Giving Container Runner Access to Additional Namespaces
To allow the task-agent pods (the pods container-agent uses to spin up to run your jobs) you will need to create a RoleBinding for each namespace you wish to give access to the task-agent pod.
Additional Resources
This example could be specific to GKE but does have great resources for
rules.apiGroup