绑定命名空间账号
apiVersion: v1
kind: ServiceAccount
metadata:name: zhangsannamespace: kube-system---
kind: Role
apiVersion: rbac.authorization.k8s.io/v1
metadata:namespace: internal-testname: dev-test
rules:
- apiGroups: ["","extensions", "apps"]resources: ["pods","namespaces","statefulsets","deployments","daemonsets","services","ingresses"]verbs: ["get", "watch", "list"]---
kind: RoleBinding
apiVersion: rbac.authorization.k8s.io/v1
metadata:name: rd-devnamespace: dev-test
subjects:
- kind: ServiceAccountname: zhangsannamespace: kube-system
roleRef:kind: Rolename: dev-testapiGroup: rbac.authorization.k8s.io
绑定管理员账号
apiVersion: v1
kind: ServiceAccount
metadata:name: adminnamespace: kube-system---
apiVersion: rbac.authorization.k8s.io/v1
kind: ClusterRoleBinding
metadata:name: admin
roleRef:apiGroup: rbac.authorization.k8s.iokind: ClusterRolename: cluster-admin
subjects:
- kind: ServiceAccountname: adminnamespace: kube-system