youtube image
From YouTube: Sharing Clusters: Learnings From Building a Namespace On-Demand Platform - Lukas Gentele, DevSpace

Description

Don’t miss out! Join us at our upcoming events: EnvoyCon Virtual on October 15 and KubeCon + CloudNativeCon North America 2020 Virtual from November 17-20. Learn more at https://kubecon.io. The conferences feature presentations from developers and end users of Kubernetes, Prometheus, Envoy, and all of the other CNCF-hosted projects.

Sharing Clusters: Learnings From Building a Namespace On-Demand Platform - Lukas Gentele, DevSpace Technologies Inc.

Multi-tenancy is a hot topic in the Kubernetes community right now. IT teams want to enable engineers to work in shared clusters and allow them provision namespaces on-demand whenever needed. This creates a plethora of challenges that cluster admins have to address. This case study will show how the team behind DevSpace Cloud built a public Kubernetes-Namespace-as-a-Service offering, including: - Authentication via Dex - Automatic RBAC configuration - Dynamic admission control via Open Policy Agent - On-Demand namespace provisioning via CRDs - Network isolation using network policies - Resource management using resource quotas and limit ranges - Inactivity detection and automated cleanup of abandoned namespaces - Sandboxing This talk is intended for IT teams that want to create internal Kubernetes offerings to allow engineering teams to provision namespaces in an on-demand fashion.

https://sched.co/ZeiV