How can I define that only configmap and secret are forbidden to be obtained?

Cluster information:


- apiGroups:
  - '*'
  - '*'
  - get
  - list

I expect to use

- "!secrets"
- "!configmaps"

, but it doesn’t seem to take effect

Kubernetes version: 1.16
