{{- if .Values.rbac.create -}} apiVersion: rbac.authorization.k8s.io/v1 kind: ClusterRole metadata: name: {{ include "velero.fullname" . }}-server labels: {{- include "velero.labels" . | nindent 4 }} rules: - apiGroups: - "*" resources: - "*" verbs: - get - list - watch - describe - apiGroups: - "" resources: - pods - pods/exec verbs: - create - get - list - delete - update - apiGroups: - "" resources: - namespaces verbs: - get - list - watch - apiGroups: - apps resources: - deployments - statefulsets verbs: - get - list - watch - create - update - delete - apiGroups: - "" resources: - persistentvolumes - persistentvolumeclaims - secrets - configmaps verbs: - get - list - watch - create - update - delete - apiGroups: - snapshot.storage.k8s.io resources: - volumesnapshots - volumesnapshotcontents - volumesnapshotclasses verbs: - get - list - watch - create - update - delete - apiGroups: - velero.io resources: - "*" verbs: - "*" - apiGroups: - batch resources: - jobs verbs: - get - list - watch - create - update - delete {{- end }}