apiVersion: rbac.authorization.k8s.io/v1 kind: ClusterRole metadata: name: edit-namespaces rules: - apiGroups: [""] resources: ["namespaces"] verbs: ["create", "get", "list", "watch", "update", "patch", "delete"] --- apiVersion: rbac.authorization.k8s.io/v1 kind: ClusterRoleBinding metadata: name: edit-stages-clusterrolebinding subjects: - kind: ServiceAccount name: stage-editor namespace: ontime-operator roleRef: kind: ClusterRole name: ontime-operator-stage-editor-role apiGroup: rbac.authorization.k8s.io --- apiVersion: rbac.authorization.k8s.io/v1 kind: ClusterRoleBinding metadata: name: edit-namespaces-clusterrolebinding subjects: - kind: ServiceAccount name: stage-editor namespace: ontime-operator roleRef: kind: ClusterRole name: edit-namespaces apiGroup: rbac.authorization.k8s.io