apiVersion: v1 kind: ServiceAccount metadata: name: postgres-pod namespace: default --- apiVersion: rbac.authorization.k8s.io/v1 kind: ClusterRole metadata: name: postgres-pod rules: - apiGroups: - "" resources: - endpoints verbs: - create - delete - deletecollection - get - list - patch - update - watch - apiGroups: - "" resources: - pods verbs: - get - list - patch - update - watch - apiGroups: - "" resources: - services verbs: - create - apiGroups: - extensions resources: - podsecuritypolicies resourceNames: - privileged verbs: - use