--- apiVersion: policy/v1beta1 kind: PodSecurityPolicy metadata: name: rbd-csi-vault-token-review-psp spec: fsGroup: rule: RunAsAny runAsUser: rule: RunAsAny seLinux: rule: RunAsAny supplementalGroups: rule: RunAsAny volumes: - 'configMap' - 'secret' --- kind: Role apiVersion: rbac.authorization.k8s.io/v1 metadata: # replace with non-default namespace name namespace: default name: rbd-csi-vault-token-review-psp rules: - apiGroups: ['policy'] resources: ['podsecuritypolicies'] verbs: ['use'] resourceNames: ['rbd-csi-vault-token-review-psp'] --- kind: RoleBinding apiVersion: rbac.authorization.k8s.io/v1 metadata: name: rbd-csi-vault-token-review-psp # replace with non-default namespace name namespace: default subjects: - kind: ServiceAccount name: rbd-csi-vault-token-review # replace with non-default namespace name namespace: default roleRef: kind: Role name: rbd-csi-vault-token-review-psp apiGroup: rbac.authorization.k8s.io