Issue had been opened per: #656 (comment)
Currently the operator and control plane are using roles and rolebindings that are cluster scoped.
Some resources however, are specific ones (namespace/name). For example, coredns configmaps and deployments.
It would be good to identify these resources and use namespaced roles/rolebinding with resourceNames for them.