Slide 17
Slide 17 text
17
ClusterRoles example - a clusterrole can read pods in all namespaces
kind: ClusterRole
apiVersion: rbac.authorization.k8s.io/v1
metadata:
# “namespace” is not required
name: global-pod-reader
rules:
- apiGroups: [""] # "" indicates the core API group
resources: ["pods"]
verbs: ["get", "watch", "list"]