Helm RBAC setup for K8s v1.6+ (tested on minikube)
kubectl -n kube-system create sa tiller
kubectl create clusterrolebinding tiller --clusterrole cluster-admin --serviceaccount=kube-system:tiller
helm init --service-account tiller
tmc commented Nov 1, 2017

A discussion of the security implications here would be useful.

Tested on 1.8.3. Works too! Thanks man

@tmc I think with this, anyone who has enough access to talk to tiller (which requires you be able to use the k8s API to port forward or exec I think) has root on the cluster.

ghost commented Dec 6, 2017

Thanks. had been stuck for hours...

jengo commented Jan 18, 2018

Awesome thanks!

Thanks a lot, it saves me a lot of hours....

Thanks a lot.

