Why are you separating out the route domains? Are you looking to truly create separation between the three environments or are you content to let them run in the same context? If it is the former, than you need to go further than just Route Domains. With just route domains in place, it will be posssible on the F5 create configurations that can traverse the zones and potentially bypass external security.
If you are looking for full separation, then you will need to plan individual partitions for each area, with a route domain and vlans associated that have no parent route domain. That is the only true way to create full separation on a common instance.