apiGroups
can be left blank[!Important]
Role
andRoleBinding
are namespaced.
metadata
kubectl auth can-i create deployments
kubectl auth can-i create pods --as dev-user --namespace test
resourceName
under rules
in Role
object to restrict access only to those specifief resources:
kubectl api-resource --namespaced=true