kind: ClusterRoleBinding apiVersion: rbac.authorization.k8s.io/v1 metadata: name: front-proxy-client subjects: - kind: User name: front-proxy-client apiGroup: rbac.authorization.k8s.io roleRef: apiGroup: rbac.authorization.k8s.io kind: ClusterRole name: front-proxy-client --- apiVersion: rbac.authorization.k8s.io/v1 kind: ClusterRole metadata: name: front-proxy-client rules: - apiGroups: - "webhook.cert-manager.io" resources: - mutations - validations verbs: [ "*" ] - apiGroups: - metrics.k8s.io resources: - pods - nodes verbs: - get - list - watch