apiVersion: rbac.authorization.k8s.io/v1 kind: ClusterRole metadata: name: stage-editor-role rules: - apiGroups: - ontime.getontime.no resources: - stages verbs: - create - delete - get - list - patch - update - watch - apiGroups: - ontime.getontime.no resources: - stages/status verbs: - get --- apiVersion: rbac.authorization.k8s.io/v1 kind: ClusterRoleBinding metadata: name: edit-stages-clusterrolebinding subjects: - kind: ServiceAccount name: stage-editor namespace: stage-maker roleRef: kind: ClusterRole name: stage-editor-role apiGroup: rbac.authorization.k8s.io