# restrictedPSP grants access to use # the restricted PSP. apiVersion: rbac.authorization.k8s.io/v1beta1 kind: ClusterRole metadata: name: restricted-psp-user rules: - apiGroups: - extensions resources: - podsecuritypolicies resourceNames: - restricted verbs: - use --- # privilegedPSP grants access to use the privileged # PSP. apiVersion: rbac.authorization.k8s.io/v1beta1 kind: ClusterRole metadata: name: privileged-psp-user rules: - apiGroups: - extensions resources: - podsecuritypolicies resourceNames: - privileged verbs: - use