Humans authenticate to the API server with their own credentials; applications running in Pods use ServiceAccounts. A ServiceAccount is a namespaced object that gives a Pod an identity, which RBAC can then grant permissions to. Every namespace automatically has one called default, and a Pod that does not name a ServiceAccount runs as that one.
Keep reading for free
Create a free StudyToCert account to read the rest of this lesson: 6 more sections, 5 key terms, a real-world example, an exam tip and self-check questions. Every lesson, lab and practice test is free with an account.