I have an application that has two parts: one deployer and the application runtime environment. The deployer needs to have access to different namespaces to be able to launch, edit and delete the application deployments, svc, configmaps, etc.
I first launch the deployer via a helm chart and then the deployer exposes some APIs to manage the application (launch, edit, delete).
My question is how to write the ClusterRole for my deployer that can only have access to a set of pre-created namespaces without giving it full cluster access (deployer should not be able to create, edit or delete namespaces). OR I have to create one Role for each of those namespaces and add them to the Helm chart of the deployer before installing it?