bind.yaml
 1  apiVersion: rbac.authorization.k8s.io/v1
 2  kind: Role
 3  metadata:
 4    namespace: zerotesting
 5    name: pod-service-reader
 6  rules:
 7  - apiGroups: [""]
 8    resources: ["pods", "services"]
 9    verbs: ["get", "list", "watch"]
10  
11  ---
12  apiVersion: rbac.authorization.k8s.io/v1
13  kind: RoleBinding
14  metadata:
15    name: pod-service-reader-binding
16    namespace: zerotesting
17  subjects:
18  - kind: ServiceAccount
19    name: default
20    namespace: zerotesting
21  roleRef:
22    kind: Role
23    name: pod-service-reader
24    apiGroup: rbac.authorization.k8s.io