Subject matches the originator of a request, as identified by the request authentication system. There are three ways of matching an originator; by user, group, or service account.
Optional
group matches based on user group name.
group
kind indicates which one of the other fields is non-empty. Required
kind
serviceAccount matches ServiceAccounts.
serviceAccount
user matches based on username.
user
Subject matches the originator of a request, as identified by the request authentication system. There are three ways of matching an originator; by user, group, or service account.