apiVersion: rbac.authorization.k8s.io/v1 kind: Role metadata: name: default namespace: git rules: - apiGroups: - "" resources: - pods - pods/log - namespaces - serviceaccounts - persistentvolumeclaims - services - configmaps verbs: - watch - create - delete - get - list - apiGroups: - "apps" resources: - deployments - daemonsets verbs: - get - apiGroups: - "helm.cattle.io" resources: - helmcharts verbs: - get - apiGroups: - "apiextensions.k8s.io" resources: - customresourcedefinitions verbs: - get - apiGroups: - "rbac.authorization.k8s.io" resources: - clusterroles - rolebindings - clusterrolebindings verbs: - get - apiGroups: - "apiregistration.k8s.io" resources: - apiservices verbs: - get - apiGroups: - "metallb.io" resources: - ipaddresspools - l2advertisements verbs: - get - apiGroups: - "networking.k8s.io" resources: - ingresses verbs: - get