🎯 Lesson Objective
Understand Namespaces as a resource partitioning mechanism in a Kubernetes cluster. How to set Resource Quotas and LimitRanges to control resources per namespace. Best practices for multi-tenancy.
1. What is Namespace?
Namespace provides name scope (scope) for Kubernetes resources. Two Deployments named nginx can exist in two different Namespaces without conflict.
Namespace allowed:
- Isolation: separate environments (dev, staging, production) or teams (team-a, team-b)
- Resource quotas: resource limits per namespace
- RBAC scoping: permissions per namespace
- Network policies: control traffic between namespaces
2. Default Namespaces
- default: default namespace when not specified
- kube-system: components of the Kubernetes control plane (CoreDNS, kube-proxy, metrics-server)
- kube-public: readable by all users, even unauthenticated. Contains cluster info
- kube-node-lease: Node heartbeat leases — improve performance of node failure detection
kubectl get namespaces
# hoặc
kubectl get ns
3. Create and Manage Namespaces
# Tạo namespace kubectl create namespace production kubectl create namespace staging kubectl create namespace team-aTạo bằng YAML
kubectl apply -f - <<EOF apiVersion: v1 kind: Namespace metadata: name: production labels: environment: production team: platform EOF
Xóa namespace (xóa cả tất cả resources bên trong!)
kubectl delete namespace staging
4. Working with Namespaces
# Chỉ định namespace với -n flag kubectl get pods -n production kubectl get all -n kube-systemXem resources ở tất cả namespaces
kubectl get pods --all-namespaces kubectl get pods -A
Đặt default namespace cho kubectl context
kubectl config set-context --current --namespace=production
Sau đó không cần -n production nữa
Dùng kubens (cài krew + kubens plugin)
kubens production
5. Resource Quotas
ResourceQuota limits the total resources allowed in a namespace.
apiVersion: v1
kind: ResourceQuota
metadata:
name: team-a-quota
namespace: team-a
spec:
hard:
# Compute resources
requests.cpu: "4" # tổng CPU requests không vượt 4 cores
requests.memory: 8Gi # tổng memory requests không vượt 8Gi
limits.cpu: "8"
limits.memory: 16Gi
# Object count
pods: "20" # tối đa 20 pods
services: "10"
persistentvolumeclaims: "5"
# Storage
requests.storage: 100Gi
# Xem quota usage kubectl describe resourcequota team-a-quota -n team-aOutput:
Name: team-a-quota
Namespace: team-a
Resource Used Hard
-------- ---- ----
limits.cpu 2 8
limits.memory 4Gi 16Gi
pods 8 20
6. LimitRanges
LimitRange sets default requests/limits and min/max per container in namespace. If the container does not declare resources, LimitRange automatically applies default.
apiVersion: v1
kind: LimitRange
metadata:
name: default-limits
namespace: team-a
spec:
limits:
- type: Container
default: # default limits nếu không khai báo
cpu: "500m"
memory: "256Mi"
defaultRequest: # default requests nếu không khai báo
cpu: "100m"
memory: "128Mi"
min: # container phải request ít nhất
cpu: "50m"
memory: "64Mi"
max: # container không được vượt
cpu: "2"
memory: "2Gi"
- type: PersistentVolumeClaim
max:
storage: 10Gi
7. RBAC per Namespace
# Role chỉ có quyền trong namespace "team-a"
apiVersion: rbac.authorization.k8s.io/v1
kind: Role
metadata:
name: developer
namespace: team-a
rules:
- apiGroups: ["apps"]
resources: ["deployments", "replicasets"]
verbs: ["get", "list", "create", "update", "patch"]
- apiGroups: [""]
resources: ["pods", "services", "configmaps"]
verbs: ["get", "list", "watch"]
---
apiVersion: rbac.authorization.k8s.io/v1
kind: RoleBinding
metadata:
name: developer-binding
namespace: team-a
subjects:
- kind: User
name: john
roleRef:
kind: Role
name: developer
apiGroup: rbac.authorization.k8s.io
8. Cross-namespace Communication
# Service trong namespace khác curl http://backend-service.production.svc.cluster.localVới NetworkPolicy, bạn có thể chặn/cho phép cross-namespace traffic
9. Namespace Scope vs Cluster Scope
Not all resources have namespace:
- Namespaced: Pods, Deployments, Services, ConfigMaps, Secrets, PVCs, Roles, RoleBindings
- Cluster-scoped: Nodes, PersistentVolumes, ClusterRoles, ClusterRoleBindings, Namespaces, StorageClasses
# Xem loại resources có namespace hay không
kubectl api-resources --namespaced=true
kubectl api-resources --namespaced=false
10. Best Practices Multi-tenancy
- A namespace per team and environment:
team-a-prod,team-a-staging__HTMLTAG_156___,team-b-prod - Always set ResourceQuota: prevents one team from taking up all cluster resources
- Use LimitRange: ensure containers always have resource limits
- ConsistencyLabels:
team,environment,app - Hierarchical Namespaces Controller (HNC): organize namespaces in a tree, inherit policies from parent
# Cài HNC
kubectl apply -f https://github.com/kubernetes-sigs/hierarchical-namespaces/releases/download/v1.1.0/default.yaml
Tạo namespace hierarchy
kubectl hns create team-a-prod -n team-a
Policies trong "team-a" tự động propagate xuống "team-a-prod"
Summary
- Namespace = name scope and isolation for resources
- 4 default namespaces: default, kube-system, kube-public, kube-node-lease
- ResourceQuota: limit total resources per namespace__HTMLTAG_191___
- LimitRange: default and min/max per container__HTMLTAG_193___
- Best practice: namespace per team per environment + ResourceQuota + LimitRange