Request access to clusters by updating a helm chart:
* For each cluster type (A, B, C) a helm chart exists which defines clusterrole's, role's and appropriate bindings to provide for cluster level R/O access, cluster level admin access and namespace specific R/O R/W access.
** Consider a way to template this as the manifest for roles will be
* A user can grant themselves access to a cluster by updating this chart, obtaining PR approval from their manager and then the chart being deployed to the appropriate cluster. No AD groups are used to grant access, only individual user accounts
** Dev Team members have access as cluster admins to all clusters
** Test Team members have R/O access to all clusters
** DevOps teams have R/O access to clusters for their role (A to A and B to B)
* The existing group based clusterrolebinding is removed from all clusters