--- kind: ClusterRole apiVersion: rbac.authorization.k8s.io/v1 metadata: name: cert-manager-certificates rules: - apiGroups: ["cert-manager.io"] resources: [ "certificates", "certificates/status", "certificaterequests", "certificaterequests/status", ] verbs: ["update", "patch"] - apiGroups: ["cert-manager.io"] resources: ["certificates", "certificaterequests", "clusterissuers", "issuers"] verbs: ["get", "list", "watch"] - apiGroups: ["cert-manager.io"] resources: ["certificates/finalizers", "certificaterequests/finalizers"] verbs: ["update"] - apiGroups: ["acme.cert-manager.io"] resources: ["orders"] verbs: ["create", "delete", "get", "list", "watch"] - apiGroups: [""] resources: ["secrets"] verbs: ["get", "list", "watch", "create", "update", "delete", "patch"] - apiGroups: [""] resources: ["events"] verbs: ["create", "patch"] --- kind: ClusterRoleBinding apiVersion: rbac.authorization.k8s.io/v1 metadata: name: cert-manager-certificates roleRef: kind: ClusterRole apiGroup: rbac.authorization.k8s.io name: cert-manager-certificates subjects: - kind: ServiceAccount namespace: cert-manager name: cert-manager