Chuyển đến nội dung chính

LESSON 8: NAMESPACES

Organize and separate resources with Namespaces in Kubernetes. Resource quotas, LimitRanges, Network Policies per namespace. Best practices for multi-tenancy and team isolation.

🔒 DevSecOps — Lesson 8 LESSON 8: NAMESPACES

KUBERNETES: FROM BASIC TO ADVANCED

Module 2: Basic Kubernetes Objects

xdev.asia

🎯 Lesson Objective

Understand Namespaces as a resource partitioning mechanism in a Kubernetes cluster. How to set Resource Quotas and LimitRanges to control resources per namespace. Best practices for multi-tenancy.

1. What is Namespace?

Namespace provides name scope (scope) for Kubernetes resources. Two Deployments named nginx can exist in two different Namespaces without conflict.

Namespace allowed:

  • Isolation: separate environments (dev, staging, production) or teams (team-a, team-b)
  • Resource quotas: resource limits per namespace
  • RBAC scoping: permissions per namespace
  • Network policies: control traffic between namespaces

2. Default Namespaces

  • default: default namespace when not specified
  • kube-system: components of the Kubernetes control plane (CoreDNS, kube-proxy, metrics-server)
  • kube-public: readable by all users, even unauthenticated. Contains cluster info
  • kube-node-lease: Node heartbeat leases — improve performance of node failure detection
kubectl get namespaces
# hoặc
kubectl get ns

3. Create and Manage Namespaces

# Tạo namespace
kubectl create namespace production
kubectl create namespace staging
kubectl create namespace team-a

Tạo bằng YAML

kubectl apply -f - <<EOF apiVersion: v1 kind: Namespace metadata: name: production labels: environment: production team: platform EOF

Xóa namespace (xóa cả tất cả resources bên trong!)

kubectl delete namespace staging

4. Working with Namespaces

# Chỉ định namespace với -n flag
kubectl get pods -n production
kubectl get all -n kube-system

Xem resources ở tất cả namespaces

kubectl get pods --all-namespaces kubectl get pods -A

Đặt default namespace cho kubectl context

kubectl config set-context --current --namespace=production

Sau đó không cần -n production nữa

Dùng kubens (cài krew + kubens plugin)

kubens production

5. Resource Quotas

ResourceQuota limits the total resources allowed in a namespace.

apiVersion: v1
kind: ResourceQuota
metadata:
  name: team-a-quota
  namespace: team-a
spec:
  hard:
    # Compute resources
    requests.cpu: "4"          # tổng CPU requests không vượt 4 cores
    requests.memory: 8Gi       # tổng memory requests không vượt 8Gi
    limits.cpu: "8"
    limits.memory: 16Gi
    # Object count
    pods: "20"                 # tối đa 20 pods
    services: "10"
    persistentvolumeclaims: "5"
    # Storage
    requests.storage: 100Gi
# Xem quota usage
kubectl describe resourcequota team-a-quota -n team-a

Output:

Name: team-a-quota

Namespace: team-a

Resource Used Hard

-------- ---- ----

limits.cpu 2 8

limits.memory 4Gi 16Gi

pods 8 20

6. LimitRanges

LimitRange sets default requests/limits and min/max per container in namespace. If the container does not declare resources, LimitRange automatically applies default.

apiVersion: v1
kind: LimitRange
metadata:
  name: default-limits
  namespace: team-a
spec:
  limits:
  - type: Container
    default:              # default limits nếu không khai báo
      cpu: "500m"
      memory: "256Mi"
    defaultRequest:       # default requests nếu không khai báo
      cpu: "100m"
      memory: "128Mi"
    min:                  # container phải request ít nhất
      cpu: "50m"
      memory: "64Mi"
    max:                  # container không được vượt
      cpu: "2"
      memory: "2Gi"
  - type: PersistentVolumeClaim
    max:
      storage: 10Gi

7. RBAC per Namespace

# Role chỉ có quyền trong namespace "team-a"
apiVersion: rbac.authorization.k8s.io/v1
kind: Role
metadata:
  name: developer
  namespace: team-a
rules:
- apiGroups: ["apps"]
  resources: ["deployments", "replicasets"]
  verbs: ["get", "list", "create", "update", "patch"]
- apiGroups: [""]
  resources: ["pods", "services", "configmaps"]
  verbs: ["get", "list", "watch"]
---
apiVersion: rbac.authorization.k8s.io/v1
kind: RoleBinding
metadata:
  name: developer-binding
  namespace: team-a
subjects:
- kind: User
  name: john
roleRef:
  kind: Role
  name: developer
  apiGroup: rbac.authorization.k8s.io

8. Cross-namespace Communication

# Service trong namespace khác
curl http://backend-service.production.svc.cluster.local

Với NetworkPolicy, bạn có thể chặn/cho phép cross-namespace traffic

9. Namespace Scope vs Cluster Scope

Not all resources have namespace:

  • Namespaced: Pods, Deployments, Services, ConfigMaps, Secrets, PVCs, Roles, RoleBindings
  • Cluster-scoped: Nodes, PersistentVolumes, ClusterRoles, ClusterRoleBindings, Namespaces, StorageClasses
# Xem loại resources có namespace hay không
kubectl api-resources --namespaced=true
kubectl api-resources --namespaced=false

10. Best Practices Multi-tenancy

  • A namespace per team and environment: team-a-prod, team-a-staging__HTMLTAG_156___, team-b-prod
  • Always set ResourceQuota: prevents one team from taking up all cluster resources
  • Use LimitRange: ensure containers always have resource limits
  • ConsistencyLabels: team, environment, app
  • Hierarchical Namespaces Controller (HNC): organize namespaces in a tree, inherit policies from parent
# Cài HNC
kubectl apply -f https://github.com/kubernetes-sigs/hierarchical-namespaces/releases/download/v1.1.0/default.yaml

Tạo namespace hierarchy

kubectl hns create team-a-prod -n team-a

Policies trong "team-a" tự động propagate xuống "team-a-prod"

Summary

  • Namespace = name scope and isolation for resources
  • 4 default namespaces: default, kube-system, kube-public, kube-node-lease
  • ResourceQuota: limit total resources per namespace__HTMLTAG_191___
  • LimitRange: default and min/max per container__HTMLTAG_193___
  • Best practice: namespace per team per environment + ResourceQuota + LimitRange