apiVersion: rbac.authorization.k8s.io/v1 kind: ClusterRole metadata: name: operator-cr rules: - apiGroups: - "" resources: - pods verbs: - '*' - apiGroups: - "" resources: - services - configmaps - secrets verbs: - create - get - delete - update - apiGroups: - extensions - networking.k8s.io resources: - ingresses verbs: - create - get - delete - apiGroups: - "" resources: - nodes verbs: - get - apiGroups: - "" resources: - events verbs: - create - update - patch - apiGroups: - apiextensions.k8s.io resources: - customresourcedefinitions verbs: - create - get - update - delete - apiGroups: - admissionregistration.k8s.io resources: - mutatingwebhookconfigurations verbs: - create - get - update - delete - apiGroups: - sparkoperator.k8s.io resources: - sparkapplications - scheduledsparkapplications - sparkapplications/status - scheduledsparkapplications/status verbs: - '*'