permissions: 640 kind: pod name: etcd-events-0 namespace: shoot--diki-comp--azure  
                                                            cluster: seed containerName: etcd details: fileName: /var/lib/kubelet/pods/74f71030-9c73-40a7-b50e-fb1bb70cb9a5/volumes/kubernetes.io~secret/backup-restore-ca/..2025_06_23_00_02_36.3194705379/bundle.crt, permissions: 640 kind: pod name: etcd-events-0 namespace: shoot--diki-comp--azure  
                                                            cluster: seed containerName: etcd details: fileName: /var/lib/kubelet/pods/74f71030-9c73-40a7-b50e-fb1bb70cb9a5/volumes/kubernetes.io~projected/kube-api-access-gardener/..2025_06_23_00_02_36.662581379/ca.crt, permissions: 644 kind: pod name: etcd-events-0 namespace: shoot--diki-comp--azure  
                                                            cluster: seed containerName: backup-restore details: fileName: /var/lib/kubelet/pods/74f71030-9c73-40a7-b50e-fb1bb70cb9a5/volumes/kubernetes.io~secret/backup-restore-server-tls/..2025_06_23_00_02_36.327312203/tls.crt, permissions: 640 kind: pod name: etcd-events-0 namespace: shoot--diki-comp--azure  
                                                            cluster: seed containerName: backup-restore details: fileName: /var/lib/kubelet/pods/74f71030-9c73-40a7-b50e-fb1bb70cb9a5/volumes/kubernetes.io~secret/etcd-ca/..2025_06_23_00_02_36.1146945202/bundle.crt, permissions: 640 kind: pod name: etcd-events-0 namespace: shoot--diki-comp--azure  
                                                            cluster: seed containerName: backup-restore details: fileName: /var/lib/kubelet/pods/74f71030-9c73-40a7-b50e-fb1bb70cb9a5/volumes/kubernetes.io~secret/etcd-client-tls/..2025_06_23_00_02_36.3852713643/tls.crt, permissions: 640 kind: pod name: etcd-events-0 namespace: shoot--diki-comp--azure  
                                                            cluster: seed containerName: backup-restore details: fileName: /var/lib/kubelet/pods/74f71030-9c73-40a7-b50e-fb1bb70cb9a5/volumes/kubernetes.io~projected/kube-api-access-gardener/..2025_06_23_00_02_36.662581379/ca.crt, permissions: 644 kind: pod name: etcd-events-0 namespace: shoot--diki-comp--azure  
                                                            cluster: shoot details: fileName: /var/lib/kubelet/pki/kubelet-client-2025-06-23-00-09-20.pem, permissions: 600 kind: node name: shoot--diki-comp--azure-worker-g7p4p-z3-66467-k6q5n  
                                                            cluster: shoot details: fileName: /var/lib/kubelet/pki/kubelet-server-2025-06-23-00-10-22.pem, permissions: 600 kind: node name: shoot--diki-comp--azure-worker-g7p4p-z3-66467-k6q5n  
                                                            cluster: shoot containerName: kube-proxy details: fileName: /var/lib/kubelet/pods/7f34a064-2a9b-48d4-a97f-57ed2fc7a389/volumes/kubernetes.io~projected/kube-api-access-gardener/..2025_06_23_00_09_26.3322732681/ca.crt, permissions: 644 kind: pod name: kube-proxy-worker-g7p4p-v1.31.8-7dnc5 namespace: kube-system  
                                                            cluster: shoot containerName: conntrack-fix details: fileName: /var/lib/kubelet/pods/7f34a064-2a9b-48d4-a97f-57ed2fc7a389/volumes/kubernetes.io~projected/kube-api-access-gardener/..2025_06_23_00_09_26.3322732681/ca.crt, permissions: 644 kind: pod name: kube-proxy-worker-g7p4p-v1.31.8-7dnc5 namespace: kube-system  
                                                            cluster: shoot containerName: cleanup details: fileName: /var/lib/kubelet/pods/7f34a064-2a9b-48d4-a97f-57ed2fc7a389/volumes/kubernetes.io~projected/kube-api-access-gardener/..2025_06_23_00_09_26.3322732681/ca.crt, permissions: 644 kind: pod name: kube-proxy-worker-g7p4p-v1.31.8-7dnc5 namespace: kube-system  
                                                            cluster: shoot containerName: kube-proxy-init details: fileName: /var/lib/kubelet/pods/7f34a064-2a9b-48d4-a97f-57ed2fc7a389/volumes/kubernetes.io~projected/kube-api-access-gardener/..2025_06_23_00_09_26.3322732681/ca.crt, permissions: 644 kind: pod name: kube-proxy-worker-g7p4p-v1.31.8-7dnc5 namespace: kube-system  
                                                         
                                                     
                                                    
                                                        gcp 
                                                        
                                                            cluster: seed containerName: etcd details: fileName: /var/lib/kubelet/pods/5b8aebf9-d079-4ec9-a1dc-f2e2adadf242/volumes/kubernetes.io~secret/etcd-ca/..2025_06_23_00_02_35.359863374/bundle.crt, permissions: 640 kind: pod name: etcd-main-0 namespace: shoot--diki-comp--gcp  
                                                            cluster: seed containerName: etcd details: fileName: /var/lib/kubelet/pods/5b8aebf9-d079-4ec9-a1dc-f2e2adadf242/volumes/kubernetes.io~secret/etcd-server-tls/..2025_06_23_00_02_35.761653683/tls.crt, permissions: 640 kind: pod name: etcd-main-0 namespace: shoot--diki-comp--gcp  
                                                            cluster: seed containerName: etcd details: fileName: /var/lib/kubelet/pods/5b8aebf9-d079-4ec9-a1dc-f2e2adadf242/volumes/kubernetes.io~secret/etcd-client-tls/..2025_06_23_00_02_35.270682216/tls.crt, permissions: 640 kind: pod name: etcd-main-0 namespace: shoot--diki-comp--gcp  
                                                            cluster: seed containerName: etcd details: fileName: /var/lib/kubelet/pods/5b8aebf9-d079-4ec9-a1dc-f2e2adadf242/volumes/kubernetes.io~secret/backup-restore-ca/..2025_06_23_00_02_35.2072965808/bundle.crt, permissions: 640 kind: pod name: etcd-main-0 namespace: shoot--diki-comp--gcp  
                                                            cluster: seed containerName: etcd details: fileName: /var/lib/kubelet/pods/5b8aebf9-d079-4ec9-a1dc-f2e2adadf242/volumes/kubernetes.io~projected/kube-api-access-gardener/..2025_06_23_00_02_35.3521445574/ca.crt, permissions: 644 kind: pod name: etcd-main-0 namespace: shoot--diki-comp--gcp  
                                                            cluster: seed containerName: backup-restore details: fileName: /var/lib/kubelet/pods/5b8aebf9-d079-4ec9-a1dc-f2e2adadf242/volumes/kubernetes.io~secret/backup-restore-server-tls/..2025_06_23_00_02_35.1035566417/tls.crt, permissions: 640 kind: pod name: etcd-main-0 namespace: shoot--diki-comp--gcp  
                                                            cluster: seed containerName: backup-restore details: fileName: /var/lib/kubelet/pods/5b8aebf9-d079-4ec9-a1dc-f2e2adadf242/volumes/kubernetes.io~secret/etcd-ca/..2025_06_23_00_02_35.359863374/bundle.crt, permissions: 640 kind: pod name: etcd-main-0 namespace: shoot--diki-comp--gcp  
                                                            cluster: seed containerName: backup-restore details: fileName: /var/lib/kubelet/pods/5b8aebf9-d079-4ec9-a1dc-f2e2adadf242/volumes/kubernetes.io~secret/etcd-client-tls/..2025_06_23_00_02_35.270682216/tls.crt, permissions: 640 kind: pod name: etcd-main-0 namespace: shoot--diki-comp--gcp  
                                                            cluster: seed containerName: backup-restore details: fileName: /var/lib/kubelet/pods/5b8aebf9-d079-4ec9-a1dc-f2e2adadf242/volumes/kubernetes.io~projected/kube-api-access-gardener/..2025_06_23_00_02_35.3521445574/ca.crt, permissions: 644 kind: pod name: etcd-main-0 namespace: shoot--diki-comp--gcp  
                                                            cluster: seed containerName: etcd details: fileName: /var/lib/kubelet/pods/56b8ee4f-315f-4054-af24-a9fd2f484963/volumes/kubernetes.io~secret/etcd-ca/..2025_06_23_00_02_35.3098522537/bundle.crt, permissions: 640 kind: pod name: etcd-events-0 namespace: shoot--diki-comp--gcp  
                                                            cluster: seed containerName: etcd details: fileName: /var/lib/kubelet/pods/56b8ee4f-315f-4054-af24-a9fd2f484963/volumes/kubernetes.io~secret/etcd-server-tls/..2025_06_23_00_02_35.3565116838/tls.crt, permissions: 640 kind: pod name: etcd-events-0 namespace: shoot--diki-comp--gcp  
                                                            cluster: seed containerName: etcd details: fileName: /var/lib/kubelet/pods/56b8ee4f-315f-4054-af24-a9fd2f484963/volumes/kubernetes.io~secret/etcd-client-tls/..2025_06_23_00_02_35.3308771745/tls.crt, permissions: 640 kind: pod name: etcd-events-0 namespace: shoot--diki-comp--gcp  
                                                            cluster: seed containerName: etcd details: fileName: /var/lib/kubelet/pods/56b8ee4f-315f-4054-af24-a9fd2f484963/volumes/kubernetes.io~secret/backup-restore-ca/..2025_06_23_00_02_35.4083445152/bundle.crt, permissions: 640 kind: pod name: etcd-events-0 namespace: shoot--diki-comp--gcp  
                                                            cluster: seed containerName: etcd details: fileName: /var/lib/kubelet/pods/56b8ee4f-315f-4054-af24-a9fd2f484963/volumes/kubernetes.io~projected/kube-api-access-gardener/..2025_06_23_00_02_35.4217059112/ca.crt, permissions: 644 kind: pod name: etcd-events-0 namespace: shoot--diki-comp--gcp  
                                                            cluster: seed containerName: backup-restore details: fileName: /var/lib/kubelet/pods/56b8ee4f-315f-4054-af24-a9fd2f484963/volumes/kubernetes.io~secret/backup-restore-server-tls/..2025_06_23_00_02_35.375113374/tls.crt, permissions: 640 kind: pod name: etcd-events-0 namespace: shoot--diki-comp--gcp  
                                                            cluster: seed containerName: backup-restore details: fileName: /var/lib/kubelet/pods/56b8ee4f-315f-4054-af24-a9fd2f484963/volumes/kubernetes.io~secret/etcd-ca/..2025_06_23_00_02_35.3098522537/bundle.crt, permissions: 640 kind: pod name: etcd-events-0 namespace: shoot--diki-comp--gcp  
                                                            cluster: seed containerName: backup-restore details: fileName: /var/lib/kubelet/pods/56b8ee4f-315f-4054-af24-a9fd2f484963/volumes/kubernetes.io~secret/etcd-client-tls/..2025_06_23_00_02_35.3308771745/tls.crt, permissions: 640 kind: pod name: etcd-events-0 namespace: shoot--diki-comp--gcp  
                                                            cluster: seed containerName: backup-restore details: fileName: /var/lib/kubelet/pods/56b8ee4f-315f-4054-af24-a9fd2f484963/volumes/kubernetes.io~projected/kube-api-access-gardener/..2025_06_23_00_02_35.4217059112/ca.crt, permissions: 644 kind: pod name: etcd-events-0 namespace: shoot--diki-comp--gcp  
                                                            cluster: seed containerName: kube-scheduler details: fileName: /var/lib/kubelet/pods/d1968ae3-bf95-4709-b100-13709ba484c9/volumes/kubernetes.io~projected/client-ca/..2025_06_23_00_22_41.2638774521/bundle.crt, permissions: 644 kind: pod name: kube-scheduler-7d978d746c-2vbm4 namespace: shoot--diki-comp--gcp  
                                                            cluster: seed containerName: kube-scheduler details: fileName: /var/lib/kubelet/pods/d1968ae3-bf95-4709-b100-13709ba484c9/volumes/kubernetes.io~secret/kube-scheduler-server/..2025_06_23_00_22_41.3181132458/tls.crt, permissions: 640 kind: pod name: kube-scheduler-7d978d746c-2vbm4 namespace: shoot--diki-comp--gcp  
                                                            cluster: seed containerName: kube-apiserver details: fileName: /var/lib/kubelet/pods/bcae6617-9cf5-48c4-a654-323e2fd06c94/volumes/kubernetes.io~secret/ca/..2025_06_23_00_05_00.1635859179/bundle.crt, permissions: 644 kind: pod name: kube-apiserver-789b87d9bc-m288k namespace: shoot--diki-comp--gcp  
                                                            cluster: seed containerName: kube-apiserver details: fileName: /var/lib/kubelet/pods/bcae6617-9cf5-48c4-a654-323e2fd06c94/volumes/kubernetes.io~secret/ca-client/..2025_06_23_00_05_00.3123507849/bundle.crt, permissions: 644 kind: pod name: kube-apiserver-789b87d9bc-m288k namespace: shoot--diki-comp--gcp  
                                                            cluster: seed containerName: kube-apiserver details: fileName: /var/lib/kubelet/pods/bcae6617-9cf5-48c4-a654-323e2fd06c94/volumes/kubernetes.io~secret/ca-front-proxy/..2025_06_23_00_05_00.3311897769/bundle.crt, permissions: 644 kind: pod name: kube-apiserver-789b87d9bc-m288k namespace: shoot--diki-comp--gcp  
                                                            cluster: seed containerName: kube-apiserver details: fileName: /var/lib/kubelet/pods/bcae6617-9cf5-48c4-a654-323e2fd06c94/volumes/kubernetes.io~secret/kube-aggregator/..2025_06_23_00_05_00.8440286/tls.crt, permissions: 640 kind: pod name: kube-apiserver-789b87d9bc-m288k namespace: shoot--diki-comp--gcp  
                                                            cluster: seed containerName: kube-apiserver details: fileName: /var/lib/kubelet/pods/bcae6617-9cf5-48c4-a654-323e2fd06c94/volumes/kubernetes.io~secret/server/..2025_06_23_00_05_00.2211691282/tls.crt, permissions: 640 kind: pod name: kube-apiserver-789b87d9bc-m288k namespace: shoot--diki-comp--gcp  
                                                            cluster: seed containerName: kube-apiserver details: fileName: /var/lib/kubelet/pods/bcae6617-9cf5-48c4-a654-323e2fd06c94/volumes/kubernetes.io~secret/ca-vpn/..2025_06_23_00_05_00.3200529218/bundle.crt, permissions: 644 kind: pod name: kube-apiserver-789b87d9bc-m288k namespace: shoot--diki-comp--gcp  
                                                            cluster: seed containerName: kube-apiserver details: fileName: /var/lib/kubelet/pods/bcae6617-9cf5-48c4-a654-323e2fd06c94/volumes/kubernetes.io~secret/ca-kubelet/..2025_06_23_00_05_00.1340282604/bundle.crt, permissions: 644 kind: pod name: kube-apiserver-789b87d9bc-m288k namespace: shoot--diki-comp--gcp  
                                                            cluster: seed containerName: kube-apiserver details: fileName: /var/lib/kubelet/pods/bcae6617-9cf5-48c4-a654-323e2fd06c94/volumes/kubernetes.io~secret/kubelet-client/..2025_06_23_00_05_00.3066470044/tls.crt, permissions: 640 kind: pod name: kube-apiserver-789b87d9bc-m288k namespace: shoot--diki-comp--gcp  
                                                            cluster: seed containerName: kube-apiserver details: fileName: /var/lib/kubelet/pods/bcae6617-9cf5-48c4-a654-323e2fd06c94/volumes/kubernetes.io~secret/ca-etcd/..2025_06_23_00_05_00.599344253/bundle.crt, permissions: 644 kind: pod name: kube-apiserver-789b87d9bc-m288k namespace: shoot--diki-comp--gcp  
                                                            cluster: seed containerName: kube-apiserver details: fileName: /var/lib/kubelet/pods/bcae6617-9cf5-48c4-a654-323e2fd06c94/volumes/kubernetes.io~secret/etcd-client/..2025_06_23_00_05_00.3665142686/tls.crt, permissions: 640 kind: pod name: kube-apiserver-789b87d9bc-m288k namespace: shoot--diki-comp--gcp  
                                                            cluster: seed containerName: kube-apiserver details: fileName: /var/lib/kubelet/pods/bcae6617-9cf5-48c4-a654-323e2fd06c94/volumes/kubernetes.io~secret/tls-sni-0/..2025_06_23_00_05_00.1355552674/tls.crt, permissions: 640 kind: pod name: kube-apiserver-789b87d9bc-m288k namespace: shoot--diki-comp--gcp  
                                                            cluster: seed containerName: kube-apiserver details: fileName: /var/lib/kubelet/pods/bcae6617-9cf5-48c4-a654-323e2fd06c94/volumes/kubernetes.io~secret/tls-sni-0/..2025_06_23_00_05_00.1355552674/ca.crt, permissions: 640 kind: pod name: kube-apiserver-789b87d9bc-m288k namespace: shoot--diki-comp--gcp  
                                                            cluster: seed containerName: kube-apiserver details: fileName: /var/lib/kubelet/pods/bcae6617-9cf5-48c4-a654-323e2fd06c94/volumes/kubernetes.io~secret/http-proxy/..2025_06_23_00_05_00.2267541296/tls.crt, permissions: 640 kind: pod name: kube-apiserver-789b87d9bc-m288k namespace: shoot--diki-comp--gcp  
                                                            cluster: seed containerName: kube-controller-manager details: fileName: /var/lib/kubelet/pods/7207bfe7-1315-42f2-8383-7b79afa8437d/volumes/kubernetes.io~secret/ca/..2025_06_23_00_10_41.4029468750/bundle.crt, permissions: 644 kind: pod name: kube-controller-manager-65cdccf875-lhhzw namespace: shoot--diki-comp--gcp  
                                                            cluster: seed containerName: kube-controller-manager details: fileName: /var/lib/kubelet/pods/7207bfe7-1315-42f2-8383-7b79afa8437d/volumes/kubernetes.io~secret/ca-client/..2025_06_23_00_10_41.2990537503/ca.crt, permissions: 640 kind: pod name: kube-controller-manager-65cdccf875-lhhzw namespace: shoot--diki-comp--gcp  
                                                            cluster: seed containerName: kube-controller-manager details: fileName: /var/lib/kubelet/pods/7207bfe7-1315-42f2-8383-7b79afa8437d/volumes/kubernetes.io~secret/server/..2025_06_23_00_10_41.2206626934/tls.crt, permissions: 640 kind: pod name: kube-controller-manager-65cdccf875-lhhzw namespace: shoot--diki-comp--gcp  
                                                            cluster: seed containerName: kube-controller-manager details: fileName: /var/lib/kubelet/pods/7207bfe7-1315-42f2-8383-7b79afa8437d/volumes/kubernetes.io~secret/ca-kubelet/..2025_06_23_00_10_41.1244180931/ca.crt, permissions: 640 kind: pod name: kube-controller-manager-65cdccf875-lhhzw namespace: shoot--diki-comp--gcp  
                                                            cluster: shoot details: fileName: /var/lib/kubelet/pki/kubelet-client-2025-06-23-00-07-48.pem, permissions: 600 kind: node name: shoot--diki-comp--gcp-worker-bex82-z1-5d9b4-8fp7q  
                                                            cluster: shoot details: fileName: /var/lib/kubelet/pki/kubelet-server-2025-06-23-00-08-19.pem, permissions: 600 kind: node name: shoot--diki-comp--gcp-worker-bex82-z1-5d9b4-8fp7q  
                                                            cluster: shoot containerName: kube-proxy details: fileName: /var/lib/kubelet/pods/4933cf73-66c0-4f8e-b07d-54a68fc93917/volumes/kubernetes.io~projected/kube-api-access-gardener/..2025_06_23_00_07_50.3593682193/ca.crt, permissions: 644 kind: pod name: kube-proxy-worker-bex82-v1.31.8-x9kg4 namespace: kube-system  
                                                            cluster: shoot containerName: conntrack-fix details: fileName: /var/lib/kubelet/pods/4933cf73-66c0-4f8e-b07d-54a68fc93917/volumes/kubernetes.io~projected/kube-api-access-gardener/..2025_06_23_00_07_50.3593682193/ca.crt, permissions: 644 kind: pod name: kube-proxy-worker-bex82-v1.31.8-x9kg4 namespace: kube-system  
                                                            cluster: shoot containerName: cleanup details: fileName: /var/lib/kubelet/pods/4933cf73-66c0-4f8e-b07d-54a68fc93917/volumes/kubernetes.io~projected/kube-api-access-gardener/..2025_06_23_00_07_50.3593682193/ca.crt, permissions: 644 kind: pod name: kube-proxy-worker-bex82-v1.31.8-x9kg4 namespace: kube-system  
                                                            cluster: shoot containerName: kube-proxy-init details: fileName: /var/lib/kubelet/pods/4933cf73-66c0-4f8e-b07d-54a68fc93917/volumes/kubernetes.io~projected/kube-api-access-gardener/..2025_06_23_00_07_50.3593682193/ca.crt, permissions: 644 kind: pod name: kube-proxy-worker-bex82-v1.31.8-x9kg4 namespace: kube-system  
                                                         
                                                     
                                                    
                                                        openstack 
                                                        
                                                            cluster: seed containerName: etcd details: fileName: /var/lib/kubelet/pods/7d71941f-a963-401d-b0e0-28ed7592fe7d/volumes/kubernetes.io~secret/etcd-ca/..2025_06_23_00_02_39.4052105237/bundle.crt, permissions: 640 kind: pod name: etcd-main-0 namespace: shoot--diki-comp--openstack  
                                                            cluster: seed containerName: etcd details: fileName: /var/lib/kubelet/pods/7d71941f-a963-401d-b0e0-28ed7592fe7d/volumes/kubernetes.io~secret/etcd-server-tls/..2025_06_23_00_02_39.149437060/tls.crt, permissions: 640 kind: pod name: etcd-main-0 namespace: shoot--diki-comp--openstack  
                                                            cluster: seed containerName: etcd details: fileName: /var/lib/kubelet/pods/7d71941f-a963-401d-b0e0-28ed7592fe7d/volumes/kubernetes.io~secret/etcd-client-tls/..2025_06_23_00_02_39.296248316/tls.crt, permissions: 640 kind: pod name: etcd-main-0 namespace: shoot--diki-comp--openstack  
                                                            cluster: seed containerName: etcd details: fileName: /var/lib/kubelet/pods/7d71941f-a963-401d-b0e0-28ed7592fe7d/volumes/kubernetes.io~secret/backup-restore-ca/..2025_06_23_00_02_39.2679800161/bundle.crt, permissions: 640 kind: pod name: etcd-main-0 namespace: shoot--diki-comp--openstack  
                                                            cluster: seed containerName: etcd details: fileName: /var/lib/kubelet/pods/7d71941f-a963-401d-b0e0-28ed7592fe7d/volumes/kubernetes.io~projected/kube-api-access-gardener/..2025_06_23_00_02_39.1703787134/ca.crt, permissions: 644 kind: pod name: etcd-main-0 namespace: shoot--diki-comp--openstack  
                                                            cluster: seed containerName: backup-restore details: fileName: /var/lib/kubelet/pods/7d71941f-a963-401d-b0e0-28ed7592fe7d/volumes/kubernetes.io~secret/backup-restore-server-tls/..2025_06_23_00_02_39.456523922/tls.crt, permissions: 640 kind: pod name: etcd-main-0 namespace: shoot--diki-comp--openstack  
                                                            cluster: seed containerName: backup-restore details: fileName: /var/lib/kubelet/pods/7d71941f-a963-401d-b0e0-28ed7592fe7d/volumes/kubernetes.io~secret/etcd-ca/..2025_06_23_00_02_39.4052105237/bundle.crt, permissions: 640 kind: pod name: etcd-main-0 namespace: shoot--diki-comp--openstack  
                                                            cluster: seed containerName: backup-restore details: fileName: /var/lib/kubelet/pods/7d71941f-a963-401d-b0e0-28ed7592fe7d/volumes/kubernetes.io~secret/etcd-client-tls/..2025_06_23_00_02_39.296248316/tls.crt, permissions: 640 kind: pod name: etcd-main-0 namespace: shoot--diki-comp--openstack  
                                                            cluster: seed containerName: backup-restore details: fileName: /var/lib/kubelet/pods/7d71941f-a963-401d-b0e0-28ed7592fe7d/volumes/kubernetes.io~projected/kube-api-access-gardener/..2025_06_23_00_02_39.1703787134/ca.crt, permissions: 644 kind: pod name: etcd-main-0 namespace: shoot--diki-comp--openstack  
                                                            cluster: seed containerName: etcd details: fileName: /var/lib/kubelet/pods/9c7e7507-c95f-4034-bb45-54d9a5a0061e/volumes/kubernetes.io~secret/etcd-ca/..2025_06_23_00_02_39.2818779423/bundle.crt, permissions: 640 kind: pod name: etcd-events-0 namespace: shoot--diki-comp--openstack  
                                                            cluster: seed containerName: etcd details: fileName: /var/lib/kubelet/pods/9c7e7507-c95f-4034-bb45-54d9a5a0061e/volumes/kubernetes.io~secret/etcd-server-tls/..2025_06_23_00_02_39.1241938029/tls.crt, permissions: 640 kind: pod name: etcd-events-0 namespace: shoot--diki-comp--openstack  
                                                            cluster: seed containerName: etcd details: fileName: /var/lib/kubelet/pods/9c7e7507-c95f-4034-bb45-54d9a5a0061e/volumes/kubernetes.io~secret/etcd-client-tls/..2025_06_23_00_02_39.2589051175/tls.crt, permissions: 640 kind: pod name: etcd-events-0 namespace: shoot--diki-comp--openstack  
                                                            cluster: seed containerName: etcd details: fileName: /var/lib/kubelet/pods/9c7e7507-c95f-4034-bb45-54d9a5a0061e/volumes/kubernetes.io~secret/backup-restore-ca/..2025_06_23_00_02_39.735587336/bundle.crt, permissions: 640 kind: pod name: etcd-events-0 namespace: shoot--diki-comp--openstack  
                                                            cluster: seed containerName: etcd details: fileName: /var/lib/kubelet/pods/9c7e7507-c95f-4034-bb45-54d9a5a0061e/volumes/kubernetes.io~projected/kube-api-access-gardener/..2025_06_23_00_02_39.3883414360/ca.crt, permissions: 644 kind: pod name: etcd-events-0 namespace: shoot--diki-comp--openstack  
                                                            cluster: seed containerName: backup-restore details: fileName: /var/lib/kubelet/pods/9c7e7507-c95f-4034-bb45-54d9a5a0061e/volumes/kubernetes.io~secret/backup-restore-server-tls/..2025_06_23_00_02_39.705338586/tls.crt, permissions: 640 kind: pod name: etcd-events-0 namespace: shoot--diki-comp--openstack  
                                                            cluster: seed containerName: backup-restore details: fileName: /var/lib/kubelet/pods/9c7e7507-c95f-4034-bb45-54d9a5a0061e/volumes/kubernetes.io~secret/etcd-ca/..2025_06_23_00_02_39.2818779423/bundle.crt, permissions: 640 kind: pod name: etcd-events-0 namespace: shoot--diki-comp--openstack  
                                                            cluster: seed containerName: backup-restore details: fileName: /var/lib/kubelet/pods/9c7e7507-c95f-4034-bb45-54d9a5a0061e/volumes/kubernetes.io~secret/etcd-client-tls/..2025_06_23_00_02_39.2589051175/tls.crt, permissions: 640 kind: pod name: etcd-events-0 namespace: shoot--diki-comp--openstack  
                                                            cluster: seed containerName: backup-restore details: fileName: /var/lib/kubelet/pods/9c7e7507-c95f-4034-bb45-54d9a5a0061e/volumes/kubernetes.io~projected/kube-api-access-gardener/..2025_06_23_00_02_39.3883414360/ca.crt, permissions: 644 kind: pod name: etcd-events-0 namespace: shoot--diki-comp--openstack  
                                                            cluster: seed containerName: kube-controller-manager details: fileName: /var/lib/kubelet/pods/0b27d4d8-1580-4d41-8c12-a56ef49072dc/volumes/kubernetes.io~secret/ca/..2025_06_23_00_12_57.3765708577/bundle.crt, permissions: 644 kind: pod name: kube-controller-manager-76f68f67cf-z8lm4 namespace: shoot--diki-comp--openstack  
                                                            cluster: seed containerName: kube-controller-manager details: fileName: /var/lib/kubelet/pods/0b27d4d8-1580-4d41-8c12-a56ef49072dc/volumes/kubernetes.io~secret/ca-client/..2025_06_23_00_12_57.3596785791/ca.crt, permissions: 640 kind: pod name: kube-controller-manager-76f68f67cf-z8lm4 namespace: shoot--diki-comp--openstack  
                                                            cluster: seed containerName: kube-controller-manager details: fileName: /var/lib/kubelet/pods/0b27d4d8-1580-4d41-8c12-a56ef49072dc/volumes/kubernetes.io~secret/server/..2025_06_23_00_12_57.4281910611/tls.crt, permissions: 640 kind: pod name: kube-controller-manager-76f68f67cf-z8lm4 namespace: shoot--diki-comp--openstack  
                                                            cluster: seed containerName: kube-controller-manager details: fileName: /var/lib/kubelet/pods/0b27d4d8-1580-4d41-8c12-a56ef49072dc/volumes/kubernetes.io~secret/ca-kubelet/..2025_06_23_00_12_57.775870841/ca.crt, permissions: 640 kind: pod name: kube-controller-manager-76f68f67cf-z8lm4 namespace: shoot--diki-comp--openstack  
                                                            cluster: seed containerName: kube-scheduler details: fileName: /var/lib/kubelet/pods/b2afa8e5-74e9-4932-af53-bf0fcfd84066/volumes/kubernetes.io~projected/client-ca/..2025_06_23_00_11_57.2527488857/bundle.crt, permissions: 644 kind: pod name: kube-scheduler-785644b95f-fzldg namespace: shoot--diki-comp--openstack  
                                                            cluster: seed containerName: kube-scheduler details: fileName: /var/lib/kubelet/pods/b2afa8e5-74e9-4932-af53-bf0fcfd84066/volumes/kubernetes.io~secret/kube-scheduler-server/..2025_06_23_00_11_57.748288227/tls.crt, permissions: 640 kind: pod name: kube-scheduler-785644b95f-fzldg namespace: shoot--diki-comp--openstack  
                                                            cluster: seed containerName: kube-apiserver details: fileName: /var/lib/kubelet/pods/4a414212-471d-49e1-ba69-657ac6fd352a/volumes/kubernetes.io~secret/ca/..2025_06_23_00_05_31.3801277659/bundle.crt, permissions: 644 kind: pod name: kube-apiserver-5ffd79587b-574wj namespace: shoot--diki-comp--openstack  
                                                            cluster: seed containerName: kube-apiserver details: fileName: /var/lib/kubelet/pods/4a414212-471d-49e1-ba69-657ac6fd352a/volumes/kubernetes.io~secret/ca-client/..2025_06_23_00_05_31.316180318/bundle.crt, permissions: 644 kind: pod name: kube-apiserver-5ffd79587b-574wj namespace: shoot--diki-comp--openstack  
                                                            cluster: seed containerName: kube-apiserver details: fileName: /var/lib/kubelet/pods/4a414212-471d-49e1-ba69-657ac6fd352a/volumes/kubernetes.io~secret/ca-front-proxy/..2025_06_23_00_05_31.1046019673/bundle.crt, permissions: 644 kind: pod name: kube-apiserver-5ffd79587b-574wj namespace: shoot--diki-comp--openstack  
                                                            cluster: seed containerName: kube-apiserver details: fileName: /var/lib/kubelet/pods/4a414212-471d-49e1-ba69-657ac6fd352a/volumes/kubernetes.io~secret/kube-aggregator/..2025_06_23_00_05_31.974579027/tls.crt, permissions: 640 kind: pod name: kube-apiserver-5ffd79587b-574wj namespace: shoot--diki-comp--openstack  
                                                            cluster: seed containerName: kube-apiserver details: fileName: /var/lib/kubelet/pods/4a414212-471d-49e1-ba69-657ac6fd352a/volumes/kubernetes.io~secret/server/..2025_06_23_00_05_31.110607305/tls.crt, permissions: 640 kind: pod name: kube-apiserver-5ffd79587b-574wj namespace: shoot--diki-comp--openstack  
                                                            cluster: seed containerName: kube-apiserver details: fileName: /var/lib/kubelet/pods/4a414212-471d-49e1-ba69-657ac6fd352a/volumes/kubernetes.io~secret/ca-vpn/..2025_06_23_00_05_31.1571181539/bundle.crt, permissions: 644 kind: pod name: kube-apiserver-5ffd79587b-574wj namespace: shoot--diki-comp--openstack  
                                                            cluster: seed containerName: kube-apiserver details: fileName: /var/lib/kubelet/pods/4a414212-471d-49e1-ba69-657ac6fd352a/volumes/kubernetes.io~secret/ca-kubelet/..2025_06_23_00_05_31.1055204524/bundle.crt, permissions: 644 kind: pod name: kube-apiserver-5ffd79587b-574wj namespace: shoot--diki-comp--openstack  
                                                            cluster: seed containerName: kube-apiserver details: fileName: /var/lib/kubelet/pods/4a414212-471d-49e1-ba69-657ac6fd352a/volumes/kubernetes.io~secret/kubelet-client/..2025_06_23_00_05_31.529535444/tls.crt, permissions: 640 kind: pod name: kube-apiserver-5ffd79587b-574wj namespace: shoot--diki-comp--openstack  
                                                            cluster: seed containerName: kube-apiserver details: fileName: /var/lib/kubelet/pods/4a414212-471d-49e1-ba69-657ac6fd352a/volumes/kubernetes.io~secret/ca-etcd/..2025_06_23_00_05_31.3135557557/bundle.crt, permissions: 644 kind: pod name: kube-apiserver-5ffd79587b-574wj namespace: shoot--diki-comp--openstack  
                                                            cluster: seed containerName: kube-apiserver details: fileName: /var/lib/kubelet/pods/4a414212-471d-49e1-ba69-657ac6fd352a/volumes/kubernetes.io~secret/etcd-client/..2025_06_23_00_05_31.3982193628/tls.crt, permissions: 640 kind: pod name: kube-apiserver-5ffd79587b-574wj namespace: shoot--diki-comp--openstack  
                                                            cluster: seed containerName: kube-apiserver details: fileName: /var/lib/kubelet/pods/4a414212-471d-49e1-ba69-657ac6fd352a/volumes/kubernetes.io~secret/tls-sni-0/..2025_06_23_00_05_31.1069974019/tls.crt, permissions: 640 kind: pod name: kube-apiserver-5ffd79587b-574wj namespace: shoot--diki-comp--openstack  
                                                            cluster: seed containerName: kube-apiserver details: fileName: /var/lib/kubelet/pods/4a414212-471d-49e1-ba69-657ac6fd352a/volumes/kubernetes.io~secret/tls-sni-0/..2025_06_23_00_05_31.1069974019/ca.crt, permissions: 640 kind: pod name: kube-apiserver-5ffd79587b-574wj namespace: shoot--diki-comp--openstack  
                                                            cluster: seed containerName: kube-apiserver details: fileName: /var/lib/kubelet/pods/4a414212-471d-49e1-ba69-657ac6fd352a/volumes/kubernetes.io~secret/http-proxy/..2025_06_23_00_05_31.3012580451/tls.crt, permissions: 640 kind: pod name: kube-apiserver-5ffd79587b-574wj namespace: shoot--diki-comp--openstack  
                                                            cluster: shoot details: fileName: /var/lib/kubelet/pki/kubelet-client-2025-06-23-00-10-31.pem, permissions: 600 kind: node name: shoot--diki-comp--openstack-worker-dqty2-z1-64f7d-jllmm  
                                                            cluster: shoot details: fileName: /var/lib/kubelet/pki/kubelet-server-2025-06-23-00-10-38.pem, permissions: 600 kind: node name: shoot--diki-comp--openstack-worker-dqty2-z1-64f7d-jllmm  
                                                            cluster: shoot containerName: kube-proxy details: fileName: /var/lib/kubelet/pods/c1afd1ba-2ab9-43f3-a306-c810e02cd47d/volumes/kubernetes.io~projected/kube-api-access-gardener/..2025_06_23_00_10_32.3842156420/ca.crt, permissions: 644 kind: pod name: kube-proxy-worker-dqty2-v1.31.8-9sx78 namespace: kube-system  
                                                            cluster: shoot containerName: conntrack-fix details: fileName: /var/lib/kubelet/pods/c1afd1ba-2ab9-43f3-a306-c810e02cd47d/volumes/kubernetes.io~projected/kube-api-access-gardener/..2025_06_23_00_10_32.3842156420/ca.crt, permissions: 644 kind: pod name: kube-proxy-worker-dqty2-v1.31.8-9sx78 namespace: kube-system  
                                                            cluster: shoot containerName: cleanup details: fileName: /var/lib/kubelet/pods/c1afd1ba-2ab9-43f3-a306-c810e02cd47d/volumes/kubernetes.io~projected/kube-api-access-gardener/..2025_06_23_00_10_32.3842156420/ca.crt, permissions: 644 kind: pod name: kube-proxy-worker-dqty2-v1.31.8-9sx78 namespace: kube-system  
                                                            cluster: shoot containerName: kube-proxy-init details: fileName: /var/lib/kubelet/pods/c1afd1ba-2ab9-43f3-a306-c810e02cd47d/volumes/kubernetes.io~projected/kube-api-access-gardener/..2025_06_23_00_10_32.3842156420/ca.crt, permissions: 644 kind: pod name: kube-proxy-worker-dqty2-v1.31.8-9sx78 namespace: kube-system  
                                                         
                                                     
                                                 
                                             
                                         
                                     
                                    
                                        242467 (Medium) - The Kubernetes PKI keys must have file permissions set to 600 or more restrictive. 
                                        
                                            
                                                File has expected permissions 
                                                
                                                    
                                                        aws 
                                                        
                                                            cluster: seed containerName: etcd details: fileName: /var/lib/kubelet/pods/e9a97103-bea9-4174-9f2f-d11c7dee0b81/volumes/kubernetes.io~secret/etcd-server-tls/..2025_06_23_00_02_28.941742504/tls.key, permissions: 640 kind: pod name: etcd-main-0 namespace: shoot--diki-comp--aws  
                                                            cluster: seed containerName: etcd details: fileName: /var/lib/kubelet/pods/e9a97103-bea9-4174-9f2f-d11c7dee0b81/volumes/kubernetes.io~secret/etcd-client-tls/..2025_06_23_00_02_28.581061777/tls.key, permissions: 640 kind: pod name: etcd-main-0 namespace: shoot--diki-comp--aws  
                                                            cluster: seed containerName: backup-restore details: fileName: /var/lib/kubelet/pods/e9a97103-bea9-4174-9f2f-d11c7dee0b81/volumes/kubernetes.io~secret/backup-restore-server-tls/..2025_06_23_00_02_28.137193825/tls.key, permissions: 640 kind: pod name: etcd-main-0 namespace: shoot--diki-comp--aws  
                                                            cluster: seed containerName: backup-restore details: fileName: /var/lib/kubelet/pods/e9a97103-bea9-4174-9f2f-d11c7dee0b81/volumes/kubernetes.io~secret/etcd-client-tls/..2025_06_23_00_02_28.581061777/tls.key, permissions: 640 kind: pod name: etcd-main-0 namespace: shoot--diki-comp--aws  
                                                            cluster: seed containerName: kube-controller-manager details: fileName: /var/lib/kubelet/pods/c423b64c-cb58-46fa-a956-022b9b1664c6/volumes/kubernetes.io~secret/ca-client/..2025_06_23_00_16_39.4293646224/ca.key, permissions: 640 kind: pod name: kube-controller-manager-7c9bc75987-cqgs4 namespace: shoot--diki-comp--aws  
                                                            cluster: seed containerName: kube-controller-manager details: fileName: /var/lib/kubelet/pods/c423b64c-cb58-46fa-a956-022b9b1664c6/volumes/kubernetes.io~secret/server/..2025_06_23_00_16_39.867879351/tls.key, permissions: 640 kind: pod name: kube-controller-manager-7c9bc75987-cqgs4 namespace: shoot--diki-comp--aws  
                                                            cluster: seed containerName: kube-controller-manager details: fileName: /var/lib/kubelet/pods/c423b64c-cb58-46fa-a956-022b9b1664c6/volumes/kubernetes.io~secret/ca-kubelet/..2025_06_23_00_16_39.254040933/ca.key, permissions: 640 kind: pod name: kube-controller-manager-7c9bc75987-cqgs4 namespace: shoot--diki-comp--aws  
                                                            cluster: seed containerName: kube-apiserver details: fileName: /var/lib/kubelet/pods/42db629f-9d43-492e-92df-f2a0ac97d2b6/volumes/kubernetes.io~secret/service-account-key-bundle/..2025_06_23_00_09_39.1536096673/bundle.key, permissions: 640 kind: pod name: kube-apiserver-6d847f96d4-82qpt namespace: shoot--diki-comp--aws  
                                                            cluster: seed containerName: kube-apiserver details: fileName: /var/lib/kubelet/pods/42db629f-9d43-492e-92df-f2a0ac97d2b6/volumes/kubernetes.io~secret/kube-aggregator/..2025_06_23_00_09_39.3585741192/tls.key, permissions: 640 kind: pod name: kube-apiserver-6d847f96d4-82qpt namespace: shoot--diki-comp--aws  
                                                            cluster: seed containerName: kube-apiserver details: fileName: /var/lib/kubelet/pods/42db629f-9d43-492e-92df-f2a0ac97d2b6/volumes/kubernetes.io~secret/server/..2025_06_23_00_09_39.2101876528/tls.key, permissions: 640 kind: pod name: kube-apiserver-6d847f96d4-82qpt namespace: shoot--diki-comp--aws  
                                                            cluster: seed containerName: kube-apiserver details: fileName: /var/lib/kubelet/pods/42db629f-9d43-492e-92df-f2a0ac97d2b6/volumes/kubernetes.io~secret/kubelet-client/..2025_06_23_00_09_39.2120918226/tls.key, permissions: 640 kind: pod name: kube-apiserver-6d847f96d4-82qpt namespace: shoot--diki-comp--aws  
                                                            cluster: seed containerName: kube-apiserver details: fileName: /var/lib/kubelet/pods/42db629f-9d43-492e-92df-f2a0ac97d2b6/volumes/kubernetes.io~secret/etcd-client/..2025_06_23_00_09_39.3841361014/tls.key, permissions: 640 kind: pod name: kube-apiserver-6d847f96d4-82qpt namespace: shoot--diki-comp--aws  
                                                            cluster: seed containerName: kube-apiserver details: fileName: /var/lib/kubelet/pods/42db629f-9d43-492e-92df-f2a0ac97d2b6/volumes/kubernetes.io~secret/tls-sni-0/..2025_06_23_00_09_39.1534744055/tls.key, permissions: 640 kind: pod name: kube-apiserver-6d847f96d4-82qpt namespace: shoot--diki-comp--aws  
                                                            cluster: seed containerName: kube-apiserver details: fileName: /var/lib/kubelet/pods/42db629f-9d43-492e-92df-f2a0ac97d2b6/volumes/kubernetes.io~secret/http-proxy/..2025_06_23_00_09_39.1635279459/tls.key, permissions: 640 kind: pod name: kube-apiserver-6d847f96d4-82qpt namespace: shoot--diki-comp--aws  
                                                            cluster: seed containerName: etcd details: fileName: /var/lib/kubelet/pods/8500de88-870c-4453-a9d3-673fe2e83591/volumes/kubernetes.io~secret/etcd-server-tls/..2025_06_23_00_02_28.1081429868/tls.key, permissions: 640 kind: pod name: etcd-events-0 namespace: shoot--diki-comp--aws  
                                                            cluster: seed containerName: etcd details: fileName: /var/lib/kubelet/pods/8500de88-870c-4453-a9d3-673fe2e83591/volumes/kubernetes.io~secret/etcd-client-tls/..2025_06_23_00_02_28.830733358/tls.key, permissions: 640 kind: pod name: etcd-events-0 namespace: shoot--diki-comp--aws  
                                                            cluster: seed containerName: backup-restore details: fileName: /var/lib/kubelet/pods/8500de88-870c-4453-a9d3-673fe2e83591/volumes/kubernetes.io~secret/backup-restore-server-tls/..2025_06_23_00_02_28.1357612372/tls.key, permissions: 640 kind: pod name: etcd-events-0 namespace: shoot--diki-comp--aws  
                                                            cluster: seed containerName: backup-restore details: fileName: /var/lib/kubelet/pods/8500de88-870c-4453-a9d3-673fe2e83591/volumes/kubernetes.io~secret/etcd-client-tls/..2025_06_23_00_02_28.830733358/tls.key, permissions: 640 kind: pod name: etcd-events-0 namespace: shoot--diki-comp--aws  
                                                            cluster: seed containerName: kube-scheduler details: fileName: /var/lib/kubelet/pods/06134fb6-0360-493d-adc6-38d710393b11/volumes/kubernetes.io~secret/kube-scheduler-server/..2025_06_23_00_10_38.1273189684/tls.key, permissions: 640 kind: pod name: kube-scheduler-5854d54c7c-2b7mv namespace: shoot--diki-comp--aws  
                                                            cluster: shoot details: fileName: /var/lib/kubelet/pki/kubelet-client-2025-06-23-00-08-33.pem, permissions: 600 kind: node name: ip-IP-Address.eu-west-1.compute.internal  
                                                            cluster: shoot details: fileName: /var/lib/kubelet/pki/kubelet-server-2025-06-23-00-08-57.pem, permissions: 600 kind: node name: ip-IP-Address.eu-west-1.compute.internal  
                                                         
