apiVersion: rbac.authorization.k8s.io/v1 kind: ClusterRole metadata: name: k8s-registry-api-discovery rules: - apiGroups: - toolhive.stacklok.dev resources: - mcpservers - mcpremoteproxies - virtualmcpservers verbs: - get - list - watch - apiGroups: - "" resources: - services verbs: - get - list - watch - apiGroups: - gateway.networking.k8s.io resources: - httproutes - gateways verbs: - get - list - watch --- apiVersion: rbac.authorization.k8s.io/v1 kind: ClusterRoleBinding metadata: name: k8s-registry-api-discovery roleRef: apiGroup: rbac.authorization.k8s.io kind: ClusterRole name: k8s-registry-api-discovery subjects: - kind: ServiceAccount name: k8s-registry-registry-api namespace: toolhive-system --- apiVersion: rbac.authorization.k8s.io/v1 kind: Role metadata: name: k8s-registry-api-events namespace: toolhive-system rules: - apiGroups: - "" resources: - events verbs: - create - patch --- apiVersion: rbac.authorization.k8s.io/v1 kind: RoleBinding metadata: name: k8s-registry-api-events namespace: toolhive-system roleRef: apiGroup: rbac.authorization.k8s.io kind: Role name: k8s-registry-api-events subjects: - kind: ServiceAccount name: k8s-registry-registry-api namespace: toolhive-system