CRD-based implementation can provide only namespace scope (with proper ACL). We need a way to define config at a broader scope (cluster and/or mesh)