CONTAINERS / A CONCEPT NOTE
Namespaces & Multi-tenancy
many teams, one cluster
Overview · mechanism
pitfall · examples
01 / THE SHORT VERSION
The idea in a few sentences.
Kubernetes Namespaces partition a single physical cluster into multiple virtual clusters, allowing teams to share compute resources without interfering with each other's configuration.
02 / FOLLOW THE MECHANISM
How namespace isolation works
Request division
administrator creates two namespaces: team-a and team-b.
RBAC assign
assigns permissions restricting developers to their respective namespaces.
Quota limit
allocates CPU/Memory caps per namespace to prevent resource hogging.
DNS Routing
service names resolve locally (my-svc) or across namespaces (my-svc.team-a.svc.cluster.local).
04 / COMMAND NOTES
Read the command, then the result.
Inspect the flags and arguments before trying an example. Snippets can need local setup, replacement values, or resources in your own environment.
list all namespaces in the cluster
kubectl get nscreate a new namespace
kubectl create ns test-env05 / CHECK YOURSELF
Could you explain Namespaces & Multi-tenancy to a teammate?
Try it out loud in two sentences: what it is, and the one detail that changes the picture. If you stall, the gap is the part to reread.
Up next in Containers & KubernetesStatefulSets & Operatorsrunning databases in clusters