{{- if .Values.rbac.enabled }} --- apiVersion: rbac.authorization.k8s.io/v1 kind: ClusterRole metadata: creationTimestamp: null name: {{ template "logging-operator.fullname" . }} rules: - apiGroups: - "" resources: - configmaps - secrets verbs: - create - delete - get - list - patch - update - watch - apiGroups: - "" resources: - endpoints - namespaces - nodes verbs: - get - list - watch - apiGroups: - "" resources: - persistentvolumeclaims - pods - serviceaccounts - services verbs: - create - delete - get - list - patch - update - watch - apiGroups: - "" - events.k8s.io resources: - events verbs: - create - get - list - watch - apiGroups: - apps resources: - daemonsets - replicasets - statefulsets verbs: - create - delete - get - list - patch - update - watch - apiGroups: - apps - extensions resources: - deployments verbs: - create - delete - get - list - patch - update - watch - apiGroups: - extensions - networking.k8s.io resources: - ingresses verbs: - create - delete - get - list - patch - update - watch - apiGroups: - extensions - policy resources: - podsecuritypolicies verbs: - create - delete - get - list - patch - update - use - watch - apiGroups: - logging.banzaicloud.io resources: - clusterflows - clusteroutputs - flows - loggings - outputs verbs: - create - delete - get - list - patch - update - watch - apiGroups: - logging.banzaicloud.io resources: - clusterflows/status - clusteroutputs/status - flows/status - loggings/status - outputs/status verbs: - get - patch - update - apiGroups: - monitoring.coreos.com resources: - servicemonitors verbs: - create - delete - get - list - patch - update - watch - apiGroups: - rbac.authorization.k8s.io resources: - clusterrolebindings - clusterroles - rolebindings - roles verbs: - create - delete - get - list - patch - update - watch {{- end }}