--- apiVersion: rbac.authorization.k8s.io/v1 kind: ClusterRole metadata: labels: rbac.kyverno.io/aggregate-to-background-controller: "true" name: kyverno:airm-policy-roles rules: - apiGroups: - rbac.authorization.k8s.io resources: - clusterroles - rolebindings verbs: - get - list - watch - apiGroups: - rbac.authorization.k8s.io resources: - clusterroles verbs: - bind