Currently, we have enforcedNamespaceLabel field at VMAgent, VMAlert and VMAlertmanager. It allows to enforce object namespace for CRD resources and to build isolated environments for operator users.
It'd be great to have a guide, how to achieve it with operator and how isolation of resources could be used to provide Managed monitoring service. This guide show target Kubernetes administrators which build internal monitoring platform on top of it.