Minimal SA for helm client to connect to tiller running inside k8s cluster. Actual permissions needed for deployments are assigned to tiller's own SA and not shown here.
More details for setting up Tiller with RBAC can be found in the helm docs
This works if helm is running inside a pod as well as from CLI. Useful for CI/CD tools like drone-helm
List pods:
kubectl --kubeconfig helm.kubecfg -n util get pod