All Things K8s 3 Instances When K8s Namespaces | Rafay
All Things Kubernetes: 3 Instances When Kubernetes Namespaces Don’t Work
June 5, 2020
Background
Kubernetes natively provides the means to logically separate a physical cluster into multiple virtual clusters via namespaces.
Namespaces are intended for situations where multiple users need to share the same Kubernetes cluster. Namespaces can be configured to ensure that each user or application exists within its namespace and is isolated from every other user of the cluster.
Challenges and Solutions
Although namespaces are extremely useful, they are not viable for many common scenarios. Let us review the challenges that users face for these relatively common scenarios.
Challenge #1: True Partitioning
Although namespaces provide the ability to logically partition a cluster, it is not possible to truly enforce partitioning. This means users or resources operating in the same Kubernetes cluster can access any other resource in the cluster regardless of the namespace it is operating in. The only practical solution is to use dedicated Kubernetes clusters to guarantee true separation across operational boundaries.
Some of Rafay’s customers, especially service providers, have a business requirement to operate large fleets (100s or 1000s) of geographically distributed Kubernetes clusters. These clusters are deployed to retail stores, factories and hospitals providing a managed application operations platform for application teams at these organizations.
Solution
Rafay enables customers to organize their fleet of Kubernetes clusters into projects. Each project has dedicated clusters associated with it and only identified personnel are authorized to access resources in each project.
In addition, to reduce operational complexity, Rafay also provides a unified control plane to manage their clusters, workloads, user access, policy and security across all projects.
Challenge #2: Accurate Chargebacks
Many “shared services” infrastructure Ops teams are required to implement fine grained chargebacks to dependent application teams. It is operationally cumbersome and challenging to use namespaces as the means to track utilization and implement chargebacks.
Solution
Rafay’s enterprise customers create projects for every business unit or application team. Every project can have one or many dedicated clusters. This provides a simple and streamlined process for organizational chargebacks without any incremental operational burden.
Challenge #3: Managing Upgrades
Some containerized applications have dependencies on critical software add-ons that are supported only on certain versions of Kubernetes. As a result, it may not be possible to upgrade these Kubernetes clusters before an updated version of the add-on is available.
Solution
For example, some of Rafay’s customers use Kubeflow (a critical software add-on for machine learning). However, at the time this blog was published, Kubeflow is not supported on k8s v1.16 which is two versions behind then latest version.
Next Steps
Interested in learning more about Projects? Watch a video showcasing how customers can use Projects in Rafay to address the challenges described above.
Sign up for a free Rafay account if you want to try out the Rafay platform or Contact us if you would like to learn more about where and when to namespaces (or not).
About Rafay
Rafay Systems delivers a turnkey SaaS platform that automates the ongoing operations and lifecycle management for containerized applications. The platform is designed for IT and DevOps teams to instantly build and operate Kubernetes clusters, while maintaining complete governance and control over the containerized applications being deployed on clusters under management.