# Global read-only Role

**URL:** <https://forums.suse.com/t/global-read-only-role/41165>\
**Category:** General\
**Created:** [July 21, 2023, 6:31am UTC](https://forums.suse.com/t/global-read-only-role/41165 "2023-07-21T06:31:49Z")\
**Posts on this page:** 1\
**Page:** 1

<div class="post-metadata">

**Author:** ![Andreas\_Kappel](https://sea2.discourse-cdn.com/flex022/user_avatar/forums.suse.com/andreas_kappel/32/10372_2.png) [@Andreas\_Kappel](https://forums.suse.com/u/Andreas_Kappel)\
**Post date:** [July 21, 2023, 6:31am UTC](https://forums.suse.com/t/global-read-only-role/41165/1 "2023-07-21T06:31:50Z")

</div>

Hi,

I am looking for a way, to allow a group read-only permissions on all Clusters for all resources without having to add them to all clusters individually. I managed to create a global role where all clusters are visible, but no resource inside the cluster can be retrieved

I am using terraform to provision the role:

```auto
resource "rancher2_global_role" "cluster-readonly" {
  name = "Cluster Reader"
  rules {
    api_groups = ["*"]
    resources = ["*"]
    verbs = ["get","list","watch"]
  }
  rules {
    verbs = ["get","list","watch"]
    non_resource_urls = ["*"]
  }
}

```