                                                     
                                                    
                                                        azure 
                                                        
                                                            cluster: seed containerName: etcd details: fileName: /var/lib/kubelet/pods/74f71030-9c73-40a7-b50e-fb1bb70cb9a5/volumes/kubernetes.io~secret/etcd-server-tls/..2025_06_23_00_02_36.3673560748/tls.key, permissions: 640 kind: pod name: etcd-events-0 namespace: shoot--diki-comp--azure  
                                                            cluster: seed containerName: etcd details: fileName: /var/lib/kubelet/pods/74f71030-9c73-40a7-b50e-fb1bb70cb9a5/volumes/kubernetes.io~secret/etcd-client-tls/..2025_06_23_00_02_36.3852713643/tls.key, permissions: 640 kind: pod name: etcd-events-0 namespace: shoot--diki-comp--azure  
                                                            cluster: seed containerName: backup-restore details: fileName: /var/lib/kubelet/pods/74f71030-9c73-40a7-b50e-fb1bb70cb9a5/volumes/kubernetes.io~secret/backup-restore-server-tls/..2025_06_23_00_02_36.327312203/tls.key, permissions: 640 kind: pod name: etcd-events-0 namespace: shoot--diki-comp--azure  
                                                            cluster: seed containerName: backup-restore details: fileName: /var/lib/kubelet/pods/74f71030-9c73-40a7-b50e-fb1bb70cb9a5/volumes/kubernetes.io~secret/etcd-client-tls/..2025_06_23_00_02_36.3852713643/tls.key, permissions: 640 kind: pod name: etcd-events-0 namespace: shoot--diki-comp--azure  
                                                            cluster: seed containerName: kube-apiserver details: fileName: /var/lib/kubelet/pods/19e8d0fb-e648-458d-9824-7002ba098bce/volumes/kubernetes.io~secret/service-account-key-bundle/..2025_06_23_00_14_46.504056214/bundle.key, permissions: 640 kind: pod name: kube-apiserver-d66f4d44f-tm4cs namespace: shoot--diki-comp--azure  
                                                            cluster: seed containerName: kube-apiserver details: fileName: /var/lib/kubelet/pods/19e8d0fb-e648-458d-9824-7002ba098bce/volumes/kubernetes.io~secret/kube-aggregator/..2025_06_23_00_14_46.2139614939/tls.key, permissions: 640 kind: pod name: kube-apiserver-d66f4d44f-tm4cs namespace: shoot--diki-comp--azure  
                                                            cluster: seed containerName: kube-apiserver details: fileName: /var/lib/kubelet/pods/19e8d0fb-e648-458d-9824-7002ba098bce/volumes/kubernetes.io~secret/server/..2025_06_23_00_14_46.2186093174/tls.key, permissions: 640 kind: pod name: kube-apiserver-d66f4d44f-tm4cs namespace: shoot--diki-comp--azure  
                                                            cluster: seed containerName: kube-apiserver details: fileName: /var/lib/kubelet/pods/19e8d0fb-e648-458d-9824-7002ba098bce/volumes/kubernetes.io~secret/kubelet-client/..2025_06_23_00_14_46.2446316166/tls.key, permissions: 640 kind: pod name: kube-apiserver-d66f4d44f-tm4cs namespace: shoot--diki-comp--azure  
                                                            cluster: seed containerName: kube-apiserver details: fileName: /var/lib/kubelet/pods/19e8d0fb-e648-458d-9824-7002ba098bce/volumes/kubernetes.io~secret/etcd-client/..2025_06_23_00_14_46.1466414181/tls.key, permissions: 640 kind: pod name: kube-apiserver-d66f4d44f-tm4cs namespace: shoot--diki-comp--azure  
                                                            cluster: seed containerName: kube-apiserver details: fileName: /var/lib/kubelet/pods/19e8d0fb-e648-458d-9824-7002ba098bce/volumes/kubernetes.io~secret/tls-sni-0/..2025_06_23_00_14_46.1021198322/tls.key, permissions: 640 kind: pod name: kube-apiserver-d66f4d44f-tm4cs namespace: shoot--diki-comp--azure  
                                                            cluster: seed containerName: kube-apiserver details: fileName: /var/lib/kubelet/pods/19e8d0fb-e648-458d-9824-7002ba098bce/volumes/kubernetes.io~secret/http-proxy/..2025_06_23_00_14_46.234968055/tls.key, permissions: 640 kind: pod name: kube-apiserver-d66f4d44f-tm4cs namespace: shoot--diki-comp--azure  
                                                            cluster: seed containerName: kube-controller-manager details: fileName: /var/lib/kubelet/pods/8a5510fe-a88b-42cc-b90a-1d8f9487d887/volumes/kubernetes.io~secret/ca-client/..2025_06_23_00_19_46.1556017874/ca.key, permissions: 640 kind: pod name: kube-controller-manager-7d869c84b8-kz7dm namespace: shoot--diki-comp--azure  
                                                            cluster: seed containerName: kube-controller-manager details: fileName: /var/lib/kubelet/pods/8a5510fe-a88b-42cc-b90a-1d8f9487d887/volumes/kubernetes.io~secret/server/..2025_06_23_00_19_46.3137963724/tls.key, permissions: 640 kind: pod name: kube-controller-manager-7d869c84b8-kz7dm namespace: shoot--diki-comp--azure  
                                                            cluster: seed containerName: kube-controller-manager details: fileName: /var/lib/kubelet/pods/8a5510fe-a88b-42cc-b90a-1d8f9487d887/volumes/kubernetes.io~secret/ca-kubelet/..2025_06_23_00_19_46.2139875717/ca.key, permissions: 640 kind: pod name: kube-controller-manager-7d869c84b8-kz7dm namespace: shoot--diki-comp--azure  
                                                            cluster: seed containerName: kube-scheduler details: fileName: /var/lib/kubelet/pods/8afdd891-92eb-4c6a-aac5-9a324987f6ad/volumes/kubernetes.io~secret/kube-scheduler-server/..2025_06_23_00_14_46.366944806/tls.key, permissions: 640 kind: pod name: kube-scheduler-67fdbc4569-h6j7v namespace: shoot--diki-comp--azure  
                                                            cluster: seed containerName: etcd details: fileName: /var/lib/kubelet/pods/d86b08b7-3d10-49ae-a4d6-4fe9fa757c93/volumes/kubernetes.io~secret/etcd-server-tls/..2025_06_23_00_02_37.4111409223/tls.key, permissions: 640 kind: pod name: etcd-main-0 namespace: shoot--diki-comp--azure  
                                                            cluster: seed containerName: etcd details: fileName: /var/lib/kubelet/pods/d86b08b7-3d10-49ae-a4d6-4fe9fa757c93/volumes/kubernetes.io~secret/etcd-client-tls/..2025_06_23_00_02_37.256397641/tls.key, permissions: 640 kind: pod name: etcd-main-0 namespace: shoot--diki-comp--azure  
                                                            cluster: seed containerName: backup-restore details: fileName: /var/lib/kubelet/pods/d86b08b7-3d10-49ae-a4d6-4fe9fa757c93/volumes/kubernetes.io~secret/backup-restore-server-tls/..2025_06_23_00_02_37.2487232432/tls.key, permissions: 640 kind: pod name: etcd-main-0 namespace: shoot--diki-comp--azure  
                                                            cluster: seed containerName: backup-restore details: fileName: /var/lib/kubelet/pods/d86b08b7-3d10-49ae-a4d6-4fe9fa757c93/volumes/kubernetes.io~secret/etcd-client-tls/..2025_06_23_00_02_37.256397641/tls.key, permissions: 640 kind: pod name: etcd-main-0 namespace: shoot--diki-comp--azure  
                                                            cluster: shoot details: fileName: /var/lib/kubelet/pki/kubelet-client-2025-06-23-00-09-20.pem, permissions: 600 kind: node name: shoot--diki-comp--azure-worker-g7p4p-z3-66467-k6q5n  
                                                            cluster: shoot details: fileName: /var/lib/kubelet/pki/kubelet-server-2025-06-23-00-10-22.pem, permissions: 600 kind: node name: shoot--diki-comp--azure-worker-g7p4p-z3-66467-k6q5n  
                                                         
                                                     
                                                    
                                                        gcp 
                                                        
                                                            cluster: seed containerName: etcd details: fileName: /var/lib/kubelet/pods/56b8ee4f-315f-4054-af24-a9fd2f484963/volumes/kubernetes.io~secret/etcd-server-tls/..2025_06_23_00_02_35.3565116838/tls.key, permissions: 640 kind: pod name: etcd-events-0 namespace: shoot--diki-comp--gcp  
                                                            cluster: seed containerName: etcd details: fileName: /var/lib/kubelet/pods/56b8ee4f-315f-4054-af24-a9fd2f484963/volumes/kubernetes.io~secret/etcd-client-tls/..2025_06_23_00_02_35.3308771745/tls.key, permissions: 640 kind: pod name: etcd-events-0 namespace: shoot--diki-comp--gcp  
                                                            cluster: seed containerName: backup-restore details: fileName: /var/lib/kubelet/pods/56b8ee4f-315f-4054-af24-a9fd2f484963/volumes/kubernetes.io~secret/backup-restore-server-tls/..2025_06_23_00_02_35.375113374/tls.key, permissions: 640 kind: pod name: etcd-events-0 namespace: shoot--diki-comp--gcp  
                                                            cluster: seed containerName: backup-restore details: fileName: /var/lib/kubelet/pods/56b8ee4f-315f-4054-af24-a9fd2f484963/volumes/kubernetes.io~secret/etcd-client-tls/..2025_06_23_00_02_35.3308771745/tls.key, permissions: 640 kind: pod name: etcd-events-0 namespace: shoot--diki-comp--gcp  
                                                            cluster: seed containerName: kube-scheduler details: fileName: /var/lib/kubelet/pods/d1968ae3-bf95-4709-b100-13709ba484c9/volumes/kubernetes.io~secret/kube-scheduler-server/..2025_06_23_00_22_41.3181132458/tls.key, permissions: 640 kind: pod name: kube-scheduler-7d978d746c-2vbm4 namespace: shoot--diki-comp--gcp  
                                                            cluster: seed containerName: kube-apiserver details: fileName: /var/lib/kubelet/pods/bcae6617-9cf5-48c4-a654-323e2fd06c94/volumes/kubernetes.io~secret/service-account-key-bundle/..2025_06_23_00_05_00.527676273/bundle.key, permissions: 640 kind: pod name: kube-apiserver-789b87d9bc-m288k namespace: shoot--diki-comp--gcp  
                                                            cluster: seed containerName: kube-apiserver details: fileName: /var/lib/kubelet/pods/bcae6617-9cf5-48c4-a654-323e2fd06c94/volumes/kubernetes.io~secret/kube-aggregator/..2025_06_23_00_05_00.8440286/tls.key, permissions: 640 kind: pod name: kube-apiserver-789b87d9bc-m288k namespace: shoot--diki-comp--gcp  
                                                            cluster: seed containerName: kube-apiserver details: fileName: /var/lib/kubelet/pods/bcae6617-9cf5-48c4-a654-323e2fd06c94/volumes/kubernetes.io~secret/server/..2025_06_23_00_05_00.2211691282/tls.key, permissions: 640 kind: pod name: kube-apiserver-789b87d9bc-m288k namespace: shoot--diki-comp--gcp  
                                                            cluster: seed containerName: kube-apiserver details: fileName: /var/lib/kubelet/pods/bcae6617-9cf5-48c4-a654-323e2fd06c94/volumes/kubernetes.io~secret/kubelet-client/..2025_06_23_00_05_00.3066470044/tls.key, permissions: 640 kind: pod name: kube-apiserver-789b87d9bc-m288k namespace: shoot--diki-comp--gcp  
                                                            cluster: seed containerName: kube-apiserver details: fileName: /var/lib/kubelet/pods/bcae6617-9cf5-48c4-a654-323e2fd06c94/volumes/kubernetes.io~secret/etcd-client/..2025_06_23_00_05_00.3665142686/tls.key, permissions: 640 kind: pod name: kube-apiserver-789b87d9bc-m288k namespace: shoot--diki-comp--gcp  
                                                            cluster: seed containerName: kube-apiserver details: fileName: /var/lib/kubelet/pods/bcae6617-9cf5-48c4-a654-323e2fd06c94/volumes/kubernetes.io~secret/tls-sni-0/..2025_06_23_00_05_00.1355552674/tls.key, permissions: 640 kind: pod name: kube-apiserver-789b87d9bc-m288k namespace: shoot--diki-comp--gcp  
                                                            cluster: seed containerName: kube-apiserver details: fileName: /var/lib/kubelet/pods/bcae6617-9cf5-48c4-a654-323e2fd06c94/volumes/kubernetes.io~secret/http-proxy/..2025_06_23_00_05_00.2267541296/tls.key, permissions: 640 kind: pod name: kube-apiserver-789b87d9bc-m288k namespace: shoot--diki-comp--gcp  
                                                            cluster: seed containerName: kube-controller-manager details: fileName: /var/lib/kubelet/pods/7207bfe7-1315-42f2-8383-7b79afa8437d/volumes/kubernetes.io~secret/ca-client/..2025_06_23_00_10_41.2990537503/ca.key, permissions: 640 kind: pod name: kube-controller-manager-65cdccf875-lhhzw namespace: shoot--diki-comp--gcp  
                                                            cluster: seed containerName: kube-controller-manager details: fileName: /var/lib/kubelet/pods/7207bfe7-1315-42f2-8383-7b79afa8437d/volumes/kubernetes.io~secret/server/..2025_06_23_00_10_41.2206626934/tls.key, permissions: 640 kind: pod name: kube-controller-manager-65cdccf875-lhhzw namespace: shoot--diki-comp--gcp  
                                                            cluster: seed containerName: kube-controller-manager details: fileName: /var/lib/kubelet/pods/7207bfe7-1315-42f2-8383-7b79afa8437d/volumes/kubernetes.io~secret/ca-kubelet/..2025_06_23_00_10_41.1244180931/ca.key, permissions: 640 kind: pod name: kube-controller-manager-65cdccf875-lhhzw namespace: shoot--diki-comp--gcp  
                                                            cluster: seed containerName: backup-restore details: fileName: /var/lib/kubelet/pods/5b8aebf9-d079-4ec9-a1dc-f2e2adadf242/volumes/kubernetes.io~secret/backup-restore-server-tls/..2025_06_23_00_02_35.1035566417/tls.key, permissions: 640 kind: pod name: etcd-main-0 namespace: shoot--diki-comp--gcp  
                                                            cluster: seed containerName: backup-restore details: fileName: /var/lib/kubelet/pods/5b8aebf9-d079-4ec9-a1dc-f2e2adadf242/volumes/kubernetes.io~secret/etcd-client-tls/..2025_06_23_00_02_35.270682216/tls.key, permissions: 640 kind: pod name: etcd-main-0 namespace: shoot--diki-comp--gcp  
                                                            cluster: seed containerName: etcd details: fileName: /var/lib/kubelet/pods/5b8aebf9-d079-4ec9-a1dc-f2e2adadf242/volumes/kubernetes.io~secret/etcd-server-tls/..2025_06_23_00_02_35.761653683/tls.key, permissions: 640 kind: pod name: etcd-main-0 namespace: shoot--diki-comp--gcp  
                                                            cluster: seed containerName: etcd details: fileName: /var/lib/kubelet/pods/5b8aebf9-d079-4ec9-a1dc-f2e2adadf242/volumes/kubernetes.io~secret/etcd-client-tls/..2025_06_23_00_02_35.270682216/tls.key, permissions: 640 kind: pod name: etcd-main-0 namespace: shoot--diki-comp--gcp  
                                                            cluster: shoot details: fileName: /var/lib/kubelet/pki/kubelet-client-2025-06-23-00-07-48.pem, permissions: 600 kind: node name: shoot--diki-comp--gcp-worker-bex82-z1-5d9b4-8fp7q  
                                                            cluster: shoot details: fileName: /var/lib/kubelet/pki/kubelet-server-2025-06-23-00-08-19.pem, permissions: 600 kind: node name: shoot--diki-comp--gcp-worker-bex82-z1-5d9b4-8fp7q  
                                                         
                                                     
                                                    
                                                        openstack 
                                                        
                                                            cluster: seed containerName: kube-controller-manager details: fileName: /var/lib/kubelet/pods/0b27d4d8-1580-4d41-8c12-a56ef49072dc/volumes/kubernetes.io~secret/ca-client/..2025_06_23_00_12_57.3596785791/ca.key, permissions: 640 kind: pod name: kube-controller-manager-76f68f67cf-z8lm4 namespace: shoot--diki-comp--openstack  
                                                            cluster: seed containerName: kube-controller-manager details: fileName: /var/lib/kubelet/pods/0b27d4d8-1580-4d41-8c12-a56ef49072dc/volumes/kubernetes.io~secret/server/..2025_06_23_00_12_57.4281910611/tls.key, permissions: 640 kind: pod name: kube-controller-manager-76f68f67cf-z8lm4 namespace: shoot--diki-comp--openstack  
                                                            cluster: seed containerName: kube-controller-manager details: fileName: /var/lib/kubelet/pods/0b27d4d8-1580-4d41-8c12-a56ef49072dc/volumes/kubernetes.io~secret/ca-kubelet/..2025_06_23_00_12_57.775870841/ca.key, permissions: 640 kind: pod name: kube-controller-manager-76f68f67cf-z8lm4 namespace: shoot--diki-comp--openstack  
                                                            cluster: seed containerName: kube-scheduler details: fileName: /var/lib/kubelet/pods/b2afa8e5-74e9-4932-af53-bf0fcfd84066/volumes/kubernetes.io~secret/kube-scheduler-server/..2025_06_23_00_11_57.748288227/tls.key, permissions: 640 kind: pod name: kube-scheduler-785644b95f-fzldg namespace: shoot--diki-comp--openstack  
                                                            cluster: seed containerName: kube-apiserver details: fileName: /var/lib/kubelet/pods/4a414212-471d-49e1-ba69-657ac6fd352a/volumes/kubernetes.io~secret/service-account-key-bundle/..2025_06_23_00_05_31.2877576203/bundle.key, permissions: 640 kind: pod name: kube-apiserver-5ffd79587b-574wj namespace: shoot--diki-comp--openstack  
                                                            cluster: seed containerName: kube-apiserver details: fileName: /var/lib/kubelet/pods/4a414212-471d-49e1-ba69-657ac6fd352a/volumes/kubernetes.io~secret/kube-aggregator/..2025_06_23_00_05_31.974579027/tls.key, permissions: 640 kind: pod name: kube-apiserver-5ffd79587b-574wj namespace: shoot--diki-comp--openstack  
                                                            cluster: seed containerName: kube-apiserver details: fileName: /var/lib/kubelet/pods/4a414212-471d-49e1-ba69-657ac6fd352a/volumes/kubernetes.io~secret/server/..2025_06_23_00_05_31.110607305/tls.key, permissions: 640 kind: pod name: kube-apiserver-5ffd79587b-574wj namespace: shoot--diki-comp--openstack  
                                                            cluster: seed containerName: kube-apiserver details: fileName: /var/lib/kubelet/pods/4a414212-471d-49e1-ba69-657ac6fd352a/volumes/kubernetes.io~secret/kubelet-client/..2025_06_23_00_05_31.529535444/tls.key, permissions: 640 kind: pod name: kube-apiserver-5ffd79587b-574wj namespace: shoot--diki-comp--openstack  
                                                            cluster: seed containerName: kube-apiserver details: fileName: /var/lib/kubelet/pods/4a414212-471d-49e1-ba69-657ac6fd352a/volumes/kubernetes.io~secret/etcd-client/..2025_06_23_00_05_31.3982193628/tls.key, permissions: 640 kind: pod name: kube-apiserver-5ffd79587b-574wj namespace: shoot--diki-comp--openstack  
                                                            cluster: seed containerName: kube-apiserver details: fileName: /var/lib/kubelet/pods/4a414212-471d-49e1-ba69-657ac6fd352a/volumes/kubernetes.io~secret/tls-sni-0/..2025_06_23_00_05_31.1069974019/tls.key, permissions: 640 kind: pod name: kube-apiserver-5ffd79587b-574wj namespace: shoot--diki-comp--openstack  
                                                            cluster: seed containerName: kube-apiserver details: fileName: /var/lib/kubelet/pods/4a414212-471d-49e1-ba69-657ac6fd352a/volumes/kubernetes.io~secret/http-proxy/..2025_06_23_00_05_31.3012580451/tls.key, permissions: 640 kind: pod name: kube-apiserver-5ffd79587b-574wj namespace: shoot--diki-comp--openstack  
                                                            cluster: seed containerName: etcd details: fileName: /var/lib/kubelet/pods/7d71941f-a963-401d-b0e0-28ed7592fe7d/volumes/kubernetes.io~secret/etcd-server-tls/..2025_06_23_00_02_39.149437060/tls.key, permissions: 640 kind: pod name: etcd-main-0 namespace: shoot--diki-comp--openstack  
                                                            cluster: seed containerName: etcd details: fileName: /var/lib/kubelet/pods/7d71941f-a963-401d-b0e0-28ed7592fe7d/volumes/kubernetes.io~secret/etcd-client-tls/..2025_06_23_00_02_39.296248316/tls.key, permissions: 640 kind: pod name: etcd-main-0 namespace: shoot--diki-comp--openstack  
                                                            cluster: seed containerName: backup-restore details: fileName: /var/lib/kubelet/pods/7d71941f-a963-401d-b0e0-28ed7592fe7d/volumes/kubernetes.io~secret/backup-restore-server-tls/..2025_06_23_00_02_39.456523922/tls.key, permissions: 640 kind: pod name: etcd-main-0 namespace: shoot--diki-comp--openstack  
                                                            cluster: seed containerName: backup-restore details: fileName: /var/lib/kubelet/pods/7d71941f-a963-401d-b0e0-28ed7592fe7d/volumes/kubernetes.io~secret/etcd-client-tls/..2025_06_23_00_02_39.296248316/tls.key, permissions: 640 kind: pod name: etcd-main-0 namespace: shoot--diki-comp--openstack  
                                                            cluster: seed containerName: etcd details: fileName: /var/lib/kubelet/pods/9c7e7507-c95f-4034-bb45-54d9a5a0061e/volumes/kubernetes.io~secret/etcd-server-tls/..2025_06_23_00_02_39.1241938029/tls.key, permissions: 640 kind: pod name: etcd-events-0 namespace: shoot--diki-comp--openstack  
                                                            cluster: seed containerName: etcd details: fileName: /var/lib/kubelet/pods/9c7e7507-c95f-4034-bb45-54d9a5a0061e/volumes/kubernetes.io~secret/etcd-client-tls/..2025_06_23_00_02_39.2589051175/tls.key, permissions: 640 kind: pod name: etcd-events-0 namespace: shoot--diki-comp--openstack  
                                                            cluster: seed containerName: backup-restore details: fileName: /var/lib/kubelet/pods/9c7e7507-c95f-4034-bb45-54d9a5a0061e/volumes/kubernetes.io~secret/backup-restore-server-tls/..2025_06_23_00_02_39.705338586/tls.key, permissions: 640 kind: pod name: etcd-events-0 namespace: shoot--diki-comp--openstack  
                                                            cluster: seed containerName: backup-restore details: fileName: /var/lib/kubelet/pods/9c7e7507-c95f-4034-bb45-54d9a5a0061e/volumes/kubernetes.io~secret/etcd-client-tls/..2025_06_23_00_02_39.2589051175/tls.key, permissions: 640 kind: pod name: etcd-events-0 namespace: shoot--diki-comp--openstack  
                                                            cluster: shoot details: fileName: /var/lib/kubelet/pki/kubelet-client-2025-06-23-00-10-31.pem, permissions: 600 kind: node name: shoot--diki-comp--openstack-worker-dqty2-z1-64f7d-jllmm  
                                                            cluster: shoot details: fileName: /var/lib/kubelet/pki/kubelet-server-2025-06-23-00-10-38.pem, permissions: 600 kind: node name: shoot--diki-comp--openstack-worker-dqty2-z1-64f7d-jllmm  
                                                         
                                                     
                                                 
                                             
                                         
                                     
                                    
                                        245541 (Medium) - Kubernetes Kubelet must not disable timeouts. 
                                        
                                            
                                                Option streamingConnectionIdleTimeout set to allowed value. 
                                                
                                                    
                                                        aws 
                                                        
                                                            kind: node name: ip-IP-Address.eu-west-1.compute.internal  
                                                            kind: node name: ip-IP-Address.eu-west-1.compute.internal  
                                                         
                                                     
                                                    
                                                        azure 
                                                        
                                                            kind: node name: shoot--diki-comp--azure-worker-g7p4p-z3-66467-k6q5n  
                                                            kind: node name: shoot--diki-comp--azure-worker-g7p4p-z3-66467-xzlbf  
                                                         
                                                     
                                                    
                                                        gcp 
                                                        
                                                            kind: node name: shoot--diki-comp--gcp-worker-bex82-z1-5d9b4-8fp7q  
                                                            kind: node name: shoot--diki-comp--gcp-worker-bex82-z1-5d9b4-xjxdz  
                                                         
                                                     
                                                    
                                                        openstack 
                                                        
                                                            kind: node name: shoot--diki-comp--openstack-worker-dqty2-z1-64f7d-jllmm  
                                                            kind: node name: shoot--diki-comp--openstack-worker-dqty2-z1-64f7d-wmcjr  
                                                         
                                                     
                                                 
                                             
                                         
                                     
                                    
                                        245542 (High) - Kubernetes API Server must disable basic authentication to protect information in transit. 
                                        
                                            
                                                Option basic-auth-file has not been set. 
                                                
                                                    
                                                        aws 
                                                        
                                                            kind: deployment name: kube-apiserver namespace: shoot--diki-comp--aws  
                                                         
                                                     
                                                    
                                                        azure 
                                                        
                                                            kind: deployment name: kube-apiserver namespace: shoot--diki-comp--azure  
                                                         
                                                     
                                                    
                                                        gcp 
                                                        
                                                            kind: deployment name: kube-apiserver namespace: shoot--diki-comp--gcp  
                                                         
                                                     
                                                    
                                                        openstack 
                                                        
                                                            kind: deployment name: kube-apiserver namespace: shoot--diki-comp--openstack  
                                                         
                                                     
                                                 
                                             
                                         
                                     
                                    
                                        245544 (High) - Kubernetes endpoints must use approved organizational certificate and key pair to protect information in transit. 
                                        
                                            
                                                Option kubelet-client-certificate set. 
                                                
                                                    
                                                        aws 
                                                        
                                                            kind: deployment name: kube-apiserver namespace: shoot--diki-comp--aws  
                                                         
                                                     
                                                    
                                                        azure 
                                                        
                                                            kind: deployment name: kube-apiserver namespace: shoot--diki-comp--azure  
                                                         
                                                     
                                                    
                                                        gcp 
                                                        
                                                            kind: deployment name: kube-apiserver namespace: shoot--diki-comp--gcp  
                                                         
                                                     
                                                    
                                                        openstack 
                                                        
                                                            kind: deployment name: kube-apiserver namespace: shoot--diki-comp--openstack  
                                                         
                                                     
                                                 
                                             
                                            
                                                Option kubelet-client-key set. 
                                                
                                                    
                                                        aws 
                                                        
                                                            kind: deployment name: kube-apiserver namespace: shoot--diki-comp--aws  
                                                         
                                                     
                                                    
                                                        azure 
                                                        
                                                            kind: deployment name: kube-apiserver namespace: shoot--diki-comp--azure  
                                                         
                                                     
                                                    
                                                        gcp 
                                                        
                                                            kind: deployment name: kube-apiserver namespace: shoot--diki-comp--gcp  
                                                         
                                                     
                                                    
                                                        openstack 
                                                        
                                                            kind: deployment name: kube-apiserver namespace: shoot--diki-comp--openstack  
                                                         
                                                     
                                                 
                                             
                                         
                                     
                                    
                                        254800 (High) - Kubernetes must have a Pod Security Admission control file configured. 
                                        
                                            
                                                PodSecurity is properly configured 
                                                
                                                    
                                                        aws 
                                                        
                                                            kind: PodSecurityConfiguration  
                                                         
                                                     
                                                    
                                                        azure 
                                                        
                                                            kind: PodSecurityConfiguration  
                                                         
                                                     
                                                    
                                                        gcp 
                                                        
                                                            kind: PodSecurityConfiguration  
                                                         
                                                     
                                                    
                                                        openstack 
                                                        
                                                            kind: PodSecurityConfiguration  
                                                         
                                                     
                                                 
                                             
                                         
                                     
                                 
                             
                         
                        
                            
                                🔵 Skipped 
                                
                                    
                                        242380 (Medium) - The Kubernetes etcd must use TLS to protect the confidentiality of sensitive data during electronic dissemination. 
                                        
                                            
                                                ETCD runs as a single instance, peer communication options are not used. 
                                                
                                                    
                                                        aws 
                                                        
                                                            kind: statefulSet name: etcd-main namespace: shoot--diki-comp--aws  
                                                            kind: statefulSet name: etcd-events namespace: shoot--diki-comp--aws  
                                                         
                                                     
                                                    
                                                        azure 
                                                        
                                                            kind: statefulSet name: etcd-main namespace: shoot--diki-comp--azure  
                                                            kind: statefulSet name: etcd-events namespace: shoot--diki-comp--azure  
                                                         
                                                     
                                                    
                                                        gcp 
                                                        
                                                            kind: statefulSet name: etcd-main namespace: shoot--diki-comp--gcp  
                                                            kind: statefulSet name: etcd-events namespace: shoot--diki-comp--gcp  
                                                         
                                                     
                                                    
                                                        openstack 
                                                        
                                                            kind: statefulSet name: etcd-main namespace: shoot--diki-comp--openstack  
                                                            kind: statefulSet name: etcd-events namespace: shoot--diki-comp--openstack  
                                                         
                                                     
                                                 
                                             
                                         
                                     
                                    
                                        242384 (Medium) - The Kubernetes Scheduler must have secure binding. 
                                        
                                            
                                                The Kubernetes Scheduler runs in a container which already has limited access to network interfaces. In addition ingress traffic to the Kubernetes Scheduler is restricted via network policies, making an unintended exposure less likely. 
                                                
                                             
                                         
                                     
                                    
                                        242385 (Medium) - The Kubernetes Controller Manager must have secure binding. 
                                        
                                            
                                                The Kubernetes Controller Manager runs in a container which already has limited access to network interfaces. In addition ingress traffic to the Kubernetes Controller Manager is restricted via network policies, making an unintended exposure less likely. 
                                                
                                             
                                         
                                     
                                    
                                        242396 (Medium) - Kubernetes Kubectl cp command must give expected access and results. 
                                        
                                            
                                                "kubectl" is not installed into control plane pods or worker nodes and Gardener does not offer Kubernetes v1.12 or older. 
                                                
                                             
                                         
                                     
                                    
                                        242398 (Medium) - Kubernetes DynamicAuditing must not be enabled. 
                                        
                                            
                                                Option feature-gates.DynamicAuditing removed in Kubernetes v1.19. 
                                                
                                             
                                         
                                     
                                    
                                        242399 (Medium) - Kubernetes DynamicKubeletConfig must not be enabled. 
                                        
                                            
                                                Option feature-gates.DynamicKubeletConfig removed in Kubernetes v1.26. 
                                                
                                             
                                         
                                     
                                    
                                        242405 (Medium) - Kubernetes manifests must be owned by root. 
                                        
                                            
                                                Gardener does not deploy any control plane component as systemd processes or static pod. 
                                                
                                             
                                         
                                     
                                    
                                        242408 (Medium) - The Kubernetes manifest files must have least privileges. 
                                        
                                            
                                                Gardener does not deploy any control plane component as systemd processes or static pod. 
                                                
                                             
                                         
                                     
                                    
                                        242410 (Medium) - The Kubernetes API Server must enforce ports, protocols, and services (PPS) that adhere to the Ports, Protocols, and Services Management Category Assurance List (PPSM CAL). 
                                        
                                            
                                                Cannot be tested and should be enforced organizationally. Gardener uses a minimum of known and automatically opened/used/created ports/protocols/services (PPSM stands for Ports, Protocols, Service Management). 
                                                
                                             
                                         
                                     
                                    
                                        242411 (Medium) - The Kubernetes Scheduler must enforce ports, protocols, and services (PPS) that adhere to the Ports, Protocols, and Services Management Category Assurance List (PPSM CAL). 
                                        
                                            
                                                Cannot be tested and should be enforced organizationally. Gardener uses a minimum of known and automatically opened/used/created ports/protocols/services (PPSM stands for Ports, Protocols, Service Management). 
                                                
                                             
                                         
                                     
                                    
                                        242412 (Medium) - The Kubernetes Controllers must enforce ports, protocols, and services (PPS) that adhere to the Ports, Protocols, and Services Management Category Assurance List (PPSM CAL). 
                                        
                                            
                                                Cannot be tested and should be enforced organizationally. Gardener uses a minimum of known and automatically opened/used/created ports/protocols/services (PPSM stands for Ports, Protocols, Service Management). 
                                                
                                             
                                         
                                     
                                    
                                        242413 (Medium) - The Kubernetes etcd must enforce ports, protocols, and services (PPS) that adhere to the Ports, Protocols, and Services Management Category Assurance List (PPSM CAL). 
                                        
                                            
                                                Cannot be tested and should be enforced organizationally. Gardener uses a minimum of known and automatically opened/used/created ports/protocols/services (PPSM stands for Ports, Protocols, Service Management). 
                                                
                                             
                                         
                                     
                                    
                                        242426 (Medium) - Kubernetes etcd must enable client authentication to secure service. 
                                        
                                            
                                                ETCD runs as a single instance, peer communication options are not used. 
                                                
                                                    
                                                        aws 
                                                        
                                                            kind: statefulSet name: etcd-main namespace: shoot--diki-comp--aws  
                                                            kind: statefulSet name: etcd-events namespace: shoot--diki-comp--aws  
                                                         
                                                     
                                                    
                                                        azure 
                                                        
                                                            kind: statefulSet name: etcd-main namespace: shoot--diki-comp--azure  
                                                            kind: statefulSet name: etcd-events namespace: shoot--diki-comp--azure  
                                                         
                                                     
                                                    
                                                        gcp 
                                                        
                                                            kind: statefulSet name: etcd-main namespace: shoot--diki-comp--gcp  
                                                            kind: statefulSet name: etcd-events namespace: shoot--diki-comp--gcp  
                                                         
                                                     
                                                    
                                                        openstack 
                                                        
                                                            kind: statefulSet name: etcd-main namespace: shoot--diki-comp--openstack  
                                                            kind: statefulSet name: etcd-events namespace: shoot--diki-comp--openstack  
                                                         
                                                     
                                                 
                                             
                                         
                                     
                                    
                                        242432 (Medium) - Kubernetes etcd must have peer-cert-file set for secure communication. 
                                        
                                            
                                                ETCD runs as a single instance, peer communication options are not used. 
                                                
                                                    
                                                        aws 
                                                        
                                                            kind: statefulSet name: etcd-main namespace: shoot--diki-comp--aws  
                                                            kind: statefulSet name: etcd-events namespace: shoot--diki-comp--aws  
                                                         
                                                     
                                                    
                                                        azure 
                                                        
                                                            kind: statefulSet name: etcd-main namespace: shoot--diki-comp--azure  
                                                            kind: statefulSet name: etcd-events namespace: shoot--diki-comp--azure  
                                                         
                                                     
                                                    
                                                        gcp 
                                                        
                                                            kind: statefulSet name: etcd-main namespace: shoot--diki-comp--gcp  
                                                            kind: statefulSet name: etcd-events namespace: shoot--diki-comp--gcp  
                                                         
                                                     
                                                    
                                                        openstack 
                                                        
                                                            kind: statefulSet name: etcd-main namespace: shoot--diki-comp--openstack  
                                                            kind: statefulSet name: etcd-events namespace: shoot--diki-comp--openstack  
                                                         
                                                     
                                                 
                                             
                                         
                                     
                                    
                                        242433 (Medium) - Kubernetes etcd must have a peer-key-file set for secure communication. 
                                        
                                            
                                                ETCD runs as a single instance, peer communication options are not used. 
                                                
                                                    
                                                        aws 
                                                        
                                                            kind: statefulSet name: etcd-main namespace: shoot--diki-comp--aws  
                                                            kind: statefulSet name: etcd-events namespace: shoot--diki-comp--aws  
                                                         
                                                     
                                                    
                                                        azure 
                                                        
                                                            kind: statefulSet name: etcd-main namespace: shoot--diki-comp--azure  
                                                            kind: statefulSet name: etcd-events namespace: shoot--diki-comp--azure  
                                                         
                                                     
                                                    
                                                        gcp 
                                                        
                                                            kind: statefulSet name: etcd-main namespace: shoot--diki-comp--gcp  
                                                            kind: statefulSet name: etcd-events namespace: shoot--diki-comp--gcp  
                                                         
                                                     
                                                    
                                                        openstack 
                                                        
                                                            kind: statefulSet name: etcd-main namespace: shoot--diki-comp--openstack  
                                                            kind: statefulSet name: etcd-events namespace: shoot--diki-comp--openstack  
                                                         
                                                     
                                                 
                                             
                                         
                                     
                                    
                                        242437 (High) - Kubernetes must have a pod security policy set. 
                                        
                                            
                                                PSPs are removed in K8s version 1.25. 
                                                
                                             
                                         
                                     
                                    
                                        242443 (Medium) - Kubernetes must contain the latest updates as authorized by IAVMs, CTOs, DTMs, and STIGs. 
                                        
                                            
                                                Scanning/patching security vulnerabilities should be enforced organizationally. Security vulnerability scanning should be automated and maintainers should be informed automatically. 
                                                
                                             
                                         
                                     
                                    
                                        242444 (Medium) - Kubernetes component manifests must be owned by root. 
                                        
                                            
                                                Rule is duplicate of "242405" 
                                                
                                             
                                         
                                     
                                    
                                        242454 (Medium) - Kubernetes kubeadm.conf must be owned by root. 
                                        
                                            
                                                Gardener does not use "kubeadm" and also does not store any "main config" anywhere in seed or shoot (flow/component logic built-in/in-code). 
                                                
                                             
                                         
                                     
                                    
                                        242455 (Medium) - Kubernetes kubeadm.conf must have file permissions set to 644 or more restrictive. 
                                        
                                            
                                                Gardener does not use "kubeadm" and also does not store any "main config" anywhere in seed or shoot (flow/component logic built-in/in-code). 
                                                
                                             
                                         
                                     
                                    
                                        242456 (Medium) - Kubernetes kubelet config must have file permissions set to 644 or more restrictive. 
                                        
                                            
                                                Rule is duplicate of "242452". 
                                                
                                             
                                         
                                     
                                    
                                        242457 (Medium) - Kubernetes kubelet config must be owned by root. 
                                        
                                            
                                                Rule is duplicate of "242453". 
                                                
                                             
                                         
                                     
                                    
                                        242465 (Medium) - Kubernetes API Server audit log path must be set. 
                                        
                                            
                                                Rule is duplicate of "242402" 
                                                
                                             
                                         
                                     
                                    
                                        254801 (High) - Kubernetes must enable PodSecurity admission controller on static pods and Kubelets. 
                                        
                                            
                                                Option featureGates.PodSecurity was made GA in v1.25 and removed in v1.28. 
                                                
                                             
                                         
                                     
                                 
                             
                         
                        
                            
                                🔵 Accepted 
                                
                                    
                                        242402 (Medium) - The Kubernetes API Server must have an audit log path set. 
                                        
                                            
                                                Gardener can integrate with different audit logging solutions. 
                                                
                                             
                                         
                                     
                                    
