admin service account
kubectl -n kube-system create serviceaccount kube-admin
kubectl create clusterrolebinding add-on-cluster-admin --clusterrole=cluster-admin --serviceaccount=kube-system:kube-admin
kubectl -n kube-system get serviceaccount/kube-admin -o jsonpath='{.secrets[0].name}'
kubectl -n kube-system get secret kube-admin-token-v8qk7 -o jsonpath='{.data.token}'
TOKEN=`<base64-decoded-output>`
kubectl config set-credentials <service-account-name> --token=$TOKEN
kubectl config set-context --current --user=<service-account-name>