Gke Multitenancy

作者 google55b4e13eba6d无许可证21K 个星标收录于 2026年10月8日更新于 2026年10月8日仓库今天更新

Plans and configures multi-tenancy on GKE. Covers namespace isolation, RBAC planning for teams, resource quotas, LimitRanges, network isolation, and cost allocation. Use when designing GKE multi-tenancy, configuring GKE namespaces, setting up resource quotas, or isolating GKE teams. Don't use for single-tenant cluster configuration or general deployment instructions (use gke-basics or gke-app-onboarding instead).

精选仅含说明DevOps & Cloud
AI 生成的概览

规划并配置 GKE 多租户,涵盖命名空间、RBAC、配额与网络隔离。

功能
该参考技能指导在 Google Kubernetes Engine 上设计和配置多租户。它比较多种隔离模型(按团队划分命名空间、按环境划分命名空间、按团队划分节点池、按团队划分集群),并提供命名空间、RBAC Role 与 RoleBinding、ResourceQuota、LimitRange、NetworkPolicy 以及成本分摊标签的清单与命令。文中还提到用于应用和查看 Kubernetes 资源的 MCP 工具。
适用场景
当多个团队或环境共用一个 GKE 集群,需要命名空间隔离、最小权限访问、资源限制或按团队分摊成本时使用。它不适用于单租户集群配置或一般部署说明。
运行要求
需要 GKE 集群以及 kubectl 和 gcloud 访问权限,可选使用用于 Kubernetes 资源的 MCP 工具。该技能不包含脚本,仅为说明与清单。

GKE Multi-Tenancy

This reference covers enterprise multi-tenancy patterns on GKE, including namespace isolation, RBAC planning, resource quotas, and network segmentation.

MCP Tools: apply_k8s_manifest, get_k8s_resource, check_k8s_auth, describe_k8s_resource, delete_k8s_resource

When to Use

  • Multiple teams sharing a single GKE cluster
  • Isolating workloads by environment (dev/staging/prod) within one cluster
  • Implementing least-privilege access control
  • Cost allocation across teams or projects

Multi-Tenancy Models

ModelIsolationComplexityCost
Namespace-per-teamSoft (RBAC +LowLowest (shared
: : Network : : cluster) :
: : Policy) : : :
Namespace-per-environmentSoftLowLow
Node pool-per-teamMediumMediumMedium
: : (dedicated : : :
: : compute) : : :
Cluster-per-teamHard (fullHighHighest
: : isolation) : : :

Golden path recommendation: Start with namespace-per-team for cost efficiency. Escalate to stronger isolation only when compliance requires it.

Namespace Isolation Setup

1. Create Namespaces

bash
kubectl create namespace team-akubectl create namespace team-bkubectl label namespace team-a team=akubectl label namespace team-b team=b

2. RBAC Configuration

Principle: Grant minimal permissions per namespace. Never bind to system:authenticated.

yaml
# Namespace-scoped role for a teamapiVersion: rbac.authorization.k8s.io/v1kind: Rolemetadata:  name: team-a-developer  namespace: team-arules:- apiGroups: ["", "apps", "batch"]  resources: ["pods", "deployments", "services", "configmaps", "jobs"]  verbs: ["get", "list", "watch", "create", "update", "patch", "delete"]---apiVersion: rbac.authorization.k8s.io/v1kind: RoleBindingmetadata:  name: team-a-developers  namespace: team-asubjects:- kind: Group  name: "[email protected]"  # Google Group  apiGroup: rbac.authorization.k8s.ioroleRef:  kind: Role  name: team-a-developer  apiGroup: rbac.authorization.k8s.io

RBAC best practices: Use Google Groups for subject bindings. Prefer namespace-scoped Roles over ClusterRoles. See the gke-platform-security skill for full RBAC hardening guidance.

3. Resource Quotas

Prevent any single team from consuming all cluster resources:

yaml
apiVersion: v1kind: ResourceQuotametadata:  name: team-a-quota  namespace: team-aspec:  hard:    requests.cpu: "10"    requests.memory: "20Gi"    limits.cpu: "20"    limits.memory: "40Gi"    pods: "50"    services: "10"    persistentvolumeclaims: "10"

4. LimitRanges

Set default and maximum resource constraints per container:

yaml
apiVersion: v1kind: LimitRangemetadata:  name: team-a-limits  namespace: team-aspec:  limits:  - type: Container    default:      cpu: "500m"      memory: "512Mi"    defaultRequest:      cpu: "100m"      memory: "128Mi"    max:      cpu: "4"      memory: "8Gi"

[!IMPORTANT] Mandatory Defaults: When defining min or max limits in a LimitRange, you must also define corresponding default and defaultRequest values. If you set a min or max without defaults, any pod deployed without explicit resource requests/limits will be rejected by the admission controller.

5. Network Isolation

Apply default-deny per namespace (see the gke-workload-security skill), then allow intra-team traffic:

yaml
# Allow same-namespace pods to talk + DNSapiVersion: networking.k8s.io/v1kind: NetworkPolicymetadata:  name: allow-same-namespace  namespace: team-aspec:  podSelector: {}  ingress:  - from:    - podSelector: {}  egress:  - to:    - podSelector: {}  - to:  # Allow DNS    - namespaceSelector: {}      podSelector:        matchLabels:          k8s-app: kube-dns    ports:    - protocol: UDP      port: 53

Cost Allocation

Labels for Cost Attribution

bash
# Label namespaces for billingkubectl label namespace team-a cost-center=engineeringkubectl label namespace team-b cost-center=data-science

GKE Cost Allocation

Enable GKE cost allocation to break down costs by namespace and label:

bash
gcloud container clusters update <CLUSTER_NAME> --region <REGION> \  --enable-cost-allocation

View in Cloud Billing > GKE Cost Allocation.

来源与署名

来源:google/skills位于skills/cloud/gke-multitenancy提交55b4e13

许可证: 无许可证

内容归原作者所有。SourceWeft 从公开仓库中收录这些内容。

举报或申请下架

更多来自 google/skills 的技能