--- apiVersion: rbac.authorization.k8s.io/v1 kind: ClusterRole metadata: name: {{ include "kiali-server.fullname" . }}-viewer labels: {{- include "kiali-server.labels" . | nindent 4 }} rules: - apiGroups: [""] resources: - configmaps - endpoints - pods/log verbs: - get - list - watch - apiGroups: [""] resources: - namespaces - pods - replicationcontrollers - services verbs: - get - list - watch - apiGroups: [""] resources: - pods/portforward verbs: - create - post - apiGroups: ["extensions", "apps"] resources: - daemonsets - deployments - replicasets - statefulsets verbs: - get - list - watch - apiGroups: ["batch"] resources: - cronjobs - jobs verbs: - get - list - watch - apiGroups: - networking.istio.io - security.istio.io resources: ["*"] verbs: - get - list - watch - apiGroups: ["apps.openshift.io"] resources: - deploymentconfigs verbs: - get - list - watch - apiGroups: ["project.openshift.io"] resources: - projects verbs: - get - apiGroups: ["route.openshift.io"] resources: - routes verbs: - get - apiGroups: ["iter8.tools"] resources: - experiments verbs: - get - list - watch - apiGroups: ["authentication.k8s.io"] resources: - tokenreviews verbs: - create ...