--- apiVersion: rbac.authorization.k8s.io/v1 kind: ClusterRole metadata: creationTimestamp: "2026-02-17T12:42:31Z" managedFields: - apiVersion: rbac.authorization.k8s.io/v1 fieldsType: FieldsV1 fieldsV1: f:rules: {} manager: cluster-storage-operator operation: Update time: "2026-02-17T12:42:31Z" name: aws-ebs-csi-driver-operator-clusterrole resourceVersion: "1669" uid: 4395cca0-1ef7-4e99-bccb-3319ff3f1df0 rules: - apiGroups: - security.openshift.io resourceNames: - privileged resources: - securitycontextconstraints verbs: - use - apiGroups: - operator.openshift.io resources: - clustercsidrivers verbs: - get - list - watch - update - patch - apiGroups: - operator.openshift.io resources: - clustercsidrivers/status verbs: - get - list - watch - update - patch - apiGroups: - "" resourceNames: - extension-apiserver-authentication - aws-ebs-csi-driver-operator-lock resources: - configmaps verbs: - get - list - watch - create - update - patch - delete - apiGroups: - rbac.authorization.k8s.io resources: - clusterroles - clusterrolebindings - roles - rolebindings verbs: - watch - list - get - create - delete - patch - update - apiGroups: - "" resources: - serviceaccounts verbs: - get - list - watch - create - update - patch - delete - apiGroups: - apiextensions.k8s.io resources: - customresourcedefinitions verbs: - get - list - create - watch - delete - apiGroups: - "" resources: - nodes verbs: - get - list - watch - create - update - patch - delete - apiGroups: - "" resources: - secrets verbs: - get - list - watch - apiGroups: - "" resources: - namespaces verbs: - get - list - watch - create - patch - delete - update - apiGroups: - "" resources: - persistentvolumes verbs: - create - delete - list - get - watch - update - patch - apiGroups: - "" resources: - persistentvolumeclaims verbs: - get - list - watch - update - apiGroups: - "" resources: - pods verbs: - get - list - watch - apiGroups: - "" resources: - persistentvolumeclaims/status verbs: - patch - update - apiGroups: - apps resources: - deployments - daemonsets - replicasets - statefulsets verbs: - get - list - watch - create - update - patch - delete - apiGroups: - storage.k8s.io resources: - volumeattachments verbs: - get - list - watch - update - delete - create - patch - apiGroups: - storage.k8s.io resources: - volumeattachments/status verbs: - patch - apiGroups: - snapshot.storage.k8s.io resources: - volumesnapshotcontents/status verbs: - update - patch - apiGroups: - storage.k8s.io resources: - storageclasses - csinodes verbs: - create - get - list - watch - update - delete - apiGroups: - storage.k8s.io resources: - volumeattributesclasses verbs: - get - list - watch - apiGroups: - '*' resources: - events verbs: - get - patch - create - list - watch - update - delete - apiGroups: - snapshot.storage.k8s.io resources: - volumesnapshotclasses verbs: - get - list - watch - create - update - delete - apiGroups: - snapshot.storage.k8s.io resources: - volumesnapshotcontents verbs: - create - get - list - watch - update - delete - patch - apiGroups: - snapshot.storage.k8s.io resources: - volumesnapshots verbs: - get - list - watch - update - patch - apiGroups: - snapshot.storage.k8s.io resources: - volumesnapshots/status verbs: - patch - apiGroups: - storage.k8s.io resources: - csidrivers verbs: - create - get - list - watch - update - delete - apiGroups: - config.openshift.io resources: - infrastructures - proxies - apiservers - featuregates - clusterversions verbs: - get - list - watch - apiGroups: - authentication.k8s.io resources: - tokenreviews verbs: - create