--- apiVersion: rbac.authorization.k8s.io/v1 kind: ClusterRole metadata: labels: prometheus: federated-prometheus name: federated-prometheus-role rules: - apiGroups: - "" resources: - namespaces - pods - services - endpoints verbs: - list - get - watch --- apiVersion: rbac.authorization.k8s.io/v1 kind: ClusterRoleBinding metadata: name: federated-prometheus-role roleRef: apiGroup: rbac.authorization.k8s.io kind: ClusterRole name: federated-prometheus-role subjects: - kind: ServiceAccount name: prometheus-k8s namespace: thanos