Core objects
Namespaces
13 / 82

A namespace is a scope for names, quotas and access, not a security boundary by itself.

Teams, environments and apps share one cluster by living in separate namespaces. Your kubeconfig decides which cluster and namespace each command targets.

ns icon
shop
checkout, catalog, payments

quota: 20 CPU, 50 pods
RBAC: team-shop

ns icon
monitoring
prometheus, grafana

quota: 8 CPU
RBAC: platform

ns icon
kube-system
CoreDNS, kube-proxy, CNI

managed by the platform
do not edit casually

Scopes names

Two Pods may both be called web in different namespaces.

Scopes policy

ResourceQuota, LimitRange and RBAC Roles are per namespace.

Not isolation

By default Pods in any namespace can still reach each other. Add NetworkPolicy.

kubeconfig contexts
$ kubectl config get-contexts
CURRENT  NAME             CLUSTER          NAMESPACE
*        gke-eu-prod      gke_shop_euw1    shop
         eks-eu-prod      eks-shop-euw1    shop
         rancher-wh-1     k3s-warehouse1   default
$ kubectl config use-context eks-eu-prod
$ kubectl get pods -n monitoring
$ kubectl get pods -A      # every namespace
$ kubectl config set-context --current \
    --namespace=shop

Always know your current context before running a write command: the same kubectl line is harmless on staging and an incident on production.