kind: ClusterRoleBinding apiVersion: rbac.authorization.k8s.io/v1 metadata: name: kubemq-operator-{{ .Release.Namespace }}-crb subjects: - kind: ServiceAccount name: kubemq-operator namespace: {{ .Release.Namespace }} roleRef: kind: ClusterRole name: kubemq-operator apiGroup: rbac.authorization.k8s.io --- apiVersion: rbac.authorization.k8s.io/v1 kind: Role metadata: name: kubemq-cluster-role namespace: {{ .Release.Namespace }} rules: - apiGroups: - security.openshift.io resources: - securitycontextconstraints verbs: - use - delete - get - list - patch - update - watch resourceNames: - privileged