- ensure the new service accounts can read cephrbd/cephfs - ensure correct namespace is allowed
- add policies to sign/issue certificates - manage auth roles for ceph-csi, certmanager, externaldns, huntarr