--- apiVersion: rbac.authorization.k8s.io/v1beta1 kind: ClusterRole metadata: labels: rbac.authorization.k8s.io/aggregate-to-admin: "true" name: system:service-catalog:aggregate-to-admin rules: - apiGroups: - "servicecatalog.k8s.io" attributeRestrictions: null resources: - serviceinstances - servicebindings verbs: - create - update - delete - get - list - watch - patch - apiGroups: - "settings.k8s.io" attributeRestrictions: null resources: - podpresets verbs: - create - update - delete - get - list - watch --- apiVersion: rbac.authorization.k8s.io/v1beta1 kind: ClusterRole metadata: labels: rbac.authorization.k8s.io/aggregate-to-edit: "true" name: system:service-catalog:aggregate-to-edit rules: - apiGroups: - "servicecatalog.k8s.io" attributeRestrictions: null resources: - serviceinstances - servicebindings verbs: - create - update - delete - get - list - watch - patch - apiGroups: - "settings.k8s.io" attributeRestrictions: null resources: - podpresets verbs: - create - update - delete - get - list - watch --- apiVersion: rbac.authorization.k8s.io/v1beta1 kind: ClusterRole metadata: labels: rbac.authorization.k8s.io/aggregate-to-view: "true" name: system:service-catalog:aggregate-to-view rules: - apiGroups: - "servicecatalog.k8s.io" attributeRestrictions: null resources: - serviceinstances - servicebindings verbs: - get - list - watch