--- apiVersion: rbac.authorization.k8s.io/v1 kind: ClusterRole metadata: name: my-psp rules: - apiGroups: ['policy'] resources: ['podsecuritypolicies'] verbs: ['use'] resourceNames: - my-psp --- apiVersion: rbac.authorization.k8s.io/v1 kind: ClusterRoleBinding metadata: name: psp-baseline-namespaces roleRef: kind: ClusterRole name: my-psp apiGroup: rbac.authorization.k8s.io subjects: - kind: Group name: system:serviceaccounts:default apiGroup: rbac.authorization.k8s.io