KubeCon + CloudNativeCon Europe

How To Break Multi-Tenancy Again and Again ...and What We Can Learn F... Lorin Lehawany & Sven Nobis

28:34 · 23 Mar 2026 – 26 Mar 2026 · YouTube

About this talk

This talk explores the complexities of namespace-based multi-tenancy in Kubernetes and challenges the prevailing view that control-plane isolation is always superior. Speakers Lorin Lehawany and Sven Nobis delve into the hidden multi-tenancy issues that arise from workloads like machine learning and scripting capabilities, raising concerns about their secure isolation in clustered environments. The discussion highlights real-world exploits encountered in Kubeflow, Istio, and Traefik, demonstrating how these vulnerabilities can breach threat boundaries between namespaces and workloads. The session also offers a methodology for evaluating environments with isolation challenges and provides guidance on addressing these security concerns effectively.