CONTAINERS / A CONCEPT NOTE

Namespaces & Multi-tenancy

many teams, one cluster

~70 sec read

Overview · mechanism
pitfall · examples

01 / THE SHORT VERSION

The idea in a few sentences.

Kubernetes Namespaces partition a single physical cluster into multiple virtual clusters, allowing teams to share compute resources without interfering with each other's configuration.

02 / FOLLOW THE MECHANISM

How namespace isolation works

  1. Request division

    administrator creates two namespaces: team-a and team-b.

  2. RBAC assign

    assigns permissions restricting developers to their respective namespaces.

  3. Quota limit

    allocates CPU/Memory caps per namespace to prevent resource hogging.

  4. DNS Routing

    service names resolve locally (my-svc) or across namespaces (my-svc.team-a.svc.cluster.local).

04 / COMMAND NOTES

Read the command, then the result.

Inspect the flags and arguments before trying an example. Snippets can need local setup, replacement values, or resources in your own environment.

EXAMPLE 01 · REFERENCE

list all namespaces in the cluster

kubectl get ns

EXAMPLE 02 · REFERENCE

create a new namespace

kubectl create ns test-env

Explore command anatomy in the CLI lab