← Permission Reference
T2
update deployments/scale
The scale subresource carries only replicas and a read-only selector.
An unrecognized field such as a pod template is dropped rather than applied, and refused outright under strict field validation.
Unlike full update or patch, this cannot inject a template change.
The same holds for statefulsets/scale and replicasets/scale.
Scaling up still creates fresh pods from whatever template is current, so it can activate a poisoning performed through another grant.
- API Group
- apps
- Scope
- namespaced
- Audit Level
- Request

