Scenario: you are a developer on-call, there is an issue with the cluster that you need to investigate and correct.
sudo for kubectl was the basic idea (Mattz):
- assume admin role
- ideally still have constraints as to which namespaces it can impact
(i.e. stay out of kube-system, monitoring, etc...)