                                        242403 (Medium) - The Kubernetes API Server must generate audit records that identify what type of event has occurred, identify the source of the event, contain the event results, identify any users, and identify any containers associated with the event. 
                                        
                                            
                                                Gardener can integrate with different audit logging solutions. 
                                                
                                             
                                         
                                     
                                    
                                        242414 (Medium) - The Kubernetes cluster must use non-privileged host ports for user pods. 
                                        
                                            
                                                Node local dns requires port 53 in order to operate properly. 
                                                
                                                    
                                                        aws 
                                                        
                                                            cluster: shoot container: node-cache details: port: 53 kind: pod name: node-local-dns-mnx5f namespace: kube-system  
                                                            cluster: shoot container: node-cache details: port: 53 kind: pod name: node-local-dns-mnx5f namespace: kube-system  
                                                            cluster: shoot container: node-cache details: port: 53 kind: pod name: node-local-dns-pjrjg namespace: kube-system  
                                                            cluster: shoot container: node-cache details: port: 53 kind: pod name: node-local-dns-pjrjg namespace: kube-system  
                                                         
                                                     
                                                    
                                                        azure 
                                                        
                                                            cluster: shoot container: node-cache details: port: 53 kind: pod name: node-local-dns-d6lgp namespace: kube-system  
                                                            cluster: shoot container: node-cache details: port: 53 kind: pod name: node-local-dns-d6lgp namespace: kube-system  
                                                            cluster: shoot container: node-cache details: port: 53 kind: pod name: node-local-dns-r6zzr namespace: kube-system  
                                                            cluster: shoot container: node-cache details: port: 53 kind: pod name: node-local-dns-r6zzr namespace: kube-system  
                                                         
                                                     
                                                    
                                                        gcp 
                                                        
                                                            cluster: shoot container: node-cache details: port: 53 kind: pod name: node-local-dns-f29m2 namespace: kube-system  
                                                            cluster: shoot container: node-cache details: port: 53 kind: pod name: node-local-dns-f29m2 namespace: kube-system  
                                                            cluster: shoot container: node-cache details: port: 53 kind: pod name: node-local-dns-srwg9 namespace: kube-system  
                                                            cluster: shoot container: node-cache details: port: 53 kind: pod name: node-local-dns-srwg9 namespace: kube-system  
                                                         
                                                     
                                                    
                                                        openstack 
                                                        
                                                            cluster: shoot container: node-cache details: port: 53 kind: pod name: node-local-dns-57bpm namespace: kube-system  
                                                            cluster: shoot container: node-cache details: port: 53 kind: pod name: node-local-dns-57bpm namespace: kube-system  
                                                            cluster: shoot container: node-cache details: port: 53 kind: pod name: node-local-dns-8b6dg namespace: kube-system  
                                                            cluster: shoot container: node-cache details: port: 53 kind: pod name: node-local-dns-8b6dg namespace: kube-system  
                                                         
                                                     
                                                 
                                             
                                         
                                     
                                    
                                        242462 (Medium) - The Kubernetes API Server must be set to audit log max size. 
                                        
                                            
                                                Gardener can integrate with different audit logging solutions. 
                                                
                                             
                                         
                                     
                                    
                                        242463 (Medium) - The Kubernetes API Server must be set to audit log maximum backup. 
                                        
                                            
                                                Gardener can integrate with different audit logging solutions. 
                                                
                                             
                                         
                                     
                                    
                                        242464 (Medium) - The Kubernetes API Server audit log retention must be set. 
                                        
                                            
                                                Gardener can integrate with different audit logging solutions. 
                                                
                                             
                                         
                                     
                                    
                                        245543 (High) - Kubernetes API Server must disable token authentication to protect information in transit. 
                                        
                                            
                                                All defined tokens are accepted. 
                                                
                                                    
                                                        aws 
                                                        
                                                            kind: deployment name: kube-apiserver namespace: shoot--diki-comp--aws  
                                                         
                                                     
                                                    
                                                        azure 
                                                        
                                                            kind: deployment name: kube-apiserver namespace: shoot--diki-comp--azure  
                                                         
                                                     
                                                    
                                                        gcp 
                                                        
                                                            kind: deployment name: kube-apiserver namespace: shoot--diki-comp--gcp  
                                                         
                                                     
                                                    
                                                        openstack 
                                                        
                                                            kind: deployment name: kube-apiserver namespace: shoot--diki-comp--openstack  
                                                         
                                                     
                                                 
                                             
                                         
                                     
                                 
                             
                         
                     
                 
             
            
                Provider Managed Kubernetes 
                Evaluated targets 
                
                    aws  (gardenerVersion: v1.121.1, projectName: diki-comp, time: 06-23-2025 00:22:41)azure  (gardenerVersion: v1.121.1, projectName: diki-comp, time: 06-23-2025 00:24:13)gcp  (gardenerVersion: v1.121.1, projectName: diki-comp, time: 06-23-2025 00:25:57)openstack  (gardenerVersion: v1.121.1, projectName: diki-comp, time: 06-23-2025 00:28:18) 
                
                    
                        v0.1.0 Security Hardened Kubernetes Cluster  (9x Passed 🟢, 5x Accepted 🔵, 1x Failed 🔴)
                            
                                🟢 Passed 
                                
                                    
                                        2000 (High) - Ingress and egress traffic must be restricted by default. 
                                        
                                            
                                                Ingress traffic is denied by default. 
                                                
                                                    
                                                        aws 
                                                        
                                                            kind: networkPolicy name: deny-all namespace: kube-public  
                                                            kind: networkPolicy name: deny-all namespace: default  
                                                            kind: networkPolicy name: deny-all namespace: kube-node-lease  
                                                         
                                                     
                                                    
                                                        azure 
                                                        
                                                            kind: networkPolicy name: deny-all namespace: default  
                                                            kind: networkPolicy name: deny-all namespace: kube-node-lease  
                                                            kind: networkPolicy name: deny-all namespace: kube-public  
                                                         
                                                     
                                                    
                                                        gcp 
                                                        
                                                            kind: networkPolicy name: deny-all namespace: default  
                                                            kind: networkPolicy name: deny-all namespace: kube-node-lease  
                                                            kind: networkPolicy name: deny-all namespace: kube-public  
                                                         
                                                     
                                                    
                                                        openstack 
                                                        
                                                            kind: networkPolicy name: deny-all namespace: default  
                                                            kind: networkPolicy name: deny-all namespace: kube-node-lease  
                                                            kind: networkPolicy name: deny-all namespace: kube-public  
                                                         
                                                     
                                                 
                                             
                                            
                                                Egress traffic is denied by default. 
                                                
                                                    
                                                        aws 
                                                        
                                                            kind: networkPolicy name: deny-all namespace: kube-public  
                                                            kind: networkPolicy name: deny-all namespace: default  
                                                            kind: networkPolicy name: deny-all namespace: kube-node-lease  
                                                         
                                                     
                                                    
                                                        azure 
                                                        
                                                            kind: networkPolicy name: deny-all namespace: default  
                                                            kind: networkPolicy name: deny-all namespace: kube-node-lease  
                                                            kind: networkPolicy name: deny-all namespace: kube-public  
                                                         
                                                     
                                                    
                                                        gcp 
                                                        
                                                            kind: networkPolicy name: deny-all namespace: default  
                                                            kind: networkPolicy name: deny-all namespace: kube-node-lease  
                                                            kind: networkPolicy name: deny-all namespace: kube-public  
                                                         
                                                     
                                                    
                                                        openstack 
                                                        
                                                            kind: networkPolicy name: deny-all namespace: default  
                                                            kind: networkPolicy name: deny-all namespace: kube-node-lease  
                                                            kind: networkPolicy name: deny-all namespace: kube-public  
                                                         
                                                     
                                                 
                                             
                                         
                                     
                                    
                                        2001 (High) - Containers must be forbidden to escalate privileges. 
                                        
                                            
                                                Pod does not escalate privileges. 
                                                
                                                    
                                                        aws 
                                                        
                                                            kind: pod name: apiserver-proxy-4dqc8 namespace: kube-system  
                                                            kind: pod name: apiserver-proxy-qmw5c namespace: kube-system  
                                                            kind: pod name: blackbox-exporter-54d6476f57-9r7pm namespace: kube-system  
                                                            kind: pod name: blackbox-exporter-54d6476f57-s87tl namespace: kube-system  
                                                            kind: pod name: calico-node-vertical-autoscaler-75c94f77bb-d8kc9 namespace: kube-system  
                                                            kind: pod name: calico-typha-deploy-6c94dc645b-hmjtm namespace: kube-system  
                                                            kind: pod name: calico-typha-deploy-6c94dc645b-pmv7f namespace: kube-system  
                                                            kind: pod name: calico-typha-horizontal-autoscaler-745ff89c8f-55hfh namespace: kube-system  
                                                            kind: pod name: calico-typha-vertical-autoscaler-59b9756658-jfws7 namespace: kube-system  
                                                            kind: pod name: coredns-7dc94444b8-9vvfv namespace: kube-system  
                                                            kind: pod name: coredns-7dc94444b8-zg7b7 namespace: kube-system  
                                                            kind: pod name: egress-filter-applier-5t7l2 namespace: kube-system  
                                                            kind: pod name: egress-filter-applier-z2bgp namespace: kube-system  
                                                            kind: pod name: metrics-server-6bf765d77d-djkfx namespace: kube-system  
                                                            kind: pod name: metrics-server-6bf765d77d-fsgdq namespace: kube-system  
                                                            kind: pod name: network-problem-detector-host-2cvlq namespace: kube-system  
                                                            kind: pod name: network-problem-detector-host-7xff6 namespace: kube-system  
                                                            kind: pod name: network-problem-detector-pod-9t5fl namespace: kube-system  
                                                            kind: pod name: network-problem-detector-pod-v89js namespace: kube-system  
                                                            kind: pod name: node-exporter-45s48 namespace: kube-system  
                                                            kind: pod name: node-exporter-fb7c7 namespace: kube-system  
                                                            kind: pod name: node-local-dns-mnx5f namespace: kube-system  
                                                            kind: pod name: node-local-dns-pjrjg namespace: kube-system  
                                                         
                                                     
                                                    
                                                        azure 
                                                        
                                                            kind: pod name: apiserver-proxy-8r626 namespace: kube-system  
                                                            kind: pod name: apiserver-proxy-l8lgd namespace: kube-system  
                                                            kind: pod name: blackbox-exporter-54d6476f57-bsw76 namespace: kube-system  
                                                            kind: pod name: blackbox-exporter-54d6476f57-c7wc2 namespace: kube-system  
                                                            kind: pod name: calico-node-vertical-autoscaler-75c94f77bb-44czk namespace: kube-system  
                                                            kind: pod name: calico-typha-deploy-6c94dc645b-cn7v8 namespace: kube-system  
                                                            kind: pod name: calico-typha-deploy-6c94dc645b-vgg9l namespace: kube-system  
                                                            kind: pod name: calico-typha-horizontal-autoscaler-745ff89c8f-2rpxc namespace: kube-system  
                                                            kind: pod name: calico-typha-vertical-autoscaler-59b9756658-p8mzz namespace: kube-system  
                                                            kind: pod name: cloud-node-manager-p7tm2 namespace: kube-system  
                                                            kind: pod name: cloud-node-manager-ps8pw namespace: kube-system  
                                                            kind: pod name: coredns-556cd47d78-g9h8v namespace: kube-system  
                                                            kind: pod name: coredns-556cd47d78-ql2rp namespace: kube-system  
                                                            kind: pod name: egress-filter-applier-2bmgq namespace: kube-system  
                                                            kind: pod name: egress-filter-applier-tssl5 namespace: kube-system  
                                                            kind: pod name: metrics-server-d94c5968-fbmdw namespace: kube-system  
                                                            kind: pod name: metrics-server-d94c5968-m2x7r namespace: kube-system  
                                                            kind: pod name: network-problem-detector-host-cprp9 namespace: kube-system  
                                                            kind: pod name: network-problem-detector-host-xvzkb namespace: kube-system  
                                                            kind: pod name: network-problem-detector-pod-ck849 namespace: kube-system  
                                                            kind: pod name: network-problem-detector-pod-jgf7j namespace: kube-system  
                                                            kind: pod name: node-exporter-8nn24 namespace: kube-system  
                                                            kind: pod name: node-exporter-lzf7z namespace: kube-system  
                                                            kind: pod name: node-local-dns-d6lgp namespace: kube-system  
                                                            kind: pod name: node-local-dns-r6zzr namespace: kube-system  
                                                         
                                                     
                                                    
                                                        gcp 
                                                        
                                                            kind: pod name: apiserver-proxy-dxk6r namespace: kube-system  
                                                            kind: pod name: apiserver-proxy-wdccl namespace: kube-system  
                                                            kind: pod name: blackbox-exporter-54d6476f57-8wfq2 namespace: kube-system  
                                                            kind: pod name: blackbox-exporter-54d6476f57-vvg7r namespace: kube-system  
                                                            kind: pod name: calico-node-vertical-autoscaler-75c94f77bb-7sxbj namespace: kube-system  
                                                            kind: pod name: calico-typha-deploy-6c94dc645b-hxc9n namespace: kube-system  
                                                            kind: pod name: calico-typha-deploy-6c94dc645b-jx2gb namespace: kube-system  
                                                            kind: pod name: calico-typha-horizontal-autoscaler-745ff89c8f-wfsgm namespace: kube-system  
                                                            kind: pod name: calico-typha-vertical-autoscaler-59b9756658-zn42c namespace: kube-system  
                                                            kind: pod name: coredns-f68b78c49-8xjpl namespace: kube-system  
                                                            kind: pod name: coredns-f68b78c49-zkfxf namespace: kube-system  
                                                            kind: pod name: egress-filter-applier-b9b5x namespace: kube-system  
                                                            kind: pod name: egress-filter-applier-pkr9q namespace: kube-system  
                                                            kind: pod name: metrics-server-5df6676dbf-kbm29 namespace: kube-system  
                                                            kind: pod name: metrics-server-5df6676dbf-tkhb2 namespace: kube-system  
                                                            kind: pod name: network-problem-detector-host-8ltzf namespace: kube-system  
                                                            kind: pod name: network-problem-detector-host-hd4cf namespace: kube-system  
                                                            kind: pod name: network-problem-detector-pod-gz2ph namespace: kube-system  
                                                            kind: pod name: network-problem-detector-pod-q8tj6 namespace: kube-system  
                                                            kind: pod name: node-exporter-5jtvr namespace: kube-system  
                                                            kind: pod name: node-exporter-s5t8x namespace: kube-system  
                                                            kind: pod name: node-local-dns-f29m2 namespace: kube-system  
                                                            kind: pod name: node-local-dns-srwg9 namespace: kube-system  
                                                         
                                                     
                                                    
                                                        openstack 
                                                        
                                                            kind: pod name: apiserver-proxy-mjfl5 namespace: kube-system  
                                                            kind: pod name: apiserver-proxy-zp6mh namespace: kube-system  
                                                            kind: pod name: blackbox-exporter-54d6476f57-4jfn4 namespace: kube-system  
                                                            kind: pod name: blackbox-exporter-54d6476f57-vprcp namespace: kube-system  
                                                            kind: pod name: calico-kube-controllers-5f4cb8d889-mcgpq namespace: kube-system  
                                                            kind: pod name: calico-node-vertical-autoscaler-75c94f77bb-zjc72 namespace: kube-system  
                                                            kind: pod name: calico-typha-deploy-6c94dc645b-fzc8v namespace: kube-system  
                                                            kind: pod name: calico-typha-deploy-6c94dc645b-jvpdv namespace: kube-system  
                                                            kind: pod name: calico-typha-horizontal-autoscaler-745ff89c8f-jwh2r namespace: kube-system  
                                                            kind: pod name: calico-typha-vertical-autoscaler-59b9756658-qx9sd namespace: kube-system  
                                                            kind: pod name: coredns-5464fd5895-gzjzz namespace: kube-system  
                                                            kind: pod name: coredns-5464fd5895-mgtdc namespace: kube-system  
                                                            kind: pod name: egress-filter-applier-b5z8f namespace: kube-system  
                                                            kind: pod name: egress-filter-applier-b6786 namespace: kube-system  
                                                            kind: pod name: metrics-server-7c7946c76-gsxtg namespace: kube-system  
                                                            kind: pod name: metrics-server-7c7946c76-szr7s namespace: kube-system  
                                                            kind: pod name: network-problem-detector-host-75kzx namespace: kube-system  
                                                            kind: pod name: network-problem-detector-host-xhqzr namespace: kube-system  
                                                            kind: pod name: network-problem-detector-pod-7kj5v namespace: kube-system  
                                                            kind: pod name: network-problem-detector-pod-bb6zl namespace: kube-system  
                                                            kind: pod name: node-exporter-4cp5g namespace: kube-system  
                                                            kind: pod name: node-exporter-rshd2 namespace: kube-system  
                                                            kind: pod name: node-local-dns-57bpm namespace: kube-system  
                                                            kind: pod name: node-local-dns-8b6dg namespace: kube-system  
                                                         
                                                     
                                                 
                                             
                                         
                                     
                                    
                                        2002 (Medium) - Storage Classes should have a "Delete" reclaim policy. 
                                        
                                            
                                                StorageClass has a Delete ReclaimPolicy set. 
                                                
                                                    
                                                        aws 
                                                        
                                                            kind: storageClass name: default  
                                                         
                                                     
                                                    
                                                        azure 
                                                        
                                                            kind: storageClass name: default  
                                                            kind: storageClass name: files  
                                                            kind: storageClass name: managed-premium-ssd  
                                                            kind: storageClass name: managed-standard-hdd  
                                                            kind: storageClass name: managed-standard-ssd  
                                                         
                                                     
                                                    
                                                        gcp 
                                                        
                                                            kind: storageClass name: default  
                                                            kind: storageClass name: gce-sc-fast  
                                                            kind: storageClass name: gce-sc-hdd  
                                                         
                                                     
                                                    
                                                        openstack 
                                                        
                                                            kind: storageClass name: default  
                                                            kind: storageClass name: default-class  
                                                         
                                                     
                                                 
                                             
                                         
                                     
                                    
                                        2003 (Medium) - Pods should use only allowed volume types. 
                                        
                                            
                                                Pod uses only allowed volume types. 
                                                
                                                    
                                                        aws 
                                                        
                                                            kind: pod name: apiserver-proxy-4dqc8 namespace: kube-system  
                                                            kind: pod name: apiserver-proxy-qmw5c namespace: kube-system  
                                                            kind: pod name: blackbox-exporter-54d6476f57-9r7pm namespace: kube-system  
                                                            kind: pod name: blackbox-exporter-54d6476f57-s87tl namespace: kube-system  
                                                            kind: pod name: calico-node-vertical-autoscaler-75c94f77bb-d8kc9 namespace: kube-system  
                                                            kind: pod name: calico-typha-deploy-6c94dc645b-hmjtm namespace: kube-system  
                                                            kind: pod name: calico-typha-deploy-6c94dc645b-pmv7f namespace: kube-system  
                                                            kind: pod name: calico-typha-horizontal-autoscaler-745ff89c8f-55hfh namespace: kube-system  
                                                            kind: pod name: calico-typha-vertical-autoscaler-59b9756658-jfws7 namespace: kube-system  
                                                            kind: pod name: coredns-7dc94444b8-9vvfv namespace: kube-system  
                                                            kind: pod name: coredns-7dc94444b8-zg7b7 namespace: kube-system  
                                                            kind: pod name: metrics-server-6bf765d77d-djkfx namespace: kube-system  
                                                            kind: pod name: metrics-server-6bf765d77d-fsgdq namespace: kube-system  
                                                         
                                                     
                                                    
                                                        azure 
                                                        
                                                            kind: pod name: apiserver-proxy-8r626 namespace: kube-system  
                                                            kind: pod name: apiserver-proxy-l8lgd namespace: kube-system  
                                                            kind: pod name: blackbox-exporter-54d6476f57-bsw76 namespace: kube-system  
                                                            kind: pod name: blackbox-exporter-54d6476f57-c7wc2 namespace: kube-system  
                                                            kind: pod name: calico-node-vertical-autoscaler-75c94f77bb-44czk namespace: kube-system  
                                                            kind: pod name: calico-typha-deploy-6c94dc645b-cn7v8 namespace: kube-system  
                                                            kind: pod name: calico-typha-deploy-6c94dc645b-vgg9l namespace: kube-system  
                                                            kind: pod name: calico-typha-horizontal-autoscaler-745ff89c8f-2rpxc namespace: kube-system  
                                                            kind: pod name: calico-typha-vertical-autoscaler-59b9756658-p8mzz namespace: kube-system  
                                                            kind: pod name: cloud-node-manager-p7tm2 namespace: kube-system  
                                                            kind: pod name: cloud-node-manager-ps8pw namespace: kube-system  
                                                            kind: pod name: coredns-556cd47d78-g9h8v namespace: kube-system  
                                                            kind: pod name: coredns-556cd47d78-ql2rp namespace: kube-system  
                                                            kind: pod name: metrics-server-d94c5968-fbmdw namespace: kube-system  
                                                            kind: pod name: metrics-server-d94c5968-m2x7r namespace: kube-system  
                                                         
                                                     
                                                    
                                                        gcp 
                                                        
                                                            kind: pod name: apiserver-proxy-dxk6r namespace: kube-system  
                                                            kind: pod name: apiserver-proxy-wdccl namespace: kube-system  
                                                            kind: pod name: blackbox-exporter-54d6476f57-8wfq2 namespace: kube-system  
                                                            kind: pod name: blackbox-exporter-54d6476f57-vvg7r namespace: kube-system  
                                                            kind: pod name: calico-node-vertical-autoscaler-75c94f77bb-7sxbj namespace: kube-system  
                                                            kind: pod name: calico-typha-deploy-6c94dc645b-hxc9n namespace: kube-system  
                                                            kind: pod name: calico-typha-deploy-6c94dc645b-jx2gb namespace: kube-system  
                                                            kind: pod name: calico-typha-horizontal-autoscaler-745ff89c8f-wfsgm namespace: kube-system  
                                                            kind: pod name: calico-typha-vertical-autoscaler-59b9756658-zn42c namespace: kube-system  
                                                            kind: pod name: coredns-f68b78c49-8xjpl namespace: kube-system  
                                                            kind: pod name: coredns-f68b78c49-zkfxf namespace: kube-system  
                                                            kind: pod name: metrics-server-5df6676dbf-kbm29 namespace: kube-system  
                                                            kind: pod name: metrics-server-5df6676dbf-tkhb2 namespace: kube-system  
                                                         
                                                     
                                                    
                                                        openstack 
                                                        
                                                            kind: pod name: apiserver-proxy-mjfl5 namespace: kube-system  
                                                            kind: pod name: apiserver-proxy-zp6mh namespace: kube-system  
                                                            kind: pod name: blackbox-exporter-54d6476f57-4jfn4 namespace: kube-system  
                                                            kind: pod name: blackbox-exporter-54d6476f57-vprcp namespace: kube-system  
                                                            kind: pod name: calico-kube-controllers-5f4cb8d889-mcgpq namespace: kube-system  
                                                            kind: pod name: calico-node-vertical-autoscaler-75c94f77bb-zjc72 namespace: kube-system  
                                                            kind: pod name: calico-typha-deploy-6c94dc645b-fzc8v namespace: kube-system  
                                                            kind: pod name: calico-typha-deploy-6c94dc645b-jvpdv namespace: kube-system  
                                                            kind: pod name: calico-typha-horizontal-autoscaler-745ff89c8f-jwh2r namespace: kube-system  
                                                            kind: pod name: calico-typha-vertical-autoscaler-59b9756658-qx9sd namespace: kube-system  
                                                            kind: pod name: coredns-5464fd5895-gzjzz namespace: kube-system  
                                                            kind: pod name: coredns-5464fd5895-mgtdc namespace: kube-system  
                                                            kind: pod name: metrics-server-7c7946c76-gsxtg namespace: kube-system  
                                                            kind: pod name: metrics-server-7c7946c76-szr7s namespace: kube-system  
                                                         
                                                     
                                                 
                                             
                                         
                                     
                                    
                                        2004 (Medium) - Limit the Services of type NodePort. 
                                        
                                            
                                                Service is not of type NodePort. 
                                                
                                                    
                                                        aws 
                                                        
                                                            kind: service name: kubernetes namespace: default  
                                                            kind: service name: apiserver-proxy namespace: kube-system  
                                                            kind: service name: blackbox-exporter namespace: kube-system  
                                                            kind: service name: calico-felix-monitoring namespace: kube-system  
                                                            kind: service name: calico-typha namespace: kube-system  
                                                            kind: service name: calico-typha-monitoring namespace: kube-system  
                                                            kind: service name: kube-dns namespace: kube-system  
                                                            kind: service name: kube-dns-upstream namespace: kube-system  
                                                            kind: service name: kube-proxy namespace: kube-system  
                                                            kind: service name: metrics-server namespace: kube-system  
                                                            kind: service name: network-problem-detector-host namespace: kube-system  
                                                            kind: service name: network-problem-detector-pod namespace: kube-system  
                                                            kind: service name: node-exporter namespace: kube-system  
                                                            kind: service name: node-problem-detector namespace: kube-system  
                                                         
                                                     
                                                    
                                                        azure 
                                                        
                                                            kind: service name: kubernetes namespace: default  
                                                            kind: service name: allow-tcp-egress namespace: kube-system  
                                                            kind: service name: allow-udp-egress namespace: kube-system  
                                                            kind: service name: apiserver-proxy namespace: kube-system  
                                                            kind: service name: blackbox-exporter namespace: kube-system  
                                                            kind: service name: calico-felix-monitoring namespace: kube-system  
                                                            kind: service name: calico-typha namespace: kube-system  
                                                            kind: service name: calico-typha-monitoring namespace: kube-system  
                                                            kind: service name: kube-dns namespace: kube-system  
                                                            kind: service name: kube-dns-upstream namespace: kube-system  
                                                            kind: service name: kube-proxy namespace: kube-system  
                                                            kind: service name: metrics-server namespace: kube-system  
                                                            kind: service name: network-problem-detector-host namespace: kube-system  
                                                            kind: service name: network-problem-detector-pod namespace: kube-system  
                                                            kind: service name: node-exporter namespace: kube-system  
                                                            kind: service name: node-problem-detector namespace: kube-system  
                                                         
                                                     
                                                    
                                                        gcp 
                                                        
                                                            kind: service name: kubernetes namespace: default  
                                                            kind: service name: apiserver-proxy namespace: kube-system  
                                                            kind: service name: blackbox-exporter namespace: kube-system  
                                                            kind: service name: calico-felix-monitoring namespace: kube-system  
                                                            kind: service name: calico-typha namespace: kube-system  
                                                            kind: service name: calico-typha-monitoring namespace: kube-system  
                                                            kind: service name: kube-dns namespace: kube-system  
                                                            kind: service name: kube-dns-upstream namespace: kube-system  
                                                            kind: service name: kube-proxy namespace: kube-system  
                                                            kind: service name: metrics-server namespace: kube-system  
                                                            kind: service name: network-problem-detector-host namespace: kube-system  
                                                            kind: service name: network-problem-detector-pod namespace: kube-system  
                                                            kind: service name: node-exporter namespace: kube-system  
                                                            kind: service name: node-problem-detector namespace: kube-system  
                                                         
                                                     
                                                    
                                                        openstack 
                                                        
                                                            kind: service name: kubernetes namespace: default  
                                                            kind: service name: apiserver-proxy namespace: kube-system  
                                                            kind: service name: blackbox-exporter namespace: kube-system  
                                                            kind: service name: calico-felix-monitoring namespace: kube-system  
                                                            kind: service name: calico-typha namespace: kube-system  
                                                            kind: service name: calico-typha-monitoring namespace: kube-system  
                                                            kind: service name: kube-dns namespace: kube-system  
                                                            kind: service name: kube-dns-upstream namespace: kube-system  
                                                            kind: service name: kube-proxy namespace: kube-system  
                                                            kind: service name: metrics-server namespace: kube-system  
                                                            kind: service name: network-problem-detector-host namespace: kube-system  
                                                            kind: service name: network-problem-detector-pod namespace: kube-system  
                                                            kind: service name: node-exporter namespace: kube-system  
                                                            kind: service name: node-problem-detector namespace: kube-system  
                                                         
                                                     
                                                 
                                             
                                         
                                     
                                    
                                        2005 (High) - Container images must come from trusted repositories. 
                                        
                                            
                                                Image has allowed prefix. 
                                                
                                                    
                                                        aws 
                                                        
                                                            container: sidecar imageRef: europe-docker.pkg.dev/sap-se-gcp-k8s-c-delivery/releases-canary-public/europe-docker_pkg_dev/gardener-project/releases/gardener/apiserver-proxy@sha256:d3b9d9af4f420682fda692211a170a52702efb0ee3a3a12e1532f6ff10e2e764 kind: pod name: apiserver-proxy-4dqc8 namespace: kube-system  
                                                            container: proxy imageRef: europe-docker.pkg.dev/sap-se-gcp-k8s-c-delivery/releases-canary-public/europe-docker_pkg_dev/gardener-project/releases/3rd/envoyproxy/envoy-distroless@sha256:26baf54b0e1f6eac2b2f47ade7dbbf69d44426d3b0acc310c4c48772cecd7e6c kind: pod name: apiserver-proxy-4dqc8 namespace: kube-system  
                                                            container: setup imageRef: europe-docker.pkg.dev/sap-se-gcp-k8s-c-delivery/releases-canary-public/europe-docker_pkg_dev/gardener-project/releases/gardener/apiserver-proxy@sha256:d3b9d9af4f420682fda692211a170a52702efb0ee3a3a12e1532f6ff10e2e764 kind: pod name: apiserver-proxy-4dqc8 namespace: kube-system  
                                                            container: sidecar imageRef: europe-docker.pkg.dev/sap-se-gcp-k8s-c-delivery/releases-canary-public/europe-docker_pkg_dev/gardener-project/releases/gardener/apiserver-proxy@sha256:d3b9d9af4f420682fda692211a170a52702efb0ee3a3a12e1532f6ff10e2e764 kind: pod name: apiserver-proxy-qmw5c namespace: kube-system  
                                                            container: proxy imageRef: europe-docker.pkg.dev/sap-se-gcp-k8s-c-delivery/releases-canary-public/europe-docker_pkg_dev/gardener-project/releases/3rd/envoyproxy/envoy-distroless@sha256:26baf54b0e1f6eac2b2f47ade7dbbf69d44426d3b0acc310c4c48772cecd7e6c kind: pod name: apiserver-proxy-qmw5c namespace: kube-system  
                                                            container: setup imageRef: europe-docker.pkg.dev/sap-se-gcp-k8s-c-delivery/releases-canary-public/europe-docker_pkg_dev/gardener-project/releases/gardener/apiserver-proxy@sha256:d3b9d9af4f420682fda692211a170a52702efb0ee3a3a12e1532f6ff10e2e764 kind: pod name: apiserver-proxy-qmw5c namespace: kube-system  
                                                            container: blackbox-exporter imageRef: europe-docker.pkg.dev/sap-se-gcp-k8s-c-delivery/releases-canary-public/quay_io/prometheus/blackbox-exporter@sha256:c0b5630237ab1f8cbe46535a28518ff453289ca1fdccd54d7305a4afdf3ef691 kind: pod name: blackbox-exporter-54d6476f57-9r7pm namespace: kube-system  
                                                            container: blackbox-exporter imageRef: europe-docker.pkg.dev/sap-se-gcp-k8s-c-delivery/releases-canary-public/quay_io/prometheus/blackbox-exporter@sha256:c0b5630237ab1f8cbe46535a28518ff453289ca1fdccd54d7305a4afdf3ef691 kind: pod name: blackbox-exporter-54d6476f57-s87tl namespace: kube-system  
                                                            container: add-snat-rule-to-upstream-dns imageRef: europe-docker.pkg.dev/sap-se-gcp-k8s-c-delivery/releases-canary-public/quay_io/calico/node@sha256:77e4e7e76d376136b6567ebcb6738602bcea57c33f996f0f0759660bd29f89ae kind: pod name: calico-node-ftrmj namespace: kube-system  
                                                            container: calico-node imageRef: europe-docker.pkg.dev/sap-se-gcp-k8s-c-delivery/releases-canary-public/quay_io/calico/node@sha256:77e4e7e76d376136b6567ebcb6738602bcea57c33f996f0f0759660bd29f89ae kind: pod name: calico-node-ftrmj namespace: kube-system  
                                                            container: cleanup-routes imageRef: europe-docker.pkg.dev/sap-se-gcp-k8s-c-delivery/releases-canary-public/quay_io/calico/node@sha256:77e4e7e76d376136b6567ebcb6738602bcea57c33f996f0f0759660bd29f89ae kind: pod name: calico-node-ftrmj namespace: kube-system  
                                                            container: install-cni imageRef: europe-docker.pkg.dev/sap-se-gcp-k8s-c-delivery/releases-canary-public/quay_io/calico/cni@sha256:f9cb36be9c688a3b5e122f2089e2379001836f727e5d7276084537faa0282277 kind: pod name: calico-node-ftrmj namespace: kube-system  
                                                            container: autoscaler imageRef: europe-docker.pkg.dev/sap-se-gcp-k8s-c-delivery/releases-canary-public/registry_k8s_io/cpa/cpvpa@sha256:718f252d47f13e9d47f0b9b51adbff72f43329602d3567cdf7f2c78d51505692 kind: pod name: calico-node-vertical-autoscaler-75c94f77bb-d8kc9 namespace: kube-system  
                                                            container: add-snat-rule-to-upstream-dns imageRef: europe-docker.pkg.dev/sap-se-gcp-k8s-c-delivery/releases-canary-public/quay_io/calico/node@sha256:77e4e7e76d376136b6567ebcb6738602bcea57c33f996f0f0759660bd29f89ae kind: pod name: calico-node-znq6v namespace: kube-system  
                                                            container: calico-node imageRef: europe-docker.pkg.dev/sap-se-gcp-k8s-c-delivery/releases-canary-public/quay_io/calico/node@sha256:77e4e7e76d376136b6567ebcb6738602bcea57c33f996f0f0759660bd29f89ae kind: pod name: calico-node-znq6v namespace: kube-system  
                                                            container: cleanup-routes imageRef: europe-docker.pkg.dev/sap-se-gcp-k8s-c-delivery/releases-canary-public/quay_io/calico/node@sha256:77e4e7e76d376136b6567ebcb6738602bcea57c33f996f0f0759660bd29f89ae kind: pod name: calico-node-znq6v namespace: kube-system  
                                                            container: install-cni imageRef: europe-docker.pkg.dev/sap-se-gcp-k8s-c-delivery/releases-canary-public/quay_io/calico/cni@sha256:f9cb36be9c688a3b5e122f2089e2379001836f727e5d7276084537faa0282277 kind: pod name: calico-node-znq6v namespace: kube-system  
                                                            container: calico-typha imageRef: europe-docker.pkg.dev/sap-se-gcp-k8s-c-delivery/releases-canary-public/quay_io/calico/typha@sha256:bec6400331c3d36ba035b4ddcfda2b3ad6a5758a2adeaa69116a4e76ca7a70c0 kind: pod name: calico-typha-deploy-6c94dc645b-hmjtm namespace: kube-system  
                                                            container: calico-typha imageRef: europe-docker.pkg.dev/sap-se-gcp-k8s-c-delivery/releases-canary-public/quay_io/calico/typha@sha256:bec6400331c3d36ba035b4ddcfda2b3ad6a5758a2adeaa69116a4e76ca7a70c0 kind: pod name: calico-typha-deploy-6c94dc645b-pmv7f namespace: kube-system  
                                                            container: autoscaler imageRef: europe-docker.pkg.dev/sap-se-gcp-k8s-c-delivery/releases-canary-public/registry_k8s_io/cpa/cluster-proportional-autoscaler@sha256:bc5be9858d29652151d43354e606f2c70789d3a3761998bd75df9198ba9728d1 kind: pod name: calico-typha-horizontal-autoscaler-745ff89c8f-55hfh namespace: kube-system  
                                                            container: autoscaler imageRef: europe-docker.pkg.dev/sap-se-gcp-k8s-c-delivery/releases-canary-public/registry_k8s_io/cpa/cpvpa@sha256:718f252d47f13e9d47f0b9b51adbff72f43329602d3567cdf7f2c78d51505692 kind: pod name: calico-typha-vertical-autoscaler-59b9756658-jfws7 namespace: kube-system  
                                                            container: coredns imageRef: europe-docker.pkg.dev/sap-se-gcp-k8s-c-delivery/releases-canary-public/registry_k8s_io/coredns/coredns@sha256:8d4d5cbada86a545879789f5c13416bc34e3f5e15f3f4c0abdc0dbfd43a2fe6e kind: pod name: coredns-7dc94444b8-9vvfv namespace: kube-system  
                                                            container: coredns imageRef: europe-docker.pkg.dev/sap-se-gcp-k8s-c-delivery/releases-canary-public/registry_k8s_io/coredns/coredns@sha256:8d4d5cbada86a545879789f5c13416bc34e3f5e15f3f4c0abdc0dbfd43a2fe6e kind: pod name: coredns-7dc94444b8-zg7b7 namespace: kube-system  
                                                            container: csi-driver imageRef: europe-docker.pkg.dev/sap-se-gcp-k8s-c-delivery/releases-canary-public/registry_k8s_io/provider-aws/aws-ebs-csi-driver@sha256:11d1178f990e400a546cd6d8ccd013ef5e329e55a79004bc8bde38f7482dc671 kind: pod name: csi-driver-node-jcrqk namespace: kube-system  
                                                            container: csi-node-driver-registrar imageRef: europe-docker.pkg.dev/sap-se-gcp-k8s-c-delivery/releases-canary-public/registry_k8s_io/sig-storage/csi-node-driver-registrar@sha256:ada6716264d1832d0b5d6aea0bea89215d17d076ab00dd79bce934283eba745c kind: pod name: csi-driver-node-jcrqk namespace: kube-system  
                                                            container: csi-liveness-probe imageRef: europe-docker.pkg.dev/sap-se-gcp-k8s-c-delivery/releases-canary-public/registry_k8s_io/sig-storage/livenessprobe@sha256:ff3acba1cf4edc93e326c33c5e17466894e08d7ba3c4ff17ec9c1ba647014888 kind: pod name: csi-driver-node-jcrqk namespace: kube-system  
                                                            container: csi-driver imageRef: europe-docker.pkg.dev/sap-se-gcp-k8s-c-delivery/releases-canary-public/registry_k8s_io/provider-aws/aws-ebs-csi-driver@sha256:11d1178f990e400a546cd6d8ccd013ef5e329e55a79004bc8bde38f7482dc671 kind: pod name: csi-driver-node-r2wkr namespace: kube-system  
                                                            container: csi-node-driver-registrar imageRef: europe-docker.pkg.dev/sap-se-gcp-k8s-c-delivery/releases-canary-public/registry_k8s_io/sig-storage/csi-node-driver-registrar@sha256:ada6716264d1832d0b5d6aea0bea89215d17d076ab00dd79bce934283eba745c kind: pod name: csi-driver-node-r2wkr namespace: kube-system  
                                                            container: csi-liveness-probe imageRef: europe-docker.pkg.dev/sap-se-gcp-k8s-c-delivery/releases-canary-public/registry_k8s_io/sig-storage/livenessprobe@sha256:ff3acba1cf4edc93e326c33c5e17466894e08d7ba3c4ff17ec9c1ba647014888 kind: pod name: csi-driver-node-r2wkr namespace: kube-system  
                                                            container: egress-filter-applier imageRef: europe-docker.pkg.dev/sap-se-gcp-k8s-c-delivery/releases-canary-public/europe-docker_pkg_dev/gardener-project/releases/gardener/egress-filter@sha256:b4d3a4929cbfcc7f8886881292ff2dd7cf1804de3527f8f408429686b7cd56bb kind: pod name: egress-filter-applier-5t7l2 namespace: kube-system  
                                                            container: egress-filter-applier imageRef: europe-docker.pkg.dev/sap-se-gcp-k8s-c-delivery/releases-canary-public/europe-docker_pkg_dev/gardener-project/releases/gardener/egress-filter@sha256:b4d3a4929cbfcc7f8886881292ff2dd7cf1804de3527f8f408429686b7cd56bb kind: pod name: egress-filter-applier-z2bgp namespace: kube-system  
                                                            container: kube-proxy imageRef: europe-docker.pkg.dev/sap-se-gcp-k8s-c-delivery/releases-canary-public/registry_k8s_io/kube-proxy@sha256:41eac9ffe4ecc06e10555cefd5a821cd1470674d32804975f1d95774cc0fbac2 kind: pod name: kube-proxy-worker-kkfk1-v1.31.8-8bvtn namespace: kube-system  
                                                            container: conntrack-fix imageRef: europe-docker.pkg.dev/sap-se-gcp-k8s-c-delivery/releases-canary-public/europe-docker_pkg_dev/gardener-project/releases/gardener/alpine-conntrack@sha256:78af1e338e7bd65c566e2edf298daae4fba78edbde12aadbe19c7ba504aa726a kind: pod name: kube-proxy-worker-kkfk1-v1.31.8-8bvtn namespace: kube-system  
                                                            container: cleanup imageRef: europe-docker.pkg.dev/sap-se-gcp-k8s-c-delivery/releases-canary-public/registry_k8s_io/kube-proxy@sha256:41eac9ffe4ecc06e10555cefd5a821cd1470674d32804975f1d95774cc0fbac2 kind: pod name: kube-proxy-worker-kkfk1-v1.31.8-8bvtn namespace: kube-system  
                                                            container: kube-proxy-init imageRef: europe-docker.pkg.dev/sap-se-gcp-k8s-c-delivery/releases-canary-public/registry_k8s_io/kube-proxy@sha256:41eac9ffe4ecc06e10555cefd5a821cd1470674d32804975f1d95774cc0fbac2 kind: pod name: kube-proxy-worker-kkfk1-v1.31.8-8bvtn namespace: kube-system  
                                                            container: kube-proxy imageRef: europe-docker.pkg.dev/sap-se-gcp-k8s-c-delivery/releases-canary-public/registry_k8s_io/kube-proxy@sha256:41eac9ffe4ecc06e10555cefd5a821cd1470674d32804975f1d95774cc0fbac2 kind: pod name: kube-proxy-worker-kkfk1-v1.31.8-fdssd namespace: kube-system  
                                                            container: conntrack-fix imageRef: europe-docker.pkg.dev/sap-se-gcp-k8s-c-delivery/releases-canary-public/europe-docker_pkg_dev/gardener-project/releases/gardener/alpine-conntrack@sha256:78af1e338e7bd65c566e2edf298daae4fba78edbde12aadbe19c7ba504aa726a kind: pod name: kube-proxy-worker-kkfk1-v1.31.8-fdssd namespace: kube-system  
                                                            container: cleanup imageRef: europe-docker.pkg.dev/sap-se-gcp-k8s-c-delivery/releases-canary-public/registry_k8s_io/kube-proxy@sha256:41eac9ffe4ecc06e10555cefd5a821cd1470674d32804975f1d95774cc0fbac2 kind: pod name: kube-proxy-worker-kkfk1-v1.31.8-fdssd namespace: kube-system  
                                                            container: kube-proxy-init imageRef: europe-docker.pkg.dev/sap-se-gcp-k8s-c-delivery/releases-canary-public/registry_k8s_io/kube-proxy@sha256:41eac9ffe4ecc06e10555cefd5a821cd1470674d32804975f1d95774cc0fbac2 kind: pod name: kube-proxy-worker-kkfk1-v1.31.8-fdssd namespace: kube-system  
                                                            container: metrics-server imageRef: europe-docker.pkg.dev/sap-se-gcp-k8s-c-delivery/releases-canary-public/registry_k8s_io/metrics-server/metrics-server@sha256:c23c277b728b2838a0c7a9634d170e1e5d3a0324bfa5b049216f98348989711e kind: pod name: metrics-server-6bf765d77d-djkfx namespace: kube-system  
                                                            container: metrics-server imageRef: europe-docker.pkg.dev/sap-se-gcp-k8s-c-delivery/releases-canary-public/registry_k8s_io/metrics-server/metrics-server@sha256:c23c277b728b2838a0c7a9634d170e1e5d3a0324bfa5b049216f98348989711e kind: pod name: metrics-server-6bf765d77d-fsgdq namespace: kube-system  
                                                            container: network-problem-detector-host imageRef: europe-docker.pkg.dev/sap-se-gcp-k8s-c-delivery/releases-canary-public/europe-docker_pkg_dev/gardener-project/releases/gardener/network-problem-detector@sha256:eb29f76998e46429c61d7dd1597aef3812d9d2abe2754dfe6c2e6ca0888c0599 kind: pod name: network-problem-detector-host-2cvlq namespace: kube-system  
                                                            container: network-problem-detector-host imageRef: europe-docker.pkg.dev/sap-se-gcp-k8s-c-delivery/releases-canary-public/europe-docker_pkg_dev/gardener-project/releases/gardener/network-problem-detector@sha256:eb29f76998e46429c61d7dd1597aef3812d9d2abe2754dfe6c2e6ca0888c0599 kind: pod name: network-problem-detector-host-7xff6 namespace: kube-system  
                                                            container: network-problem-detector-pod imageRef: europe-docker.pkg.dev/sap-se-gcp-k8s-c-delivery/releases-canary-public/europe-docker_pkg_dev/gardener-project/releases/gardener/network-problem-detector@sha256:eb29f76998e46429c61d7dd1597aef3812d9d2abe2754dfe6c2e6ca0888c0599 kind: pod name: network-problem-detector-pod-9t5fl namespace: kube-system  
                                                            container: network-problem-detector-pod imageRef: europe-docker.pkg.dev/sap-se-gcp-k8s-c-delivery/releases-canary-public/europe-docker_pkg_dev/gardener-project/releases/gardener/network-problem-detector@sha256:eb29f76998e46429c61d7dd1597aef3812d9d2abe2754dfe6c2e6ca0888c0599 kind: pod name: network-problem-detector-pod-v89js namespace: kube-system  
                                                            container: node-exporter imageRef: europe-docker.pkg.dev/sap-se-gcp-k8s-c-delivery/releases-canary-public/quay_io/prometheus/node-exporter@sha256:d88466fb3dd1c9b0c2b855204813cb282ffdad4e74082c54f9928aa0f4a61b1c kind: pod name: node-exporter-45s48 namespace: kube-system  
                                                            container: node-exporter imageRef: europe-docker.pkg.dev/sap-se-gcp-k8s-c-delivery/releases-canary-public/quay_io/prometheus/node-exporter@sha256:d88466fb3dd1c9b0c2b855204813cb282ffdad4e74082c54f9928aa0f4a61b1c kind: pod name: node-exporter-fb7c7 namespace: kube-system  
                                                            container: node-cache imageRef: europe-docker.pkg.dev/sap-se-gcp-k8s-c-delivery/releases-canary-public/registry_k8s_io/dns/k8s-dns-node-cache@sha256:3d39a99c3f3b17724e5feee1645b4e7d4a0637212df1d242c7da3104cda4da9f kind: pod name: node-local-dns-mnx5f namespace: kube-system  
                                                            container: node-cache imageRef: europe-docker.pkg.dev/sap-se-gcp-k8s-c-delivery/releases-canary-public/registry_k8s_io/dns/k8s-dns-node-cache@sha256:3d39a99c3f3b17724e5feee1645b4e7d4a0637212df1d242c7da3104cda4da9f kind: pod name: node-local-dns-pjrjg namespace: kube-system  
                                                            container: node-problem-detector imageRef: europe-docker.pkg.dev/sap-se-gcp-k8s-c-delivery/releases-canary-public/registry_k8s_io/node-problem-detector/node-problem-detector@sha256:bf1d6e7fed0dbc403a7513065ebe071d748b2fe8fe754d76eb9afe988bfc5f67 kind: pod name: node-problem-detector-gtfpl namespace: kube-system  
                                                            container: node-problem-detector imageRef: europe-docker.pkg.dev/sap-se-gcp-k8s-c-delivery/releases-canary-public/registry_k8s_io/node-problem-detector/node-problem-detector@sha256:bf1d6e7fed0dbc403a7513065ebe071d748b2fe8fe754d76eb9afe988bfc5f67 kind: pod name: node-problem-detector-kpczj namespace: kube-system  
                                                            container: vpn-shoot imageRef: europe-docker.pkg.dev/sap-se-gcp-k8s-c-delivery/releases-canary-public/europe-docker_pkg_dev/gardener-project/releases/gardener/vpn-client@sha256:f90507cc750e0e6223edfe2fe58e4dd923a492d154329ea00d6ff7f9e6285217 kind: pod name: vpn-shoot-b79bb6f9-7vnr4 namespace: kube-system  
                                                            container: vpn-shoot-init imageRef: europe-docker.pkg.dev/sap-se-gcp-k8s-c-delivery/releases-canary-public/europe-docker_pkg_dev/gardener-project/releases/gardener/vpn-client@sha256:f90507cc750e0e6223edfe2fe58e4dd923a492d154329ea00d6ff7f9e6285217 kind: pod name: vpn-shoot-b79bb6f9-7vnr4 namespace: kube-system  
                                                         
