apiVersion: rbac.authorization.k8s.io/v1 kind: ClusterRole metadata: name: rancher-operator rules: - apiGroups: - "" resources: - secrets - configmaps - namespaces verbs: - '*' - apiGroups: - apps resources: - daemonsets - deployments verbs: - list - get - watch - apiGroups: - "rancher.cattle.io" - "management.cattle.io" - "fleet.cattle.io" resources: - '*' verbs: - '*' --- apiVersion: rbac.authorization.k8s.io/v1 kind: ClusterRoleBinding metadata: name: rancher-operator roleRef: apiGroup: rbac.authorization.k8s.io kind: ClusterRole name: rancher-operator subjects: - kind: ServiceAccount name: rancher-operator namespace: {{.Release.Namespace}}