Q: You have a multi-tenant cluster where different teams share the cluster. How do you isolate them?
Soft multi-tenancy in Kubernetes (hard isolation requires separate clusters):
#Kubernetes #Advanced Scenarios #L3 #Container Orchestration #K8s
🎙️ Candidate Opening & Architectural Context
""In our production Kubernetes clusters running microservices on EKS/AKS, this was a classic operational challenge. When addressing this question, I walk the interviewer through our production incident runbook: isolating the blast radius, checking diagnostic logs and metrics, and applying a safe fix.""
Advertisement
🛠️ Production Runbook & Step-by-Step Resolution
1️⃣
Initial Diagnostics & Root Cause Analysis
Soft multi-tenancy in Kubernetes (hard isolation requires separate clusters):
- Namespaces — one namespace per team.
- RBAC — teams can only access their own namespace.
- ResourceQuotas — limit total CPU/memory/pods per namespace.
- LimitRanges — default limits per pod/container.
2️⃣
Remediation & Permanent Safeguards
True hard isolation (different teams can't see each other's API resources at all) requires separate clusters or a multi-tenant solution like vCluster.
- NetworkPolicies — namespace-to-namespace traffic blocked by default.
- Pod Security Admission — enforce security baselines (no privileged pods, no hostPath, etc.).
- OPA/Gatekeeper or Kyverno — custom policy enforcement (e.g., all images must come from internal registry).
💡 The Senior SRE Gold Nugget (Key Architectural Takeaway)
"Pro-Tip: Namespaces — one namespace per team.."
⚡ 60-Second Elevator Pitch Talking Points
- Namespaces — one namespace per team.
- RBAC — teams can only access their own namespace.
- ResourceQuotas — limit total CPU/memory/pods per namespace.
Advertisement