apiVersion: rbac.authorization.k8s.io/v1 kind: ClusterRole metadata: name: {{ template "netdata.fullname" . }} labels: app: {{ template "netdata.name" . }} chart: {{ template "netdata.chart" . }} release: {{ .Release.Name }} heritage: {{ .Release.Service }} rules: - apiGroups: [""] resources: - "pods" # used by sd, netdata (cgroup-name.sh, get-kubernetes-labels.sh) - "services" # used by sd - "configmaps" # used by sd - "secrets" # used by sd verbs: - "get" - "list" - "watch" - apiGroups: [""] resources: - "namespaces" # used by netdata (cgroup-name.sh, get-kubernetes-labels.sh) verbs: - "get"