A namespace is a scope for names, quotas and access, not a security boundary by itself.
Teams, environments and apps share one cluster by living in separate namespaces. Your kubeconfig decides which cluster and namespace each command targets.
shop
checkout, catalog, payments
quota: 20 CPU, 50 pods
RBAC: team-shop
monitoring
prometheus, grafana
quota: 8 CPU
RBAC: platform
kube-system
CoreDNS, kube-proxy, CNI
managed by the platform
do not edit casually
Scopes names
Two Pods may both be called web in different namespaces.
Scopes policy
ResourceQuota, LimitRange and RBAC Roles are per namespace.
Not isolation
By default Pods in any namespace can still reach each other. Add NetworkPolicy.
kubeconfig contexts
$ kubectl config get-contexts CURRENT NAME CLUSTER NAMESPACE * gke-eu-prod gke_shop_euw1 shop eks-eu-prod eks-shop-euw1 shop rancher-wh-1 k3s-warehouse1 default $ kubectl config use-context eks-eu-prod $ kubectl get pods -n monitoring $ kubectl get pods -A # every namespace $ kubectl config set-context --current \ --namespace=shop
Always know your current context before running a write command: the same kubectl line is harmless on staging and an incident on production.