https://kubernetes.io/docs/reference/access-authn-authz/rbac/#user-facing-roles
cluster-admin
admin
edit
view
kubectl describe clusterrole view
aws-auth
system:masters
kubectl get clusterroles
kubectl auth, kubectl auth can-i, kubectl auth reconcile
kubectl create [ role | clusterrole | clusterrolebinding
rolebinding | serviceaccount ], groups:
kube2iam
rbac.authorization.k8s.io
system:
Advertising: