Is there a way to create a K8s cluster role with full access (all resources, verbs and apigroups on any namespaces) but no commands execution on all namespaces for example: kubectl delete pods --all-namespaces or kubectl delete pv --all-namespaces?
(Running the same commands on a single namespace should be allowed, just not in bulk to all namespaces).
If this cannot be achieved with a cluster role, is there another way to achieve it?