apiVersion: rbac.authorization.k8s.io/v1 kind: ClusterRole metadata: labels: app.kubernetes.io/component: storage app.kubernetes.io/managed-by: cdi-operator cdi.kubevirt.io: "" name: cdi rules: - apiGroups: - "" resources: - events verbs: - create - patch - apiGroups: - "" resources: - persistentvolumes - persistentvolumeclaims verbs: - get - list - watch - create - update - delete - deletecollection - patch - apiGroups: - "" resources: - persistentvolumeclaims/finalizers - pods/finalizers verbs: - update - apiGroups: - "" resources: - pods - services verbs: - get - list - watch - create - delete - apiGroups: - "" resources: - configmaps verbs: - get - create - apiGroups: - storage.k8s.io resources: - storageclasses - csidrivers verbs: - get - list - watch - apiGroups: - config.openshift.io resources: - proxies verbs: - get - list - watch - apiGroups: - cdi.kubevirt.io resources: - '*' verbs: - '*' - apiGroups: - snapshot.storage.k8s.io resources: - '*' verbs: - '*' - apiGroups: - apiextensions.k8s.io resources: - customresourcedefinitions verbs: - get - list - watch - apiGroups: - scheduling.k8s.io resources: - priorityclasses verbs: - get - list - watch - apiGroups: - image.openshift.io resources: - imagestreams verbs: - get - list - watch - apiGroups: - "" resources: - secrets verbs: - create - apiGroups: - batch resources: - cronjobs verbs: - list - watch - apiGroups: - batch resources: - jobs verbs: - list - watch - apiGroups: - kubevirt.io resources: - virtualmachines/finalizers verbs: - update