Wildcards in apiGroups, resources, and verbs grant unrestricted access to all Kubernetes API operations, which is functionally equivalent to the built-in cluster-admin ClusterRole.