- update bound service account names to be `rancher` - update namespace to cattle-system (do not run rancher in another namespace)
- add kubernetes role for rancher - add policy to enable access to bootstrap-password