kubernetes.io/cluster-service: "true"
addonmanager.kubernetes.io/mode: Reconcile
apiVersion: rbac.authorization.k8s.io/v1
kubernetes.io/bootstrapping: rbac-defaults
addonmanager.kubernetes.io/mode: Reconcile
# 3. cluster role binding
apiVersion: rbac.authorization.k8s.io/v1
rbac.authorization.kubernetes.io/autoupdate: "true"
kubernetes.io/bootstrapping: rbac-defaults
addonmanager.kubernetes.io/mode: EnsureExists
apiGroup: rbac.authorization.k8s.io
# 4. use created service account
apiVersion: extensions/v1beta1
kubernetes.io/cluster-service: "true"
addonmanager.kubernetes.io/mode: Reconcile
kubernetes.io/name: "CoreDNS"
serviceAccountName: coredns