--- apiVersion: rbac.authorization.k8s.io/v1 kind: ClusterRole metadata: name: allow-creation rules: - apiGroups: - "" - "apps" - "deploy" - "networking.istio.io" resources: - pods - serviceaccounts - namespaces - services - deployments - deployments.apps - destinationrules - gateways - virtualservices verbs: - list - watch - get - create - update - patch - delete