# rbac for project owner, not allow for delete roles: - domain_admin scope: domain policy: *: *: *: allow