apiVersion: rbac.authorization.k8s.io/v1 kind: RoleBinding metadata: name: read-pods namespace: default subjects: - kind: User name: testuser apiGroup: rbac.authorization.k8s.io - kind: ServiceAccount name: testserviceaccount roleRef: kind: Role name: pod-reader apiGroup: rbac.authorization.k8s.io