Start them using specific RBAC that prevents them from doing something wrong or start them in a dedicated cluster (setup will be harder)