                                                     
                                                    
                                                        azure 
                                                        
                                                            container: sidecar imageRef: europe-docker.pkg.dev/sap-se-gcp-k8s-c-delivery/releases-canary-public/europe-docker_pkg_dev/gardener-project/releases/gardener/apiserver-proxy@sha256:d3b9d9af4f420682fda692211a170a52702efb0ee3a3a12e1532f6ff10e2e764 kind: pod name: apiserver-proxy-8r626 namespace: kube-system  
                                                            container: proxy imageRef: europe-docker.pkg.dev/sap-se-gcp-k8s-c-delivery/releases-canary-public/europe-docker_pkg_dev/gardener-project/releases/3rd/envoyproxy/envoy-distroless@sha256:26baf54b0e1f6eac2b2f47ade7dbbf69d44426d3b0acc310c4c48772cecd7e6c kind: pod name: apiserver-proxy-8r626 namespace: kube-system  
                                                            container: setup imageRef: europe-docker.pkg.dev/sap-se-gcp-k8s-c-delivery/releases-canary-public/europe-docker_pkg_dev/gardener-project/releases/gardener/apiserver-proxy@sha256:d3b9d9af4f420682fda692211a170a52702efb0ee3a3a12e1532f6ff10e2e764 kind: pod name: apiserver-proxy-8r626 namespace: kube-system  
                                                            container: sidecar imageRef: europe-docker.pkg.dev/sap-se-gcp-k8s-c-delivery/releases-canary-public/europe-docker_pkg_dev/gardener-project/releases/gardener/apiserver-proxy@sha256:d3b9d9af4f420682fda692211a170a52702efb0ee3a3a12e1532f6ff10e2e764 kind: pod name: apiserver-proxy-l8lgd namespace: kube-system  
                                                            container: proxy imageRef: europe-docker.pkg.dev/sap-se-gcp-k8s-c-delivery/releases-canary-public/europe-docker_pkg_dev/gardener-project/releases/3rd/envoyproxy/envoy-distroless@sha256:26baf54b0e1f6eac2b2f47ade7dbbf69d44426d3b0acc310c4c48772cecd7e6c kind: pod name: apiserver-proxy-l8lgd namespace: kube-system  
                                                            container: setup imageRef: europe-docker.pkg.dev/sap-se-gcp-k8s-c-delivery/releases-canary-public/europe-docker_pkg_dev/gardener-project/releases/gardener/apiserver-proxy@sha256:d3b9d9af4f420682fda692211a170a52702efb0ee3a3a12e1532f6ff10e2e764 kind: pod name: apiserver-proxy-l8lgd namespace: kube-system  
                                                            container: blackbox-exporter imageRef: europe-docker.pkg.dev/sap-se-gcp-k8s-c-delivery/releases-canary-public/quay_io/prometheus/blackbox-exporter@sha256:c0b5630237ab1f8cbe46535a28518ff453289ca1fdccd54d7305a4afdf3ef691 kind: pod name: blackbox-exporter-54d6476f57-bsw76 namespace: kube-system  
                                                            container: blackbox-exporter imageRef: europe-docker.pkg.dev/sap-se-gcp-k8s-c-delivery/releases-canary-public/quay_io/prometheus/blackbox-exporter@sha256:c0b5630237ab1f8cbe46535a28518ff453289ca1fdccd54d7305a4afdf3ef691 kind: pod name: blackbox-exporter-54d6476f57-c7wc2 namespace: kube-system  
                                                            container: calico-node imageRef: europe-docker.pkg.dev/sap-se-gcp-k8s-c-delivery/releases-canary-public/quay_io/calico/node@sha256:77e4e7e76d376136b6567ebcb6738602bcea57c33f996f0f0759660bd29f89ae kind: pod name: calico-node-6j4zv namespace: kube-system  
                                                            container: install-cni imageRef: europe-docker.pkg.dev/sap-se-gcp-k8s-c-delivery/releases-canary-public/quay_io/calico/cni@sha256:f9cb36be9c688a3b5e122f2089e2379001836f727e5d7276084537faa0282277 kind: pod name: calico-node-6j4zv namespace: kube-system  
                                                            container: calico-node imageRef: europe-docker.pkg.dev/sap-se-gcp-k8s-c-delivery/releases-canary-public/quay_io/calico/node@sha256:77e4e7e76d376136b6567ebcb6738602bcea57c33f996f0f0759660bd29f89ae kind: pod name: calico-node-cbmrk namespace: kube-system  
                                                            container: install-cni imageRef: europe-docker.pkg.dev/sap-se-gcp-k8s-c-delivery/releases-canary-public/quay_io/calico/cni@sha256:f9cb36be9c688a3b5e122f2089e2379001836f727e5d7276084537faa0282277 kind: pod name: calico-node-cbmrk namespace: kube-system  
                                                            container: autoscaler imageRef: europe-docker.pkg.dev/sap-se-gcp-k8s-c-delivery/releases-canary-public/registry_k8s_io/cpa/cpvpa@sha256:718f252d47f13e9d47f0b9b51adbff72f43329602d3567cdf7f2c78d51505692 kind: pod name: calico-node-vertical-autoscaler-75c94f77bb-44czk namespace: kube-system  
                                                            container: calico-typha imageRef: europe-docker.pkg.dev/sap-se-gcp-k8s-c-delivery/releases-canary-public/quay_io/calico/typha@sha256:bec6400331c3d36ba035b4ddcfda2b3ad6a5758a2adeaa69116a4e76ca7a70c0 kind: pod name: calico-typha-deploy-6c94dc645b-cn7v8 namespace: kube-system  
                                                            container: calico-typha imageRef: europe-docker.pkg.dev/sap-se-gcp-k8s-c-delivery/releases-canary-public/quay_io/calico/typha@sha256:bec6400331c3d36ba035b4ddcfda2b3ad6a5758a2adeaa69116a4e76ca7a70c0 kind: pod name: calico-typha-deploy-6c94dc645b-vgg9l namespace: kube-system  
                                                            container: autoscaler imageRef: europe-docker.pkg.dev/sap-se-gcp-k8s-c-delivery/releases-canary-public/registry_k8s_io/cpa/cluster-proportional-autoscaler@sha256:bc5be9858d29652151d43354e606f2c70789d3a3761998bd75df9198ba9728d1 kind: pod name: calico-typha-horizontal-autoscaler-745ff89c8f-2rpxc namespace: kube-system  
                                                            container: autoscaler imageRef: europe-docker.pkg.dev/sap-se-gcp-k8s-c-delivery/releases-canary-public/registry_k8s_io/cpa/cpvpa@sha256:718f252d47f13e9d47f0b9b51adbff72f43329602d3567cdf7f2c78d51505692 kind: pod name: calico-typha-vertical-autoscaler-59b9756658-p8mzz namespace: kube-system  
                                                            container: cloud-node-manager imageRef: europe-docker.pkg.dev/sap-se-gcp-k8s-c-delivery/releases-canary-public/mcr_microsoft_com/oss/kubernetes/azure-cloud-node-manager@sha256:cbf8333a624e7580b0ffea20eb2eee65d906899d0a6a745aee27811a246c1472 kind: pod name: cloud-node-manager-p7tm2 namespace: kube-system  
                                                            container: cloud-node-manager imageRef: europe-docker.pkg.dev/sap-se-gcp-k8s-c-delivery/releases-canary-public/mcr_microsoft_com/oss/kubernetes/azure-cloud-node-manager@sha256:cbf8333a624e7580b0ffea20eb2eee65d906899d0a6a745aee27811a246c1472 kind: pod name: cloud-node-manager-ps8pw namespace: kube-system  
                                                            container: coredns imageRef: europe-docker.pkg.dev/sap-se-gcp-k8s-c-delivery/releases-canary-public/registry_k8s_io/coredns/coredns@sha256:8d4d5cbada86a545879789f5c13416bc34e3f5e15f3f4c0abdc0dbfd43a2fe6e kind: pod name: coredns-556cd47d78-g9h8v namespace: kube-system  
                                                            container: coredns imageRef: europe-docker.pkg.dev/sap-se-gcp-k8s-c-delivery/releases-canary-public/registry_k8s_io/coredns/coredns@sha256:8d4d5cbada86a545879789f5c13416bc34e3f5e15f3f4c0abdc0dbfd43a2fe6e kind: pod name: coredns-556cd47d78-ql2rp namespace: kube-system  
                                                            container: csi-driver imageRef: europe-docker.pkg.dev/sap-se-gcp-k8s-c-delivery/releases-canary-public/mcr_microsoft_com/oss/kubernetes-csi/azuredisk-csi@sha256:1e093eaa7636fc8b9354474d2b99e212080534065a2a5848d985fdfdfb7c2166 kind: pod name: csi-driver-node-disk-ch2pm namespace: kube-system  
                                                            container: csi-node-driver-registrar imageRef: europe-docker.pkg.dev/sap-se-gcp-k8s-c-delivery/releases-canary-public/registry_k8s_io/sig-storage/csi-node-driver-registrar@sha256:ada6716264d1832d0b5d6aea0bea89215d17d076ab00dd79bce934283eba745c kind: pod name: csi-driver-node-disk-ch2pm namespace: kube-system  
                                                            container: csi-liveness-probe imageRef: europe-docker.pkg.dev/sap-se-gcp-k8s-c-delivery/releases-canary-public/registry_k8s_io/sig-storage/livenessprobe@sha256:ff3acba1cf4edc93e326c33c5e17466894e08d7ba3c4ff17ec9c1ba647014888 kind: pod name: csi-driver-node-disk-ch2pm namespace: kube-system  
                                                            container: csi-driver imageRef: europe-docker.pkg.dev/sap-se-gcp-k8s-c-delivery/releases-canary-public/mcr_microsoft_com/oss/kubernetes-csi/azuredisk-csi@sha256:1e093eaa7636fc8b9354474d2b99e212080534065a2a5848d985fdfdfb7c2166 kind: pod name: csi-driver-node-disk-jfxtn namespace: kube-system  
                                                            container: csi-node-driver-registrar imageRef: europe-docker.pkg.dev/sap-se-gcp-k8s-c-delivery/releases-canary-public/registry_k8s_io/sig-storage/csi-node-driver-registrar@sha256:ada6716264d1832d0b5d6aea0bea89215d17d076ab00dd79bce934283eba745c kind: pod name: csi-driver-node-disk-jfxtn namespace: kube-system  
                                                            container: csi-liveness-probe imageRef: europe-docker.pkg.dev/sap-se-gcp-k8s-c-delivery/releases-canary-public/registry_k8s_io/sig-storage/livenessprobe@sha256:ff3acba1cf4edc93e326c33c5e17466894e08d7ba3c4ff17ec9c1ba647014888 kind: pod name: csi-driver-node-disk-jfxtn namespace: kube-system  
                                                            container: csi-driver imageRef: europe-docker.pkg.dev/sap-se-gcp-k8s-c-delivery/releases-canary-public/mcr_microsoft_com/oss/kubernetes-csi/azurefile-csi@sha256:bb80cc1f1adab1fbdfc623181c16fe67b6ee46c54124b4570d8ef7db778179a7 kind: pod name: csi-driver-node-file-6dn4x namespace: kube-system  
                                                            container: csi-node-driver-registrar imageRef: europe-docker.pkg.dev/sap-se-gcp-k8s-c-delivery/releases-canary-public/registry_k8s_io/sig-storage/csi-node-driver-registrar@sha256:ada6716264d1832d0b5d6aea0bea89215d17d076ab00dd79bce934283eba745c kind: pod name: csi-driver-node-file-6dn4x namespace: kube-system  
                                                            container: csi-liveness-probe imageRef: europe-docker.pkg.dev/sap-se-gcp-k8s-c-delivery/releases-canary-public/registry_k8s_io/sig-storage/livenessprobe@sha256:ff3acba1cf4edc93e326c33c5e17466894e08d7ba3c4ff17ec9c1ba647014888 kind: pod name: csi-driver-node-file-6dn4x namespace: kube-system  
                                                            container: csi-driver imageRef: europe-docker.pkg.dev/sap-se-gcp-k8s-c-delivery/releases-canary-public/mcr_microsoft_com/oss/kubernetes-csi/azurefile-csi@sha256:bb80cc1f1adab1fbdfc623181c16fe67b6ee46c54124b4570d8ef7db778179a7 kind: pod name: csi-driver-node-file-kjgcg namespace: kube-system  
                                                            container: csi-node-driver-registrar imageRef: europe-docker.pkg.dev/sap-se-gcp-k8s-c-delivery/releases-canary-public/registry_k8s_io/sig-storage/csi-node-driver-registrar@sha256:ada6716264d1832d0b5d6aea0bea89215d17d076ab00dd79bce934283eba745c kind: pod name: csi-driver-node-file-kjgcg namespace: kube-system  
                                                            container: csi-liveness-probe imageRef: europe-docker.pkg.dev/sap-se-gcp-k8s-c-delivery/releases-canary-public/registry_k8s_io/sig-storage/livenessprobe@sha256:ff3acba1cf4edc93e326c33c5e17466894e08d7ba3c4ff17ec9c1ba647014888 kind: pod name: csi-driver-node-file-kjgcg namespace: kube-system  
                                                            container: egress-filter-applier imageRef: europe-docker.pkg.dev/sap-se-gcp-k8s-c-delivery/releases-canary-public/europe-docker_pkg_dev/gardener-project/releases/gardener/egress-filter@sha256:b4d3a4929cbfcc7f8886881292ff2dd7cf1804de3527f8f408429686b7cd56bb kind: pod name: egress-filter-applier-2bmgq namespace: kube-system  
                                                            container: egress-filter-applier imageRef: europe-docker.pkg.dev/sap-se-gcp-k8s-c-delivery/releases-canary-public/europe-docker_pkg_dev/gardener-project/releases/gardener/egress-filter@sha256:b4d3a4929cbfcc7f8886881292ff2dd7cf1804de3527f8f408429686b7cd56bb kind: pod name: egress-filter-applier-tssl5 namespace: kube-system  
                                                            container: kube-proxy imageRef: europe-docker.pkg.dev/sap-se-gcp-k8s-c-delivery/releases-canary-public/registry_k8s_io/kube-proxy@sha256:41eac9ffe4ecc06e10555cefd5a821cd1470674d32804975f1d95774cc0fbac2 kind: pod name: kube-proxy-worker-g7p4p-v1.31.8-7dnc5 namespace: kube-system  
                                                            container: conntrack-fix imageRef: europe-docker.pkg.dev/sap-se-gcp-k8s-c-delivery/releases-canary-public/europe-docker_pkg_dev/gardener-project/releases/gardener/alpine-conntrack@sha256:78af1e338e7bd65c566e2edf298daae4fba78edbde12aadbe19c7ba504aa726a kind: pod name: kube-proxy-worker-g7p4p-v1.31.8-7dnc5 namespace: kube-system  
                                                            container: cleanup imageRef: europe-docker.pkg.dev/sap-se-gcp-k8s-c-delivery/releases-canary-public/registry_k8s_io/kube-proxy@sha256:41eac9ffe4ecc06e10555cefd5a821cd1470674d32804975f1d95774cc0fbac2 kind: pod name: kube-proxy-worker-g7p4p-v1.31.8-7dnc5 namespace: kube-system  
                                                            container: kube-proxy-init imageRef: europe-docker.pkg.dev/sap-se-gcp-k8s-c-delivery/releases-canary-public/registry_k8s_io/kube-proxy@sha256:41eac9ffe4ecc06e10555cefd5a821cd1470674d32804975f1d95774cc0fbac2 kind: pod name: kube-proxy-worker-g7p4p-v1.31.8-7dnc5 namespace: kube-system  
                                                            container: kube-proxy imageRef: europe-docker.pkg.dev/sap-se-gcp-k8s-c-delivery/releases-canary-public/registry_k8s_io/kube-proxy@sha256:41eac9ffe4ecc06e10555cefd5a821cd1470674d32804975f1d95774cc0fbac2 kind: pod name: kube-proxy-worker-g7p4p-v1.31.8-th5l5 namespace: kube-system  
                                                            container: conntrack-fix imageRef: europe-docker.pkg.dev/sap-se-gcp-k8s-c-delivery/releases-canary-public/europe-docker_pkg_dev/gardener-project/releases/gardener/alpine-conntrack@sha256:78af1e338e7bd65c566e2edf298daae4fba78edbde12aadbe19c7ba504aa726a kind: pod name: kube-proxy-worker-g7p4p-v1.31.8-th5l5 namespace: kube-system  
                                                            container: cleanup imageRef: europe-docker.pkg.dev/sap-se-gcp-k8s-c-delivery/releases-canary-public/registry_k8s_io/kube-proxy@sha256:41eac9ffe4ecc06e10555cefd5a821cd1470674d32804975f1d95774cc0fbac2 kind: pod name: kube-proxy-worker-g7p4p-v1.31.8-th5l5 namespace: kube-system  
                                                            container: kube-proxy-init imageRef: europe-docker.pkg.dev/sap-se-gcp-k8s-c-delivery/releases-canary-public/registry_k8s_io/kube-proxy@sha256:41eac9ffe4ecc06e10555cefd5a821cd1470674d32804975f1d95774cc0fbac2 kind: pod name: kube-proxy-worker-g7p4p-v1.31.8-th5l5 namespace: kube-system  
                                                            container: metrics-server imageRef: europe-docker.pkg.dev/sap-se-gcp-k8s-c-delivery/releases-canary-public/registry_k8s_io/metrics-server/metrics-server@sha256:c23c277b728b2838a0c7a9634d170e1e5d3a0324bfa5b049216f98348989711e kind: pod name: metrics-server-d94c5968-fbmdw namespace: kube-system  
                                                            container: metrics-server imageRef: europe-docker.pkg.dev/sap-se-gcp-k8s-c-delivery/releases-canary-public/registry_k8s_io/metrics-server/metrics-server@sha256:c23c277b728b2838a0c7a9634d170e1e5d3a0324bfa5b049216f98348989711e kind: pod name: metrics-server-d94c5968-m2x7r namespace: kube-system  
                                                            container: network-problem-detector-host imageRef: europe-docker.pkg.dev/sap-se-gcp-k8s-c-delivery/releases-canary-public/europe-docker_pkg_dev/gardener-project/releases/gardener/network-problem-detector@sha256:eb29f76998e46429c61d7dd1597aef3812d9d2abe2754dfe6c2e6ca0888c0599 kind: pod name: network-problem-detector-host-cprp9 namespace: kube-system  
                                                            container: network-problem-detector-host imageRef: europe-docker.pkg.dev/sap-se-gcp-k8s-c-delivery/releases-canary-public/europe-docker_pkg_dev/gardener-project/releases/gardener/network-problem-detector@sha256:eb29f76998e46429c61d7dd1597aef3812d9d2abe2754dfe6c2e6ca0888c0599 kind: pod name: network-problem-detector-host-xvzkb namespace: kube-system  
                                                            container: network-problem-detector-pod imageRef: europe-docker.pkg.dev/sap-se-gcp-k8s-c-delivery/releases-canary-public/europe-docker_pkg_dev/gardener-project/releases/gardener/network-problem-detector@sha256:eb29f76998e46429c61d7dd1597aef3812d9d2abe2754dfe6c2e6ca0888c0599 kind: pod name: network-problem-detector-pod-ck849 namespace: kube-system  
                                                            container: network-problem-detector-pod imageRef: europe-docker.pkg.dev/sap-se-gcp-k8s-c-delivery/releases-canary-public/europe-docker_pkg_dev/gardener-project/releases/gardener/network-problem-detector@sha256:eb29f76998e46429c61d7dd1597aef3812d9d2abe2754dfe6c2e6ca0888c0599 kind: pod name: network-problem-detector-pod-jgf7j namespace: kube-system  
                                                            container: node-exporter imageRef: europe-docker.pkg.dev/sap-se-gcp-k8s-c-delivery/releases-canary-public/quay_io/prometheus/node-exporter@sha256:d88466fb3dd1c9b0c2b855204813cb282ffdad4e74082c54f9928aa0f4a61b1c kind: pod name: node-exporter-8nn24 namespace: kube-system  
                                                            container: node-exporter imageRef: europe-docker.pkg.dev/sap-se-gcp-k8s-c-delivery/releases-canary-public/quay_io/prometheus/node-exporter@sha256:d88466fb3dd1c9b0c2b855204813cb282ffdad4e74082c54f9928aa0f4a61b1c kind: pod name: node-exporter-lzf7z namespace: kube-system  
                                                            container: node-cache imageRef: europe-docker.pkg.dev/sap-se-gcp-k8s-c-delivery/releases-canary-public/registry_k8s_io/dns/k8s-dns-node-cache@sha256:3d39a99c3f3b17724e5feee1645b4e7d4a0637212df1d242c7da3104cda4da9f kind: pod name: node-local-dns-d6lgp namespace: kube-system  
                                                            container: node-cache imageRef: europe-docker.pkg.dev/sap-se-gcp-k8s-c-delivery/releases-canary-public/registry_k8s_io/dns/k8s-dns-node-cache@sha256:3d39a99c3f3b17724e5feee1645b4e7d4a0637212df1d242c7da3104cda4da9f kind: pod name: node-local-dns-r6zzr namespace: kube-system  
                                                            container: node-problem-detector imageRef: europe-docker.pkg.dev/sap-se-gcp-k8s-c-delivery/releases-canary-public/registry_k8s_io/node-problem-detector/node-problem-detector@sha256:bf1d6e7fed0dbc403a7513065ebe071d748b2fe8fe754d76eb9afe988bfc5f67 kind: pod name: node-problem-detector-ddmx4 namespace: kube-system  
                                                            container: node-problem-detector imageRef: europe-docker.pkg.dev/sap-se-gcp-k8s-c-delivery/releases-canary-public/registry_k8s_io/node-problem-detector/node-problem-detector@sha256:bf1d6e7fed0dbc403a7513065ebe071d748b2fe8fe754d76eb9afe988bfc5f67 kind: pod name: node-problem-detector-qxs5g namespace: kube-system  
                                                            container: vpn-shoot imageRef: europe-docker.pkg.dev/sap-se-gcp-k8s-c-delivery/releases-canary-public/europe-docker_pkg_dev/gardener-project/releases/gardener/vpn-client@sha256:f90507cc750e0e6223edfe2fe58e4dd923a492d154329ea00d6ff7f9e6285217 kind: pod name: vpn-shoot-84954fb6df-sqkt9 namespace: kube-system  
                                                            container: vpn-shoot-init imageRef: europe-docker.pkg.dev/sap-se-gcp-k8s-c-delivery/releases-canary-public/europe-docker_pkg_dev/gardener-project/releases/gardener/vpn-client@sha256:f90507cc750e0e6223edfe2fe58e4dd923a492d154329ea00d6ff7f9e6285217 kind: pod name: vpn-shoot-84954fb6df-sqkt9 namespace: kube-system  
                                                         
                                                     
                                                    
                                                        gcp 
                                                        
                                                            container: sidecar imageRef: europe-docker.pkg.dev/sap-se-gcp-k8s-c-delivery/releases-canary-public/europe-docker_pkg_dev/gardener-project/releases/gardener/apiserver-proxy@sha256:d3b9d9af4f420682fda692211a170a52702efb0ee3a3a12e1532f6ff10e2e764 kind: pod name: apiserver-proxy-dxk6r namespace: kube-system  
                                                            container: proxy imageRef: europe-docker.pkg.dev/sap-se-gcp-k8s-c-delivery/releases-canary-public/europe-docker_pkg_dev/gardener-project/releases/3rd/envoyproxy/envoy-distroless@sha256:26baf54b0e1f6eac2b2f47ade7dbbf69d44426d3b0acc310c4c48772cecd7e6c kind: pod name: apiserver-proxy-dxk6r namespace: kube-system  
                                                            container: setup imageRef: europe-docker.pkg.dev/sap-se-gcp-k8s-c-delivery/releases-canary-public/europe-docker_pkg_dev/gardener-project/releases/gardener/apiserver-proxy@sha256:d3b9d9af4f420682fda692211a170a52702efb0ee3a3a12e1532f6ff10e2e764 kind: pod name: apiserver-proxy-dxk6r namespace: kube-system  
                                                            container: sidecar imageRef: europe-docker.pkg.dev/sap-se-gcp-k8s-c-delivery/releases-canary-public/europe-docker_pkg_dev/gardener-project/releases/gardener/apiserver-proxy@sha256:d3b9d9af4f420682fda692211a170a52702efb0ee3a3a12e1532f6ff10e2e764 kind: pod name: apiserver-proxy-wdccl namespace: kube-system  
                                                            container: proxy imageRef: europe-docker.pkg.dev/sap-se-gcp-k8s-c-delivery/releases-canary-public/europe-docker_pkg_dev/gardener-project/releases/3rd/envoyproxy/envoy-distroless@sha256:26baf54b0e1f6eac2b2f47ade7dbbf69d44426d3b0acc310c4c48772cecd7e6c kind: pod name: apiserver-proxy-wdccl namespace: kube-system  
                                                            container: setup imageRef: europe-docker.pkg.dev/sap-se-gcp-k8s-c-delivery/releases-canary-public/europe-docker_pkg_dev/gardener-project/releases/gardener/apiserver-proxy@sha256:d3b9d9af4f420682fda692211a170a52702efb0ee3a3a12e1532f6ff10e2e764 kind: pod name: apiserver-proxy-wdccl namespace: kube-system  
                                                            container: blackbox-exporter imageRef: europe-docker.pkg.dev/sap-se-gcp-k8s-c-delivery/releases-canary-public/quay_io/prometheus/blackbox-exporter@sha256:c0b5630237ab1f8cbe46535a28518ff453289ca1fdccd54d7305a4afdf3ef691 kind: pod name: blackbox-exporter-54d6476f57-8wfq2 namespace: kube-system  
                                                            container: blackbox-exporter imageRef: europe-docker.pkg.dev/sap-se-gcp-k8s-c-delivery/releases-canary-public/quay_io/prometheus/blackbox-exporter@sha256:c0b5630237ab1f8cbe46535a28518ff453289ca1fdccd54d7305a4afdf3ef691 kind: pod name: blackbox-exporter-54d6476f57-vvg7r namespace: kube-system  
                                                            container: calico-node imageRef: europe-docker.pkg.dev/sap-se-gcp-k8s-c-delivery/releases-canary-public/quay_io/calico/node@sha256:77e4e7e76d376136b6567ebcb6738602bcea57c33f996f0f0759660bd29f89ae kind: pod name: calico-node-pbp5x namespace: kube-system  
                                                            container: cleanup-routes imageRef: europe-docker.pkg.dev/sap-se-gcp-k8s-c-delivery/releases-canary-public/quay_io/calico/node@sha256:77e4e7e76d376136b6567ebcb6738602bcea57c33f996f0f0759660bd29f89ae kind: pod name: calico-node-pbp5x namespace: kube-system  
                                                            container: install-cni imageRef: europe-docker.pkg.dev/sap-se-gcp-k8s-c-delivery/releases-canary-public/quay_io/calico/cni@sha256:f9cb36be9c688a3b5e122f2089e2379001836f727e5d7276084537faa0282277 kind: pod name: calico-node-pbp5x namespace: kube-system  
                                                            container: autoscaler imageRef: europe-docker.pkg.dev/sap-se-gcp-k8s-c-delivery/releases-canary-public/registry_k8s_io/cpa/cpvpa@sha256:718f252d47f13e9d47f0b9b51adbff72f43329602d3567cdf7f2c78d51505692 kind: pod name: calico-node-vertical-autoscaler-75c94f77bb-7sxbj namespace: kube-system  
                                                            container: calico-node imageRef: europe-docker.pkg.dev/sap-se-gcp-k8s-c-delivery/releases-canary-public/quay_io/calico/node@sha256:77e4e7e76d376136b6567ebcb6738602bcea57c33f996f0f0759660bd29f89ae kind: pod name: calico-node-xjxgs namespace: kube-system  
                                                            container: cleanup-routes imageRef: europe-docker.pkg.dev/sap-se-gcp-k8s-c-delivery/releases-canary-public/quay_io/calico/node@sha256:77e4e7e76d376136b6567ebcb6738602bcea57c33f996f0f0759660bd29f89ae kind: pod name: calico-node-xjxgs namespace: kube-system  
                                                            container: install-cni imageRef: europe-docker.pkg.dev/sap-se-gcp-k8s-c-delivery/releases-canary-public/quay_io/calico/cni@sha256:f9cb36be9c688a3b5e122f2089e2379001836f727e5d7276084537faa0282277 kind: pod name: calico-node-xjxgs namespace: kube-system  
                                                            container: calico-typha imageRef: europe-docker.pkg.dev/sap-se-gcp-k8s-c-delivery/releases-canary-public/quay_io/calico/typha@sha256:bec6400331c3d36ba035b4ddcfda2b3ad6a5758a2adeaa69116a4e76ca7a70c0 kind: pod name: calico-typha-deploy-6c94dc645b-hxc9n namespace: kube-system  
                                                            container: calico-typha imageRef: europe-docker.pkg.dev/sap-se-gcp-k8s-c-delivery/releases-canary-public/quay_io/calico/typha@sha256:bec6400331c3d36ba035b4ddcfda2b3ad6a5758a2adeaa69116a4e76ca7a70c0 kind: pod name: calico-typha-deploy-6c94dc645b-jx2gb namespace: kube-system  
                                                            container: autoscaler imageRef: europe-docker.pkg.dev/sap-se-gcp-k8s-c-delivery/releases-canary-public/registry_k8s_io/cpa/cluster-proportional-autoscaler@sha256:bc5be9858d29652151d43354e606f2c70789d3a3761998bd75df9198ba9728d1 kind: pod name: calico-typha-horizontal-autoscaler-745ff89c8f-wfsgm namespace: kube-system  
                                                            container: autoscaler imageRef: europe-docker.pkg.dev/sap-se-gcp-k8s-c-delivery/releases-canary-public/registry_k8s_io/cpa/cpvpa@sha256:718f252d47f13e9d47f0b9b51adbff72f43329602d3567cdf7f2c78d51505692 kind: pod name: calico-typha-vertical-autoscaler-59b9756658-zn42c namespace: kube-system  
                                                            container: coredns imageRef: europe-docker.pkg.dev/sap-se-gcp-k8s-c-delivery/releases-canary-public/registry_k8s_io/coredns/coredns@sha256:8d4d5cbada86a545879789f5c13416bc34e3f5e15f3f4c0abdc0dbfd43a2fe6e kind: pod name: coredns-f68b78c49-8xjpl namespace: kube-system  
                                                            container: coredns imageRef: europe-docker.pkg.dev/sap-se-gcp-k8s-c-delivery/releases-canary-public/registry_k8s_io/coredns/coredns@sha256:8d4d5cbada86a545879789f5c13416bc34e3f5e15f3f4c0abdc0dbfd43a2fe6e kind: pod name: coredns-f68b78c49-zkfxf namespace: kube-system  
                                                            container: csi-driver imageRef: europe-docker.pkg.dev/sap-se-gcp-k8s-c-delivery/releases-canary-public/registry_k8s_io/cloud-provider-gcp/gcp-compute-persistent-disk-csi-driver@sha256:c94d6e01f95c8f7b67faed96213ff44eb9669cea21818c50a2ab3d94300aed41 kind: pod name: csi-driver-node-4mx2n namespace: kube-system  
                                                            container: csi-node-driver-registrar imageRef: europe-docker.pkg.dev/sap-se-gcp-k8s-c-delivery/releases-canary-public/registry_k8s_io/sig-storage/csi-node-driver-registrar@sha256:ada6716264d1832d0b5d6aea0bea89215d17d076ab00dd79bce934283eba745c kind: pod name: csi-driver-node-4mx2n namespace: kube-system  
                                                            container: csi-liveness-probe imageRef: europe-docker.pkg.dev/sap-se-gcp-k8s-c-delivery/releases-canary-public/registry_k8s_io/sig-storage/livenessprobe@sha256:ff3acba1cf4edc93e326c33c5e17466894e08d7ba3c4ff17ec9c1ba647014888 kind: pod name: csi-driver-node-4mx2n namespace: kube-system  
                                                            container: csi-driver imageRef: europe-docker.pkg.dev/sap-se-gcp-k8s-c-delivery/releases-canary-public/registry_k8s_io/cloud-provider-gcp/gcp-compute-persistent-disk-csi-driver@sha256:c94d6e01f95c8f7b67faed96213ff44eb9669cea21818c50a2ab3d94300aed41 kind: pod name: csi-driver-node-j8pfg namespace: kube-system  
                                                            container: csi-node-driver-registrar imageRef: europe-docker.pkg.dev/sap-se-gcp-k8s-c-delivery/releases-canary-public/registry_k8s_io/sig-storage/csi-node-driver-registrar@sha256:ada6716264d1832d0b5d6aea0bea89215d17d076ab00dd79bce934283eba745c kind: pod name: csi-driver-node-j8pfg namespace: kube-system  
                                                            container: csi-liveness-probe imageRef: europe-docker.pkg.dev/sap-se-gcp-k8s-c-delivery/releases-canary-public/registry_k8s_io/sig-storage/livenessprobe@sha256:ff3acba1cf4edc93e326c33c5e17466894e08d7ba3c4ff17ec9c1ba647014888 kind: pod name: csi-driver-node-j8pfg namespace: kube-system  
                                                            container: egress-filter-applier imageRef: europe-docker.pkg.dev/sap-se-gcp-k8s-c-delivery/releases-canary-public/europe-docker_pkg_dev/gardener-project/releases/gardener/egress-filter@sha256:b4d3a4929cbfcc7f8886881292ff2dd7cf1804de3527f8f408429686b7cd56bb kind: pod name: egress-filter-applier-b9b5x namespace: kube-system  
                                                            container: egress-filter-applier imageRef: europe-docker.pkg.dev/sap-se-gcp-k8s-c-delivery/releases-canary-public/europe-docker_pkg_dev/gardener-project/releases/gardener/egress-filter@sha256:b4d3a4929cbfcc7f8886881292ff2dd7cf1804de3527f8f408429686b7cd56bb kind: pod name: egress-filter-applier-pkr9q namespace: kube-system  
                                                            container: kube-proxy imageRef: europe-docker.pkg.dev/sap-se-gcp-k8s-c-delivery/releases-canary-public/registry_k8s_io/kube-proxy@sha256:41eac9ffe4ecc06e10555cefd5a821cd1470674d32804975f1d95774cc0fbac2 kind: pod name: kube-proxy-worker-bex82-v1.31.8-krn64 namespace: kube-system  
                                                            container: conntrack-fix imageRef: europe-docker.pkg.dev/sap-se-gcp-k8s-c-delivery/releases-canary-public/europe-docker_pkg_dev/gardener-project/releases/gardener/alpine-conntrack@sha256:78af1e338e7bd65c566e2edf298daae4fba78edbde12aadbe19c7ba504aa726a kind: pod name: kube-proxy-worker-bex82-v1.31.8-krn64 namespace: kube-system  
                                                            container: cleanup imageRef: europe-docker.pkg.dev/sap-se-gcp-k8s-c-delivery/releases-canary-public/registry_k8s_io/kube-proxy@sha256:41eac9ffe4ecc06e10555cefd5a821cd1470674d32804975f1d95774cc0fbac2 kind: pod name: kube-proxy-worker-bex82-v1.31.8-krn64 namespace: kube-system  
                                                            container: kube-proxy-init imageRef: europe-docker.pkg.dev/sap-se-gcp-k8s-c-delivery/releases-canary-public/registry_k8s_io/kube-proxy@sha256:41eac9ffe4ecc06e10555cefd5a821cd1470674d32804975f1d95774cc0fbac2 kind: pod name: kube-proxy-worker-bex82-v1.31.8-krn64 namespace: kube-system  
                                                            container: kube-proxy imageRef: europe-docker.pkg.dev/sap-se-gcp-k8s-c-delivery/releases-canary-public/registry_k8s_io/kube-proxy@sha256:41eac9ffe4ecc06e10555cefd5a821cd1470674d32804975f1d95774cc0fbac2 kind: pod name: kube-proxy-worker-bex82-v1.31.8-x9kg4 namespace: kube-system  
                                                            container: conntrack-fix imageRef: europe-docker.pkg.dev/sap-se-gcp-k8s-c-delivery/releases-canary-public/europe-docker_pkg_dev/gardener-project/releases/gardener/alpine-conntrack@sha256:78af1e338e7bd65c566e2edf298daae4fba78edbde12aadbe19c7ba504aa726a kind: pod name: kube-proxy-worker-bex82-v1.31.8-x9kg4 namespace: kube-system  
                                                            container: cleanup imageRef: europe-docker.pkg.dev/sap-se-gcp-k8s-c-delivery/releases-canary-public/registry_k8s_io/kube-proxy@sha256:41eac9ffe4ecc06e10555cefd5a821cd1470674d32804975f1d95774cc0fbac2 kind: pod name: kube-proxy-worker-bex82-v1.31.8-x9kg4 namespace: kube-system  
                                                            container: kube-proxy-init imageRef: europe-docker.pkg.dev/sap-se-gcp-k8s-c-delivery/releases-canary-public/registry_k8s_io/kube-proxy@sha256:41eac9ffe4ecc06e10555cefd5a821cd1470674d32804975f1d95774cc0fbac2 kind: pod name: kube-proxy-worker-bex82-v1.31.8-x9kg4 namespace: kube-system  
                                                            container: metrics-server imageRef: europe-docker.pkg.dev/sap-se-gcp-k8s-c-delivery/releases-canary-public/registry_k8s_io/metrics-server/metrics-server@sha256:c23c277b728b2838a0c7a9634d170e1e5d3a0324bfa5b049216f98348989711e kind: pod name: metrics-server-5df6676dbf-kbm29 namespace: kube-system  
                                                            container: metrics-server imageRef: europe-docker.pkg.dev/sap-se-gcp-k8s-c-delivery/releases-canary-public/registry_k8s_io/metrics-server/metrics-server@sha256:c23c277b728b2838a0c7a9634d170e1e5d3a0324bfa5b049216f98348989711e kind: pod name: metrics-server-5df6676dbf-tkhb2 namespace: kube-system  
                                                            container: network-problem-detector-host imageRef: europe-docker.pkg.dev/sap-se-gcp-k8s-c-delivery/releases-canary-public/europe-docker_pkg_dev/gardener-project/releases/gardener/network-problem-detector@sha256:eb29f76998e46429c61d7dd1597aef3812d9d2abe2754dfe6c2e6ca0888c0599 kind: pod name: network-problem-detector-host-8ltzf namespace: kube-system  
                                                            container: network-problem-detector-host imageRef: europe-docker.pkg.dev/sap-se-gcp-k8s-c-delivery/releases-canary-public/europe-docker_pkg_dev/gardener-project/releases/gardener/network-problem-detector@sha256:eb29f76998e46429c61d7dd1597aef3812d9d2abe2754dfe6c2e6ca0888c0599 kind: pod name: network-problem-detector-host-hd4cf namespace: kube-system  
                                                            container: network-problem-detector-pod imageRef: europe-docker.pkg.dev/sap-se-gcp-k8s-c-delivery/releases-canary-public/europe-docker_pkg_dev/gardener-project/releases/gardener/network-problem-detector@sha256:eb29f76998e46429c61d7dd1597aef3812d9d2abe2754dfe6c2e6ca0888c0599 kind: pod name: network-problem-detector-pod-gz2ph namespace: kube-system  
                                                            container: network-problem-detector-pod imageRef: europe-docker.pkg.dev/sap-se-gcp-k8s-c-delivery/releases-canary-public/europe-docker_pkg_dev/gardener-project/releases/gardener/network-problem-detector@sha256:eb29f76998e46429c61d7dd1597aef3812d9d2abe2754dfe6c2e6ca0888c0599 kind: pod name: network-problem-detector-pod-q8tj6 namespace: kube-system  
                                                            container: node-exporter imageRef: europe-docker.pkg.dev/sap-se-gcp-k8s-c-delivery/releases-canary-public/quay_io/prometheus/node-exporter@sha256:d88466fb3dd1c9b0c2b855204813cb282ffdad4e74082c54f9928aa0f4a61b1c kind: pod name: node-exporter-5jtvr namespace: kube-system  
                                                            container: node-exporter imageRef: europe-docker.pkg.dev/sap-se-gcp-k8s-c-delivery/releases-canary-public/quay_io/prometheus/node-exporter@sha256:d88466fb3dd1c9b0c2b855204813cb282ffdad4e74082c54f9928aa0f4a61b1c kind: pod name: node-exporter-s5t8x namespace: kube-system  
                                                            container: node-cache imageRef: europe-docker.pkg.dev/sap-se-gcp-k8s-c-delivery/releases-canary-public/registry_k8s_io/dns/k8s-dns-node-cache@sha256:3d39a99c3f3b17724e5feee1645b4e7d4a0637212df1d242c7da3104cda4da9f kind: pod name: node-local-dns-f29m2 namespace: kube-system  
                                                            container: node-cache imageRef: europe-docker.pkg.dev/sap-se-gcp-k8s-c-delivery/releases-canary-public/registry_k8s_io/dns/k8s-dns-node-cache@sha256:3d39a99c3f3b17724e5feee1645b4e7d4a0637212df1d242c7da3104cda4da9f kind: pod name: node-local-dns-srwg9 namespace: kube-system  
                                                            container: node-problem-detector imageRef: europe-docker.pkg.dev/sap-se-gcp-k8s-c-delivery/releases-canary-public/registry_k8s_io/node-problem-detector/node-problem-detector@sha256:bf1d6e7fed0dbc403a7513065ebe071d748b2fe8fe754d76eb9afe988bfc5f67 kind: pod name: node-problem-detector-2jzhw namespace: kube-system  
                                                            container: node-problem-detector imageRef: europe-docker.pkg.dev/sap-se-gcp-k8s-c-delivery/releases-canary-public/registry_k8s_io/node-problem-detector/node-problem-detector@sha256:bf1d6e7fed0dbc403a7513065ebe071d748b2fe8fe754d76eb9afe988bfc5f67 kind: pod name: node-problem-detector-5qmlk namespace: kube-system  
                                                            container: vpn-shoot imageRef: europe-docker.pkg.dev/sap-se-gcp-k8s-c-delivery/releases-canary-public/europe-docker_pkg_dev/gardener-project/releases/gardener/vpn-client@sha256:f90507cc750e0e6223edfe2fe58e4dd923a492d154329ea00d6ff7f9e6285217 kind: pod name: vpn-shoot-5b6c54bdc9-dh49n namespace: kube-system  
                                                            container: vpn-shoot-init imageRef: europe-docker.pkg.dev/sap-se-gcp-k8s-c-delivery/releases-canary-public/europe-docker_pkg_dev/gardener-project/releases/gardener/vpn-client@sha256:f90507cc750e0e6223edfe2fe58e4dd923a492d154329ea00d6ff7f9e6285217 kind: pod name: vpn-shoot-5b6c54bdc9-dh49n namespace: kube-system  
                                                         
