There are no Deny rules in Kubernetes RBAC
ClusterRoles can be applied to one or more namespaces
RBAC permissions are additive
202404011006