Currently, Namespace (NS) can be created by any user (who signed the publisher agreement). This is too volatile.
Instead, the process should be reversed: creation of NS should be administrative task, happening only after the "claim", proving NS ownership that has been accepted and vetted, and user should end up with "claimed" NS and be owner of it.
In short, non-admin user (or a user without some dedicated role) should not be able to create NS on his own, this should be administrative task instead.
A feature flag (configuration) should be able to control this behaviour, as on some (ie in-house) instances, this may be not needed, but on some (ie publicly reachable) instances may be required.
Currently, Namespace (NS) can be created by any user (who signed the publisher agreement). This is too volatile.
Instead, the process should be reversed: creation of NS should be administrative task, happening only after the "claim", proving NS ownership that has been accepted and vetted, and user should end up with "claimed" NS and be owner of it.
In short, non-admin user (or a user without some dedicated role) should not be able to create NS on his own, this should be administrative task instead.
A feature flag (configuration) should be able to control this behaviour, as on some (ie in-house) instances, this may be not needed, but on some (ie publicly reachable) instances may be required.