Gke Multitenancy

作者 google55b4e13eba6d無授權條款21K 個星標收錄於 2026年10月8日更新於 2026年10月8日儲存庫今天更新

Plans and configures multi-tenancy on GKE. Covers namespace isolation, RBAC planning for teams, resource quotas, LimitRanges, network isolation, and cost allocation. Use when designing GKE multi-tenancy, configuring GKE namespaces, setting up resource quotas, or isolating GKE teams. Don't use for single-tenant cluster configuration or general deployment instructions (use gke-basics or gke-app-onboarding instead).

精選僅含說明DevOps & Cloud
AI 產生的概覽

規劃並設定 GKE 多租戶,涵蓋命名空間、RBAC、配額與網路隔離。

功能
這份參考技能說明如何在 Google Kubernetes Engine 上設計與設定多租戶。它比較多種隔離模型(依團隊劃分命名空間、依環境劃分命名空間、依團隊劃分節點集區、依團隊劃分叢集),並提供命名空間、RBAC Role 與 RoleBinding、ResourceQuota、LimitRange、NetworkPolicy 以及成本分攤標籤的資訊清單與指令。文中也提到用來套用與檢視 Kubernetes 資源的 MCP 工具。
適用情境
當多個團隊或環境共用同一個 GKE 叢集,需要命名空間隔離、最小權限存取、資源限制或依團隊分攤成本時使用。它不適用於單一租戶叢集設定或一般部署說明。
執行需求
需要 GKE 叢集以及 kubectl 和 gcloud 存取權,可選用於 Kubernetes 資源的 MCP 工具。此技能不含指令碼,僅為說明與資訊清單。

GKE Multi-Tenancy

This reference covers enterprise multi-tenancy patterns on GKE, including namespace isolation, RBAC planning, resource quotas, and network segmentation.

MCP Tools: apply_k8s_manifest, get_k8s_resource, check_k8s_auth, describe_k8s_resource, delete_k8s_resource

When to Use

  • Multiple teams sharing a single GKE cluster
  • Isolating workloads by environment (dev/staging/prod) within one cluster
  • Implementing least-privilege access control
  • Cost allocation across teams or projects

Multi-Tenancy Models

ModelIsolationComplexityCost
Namespace-per-teamSoft (RBAC +LowLowest (shared
: : Network : : cluster) :
: : Policy) : : :
Namespace-per-environmentSoftLowLow
Node pool-per-teamMediumMediumMedium
: : (dedicated : : :
: : compute) : : :
Cluster-per-teamHard (fullHighHighest
: : isolation) : : :

Golden path recommendation: Start with namespace-per-team for cost efficiency. Escalate to stronger isolation only when compliance requires it.

Namespace Isolation Setup

1. Create Namespaces

bash
kubectl create namespace team-akubectl create namespace team-bkubectl label namespace team-a team=akubectl label namespace team-b team=b

2. RBAC Configuration

Principle: Grant minimal permissions per namespace. Never bind to system:authenticated.

yaml
# Namespace-scoped role for a teamapiVersion: rbac.authorization.k8s.io/v1kind: Rolemetadata:  name: team-a-developer  namespace: team-arules:- apiGroups: ["", "apps", "batch"]  resources: ["pods", "deployments", "services", "configmaps", "jobs"]  verbs: ["get", "list", "watch", "create", "update", "patch", "delete"]---apiVersion: rbac.authorization.k8s.io/v1kind: RoleBindingmetadata:  name: team-a-developers  namespace: team-asubjects:- kind: Group  name: "[email protected]"  # Google Group  apiGroup: rbac.authorization.k8s.ioroleRef:  kind: Role  name: team-a-developer  apiGroup: rbac.authorization.k8s.io

RBAC best practices: Use Google Groups for subject bindings. Prefer namespace-scoped Roles over ClusterRoles. See the gke-platform-security skill for full RBAC hardening guidance.

3. Resource Quotas

Prevent any single team from consuming all cluster resources:

yaml
apiVersion: v1kind: ResourceQuotametadata:  name: team-a-quota  namespace: team-aspec:  hard:    requests.cpu: "10"    requests.memory: "20Gi"    limits.cpu: "20"    limits.memory: "40Gi"    pods: "50"    services: "10"    persistentvolumeclaims: "10"

4. LimitRanges

Set default and maximum resource constraints per container:

yaml
apiVersion: v1kind: LimitRangemetadata:  name: team-a-limits  namespace: team-aspec:  limits:  - type: Container    default:      cpu: "500m"      memory: "512Mi"    defaultRequest:      cpu: "100m"      memory: "128Mi"    max:      cpu: "4"      memory: "8Gi"

[!IMPORTANT] Mandatory Defaults: When defining min or max limits in a LimitRange, you must also define corresponding default and defaultRequest values. If you set a min or max without defaults, any pod deployed without explicit resource requests/limits will be rejected by the admission controller.

5. Network Isolation

Apply default-deny per namespace (see the gke-workload-security skill), then allow intra-team traffic:

yaml
# Allow same-namespace pods to talk + DNSapiVersion: networking.k8s.io/v1kind: NetworkPolicymetadata:  name: allow-same-namespace  namespace: team-aspec:  podSelector: {}  ingress:  - from:    - podSelector: {}  egress:  - to:    - podSelector: {}  - to:  # Allow DNS    - namespaceSelector: {}      podSelector:        matchLabels:          k8s-app: kube-dns    ports:    - protocol: UDP      port: 53

Cost Allocation

Labels for Cost Attribution

bash
# Label namespaces for billingkubectl label namespace team-a cost-center=engineeringkubectl label namespace team-b cost-center=data-science

GKE Cost Allocation

Enable GKE cost allocation to break down costs by namespace and label:

bash
gcloud container clusters update <CLUSTER_NAME> --region <REGION> \  --enable-cost-allocation

View in Cloud Billing > GKE Cost Allocation.

來源與署名

來源:google/skills位於skills/cloud/gke-multitenancy提交55b4e13

授權條款: 無授權條款

內容歸原作者所有。SourceWeft 從公開儲存庫中收錄這些內容。

檢舉或申請下架

更多來自 google/skills 的技能

Dpop Adoption

google

精選

指導為 Google OAuth 平台實作 OAuth 2.0 DPoP(RFC 9449)傳送方約束的更新權杖。

Security21K今天更新

Finding Google Skills

google

精選

Google platform decision and setup guidance, loaded on demand from Google's skill catalog. Use when a developer is choosing or setting up part of their stack, such as where to run a service, a database, storage, messaging, authentication, analytics, ads, or AI model serving, and a Google product is a reasonable candidate - whether or not a vendor is named - or when a request names a Google product or API. Brings in the matching Google skill so the answer can weigh Google options, their trade-offs, and when they are not the right fit. Skip when the stack is already settled on another provider and no Google product is named, or the task involves no platform choice.

待分類21K今天更新

Spanner Basics

google

精選

指導 Google Cloud Spanner 的執行個體與資料庫管理、結構定義設計、查詢與效能診斷。

Data & Analytics21K今天更新

Secops Triage

google

精選

引導 SOC 分析師對 Google SecOps 安全警示進行分診,從調查到結案或升級。

Security21K今天更新

Secops Investigate

google

精選

指導 SOC 分析師在 Google SecOps 中使用 UDM 查詢與時間軸進行深入的安全事件與實體調查。

Security21K今天更新

Secops Hunt

google

精選

指導在 Google SecOps 中使用 UDM 查詢、IoC 回溯、普遍性與異常分析進行主動威脅狩獵。

Security21K今天更新