### 1.创建sa - 不会自动创建secret ```bash kubectl create sa sa-demo ``` ### 2.创建secret ```yaml apiVersion: v1 kind: Secret metadata: name: secret-sa-demo namespace: default annotations: kubernetes.io/service-account.name: sa-demo type: kubernetes.io/service-account-token ```