apiVersion: rbac.authorization.k8s.io/v1 kind: Role metadata: name: emr-containers rules: - apiGroups: - "" resources: - namespaces verbs: - get - apiGroups: - "" resources: - serviceaccounts - services - configmaps - events - pods - pods/log verbs: - get - list - watch - describe - create - edit - delete - deletecollection - annotate - patch - label - apiGroups: - "" resources: - secrets verbs: - create - patch - delete - watch - apiGroups: - apps resources: - statefulsets - deployments verbs: - get - list - watch - describe - create - edit - delete - annotate - patch - label - apiGroups: - batch resources: - jobs verbs: - get - list - watch - describe - create - edit - delete - annotate - patch - label - apiGroups: - extensions - networking.k8s.io resources: - ingresses verbs: - get - list - watch - describe - create - edit - delete - annotate - patch - label - apiGroups: - rbac.authorization.k8s.io resources: - roles - rolebindings verbs: - get - list - watch - describe - create - edit - delete - deletecollection - annotate - patch - label - apiGroups: - "" resources: - persistentvolumeclaims verbs: - create - list - delete