apiVersion: rbac.authorization.k8s.io/v1 kind: ClusterRole metadata: name: kiosk-template-admin labels: rbac.kiosk.sh/aggregate-to-space-admin: "true" rules: - apiGroups: - config.kiosk.sh resources: - templateinstances verbs: - get - list - watch - create - delete - deletecollection - patch - update