The operator kube context (Vault-minted cluster-operator creds) is a
read-only ClusterRole and is RBAC-forbidden from get/list/watch on
operator-owned CRDs such as valkeyclusters.valkey.io. Grant read on the
CRD API groups of the operators deployed via argocd-apps.