--- # Source: rook-ceph/charts/rook-ceph/templates/role.yaml # Allow the operator to manage resources in its own namespace kind: Role apiVersion: rbac.authorization.k8s.io/v1 metadata: name: rook-ceph-system namespace: rook-ceph # namespace:operator labels: operator: rook storage-backend: ceph app.kubernetes.io/name: rook-ceph app.kubernetes.io/instance: rook-ceph app.kubernetes.io/version: v1.18.8 app.kubernetes.io/part-of: rook-ceph-operator app.kubernetes.io/managed-by: Helm app.kubernetes.io/created-by: helm helm.sh/chart: "rook-ceph-v1.18.8" rules: - apiGroups: - "" resources: - pods - configmaps - services verbs: - get - list - watch - patch - create - update - delete - apiGroups: - apps - extensions resources: - daemonsets - statefulsets - deployments verbs: - get - list - watch - create - update - delete - deletecollection - apiGroups: - batch resources: - cronjobs verbs: - delete - apiGroups: - cert-manager.io resources: - certificates - issuers verbs: - get - create - delete - apiGroups: - multicluster.x-k8s.io resources: - serviceexports verbs: - get - create