# Member Cluster, namespace-scoped resources apiVersion: rbac.authorization.k8s.io/v1 kind: Role metadata: creationTimestamp: null labels: multi-cluster: "true" name: mongodb-kubernetes-appdb namespace: member-namespace rules: - apiGroups: - "" resources: - secrets verbs: - get - apiGroups: - "" resources: - pods verbs: - patch - delete - get --- apiVersion: rbac.authorization.k8s.io/v1 kind: Role metadata: creationTimestamp: null labels: multi-cluster: "true" name: mongodb-kubernetes-operator-multi-role namespace: member-namespace rules: - apiGroups: - "" resources: - secrets - configmaps - services verbs: - get - list - create - update - delete - watch - deletecollection - apiGroups: - apps resources: - statefulsets verbs: - get - list - create - update - delete - watch - deletecollection - apiGroups: - "" resources: - persistentvolumeclaims verbs: - get - list - create - update - watch - patch - apiGroups: - "" resources: - pods verbs: - get - list - watch - delete - deletecollection --- # Member Cluster, namespace-scoped resources apiVersion: rbac.authorization.k8s.io/v1 kind: RoleBinding metadata: creationTimestamp: null labels: multi-cluster: "true" name: mongodb-kubernetes-appdb namespace: member-namespace roleRef: apiGroup: "" kind: Role name: mongodb-kubernetes-appdb subjects: - kind: ServiceAccount name: mongodb-kubernetes-appdb --- apiVersion: rbac.authorization.k8s.io/v1 kind: RoleBinding metadata: creationTimestamp: null labels: multi-cluster: "true" name: mongodb-kubernetes-operator-multi-role-binding namespace: member-namespace roleRef: apiGroup: rbac.authorization.k8s.io kind: Role name: mongodb-kubernetes-operator-multi-role subjects: - kind: ServiceAccount name: mongodb-kubernetes-operator-multicluster namespace: central-namespace --- # Member Cluster, namespace-scoped resources apiVersion: v1 kind: ServiceAccount metadata: creationTimestamp: null labels: multi-cluster: "true" name: mongodb-kubernetes-appdb namespace: member-namespace --- apiVersion: v1 kind: ServiceAccount metadata: creationTimestamp: null labels: multi-cluster: "true" name: mongodb-kubernetes-database-pods namespace: member-namespace --- apiVersion: v1 kind: ServiceAccount metadata: creationTimestamp: null labels: multi-cluster: "true" name: mongodb-kubernetes-ops-manager namespace: member-namespace ---