Import existing K8s into ranche

Hi, follow import k8s 1.22 into rancher 2.4.12 a have this error
level=fatal msg=“customresourcedefinitions.apiextensions.k8s.io is forbidden:
User “system:serviceaccount:cattle-system:cattle”
cannot list resource “customresourcedefinitions” in API group
apiextensions.k8s.io” at the cluster scope”

Im understand i must add user and role

But i cant understand what and where i must create , on rancher side or kuber)) sorry my english

@Anton conseguiu resolver? estou com um problema semelhante aqui e sem solução.