# Replacing cluster level objects (e.g. ClusterRole)

**URL:** <https://discuss.elastic.co/t/replacing-cluster-level-objects-e-g-clusterrole/283986>\
**Category:** Elastic Cloud on Kubernetes (ECK)\
**Created:** [September 12, 2021, 6:48pm UTC](https://discuss.elastic.co/t/replacing-cluster-level-objects-e-g-clusterrole/283986 "2021-09-12T18:48:17Z")\
**Posts on this page:** 3\
**Page:** 1

<div class="post-metadata">

**Author:** ![AndreyL](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/andreyl/32/19365_2.png) [@AndreyL](https://discuss.elastic.co/u/AndreyL)\
**Post date:** [September 12, 2021, 6:48pm UTC](https://discuss.elastic.co/t/replacing-cluster-level-objects-e-g-clusterrole/283986/1 "2021-09-12T18:48:17Z")

</div>

I want to deploy ECK to our internal Kubernetes cluster. The issue I ran into is that ECK uses cluster level objects like ClusterRole, and I am not able to deploy those - we use Nirmata for cluster management, and each app gets a namespace within which an app can be deployed, no cluster level access for deployments. Basically, I need to make sure anything that's deployed by crd.yaml and operator.yaml is namespaced to my app namespace, and no cluster level objects should be deployed.  
Any recommendations for an approach to take changing crd.yaml? I am concerned about it as it will break upgradeability of ECK if I need to upgrade it in the future with a newer version. Any ideas are highly appreciated!

---

<div class="post-metadata">

**Author:** ![dkow](https://sea2.discourse-cdn.com/elastic/user_avatar/discuss.elastic.co/dkow/32/47340_2.png) [@dkow](https://discuss.elastic.co/u/dkow)\
**Post date:** [September 13, 2021, 7:01am UTC](https://discuss.elastic.co/t/replacing-cluster-level-objects-e-g-clusterrole/283986/2 "2021-09-13T07:01:27Z")

</div>

Hey @AndreyL, thanks for your question.

As for the contents of `operator.yaml`, it is possible to use only namespaced resources. You can see [installation](https://www.elastic.co/guide/en/cloud-on-k8s/current/k8s-installing-eck.html) and [Helm](https://www.elastic.co/guide/en/cloud-on-k8s/current/k8s-install-helm.html#k8s-install-helm-restricted) docs for more details.

`crds.yaml` contents, on the other hand, are CRDs and as cluster-wide resources don't offer any namespace variant. Hope this helps.

Thanks,  
David

---

<div class="post-metadata">

**Author:** ![system](https://us1.discourse-cdn.com/elastic/original/3X/1/a/1ac57faf039f6b580b3f104ef42a2a89e41014de.png) [@system](https://discuss.elastic.co/u/system)\
**Post date:** [October 11, 2021, 7:01am UTC](https://discuss.elastic.co/t/replacing-cluster-level-objects-e-g-clusterrole/283986/3 "2021-10-11T07:01:45Z")

</div>

This topic was automatically closed 28 days after the last reply. New replies are no longer allowed.
