apiVersion: rbac.authorization.k8s.io/v1 kind: ClusterRoleBinding metadata: name: kube-explorer-pod-reader labels: kubernetes.courselabs.co: rbac roleRef: apiGroup: rbac.authorization.k8s.io kind: ClusterRole name: pod-reader subjects: - kind: ServiceAccount name: kube-explorer namespace: default # can be any ns