                                                     
                                                    
                                                        openstack 
                                                        
                                                            container: sidecar imageRef: europe-docker.pkg.dev/sap-se-gcp-k8s-c-delivery/releases-canary-public/europe-docker_pkg_dev/gardener-project/releases/gardener/apiserver-proxy@sha256:d3b9d9af4f420682fda692211a170a52702efb0ee3a3a12e1532f6ff10e2e764 kind: pod name: apiserver-proxy-mjfl5 namespace: kube-system  
                                                            container: proxy imageRef: europe-docker.pkg.dev/sap-se-gcp-k8s-c-delivery/releases-canary-public/europe-docker_pkg_dev/gardener-project/releases/3rd/envoyproxy/envoy-distroless@sha256:26baf54b0e1f6eac2b2f47ade7dbbf69d44426d3b0acc310c4c48772cecd7e6c kind: pod name: apiserver-proxy-mjfl5 namespace: kube-system  
                                                            container: setup imageRef: europe-docker.pkg.dev/sap-se-gcp-k8s-c-delivery/releases-canary-public/europe-docker_pkg_dev/gardener-project/releases/gardener/apiserver-proxy@sha256:d3b9d9af4f420682fda692211a170a52702efb0ee3a3a12e1532f6ff10e2e764 kind: pod name: apiserver-proxy-mjfl5 namespace: kube-system  
                                                            container: sidecar imageRef: europe-docker.pkg.dev/sap-se-gcp-k8s-c-delivery/releases-canary-public/europe-docker_pkg_dev/gardener-project/releases/gardener/apiserver-proxy@sha256:d3b9d9af4f420682fda692211a170a52702efb0ee3a3a12e1532f6ff10e2e764 kind: pod name: apiserver-proxy-zp6mh namespace: kube-system  
                                                            container: proxy imageRef: europe-docker.pkg.dev/sap-se-gcp-k8s-c-delivery/releases-canary-public/europe-docker_pkg_dev/gardener-project/releases/3rd/envoyproxy/envoy-distroless@sha256:26baf54b0e1f6eac2b2f47ade7dbbf69d44426d3b0acc310c4c48772cecd7e6c kind: pod name: apiserver-proxy-zp6mh namespace: kube-system  
                                                            container: setup imageRef: europe-docker.pkg.dev/sap-se-gcp-k8s-c-delivery/releases-canary-public/europe-docker_pkg_dev/gardener-project/releases/gardener/apiserver-proxy@sha256:d3b9d9af4f420682fda692211a170a52702efb0ee3a3a12e1532f6ff10e2e764 kind: pod name: apiserver-proxy-zp6mh namespace: kube-system  
                                                            container: blackbox-exporter imageRef: europe-docker.pkg.dev/sap-se-gcp-k8s-c-delivery/releases-canary-public/quay_io/prometheus/blackbox-exporter@sha256:c0b5630237ab1f8cbe46535a28518ff453289ca1fdccd54d7305a4afdf3ef691 kind: pod name: blackbox-exporter-54d6476f57-4jfn4 namespace: kube-system  
                                                            container: blackbox-exporter imageRef: europe-docker.pkg.dev/sap-se-gcp-k8s-c-delivery/releases-canary-public/quay_io/prometheus/blackbox-exporter@sha256:c0b5630237ab1f8cbe46535a28518ff453289ca1fdccd54d7305a4afdf3ef691 kind: pod name: blackbox-exporter-54d6476f57-vprcp namespace: kube-system  
                                                            container: calico-kube-controllers imageRef: europe-docker.pkg.dev/sap-se-gcp-k8s-c-delivery/releases-canary-public/quay_io/calico/kube-controllers@sha256:9d1ea173e7d4e9de8ef87a82fdbc7105c6e470c321301df33311f6b7ba8d6435 kind: pod name: calico-kube-controllers-5f4cb8d889-mcgpq namespace: kube-system  
                                                            container: network-unavailable-condition-ensurer imageRef: europe-docker.pkg.dev/sap-se-gcp-k8s-c-delivery/releases-canary-public/quay_io/calico/node@sha256:77e4e7e76d376136b6567ebcb6738602bcea57c33f996f0f0759660bd29f89ae kind: pod name: calico-node-rsrv5 namespace: kube-system  
                                                            container: calico-node imageRef: europe-docker.pkg.dev/sap-se-gcp-k8s-c-delivery/releases-canary-public/quay_io/calico/node@sha256:77e4e7e76d376136b6567ebcb6738602bcea57c33f996f0f0759660bd29f89ae kind: pod name: calico-node-rsrv5 namespace: kube-system  
                                                            container: install-cni imageRef: europe-docker.pkg.dev/sap-se-gcp-k8s-c-delivery/releases-canary-public/quay_io/calico/cni@sha256:f9cb36be9c688a3b5e122f2089e2379001836f727e5d7276084537faa0282277 kind: pod name: calico-node-rsrv5 namespace: kube-system  
                                                            container: autoscaler imageRef: europe-docker.pkg.dev/sap-se-gcp-k8s-c-delivery/releases-canary-public/registry_k8s_io/cpa/cpvpa@sha256:718f252d47f13e9d47f0b9b51adbff72f43329602d3567cdf7f2c78d51505692 kind: pod name: calico-node-vertical-autoscaler-75c94f77bb-zjc72 namespace: kube-system  
                                                            container: network-unavailable-condition-ensurer imageRef: europe-docker.pkg.dev/sap-se-gcp-k8s-c-delivery/releases-canary-public/quay_io/calico/node@sha256:77e4e7e76d376136b6567ebcb6738602bcea57c33f996f0f0759660bd29f89ae kind: pod name: calico-node-wdnsn namespace: kube-system  
                                                            container: calico-node imageRef: europe-docker.pkg.dev/sap-se-gcp-k8s-c-delivery/releases-canary-public/quay_io/calico/node@sha256:77e4e7e76d376136b6567ebcb6738602bcea57c33f996f0f0759660bd29f89ae kind: pod name: calico-node-wdnsn namespace: kube-system  
                                                            container: install-cni imageRef: europe-docker.pkg.dev/sap-se-gcp-k8s-c-delivery/releases-canary-public/quay_io/calico/cni@sha256:f9cb36be9c688a3b5e122f2089e2379001836f727e5d7276084537faa0282277 kind: pod name: calico-node-wdnsn namespace: kube-system  
                                                            container: calico-typha imageRef: europe-docker.pkg.dev/sap-se-gcp-k8s-c-delivery/releases-canary-public/quay_io/calico/typha@sha256:bec6400331c3d36ba035b4ddcfda2b3ad6a5758a2adeaa69116a4e76ca7a70c0 kind: pod name: calico-typha-deploy-6c94dc645b-fzc8v namespace: kube-system  
                                                            container: calico-typha imageRef: europe-docker.pkg.dev/sap-se-gcp-k8s-c-delivery/releases-canary-public/quay_io/calico/typha@sha256:bec6400331c3d36ba035b4ddcfda2b3ad6a5758a2adeaa69116a4e76ca7a70c0 kind: pod name: calico-typha-deploy-6c94dc645b-jvpdv namespace: kube-system  
                                                            container: autoscaler imageRef: europe-docker.pkg.dev/sap-se-gcp-k8s-c-delivery/releases-canary-public/registry_k8s_io/cpa/cluster-proportional-autoscaler@sha256:bc5be9858d29652151d43354e606f2c70789d3a3761998bd75df9198ba9728d1 kind: pod name: calico-typha-horizontal-autoscaler-745ff89c8f-jwh2r namespace: kube-system  
                                                            container: autoscaler imageRef: europe-docker.pkg.dev/sap-se-gcp-k8s-c-delivery/releases-canary-public/registry_k8s_io/cpa/cpvpa@sha256:718f252d47f13e9d47f0b9b51adbff72f43329602d3567cdf7f2c78d51505692 kind: pod name: calico-typha-vertical-autoscaler-59b9756658-qx9sd namespace: kube-system  
                                                            container: coredns imageRef: europe-docker.pkg.dev/sap-se-gcp-k8s-c-delivery/releases-canary-public/registry_k8s_io/coredns/coredns@sha256:8d4d5cbada86a545879789f5c13416bc34e3f5e15f3f4c0abdc0dbfd43a2fe6e kind: pod name: coredns-5464fd5895-gzjzz namespace: kube-system  
                                                            container: coredns imageRef: europe-docker.pkg.dev/sap-se-gcp-k8s-c-delivery/releases-canary-public/registry_k8s_io/coredns/coredns@sha256:8d4d5cbada86a545879789f5c13416bc34e3f5e15f3f4c0abdc0dbfd43a2fe6e kind: pod name: coredns-5464fd5895-mgtdc namespace: kube-system  
                                                            container: csi-driver imageRef: europe-docker.pkg.dev/sap-se-gcp-k8s-c-delivery/releases-canary-public/registry_k8s_io/provider-os/cinder-csi-plugin@sha256:73cd7e1551653db9bd332cee1f37357335237f6661f8fb5c7023f88b5e125840 kind: pod name: csi-driver-node-46dm2 namespace: kube-system  
                                                            container: csi-node-driver-registrar imageRef: europe-docker.pkg.dev/sap-se-gcp-k8s-c-delivery/releases-canary-public/registry_k8s_io/sig-storage/csi-node-driver-registrar@sha256:ada6716264d1832d0b5d6aea0bea89215d17d076ab00dd79bce934283eba745c kind: pod name: csi-driver-node-46dm2 namespace: kube-system  
                                                            container: csi-liveness-probe imageRef: europe-docker.pkg.dev/sap-se-gcp-k8s-c-delivery/releases-canary-public/registry_k8s_io/sig-storage/livenessprobe@sha256:ff3acba1cf4edc93e326c33c5e17466894e08d7ba3c4ff17ec9c1ba647014888 kind: pod name: csi-driver-node-46dm2 namespace: kube-system  
                                                            container: csi-driver imageRef: europe-docker.pkg.dev/sap-se-gcp-k8s-c-delivery/releases-canary-public/registry_k8s_io/provider-os/cinder-csi-plugin@sha256:73cd7e1551653db9bd332cee1f37357335237f6661f8fb5c7023f88b5e125840 kind: pod name: csi-driver-node-pwcl7 namespace: kube-system  
                                                            container: csi-node-driver-registrar imageRef: europe-docker.pkg.dev/sap-se-gcp-k8s-c-delivery/releases-canary-public/registry_k8s_io/sig-storage/csi-node-driver-registrar@sha256:ada6716264d1832d0b5d6aea0bea89215d17d076ab00dd79bce934283eba745c kind: pod name: csi-driver-node-pwcl7 namespace: kube-system  
                                                            container: csi-liveness-probe imageRef: europe-docker.pkg.dev/sap-se-gcp-k8s-c-delivery/releases-canary-public/registry_k8s_io/sig-storage/livenessprobe@sha256:ff3acba1cf4edc93e326c33c5e17466894e08d7ba3c4ff17ec9c1ba647014888 kind: pod name: csi-driver-node-pwcl7 namespace: kube-system  
                                                            container: egress-filter-applier imageRef: europe-docker.pkg.dev/sap-se-gcp-k8s-c-delivery/releases-canary-public/europe-docker_pkg_dev/gardener-project/releases/gardener/egress-filter@sha256:b4d3a4929cbfcc7f8886881292ff2dd7cf1804de3527f8f408429686b7cd56bb kind: pod name: egress-filter-applier-b5z8f namespace: kube-system  
                                                            container: egress-filter-applier imageRef: europe-docker.pkg.dev/sap-se-gcp-k8s-c-delivery/releases-canary-public/europe-docker_pkg_dev/gardener-project/releases/gardener/egress-filter@sha256:b4d3a4929cbfcc7f8886881292ff2dd7cf1804de3527f8f408429686b7cd56bb kind: pod name: egress-filter-applier-b6786 namespace: kube-system  
                                                            container: kube-proxy imageRef: europe-docker.pkg.dev/sap-se-gcp-k8s-c-delivery/releases-canary-public/registry_k8s_io/kube-proxy@sha256:41eac9ffe4ecc06e10555cefd5a821cd1470674d32804975f1d95774cc0fbac2 kind: pod name: kube-proxy-worker-dqty2-v1.31.8-9sx78 namespace: kube-system  
                                                            container: conntrack-fix imageRef: europe-docker.pkg.dev/sap-se-gcp-k8s-c-delivery/releases-canary-public/europe-docker_pkg_dev/gardener-project/releases/gardener/alpine-conntrack@sha256:78af1e338e7bd65c566e2edf298daae4fba78edbde12aadbe19c7ba504aa726a kind: pod name: kube-proxy-worker-dqty2-v1.31.8-9sx78 namespace: kube-system  
                                                            container: cleanup imageRef: europe-docker.pkg.dev/sap-se-gcp-k8s-c-delivery/releases-canary-public/registry_k8s_io/kube-proxy@sha256:41eac9ffe4ecc06e10555cefd5a821cd1470674d32804975f1d95774cc0fbac2 kind: pod name: kube-proxy-worker-dqty2-v1.31.8-9sx78 namespace: kube-system  
                                                            container: kube-proxy-init imageRef: europe-docker.pkg.dev/sap-se-gcp-k8s-c-delivery/releases-canary-public/registry_k8s_io/kube-proxy@sha256:41eac9ffe4ecc06e10555cefd5a821cd1470674d32804975f1d95774cc0fbac2 kind: pod name: kube-proxy-worker-dqty2-v1.31.8-9sx78 namespace: kube-system  
                                                            container: kube-proxy imageRef: europe-docker.pkg.dev/sap-se-gcp-k8s-c-delivery/releases-canary-public/registry_k8s_io/kube-proxy@sha256:41eac9ffe4ecc06e10555cefd5a821cd1470674d32804975f1d95774cc0fbac2 kind: pod name: kube-proxy-worker-dqty2-v1.31.8-fwp8d namespace: kube-system  
                                                            container: conntrack-fix imageRef: europe-docker.pkg.dev/sap-se-gcp-k8s-c-delivery/releases-canary-public/europe-docker_pkg_dev/gardener-project/releases/gardener/alpine-conntrack@sha256:78af1e338e7bd65c566e2edf298daae4fba78edbde12aadbe19c7ba504aa726a kind: pod name: kube-proxy-worker-dqty2-v1.31.8-fwp8d namespace: kube-system  
                                                            container: cleanup imageRef: europe-docker.pkg.dev/sap-se-gcp-k8s-c-delivery/releases-canary-public/registry_k8s_io/kube-proxy@sha256:41eac9ffe4ecc06e10555cefd5a821cd1470674d32804975f1d95774cc0fbac2 kind: pod name: kube-proxy-worker-dqty2-v1.31.8-fwp8d namespace: kube-system  
                                                            container: kube-proxy-init imageRef: europe-docker.pkg.dev/sap-se-gcp-k8s-c-delivery/releases-canary-public/registry_k8s_io/kube-proxy@sha256:41eac9ffe4ecc06e10555cefd5a821cd1470674d32804975f1d95774cc0fbac2 kind: pod name: kube-proxy-worker-dqty2-v1.31.8-fwp8d namespace: kube-system  
                                                            container: metrics-server imageRef: europe-docker.pkg.dev/sap-se-gcp-k8s-c-delivery/releases-canary-public/registry_k8s_io/metrics-server/metrics-server@sha256:c23c277b728b2838a0c7a9634d170e1e5d3a0324bfa5b049216f98348989711e kind: pod name: metrics-server-7c7946c76-gsxtg namespace: kube-system  
                                                            container: metrics-server imageRef: europe-docker.pkg.dev/sap-se-gcp-k8s-c-delivery/releases-canary-public/registry_k8s_io/metrics-server/metrics-server@sha256:c23c277b728b2838a0c7a9634d170e1e5d3a0324bfa5b049216f98348989711e kind: pod name: metrics-server-7c7946c76-szr7s namespace: kube-system  
                                                            container: network-problem-detector-host imageRef: europe-docker.pkg.dev/sap-se-gcp-k8s-c-delivery/releases-canary-public/europe-docker_pkg_dev/gardener-project/releases/gardener/network-problem-detector@sha256:eb29f76998e46429c61d7dd1597aef3812d9d2abe2754dfe6c2e6ca0888c0599 kind: pod name: network-problem-detector-host-75kzx namespace: kube-system  
                                                            container: network-problem-detector-host imageRef: europe-docker.pkg.dev/sap-se-gcp-k8s-c-delivery/releases-canary-public/europe-docker_pkg_dev/gardener-project/releases/gardener/network-problem-detector@sha256:eb29f76998e46429c61d7dd1597aef3812d9d2abe2754dfe6c2e6ca0888c0599 kind: pod name: network-problem-detector-host-xhqzr namespace: kube-system  
                                                            container: network-problem-detector-pod imageRef: europe-docker.pkg.dev/sap-se-gcp-k8s-c-delivery/releases-canary-public/europe-docker_pkg_dev/gardener-project/releases/gardener/network-problem-detector@sha256:eb29f76998e46429c61d7dd1597aef3812d9d2abe2754dfe6c2e6ca0888c0599 kind: pod name: network-problem-detector-pod-7kj5v namespace: kube-system  
                                                            container: network-problem-detector-pod imageRef: europe-docker.pkg.dev/sap-se-gcp-k8s-c-delivery/releases-canary-public/europe-docker_pkg_dev/gardener-project/releases/gardener/network-problem-detector@sha256:eb29f76998e46429c61d7dd1597aef3812d9d2abe2754dfe6c2e6ca0888c0599 kind: pod name: network-problem-detector-pod-bb6zl namespace: kube-system  
                                                            container: node-exporter imageRef: europe-docker.pkg.dev/sap-se-gcp-k8s-c-delivery/releases-canary-public/quay_io/prometheus/node-exporter@sha256:d88466fb3dd1c9b0c2b855204813cb282ffdad4e74082c54f9928aa0f4a61b1c kind: pod name: node-exporter-4cp5g namespace: kube-system  
                                                            container: node-exporter imageRef: europe-docker.pkg.dev/sap-se-gcp-k8s-c-delivery/releases-canary-public/quay_io/prometheus/node-exporter@sha256:d88466fb3dd1c9b0c2b855204813cb282ffdad4e74082c54f9928aa0f4a61b1c kind: pod name: node-exporter-rshd2 namespace: kube-system  
                                                            container: node-cache imageRef: europe-docker.pkg.dev/sap-se-gcp-k8s-c-delivery/releases-canary-public/registry_k8s_io/dns/k8s-dns-node-cache@sha256:3d39a99c3f3b17724e5feee1645b4e7d4a0637212df1d242c7da3104cda4da9f kind: pod name: node-local-dns-57bpm namespace: kube-system  
                                                            container: node-cache imageRef: europe-docker.pkg.dev/sap-se-gcp-k8s-c-delivery/releases-canary-public/registry_k8s_io/dns/k8s-dns-node-cache@sha256:3d39a99c3f3b17724e5feee1645b4e7d4a0637212df1d242c7da3104cda4da9f kind: pod name: node-local-dns-8b6dg namespace: kube-system  
                                                            container: node-problem-detector imageRef: europe-docker.pkg.dev/sap-se-gcp-k8s-c-delivery/releases-canary-public/registry_k8s_io/node-problem-detector/node-problem-detector@sha256:bf1d6e7fed0dbc403a7513065ebe071d748b2fe8fe754d76eb9afe988bfc5f67 kind: pod name: node-problem-detector-2dxfn namespace: kube-system  
                                                            container: node-problem-detector imageRef: europe-docker.pkg.dev/sap-se-gcp-k8s-c-delivery/releases-canary-public/registry_k8s_io/node-problem-detector/node-problem-detector@sha256:bf1d6e7fed0dbc403a7513065ebe071d748b2fe8fe754d76eb9afe988bfc5f67 kind: pod name: node-problem-detector-5mv98 namespace: kube-system  
                                                            container: vpn-shoot imageRef: europe-docker.pkg.dev/sap-se-gcp-k8s-c-delivery/releases-canary-public/europe-docker_pkg_dev/gardener-project/releases/gardener/vpn-client@sha256:f90507cc750e0e6223edfe2fe58e4dd923a492d154329ea00d6ff7f9e6285217 kind: pod name: vpn-shoot-54dfc94bd-jlgl9 namespace: kube-system  
                                                            container: vpn-shoot-init imageRef: europe-docker.pkg.dev/sap-se-gcp-k8s-c-delivery/releases-canary-public/europe-docker_pkg_dev/gardener-project/releases/gardener/vpn-client@sha256:f90507cc750e0e6223edfe2fe58e4dd923a492d154329ea00d6ff7f9e6285217 kind: pod name: vpn-shoot-54dfc94bd-jlgl9 namespace: kube-system  
                                                         
                                                     
                                                 
                                             
                                         
                                     
                                    
                                        2006 (Medium) - Limit the use of wildcards in RBAC resources. 
                                        
                                            
                                                Role does not use "*" in policy rule resources. 
                                                
                                                    
                                                        aws 
                                                        
                                                            kind: role name: gardener.cloud:target:dependency-watchdog namespace: kube-node-lease  
                                                            kind: role name: system:controller:bootstrap-signer namespace: kube-public  
                                                            kind: role name: extension-apiserver-authentication-reader namespace: kube-system  
                                                            kind: role name: extensions.gardener.cloud:extension-shoot-cert-service:cert-controller-manager namespace: kube-system  
                                                            kind: role name: extensions.gardener.cloud:extension-shoot-dns-service:shoot-dns-service namespace: kube-system  
                                                            kind: role name: extensions.gardener.cloud:extension-shoot-networking-problem-detector:shoot namespace: kube-system  
                                                            kind: role name: extensions.gardener.cloud:provider-aws:aws-custom-route-controller namespace: kube-system  
                                                            kind: role name: extensions.gardener.cloud:provider-aws:csi-attacher namespace: kube-system  
                                                            kind: role name: extensions.gardener.cloud:provider-aws:csi-provisioner namespace: kube-system  
                                                            kind: role name: extensions.gardener.cloud:provider-aws:csi-resizer namespace: kube-system  
                                                            kind: role name: extensions.gardener.cloud:provider-aws:csi-snapshot-controller namespace: kube-system  
                                                            kind: role name: extensions.gardener.cloud:provider-aws:csi-snapshotter namespace: kube-system  
                                                            kind: role name: extensions.gardener.cloud:provider-aws:csi-volume-modifier namespace: kube-system  
                                                            kind: role name: gardener-node-agent namespace: kube-system  
                                                            kind: role name: gardener.cloud:target:machine-controller-manager namespace: kube-system  
                                                            kind: role name: gardener.cloud:vpa:target:leader-locking-vpa-recommender namespace: kube-system  
                                                            kind: role name: gardener.cloud:vpa:target:leader-locking-vpa-updater namespace: kube-system  
                                                            kind: role name: system::leader-locking-kube-controller-manager namespace: kube-system  
                                                            kind: role name: system::leader-locking-kube-scheduler namespace: kube-system  
                                                            kind: role name: system:controller:bootstrap-signer namespace: kube-system  
                                                            kind: role name: system:controller:cloud-provider namespace: kube-system  
                                                            kind: role name: system:controller:token-cleaner namespace: kube-system  
                                                            kind: role name: typha-cpha namespace: kube-system  
                                                            kind: clusterRole name: admin  
                                                            kind: clusterRole name: calico-cni-plugin  
                                                            kind: clusterRole name: calico-node  
                                                            kind: clusterRole name: calico-node-cpva  
                                                            kind: clusterRole name: edit  
                                                            kind: clusterRole name: event-logger  
                                                            kind: clusterRole name: extensions.gardener.cloud:extension-shoot-cert-service:shoot  
                                                            kind: clusterRole name: extensions.gardener.cloud:extension-shoot-dns-service:shoot-dns-service  
                                                            kind: clusterRole name: extensions.gardener.cloud:extension-shoot-networking-problem-detector:shoot  
                                                            kind: clusterRole name: extensions.gardener.cloud:provider-aws:aws-custom-route-controller  
                                                            kind: clusterRole name: extensions.gardener.cloud:provider-aws:csi-attacher  
                                                            kind: clusterRole name: extensions.gardener.cloud:provider-aws:csi-driver  
                                                            kind: clusterRole name: extensions.gardener.cloud:provider-aws:csi-provisioner  
                                                            kind: clusterRole name: extensions.gardener.cloud:provider-aws:csi-resizer  
                                                            kind: clusterRole name: extensions.gardener.cloud:provider-aws:csi-snapshot-controller  
                                                            kind: clusterRole name: extensions.gardener.cloud:provider-aws:csi-snapshotter  
                                                            kind: clusterRole name: extensions.gardener.cloud:provider-aws:csi-volume-modifier  
                                                            kind: clusterRole name: gardener-extension-shoot-lakom-service-resource-reader  
                                                            kind: clusterRole name: gardener-node-agent  
                                                            kind: clusterRole name: gardener.cloud:kube-system:network-problem-detector  
                                                            kind: clusterRole name: gardener.cloud:logging:valitail  
                                                            kind: clusterRole name: gardener.cloud:monitoring:kube-state-metrics  
                                                            kind: clusterRole name: gardener.cloud:monitoring:prometheus-shoot  
                                                            kind: clusterRole name: gardener.cloud:system:read-only  
                                                            kind: clusterRole name: gardener.cloud:target:dependency-watchdog  
                                                            kind: clusterRole name: gardener.cloud:target:machine-controller-manager  
                                                            kind: clusterRole name: gardener.cloud:vpa:target:actor  
                                                            kind: clusterRole name: gardener.cloud:vpa:target:admission-controller  
                                                            kind: clusterRole name: gardener.cloud:vpa:target:checkpoint-actor  
                                                            kind: clusterRole name: gardener.cloud:vpa:target:evictioner  
                                                            kind: clusterRole name: gardener.cloud:vpa:target:metrics-reader  
                                                            kind: clusterRole name: gardener.cloud:vpa:target:status-actor  
                                                            kind: clusterRole name: node-problem-detector  
                                                            kind: clusterRole name: system:aggregate-to-admin  
                                                            kind: clusterRole name: system:aggregate-to-edit  
                                                            kind: clusterRole name: system:aggregate-to-view  
                                                            kind: clusterRole name: system:apiserver:kubelet  
                                                            kind: clusterRole name: system:auth-delegator  
                                                            kind: clusterRole name: system:basic-user  
                                                            kind: clusterRole name: system:certificates.k8s.io:certificatesigningrequests:nodeclient  
                                                            kind: clusterRole name: system:certificates.k8s.io:certificatesigningrequests:selfnodeclient  
                                                            kind: clusterRole name: system:certificates.k8s.io:kube-apiserver-client-approver  
                                                            kind: clusterRole name: system:certificates.k8s.io:kube-apiserver-client-kubelet-approver  
                                                            kind: clusterRole name: system:certificates.k8s.io:kubelet-serving-approver  
                                                            kind: clusterRole name: system:certificates.k8s.io:legacy-unknown-approver  
                                                            kind: clusterRole name: system:controller:attachdetach-controller  
                                                            kind: clusterRole name: system:controller:certificate-controller  
                                                            kind: clusterRole name: system:controller:clusterrole-aggregation-controller  
                                                            kind: clusterRole name: system:controller:cronjob-controller  
                                                            kind: clusterRole name: system:controller:daemon-set-controller  
                                                            kind: clusterRole name: system:controller:deployment-controller  
                                                            kind: clusterRole name: system:controller:endpoint-controller  
                                                            kind: clusterRole name: system:controller:endpointslice-controller  
                                                            kind: clusterRole name: system:controller:endpointslicemirroring-controller  
                                                            kind: clusterRole name: system:controller:ephemeral-volume-controller  
                                                            kind: clusterRole name: system:controller:expand-controller  
                                                            kind: clusterRole name: system:controller:job-controller  
                                                            kind: clusterRole name: system:controller:legacy-service-account-token-cleaner  
                                                            kind: clusterRole name: system:controller:node-controller  
                                                            kind: clusterRole name: system:controller:persistent-volume-binder  
                                                            kind: clusterRole name: system:controller:pod-garbage-collector  
                                                            kind: clusterRole name: system:controller:pv-protection-controller  
                                                            kind: clusterRole name: system:controller:pvc-protection-controller  
                                                            kind: clusterRole name: system:controller:replicaset-controller  
                                                            kind: clusterRole name: system:controller:replication-controller  
                                                            kind: clusterRole name: system:controller:root-ca-cert-publisher  
                                                            kind: clusterRole name: system:controller:route-controller  
                                                            kind: clusterRole name: system:controller:service-account-controller  
                                                            kind: clusterRole name: system:controller:service-controller  
                                                            kind: clusterRole name: system:controller:statefulset-controller  
                                                            kind: clusterRole name: system:controller:ttl-after-finished-controller  
                                                            kind: clusterRole name: system:controller:ttl-controller  
                                                            kind: clusterRole name: system:controller:validatingadmissionpolicy-status-controller  
                                                            kind: clusterRole name: system:coredns  
                                                            kind: clusterRole name: system:discovery  
                                                            kind: clusterRole name: system:heapster  
                                                            kind: clusterRole name: system:kube-aggregator  
                                                            kind: clusterRole name: system:kube-dns  
                                                            kind: clusterRole name: system:kube-scheduler  
                                                            kind: clusterRole name: system:kubelet-api-admin  
                                                            kind: clusterRole name: system:metrics-server  
                                                            kind: clusterRole name: system:monitoring  
                                                            kind: clusterRole name: system:node  
                                                            kind: clusterRole name: system:node-bootstrapper  
                                                            kind: clusterRole name: system:node-problem-detector  
                                                            kind: clusterRole name: system:node-proxier  
                                                            kind: clusterRole name: system:persistent-volume-provisioner  
                                                            kind: clusterRole name: system:public-info-viewer  
                                                            kind: clusterRole name: system:service-account-issuer-discovery  
                                                            kind: clusterRole name: system:volume-scheduler  
                                                            kind: clusterRole name: typha-cpha  
                                                            kind: clusterRole name: typha-cpva  
                                                            kind: clusterRole name: view  
                                                         
                                                     
                                                    
                                                        azure 
                                                        
                                                            kind: role name: gardener.cloud:target:dependency-watchdog namespace: kube-node-lease  
                                                            kind: role name: system:controller:bootstrap-signer namespace: kube-public  
                                                            kind: role name: extension-apiserver-authentication-reader namespace: kube-system  
                                                            kind: role name: extensions.gardener.cloud:extension-shoot-cert-service:cert-controller-manager namespace: kube-system  
                                                            kind: role name: extensions.gardener.cloud:extension-shoot-dns-service:shoot-dns-service namespace: kube-system  
                                                            kind: role name: extensions.gardener.cloud:extension-shoot-networking-problem-detector:shoot namespace: kube-system  
                                                            kind: role name: extensions.gardener.cloud:provider-azure:csi-attacher namespace: kube-system  
                                                            kind: role name: extensions.gardener.cloud:provider-azure:csi-provisioner namespace: kube-system  
                                                            kind: role name: extensions.gardener.cloud:provider-azure:csi-resizer namespace: kube-system  
                                                            kind: role name: extensions.gardener.cloud:provider-azure:csi-snapshot-controller namespace: kube-system  
                                                            kind: role name: extensions.gardener.cloud:provider-azure:csi-snapshotter namespace: kube-system  
                                                            kind: role name: gardener-node-agent namespace: kube-system  
                                                            kind: role name: gardener.cloud:target:machine-controller-manager namespace: kube-system  
                                                            kind: role name: gardener.cloud:vpa:target:leader-locking-vpa-recommender namespace: kube-system  
                                                            kind: role name: gardener.cloud:vpa:target:leader-locking-vpa-updater namespace: kube-system  
                                                            kind: role name: system::leader-locking-kube-controller-manager namespace: kube-system  
                                                            kind: role name: system::leader-locking-kube-scheduler namespace: kube-system  
                                                            kind: role name: system:controller:bootstrap-signer namespace: kube-system  
                                                            kind: role name: system:controller:cloud-provider namespace: kube-system  
                                                            kind: role name: system:controller:token-cleaner namespace: kube-system  
                                                            kind: role name: typha-cpha namespace: kube-system  
                                                            kind: clusterRole name: admin  
                                                            kind: clusterRole name: calico-cni-plugin  
                                                            kind: clusterRole name: calico-node  
                                                            kind: clusterRole name: calico-node-cpva  
                                                            kind: clusterRole name: cloud-node-manager  
                                                            kind: clusterRole name: edit  
                                                            kind: clusterRole name: event-logger  
                                                            kind: clusterRole name: extensions.gardener.cloud:extension-shoot-cert-service:shoot  
                                                            kind: clusterRole name: extensions.gardener.cloud:extension-shoot-dns-service:shoot-dns-service  
                                                            kind: clusterRole name: extensions.gardener.cloud:extension-shoot-networking-problem-detector:shoot  
                                                            kind: clusterRole name: extensions.gardener.cloud:provider-azure:csi-attacher  
                                                            kind: clusterRole name: extensions.gardener.cloud:provider-azure:csi-driver  
                                                            kind: clusterRole name: extensions.gardener.cloud:provider-azure:csi-driver-controller-disk  
                                                            kind: clusterRole name: extensions.gardener.cloud:provider-azure:csi-driver-controller-file  
                                                            kind: clusterRole name: extensions.gardener.cloud:provider-azure:csi-provisioner  
                                                            kind: clusterRole name: extensions.gardener.cloud:provider-azure:csi-resizer  
                                                            kind: clusterRole name: extensions.gardener.cloud:provider-azure:csi-snapshot-controller  
                                                            kind: clusterRole name: extensions.gardener.cloud:provider-azure:csi-snapshot-validation  
                                                            kind: clusterRole name: extensions.gardener.cloud:provider-azure:csi-snapshotter  
                                                            kind: clusterRole name: extensions.gardener.cloud:provider-azure:remedy-controller-azure  
                                                            kind: clusterRole name: gardener-extension-shoot-lakom-service-resource-reader  
                                                            kind: clusterRole name: gardener-node-agent  
                                                            kind: clusterRole name: gardener.cloud:kube-system:network-problem-detector  
                                                            kind: clusterRole name: gardener.cloud:logging:valitail  
                                                            kind: clusterRole name: gardener.cloud:monitoring:kube-state-metrics  
                                                            kind: clusterRole name: gardener.cloud:monitoring:prometheus-shoot  
                                                            kind: clusterRole name: gardener.cloud:system:read-only  
                                                            kind: clusterRole name: gardener.cloud:target:dependency-watchdog  
                                                            kind: clusterRole name: gardener.cloud:target:machine-controller-manager  
                                                            kind: clusterRole name: gardener.cloud:vpa:target:actor  
                                                            kind: clusterRole name: gardener.cloud:vpa:target:admission-controller  
                                                            kind: clusterRole name: gardener.cloud:vpa:target:checkpoint-actor  
                                                            kind: clusterRole name: gardener.cloud:vpa:target:evictioner  
                                                            kind: clusterRole name: gardener.cloud:vpa:target:metrics-reader  
                                                            kind: clusterRole name: gardener.cloud:vpa:target:status-actor  
                                                            kind: clusterRole name: node-problem-detector  
                                                            kind: clusterRole name: system:aggregate-to-admin  
                                                            kind: clusterRole name: system:aggregate-to-edit  
                                                            kind: clusterRole name: system:aggregate-to-view  
                                                            kind: clusterRole name: system:apiserver:kubelet  
                                                            kind: clusterRole name: system:auth-delegator  
                                                            kind: clusterRole name: system:azure-cloud-provider  
                                                            kind: clusterRole name: system:basic-user  
                                                            kind: clusterRole name: system:certificates.k8s.io:certificatesigningrequests:nodeclient  
                                                            kind: clusterRole name: system:certificates.k8s.io:certificatesigningrequests:selfnodeclient  
                                                            kind: clusterRole name: system:certificates.k8s.io:kube-apiserver-client-approver  
                                                            kind: clusterRole name: system:certificates.k8s.io:kube-apiserver-client-kubelet-approver  
                                                            kind: clusterRole name: system:certificates.k8s.io:kubelet-serving-approver  
                                                            kind: clusterRole name: system:certificates.k8s.io:legacy-unknown-approver  
                                                            kind: clusterRole name: system:cloud-controller-manager  
                                                            kind: clusterRole name: system:controller:attachdetach-controller  
                                                            kind: clusterRole name: system:controller:certificate-controller  
                                                            kind: clusterRole name: system:controller:clusterrole-aggregation-controller  
                                                            kind: clusterRole name: system:controller:cronjob-controller  
                                                            kind: clusterRole name: system:controller:daemon-set-controller  
                                                            kind: clusterRole name: system:controller:deployment-controller  
                                                            kind: clusterRole name: system:controller:endpoint-controller  
                                                            kind: clusterRole name: system:controller:endpointslice-controller  
                                                            kind: clusterRole name: system:controller:endpointslicemirroring-controller  
                                                            kind: clusterRole name: system:controller:ephemeral-volume-controller  
                                                            kind: clusterRole name: system:controller:expand-controller  
                                                            kind: clusterRole name: system:controller:job-controller  
                                                            kind: clusterRole name: system:controller:legacy-service-account-token-cleaner  
                                                            kind: clusterRole name: system:controller:node-controller  
                                                            kind: clusterRole name: system:controller:persistent-volume-binder  
                                                            kind: clusterRole name: system:controller:pod-garbage-collector  
                                                            kind: clusterRole name: system:controller:pv-protection-controller  
                                                            kind: clusterRole name: system:controller:pvc-protection-controller  
                                                            kind: clusterRole name: system:controller:replicaset-controller  
                                                            kind: clusterRole name: system:controller:replication-controller  
                                                            kind: clusterRole name: system:controller:root-ca-cert-publisher  
                                                            kind: clusterRole name: system:controller:route-controller  
                                                            kind: clusterRole name: system:controller:service-account-controller  
                                                            kind: clusterRole name: system:controller:service-controller  
                                                            kind: clusterRole name: system:controller:statefulset-controller  
                                                            kind: clusterRole name: system:controller:ttl-after-finished-controller  
                                                            kind: clusterRole name: system:controller:ttl-controller  
                                                            kind: clusterRole name: system:controller:validatingadmissionpolicy-status-controller  
                                                            kind: clusterRole name: system:coredns  
                                                            kind: clusterRole name: system:discovery  
                                                            kind: clusterRole name: system:heapster  
                                                            kind: clusterRole name: system:kube-aggregator  
                                                            kind: clusterRole name: system:kube-dns  
                                                            kind: clusterRole name: system:kube-scheduler  
                                                            kind: clusterRole name: system:kubelet-api-admin  
                                                            kind: clusterRole name: system:metrics-server  
                                                            kind: clusterRole name: system:monitoring  
                                                            kind: clusterRole name: system:node  
                                                            kind: clusterRole name: system:node-bootstrapper  
                                                            kind: clusterRole name: system:node-problem-detector  
                                                            kind: clusterRole name: system:node-proxier  
                                                            kind: clusterRole name: system:persistent-volume-provisioner  
                                                            kind: clusterRole name: system:public-info-viewer  
                                                            kind: clusterRole name: system:service-account-issuer-discovery  
                                                            kind: clusterRole name: system:volume-scheduler  
                                                            kind: clusterRole name: typha-cpha  
                                                            kind: clusterRole name: typha-cpva  
                                                            kind: clusterRole name: view  
                                                         
