apiVersion: rbac.authorization.k8s.io/v1 kind: Role metadata: name: external-secrets-kubernetes-global-secrets namespace: {{ .Release.Namespace }} rules: - apiGroups: - "" resources: - secrets verbs: - get - list - watch - apiGroups: - authorization.k8s.io resources: - selfsubjectrulesreviews verbs: - create