k8s-rbac
# 创建用户,在命名空间下
kubectl create serviceaccount huhu -n mytest
# 创建用户的权限,资源是pods|权限是list\get\watch
kubectl create role huhu-pod --verb=list,get,watch --resource=pods
# 将用户权限和用户 绑定
kubectl create rolebinding huhu-pod-role --user=huhu --role= huhu-pod
# 创建 集群权限
kubectl create clusterrole deployment-clusterrole --verb=create,list,get,watch --resource=Deployment,StatefulSet,DaemonSet