Add RBAC role and rolebinding for cni-genie

Change-Id: I5b89e3d892c157621a4a0db766ddb7f75d8719be
Related-PROD: PROD-21554
diff --git a/metadata/service/control/roles/genie-pod-patch.yml b/metadata/service/control/roles/genie-pod-patch.yml
new file mode 100644
index 0000000..d3f2da3
--- /dev/null
+++ b/metadata/service/control/roles/genie-pod-patch.yml
@@ -0,0 +1,19 @@
+parameters:
+  kubernetes:
+    control:
+      role:
+        patch:
+          enabled: true
+          kind: ClusterRole
+          rules:
+            - apiGroups:
+                - ""
+              resources:
+                - "pods"
+              verbs:
+                - "patch"
+          binding:
+            genie-pod-patch:
+              subject:
+                system:nodes:
+                  kind: Group