apiVersion: v1 kind: ServiceAccount metadata: name: kubent --- apiVersion: rbac.authorization.k8s.io/v1 kind: ClusterRole metadata: name: kubent-reader rules: - apiGroups: ["*"] resources: ["*"] verbs: ["get", "list"] --- apiVersion: rbac.authorization.k8s.io/v1 kind: ClusterRoleBinding metadata: name: kubent-read-everything subjects: - kind: ServiceAccount name: kubent namespace: default roleRef: kind: ClusterRole name: kubent-reader apiGroup: rbac.authorization.k8s.io