---
apiVersion: rbac.authorization.k8s.io/v1
kind: ClusterRoleBinding
metadata:
name: iop-dev #ClusterRoleBinding的名字
subjects:
- kind: ServiceAccount
name: iop-dev-sa #serviceaccount资源对象的name
namespace: iop-dev #serviceaccount的namespace
roleRef:
kind: ClusterRole
name: cluster-admin #k8s集群中最高权限的角色
apiGroup: rbac.authorization.k8s.io
---
apiVersion: v1
kind: ServiceAccount
metadata:
name: iop-dev-sa # ServiceAccount的名字
namespace: iop-dev # serviceaccount的namespace
labels:
app: iop-dev-sa #ServiceAccount的标签