                                                     
                                                    
                                                        gcp 
                                                        
                                                            kind: role name: gardener.cloud:target:dependency-watchdog namespace: kube-node-lease  
                                                            kind: role name: system:controller:bootstrap-signer namespace: kube-public  
                                                            kind: role name: extension-apiserver-authentication-reader namespace: kube-system  
                                                            kind: role name: extensions.gardener.cloud:extension-shoot-cert-service:cert-controller-manager namespace: kube-system  
                                                            kind: role name: extensions.gardener.cloud:extension-shoot-dns-service:shoot-dns-service namespace: kube-system  
                                                            kind: role name: extensions.gardener.cloud:extension-shoot-networking-problem-detector:shoot namespace: kube-system  
                                                            kind: role name: extensions.gardener.cloud:provider-gcp:csi-attacher namespace: kube-system  
                                                            kind: role name: extensions.gardener.cloud:provider-gcp:csi-provisioner namespace: kube-system  
                                                            kind: role name: extensions.gardener.cloud:provider-gcp:csi-resizer namespace: kube-system  
                                                            kind: role name: extensions.gardener.cloud:provider-gcp:csi-snapshot-controller namespace: kube-system  
                                                            kind: role name: extensions.gardener.cloud:provider-gcp:csi-snapshotter namespace: kube-system  
                                                            kind: role name: gardener-node-agent namespace: kube-system  
                                                            kind: role name: gardener.cloud:target:machine-controller-manager namespace: kube-system  
                                                            kind: role name: gardener.cloud:vpa:target:leader-locking-vpa-recommender namespace: kube-system  
                                                            kind: role name: gardener.cloud:vpa:target:leader-locking-vpa-updater namespace: kube-system  
                                                            kind: role name: system::leader-locking-kube-controller-manager namespace: kube-system  
                                                            kind: role name: system::leader-locking-kube-scheduler namespace: kube-system  
                                                            kind: role name: system:controller:bootstrap-signer namespace: kube-system  
                                                            kind: role name: system:controller:cloud-provider namespace: kube-system  
                                                            kind: role name: system:controller:token-cleaner namespace: kube-system  
                                                            kind: role name: typha-cpha namespace: kube-system  
                                                            kind: clusterRole name: admin  
                                                            kind: clusterRole name: calico-cni-plugin  
                                                            kind: clusterRole name: calico-node  
                                                            kind: clusterRole name: calico-node-cpva  
                                                            kind: clusterRole name: edit  
                                                            kind: clusterRole name: event-logger  
                                                            kind: clusterRole name: extensions.gardener.cloud:extension-shoot-cert-service:shoot  
                                                            kind: clusterRole name: extensions.gardener.cloud:extension-shoot-dns-service:shoot-dns-service  
                                                            kind: clusterRole name: extensions.gardener.cloud:extension-shoot-networking-problem-detector:shoot  
                                                            kind: clusterRole name: extensions.gardener.cloud:provider-gcp:csi-attacher  
                                                            kind: clusterRole name: extensions.gardener.cloud:provider-gcp:csi-driver  
                                                            kind: clusterRole name: extensions.gardener.cloud:provider-gcp:csi-provisioner  
                                                            kind: clusterRole name: extensions.gardener.cloud:provider-gcp:csi-resizer  
                                                            kind: clusterRole name: extensions.gardener.cloud:provider-gcp:csi-snapshot-controller  
                                                            kind: clusterRole name: extensions.gardener.cloud:provider-gcp:csi-snapshotter  
                                                            kind: clusterRole name: gardener-extension-shoot-lakom-service-resource-reader  
                                                            kind: clusterRole name: gardener-node-agent  
                                                            kind: clusterRole name: gardener.cloud:kube-system:network-problem-detector  
                                                            kind: clusterRole name: gardener.cloud:logging:valitail  
                                                            kind: clusterRole name: gardener.cloud:monitoring:kube-state-metrics  
                                                            kind: clusterRole name: gardener.cloud:monitoring:prometheus-shoot  
                                                            kind: clusterRole name: gardener.cloud:system:read-only  
                                                            kind: clusterRole name: gardener.cloud:target:dependency-watchdog  
                                                            kind: clusterRole name: gardener.cloud:target:machine-controller-manager  
                                                            kind: clusterRole name: gardener.cloud:vpa:target:actor  
                                                            kind: clusterRole name: gardener.cloud:vpa:target:admission-controller  
                                                            kind: clusterRole name: gardener.cloud:vpa:target:checkpoint-actor  
                                                            kind: clusterRole name: gardener.cloud:vpa:target:evictioner  
                                                            kind: clusterRole name: gardener.cloud:vpa:target:metrics-reader  
                                                            kind: clusterRole name: gardener.cloud:vpa:target:status-actor  
                                                            kind: clusterRole name: gce:cloud-provider  
                                                            kind: clusterRole name: node-problem-detector  
                                                            kind: clusterRole name: system:aggregate-to-admin  
                                                            kind: clusterRole name: system:aggregate-to-edit  
                                                            kind: clusterRole name: system:aggregate-to-view  
                                                            kind: clusterRole name: system:apiserver:kubelet  
                                                            kind: clusterRole name: system:auth-delegator  
                                                            kind: clusterRole name: system:basic-user  
                                                            kind: clusterRole name: system:certificates.k8s.io:certificatesigningrequests:nodeclient  
                                                            kind: clusterRole name: system:certificates.k8s.io:certificatesigningrequests:selfnodeclient  
                                                            kind: clusterRole name: system:certificates.k8s.io:kube-apiserver-client-approver  
                                                            kind: clusterRole name: system:certificates.k8s.io:kube-apiserver-client-kubelet-approver  
                                                            kind: clusterRole name: system:certificates.k8s.io:kubelet-serving-approver  
                                                            kind: clusterRole name: system:certificates.k8s.io:legacy-unknown-approver  
                                                            kind: clusterRole name: system:controller:attachdetach-controller  
                                                            kind: clusterRole name: system:controller:certificate-controller  
                                                            kind: clusterRole name: system:controller:cloud-node-controller  
                                                            kind: clusterRole name: system:controller:clusterrole-aggregation-controller  
                                                            kind: clusterRole name: system:controller:cronjob-controller  
                                                            kind: clusterRole name: system:controller:daemon-set-controller  
                                                            kind: clusterRole name: system:controller:deployment-controller  
                                                            kind: clusterRole name: system:controller:endpoint-controller  
                                                            kind: clusterRole name: system:controller:endpointslice-controller  
                                                            kind: clusterRole name: system:controller:endpointslicemirroring-controller  
                                                            kind: clusterRole name: system:controller:ephemeral-volume-controller  
                                                            kind: clusterRole name: system:controller:expand-controller  
                                                            kind: clusterRole name: system:controller:job-controller  
                                                            kind: clusterRole name: system:controller:legacy-service-account-token-cleaner  
                                                            kind: clusterRole name: system:controller:node-controller  
                                                            kind: clusterRole name: system:controller:persistent-volume-binder  
                                                            kind: clusterRole name: system:controller:pod-garbage-collector  
                                                            kind: clusterRole name: system:controller:pv-protection-controller  
                                                            kind: clusterRole name: system:controller:pvc-protection-controller  
                                                            kind: clusterRole name: system:controller:replicaset-controller  
                                                            kind: clusterRole name: system:controller:replication-controller  
                                                            kind: clusterRole name: system:controller:root-ca-cert-publisher  
                                                            kind: clusterRole name: system:controller:route-controller  
                                                            kind: clusterRole name: system:controller:service-account-controller  
                                                            kind: clusterRole name: system:controller:service-controller  
                                                            kind: clusterRole name: system:controller:statefulset-controller  
                                                            kind: clusterRole name: system:controller:ttl-after-finished-controller  
                                                            kind: clusterRole name: system:controller:ttl-controller  
                                                            kind: clusterRole name: system:controller:validatingadmissionpolicy-status-controller  
                                                            kind: clusterRole name: system:coredns  
                                                            kind: clusterRole name: system:discovery  
                                                            kind: clusterRole name: system:heapster  
                                                            kind: clusterRole name: system:kube-aggregator  
                                                            kind: clusterRole name: system:kube-dns  
                                                            kind: clusterRole name: system:kube-scheduler  
                                                            kind: clusterRole name: system:kubelet-api-admin  
                                                            kind: clusterRole name: system:metrics-server  
                                                            kind: clusterRole name: system:monitoring  
                                                            kind: clusterRole name: system:node  
                                                            kind: clusterRole name: system:node-bootstrapper  
                                                            kind: clusterRole name: system:node-problem-detector  
                                                            kind: clusterRole name: system:node-proxier  
                                                            kind: clusterRole name: system:persistent-volume-provisioner  
                                                            kind: clusterRole name: system:public-info-viewer  
                                                            kind: clusterRole name: system:service-account-issuer-discovery  
                                                            kind: clusterRole name: system:volume-scheduler  
                                                            kind: clusterRole name: typha-cpha  
                                                            kind: clusterRole name: typha-cpva  
                                                            kind: clusterRole name: view  
                                                         
                                                     
                                                    
                                                        openstack 
                                                        
                                                            kind: role name: gardener.cloud:target:dependency-watchdog namespace: kube-node-lease  
                                                            kind: role name: system:controller:bootstrap-signer namespace: kube-public  
                                                            kind: role name: extension-apiserver-authentication-reader namespace: kube-system  
                                                            kind: role name: extensions.gardener.cloud:extension-shoot-cert-service:cert-controller-manager namespace: kube-system  
                                                            kind: role name: extensions.gardener.cloud:extension-shoot-dns-service:shoot-dns-service namespace: kube-system  
                                                            kind: role name: extensions.gardener.cloud:extension-shoot-networking-problem-detector:shoot namespace: kube-system  
                                                            kind: role name: extensions.gardener.cloud:provider-openstack:csi-attacher namespace: kube-system  
                                                            kind: role name: extensions.gardener.cloud:provider-openstack:csi-provisioner namespace: kube-system  
                                                            kind: role name: extensions.gardener.cloud:provider-openstack:csi-resizer namespace: kube-system  
                                                            kind: role name: extensions.gardener.cloud:provider-openstack:csi-snapshot-controller namespace: kube-system  
                                                            kind: role name: extensions.gardener.cloud:provider-openstack:csi-snapshotter namespace: kube-system  
                                                            kind: role name: gardener-node-agent namespace: kube-system  
                                                            kind: role name: gardener.cloud:target:machine-controller-manager namespace: kube-system  
                                                            kind: role name: gardener.cloud:vpa:target:leader-locking-vpa-recommender namespace: kube-system  
                                                            kind: role name: gardener.cloud:vpa:target:leader-locking-vpa-updater namespace: kube-system  
                                                            kind: role name: system::leader-locking-kube-controller-manager namespace: kube-system  
                                                            kind: role name: system::leader-locking-kube-scheduler namespace: kube-system  
                                                            kind: role name: system:controller:bootstrap-signer namespace: kube-system  
                                                            kind: role name: system:controller:cloud-provider namespace: kube-system  
                                                            kind: role name: system:controller:token-cleaner namespace: kube-system  
                                                            kind: role name: typha-cpha namespace: kube-system  
                                                            kind: clusterRole name: admin  
                                                            kind: clusterRole name: calico-cni-plugin  
                                                            kind: clusterRole name: calico-kube-controllers  
                                                            kind: clusterRole name: calico-node  
                                                            kind: clusterRole name: calico-node-cpva  
                                                            kind: clusterRole name: edit  
                                                            kind: clusterRole name: event-logger  
                                                            kind: clusterRole name: extensions.gardener.cloud:extension-shoot-cert-service:shoot  
                                                            kind: clusterRole name: extensions.gardener.cloud:extension-shoot-dns-service:shoot-dns-service  
                                                            kind: clusterRole name: extensions.gardener.cloud:extension-shoot-networking-problem-detector:shoot  
                                                            kind: clusterRole name: extensions.gardener.cloud:provider-openstack:csi-attacher  
                                                            kind: clusterRole name: extensions.gardener.cloud:provider-openstack:csi-driver  
                                                            kind: clusterRole name: extensions.gardener.cloud:provider-openstack:csi-provisioner  
                                                            kind: clusterRole name: extensions.gardener.cloud:provider-openstack:csi-resizer  
                                                            kind: clusterRole name: extensions.gardener.cloud:provider-openstack:csi-snapshot-controller  
                                                            kind: clusterRole name: extensions.gardener.cloud:provider-openstack:csi-snapshotter  
                                                            kind: clusterRole name: gardener-extension-shoot-lakom-service-resource-reader  
                                                            kind: clusterRole name: gardener-node-agent  
                                                            kind: clusterRole name: gardener.cloud:kube-system:network-problem-detector  
                                                            kind: clusterRole name: gardener.cloud:logging:valitail  
                                                            kind: clusterRole name: gardener.cloud:monitoring:kube-state-metrics  
                                                            kind: clusterRole name: gardener.cloud:monitoring:prometheus-shoot  
                                                            kind: clusterRole name: gardener.cloud:system:read-only  
                                                            kind: clusterRole name: gardener.cloud:target:dependency-watchdog  
                                                            kind: clusterRole name: gardener.cloud:target:machine-controller-manager  
                                                            kind: clusterRole name: gardener.cloud:vpa:target:actor  
                                                            kind: clusterRole name: gardener.cloud:vpa:target:admission-controller  
                                                            kind: clusterRole name: gardener.cloud:vpa:target:checkpoint-actor  
                                                            kind: clusterRole name: gardener.cloud:vpa:target:evictioner  
                                                            kind: clusterRole name: gardener.cloud:vpa:target:metrics-reader  
                                                            kind: clusterRole name: gardener.cloud:vpa:target:status-actor  
                                                            kind: clusterRole name: node-problem-detector  
                                                            kind: clusterRole name: system:aggregate-to-admin  
                                                            kind: clusterRole name: system:aggregate-to-edit  
                                                            kind: clusterRole name: system:aggregate-to-view  
                                                            kind: clusterRole name: system:apiserver:kubelet  
                                                            kind: clusterRole name: system:auth-delegator  
                                                            kind: clusterRole name: system:basic-user  
                                                            kind: clusterRole name: system:certificates.k8s.io:certificatesigningrequests:nodeclient  
                                                            kind: clusterRole name: system:certificates.k8s.io:certificatesigningrequests:selfnodeclient  
                                                            kind: clusterRole name: system:certificates.k8s.io:kube-apiserver-client-approver  
                                                            kind: clusterRole name: system:certificates.k8s.io:kube-apiserver-client-kubelet-approver  
                                                            kind: clusterRole name: system:certificates.k8s.io:kubelet-serving-approver  
                                                            kind: clusterRole name: system:certificates.k8s.io:legacy-unknown-approver  
                                                            kind: clusterRole name: system:controller:attachdetach-controller  
                                                            kind: clusterRole name: system:controller:certificate-controller  
                                                            kind: clusterRole name: system:controller:cloud-node-controller  
                                                            kind: clusterRole name: system:controller:clusterrole-aggregation-controller  
                                                            kind: clusterRole name: system:controller:cronjob-controller  
                                                            kind: clusterRole name: system:controller:daemon-set-controller  
                                                            kind: clusterRole name: system:controller:deployment-controller  
                                                            kind: clusterRole name: system:controller:endpoint-controller  
                                                            kind: clusterRole name: system:controller:endpointslice-controller  
                                                            kind: clusterRole name: system:controller:endpointslicemirroring-controller  
                                                            kind: clusterRole name: system:controller:ephemeral-volume-controller  
                                                            kind: clusterRole name: system:controller:expand-controller  
                                                            kind: clusterRole name: system:controller:job-controller  
                                                            kind: clusterRole name: system:controller:legacy-service-account-token-cleaner  
                                                            kind: clusterRole name: system:controller:node-controller  
                                                            kind: clusterRole name: system:controller:persistent-volume-binder  
                                                            kind: clusterRole name: system:controller:pod-garbage-collector  
                                                            kind: clusterRole name: system:controller:pv-protection-controller  
                                                            kind: clusterRole name: system:controller:pvc-protection-controller  
                                                            kind: clusterRole name: system:controller:replicaset-controller  
                                                            kind: clusterRole name: system:controller:replication-controller  
                                                            kind: clusterRole name: system:controller:root-ca-cert-publisher  
                                                            kind: clusterRole name: system:controller:route-controller  
                                                            kind: clusterRole name: system:controller:service-account-controller  
                                                            kind: clusterRole name: system:controller:service-controller  
                                                            kind: clusterRole name: system:controller:statefulset-controller  
                                                            kind: clusterRole name: system:controller:ttl-after-finished-controller  
                                                            kind: clusterRole name: system:controller:ttl-controller  
                                                            kind: clusterRole name: system:controller:validatingadmissionpolicy-status-controller  
                                                            kind: clusterRole name: system:coredns  
                                                            kind: clusterRole name: system:discovery  
                                                            kind: clusterRole name: system:heapster  
                                                            kind: clusterRole name: system:kube-aggregator  
                                                            kind: clusterRole name: system:kube-dns  
                                                            kind: clusterRole name: system:kube-scheduler  
                                                            kind: clusterRole name: system:kubelet-api-admin  
                                                            kind: clusterRole name: system:metrics-server  
                                                            kind: clusterRole name: system:monitoring  
                                                            kind: clusterRole name: system:node  
                                                            kind: clusterRole name: system:node-bootstrapper  
                                                            kind: clusterRole name: system:node-problem-detector  
                                                            kind: clusterRole name: system:node-proxier  
                                                            kind: clusterRole name: system:persistent-volume-provisioner  
                                                            kind: clusterRole name: system:public-info-viewer  
                                                            kind: clusterRole name: system:service-account-issuer-discovery  
                                                            kind: clusterRole name: system:volume-scheduler  
                                                            kind: clusterRole name: typha-cpha  
                                                            kind: clusterRole name: typha-cpva  
                                                            kind: clusterRole name: view  
                                                         
                                                     
                                                 
                                             
                                         
                                     
                                    
                                        2007 (Medium) - Limit the use of wildcards in RBAC verbs. 
                                        
                                            
                                                Role does not use "*" in policy rule verbs. 
                                                
                                                    
                                                        aws 
                                                        
                                                            kind: role name: gardener.cloud:target:dependency-watchdog namespace: kube-node-lease  
                                                            kind: role name: system:controller:bootstrap-signer namespace: kube-public  
                                                            kind: role name: extension-apiserver-authentication-reader namespace: kube-system  
                                                            kind: role name: extensions.gardener.cloud:extension-shoot-cert-service:cert-controller-manager namespace: kube-system  
                                                            kind: role name: extensions.gardener.cloud:extension-shoot-dns-service:shoot-dns-service namespace: kube-system  
                                                            kind: role name: extensions.gardener.cloud:extension-shoot-networking-problem-detector:shoot namespace: kube-system  
                                                            kind: role name: extensions.gardener.cloud:provider-aws:aws-custom-route-controller namespace: kube-system  
                                                            kind: role name: extensions.gardener.cloud:provider-aws:csi-attacher namespace: kube-system  
                                                            kind: role name: extensions.gardener.cloud:provider-aws:csi-provisioner namespace: kube-system  
                                                            kind: role name: extensions.gardener.cloud:provider-aws:csi-resizer namespace: kube-system  
                                                            kind: role name: extensions.gardener.cloud:provider-aws:csi-snapshot-controller namespace: kube-system  
                                                            kind: role name: extensions.gardener.cloud:provider-aws:csi-snapshotter namespace: kube-system  
                                                            kind: role name: extensions.gardener.cloud:provider-aws:csi-volume-modifier namespace: kube-system  
                                                            kind: role name: gardener-node-agent namespace: kube-system  
                                                            kind: role name: gardener.cloud:target:machine-controller-manager namespace: kube-system  
                                                            kind: role name: gardener.cloud:vpa:target:leader-locking-vpa-recommender namespace: kube-system  
                                                            kind: role name: gardener.cloud:vpa:target:leader-locking-vpa-updater namespace: kube-system  
                                                            kind: role name: system::leader-locking-kube-controller-manager namespace: kube-system  
                                                            kind: role name: system::leader-locking-kube-scheduler namespace: kube-system  
                                                            kind: role name: system:controller:bootstrap-signer namespace: kube-system  
                                                            kind: role name: system:controller:cloud-provider namespace: kube-system  
                                                            kind: role name: system:controller:token-cleaner namespace: kube-system  
                                                            kind: role name: typha-cpha namespace: kube-system  
                                                            kind: clusterRole name: admin  
                                                            kind: clusterRole name: calico-cni-plugin  
                                                            kind: clusterRole name: calico-node  
                                                            kind: clusterRole name: calico-node-cpva  
                                                            kind: clusterRole name: edit  
                                                            kind: clusterRole name: event-logger  
                                                            kind: clusterRole name: extensions.gardener.cloud:extension-shoot-cert-service:shoot  
                                                            kind: clusterRole name: extensions.gardener.cloud:extension-shoot-dns-service:shoot-dns-service  
                                                            kind: clusterRole name: extensions.gardener.cloud:extension-shoot-networking-problem-detector:shoot  
                                                            kind: clusterRole name: extensions.gardener.cloud:provider-aws:aws-custom-route-controller  
                                                            kind: clusterRole name: extensions.gardener.cloud:provider-aws:csi-attacher  
                                                            kind: clusterRole name: extensions.gardener.cloud:provider-aws:csi-driver  
                                                            kind: clusterRole name: extensions.gardener.cloud:provider-aws:csi-provisioner  
                                                            kind: clusterRole name: extensions.gardener.cloud:provider-aws:csi-resizer  
                                                            kind: clusterRole name: extensions.gardener.cloud:provider-aws:csi-snapshot-controller  
                                                            kind: clusterRole name: extensions.gardener.cloud:provider-aws:csi-snapshotter  
                                                            kind: clusterRole name: extensions.gardener.cloud:provider-aws:csi-volume-modifier  
                                                            kind: clusterRole name: gardener-extension-shoot-lakom-service-resource-reader  
                                                            kind: clusterRole name: gardener-node-agent  
                                                            kind: clusterRole name: gardener.cloud:kube-system:network-problem-detector  
                                                            kind: clusterRole name: gardener.cloud:logging:valitail  
                                                            kind: clusterRole name: gardener.cloud:monitoring:kube-state-metrics  
                                                            kind: clusterRole name: gardener.cloud:monitoring:prometheus-shoot  
                                                            kind: clusterRole name: gardener.cloud:system:read-only  
                                                            kind: clusterRole name: gardener.cloud:target:dependency-watchdog  
                                                            kind: clusterRole name: gardener.cloud:target:machine-controller-manager  
                                                            kind: clusterRole name: gardener.cloud:vpa:target:actor  
                                                            kind: clusterRole name: gardener.cloud:vpa:target:admission-controller  
                                                            kind: clusterRole name: gardener.cloud:vpa:target:checkpoint-actor  
                                                            kind: clusterRole name: gardener.cloud:vpa:target:evictioner  
                                                            kind: clusterRole name: gardener.cloud:vpa:target:metrics-reader  
                                                            kind: clusterRole name: gardener.cloud:vpa:target:status-actor  
                                                            kind: clusterRole name: gardener.cloud:vpa:target:target-reader  
                                                            kind: clusterRole name: node-problem-detector  
                                                            kind: clusterRole name: system:aggregate-to-admin  
                                                            kind: clusterRole name: system:aggregate-to-edit  
                                                            kind: clusterRole name: system:aggregate-to-view  
                                                            kind: clusterRole name: system:apiserver:kubelet  
                                                            kind: clusterRole name: system:auth-delegator  
                                                            kind: clusterRole name: system:basic-user  
                                                            kind: clusterRole name: system:certificates.k8s.io:certificatesigningrequests:nodeclient  
                                                            kind: clusterRole name: system:certificates.k8s.io:certificatesigningrequests:selfnodeclient  
                                                            kind: clusterRole name: system:certificates.k8s.io:kube-apiserver-client-approver  
                                                            kind: clusterRole name: system:certificates.k8s.io:kube-apiserver-client-kubelet-approver  
                                                            kind: clusterRole name: system:certificates.k8s.io:kubelet-serving-approver  
                                                            kind: clusterRole name: system:certificates.k8s.io:legacy-unknown-approver  
                                                            kind: clusterRole name: system:controller:attachdetach-controller  
                                                            kind: clusterRole name: system:controller:certificate-controller  
                                                            kind: clusterRole name: system:controller:clusterrole-aggregation-controller  
                                                            kind: clusterRole name: system:controller:cronjob-controller  
                                                            kind: clusterRole name: system:controller:daemon-set-controller  
                                                            kind: clusterRole name: system:controller:deployment-controller  
                                                            kind: clusterRole name: system:controller:disruption-controller  
                                                            kind: clusterRole name: system:controller:endpoint-controller  
                                                            kind: clusterRole name: system:controller:endpointslice-controller  
                                                            kind: clusterRole name: system:controller:endpointslicemirroring-controller  
                                                            kind: clusterRole name: system:controller:ephemeral-volume-controller  
                                                            kind: clusterRole name: system:controller:expand-controller  
                                                            kind: clusterRole name: system:controller:generic-garbage-collector  
                                                            kind: clusterRole name: system:controller:horizontal-pod-autoscaler  
                                                            kind: clusterRole name: system:controller:job-controller  
                                                            kind: clusterRole name: system:controller:legacy-service-account-token-cleaner  
                                                            kind: clusterRole name: system:controller:namespace-controller  
                                                            kind: clusterRole name: system:controller:node-controller  
                                                            kind: clusterRole name: system:controller:persistent-volume-binder  
                                                            kind: clusterRole name: system:controller:pod-garbage-collector  
                                                            kind: clusterRole name: system:controller:pv-protection-controller  
                                                            kind: clusterRole name: system:controller:pvc-protection-controller  
                                                            kind: clusterRole name: system:controller:replicaset-controller  
                                                            kind: clusterRole name: system:controller:replication-controller  
                                                            kind: clusterRole name: system:controller:resourcequota-controller  
                                                            kind: clusterRole name: system:controller:root-ca-cert-publisher  
                                                            kind: clusterRole name: system:controller:route-controller  
                                                            kind: clusterRole name: system:controller:service-account-controller  
                                                            kind: clusterRole name: system:controller:service-controller  
                                                            kind: clusterRole name: system:controller:statefulset-controller  
                                                            kind: clusterRole name: system:controller:ttl-after-finished-controller  
                                                            kind: clusterRole name: system:controller:ttl-controller  
                                                            kind: clusterRole name: system:controller:validatingadmissionpolicy-status-controller  
                                                            kind: clusterRole name: system:coredns  
                                                            kind: clusterRole name: system:discovery  
                                                            kind: clusterRole name: system:heapster  
                                                            kind: clusterRole name: system:kube-aggregator  
                                                            kind: clusterRole name: system:kube-controller-manager  
                                                            kind: clusterRole name: system:kube-dns  
                                                            kind: clusterRole name: system:kube-scheduler  
                                                            kind: clusterRole name: system:metrics-server  
                                                            kind: clusterRole name: system:monitoring  
                                                            kind: clusterRole name: system:node  
                                                            kind: clusterRole name: system:node-bootstrapper  
                                                            kind: clusterRole name: system:node-problem-detector  
                                                            kind: clusterRole name: system:node-proxier  
                                                            kind: clusterRole name: system:persistent-volume-provisioner  
                                                            kind: clusterRole name: system:public-info-viewer  
                                                            kind: clusterRole name: system:service-account-issuer-discovery  
                                                            kind: clusterRole name: system:volume-scheduler  
                                                            kind: clusterRole name: typha-cpha  
                                                            kind: clusterRole name: typha-cpva  
                                                            kind: clusterRole name: view  
                                                         
                                                     
                                                    
                                                        azure 
                                                        
                                                            kind: role name: gardener.cloud:target:dependency-watchdog namespace: kube-node-lease  
                                                            kind: role name: system:controller:bootstrap-signer namespace: kube-public  
                                                            kind: role name: extension-apiserver-authentication-reader namespace: kube-system  
                                                            kind: role name: extensions.gardener.cloud:extension-shoot-cert-service:cert-controller-manager namespace: kube-system  
                                                            kind: role name: extensions.gardener.cloud:extension-shoot-dns-service:shoot-dns-service namespace: kube-system  
                                                            kind: role name: extensions.gardener.cloud:extension-shoot-networking-problem-detector:shoot namespace: kube-system  
                                                            kind: role name: extensions.gardener.cloud:provider-azure:csi-attacher namespace: kube-system  
                                                            kind: role name: extensions.gardener.cloud:provider-azure:csi-provisioner namespace: kube-system  
                                                            kind: role name: extensions.gardener.cloud:provider-azure:csi-resizer namespace: kube-system  
                                                            kind: role name: extensions.gardener.cloud:provider-azure:csi-snapshot-controller namespace: kube-system  
                                                            kind: role name: extensions.gardener.cloud:provider-azure:csi-snapshotter namespace: kube-system  
                                                            kind: role name: gardener-node-agent namespace: kube-system  
                                                            kind: role name: gardener.cloud:target:machine-controller-manager namespace: kube-system  
                                                            kind: role name: gardener.cloud:vpa:target:leader-locking-vpa-recommender namespace: kube-system  
                                                            kind: role name: gardener.cloud:vpa:target:leader-locking-vpa-updater namespace: kube-system  
                                                            kind: role name: system::leader-locking-kube-controller-manager namespace: kube-system  
                                                            kind: role name: system::leader-locking-kube-scheduler namespace: kube-system  
                                                            kind: role name: system:controller:bootstrap-signer namespace: kube-system  
                                                            kind: role name: system:controller:cloud-provider namespace: kube-system  
                                                            kind: role name: system:controller:token-cleaner namespace: kube-system  
                                                            kind: role name: typha-cpha namespace: kube-system  
                                                            kind: clusterRole name: admin  
                                                            kind: clusterRole name: calico-cni-plugin  
                                                            kind: clusterRole name: calico-node  
                                                            kind: clusterRole name: calico-node-cpva  
                                                            kind: clusterRole name: cloud-node-manager  
                                                            kind: clusterRole name: edit  
                                                            kind: clusterRole name: event-logger  
                                                            kind: clusterRole name: extensions.gardener.cloud:extension-shoot-cert-service:shoot  
                                                            kind: clusterRole name: extensions.gardener.cloud:extension-shoot-dns-service:shoot-dns-service  
                                                            kind: clusterRole name: extensions.gardener.cloud:extension-shoot-networking-problem-detector:shoot  
                                                            kind: clusterRole name: extensions.gardener.cloud:provider-azure:csi-attacher  
                                                            kind: clusterRole name: extensions.gardener.cloud:provider-azure:csi-driver  
                                                            kind: clusterRole name: extensions.gardener.cloud:provider-azure:csi-driver-controller-disk  
                                                            kind: clusterRole name: extensions.gardener.cloud:provider-azure:csi-driver-controller-file  
                                                            kind: clusterRole name: extensions.gardener.cloud:provider-azure:csi-provisioner  
                                                            kind: clusterRole name: extensions.gardener.cloud:provider-azure:csi-resizer  
                                                            kind: clusterRole name: extensions.gardener.cloud:provider-azure:csi-snapshot-controller  
                                                            kind: clusterRole name: extensions.gardener.cloud:provider-azure:csi-snapshot-validation  
                                                            kind: clusterRole name: extensions.gardener.cloud:provider-azure:csi-snapshotter  
                                                            kind: clusterRole name: extensions.gardener.cloud:provider-azure:remedy-controller-azure  
                                                            kind: clusterRole name: gardener-extension-shoot-lakom-service-resource-reader  
                                                            kind: clusterRole name: gardener-node-agent  
                                                            kind: clusterRole name: gardener.cloud:kube-system:network-problem-detector  
                                                            kind: clusterRole name: gardener.cloud:logging:valitail  
                                                            kind: clusterRole name: gardener.cloud:monitoring:kube-state-metrics  
                                                            kind: clusterRole name: gardener.cloud:monitoring:prometheus-shoot  
                                                            kind: clusterRole name: gardener.cloud:system:read-only  
                                                            kind: clusterRole name: gardener.cloud:target:dependency-watchdog  
                                                            kind: clusterRole name: gardener.cloud:target:machine-controller-manager  
                                                            kind: clusterRole name: gardener.cloud:vpa:target:actor  
                                                            kind: clusterRole name: gardener.cloud:vpa:target:admission-controller  
                                                            kind: clusterRole name: gardener.cloud:vpa:target:checkpoint-actor  
                                                            kind: clusterRole name: gardener.cloud:vpa:target:evictioner  
                                                            kind: clusterRole name: gardener.cloud:vpa:target:metrics-reader  
                                                            kind: clusterRole name: gardener.cloud:vpa:target:status-actor  
                                                            kind: clusterRole name: gardener.cloud:vpa:target:target-reader  
                                                            kind: clusterRole name: node-problem-detector  
                                                            kind: clusterRole name: system:aggregate-to-admin  
                                                            kind: clusterRole name: system:aggregate-to-edit  
                                                            kind: clusterRole name: system:aggregate-to-view  
                                                            kind: clusterRole name: system:apiserver:kubelet  
                                                            kind: clusterRole name: system:auth-delegator  
                                                            kind: clusterRole name: system:azure-cloud-provider  
                                                            kind: clusterRole name: system:basic-user  
                                                            kind: clusterRole name: system:certificates.k8s.io:certificatesigningrequests:nodeclient  
                                                            kind: clusterRole name: system:certificates.k8s.io:certificatesigningrequests:selfnodeclient  
                                                            kind: clusterRole name: system:certificates.k8s.io:kube-apiserver-client-approver  
                                                            kind: clusterRole name: system:certificates.k8s.io:kube-apiserver-client-kubelet-approver  
                                                            kind: clusterRole name: system:certificates.k8s.io:kubelet-serving-approver  
                                                            kind: clusterRole name: system:certificates.k8s.io:legacy-unknown-approver  
                                                            kind: clusterRole name: system:cloud-controller-manager  
                                                            kind: clusterRole name: system:controller:attachdetach-controller  
                                                            kind: clusterRole name: system:controller:certificate-controller  
                                                            kind: clusterRole name: system:controller:clusterrole-aggregation-controller  
                                                            kind: clusterRole name: system:controller:cronjob-controller  
                                                            kind: clusterRole name: system:controller:daemon-set-controller  
                                                            kind: clusterRole name: system:controller:deployment-controller  
                                                            kind: clusterRole name: system:controller:disruption-controller  
                                                            kind: clusterRole name: system:controller:endpoint-controller  
                                                            kind: clusterRole name: system:controller:endpointslice-controller  
                                                            kind: clusterRole name: system:controller:endpointslicemirroring-controller  
                                                            kind: clusterRole name: system:controller:ephemeral-volume-controller  
                                                            kind: clusterRole name: system:controller:expand-controller  
                                                            kind: clusterRole name: system:controller:generic-garbage-collector  
                                                            kind: clusterRole name: system:controller:horizontal-pod-autoscaler  
                                                            kind: clusterRole name: system:controller:job-controller  
                                                            kind: clusterRole name: system:controller:legacy-service-account-token-cleaner  
                                                            kind: clusterRole name: system:controller:namespace-controller  
                                                            kind: clusterRole name: system:controller:node-controller  
                                                            kind: clusterRole name: system:controller:persistent-volume-binder  
                                                            kind: clusterRole name: system:controller:pod-garbage-collector  
                                                            kind: clusterRole name: system:controller:pv-protection-controller  
                                                            kind: clusterRole name: system:controller:pvc-protection-controller  
                                                            kind: clusterRole name: system:controller:replicaset-controller  
                                                            kind: clusterRole name: system:controller:replication-controller  
                                                            kind: clusterRole name: system:controller:resourcequota-controller  
                                                            kind: clusterRole name: system:controller:root-ca-cert-publisher  
                                                            kind: clusterRole name: system:controller:route-controller  
                                                            kind: clusterRole name: system:controller:service-account-controller  
                                                            kind: clusterRole name: system:controller:service-controller  
                                                            kind: clusterRole name: system:controller:statefulset-controller  
                                                            kind: clusterRole name: system:controller:ttl-after-finished-controller  
                                                            kind: clusterRole name: system:controller:ttl-controller  
                                                            kind: clusterRole name: system:controller:validatingadmissionpolicy-status-controller  
                                                            kind: clusterRole name: system:coredns  
                                                            kind: clusterRole name: system:discovery  
                                                            kind: clusterRole name: system:heapster  
                                                            kind: clusterRole name: system:kube-aggregator  
                                                            kind: clusterRole name: system:kube-controller-manager  
                                                            kind: clusterRole name: system:kube-dns  
                                                            kind: clusterRole name: system:kube-scheduler  
                                                            kind: clusterRole name: system:metrics-server  
                                                            kind: clusterRole name: system:monitoring  
                                                            kind: clusterRole name: system:node  
                                                            kind: clusterRole name: system:node-bootstrapper  
                                                            kind: clusterRole name: system:node-problem-detector  
                                                            kind: clusterRole name: system:node-proxier  
                                                            kind: clusterRole name: system:persistent-volume-provisioner  
                                                            kind: clusterRole name: system:public-info-viewer  
                                                            kind: clusterRole name: system:service-account-issuer-discovery  
                                                            kind: clusterRole name: system:volume-scheduler  
                                                            kind: clusterRole name: typha-cpha  
                                                            kind: clusterRole name: typha-cpva  
                                                            kind: clusterRole name: view  
                                                         
                                                     
                                                    
