- add kubernetes auth role for media-apps - add policies to read radarr/sonarr secrets
- ensure the new service accounts can read cephrbd/cephfs - ensure correct namespace is allowed
- add policies to sign/issue certificates - manage auth roles for ceph-csi, certmanager, externaldns, huntarr