e2e face recognition
diff --git a/controller/controller.yaml b/controller/controller.yaml
index 0055636..6b3e143 100644
--- a/controller/controller.yaml
+++ b/controller/controller.yaml
@@ -1,4 +1,30 @@
 ---
+apiVersion: v1
+kind: ServiceAccount
+metadata:
+  name: pcloud-controller
+---
+apiVersion: rbac.authorization.k8s.io/v1
+kind: Role
+metadata:
+  name: modify-pods
+rules:
+  - apiGroups: [""]
+    resources: ["pods"]
+    verbs: ["create"]
+---
+apiVersion: rbac.authorization.k8s.io/v1
+kind: RoleBinding
+metadata:
+  name: create-pods-to-sa
+subjects:
+  - kind: ServiceAccount
+    name: pcloud-controller
+roleRef:
+  kind: Role
+  name: modify-pods
+  apiGroup: rbac.authorization.k8s.io
+---
 kind: Service 
 apiVersion: v1
 metadata:
@@ -26,8 +52,9 @@
       labels:
         app: pcloud-controller
     spec:
+      serviceAccountName: pcloud-controller
       containers:
-      - name: pfs-controller
+      - name: pcloud-controller
         image: pcloud-controller:latest
         imagePullPolicy: Never
         ports:
@@ -36,7 +63,7 @@
         - name: code
           mountPath: /src/go/src/github.com/giolekva/pcloud/controller
         command: ["/bin/sh", "-c"]
-        args: ["go run main.go --port=1234 --graphql_address=http://dgraph-public.default.svc:8080/graphql --dgraph_admin_address=http://dgraph-public.default.svc:8080/admin --logtostderr"]
+        args: ["go run main.go --port=1234 --graphql_address=http://dgraph-public.dgraph.svc:8080/graphql --dgraph_admin_address=http://dgraph-public.dgraph.svc:8080/admin --logtostderr"]
       volumes:
       - name: code
         hostPath: