blob: bf28a4785b2ad64db6119b3e6cddc4e8fa352a90 [file] [log] [blame]
Giorgi Lekveishvili725bb392023-05-05 18:24:27 +04001apiVersion: rbac.authorization.k8s.io/v1
2kind: ClusterRole
3metadata:
4 name: longhorn-role
5 labels: {{- include "longhorn.labels" . | nindent 4 }}
6rules:
7- apiGroups:
8 - apiextensions.k8s.io
9 resources:
10 - customresourcedefinitions
11 verbs:
12 - "*"
13- apiGroups: [""]
14 resources: ["pods", "events", "persistentvolumes", "persistentvolumeclaims","persistentvolumeclaims/status", "nodes", "proxy/nodes", "pods/log", "secrets", "services", "endpoints", "configmaps", "serviceaccounts"]
15 verbs: ["*"]
16- apiGroups: [""]
17 resources: ["namespaces"]
18 verbs: ["get", "list"]
19- apiGroups: ["apps"]
20 resources: ["daemonsets", "statefulsets", "deployments"]
21 verbs: ["*"]
22- apiGroups: ["batch"]
23 resources: ["jobs", "cronjobs"]
24 verbs: ["*"]
25- apiGroups: ["policy"]
26 resources: ["poddisruptionbudgets", "podsecuritypolicies"]
27 verbs: ["*"]
28- apiGroups: ["scheduling.k8s.io"]
29 resources: ["priorityclasses"]
30 verbs: ["watch", "list"]
31- apiGroups: ["storage.k8s.io"]
32 resources: ["storageclasses", "volumeattachments", "volumeattachments/status", "csinodes", "csidrivers"]
33 verbs: ["*"]
34- apiGroups: ["snapshot.storage.k8s.io"]
35 resources: ["volumesnapshotclasses", "volumesnapshots", "volumesnapshotcontents", "volumesnapshotcontents/status"]
36 verbs: ["*"]
37- apiGroups: ["longhorn.io"]
38 resources: ["volumes", "volumes/status", "engines", "engines/status", "replicas", "replicas/status", "settings",
39 "engineimages", "engineimages/status", "nodes", "nodes/status", "instancemanagers", "instancemanagers/status",
40 "sharemanagers", "sharemanagers/status", "backingimages", "backingimages/status",
41 "backingimagemanagers", "backingimagemanagers/status", "backingimagedatasources", "backingimagedatasources/status",
42 "backuptargets", "backuptargets/status", "backupvolumes", "backupvolumes/status", "backups", "backups/status",
43 "recurringjobs", "recurringjobs/status", "orphans", "orphans/status", "snapshots", "snapshots/status",
44 "supportbundles", "supportbundles/status", "systembackups", "systembackups/status", "systemrestores", "systemrestores/status"]
45 verbs: ["*"]
46- apiGroups: ["coordination.k8s.io"]
47 resources: ["leases"]
48 verbs: ["*"]
49- apiGroups: ["metrics.k8s.io"]
50 resources: ["pods", "nodes"]
51 verbs: ["get", "list"]
52- apiGroups: ["apiregistration.k8s.io"]
53 resources: ["apiservices"]
54 verbs: ["list", "watch"]
55- apiGroups: ["admissionregistration.k8s.io"]
56 resources: ["mutatingwebhookconfigurations", "validatingwebhookconfigurations"]
57 verbs: ["get", "list", "create", "patch", "delete"]
58- apiGroups: ["rbac.authorization.k8s.io"]
59 resources: ["roles", "rolebindings", "clusterrolebindings", "clusterroles"]
60 verbs: ["*"]