if you are here in in 2025 the answer above still works but no need for adding the "serviceAccount:" test before the pricipals as shown in the image here .