🎯 Mục tiêu bài học
Hiểu Namespaces là cơ chế phân vùng tài nguyên trong Kubernetes cluster. Cách đặt Resource Quotas và LimitRanges để kiểm soát tài nguyên per namespace. Best practices cho multi-tenancy.
1. Namespace là gì?
Namespace cung cấp phạm vi tên (scope) cho Kubernetes resources. Hai Deployments tên nginx có thể tồn tại trong hai Namespaces khác nhau mà không conflict.
Namespace cho phép:
- Isolation: phân tách môi trường (dev, staging, production) hoặc teams (team-a, team-b)
- Resource quotas: giới hạn tài nguyên per namespace
- RBAC scoping: phân quyền per namespace
- Network policies: kiểm soát traffic giữa namespaces
2. Default Namespaces
- default: namespace mặc định khi không chỉ định
- kube-system: components của Kubernetes control plane (CoreDNS, kube-proxy, metrics-server)
- kube-public: readable bởi tất cả users, kể cả unauthenticated. Chứa cluster info
- kube-node-lease: Node heartbeat leases — cải thiện performance của node failure detection
kubectl get namespaces
# hoặc
kubectl get ns
3. Tạo và Quản lý Namespaces
# Tạo namespace kubectl create namespace production kubectl create namespace staging kubectl create namespace team-aTạo bằng YAML
kubectl apply -f - <<EOF apiVersion: v1 kind: Namespace metadata: name: production labels: environment: production team: platform EOF
Xóa namespace (xóa cả tất cả resources bên trong!)
kubectl delete namespace staging
4. Làm việc với Namespaces
# Chỉ định namespace với -n flag kubectl get pods -n production kubectl get all -n kube-systemXem resources ở tất cả namespaces
kubectl get pods --all-namespaces kubectl get pods -A
Đặt default namespace cho kubectl context
kubectl config set-context --current --namespace=production
Sau đó không cần -n production nữa
Dùng kubens (cài krew + kubens plugin)
kubens production
5. Resource Quotas
ResourceQuota giới hạn tổng tài nguyên được phép dùng trong một namespace.
apiVersion: v1
kind: ResourceQuota
metadata:
name: team-a-quota
namespace: team-a
spec:
hard:
# Compute resources
requests.cpu: "4" # tổng CPU requests không vượt 4 cores
requests.memory: 8Gi # tổng memory requests không vượt 8Gi
limits.cpu: "8"
limits.memory: 16Gi
# Object count
pods: "20" # tối đa 20 pods
services: "10"
persistentvolumeclaims: "5"
# Storage
requests.storage: 100Gi
# Xem quota usage kubectl describe resourcequota team-a-quota -n team-aOutput:
Name: team-a-quota
Namespace: team-a
Resource Used Hard
-------- ---- ----
limits.cpu 2 8
limits.memory 4Gi 16Gi
pods 8 20
6. LimitRanges
LimitRange đặt default requests/limits và min/max per container trong namespace. Nếu container không khai báo resources, LimitRange tự động áp dụng default.
apiVersion: v1
kind: LimitRange
metadata:
name: default-limits
namespace: team-a
spec:
limits:
- type: Container
default: # default limits nếu không khai báo
cpu: "500m"
memory: "256Mi"
defaultRequest: # default requests nếu không khai báo
cpu: "100m"
memory: "128Mi"
min: # container phải request ít nhất
cpu: "50m"
memory: "64Mi"
max: # container không được vượt
cpu: "2"
memory: "2Gi"
- type: PersistentVolumeClaim
max:
storage: 10Gi
7. RBAC per Namespace
# Role chỉ có quyền trong namespace "team-a"
apiVersion: rbac.authorization.k8s.io/v1
kind: Role
metadata:
name: developer
namespace: team-a
rules:
- apiGroups: ["apps"]
resources: ["deployments", "replicasets"]
verbs: ["get", "list", "create", "update", "patch"]
- apiGroups: [""]
resources: ["pods", "services", "configmaps"]
verbs: ["get", "list", "watch"]
---
apiVersion: rbac.authorization.k8s.io/v1
kind: RoleBinding
metadata:
name: developer-binding
namespace: team-a
subjects:
- kind: User
name: john
roleRef:
kind: Role
name: developer
apiGroup: rbac.authorization.k8s.io
8. Cross-namespace Communication
# Service trong namespace khác curl http://backend-service.production.svc.cluster.localVới NetworkPolicy, bạn có thể chặn/cho phép cross-namespace traffic
9. Namespace Scope vs Cluster Scope
Không phải mọi resource đều có namespace:
- Namespaced: Pods, Deployments, Services, ConfigMaps, Secrets, PVCs, Roles, RoleBindings
- Cluster-scoped: Nodes, PersistentVolumes, ClusterRoles, ClusterRoleBindings, Namespaces, StorageClasses
# Xem loại resources có namespace hay không
kubectl api-resources --namespaced=true
kubectl api-resources --namespaced=false
10. Best Practices Multi-tenancy
- Một namespace per team và environment:
team-a-prod,team-a-staging,team-b-prod - Luôn đặt ResourceQuota: ngăn một team chiếm hết tài nguyên cluster
- Dùng LimitRange: đảm bảo containers luôn có resource limits
- Labels nhất quán:
team,environment,app - Hierarchical Namespaces Controller (HNC): tổ chức namespaces theo cây, inherit policies từ parent
# Cài HNC kubectl apply -f https://github.com/kubernetes-sigs/hierarchical-namespaces/releases/download/v1.1.0/default.yamlTạo namespace hierarchy
kubectl hns create team-a-prod -n team-a
Policies trong "team-a" tự động propagate xuống "team-a-prod"
Tóm tắt
- Namespace = phạm vi tên và isolation cho resources
- 4 default namespaces: default, kube-system, kube-public, kube-node-lease
- ResourceQuota: giới hạn tổng tài nguyên per namespace
- LimitRange: default và min/max per container
- Best practice: namespace per team per environment + ResourceQuota + LimitRange