apiVersion: rbac.authorization.k8s.io/v1 kind: ClusterRole metadata: labels: app.kubernetes.io/component: storage app.kubernetes.io/managed-by: cdi-operator cdi.kubevirt.io: "" name: cdi-apiserver rules: - apiGroups: - authorization.k8s.io resources: - subjectaccessreviews verbs: - create - apiGroups: - "" resources: - configmaps verbs: - get - list - watch - apiGroups: - "" resources: - persistentvolumeclaims verbs: - get - apiGroups: - "" resources: - namespaces verbs: - get - apiGroups: - snapshot.storage.k8s.io resources: - volumesnapshots verbs: - get - apiGroups: - cdi.kubevirt.io resources: - datavolumes verbs: - list - get - apiGroups: - cdi.kubevirt.io resources: - datasources verbs: - list - get - apiGroups: - cdi.kubevirt.io resources: - cdis verbs: - get - apiGroups: - cdi.kubevirt.io resources: - cdis/finalizers verbs: - '*'