--- # Source: kubelet-serving-cert-approver/templates/cluster-role.yaml apiVersion: rbac.authorization.k8s.io/v1 kind: ClusterRole metadata: name: "certificates-kubelet-serving-cert-approver" namespace: kubelet-serving-cert-approver labels: app.kubernetes.io/name: "certificates-kubelet-serving-cert-approver" app.kubernetes.io/instance: kubelet-serving-cert-approver app.kubernetes.io/part-of: kubelet-serving-cert-approver rules: - apiGroups: - certificates.k8s.io resources: - certificatesigningrequests verbs: - get - list - watch - apiGroups: - certificates.k8s.io resources: - certificatesigningrequests/approval verbs: - update - apiGroups: - authorization.k8s.io resources: - subjectaccessreviews verbs: - create - apiGroups: - certificates.k8s.io resourceNames: - kubernetes.io/kubelet-serving resources: - signers verbs: - approve