Namespaces

Namespaces and Resource Isolation

A namespace scopes names: two teams can each own a Deployment called api. Most types are namespaced; a few describe the whole cluster, such as nodes, PersistentVolumes, StorageClasses and namespaces themselves:

Namespaces, and how many resource types live inside or outside themShell
kubectl get namespaces
echo "namespaced: $(kubectl api-resources --namespaced=true -o name | wc -l)," \
  "cluster-scoped: $(kubectl api-resources --namespaced=false -o name | wc -l)"
Output
NAME                 STATUS   AGE
booknest             Active   13m
default              Active   13m
jenkins              Active   13m
kube-node-lease      Active   13m
kube-public          Active   13m
kube-system          Active   13m
local-path-storage   Active   13m
namespaced: 42, cluster-scoped: 39

kube-system holds the control plane's add-ons, kube-node-lease one heartbeat per node, and default whatever arrives without a namespace. By itself a namespace isolates only names and DNS (api.booknest.svc); it becomes a boundary through what hangs on it: RBAC (RBAC and Service Accounts), Pod Security and NetworkPolicies (Pod Security and Policies), a ResourceQuota capping the namespace's total, and a LimitRange setting per-container defaults.