--- apiVersion: rbac.authorization.k8s.io/v1 kind: Role metadata: labels: app.kubernetes.io/component: cleanup-controller app.kubernetes.io/instance: kyverno app.kubernetes.io/part-of: kyverno app.kubernetes.io/version: 3.4.1 name: kyverno:cleanup-controller namespace: kyverno rules: - apiGroups: - "" resources: - secrets verbs: - create - apiGroups: - "" resourceNames: - kyverno-cleanup-controller.kyverno.svc.kyverno-tls-ca - kyverno-cleanup-controller.kyverno.svc.kyverno-tls-pair resources: - secrets verbs: - delete - get - list - update - watch - apiGroups: - "" resourceNames: - kyverno - kyverno-metrics resources: - configmaps verbs: - get - list - watch - apiGroups: - coordination.k8s.io resources: - leases verbs: - create - apiGroups: - coordination.k8s.io resourceNames: - kyverno-cleanup-controller resources: - leases verbs: - delete - get - patch - update - apiGroups: - apps resources: - deployments verbs: - get - list - watch