rbac.example.com/aggregate-to-monitoring
kubectl auth, kubectl auth can-i, kubectl auth reconcile
kubectl create [ role | clusterrole | clusterrolebinding
rolebinding | serviceaccount ], groups:
kube2iam
rbac.authorization.k8s.io
system:
Advertising: