Delete the CRD that a security controller or operator reconciles.
Deleting a CRD garbage-collects every custom resource of that type, so the controller's policy objects go with it.
Whether the controller then fails open or fails closed is implementation-specific.
Losing its input can equally stop it admitting anything.
Treat this as loss of a control and of its configuration, not as a reliable route to a privileged workload.
