--- kind: ClusterRole apiVersion: rbac.authorization.k8s.io/v1 metadata: name: rook-ceph-global labels: operator: rook storage-backend: ceph app.kubernetes.io/name: rook-ceph app.kubernetes.io/instance: rook-ceph app.kubernetes.io/version: v1.18.8 app.kubernetes.io/part-of: rook-ceph-operator app.kubernetes.io/managed-by: Helm app.kubernetes.io/created-by: helm helm.sh/chart: "rook-ceph-v1.18.8" rules: - apiGroups: - "" resources: - pods - nodes - nodes/proxy - secrets - configmaps verbs: - get - list - watch - apiGroups: - "" - "discovery.k8s.io" resources: - events - persistentvolumes - persistentvolumeclaims - endpoints - services - endpointslices - endpointslices/restricted verbs: - get - list - watch - patch - create - update - delete - apiGroups: - storage.k8s.io resources: - storageclasses verbs: - get - list - watch - apiGroups: - batch resources: - jobs - cronjobs verbs: - get - list - watch - create - update - delete - deletecollection - apiGroups: ["ceph.rook.io"] resources: - cephclients - cephclusters - cephblockpools - cephfilesystems - cephnfses - cephobjectstores - cephobjectstoreusers - cephobjectrealms - cephobjectzonegroups - cephobjectzones - cephbuckettopics - cephbucketnotifications - cephrbdmirrors - cephfilesystemmirrors - cephfilesystemsubvolumegroups - cephblockpoolradosnamespaces - cephcosidrivers verbs: - get - list - watch - update - apiGroups: ["ceph.rook.io"] resources: - cephclients/status - cephclusters/status - cephblockpools/status - cephfilesystems/status - cephnfses/status - cephobjectstores/status - cephobjectstoreusers/status - cephobjectrealms/status - cephobjectzonegroups/status - cephobjectzones/status - cephbuckettopics/status - cephbucketnotifications/status - cephrbdmirrors/status - cephfilesystemmirrors/status - cephfilesystemsubvolumegroups/status - cephblockpoolradosnamespaces/status verbs: ["update"] - apiGroups: ["ceph.rook.io"] resources: - cephclients/finalizers - cephclusters/finalizers - cephblockpools/finalizers - cephfilesystems/finalizers - cephnfses/finalizers - cephobjectstores/finalizers - cephobjectstoreusers/finalizers - cephobjectrealms/finalizers - cephobjectzonegroups/finalizers - cephobjectzones/finalizers - cephbuckettopics/finalizers - cephbucketnotifications/finalizers - cephrbdmirrors/finalizers - cephfilesystemmirrors/finalizers - cephfilesystemsubvolumegroups/finalizers - cephblockpoolradosnamespaces/finalizers verbs: ["update"] - apiGroups: - policy - apps - extensions resources: - poddisruptionbudgets - deployments - replicasets verbs: - get - list - watch - create - update - delete - deletecollection - apiGroups: - apps resources: - deployments/finalizers verbs: - update - apiGroups: - healthchecking.openshift.io resources: - machinedisruptionbudgets verbs: - get - list - watch - create - update - delete - apiGroups: - machine.openshift.io resources: - machines verbs: - get - list - watch - create - update - delete - apiGroups: - storage.k8s.io resources: - csidrivers verbs: - create - delete - get - update - apiGroups: - k8s.cni.cncf.io resources: - network-attachment-definitions verbs: - get