The problem is that when a deployment script creates objects, it does not delete existing ones and relies on them.
This leads to a situation when the right rolebinding and clusterrolebinding isn't created and the oeprator service account lacks privileges to get router secret and/or create oAuthclient.