kubectl get pods CN=hvapour/o=group1/o=group2 ,,,"Group1,Group2" --token-auth-file= X-Remote-User: jack X-Remote-Group: Dev1 [...] users: - name: testserviceaccount user: token: eyJh[...] [...] $ openssl req -new -keyout testuser.key -out testuser.csr -nodes -subj "/CN=testuser/O=app1" kubectl apply -f pod-reader.yml