Least-Privilege Kubernetes RBAC for a Deployer Service Account
Create a service account that can roll out Deployments in one namespace and nothing else, prove the boundary with impersonation and a real short-lived token, and audit the cluster for wildcard roles and anonymous access.