apiVersion: rbac.authorization.k8s.io/v1 kind: ClusterRole metadata: name: cluster-role rules: - apiGroups: - "" resources: - namespaces - pods verbs: - get - list - apiGroups: - authorization.k8s.io resources: - subjectaccessreviews verbs: - create - apiGroups: - "" resources: - persistentvolumeclaims verbs: - create - delete - get - list - watch - update - patch - apiGroups: - storage.k8s.io resources: - storageclasses verbs: - get - list - watch - apiGroups: - "" resources: - events verbs: - list - apiGroups: - kubeflow.org resources: - notebooks verbs: - list - apiGroups: - kubeflow.org resources: - pvcviewers verbs: - get - list - create - delete --- apiVersion: rbac.authorization.k8s.io/v1 kind: ClusterRole metadata: name: kubeflow-volume-ui-admin labels: rbac.authorization.kubeflow.org/aggregate-to-kubeflow-admin: "true" rules: [] --- apiVersion: rbac.authorization.k8s.io/v1 kind: ClusterRole metadata: name: kubeflow-volume-ui-edit labels: rbac.authorization.kubeflow.org/aggregate-to-kubeflow-edit: "true" rules: - apiGroups: - "" resources: - persistentvolumeclaims verbs: - create - delete - get - list - watch - update - patch - apiGroups: - kubeflow.org resources: - pvcviewers verbs: - get - list - create - delete --- apiVersion: rbac.authorization.k8s.io/v1 kind: ClusterRole metadata: name: kubeflow-volume-ui-view labels: rbac.authorization.kubeflow.org/aggregate-to-kubeflow-view: "true" rules: - apiGroups: - "" resources: - persistentvolumeclaims verbs: - get - list - watch - apiGroups: - storage.k8s.io resources: - storageclasses verbs: - get - list - watch - apiGroups: - kubeflow.org resources: - pvcviewers verbs: - get - list