Gke Multitenancy

by google55b4e13eba6dNo licenseListed Oct 8, 2026Updated Oct 8, 2026

Plans and configures multi-tenancy on GKE. Covers namespace isolation, RBAC planning for teams, resource quotas, LimitRanges, network isolation, and cost allocation. Use when designing GKE multi-tenancy, configuring GKE namespaces, setting up resource quotas, or isolating GKE teams. Don't use for single-tenant cluster configuration or general deployment instructions (use gke-basics or gke-app-onboarding instead).

FeaturedInstructions onlyDevOps & Cloud
AI-generated overview

Plans and configures GKE multi-tenancy with namespaces, RBAC, quotas, and network isolation.

What it does
This reference skill guides the design and configuration of multi-tenancy on Google Kubernetes Engine. It compares isolation models (namespace-per-team, namespace-per-environment, node pool-per-team, cluster-per-team) and provides manifests and commands for namespaces, RBAC Roles and RoleBindings, ResourceQuotas, LimitRanges, NetworkPolicies, and cost-allocation labels. It also notes MCP tools for applying and inspecting Kubernetes resources.
When to use it
Use it when several teams or environments share one GKE cluster and you need namespace isolation, least-privilege access, resource limits, or per-team cost attribution. It is not intended for single-tenant cluster setup or general deployment instructions.
Requirements
Requires a GKE cluster plus kubectl and gcloud access, and optionally MCP tools for Kubernetes resources. It ships no scripts; it is instructions and manifests only.

GKE Multi-Tenancy

This reference covers enterprise multi-tenancy patterns on GKE, including namespace isolation, RBAC planning, resource quotas, and network segmentation.

MCP Tools: apply_k8s_manifest, get_k8s_resource, check_k8s_auth, describe_k8s_resource, delete_k8s_resource

When to Use

  • Multiple teams sharing a single GKE cluster
  • Isolating workloads by environment (dev/staging/prod) within one cluster
  • Implementing least-privilege access control
  • Cost allocation across teams or projects

Multi-Tenancy Models

ModelIsolationComplexityCost
Namespace-per-teamSoft (RBAC +LowLowest (shared
: : Network : : cluster) :
: : Policy) : : :
Namespace-per-environmentSoftLowLow
Node pool-per-teamMediumMediumMedium
: : (dedicated : : :
: : compute) : : :
Cluster-per-teamHard (fullHighHighest
: : isolation) : : :

Golden path recommendation: Start with namespace-per-team for cost efficiency. Escalate to stronger isolation only when compliance requires it.

Namespace Isolation Setup

1. Create Namespaces

bash
kubectl create namespace team-akubectl create namespace team-bkubectl label namespace team-a team=akubectl label namespace team-b team=b

2. RBAC Configuration

Principle: Grant minimal permissions per namespace. Never bind to system:authenticated.

yaml
# Namespace-scoped role for a teamapiVersion: rbac.authorization.k8s.io/v1kind: Rolemetadata:  name: team-a-developer  namespace: team-arules:- apiGroups: ["", "apps", "batch"]  resources: ["pods", "deployments", "services", "configmaps", "jobs"]  verbs: ["get", "list", "watch", "create", "update", "patch", "delete"]---apiVersion: rbac.authorization.k8s.io/v1kind: RoleBindingmetadata:  name: team-a-developers  namespace: team-asubjects:- kind: Group  name: "[email protected]"  # Google Group  apiGroup: rbac.authorization.k8s.ioroleRef:  kind: Role  name: team-a-developer  apiGroup: rbac.authorization.k8s.io

RBAC best practices: Use Google Groups for subject bindings. Prefer namespace-scoped Roles over ClusterRoles. See the gke-platform-security skill for full RBAC hardening guidance.

3. Resource Quotas

Prevent any single team from consuming all cluster resources:

yaml
apiVersion: v1kind: ResourceQuotametadata:  name: team-a-quota  namespace: team-aspec:  hard:    requests.cpu: "10"    requests.memory: "20Gi"    limits.cpu: "20"    limits.memory: "40Gi"    pods: "50"    services: "10"    persistentvolumeclaims: "10"

4. LimitRanges

Set default and maximum resource constraints per container:

yaml
apiVersion: v1kind: LimitRangemetadata:  name: team-a-limits  namespace: team-aspec:  limits:  - type: Container    default:      cpu: "500m"      memory: "512Mi"    defaultRequest:      cpu: "100m"      memory: "128Mi"    max:      cpu: "4"      memory: "8Gi"

[!IMPORTANT] Mandatory Defaults: When defining min or max limits in a LimitRange, you must also define corresponding default and defaultRequest values. If you set a min or max without defaults, any pod deployed without explicit resource requests/limits will be rejected by the admission controller.

5. Network Isolation

Apply default-deny per namespace (see the gke-workload-security skill), then allow intra-team traffic:

yaml
# Allow same-namespace pods to talk + DNSapiVersion: networking.k8s.io/v1kind: NetworkPolicymetadata:  name: allow-same-namespace  namespace: team-aspec:  podSelector: {}  ingress:  - from:    - podSelector: {}  egress:  - to:    - podSelector: {}  - to:  # Allow DNS    - namespaceSelector: {}      podSelector:        matchLabels:          k8s-app: kube-dns    ports:    - protocol: UDP      port: 53

Cost Allocation

Labels for Cost Attribution

bash
# Label namespaces for billingkubectl label namespace team-a cost-center=engineeringkubectl label namespace team-b cost-center=data-science

GKE Cost Allocation

Enable GKE cost allocation to break down costs by namespace and label:

bash
gcloud container clusters update <CLUSTER_NAME> --region <REGION> \  --enable-cost-allocation

View in Cloud Billing > GKE Cost Allocation.

Source and attribution

Source:google/skillsinskills/cloud/gke-multitenancyat commit55b4e13

License: No license

Content belongs to its original authors. SourceWeft indexes it from a public repository.

Report or request removal

More from google/skills

Dpop Adoption

google

Featured

Guides implementation of OAuth 2.0 DPoP (RFC 9449) sender-constrained refresh tokens for Google's OAuth platform.

SecurityOct 8, 2026

Finding Google Skills

google

Featured

Google platform decision and setup guidance, loaded on demand from Google's skill catalog. Use when a developer is choosing or setting up part of their stack, such as where to run a service, a database, storage, messaging, authentication, analytics, ads, or AI model serving, and a Google product is a reasonable candidate - whether or not a vendor is named - or when a request names a Google product or API. Brings in the matching Google skill so the answer can weigh Google options, their trade-offs, and when they are not the right fit. Skip when the stack is already settled on another provider and no Google product is named, or the task involves no platform choice.

Awaiting classificationOct 8, 2026

Spanner Basics

google

Featured

Guides Google Cloud Spanner administration, schema design, querying and performance diagnosis.

Data & AnalyticsOct 8, 2026

Secops Triage

google

Featured

Guides SOC analysts through triaging Google SecOps security alerts, from investigation to closure or escalation.

SecurityOct 8, 2026

Secops Investigate

google

Featured

Guides SOC analysts through deep security incident and entity investigations in Google SecOps using UDM queries and timelines.

SecurityOct 8, 2026

Secops Hunt

google

Featured

Guides proactive threat hunting in Google SecOps using UDM queries, IoC lookback, prevalence and outlier analysis.

SecurityOct 8, 2026