This is the step with the RBAC narrowing: the cert-manager-edit aggregate
ClusterRole no longer grants create on challenges or create, patch and update on
orders. Those resources belong to cert-manager's own ACME workflow. Nothing here
is bound to that ClusterRole — zero bindings across all namespaces — so no
tooling loses a permission it was using.
Previous step verified: three deployments on v1.19.6, fifteen certificates
Ready.