apiVersion: rbac.authorization.k8s.io/v1beta1 kind: ClusterRole metadata: name: rules: - apiGroups: - etcd.database.coreos.com resources: - etcdclusters - etcdbackups - etcdrestores verbs: - "*" - apiGroups: - apiextensions.k8s.io resources: - customresourcedefinitions verbs: - "*" - apiGroups: - "" resources: - pods - services - endpoints - persistentvolumeclaims - events verbs: - "*" - apiGroups: - apps resources: - deployments verbs: - "*" # The following permissions can be removed if not using S3 backup and TLS - apiGroups: - "" resources: - secrets verbs: - get