# services/cassandra/hermes-agent-rbac.yaml apiVersion: rbac.authorization.k8s.io/v1 kind: Role metadata: name: hermes-agent-readonly namespace: cassandra rules: - apiGroups: [""] resources: - configmaps - endpoints - events - persistentvolumeclaims - pods - pods/log - replicationcontrollers - services verbs: ["get", "list", "watch"] - apiGroups: ["events.k8s.io"] resources: ["events"] verbs: ["get", "list", "watch"] - apiGroups: ["apps"] resources: - daemonsets - deployments - replicasets - statefulsets verbs: ["get", "list", "watch"] - apiGroups: ["batch"] resources: - cronjobs - jobs verbs: ["get", "list", "watch"] - apiGroups: ["networking.k8s.io"] resources: - ingresses - networkpolicies verbs: ["get", "list", "watch"] --- apiVersion: rbac.authorization.k8s.io/v1 kind: RoleBinding metadata: name: hermes-agent-readonly namespace: cassandra subjects: - kind: ServiceAccount name: hermes-agent namespace: hermes roleRef: apiGroup: rbac.authorization.k8s.io kind: Role name: hermes-agent-readonly