--- apiVersion: v1 kind: ServiceAccount metadata: name: coredns namespace: kube-system --- kind: ClusterRoleBinding apiVersion: rbac.authorization.k8s.io/v1 metadata: name: coredns annotations: rbac.authorization.kubernetes.io/autoupdate: "true" subjects: - kind: User name: coredns apiGroup: rbac.authorization.k8s.io - kind: ServiceAccount name: coredns namespace: kube-system roleRef: kind: ClusterRole name: system:coredns apiGroup: rbac.authorization.k8s.io --- apiVersion: rbac.authorization.k8s.io/v1beta1 kind: ClusterRole metadata: labels: kubernetes.io/bootstrapping: rbac-defaults name: system:coredns rules: - apiGroups: - "" resources: - endpoints - services - pods - namespaces verbs: - get - list - watch