Allow instance admins and/or group owners to prevent cleanup policies settings from being modified at the project level
Context
This is a followup from Investigate: Set default cleanup policies for y... (#292674) and can only be implemented after the latter.
Proposal
Once/if we enable configuring cleanup policies at the group level, we should consider adding the ability for instance admins and/or group owners to prevent cleanup policies settings from being modified/disabled at the project level.
This is based on customer feedback (container-registry#838 (comment 1182916470)).