Chuyển đến nội dung chính

BÀI 8: NAMESPACES

Tổ chức và phân tách resources với Namespaces trong Kubernetes. Resource quotas, LimitRanges, Network Policies per namespace. Best practices cho multi-tenancy và team isolation.

🔒 DevSecOps — Bài 8 BÀI 8: NAMESPACES

KUBERNETES: TỪ CƠ BẢN ĐẾN NÂNG CAO

Module 2: Kubernetes Objects Cơ bản

xdev.asia

🎯 Mục tiêu bài học

Hiểu Namespaces là cơ chế phân vùng tài nguyên trong Kubernetes cluster. Cách đặt Resource Quotas và LimitRanges để kiểm soát tài nguyên per namespace. Best practices cho multi-tenancy.

1. Namespace là gì?

Namespace cung cấp phạm vi tên (scope) cho Kubernetes resources. Hai Deployments tên nginx có thể tồn tại trong hai Namespaces khác nhau mà không conflict.

Namespace cho phép:

  • Isolation: phân tách môi trường (dev, staging, production) hoặc teams (team-a, team-b)
  • Resource quotas: giới hạn tài nguyên per namespace
  • RBAC scoping: phân quyền per namespace
  • Network policies: kiểm soát traffic giữa namespaces

2. Default Namespaces

  • default: namespace mặc định khi không chỉ định
  • kube-system: components của Kubernetes control plane (CoreDNS, kube-proxy, metrics-server)
  • kube-public: readable bởi tất cả users, kể cả unauthenticated. Chứa cluster info
  • kube-node-lease: Node heartbeat leases — cải thiện performance của node failure detection
kubectl get namespaces
# hoặc
kubectl get ns

3. Tạo và Quản lý Namespaces

# Tạo namespace
kubectl create namespace production
kubectl create namespace staging
kubectl create namespace team-a

Tạo bằng YAML

kubectl apply -f - <<EOF apiVersion: v1 kind: Namespace metadata: name: production labels: environment: production team: platform EOF

Xóa namespace (xóa cả tất cả resources bên trong!)

kubectl delete namespace staging

4. Làm việc với Namespaces

# Chỉ định namespace với -n flag
kubectl get pods -n production
kubectl get all -n kube-system

Xem resources ở tất cả namespaces

kubectl get pods --all-namespaces kubectl get pods -A

Đặt default namespace cho kubectl context

kubectl config set-context --current --namespace=production

Sau đó không cần -n production nữa

Dùng kubens (cài krew + kubens plugin)

kubens production

5. Resource Quotas

ResourceQuota giới hạn tổng tài nguyên được phép dùng trong một namespace.

apiVersion: v1
kind: ResourceQuota
metadata:
  name: team-a-quota
  namespace: team-a
spec:
  hard:
    # Compute resources
    requests.cpu: "4"          # tổng CPU requests không vượt 4 cores
    requests.memory: 8Gi       # tổng memory requests không vượt 8Gi
    limits.cpu: "8"
    limits.memory: 16Gi
    # Object count
    pods: "20"                 # tối đa 20 pods
    services: "10"
    persistentvolumeclaims: "5"
    # Storage
    requests.storage: 100Gi
# Xem quota usage
kubectl describe resourcequota team-a-quota -n team-a

Output:

Name: team-a-quota

Namespace: team-a

Resource Used Hard

-------- ---- ----

limits.cpu 2 8

limits.memory 4Gi 16Gi

pods 8 20

6. LimitRanges

LimitRange đặt default requests/limits và min/max per container trong namespace. Nếu container không khai báo resources, LimitRange tự động áp dụng default.

apiVersion: v1
kind: LimitRange
metadata:
  name: default-limits
  namespace: team-a
spec:
  limits:
  - type: Container
    default:              # default limits nếu không khai báo
      cpu: "500m"
      memory: "256Mi"
    defaultRequest:       # default requests nếu không khai báo
      cpu: "100m"
      memory: "128Mi"
    min:                  # container phải request ít nhất
      cpu: "50m"
      memory: "64Mi"
    max:                  # container không được vượt
      cpu: "2"
      memory: "2Gi"
  - type: PersistentVolumeClaim
    max:
      storage: 10Gi

7. RBAC per Namespace

# Role chỉ có quyền trong namespace "team-a"
apiVersion: rbac.authorization.k8s.io/v1
kind: Role
metadata:
  name: developer
  namespace: team-a
rules:
- apiGroups: ["apps"]
  resources: ["deployments", "replicasets"]
  verbs: ["get", "list", "create", "update", "patch"]
- apiGroups: [""]
  resources: ["pods", "services", "configmaps"]
  verbs: ["get", "list", "watch"]
---
apiVersion: rbac.authorization.k8s.io/v1
kind: RoleBinding
metadata:
  name: developer-binding
  namespace: team-a
subjects:
- kind: User
  name: john
roleRef:
  kind: Role
  name: developer
  apiGroup: rbac.authorization.k8s.io

8. Cross-namespace Communication

# Service trong namespace khác
curl http://backend-service.production.svc.cluster.local

Với NetworkPolicy, bạn có thể chặn/cho phép cross-namespace traffic

9. Namespace Scope vs Cluster Scope

Không phải mọi resource đều có namespace:

  • Namespaced: Pods, Deployments, Services, ConfigMaps, Secrets, PVCs, Roles, RoleBindings
  • Cluster-scoped: Nodes, PersistentVolumes, ClusterRoles, ClusterRoleBindings, Namespaces, StorageClasses
# Xem loại resources có namespace hay không
kubectl api-resources --namespaced=true
kubectl api-resources --namespaced=false

10. Best Practices Multi-tenancy

  • Một namespace per team và environment: team-a-prod, team-a-staging, team-b-prod
  • Luôn đặt ResourceQuota: ngăn một team chiếm hết tài nguyên cluster
  • Dùng LimitRange: đảm bảo containers luôn có resource limits
  • Labels nhất quán: team, environment, app
  • Hierarchical Namespaces Controller (HNC): tổ chức namespaces theo cây, inherit policies từ parent
# Cài HNC
kubectl apply -f https://github.com/kubernetes-sigs/hierarchical-namespaces/releases/download/v1.1.0/default.yaml

Tạo namespace hierarchy

kubectl hns create team-a-prod -n team-a

Policies trong "team-a" tự động propagate xuống "team-a-prod"

Tóm tắt

  • Namespace = phạm vi tên và isolation cho resources
  • 4 default namespaces: default, kube-system, kube-public, kube-node-lease
  • ResourceQuota: giới hạn tổng tài nguyên per namespace
  • LimitRange: default và min/max per container
  • Best practice: namespace per team per environment + ResourceQuota + LimitRange