# leader election rules apiVersion: rbac.authorization.k8s.io/v1beta1 kind: Role metadata: name: cert-manager-cainjector:leaderelection namespace: kube-system labels: app: cainjector app.kubernetes.io/name: cainjector app.kubernetes.io/instance: cert-manager app.kubernetes.io/managed-by: Tiller helm.sh/chart: cert-manager-v0.12.0 rules: # Used for leader election by the controller # TODO: refine the permission to *just* the leader election configmap - apiGroups: [""] resources: ["configmaps"] verbs: ["get", "create", "update", "patch"]