apiVersion: rbac.authorization.k8s.io/v1 kind: ClusterRole metadata: name: cluster-role rules: - apiGroups: - kubeflow.org resources: - poddefaults verbs: - get - watch - list - update - create - patch - delete --- apiVersion: rbac.authorization.k8s.io/v1 kind: ClusterRole metadata: name: kubeflow-poddefaults-admin labels: rbac.authorization.kubeflow.org/aggregate-to-kubeflow-admin: "true" aggregationRule: clusterRoleSelectors: - matchLabels: rbac.authorization.kubeflow.org/aggregate-to-kubeflow-poddefaults-admin: "true" rules: [] --- apiVersion: rbac.authorization.k8s.io/v1 kind: ClusterRole metadata: name: kubeflow-poddefaults-edit labels: rbac.authorization.kubeflow.org/aggregate-to-kubeflow-edit: "true" aggregationRule: clusterRoleSelectors: - matchLabels: rbac.authorization.kubeflow.org/aggregate-to-kubeflow-poddefaults-edit: "true" rules: [] --- apiVersion: rbac.authorization.k8s.io/v1 kind: ClusterRole metadata: name: kubeflow-poddefaults-view labels: rbac.authorization.kubeflow.org/aggregate-to-kubeflow-poddefaults-admin: "true" rbac.authorization.kubeflow.org/aggregate-to-kubeflow-poddefaults-edit: "true" rbac.authorization.kubeflow.org/aggregate-to-kubeflow-view: "true" rules: - apiGroups: - kubeflow.org resources: - poddefaults verbs: - get - list - watch