                                                        gcp 
                                                        
                                                            kind: role name: gardener.cloud:target:dependency-watchdog namespace: kube-node-lease  
                                                            kind: role name: system:controller:bootstrap-signer namespace: kube-public  
                                                            kind: role name: extension-apiserver-authentication-reader namespace: kube-system  
                                                            kind: role name: extensions.gardener.cloud:extension-shoot-cert-service:cert-controller-manager namespace: kube-system  
                                                            kind: role name: extensions.gardener.cloud:extension-shoot-dns-service:shoot-dns-service namespace: kube-system  
                                                            kind: role name: extensions.gardener.cloud:extension-shoot-networking-problem-detector:shoot namespace: kube-system  
                                                            kind: role name: extensions.gardener.cloud:provider-gcp:csi-attacher namespace: kube-system  
                                                            kind: role name: extensions.gardener.cloud:provider-gcp:csi-provisioner namespace: kube-system  
                                                            kind: role name: extensions.gardener.cloud:provider-gcp:csi-resizer namespace: kube-system  
                                                            kind: role name: extensions.gardener.cloud:provider-gcp:csi-snapshot-controller namespace: kube-system  
                                                            kind: role name: extensions.gardener.cloud:provider-gcp:csi-snapshotter namespace: kube-system  
                                                            kind: role name: gardener-node-agent namespace: kube-system  
                                                            kind: role name: gardener.cloud:target:machine-controller-manager namespace: kube-system  
                                                            kind: role name: gardener.cloud:vpa:target:leader-locking-vpa-recommender namespace: kube-system  
                                                            kind: role name: gardener.cloud:vpa:target:leader-locking-vpa-updater namespace: kube-system  
                                                            kind: role name: system::leader-locking-kube-controller-manager namespace: kube-system  
                                                            kind: role name: system::leader-locking-kube-scheduler namespace: kube-system  
                                                            kind: role name: system:controller:bootstrap-signer namespace: kube-system  
                                                            kind: role name: system:controller:cloud-provider namespace: kube-system  
                                                            kind: role name: system:controller:token-cleaner namespace: kube-system  
                                                            kind: role name: typha-cpha namespace: kube-system  
                                                            kind: clusterRole name: admin  
                                                            kind: clusterRole name: calico-cni-plugin  
                                                            kind: clusterRole name: calico-node  
                                                            kind: clusterRole name: calico-node-cpva  
                                                            kind: clusterRole name: edit  
                                                            kind: clusterRole name: event-logger  
                                                            kind: clusterRole name: extensions.gardener.cloud:extension-shoot-cert-service:shoot  
                                                            kind: clusterRole name: extensions.gardener.cloud:extension-shoot-dns-service:shoot-dns-service  
                                                            kind: clusterRole name: extensions.gardener.cloud:extension-shoot-networking-problem-detector:shoot  
                                                            kind: clusterRole name: extensions.gardener.cloud:provider-gcp:csi-attacher  
                                                            kind: clusterRole name: extensions.gardener.cloud:provider-gcp:csi-driver  
                                                            kind: clusterRole name: extensions.gardener.cloud:provider-gcp:csi-provisioner  
                                                            kind: clusterRole name: extensions.gardener.cloud:provider-gcp:csi-resizer  
                                                            kind: clusterRole name: extensions.gardener.cloud:provider-gcp:csi-snapshot-controller  
                                                            kind: clusterRole name: extensions.gardener.cloud:provider-gcp:csi-snapshotter  
                                                            kind: clusterRole name: gardener-extension-shoot-lakom-service-resource-reader  
                                                            kind: clusterRole name: gardener-node-agent  
                                                            kind: clusterRole name: gardener.cloud:kube-system:network-problem-detector  
                                                            kind: clusterRole name: gardener.cloud:logging:valitail  
                                                            kind: clusterRole name: gardener.cloud:monitoring:kube-state-metrics  
                                                            kind: clusterRole name: gardener.cloud:monitoring:prometheus-shoot  
                                                            kind: clusterRole name: gardener.cloud:system:read-only  
                                                            kind: clusterRole name: gardener.cloud:target:dependency-watchdog  
                                                            kind: clusterRole name: gardener.cloud:target:machine-controller-manager  
                                                            kind: clusterRole name: gardener.cloud:vpa:target:actor  
                                                            kind: clusterRole name: gardener.cloud:vpa:target:admission-controller  
                                                            kind: clusterRole name: gardener.cloud:vpa:target:checkpoint-actor  
                                                            kind: clusterRole name: gardener.cloud:vpa:target:evictioner  
                                                            kind: clusterRole name: gardener.cloud:vpa:target:metrics-reader  
                                                            kind: clusterRole name: gardener.cloud:vpa:target:status-actor  
                                                            kind: clusterRole name: gardener.cloud:vpa:target:target-reader  
                                                            kind: clusterRole name: gce:cloud-provider  
                                                            kind: clusterRole name: node-problem-detector  
                                                            kind: clusterRole name: system:aggregate-to-admin  
                                                            kind: clusterRole name: system:aggregate-to-edit  
                                                            kind: clusterRole name: system:aggregate-to-view  
                                                            kind: clusterRole name: system:apiserver:kubelet  
                                                            kind: clusterRole name: system:auth-delegator  
                                                            kind: clusterRole name: system:basic-user  
                                                            kind: clusterRole name: system:certificates.k8s.io:certificatesigningrequests:nodeclient  
                                                            kind: clusterRole name: system:certificates.k8s.io:certificatesigningrequests:selfnodeclient  
                                                            kind: clusterRole name: system:certificates.k8s.io:kube-apiserver-client-approver  
                                                            kind: clusterRole name: system:certificates.k8s.io:kube-apiserver-client-kubelet-approver  
                                                            kind: clusterRole name: system:certificates.k8s.io:kubelet-serving-approver  
                                                            kind: clusterRole name: system:certificates.k8s.io:legacy-unknown-approver  
                                                            kind: clusterRole name: system:controller:attachdetach-controller  
                                                            kind: clusterRole name: system:controller:certificate-controller  
                                                            kind: clusterRole name: system:controller:cloud-node-controller  
                                                            kind: clusterRole name: system:controller:clusterrole-aggregation-controller  
                                                            kind: clusterRole name: system:controller:cronjob-controller  
                                                            kind: clusterRole name: system:controller:daemon-set-controller  
                                                            kind: clusterRole name: system:controller:deployment-controller  
                                                            kind: clusterRole name: system:controller:disruption-controller  
                                                            kind: clusterRole name: system:controller:endpoint-controller  
                                                            kind: clusterRole name: system:controller:endpointslice-controller  
                                                            kind: clusterRole name: system:controller:endpointslicemirroring-controller  
                                                            kind: clusterRole name: system:controller:ephemeral-volume-controller  
                                                            kind: clusterRole name: system:controller:expand-controller  
                                                            kind: clusterRole name: system:controller:generic-garbage-collector  
                                                            kind: clusterRole name: system:controller:horizontal-pod-autoscaler  
                                                            kind: clusterRole name: system:controller:job-controller  
                                                            kind: clusterRole name: system:controller:legacy-service-account-token-cleaner  
                                                            kind: clusterRole name: system:controller:namespace-controller  
                                                            kind: clusterRole name: system:controller:node-controller  
                                                            kind: clusterRole name: system:controller:persistent-volume-binder  
                                                            kind: clusterRole name: system:controller:pod-garbage-collector  
                                                            kind: clusterRole name: system:controller:pv-protection-controller  
                                                            kind: clusterRole name: system:controller:pvc-protection-controller  
                                                            kind: clusterRole name: system:controller:replicaset-controller  
                                                            kind: clusterRole name: system:controller:replication-controller  
                                                            kind: clusterRole name: system:controller:resourcequota-controller  
                                                            kind: clusterRole name: system:controller:root-ca-cert-publisher  
                                                            kind: clusterRole name: system:controller:route-controller  
                                                            kind: clusterRole name: system:controller:service-account-controller  
                                                            kind: clusterRole name: system:controller:service-controller  
                                                            kind: clusterRole name: system:controller:statefulset-controller  
                                                            kind: clusterRole name: system:controller:ttl-after-finished-controller  
                                                            kind: clusterRole name: system:controller:ttl-controller  
                                                            kind: clusterRole name: system:controller:validatingadmissionpolicy-status-controller  
                                                            kind: clusterRole name: system:coredns  
                                                            kind: clusterRole name: system:discovery  
                                                            kind: clusterRole name: system:heapster  
                                                            kind: clusterRole name: system:kube-aggregator  
                                                            kind: clusterRole name: system:kube-controller-manager  
                                                            kind: clusterRole name: system:kube-dns  
                                                            kind: clusterRole name: system:kube-scheduler  
                                                            kind: clusterRole name: system:metrics-server  
                                                            kind: clusterRole name: system:monitoring  
                                                            kind: clusterRole name: system:node  
                                                            kind: clusterRole name: system:node-bootstrapper  
                                                            kind: clusterRole name: system:node-problem-detector  
                                                            kind: clusterRole name: system:node-proxier  
                                                            kind: clusterRole name: system:persistent-volume-provisioner  
                                                            kind: clusterRole name: system:public-info-viewer  
                                                            kind: clusterRole name: system:service-account-issuer-discovery  
                                                            kind: clusterRole name: system:volume-scheduler  
                                                            kind: clusterRole name: typha-cpha  
                                                            kind: clusterRole name: typha-cpva  
                                                            kind: clusterRole name: view  
                                                         
                                                     
                                                    
                                                        openstack 
                                                        
                                                            kind: role name: gardener.cloud:target:dependency-watchdog namespace: kube-node-lease  
                                                            kind: role name: system:controller:bootstrap-signer namespace: kube-public  
                                                            kind: role name: extension-apiserver-authentication-reader namespace: kube-system  
                                                            kind: role name: extensions.gardener.cloud:extension-shoot-cert-service:cert-controller-manager namespace: kube-system  
                                                            kind: role name: extensions.gardener.cloud:extension-shoot-dns-service:shoot-dns-service namespace: kube-system  
                                                            kind: role name: extensions.gardener.cloud:extension-shoot-networking-problem-detector:shoot namespace: kube-system  
                                                            kind: role name: extensions.gardener.cloud:provider-openstack:csi-attacher namespace: kube-system  
                                                            kind: role name: extensions.gardener.cloud:provider-openstack:csi-provisioner namespace: kube-system  
                                                            kind: role name: extensions.gardener.cloud:provider-openstack:csi-resizer namespace: kube-system  
                                                            kind: role name: extensions.gardener.cloud:provider-openstack:csi-snapshot-controller namespace: kube-system  
                                                            kind: role name: extensions.gardener.cloud:provider-openstack:csi-snapshotter namespace: kube-system  
                                                            kind: role name: gardener-node-agent namespace: kube-system  
                                                            kind: role name: gardener.cloud:target:machine-controller-manager namespace: kube-system  
                                                            kind: role name: gardener.cloud:vpa:target:leader-locking-vpa-recommender namespace: kube-system  
                                                            kind: role name: gardener.cloud:vpa:target:leader-locking-vpa-updater namespace: kube-system  
                                                            kind: role name: system::leader-locking-kube-controller-manager namespace: kube-system  
                                                            kind: role name: system::leader-locking-kube-scheduler namespace: kube-system  
                                                            kind: role name: system:controller:bootstrap-signer namespace: kube-system  
                                                            kind: role name: system:controller:cloud-provider namespace: kube-system  
                                                            kind: role name: system:controller:token-cleaner namespace: kube-system  
                                                            kind: role name: typha-cpha namespace: kube-system  
                                                            kind: clusterRole name: admin  
                                                            kind: clusterRole name: calico-cni-plugin  
                                                            kind: clusterRole name: calico-kube-controllers  
                                                            kind: clusterRole name: calico-node  
                                                            kind: clusterRole name: calico-node-cpva  
                                                            kind: clusterRole name: edit  
                                                            kind: clusterRole name: event-logger  
                                                            kind: clusterRole name: extensions.gardener.cloud:extension-shoot-cert-service:shoot  
                                                            kind: clusterRole name: extensions.gardener.cloud:extension-shoot-dns-service:shoot-dns-service  
                                                            kind: clusterRole name: extensions.gardener.cloud:extension-shoot-networking-problem-detector:shoot  
                                                            kind: clusterRole name: extensions.gardener.cloud:provider-openstack:csi-attacher  
                                                            kind: clusterRole name: extensions.gardener.cloud:provider-openstack:csi-driver  
                                                            kind: clusterRole name: extensions.gardener.cloud:provider-openstack:csi-provisioner  
                                                            kind: clusterRole name: extensions.gardener.cloud:provider-openstack:csi-resizer  
                                                            kind: clusterRole name: extensions.gardener.cloud:provider-openstack:csi-snapshot-controller  
                                                            kind: clusterRole name: extensions.gardener.cloud:provider-openstack:csi-snapshotter  
                                                            kind: clusterRole name: gardener-extension-shoot-lakom-service-resource-reader  
                                                            kind: clusterRole name: gardener-node-agent  
                                                            kind: clusterRole name: gardener.cloud:kube-system:network-problem-detector  
                                                            kind: clusterRole name: gardener.cloud:logging:valitail  
                                                            kind: clusterRole name: gardener.cloud:monitoring:kube-state-metrics  
                                                            kind: clusterRole name: gardener.cloud:monitoring:prometheus-shoot  
                                                            kind: clusterRole name: gardener.cloud:system:read-only  
                                                            kind: clusterRole name: gardener.cloud:target:dependency-watchdog  
                                                            kind: clusterRole name: gardener.cloud:target:machine-controller-manager  
                                                            kind: clusterRole name: gardener.cloud:vpa:target:actor  
                                                            kind: clusterRole name: gardener.cloud:vpa:target:admission-controller  
                                                            kind: clusterRole name: gardener.cloud:vpa:target:checkpoint-actor  
                                                            kind: clusterRole name: gardener.cloud:vpa:target:evictioner  
                                                            kind: clusterRole name: gardener.cloud:vpa:target:metrics-reader  
                                                            kind: clusterRole name: gardener.cloud:vpa:target:status-actor  
                                                            kind: clusterRole name: gardener.cloud:vpa:target:target-reader  
                                                            kind: clusterRole name: node-problem-detector  
                                                            kind: clusterRole name: system:aggregate-to-admin  
                                                            kind: clusterRole name: system:aggregate-to-edit  
                                                            kind: clusterRole name: system:aggregate-to-view  
                                                            kind: clusterRole name: system:apiserver:kubelet  
                                                            kind: clusterRole name: system:auth-delegator  
                                                            kind: clusterRole name: system:basic-user  
                                                            kind: clusterRole name: system:certificates.k8s.io:certificatesigningrequests:nodeclient  
                                                            kind: clusterRole name: system:certificates.k8s.io:certificatesigningrequests:selfnodeclient  
                                                            kind: clusterRole name: system:certificates.k8s.io:kube-apiserver-client-approver  
                                                            kind: clusterRole name: system:certificates.k8s.io:kube-apiserver-client-kubelet-approver  
                                                            kind: clusterRole name: system:certificates.k8s.io:kubelet-serving-approver  
                                                            kind: clusterRole name: system:certificates.k8s.io:legacy-unknown-approver  
                                                            kind: clusterRole name: system:controller:attachdetach-controller  
                                                            kind: clusterRole name: system:controller:certificate-controller  
                                                            kind: clusterRole name: system:controller:cloud-node-controller  
                                                            kind: clusterRole name: system:controller:clusterrole-aggregation-controller  
                                                            kind: clusterRole name: system:controller:cronjob-controller  
                                                            kind: clusterRole name: system:controller:daemon-set-controller  
                                                            kind: clusterRole name: system:controller:deployment-controller  
                                                            kind: clusterRole name: system:controller:disruption-controller  
                                                            kind: clusterRole name: system:controller:endpoint-controller  
                                                            kind: clusterRole name: system:controller:endpointslice-controller  
                                                            kind: clusterRole name: system:controller:endpointslicemirroring-controller  
                                                            kind: clusterRole name: system:controller:ephemeral-volume-controller  
                                                            kind: clusterRole name: system:controller:expand-controller  
                                                            kind: clusterRole name: system:controller:generic-garbage-collector  
                                                            kind: clusterRole name: system:controller:horizontal-pod-autoscaler  
                                                            kind: clusterRole name: system:controller:job-controller  
                                                            kind: clusterRole name: system:controller:legacy-service-account-token-cleaner  
                                                            kind: clusterRole name: system:controller:namespace-controller  
                                                            kind: clusterRole name: system:controller:node-controller  
                                                            kind: clusterRole name: system:controller:persistent-volume-binder  
                                                            kind: clusterRole name: system:controller:pod-garbage-collector  
                                                            kind: clusterRole name: system:controller:pv-protection-controller  
                                                            kind: clusterRole name: system:controller:pvc-protection-controller  
                                                            kind: clusterRole name: system:controller:replicaset-controller  
                                                            kind: clusterRole name: system:controller:replication-controller  
                                                            kind: clusterRole name: system:controller:resourcequota-controller  
                                                            kind: clusterRole name: system:controller:root-ca-cert-publisher  
                                                            kind: clusterRole name: system:controller:route-controller  
                                                            kind: clusterRole name: system:controller:service-account-controller  
                                                            kind: clusterRole name: system:controller:service-controller  
                                                            kind: clusterRole name: system:controller:statefulset-controller  
                                                            kind: clusterRole name: system:controller:ttl-after-finished-controller  
                                                            kind: clusterRole name: system:controller:ttl-controller  
                                                            kind: clusterRole name: system:controller:validatingadmissionpolicy-status-controller  
                                                            kind: clusterRole name: system:coredns  
                                                            kind: clusterRole name: system:discovery  
                                                            kind: clusterRole name: system:heapster  
                                                            kind: clusterRole name: system:kube-aggregator  
                                                            kind: clusterRole name: system:kube-controller-manager  
                                                            kind: clusterRole name: system:kube-dns  
                                                            kind: clusterRole name: system:kube-scheduler  
                                                            kind: clusterRole name: system:metrics-server  
                                                            kind: clusterRole name: system:monitoring  
                                                            kind: clusterRole name: system:node  
                                                            kind: clusterRole name: system:node-bootstrapper  
                                                            kind: clusterRole name: system:node-problem-detector  
                                                            kind: clusterRole name: system:node-proxier  
                                                            kind: clusterRole name: system:persistent-volume-provisioner  
                                                            kind: clusterRole name: system:public-info-viewer  
                                                            kind: clusterRole name: system:service-account-issuer-discovery  
                                                            kind: clusterRole name: system:volume-scheduler  
                                                            kind: clusterRole name: typha-cpha  
                                                            kind: clusterRole name: typha-cpva  
                                                            kind: clusterRole name: view  
                                                         
                                                     
                                                 
                                             
                                         
                                     
                                    
                                        2008 (High) - Pods must not mount host directories. 
                                        
                                            
                                                Pod does not use volumes of type hostPath. 
                                                
                                                    
                                                        aws 
                                                        
                                                            kind: pod name: apiserver-proxy-4dqc8 namespace: kube-system  
                                                            kind: pod name: apiserver-proxy-qmw5c namespace: kube-system  
                                                            kind: pod name: blackbox-exporter-54d6476f57-9r7pm namespace: kube-system  
                                                            kind: pod name: blackbox-exporter-54d6476f57-s87tl namespace: kube-system  
                                                            kind: pod name: calico-node-vertical-autoscaler-75c94f77bb-d8kc9 namespace: kube-system  
                                                            kind: pod name: calico-typha-deploy-6c94dc645b-hmjtm namespace: kube-system  
                                                            kind: pod name: calico-typha-deploy-6c94dc645b-pmv7f namespace: kube-system  
                                                            kind: pod name: calico-typha-horizontal-autoscaler-745ff89c8f-55hfh namespace: kube-system  
                                                            kind: pod name: calico-typha-vertical-autoscaler-59b9756658-jfws7 namespace: kube-system  
                                                            kind: pod name: coredns-7dc94444b8-9vvfv namespace: kube-system  
                                                            kind: pod name: coredns-7dc94444b8-zg7b7 namespace: kube-system  
                                                            kind: pod name: metrics-server-6bf765d77d-djkfx namespace: kube-system  
                                                            kind: pod name: metrics-server-6bf765d77d-fsgdq namespace: kube-system  
                                                         
                                                     
                                                    
                                                        azure 
                                                        
                                                            kind: pod name: apiserver-proxy-8r626 namespace: kube-system  
                                                            kind: pod name: apiserver-proxy-l8lgd namespace: kube-system  
                                                            kind: pod name: blackbox-exporter-54d6476f57-bsw76 namespace: kube-system  
                                                            kind: pod name: blackbox-exporter-54d6476f57-c7wc2 namespace: kube-system  
                                                            kind: pod name: calico-node-vertical-autoscaler-75c94f77bb-44czk namespace: kube-system  
                                                            kind: pod name: calico-typha-deploy-6c94dc645b-cn7v8 namespace: kube-system  
                                                            kind: pod name: calico-typha-deploy-6c94dc645b-vgg9l namespace: kube-system  
                                                            kind: pod name: calico-typha-horizontal-autoscaler-745ff89c8f-2rpxc namespace: kube-system  
                                                            kind: pod name: calico-typha-vertical-autoscaler-59b9756658-p8mzz namespace: kube-system  
                                                            kind: pod name: cloud-node-manager-p7tm2 namespace: kube-system  
                                                            kind: pod name: cloud-node-manager-ps8pw namespace: kube-system  
                                                            kind: pod name: coredns-556cd47d78-g9h8v namespace: kube-system  
                                                            kind: pod name: coredns-556cd47d78-ql2rp namespace: kube-system  
                                                            kind: pod name: metrics-server-d94c5968-fbmdw namespace: kube-system  
                                                            kind: pod name: metrics-server-d94c5968-m2x7r namespace: kube-system  
                                                         
                                                     
                                                    
                                                        gcp 
                                                        
                                                            kind: pod name: apiserver-proxy-dxk6r namespace: kube-system  
                                                            kind: pod name: apiserver-proxy-wdccl namespace: kube-system  
                                                            kind: pod name: blackbox-exporter-54d6476f57-8wfq2 namespace: kube-system  
                                                            kind: pod name: blackbox-exporter-54d6476f57-vvg7r namespace: kube-system  
                                                            kind: pod name: calico-node-vertical-autoscaler-75c94f77bb-7sxbj namespace: kube-system  
                                                            kind: pod name: calico-typha-deploy-6c94dc645b-hxc9n namespace: kube-system  
                                                            kind: pod name: calico-typha-deploy-6c94dc645b-jx2gb namespace: kube-system  
                                                            kind: pod name: calico-typha-horizontal-autoscaler-745ff89c8f-wfsgm namespace: kube-system  
                                                            kind: pod name: calico-typha-vertical-autoscaler-59b9756658-zn42c namespace: kube-system  
                                                            kind: pod name: coredns-f68b78c49-8xjpl namespace: kube-system  
                                                            kind: pod name: coredns-f68b78c49-zkfxf namespace: kube-system  
                                                            kind: pod name: metrics-server-5df6676dbf-kbm29 namespace: kube-system  
                                                            kind: pod name: metrics-server-5df6676dbf-tkhb2 namespace: kube-system  
                                                         
                                                     
                                                    
                                                        openstack 
                                                        
                                                            kind: pod name: apiserver-proxy-mjfl5 namespace: kube-system  
                                                            kind: pod name: apiserver-proxy-zp6mh namespace: kube-system  
                                                            kind: pod name: blackbox-exporter-54d6476f57-4jfn4 namespace: kube-system  
                                                            kind: pod name: blackbox-exporter-54d6476f57-vprcp namespace: kube-system  
                                                            kind: pod name: calico-kube-controllers-5f4cb8d889-mcgpq namespace: kube-system  
                                                            kind: pod name: calico-node-vertical-autoscaler-75c94f77bb-zjc72 namespace: kube-system  
                                                            kind: pod name: calico-typha-deploy-6c94dc645b-fzc8v namespace: kube-system  
                                                            kind: pod name: calico-typha-deploy-6c94dc645b-jvpdv namespace: kube-system  
                                                            kind: pod name: calico-typha-horizontal-autoscaler-745ff89c8f-jwh2r namespace: kube-system  
                                                            kind: pod name: calico-typha-vertical-autoscaler-59b9756658-qx9sd namespace: kube-system  
                                                            kind: pod name: coredns-5464fd5895-gzjzz namespace: kube-system  
                                                            kind: pod name: coredns-5464fd5895-mgtdc namespace: kube-system  
                                                            kind: pod name: metrics-server-7c7946c76-gsxtg namespace: kube-system  
                                                            kind: pod name: metrics-server-7c7946c76-szr7s namespace: kube-system  
                                                         
                                                     
                                                 
                                             
                                         
                                     
                                 
                             
                         
                        
                            
                                🔵 Accepted 
                                
                                    
                                        2001 (High) - Containers must be forbidden to escalate privileges. 
                                        
                                            
                                                Gardener managed resources are accepted to allow privilege escalation. 
                                                
                                                    
                                                        aws 
                                                        
                                                            container: add-snat-rule-to-upstream-dns kind: pod name: calico-node-ftrmj namespace: kube-system  
                                                            container: calico-node kind: pod name: calico-node-ftrmj namespace: kube-system  
                                                            container: cleanup-routes kind: pod name: calico-node-ftrmj namespace: kube-system  
                                                            container: install-cni kind: pod name: calico-node-ftrmj namespace: kube-system  
                                                            container: add-snat-rule-to-upstream-dns kind: pod name: calico-node-znq6v namespace: kube-system  
                                                            container: calico-node kind: pod name: calico-node-znq6v namespace: kube-system  
                                                            container: cleanup-routes kind: pod name: calico-node-znq6v namespace: kube-system  
                                                            container: install-cni kind: pod name: calico-node-znq6v namespace: kube-system  
                                                            container: csi-driver kind: pod name: csi-driver-node-jcrqk namespace: kube-system  
                                                            container: csi-driver kind: pod name: csi-driver-node-r2wkr namespace: kube-system  
                                                            container: cleanup kind: pod name: kube-proxy-worker-kkfk1-v1.31.8-8bvtn namespace: kube-system  
                                                            container: kube-proxy-init kind: pod name: kube-proxy-worker-kkfk1-v1.31.8-8bvtn namespace: kube-system  
                                                            container: cleanup kind: pod name: kube-proxy-worker-kkfk1-v1.31.8-fdssd namespace: kube-system  
                                                            container: kube-proxy-init kind: pod name: kube-proxy-worker-kkfk1-v1.31.8-fdssd namespace: kube-system  
                                                            container: node-problem-detector kind: pod name: node-problem-detector-gtfpl namespace: kube-system  
                                                            container: node-problem-detector kind: pod name: node-problem-detector-kpczj namespace: kube-system  
                                                            container: vpn-shoot-init kind: pod name: vpn-shoot-b79bb6f9-7vnr4 namespace: kube-system  
                                                         
                                                     
                                                    
                                                        azure 
                                                        
                                                            container: calico-node kind: pod name: calico-node-6j4zv namespace: kube-system  
                                                            container: install-cni kind: pod name: calico-node-6j4zv namespace: kube-system  
                                                            container: calico-node kind: pod name: calico-node-cbmrk namespace: kube-system  
                                                            container: install-cni kind: pod name: calico-node-cbmrk namespace: kube-system  
                                                            container: csi-driver kind: pod name: csi-driver-node-disk-ch2pm namespace: kube-system  
                                                            container: csi-driver kind: pod name: csi-driver-node-disk-jfxtn namespace: kube-system  
                                                            container: csi-driver kind: pod name: csi-driver-node-file-6dn4x namespace: kube-system  
                                                            container: csi-driver kind: pod name: csi-driver-node-file-kjgcg namespace: kube-system  
                                                            container: cleanup kind: pod name: kube-proxy-worker-g7p4p-v1.31.8-7dnc5 namespace: kube-system  
                                                            container: kube-proxy-init kind: pod name: kube-proxy-worker-g7p4p-v1.31.8-7dnc5 namespace: kube-system  
                                                            container: cleanup kind: pod name: kube-proxy-worker-g7p4p-v1.31.8-th5l5 namespace: kube-system  
                                                            container: kube-proxy-init kind: pod name: kube-proxy-worker-g7p4p-v1.31.8-th5l5 namespace: kube-system  
                                                            container: node-problem-detector kind: pod name: node-problem-detector-ddmx4 namespace: kube-system  
                                                            container: node-problem-detector kind: pod name: node-problem-detector-qxs5g namespace: kube-system  
                                                            container: vpn-shoot-init kind: pod name: vpn-shoot-84954fb6df-sqkt9 namespace: kube-system  
                                                         
                                                     
                                                    
                                                        gcp 
                                                        
                                                            container: calico-node kind: pod name: calico-node-pbp5x namespace: kube-system  
                                                            container: cleanup-routes kind: pod name: calico-node-pbp5x namespace: kube-system  
                                                            container: install-cni kind: pod name: calico-node-pbp5x namespace: kube-system  
                                                            container: calico-node kind: pod name: calico-node-xjxgs namespace: kube-system  
                                                            container: cleanup-routes kind: pod name: calico-node-xjxgs namespace: kube-system  
                                                            container: install-cni kind: pod name: calico-node-xjxgs namespace: kube-system  
                                                            container: csi-driver kind: pod name: csi-driver-node-4mx2n namespace: kube-system  
                                                            container: csi-driver kind: pod name: csi-driver-node-j8pfg namespace: kube-system  
                                                            container: cleanup kind: pod name: kube-proxy-worker-bex82-v1.31.8-krn64 namespace: kube-system  
                                                            container: kube-proxy-init kind: pod name: kube-proxy-worker-bex82-v1.31.8-krn64 namespace: kube-system  
                                                            container: cleanup kind: pod name: kube-proxy-worker-bex82-v1.31.8-x9kg4 namespace: kube-system  
                                                            container: kube-proxy-init kind: pod name: kube-proxy-worker-bex82-v1.31.8-x9kg4 namespace: kube-system  
                                                            container: node-problem-detector kind: pod name: node-problem-detector-2jzhw namespace: kube-system  
                                                            container: node-problem-detector kind: pod name: node-problem-detector-5qmlk namespace: kube-system  
                                                            container: vpn-shoot-init kind: pod name: vpn-shoot-5b6c54bdc9-dh49n namespace: kube-system  
                                                         
                                                     
                                                    
                                                        openstack 
                                                        
                                                            container: calico-node kind: pod name: calico-node-rsrv5 namespace: kube-system  
                                                            container: install-cni kind: pod name: calico-node-rsrv5 namespace: kube-system  
                                                            container: calico-node kind: pod name: calico-node-wdnsn namespace: kube-system  
                                                            container: install-cni kind: pod name: calico-node-wdnsn namespace: kube-system  
                                                            container: csi-driver kind: pod name: csi-driver-node-46dm2 namespace: kube-system  
                                                            container: csi-driver kind: pod name: csi-driver-node-pwcl7 namespace: kube-system  
                                                            container: cleanup kind: pod name: kube-proxy-worker-dqty2-v1.31.8-9sx78 namespace: kube-system  
                                                            container: kube-proxy-init kind: pod name: kube-proxy-worker-dqty2-v1.31.8-9sx78 namespace: kube-system  
                                                            container: cleanup kind: pod name: kube-proxy-worker-dqty2-v1.31.8-fwp8d namespace: kube-system  
                                                            container: kube-proxy-init kind: pod name: kube-proxy-worker-dqty2-v1.31.8-fwp8d namespace: kube-system  
                                                            container: node-problem-detector kind: pod name: node-problem-detector-2dxfn namespace: kube-system  
                                                            container: node-problem-detector kind: pod name: node-problem-detector-5mv98 namespace: kube-system  
                                                            container: vpn-shoot-init kind: pod name: vpn-shoot-54dfc94bd-jlgl9 namespace: kube-system  
                                                         
                                                     
                                                 
                                             
                                         
                                     
                                    
                                        2003 (Medium) - Pods should use only allowed volume types. 
                                        
                                            
                                                Gardener managed resources are accepted to use a wider range of volume types. 
                                                
                                                    
                                                        aws 
                                                        
                                                            kind: pod name: calico-node-ftrmj namespace: kube-system volume: lib-modules  
                                                            kind: pod name: calico-node-ftrmj namespace: kube-system volume: var-run-calico  
                                                            kind: pod name: calico-node-ftrmj namespace: kube-system volume: var-lib-calico  
                                                            kind: pod name: calico-node-ftrmj namespace: kube-system volume: xtables-lock  
                                                            kind: pod name: calico-node-ftrmj namespace: kube-system volume: cni-bin-dir  
                                                            kind: pod name: calico-node-ftrmj namespace: kube-system volume: cni-net-dir  
                                                            kind: pod name: calico-node-ftrmj namespace: kube-system volume: cni-log-dir  
                                                            kind: pod name: calico-node-ftrmj namespace: kube-system volume: policysync  
                                                            kind: pod name: calico-node-znq6v namespace: kube-system volume: lib-modules  
                                                            kind: pod name: calico-node-znq6v namespace: kube-system volume: var-run-calico  
                                                            kind: pod name: calico-node-znq6v namespace: kube-system volume: var-lib-calico  
                                                            kind: pod name: calico-node-znq6v namespace: kube-system volume: xtables-lock  
                                                            kind: pod name: calico-node-znq6v namespace: kube-system volume: cni-bin-dir  
                                                            kind: pod name: calico-node-znq6v namespace: kube-system volume: cni-net-dir  
                                                            kind: pod name: calico-node-znq6v namespace: kube-system volume: cni-log-dir  
                                                            kind: pod name: calico-node-znq6v namespace: kube-system volume: policysync  
                                                            kind: pod name: csi-driver-node-jcrqk namespace: kube-system volume: kubelet-dir  
                                                            kind: pod name: csi-driver-node-jcrqk namespace: kube-system volume: plugin-dir  
                                                            kind: pod name: csi-driver-node-jcrqk namespace: kube-system volume: registration-dir  
                                                            kind: pod name: csi-driver-node-jcrqk namespace: kube-system volume: device-dir  
                                                            kind: pod name: csi-driver-node-r2wkr namespace: kube-system volume: kubelet-dir  
                                                            kind: pod name: csi-driver-node-r2wkr namespace: kube-system volume: plugin-dir  
                                                            kind: pod name: csi-driver-node-r2wkr namespace: kube-system volume: registration-dir  
                                                            kind: pod name: csi-driver-node-r2wkr namespace: kube-system volume: device-dir  
                                                            kind: pod name: egress-filter-applier-5t7l2 namespace: kube-system volume: xtables-lock  
                                                            kind: pod name: egress-filter-applier-z2bgp namespace: kube-system volume: xtables-lock  
                                                            kind: pod name: kube-proxy-worker-kkfk1-v1.31.8-8bvtn namespace: kube-system volume: ssl-certs-hosts  
                                                            kind: pod name: kube-proxy-worker-kkfk1-v1.31.8-8bvtn namespace: kube-system volume: kernel-modules  
                                                            kind: pod name: kube-proxy-worker-kkfk1-v1.31.8-8bvtn namespace: kube-system volume: kube-proxy-dir  
                                                            kind: pod name: kube-proxy-worker-kkfk1-v1.31.8-8bvtn namespace: kube-system volume: kube-proxy-mode  
                                                            kind: pod name: kube-proxy-worker-kkfk1-v1.31.8-8bvtn namespace: kube-system volume: xtables-lock  
                                                            kind: pod name: kube-proxy-worker-kkfk1-v1.31.8-fdssd namespace: kube-system volume: ssl-certs-hosts  
                                                            kind: pod name: kube-proxy-worker-kkfk1-v1.31.8-fdssd namespace: kube-system volume: kernel-modules  
                                                            kind: pod name: kube-proxy-worker-kkfk1-v1.31.8-fdssd namespace: kube-system volume: kube-proxy-dir  
                                                            kind: pod name: kube-proxy-worker-kkfk1-v1.31.8-fdssd namespace: kube-system volume: kube-proxy-mode  
                                                            kind: pod name: kube-proxy-worker-kkfk1-v1.31.8-fdssd namespace: kube-system volume: xtables-lock  
                                                            kind: pod name: network-problem-detector-host-2cvlq namespace: kube-system volume: output  
                                                            kind: pod name: network-problem-detector-host-2cvlq namespace: kube-system volume: log  
                                                            kind: pod name: network-problem-detector-host-7xff6 namespace: kube-system volume: output  
                                                            kind: pod name: network-problem-detector-host-7xff6 namespace: kube-system volume: log  
                                                            kind: pod name: network-problem-detector-pod-9t5fl namespace: kube-system volume: output  
                                                            kind: pod name: network-problem-detector-pod-9t5fl namespace: kube-system volume: log  
                                                            kind: pod name: network-problem-detector-pod-v89js namespace: kube-system volume: output  
                                                            kind: pod name: network-problem-detector-pod-v89js namespace: kube-system volume: log  
                                                            kind: pod name: node-exporter-45s48 namespace: kube-system volume: host  
                                                            kind: pod name: node-exporter-45s48 namespace: kube-system volume: textfile  
                                                            kind: pod name: node-exporter-fb7c7 namespace: kube-system volume: host  
                                                            kind: pod name: node-exporter-fb7c7 namespace: kube-system volume: textfile  
                                                            kind: pod name: node-local-dns-mnx5f namespace: kube-system volume: xtables-lock  
                                                            kind: pod name: node-local-dns-pjrjg namespace: kube-system volume: xtables-lock  
                                                            kind: pod name: node-problem-detector-gtfpl namespace: kube-system volume: log  
                                                            kind: pod name: node-problem-detector-gtfpl namespace: kube-system volume: localtime  
                                                            kind: pod name: node-problem-detector-gtfpl namespace: kube-system volume: kmsg  
                                                            kind: pod name: node-problem-detector-kpczj namespace: kube-system volume: log  
                                                            kind: pod name: node-problem-detector-kpczj namespace: kube-system volume: localtime  
                                                            kind: pod name: node-problem-detector-kpczj namespace: kube-system volume: kmsg  
                                                            kind: pod name: vpn-shoot-b79bb6f9-7vnr4 namespace: kube-system volume: dev-net-tun  
                                                         
                                                     
                                                    
                                                        azure 
                                                        
                                                            kind: pod name: calico-node-6j4zv namespace: kube-system volume: lib-modules  
                                                            kind: pod name: calico-node-6j4zv namespace: kube-system volume: var-run-calico  
                                                            kind: pod name: calico-node-6j4zv namespace: kube-system volume: var-lib-calico  
                                                            kind: pod name: calico-node-6j4zv namespace: kube-system volume: xtables-lock  
                                                            kind: pod name: calico-node-6j4zv namespace: kube-system volume: cni-bin-dir  
                                                            kind: pod name: calico-node-6j4zv namespace: kube-system volume: cni-net-dir  
                                                            kind: pod name: calico-node-6j4zv namespace: kube-system volume: cni-log-dir  
                                                            kind: pod name: calico-node-6j4zv namespace: kube-system volume: policysync  
                                                            kind: pod name: calico-node-cbmrk namespace: kube-system volume: lib-modules  
                                                            kind: pod name: calico-node-cbmrk namespace: kube-system volume: var-run-calico  
                                                            kind: pod name: calico-node-cbmrk namespace: kube-system volume: var-lib-calico  
                                                            kind: pod name: calico-node-cbmrk namespace: kube-system volume: xtables-lock  
                                                            kind: pod name: calico-node-cbmrk namespace: kube-system volume: cni-bin-dir  
                                                            kind: pod name: calico-node-cbmrk namespace: kube-system volume: cni-net-dir  
                                                            kind: pod name: calico-node-cbmrk namespace: kube-system volume: cni-log-dir  
                                                            kind: pod name: calico-node-cbmrk namespace: kube-system volume: policysync  
                                                            kind: pod name: csi-driver-node-disk-ch2pm namespace: kube-system volume: kubelet-dir  
                                                            kind: pod name: csi-driver-node-disk-ch2pm namespace: kube-system volume: plugin-dir  
                                                            kind: pod name: csi-driver-node-disk-ch2pm namespace: kube-system volume: registration-dir  
                                                            kind: pod name: csi-driver-node-disk-ch2pm namespace: kube-system volume: device-dir  
                                                            kind: pod name: csi-driver-node-disk-ch2pm namespace: kube-system volume: sys-devices-dir  
                                                            kind: pod name: csi-driver-node-disk-ch2pm namespace: kube-system volume: scsi-host-dir  
                                                            kind: pod name: csi-driver-node-disk-jfxtn namespace: kube-system volume: kubelet-dir  
                                                            kind: pod name: csi-driver-node-disk-jfxtn namespace: kube-system volume: plugin-dir  
                                                            kind: pod name: csi-driver-node-disk-jfxtn namespace: kube-system volume: registration-dir  
                                                            kind: pod name: csi-driver-node-disk-jfxtn namespace: kube-system volume: device-dir  
                                                            kind: pod name: csi-driver-node-disk-jfxtn namespace: kube-system volume: sys-devices-dir  
                                                            kind: pod name: csi-driver-node-disk-jfxtn namespace: kube-system volume: scsi-host-dir  
                                                            kind: pod name: csi-driver-node-file-6dn4x namespace: kube-system volume: kubelet-dir  
                                                            kind: pod name: csi-driver-node-file-6dn4x namespace: kube-system volume: plugin-dir  
                                                            kind: pod name: csi-driver-node-file-6dn4x namespace: kube-system volume: registration-dir  
                                                            kind: pod name: csi-driver-node-file-6dn4x namespace: kube-system volume: device-dir  
                                                            kind: pod name: csi-driver-node-file-kjgcg namespace: kube-system volume: kubelet-dir  
                                                            kind: pod name: csi-driver-node-file-kjgcg namespace: kube-system volume: plugin-dir  
                                                            kind: pod name: csi-driver-node-file-kjgcg namespace: kube-system volume: registration-dir  
                                                            kind: pod name: csi-driver-node-file-kjgcg namespace: kube-system volume: device-dir  
                                                            kind: pod name: egress-filter-applier-2bmgq namespace: kube-system volume: xtables-lock  
                                                            kind: pod name: egress-filter-applier-tssl5 namespace: kube-system volume: xtables-lock  
                                                            kind: pod name: kube-proxy-worker-g7p4p-v1.31.8-7dnc5 namespace: kube-system volume: ssl-certs-hosts  
                                                            kind: pod name: kube-proxy-worker-g7p4p-v1.31.8-7dnc5 namespace: kube-system volume: kernel-modules  
                                                            kind: pod name: kube-proxy-worker-g7p4p-v1.31.8-7dnc5 namespace: kube-system volume: kube-proxy-dir  
                                                            kind: pod name: kube-proxy-worker-g7p4p-v1.31.8-7dnc5 namespace: kube-system volume: kube-proxy-mode  
                                                            kind: pod name: kube-proxy-worker-g7p4p-v1.31.8-7dnc5 namespace: kube-system volume: xtables-lock  
                                                            kind: pod name: kube-proxy-worker-g7p4p-v1.31.8-th5l5 namespace: kube-system volume: ssl-certs-hosts  
                                                            kind: pod name: kube-proxy-worker-g7p4p-v1.31.8-th5l5 namespace: kube-system volume: kernel-modules  
                                                            kind: pod name: kube-proxy-worker-g7p4p-v1.31.8-th5l5 namespace: kube-system volume: kube-proxy-dir  
                                                            kind: pod name: kube-proxy-worker-g7p4p-v1.31.8-th5l5 namespace: kube-system volume: kube-proxy-mode  
                                                            kind: pod name: kube-proxy-worker-g7p4p-v1.31.8-th5l5 namespace: kube-system volume: xtables-lock  
                                                            kind: pod name: network-problem-detector-host-cprp9 namespace: kube-system volume: output  
                                                            kind: pod name: network-problem-detector-host-cprp9 namespace: kube-system volume: log  
                                                            kind: pod name: network-problem-detector-host-xvzkb namespace: kube-system volume: output  
                                                            kind: pod name: network-problem-detector-host-xvzkb namespace: kube-system volume: log  
                                                            kind: pod name: network-problem-detector-pod-ck849 namespace: kube-system volume: output  
                                                            kind: pod name: network-problem-detector-pod-ck849 namespace: kube-system volume: log  
                                                            kind: pod name: network-problem-detector-pod-jgf7j namespace: kube-system volume: output  
                                                            kind: pod name: network-problem-detector-pod-jgf7j namespace: kube-system volume: log  
                                                            kind: pod name: node-exporter-8nn24 namespace: kube-system volume: host  
                                                            kind: pod name: node-exporter-8nn24 namespace: kube-system volume: textfile  
                                                            kind: pod name: node-exporter-lzf7z namespace: kube-system volume: host  
                                                            kind: pod name: node-exporter-lzf7z namespace: kube-system volume: textfile  
                                                            kind: pod name: node-local-dns-d6lgp namespace: kube-system volume: xtables-lock  
                                                            kind: pod name: node-local-dns-r6zzr namespace: kube-system volume: xtables-lock  
                                                            kind: pod name: node-problem-detector-ddmx4 namespace: kube-system volume: log  
                                                            kind: pod name: node-problem-detector-ddmx4 namespace: kube-system volume: localtime  
                                                            kind: pod name: node-problem-detector-ddmx4 namespace: kube-system volume: kmsg  
                                                            kind: pod name: node-problem-detector-qxs5g namespace: kube-system volume: log  
                                                            kind: pod name: node-problem-detector-qxs5g namespace: kube-system volume: localtime  
                                                            kind: pod name: node-problem-detector-qxs5g namespace: kube-system volume: kmsg  
                                                            kind: pod name: vpn-shoot-84954fb6df-sqkt9 namespace: kube-system volume: dev-net-tun  
                                                         
