A namespace scopes names: two teams can each own a Deployment called api. Most types are namespaced; a few describe the whole cluster, such as nodes, PersistentVolumes, StorageClasses and namespaces themselves:
kubectl get namespaces
echo "namespaced: $(kubectl api-resources --namespaced=true -o name | wc -l)," \
"cluster-scoped: $(kubectl api-resources --namespaced=false -o name | wc -l)"Output
NAME STATUS AGE booknest Active 13m default Active 13m jenkins Active 13m kube-node-lease Active 13m kube-public Active 13m kube-system Active 13m local-path-storage Active 13m namespaced: 42, cluster-scoped: 39
kube-system holds the control plane's add-ons, kube-node-lease one heartbeat per node, and default whatever arrives without a namespace. By itself a namespace isolates only names and DNS (api.booknest.svc); it becomes a boundary through what hangs on it: RBAC (RBAC and Service Accounts), Pod Security and NetworkPolicies (Pod Security and Policies), a ResourceQuota capping the namespace's total, and a LimitRange setting per-container defaults.