将创建Pod读取角色及绑定的Kubernetes YAML转换为kubectl命令
Hey there! Let's get this Role and RoleBinding set up for you using kubectl—no need to write YAML manually if you don't want to. Here are the exact commands you need:
Step 1: Create the pod-reader Role
This command creates the Role in the mynamespace namespace with the permissions you specified (get, watch, list on Pods):
kubectl create role pod-reader --namespace=mynamespace --verb=get,watch,list --resource=pods
Step 2: Bind the Default ServiceAccount to the Role
Next, we'll create a RoleBinding that links the default ServiceAccount in mynamespace to the pod-reader Role:
kubectl create rolebinding pod-reader-default-sa --namespace=mynamespace --role=pod-reader --serviceaccount=mynamespace:default
Combine into a Single Command
If you want to run both commands in one go, just chain them with &&:
kubectl create role pod-reader --namespace=mynamespace --verb=get,watch,list --resource=pods && kubectl create rolebinding pod-reader-default-sa --namespace=mynamespace --role=pod-reader --serviceaccount=mynamespace:default
Verify the Setup
To make sure everything was created correctly, run this command to check the Role and RoleBinding in your namespace:
kubectl get roles,rolebindings -n mynamespace
You should see pod-reader in the Roles list and pod-reader-default-sa in the RoleBindings list, confirming your setup is working as expected.
内容的提问来源于stack exchange,提问作者uberrebu

