I need to create a role that will be able to get the 24 hour certificate to be able to run `kubectl` calls against Karbon.
When I look at the role creation page, there are a lot of options there. I am a bit overwhelmed in trying to figure out what permissions I need to just grant this one function.
What permissions are needed for a user to be able to get the 24 hour certificate to be able to run `kubectl` commands?