Create a service account name seminar-sa on the namespace seminar
Create a new role named k8s-seminar in the namespace seminar which only allows create and update operations only on resources of type pods and deployments
Create a new rolebinding name k8s-seminar-bind binding to the newly created role to the service account created previously named seminar-sa.
kubectl create ns seminar
kubectl -n seminar create sa seminar-sa
kubectl -n seminar create role k8s-seminar --verb=create,update --resource=pods,deployments
kubectl -n seminar create rolebinding k8s-seminar-bind --role=k8s-seminar --serviceaccount=seminar:seminar-sa