# Bug in the kubernetes deploy operator helm yaml file?

**URL:** <https://discuss.ray.io/t/bug-in-the-kubernetes-deploy-operator-helm-yaml-file/3590>\
**Category:** Kubernetes\
**Created:** [September 22, 2021, 2:42am UTC](https://discuss.ray.io/t/bug-in-the-kubernetes-deploy-operator-helm-yaml-file/3590 "2021-09-22T02:42:06Z")\
**Posts on this page:** 2\
**Page:** 1

<div class="post-metadata">

**Author:** ![blublinsky](https://avatars.discourse-cdn.com/v4/letter/b/f05b48/32.png) [@blublinsky](https://discuss.ray.io/u/blublinsky)\
**Post date:** [September 22, 2021, 2:42am UTC](https://discuss.ray.io/t/bug-in-the-kubernetes-deploy-operator-helm-yaml-file/3590/1 "2021-09-22T02:42:06Z")

</div>

When using Helm deploy operator on k8, when looking at operator’s pod log I see:

```auto
Not enough permissions to watch for resources: changes (creation/deletion/updates) will not be noticed; the resources are only refreshed on operator restarts.
Not enough permissions to list namespaces. Falling back to a list of namespaces which are assumed to exist: {'ray'}
Not enough permissions to watch for namespaces: changes (deletion/creation) will not be noticed; the namespaces are only refreshed on operator restarts.

```

To fix this I add the following to the cluster role rules:

```auto
  - apiGroups: [""]
    resources: ["namespaces"]
    verbs: ["get", "list", "watch"]

```

This fixed namespace errors, but I still see:

```auto
Not enough permissions to watch for resources: changes (creation/deletion/updates) will not be noticed; the resources are only refreshed on operator restarts.

```

Any suggestions?

---

<div class="post-metadata">

**Author:** ![blublinsky](https://avatars.discourse-cdn.com/v4/letter/b/f05b48/32.png) [@blublinsky](https://discuss.ray.io/u/blublinsky)\
**Post date:** [September 22, 2021, 11:10pm UTC](https://discuss.ray.io/t/bug-in-the-kubernetes-deploy-operator-helm-yaml-file/3590/2 "2021-09-22T23:10:58Z")

</div>

I also validated that it creates cluster successfully in the same namespace that the operator is running in, but ignores CRs in other namespaces