                                                     
                                                    
                                                        gcp 
                                                        
                                                            kind: pod name: calico-node-pbp5x namespace: kube-system volume: lib-modules  
                                                            kind: pod name: calico-node-pbp5x namespace: kube-system volume: var-run-calico  
                                                            kind: pod name: calico-node-pbp5x namespace: kube-system volume: var-lib-calico  
                                                            kind: pod name: calico-node-pbp5x namespace: kube-system volume: xtables-lock  
                                                            kind: pod name: calico-node-pbp5x namespace: kube-system volume: cni-bin-dir  
                                                            kind: pod name: calico-node-pbp5x namespace: kube-system volume: cni-net-dir  
                                                            kind: pod name: calico-node-pbp5x namespace: kube-system volume: cni-log-dir  
                                                            kind: pod name: calico-node-pbp5x namespace: kube-system volume: policysync  
                                                            kind: pod name: calico-node-xjxgs namespace: kube-system volume: lib-modules  
                                                            kind: pod name: calico-node-xjxgs namespace: kube-system volume: var-run-calico  
                                                            kind: pod name: calico-node-xjxgs namespace: kube-system volume: var-lib-calico  
                                                            kind: pod name: calico-node-xjxgs namespace: kube-system volume: xtables-lock  
                                                            kind: pod name: calico-node-xjxgs namespace: kube-system volume: cni-bin-dir  
                                                            kind: pod name: calico-node-xjxgs namespace: kube-system volume: cni-net-dir  
                                                            kind: pod name: calico-node-xjxgs namespace: kube-system volume: cni-log-dir  
                                                            kind: pod name: calico-node-xjxgs namespace: kube-system volume: policysync  
                                                            kind: pod name: csi-driver-node-4mx2n namespace: kube-system volume: kubelet-dir  
                                                            kind: pod name: csi-driver-node-4mx2n namespace: kube-system volume: plugin-dir  
                                                            kind: pod name: csi-driver-node-4mx2n namespace: kube-system volume: registration-dir  
                                                            kind: pod name: csi-driver-node-4mx2n namespace: kube-system volume: device-dir  
                                                            kind: pod name: csi-driver-node-j8pfg namespace: kube-system volume: kubelet-dir  
                                                            kind: pod name: csi-driver-node-j8pfg namespace: kube-system volume: plugin-dir  
                                                            kind: pod name: csi-driver-node-j8pfg namespace: kube-system volume: registration-dir  
                                                            kind: pod name: csi-driver-node-j8pfg namespace: kube-system volume: device-dir  
                                                            kind: pod name: egress-filter-applier-b9b5x namespace: kube-system volume: xtables-lock  
                                                            kind: pod name: egress-filter-applier-pkr9q namespace: kube-system volume: xtables-lock  
                                                            kind: pod name: kube-proxy-worker-bex82-v1.31.8-krn64 namespace: kube-system volume: ssl-certs-hosts  
                                                            kind: pod name: kube-proxy-worker-bex82-v1.31.8-krn64 namespace: kube-system volume: kernel-modules  
                                                            kind: pod name: kube-proxy-worker-bex82-v1.31.8-krn64 namespace: kube-system volume: kube-proxy-dir  
                                                            kind: pod name: kube-proxy-worker-bex82-v1.31.8-krn64 namespace: kube-system volume: kube-proxy-mode  
                                                            kind: pod name: kube-proxy-worker-bex82-v1.31.8-krn64 namespace: kube-system volume: xtables-lock  
                                                            kind: pod name: kube-proxy-worker-bex82-v1.31.8-x9kg4 namespace: kube-system volume: ssl-certs-hosts  
                                                            kind: pod name: kube-proxy-worker-bex82-v1.31.8-x9kg4 namespace: kube-system volume: kernel-modules  
                                                            kind: pod name: kube-proxy-worker-bex82-v1.31.8-x9kg4 namespace: kube-system volume: kube-proxy-dir  
                                                            kind: pod name: kube-proxy-worker-bex82-v1.31.8-x9kg4 namespace: kube-system volume: kube-proxy-mode  
                                                            kind: pod name: kube-proxy-worker-bex82-v1.31.8-x9kg4 namespace: kube-system volume: xtables-lock  
                                                            kind: pod name: network-problem-detector-host-8ltzf namespace: kube-system volume: output  
                                                            kind: pod name: network-problem-detector-host-8ltzf namespace: kube-system volume: log  
                                                            kind: pod name: network-problem-detector-host-hd4cf namespace: kube-system volume: output  
                                                            kind: pod name: network-problem-detector-host-hd4cf namespace: kube-system volume: log  
                                                            kind: pod name: network-problem-detector-pod-gz2ph namespace: kube-system volume: output  
                                                            kind: pod name: network-problem-detector-pod-gz2ph namespace: kube-system volume: log  
                                                            kind: pod name: network-problem-detector-pod-q8tj6 namespace: kube-system volume: output  
                                                            kind: pod name: network-problem-detector-pod-q8tj6 namespace: kube-system volume: log  
                                                            kind: pod name: node-exporter-5jtvr namespace: kube-system volume: host  
                                                            kind: pod name: node-exporter-5jtvr namespace: kube-system volume: textfile  
                                                            kind: pod name: node-exporter-s5t8x namespace: kube-system volume: host  
                                                            kind: pod name: node-exporter-s5t8x namespace: kube-system volume: textfile  
                                                            kind: pod name: node-local-dns-f29m2 namespace: kube-system volume: xtables-lock  
                                                            kind: pod name: node-local-dns-srwg9 namespace: kube-system volume: xtables-lock  
                                                            kind: pod name: node-problem-detector-2jzhw namespace: kube-system volume: log  
                                                            kind: pod name: node-problem-detector-2jzhw namespace: kube-system volume: localtime  
                                                            kind: pod name: node-problem-detector-2jzhw namespace: kube-system volume: kmsg  
                                                            kind: pod name: node-problem-detector-5qmlk namespace: kube-system volume: log  
                                                            kind: pod name: node-problem-detector-5qmlk namespace: kube-system volume: localtime  
                                                            kind: pod name: node-problem-detector-5qmlk namespace: kube-system volume: kmsg  
                                                            kind: pod name: vpn-shoot-5b6c54bdc9-dh49n namespace: kube-system volume: dev-net-tun  
                                                         
                                                     
                                                    
                                                        openstack 
                                                        
                                                            kind: pod name: calico-node-rsrv5 namespace: kube-system volume: lib-modules  
                                                            kind: pod name: calico-node-rsrv5 namespace: kube-system volume: var-run-calico  
                                                            kind: pod name: calico-node-rsrv5 namespace: kube-system volume: var-lib-calico  
                                                            kind: pod name: calico-node-rsrv5 namespace: kube-system volume: xtables-lock  
                                                            kind: pod name: calico-node-rsrv5 namespace: kube-system volume: cni-bin-dir  
                                                            kind: pod name: calico-node-rsrv5 namespace: kube-system volume: cni-net-dir  
                                                            kind: pod name: calico-node-rsrv5 namespace: kube-system volume: cni-log-dir  
                                                            kind: pod name: calico-node-rsrv5 namespace: kube-system volume: policysync  
                                                            kind: pod name: calico-node-wdnsn namespace: kube-system volume: lib-modules  
                                                            kind: pod name: calico-node-wdnsn namespace: kube-system volume: var-run-calico  
                                                            kind: pod name: calico-node-wdnsn namespace: kube-system volume: var-lib-calico  
                                                            kind: pod name: calico-node-wdnsn namespace: kube-system volume: xtables-lock  
                                                            kind: pod name: calico-node-wdnsn namespace: kube-system volume: cni-bin-dir  
                                                            kind: pod name: calico-node-wdnsn namespace: kube-system volume: cni-net-dir  
                                                            kind: pod name: calico-node-wdnsn namespace: kube-system volume: cni-log-dir  
                                                            kind: pod name: calico-node-wdnsn namespace: kube-system volume: policysync  
                                                            kind: pod name: csi-driver-node-46dm2 namespace: kube-system volume: kubelet-dir  
                                                            kind: pod name: csi-driver-node-46dm2 namespace: kube-system volume: plugin-dir  
                                                            kind: pod name: csi-driver-node-46dm2 namespace: kube-system volume: registration-dir  
                                                            kind: pod name: csi-driver-node-46dm2 namespace: kube-system volume: device-dir  
                                                            kind: pod name: csi-driver-node-pwcl7 namespace: kube-system volume: kubelet-dir  
                                                            kind: pod name: csi-driver-node-pwcl7 namespace: kube-system volume: plugin-dir  
                                                            kind: pod name: csi-driver-node-pwcl7 namespace: kube-system volume: registration-dir  
                                                            kind: pod name: csi-driver-node-pwcl7 namespace: kube-system volume: device-dir  
                                                            kind: pod name: egress-filter-applier-b5z8f namespace: kube-system volume: xtables-lock  
                                                            kind: pod name: egress-filter-applier-b6786 namespace: kube-system volume: xtables-lock  
                                                            kind: pod name: kube-proxy-worker-dqty2-v1.31.8-9sx78 namespace: kube-system volume: ssl-certs-hosts  
                                                            kind: pod name: kube-proxy-worker-dqty2-v1.31.8-9sx78 namespace: kube-system volume: kernel-modules  
                                                            kind: pod name: kube-proxy-worker-dqty2-v1.31.8-9sx78 namespace: kube-system volume: kube-proxy-dir  
                                                            kind: pod name: kube-proxy-worker-dqty2-v1.31.8-9sx78 namespace: kube-system volume: kube-proxy-mode  
                                                            kind: pod name: kube-proxy-worker-dqty2-v1.31.8-9sx78 namespace: kube-system volume: xtables-lock  
                                                            kind: pod name: kube-proxy-worker-dqty2-v1.31.8-fwp8d namespace: kube-system volume: ssl-certs-hosts  
                                                            kind: pod name: kube-proxy-worker-dqty2-v1.31.8-fwp8d namespace: kube-system volume: kernel-modules  
                                                            kind: pod name: kube-proxy-worker-dqty2-v1.31.8-fwp8d namespace: kube-system volume: kube-proxy-dir  
                                                            kind: pod name: kube-proxy-worker-dqty2-v1.31.8-fwp8d namespace: kube-system volume: kube-proxy-mode  
                                                            kind: pod name: kube-proxy-worker-dqty2-v1.31.8-fwp8d namespace: kube-system volume: xtables-lock  
                                                            kind: pod name: network-problem-detector-host-75kzx namespace: kube-system volume: output  
                                                            kind: pod name: network-problem-detector-host-75kzx namespace: kube-system volume: log  
                                                            kind: pod name: network-problem-detector-host-xhqzr namespace: kube-system volume: output  
                                                            kind: pod name: network-problem-detector-host-xhqzr namespace: kube-system volume: log  
                                                            kind: pod name: network-problem-detector-pod-7kj5v namespace: kube-system volume: output  
                                                            kind: pod name: network-problem-detector-pod-7kj5v namespace: kube-system volume: log  
                                                            kind: pod name: network-problem-detector-pod-bb6zl namespace: kube-system volume: output  
                                                            kind: pod name: network-problem-detector-pod-bb6zl namespace: kube-system volume: log  
                                                            kind: pod name: node-exporter-4cp5g namespace: kube-system volume: host  
                                                            kind: pod name: node-exporter-4cp5g namespace: kube-system volume: textfile  
                                                            kind: pod name: node-exporter-rshd2 namespace: kube-system volume: host  
                                                            kind: pod name: node-exporter-rshd2 namespace: kube-system volume: textfile  
                                                            kind: pod name: node-local-dns-57bpm namespace: kube-system volume: xtables-lock  
                                                            kind: pod name: node-local-dns-8b6dg namespace: kube-system volume: xtables-lock  
                                                            kind: pod name: node-problem-detector-2dxfn namespace: kube-system volume: log  
                                                            kind: pod name: node-problem-detector-2dxfn namespace: kube-system volume: localtime  
                                                            kind: pod name: node-problem-detector-2dxfn namespace: kube-system volume: kmsg  
                                                            kind: pod name: node-problem-detector-5mv98 namespace: kube-system volume: log  
                                                            kind: pod name: node-problem-detector-5mv98 namespace: kube-system volume: localtime  
                                                            kind: pod name: node-problem-detector-5mv98 namespace: kube-system volume: kmsg  
                                                            kind: pod name: vpn-shoot-54dfc94bd-jlgl9 namespace: kube-system volume: dev-net-tun  
                                                         
                                                     
                                                 
                                             
                                         
                                     
                                    
                                        2006 (Medium) - Limit the use of wildcards in RBAC resources. 
                                        
                                            
                                                Default RBAC Roles. 
                                                
                                                    
                                                        aws 
                                                        
                                                            kind: clusterRole name: cluster-admin  
                                                            kind: clusterRole name: system:controller:disruption-controller  
                                                            kind: clusterRole name: system:controller:generic-garbage-collector  
                                                            kind: clusterRole name: system:controller:horizontal-pod-autoscaler  
                                                            kind: clusterRole name: system:controller:namespace-controller  
                                                            kind: clusterRole name: system:controller:resourcequota-controller  
                                                            kind: clusterRole name: system:kube-controller-manager  
                                                         
                                                     
                                                    
                                                        azure 
                                                        
                                                            kind: clusterRole name: cluster-admin  
                                                            kind: clusterRole name: system:controller:disruption-controller  
                                                            kind: clusterRole name: system:controller:generic-garbage-collector  
                                                            kind: clusterRole name: system:controller:horizontal-pod-autoscaler  
                                                            kind: clusterRole name: system:controller:namespace-controller  
                                                            kind: clusterRole name: system:controller:resourcequota-controller  
                                                            kind: clusterRole name: system:kube-controller-manager  
                                                         
                                                     
                                                    
                                                        gcp 
                                                        
                                                            kind: clusterRole name: cluster-admin  
                                                            kind: clusterRole name: system:controller:disruption-controller  
                                                            kind: clusterRole name: system:controller:generic-garbage-collector  
                                                            kind: clusterRole name: system:controller:horizontal-pod-autoscaler  
                                                            kind: clusterRole name: system:controller:namespace-controller  
                                                            kind: clusterRole name: system:controller:resourcequota-controller  
                                                            kind: clusterRole name: system:kube-controller-manager  
                                                         
                                                     
                                                    
                                                        openstack 
                                                        
                                                            kind: clusterRole name: cluster-admin  
                                                            kind: clusterRole name: system:controller:disruption-controller  
                                                            kind: clusterRole name: system:controller:generic-garbage-collector  
                                                            kind: clusterRole name: system:controller:horizontal-pod-autoscaler  
                                                            kind: clusterRole name: system:controller:namespace-controller  
                                                            kind: clusterRole name: system:controller:resourcequota-controller  
                                                            kind: clusterRole name: system:kube-controller-manager  
                                                         
                                                     
                                                 
                                             
                                            
                                                VPA RBAC Roles require */scale permissions to vertically scale resources. 
                                                
                                                    
                                                        aws 
                                                        
                                                            kind: clusterRole name: gardener.cloud:vpa:target:target-reader  
                                                         
                                                     
                                                    
                                                        azure 
                                                        
                                                            kind: clusterRole name: gardener.cloud:vpa:target:target-reader  
                                                         
                                                     
                                                    
                                                        gcp 
                                                        
                                                            kind: clusterRole name: gardener.cloud:vpa:target:target-reader  
                                                         
                                                     
                                                    
                                                        openstack 
                                                        
                                                            kind: clusterRole name: gardener.cloud:vpa:target:target-reader  
                                                         
                                                     
                                                 
                                             
                                         
                                     
                                    
                                        2007 (Medium) - Limit the use of wildcards in RBAC verbs. 
                                        
                                            
                                                Default RBAC Roles. 
                                                
                                                    
                                                        aws 
                                                        
                                                            kind: clusterRole name: cluster-admin  
                                                            kind: clusterRole name: system:kubelet-api-admin  
                                                         
                                                     
                                                    
                                                        azure 
                                                        
                                                            kind: clusterRole name: cluster-admin  
                                                            kind: clusterRole name: system:kubelet-api-admin  
                                                         
                                                     
                                                    
                                                        gcp 
                                                        
                                                            kind: clusterRole name: cluster-admin  
                                                            kind: clusterRole name: system:kubelet-api-admin  
                                                         
                                                     
                                                    
                                                        openstack 
                                                        
                                                            kind: clusterRole name: cluster-admin  
                                                            kind: clusterRole name: system:kubelet-api-admin  
                                                         
                                                     
                                                 
                                             
                                         
                                     
                                    
                                        2008 (High) - Pods must not mount host directories. 
                                        
                                            
                                                Gardener managed resources are accepted to use hostPath volumes. 
                                                
                                                    
                                                        aws 
                                                        
                                                            kind: pod name: calico-node-ftrmj namespace: kube-system volume: lib-modules  
                                                            kind: pod name: calico-node-ftrmj namespace: kube-system volume: var-run-calico  
                                                            kind: pod name: calico-node-ftrmj namespace: kube-system volume: var-lib-calico  
                                                            kind: pod name: calico-node-ftrmj namespace: kube-system volume: xtables-lock  
                                                            kind: pod name: calico-node-ftrmj namespace: kube-system volume: cni-bin-dir  
                                                            kind: pod name: calico-node-ftrmj namespace: kube-system volume: cni-net-dir  
                                                            kind: pod name: calico-node-ftrmj namespace: kube-system volume: cni-log-dir  
                                                            kind: pod name: calico-node-ftrmj namespace: kube-system volume: policysync  
                                                            kind: pod name: calico-node-znq6v namespace: kube-system volume: lib-modules  
                                                            kind: pod name: calico-node-znq6v namespace: kube-system volume: var-run-calico  
                                                            kind: pod name: calico-node-znq6v namespace: kube-system volume: var-lib-calico  
                                                            kind: pod name: calico-node-znq6v namespace: kube-system volume: xtables-lock  
                                                            kind: pod name: calico-node-znq6v namespace: kube-system volume: cni-bin-dir  
                                                            kind: pod name: calico-node-znq6v namespace: kube-system volume: cni-net-dir  
                                                            kind: pod name: calico-node-znq6v namespace: kube-system volume: cni-log-dir  
                                                            kind: pod name: calico-node-znq6v namespace: kube-system volume: policysync  
                                                            kind: pod name: csi-driver-node-jcrqk namespace: kube-system volume: kubelet-dir  
                                                            kind: pod name: csi-driver-node-jcrqk namespace: kube-system volume: plugin-dir  
                                                            kind: pod name: csi-driver-node-jcrqk namespace: kube-system volume: registration-dir  
                                                            kind: pod name: csi-driver-node-jcrqk namespace: kube-system volume: device-dir  
                                                            kind: pod name: csi-driver-node-r2wkr namespace: kube-system volume: kubelet-dir  
                                                            kind: pod name: csi-driver-node-r2wkr namespace: kube-system volume: plugin-dir  
                                                            kind: pod name: csi-driver-node-r2wkr namespace: kube-system volume: registration-dir  
                                                            kind: pod name: csi-driver-node-r2wkr namespace: kube-system volume: device-dir  
                                                            kind: pod name: egress-filter-applier-5t7l2 namespace: kube-system volume: xtables-lock  
                                                            kind: pod name: egress-filter-applier-z2bgp namespace: kube-system volume: xtables-lock  
                                                            kind: pod name: kube-proxy-worker-kkfk1-v1.31.8-8bvtn namespace: kube-system volume: ssl-certs-hosts  
                                                            kind: pod name: kube-proxy-worker-kkfk1-v1.31.8-8bvtn namespace: kube-system volume: kernel-modules  
                                                            kind: pod name: kube-proxy-worker-kkfk1-v1.31.8-8bvtn namespace: kube-system volume: kube-proxy-dir  
                                                            kind: pod name: kube-proxy-worker-kkfk1-v1.31.8-8bvtn namespace: kube-system volume: kube-proxy-mode  
                                                            kind: pod name: kube-proxy-worker-kkfk1-v1.31.8-8bvtn namespace: kube-system volume: xtables-lock  
                                                            kind: pod name: kube-proxy-worker-kkfk1-v1.31.8-fdssd namespace: kube-system volume: ssl-certs-hosts  
                                                            kind: pod name: kube-proxy-worker-kkfk1-v1.31.8-fdssd namespace: kube-system volume: kernel-modules  
                                                            kind: pod name: kube-proxy-worker-kkfk1-v1.31.8-fdssd namespace: kube-system volume: kube-proxy-dir  
                                                            kind: pod name: kube-proxy-worker-kkfk1-v1.31.8-fdssd namespace: kube-system volume: kube-proxy-mode  
                                                            kind: pod name: kube-proxy-worker-kkfk1-v1.31.8-fdssd namespace: kube-system volume: xtables-lock  
                                                            kind: pod name: network-problem-detector-host-2cvlq namespace: kube-system volume: output  
                                                            kind: pod name: network-problem-detector-host-2cvlq namespace: kube-system volume: log  
                                                            kind: pod name: network-problem-detector-host-7xff6 namespace: kube-system volume: output  
                                                            kind: pod name: network-problem-detector-host-7xff6 namespace: kube-system volume: log  
                                                            kind: pod name: network-problem-detector-pod-9t5fl namespace: kube-system volume: output  
                                                            kind: pod name: network-problem-detector-pod-9t5fl namespace: kube-system volume: log  
                                                            kind: pod name: network-problem-detector-pod-v89js namespace: kube-system volume: output  
                                                            kind: pod name: network-problem-detector-pod-v89js namespace: kube-system volume: log  
                                                            kind: pod name: node-exporter-45s48 namespace: kube-system volume: host  
                                                            kind: pod name: node-exporter-45s48 namespace: kube-system volume: textfile  
                                                            kind: pod name: node-exporter-fb7c7 namespace: kube-system volume: host  
                                                            kind: pod name: node-exporter-fb7c7 namespace: kube-system volume: textfile  
                                                            kind: pod name: node-local-dns-mnx5f namespace: kube-system volume: xtables-lock  
                                                            kind: pod name: node-local-dns-pjrjg namespace: kube-system volume: xtables-lock  
                                                            kind: pod name: node-problem-detector-gtfpl namespace: kube-system volume: log  
                                                            kind: pod name: node-problem-detector-gtfpl namespace: kube-system volume: localtime  
                                                            kind: pod name: node-problem-detector-gtfpl namespace: kube-system volume: kmsg  
                                                            kind: pod name: node-problem-detector-kpczj namespace: kube-system volume: log  
                                                            kind: pod name: node-problem-detector-kpczj namespace: kube-system volume: localtime  
                                                            kind: pod name: node-problem-detector-kpczj namespace: kube-system volume: kmsg  
                                                            kind: pod name: vpn-shoot-b79bb6f9-7vnr4 namespace: kube-system volume: dev-net-tun  
                                                         
                                                     
                                                    
                                                        azure 
                                                        
                                                            kind: pod name: calico-node-6j4zv namespace: kube-system volume: lib-modules  
                                                            kind: pod name: calico-node-6j4zv namespace: kube-system volume: var-run-calico  
                                                            kind: pod name: calico-node-6j4zv namespace: kube-system volume: var-lib-calico  
                                                            kind: pod name: calico-node-6j4zv namespace: kube-system volume: xtables-lock  
                                                            kind: pod name: calico-node-6j4zv namespace: kube-system volume: cni-bin-dir  
                                                            kind: pod name: calico-node-6j4zv namespace: kube-system volume: cni-net-dir  
                                                            kind: pod name: calico-node-6j4zv namespace: kube-system volume: cni-log-dir  
                                                            kind: pod name: calico-node-6j4zv namespace: kube-system volume: policysync  
                                                            kind: pod name: calico-node-cbmrk namespace: kube-system volume: lib-modules  
                                                            kind: pod name: calico-node-cbmrk namespace: kube-system volume: var-run-calico  
                                                            kind: pod name: calico-node-cbmrk namespace: kube-system volume: var-lib-calico  
                                                            kind: pod name: calico-node-cbmrk namespace: kube-system volume: xtables-lock  
                                                            kind: pod name: calico-node-cbmrk namespace: kube-system volume: cni-bin-dir  
                                                            kind: pod name: calico-node-cbmrk namespace: kube-system volume: cni-net-dir  
                                                            kind: pod name: calico-node-cbmrk namespace: kube-system volume: cni-log-dir  
                                                            kind: pod name: calico-node-cbmrk namespace: kube-system volume: policysync  
                                                            kind: pod name: csi-driver-node-disk-ch2pm namespace: kube-system volume: kubelet-dir  
                                                            kind: pod name: csi-driver-node-disk-ch2pm namespace: kube-system volume: plugin-dir  
                                                            kind: pod name: csi-driver-node-disk-ch2pm namespace: kube-system volume: registration-dir  
                                                            kind: pod name: csi-driver-node-disk-ch2pm namespace: kube-system volume: device-dir  
                                                            kind: pod name: csi-driver-node-disk-ch2pm namespace: kube-system volume: sys-devices-dir  
                                                            kind: pod name: csi-driver-node-disk-ch2pm namespace: kube-system volume: scsi-host-dir  
                                                            kind: pod name: csi-driver-node-disk-jfxtn namespace: kube-system volume: kubelet-dir  
                                                            kind: pod name: csi-driver-node-disk-jfxtn namespace: kube-system volume: plugin-dir  
                                                            kind: pod name: csi-driver-node-disk-jfxtn namespace: kube-system volume: registration-dir  
                                                            kind: pod name: csi-driver-node-disk-jfxtn namespace: kube-system volume: device-dir  
                                                            kind: pod name: csi-driver-node-disk-jfxtn namespace: kube-system volume: sys-devices-dir  
                                                            kind: pod name: csi-driver-node-disk-jfxtn namespace: kube-system volume: scsi-host-dir  
                                                            kind: pod name: csi-driver-node-file-6dn4x namespace: kube-system volume: kubelet-dir  
                                                            kind: pod name: csi-driver-node-file-6dn4x namespace: kube-system volume: plugin-dir  
                                                            kind: pod name: csi-driver-node-file-6dn4x namespace: kube-system volume: registration-dir  
                                                            kind: pod name: csi-driver-node-file-6dn4x namespace: kube-system volume: device-dir  
                                                            kind: pod name: csi-driver-node-file-kjgcg namespace: kube-system volume: kubelet-dir  
                                                            kind: pod name: csi-driver-node-file-kjgcg namespace: kube-system volume: plugin-dir  
                                                            kind: pod name: csi-driver-node-file-kjgcg namespace: kube-system volume: registration-dir  
                                                            kind: pod name: csi-driver-node-file-kjgcg namespace: kube-system volume: device-dir  
                                                            kind: pod name: egress-filter-applier-2bmgq namespace: kube-system volume: xtables-lock  
                                                            kind: pod name: egress-filter-applier-tssl5 namespace: kube-system volume: xtables-lock  
                                                            kind: pod name: kube-proxy-worker-g7p4p-v1.31.8-7dnc5 namespace: kube-system volume: ssl-certs-hosts  
                                                            kind: pod name: kube-proxy-worker-g7p4p-v1.31.8-7dnc5 namespace: kube-system volume: kernel-modules  
                                                            kind: pod name: kube-proxy-worker-g7p4p-v1.31.8-7dnc5 namespace: kube-system volume: kube-proxy-dir  
                                                            kind: pod name: kube-proxy-worker-g7p4p-v1.31.8-7dnc5 namespace: kube-system volume: kube-proxy-mode  
                                                            kind: pod name: kube-proxy-worker-g7p4p-v1.31.8-7dnc5 namespace: kube-system volume: xtables-lock  
                                                            kind: pod name: kube-proxy-worker-g7p4p-v1.31.8-th5l5 namespace: kube-system volume: ssl-certs-hosts  
                                                            kind: pod name: kube-proxy-worker-g7p4p-v1.31.8-th5l5 namespace: kube-system volume: kernel-modules  
                                                            kind: pod name: kube-proxy-worker-g7p4p-v1.31.8-th5l5 namespace: kube-system volume: kube-proxy-dir  
                                                            kind: pod name: kube-proxy-worker-g7p4p-v1.31.8-th5l5 namespace: kube-system volume: kube-proxy-mode  
                                                            kind: pod name: kube-proxy-worker-g7p4p-v1.31.8-th5l5 namespace: kube-system volume: xtables-lock  
                                                            kind: pod name: network-problem-detector-host-cprp9 namespace: kube-system volume: output  
                                                            kind: pod name: network-problem-detector-host-cprp9 namespace: kube-system volume: log  
                                                            kind: pod name: network-problem-detector-host-xvzkb namespace: kube-system volume: output  
                                                            kind: pod name: network-problem-detector-host-xvzkb namespace: kube-system volume: log  
                                                            kind: pod name: network-problem-detector-pod-ck849 namespace: kube-system volume: output  
                                                            kind: pod name: network-problem-detector-pod-ck849 namespace: kube-system volume: log  
                                                            kind: pod name: network-problem-detector-pod-jgf7j namespace: kube-system volume: output  
                                                            kind: pod name: network-problem-detector-pod-jgf7j namespace: kube-system volume: log  
                                                            kind: pod name: node-exporter-8nn24 namespace: kube-system volume: host  
                                                            kind: pod name: node-exporter-8nn24 namespace: kube-system volume: textfile  
                                                            kind: pod name: node-exporter-lzf7z namespace: kube-system volume: host  
                                                            kind: pod name: node-exporter-lzf7z namespace: kube-system volume: textfile  
                                                            kind: pod name: node-local-dns-d6lgp namespace: kube-system volume: xtables-lock  
                                                            kind: pod name: node-local-dns-r6zzr namespace: kube-system volume: xtables-lock  
                                                            kind: pod name: node-problem-detector-ddmx4 namespace: kube-system volume: log  
                                                            kind: pod name: node-problem-detector-ddmx4 namespace: kube-system volume: localtime  
                                                            kind: pod name: node-problem-detector-ddmx4 namespace: kube-system volume: kmsg  
                                                            kind: pod name: node-problem-detector-qxs5g namespace: kube-system volume: log  
                                                            kind: pod name: node-problem-detector-qxs5g namespace: kube-system volume: localtime  
                                                            kind: pod name: node-problem-detector-qxs5g namespace: kube-system volume: kmsg  
                                                            kind: pod name: vpn-shoot-84954fb6df-sqkt9 namespace: kube-system volume: dev-net-tun  
                                                         
                                                     
                                                    
                                                        gcp 
                                                        
                                                            kind: pod name: calico-node-pbp5x namespace: kube-system volume: lib-modules  
                                                            kind: pod name: calico-node-pbp5x namespace: kube-system volume: var-run-calico  
                                                            kind: pod name: calico-node-pbp5x namespace: kube-system volume: var-lib-calico  
                                                            kind: pod name: calico-node-pbp5x namespace: kube-system volume: xtables-lock  
                                                            kind: pod name: calico-node-pbp5x namespace: kube-system volume: cni-bin-dir  
                                                            kind: pod name: calico-node-pbp5x namespace: kube-system volume: cni-net-dir  
                                                            kind: pod name: calico-node-pbp5x namespace: kube-system volume: cni-log-dir  
                                                            kind: pod name: calico-node-pbp5x namespace: kube-system volume: policysync  
                                                            kind: pod name: calico-node-xjxgs namespace: kube-system volume: lib-modules  
                                                            kind: pod name: calico-node-xjxgs namespace: kube-system volume: var-run-calico  
                                                            kind: pod name: calico-node-xjxgs namespace: kube-system volume: var-lib-calico  
                                                            kind: pod name: calico-node-xjxgs namespace: kube-system volume: xtables-lock  
                                                            kind: pod name: calico-node-xjxgs namespace: kube-system volume: cni-bin-dir  
                                                            kind: pod name: calico-node-xjxgs namespace: kube-system volume: cni-net-dir  
                                                            kind: pod name: calico-node-xjxgs namespace: kube-system volume: cni-log-dir  
                                                            kind: pod name: calico-node-xjxgs namespace: kube-system volume: policysync  
                                                            kind: pod name: csi-driver-node-4mx2n namespace: kube-system volume: kubelet-dir  
                                                            kind: pod name: csi-driver-node-4mx2n namespace: kube-system volume: plugin-dir  
                                                            kind: pod name: csi-driver-node-4mx2n namespace: kube-system volume: registration-dir  
                                                            kind: pod name: csi-driver-node-4mx2n namespace: kube-system volume: device-dir  
                                                            kind: pod name: csi-driver-node-j8pfg namespace: kube-system volume: kubelet-dir  
                                                            kind: pod name: csi-driver-node-j8pfg namespace: kube-system volume: plugin-dir  
                                                            kind: pod name: csi-driver-node-j8pfg namespace: kube-system volume: registration-dir  
                                                            kind: pod name: csi-driver-node-j8pfg namespace: kube-system volume: device-dir  
                                                            kind: pod name: egress-filter-applier-b9b5x namespace: kube-system volume: xtables-lock  
                                                            kind: pod name: egress-filter-applier-pkr9q namespace: kube-system volume: xtables-lock  
                                                            kind: pod name: kube-proxy-worker-bex82-v1.31.8-krn64 namespace: kube-system volume: ssl-certs-hosts  
                                                            kind: pod name: kube-proxy-worker-bex82-v1.31.8-krn64 namespace: kube-system volume: kernel-modules  
                                                            kind: pod name: kube-proxy-worker-bex82-v1.31.8-krn64 namespace: kube-system volume: kube-proxy-dir  
                                                            kind: pod name: kube-proxy-worker-bex82-v1.31.8-krn64 namespace: kube-system volume: kube-proxy-mode  
                                                            kind: pod name: kube-proxy-worker-bex82-v1.31.8-krn64 namespace: kube-system volume: xtables-lock  
                                                            kind: pod name: kube-proxy-worker-bex82-v1.31.8-x9kg4 namespace: kube-system volume: ssl-certs-hosts  
                                                            kind: pod name: kube-proxy-worker-bex82-v1.31.8-x9kg4 namespace: kube-system volume: kernel-modules  
                                                            kind: pod name: kube-proxy-worker-bex82-v1.31.8-x9kg4 namespace: kube-system volume: kube-proxy-dir  
                                                            kind: pod name: kube-proxy-worker-bex82-v1.31.8-x9kg4 namespace: kube-system volume: kube-proxy-mode  
                                                            kind: pod name: kube-proxy-worker-bex82-v1.31.8-x9kg4 namespace: kube-system volume: xtables-lock  
                                                            kind: pod name: network-problem-detector-host-8ltzf namespace: kube-system volume: output  
                                                            kind: pod name: network-problem-detector-host-8ltzf namespace: kube-system volume: log  
                                                            kind: pod name: network-problem-detector-host-hd4cf namespace: kube-system volume: output  
                                                            kind: pod name: network-problem-detector-host-hd4cf namespace: kube-system volume: log  
                                                            kind: pod name: network-problem-detector-pod-gz2ph namespace: kube-system volume: output  
                                                            kind: pod name: network-problem-detector-pod-gz2ph namespace: kube-system volume: log  
                                                            kind: pod name: network-problem-detector-pod-q8tj6 namespace: kube-system volume: output  
                                                            kind: pod name: network-problem-detector-pod-q8tj6 namespace: kube-system volume: log  
                                                            kind: pod name: node-exporter-5jtvr namespace: kube-system volume: host  
                                                            kind: pod name: node-exporter-5jtvr namespace: kube-system volume: textfile  
                                                            kind: pod name: node-exporter-s5t8x namespace: kube-system volume: host  
                                                            kind: pod name: node-exporter-s5t8x namespace: kube-system volume: textfile  
                                                            kind: pod name: node-local-dns-f29m2 namespace: kube-system volume: xtables-lock  
                                                            kind: pod name: node-local-dns-srwg9 namespace: kube-system volume: xtables-lock  
                                                            kind: pod name: node-problem-detector-2jzhw namespace: kube-system volume: log  
                                                            kind: pod name: node-problem-detector-2jzhw namespace: kube-system volume: localtime  
                                                            kind: pod name: node-problem-detector-2jzhw namespace: kube-system volume: kmsg  
                                                            kind: pod name: node-problem-detector-5qmlk namespace: kube-system volume: log  
                                                            kind: pod name: node-problem-detector-5qmlk namespace: kube-system volume: localtime  
                                                            kind: pod name: node-problem-detector-5qmlk namespace: kube-system volume: kmsg  
                                                            kind: pod name: vpn-shoot-5b6c54bdc9-dh49n namespace: kube-system volume: dev-net-tun  
                                                         
                                                     
                                                    
                                                        openstack 
                                                        
                                                            kind: pod name: calico-node-rsrv5 namespace: kube-system volume: lib-modules  
                                                            kind: pod name: calico-node-rsrv5 namespace: kube-system volume: var-run-calico  
                                                            kind: pod name: calico-node-rsrv5 namespace: kube-system volume: var-lib-calico  
                                                            kind: pod name: calico-node-rsrv5 namespace: kube-system volume: xtables-lock  
                                                            kind: pod name: calico-node-rsrv5 namespace: kube-system volume: cni-bin-dir  
                                                            kind: pod name: calico-node-rsrv5 namespace: kube-system volume: cni-net-dir  
                                                            kind: pod name: calico-node-rsrv5 namespace: kube-system volume: cni-log-dir  
                                                            kind: pod name: calico-node-rsrv5 namespace: kube-system volume: policysync  
                                                            kind: pod name: calico-node-wdnsn namespace: kube-system volume: lib-modules  
                                                            kind: pod name: calico-node-wdnsn namespace: kube-system volume: var-run-calico  
                                                            kind: pod name: calico-node-wdnsn namespace: kube-system volume: var-lib-calico  
                                                            kind: pod name: calico-node-wdnsn namespace: kube-system volume: xtables-lock  
                                                            kind: pod name: calico-node-wdnsn namespace: kube-system volume: cni-bin-dir  
                                                            kind: pod name: calico-node-wdnsn namespace: kube-system volume: cni-net-dir  
                                                            kind: pod name: calico-node-wdnsn namespace: kube-system volume: cni-log-dir  
                                                            kind: pod name: calico-node-wdnsn namespace: kube-system volume: policysync  
                                                            kind: pod name: csi-driver-node-46dm2 namespace: kube-system volume: kubelet-dir  
                                                            kind: pod name: csi-driver-node-46dm2 namespace: kube-system volume: plugin-dir  
                                                            kind: pod name: csi-driver-node-46dm2 namespace: kube-system volume: registration-dir  
                                                            kind: pod name: csi-driver-node-46dm2 namespace: kube-system volume: device-dir  
                                                            kind: pod name: csi-driver-node-pwcl7 namespace: kube-system volume: kubelet-dir  
                                                            kind: pod name: csi-driver-node-pwcl7 namespace: kube-system volume: plugin-dir  
                                                            kind: pod name: csi-driver-node-pwcl7 namespace: kube-system volume: registration-dir  
                                                            kind: pod name: csi-driver-node-pwcl7 namespace: kube-system volume: device-dir  
                                                            kind: pod name: egress-filter-applier-b5z8f namespace: kube-system volume: xtables-lock  
                                                            kind: pod name: egress-filter-applier-b6786 namespace: kube-system volume: xtables-lock  
                                                            kind: pod name: kube-proxy-worker-dqty2-v1.31.8-9sx78 namespace: kube-system volume: ssl-certs-hosts  
                                                            kind: pod name: kube-proxy-worker-dqty2-v1.31.8-9sx78 namespace: kube-system volume: kernel-modules  
                                                            kind: pod name: kube-proxy-worker-dqty2-v1.31.8-9sx78 namespace: kube-system volume: kube-proxy-dir  
                                                            kind: pod name: kube-proxy-worker-dqty2-v1.31.8-9sx78 namespace: kube-system volume: kube-proxy-mode  
                                                            kind: pod name: kube-proxy-worker-dqty2-v1.31.8-9sx78 namespace: kube-system volume: xtables-lock  
                                                            kind: pod name: kube-proxy-worker-dqty2-v1.31.8-fwp8d namespace: kube-system volume: ssl-certs-hosts  
                                                            kind: pod name: kube-proxy-worker-dqty2-v1.31.8-fwp8d namespace: kube-system volume: kernel-modules  
                                                            kind: pod name: kube-proxy-worker-dqty2-v1.31.8-fwp8d namespace: kube-system volume: kube-proxy-dir  
                                                            kind: pod name: kube-proxy-worker-dqty2-v1.31.8-fwp8d namespace: kube-system volume: kube-proxy-mode  
                                                            kind: pod name: kube-proxy-worker-dqty2-v1.31.8-fwp8d namespace: kube-system volume: xtables-lock  
                                                            kind: pod name: network-problem-detector-host-75kzx namespace: kube-system volume: output  
                                                            kind: pod name: network-problem-detector-host-75kzx namespace: kube-system volume: log  
                                                            kind: pod name: network-problem-detector-host-xhqzr namespace: kube-system volume: output  
                                                            kind: pod name: network-problem-detector-host-xhqzr namespace: kube-system volume: log  
                                                            kind: pod name: network-problem-detector-pod-7kj5v namespace: kube-system volume: output  
                                                            kind: pod name: network-problem-detector-pod-7kj5v namespace: kube-system volume: log  
                                                            kind: pod name: network-problem-detector-pod-bb6zl namespace: kube-system volume: output  
                                                            kind: pod name: network-problem-detector-pod-bb6zl namespace: kube-system volume: log  
                                                            kind: pod name: node-exporter-4cp5g namespace: kube-system volume: host  
                                                            kind: pod name: node-exporter-4cp5g namespace: kube-system volume: textfile  
                                                            kind: pod name: node-exporter-rshd2 namespace: kube-system volume: host  
                                                            kind: pod name: node-exporter-rshd2 namespace: kube-system volume: textfile  
                                                            kind: pod name: node-local-dns-57bpm namespace: kube-system volume: xtables-lock  
                                                            kind: pod name: node-local-dns-8b6dg namespace: kube-system volume: xtables-lock  
                                                            kind: pod name: node-problem-detector-2dxfn namespace: kube-system volume: log  
                                                            kind: pod name: node-problem-detector-2dxfn namespace: kube-system volume: localtime  
                                                            kind: pod name: node-problem-detector-2dxfn namespace: kube-system volume: kmsg  
                                                            kind: pod name: node-problem-detector-5mv98 namespace: kube-system volume: log  
                                                            kind: pod name: node-problem-detector-5mv98 namespace: kube-system volume: localtime  
                                                            kind: pod name: node-problem-detector-5mv98 namespace: kube-system volume: kmsg  
                                                            kind: pod name: vpn-shoot-54dfc94bd-jlgl9 namespace: kube-system volume: dev-net-tun  
                                                         
                                                     
                                                 
                                             
                                         
                                     
                                 
                             
                         
                        
                            
                                🔴 Failed 
                                
                                    
                                        2000 (High) - Ingress and egress traffic must be restricted by default. 
                                        
                                            
                                                Ingress traffic is not denied by default. 
                                                
                                             
                                            
                                                Egress traffic is not denied by default.