--- apiVersion: rbac.authorization.k8s.io/v1 kind: ClusterRole metadata: labels: app.kubernetes.io/instance: external-secrets app.kubernetes.io/name: external-secrets app.kubernetes.io/version: v0.15.1 rbac.authorization.k8s.io/aggregate-to-admin: "true" rbac.authorization.k8s.io/aggregate-to-edit: "true" name: external-secrets-edit rules: - apiGroups: - external-secrets.io resources: - externalsecrets - secretstores - clustersecretstores - pushsecrets - clusterpushsecrets verbs: - create - delete - deletecollection - patch - update - apiGroups: - generators.external-secrets.io resources: - acraccesstokens - clustergenerators - ecrauthorizationtokens - fakes - gcraccesstokens - githubaccesstokens - quayaccesstokens - passwords - vaultdynamicsecrets - webhooks - grafanas - generatorstates verbs: - create - delete - deletecollection - patch - update