apiVersion: rbac.authorization.k8s.io/v1 kind: ClusterRoleBinding metadata: name: endpoints-reader subjects: - kind: ServiceAccount name: endpoints-reader namespace: kevin # the namespace that the ServiceAccount resides in roleRef: kind: ClusterRole name: endpoints-reader apiGroup: rbac.authorization.k8s.io