bind.yaml
1 apiVersion: rbac.authorization.k8s.io/v1 2 kind: Role 3 metadata: 4 namespace: zerotesting 5 name: pod-service-reader 6 rules: 7 - apiGroups: [""] 8 resources: ["pods", "services"] 9 verbs: ["get", "list", "watch"] 10 11 --- 12 apiVersion: rbac.authorization.k8s.io/v1 13 kind: RoleBinding 14 metadata: 15 name: pod-service-reader-binding 16 namespace: zerotesting 17 subjects: 18 - kind: ServiceAccount 19 name: default 20 namespace: zerotesting 21 roleRef: 22 kind: Role 23 name: pod-service-reader 24 apiGroup: rbac.authorization.k8s.io