creates a ClusterRoleBinding: 1: | apiVersion: rbac.authorization.k8s.io/v1 kind: ClusterRoleBinding metadata: name: RELEASE-NAME roleRef: apiGroup: rbac.authorization.k8s.io kind: ClusterRole name: RELEASE-NAME subjects: - kind: ServiceAccount name: RELEASE-NAME namespace: NAMESPACE sets ClusterRoleBinding labels when specified: 1: | apiVersion: rbac.authorization.k8s.io/v1 kind: ClusterRoleBinding metadata: labels: app.kubernetes.io/name: teleport-kube-agent resource: clusterrolebinding name: RELEASE-NAME roleRef: apiGroup: rbac.authorization.k8s.io kind: ClusterRole name: RELEASE-NAME subjects: - kind: ServiceAccount name: RELEASE-NAME namespace: NAMESPACE