Name: system:controller:certificate-controller Labels: kubernetes.io/bootstrapping=rbac-defaults Annotations: rbac.authorization.kubernetes.io/autoupdate: true PolicyRule: Resources Non-Resource URLs Resource Names Verbs --------- ----------------- -------------- ----- signers.certificates.k8s.io [] [kubernetes.io/kube-apiserver-client-kubelet] [approve sign] events [] [] [create patch update] events.events.k8s.io [] [] [create patch update] subjectaccessreviews.authorization.k8s.io [] [] [create] certificatesigningrequests.certificates.k8s.io [] [] [delete get list watch] signers.certificates.k8s.io [] [kubernetes.io/kube-apiserver-client] [sign] signers.certificates.k8s.io [] [kubernetes.io/kubelet-serving] [sign] signers.certificates.k8s.io [] [kubernetes.io/legacy-unknown] [sign] certificatesigningrequests.certificates.k8s.io/approval [] [] [update] certificatesigningrequests.certificates.k8s.io/status [] [] [update]