KubeCon + CloudNativeCon Europe

Project Lightning Talk: Namespace Multi-Tenancy, But All The Problems Related To It - Hristo Hristov

5:06 · 23 Mar 2026 – 26 Mar 2026 · YouTube

About this talk

This talk introduces Project Capsule, a CNCF sandbox project focused on solving challenges related to namespace multi-tenancy in Kubernetes. The speaker discusses common issues faced by developers and platform engineers, such as managing multiple namespaces and clusters as organizations scale, which can lead to increased complexity and costs. Project Capsule proposes a solution that allows multiple namespaces to be wrapped within a single tenant, providing isolation while allowing developers to operate within set resource boundaries. The architecture utilizes Kubernetes primitives, incorporating configurations for permissions, network policies, and resource pools that help manage usage limits. The project emphasizes integration with various CNCF tools like Argo CD and Gremlin, and encourages further discussions at the upcoming project pavilion.

Full transcript

All right, thank you. So, my name's Christopher and I'm a project maintainer for a project capsule, which is a CNCF sandbox project. Like we launched I think around 4 years ago. Closer microphone, okay. So, we launched around 4 years ago as a CNCF sandbox project and we're going to talk a little bit more about multi-tenancy, specifically namespace multi-tenancy. So, for people who dealt with the platform engineering

or with Kubernetes and developers overall, like they've probably been in this situation or close to this situation where you have start small, like you have few namespaces maybe for dev, staging, and production. But suddenly your company starts to scale up and you eventually reach to a point where you have around probably 200-300 microservices, a lot of developers, and so the doing kubectl get namespaces sometimes takes so

long that you have enough time to make a coffee, come back, and still not have an output. And also like your air back is absolutely all over the place, like it's very hard to keep track what is deployed, what is it. And the developers, of course, very smart people, they get around your limitations in your Kubernetes cluster by getting more namespaces and more namespaces so they can

get more resources. And you start to think about the multi-tenancy now. And the next native thing that comes to your mind in Kubernetes, that's a cluster. So, you start to do in multi-tenancy in a cluster where you provision maybe one cluster per your data, per your teams. But this also quickly turns into a nightmare. So, you have now multiple clusters, you have to patch them, you have

to secure them, you have to like the developers also do funky stuff inside them and they start to break. And generally it's a big, big nightmare. And but at this point it works, so you have a multi-tenancy now, like you're multi-tenant. Then you see okay, job is done. And eventually you get a thank you letter, but that thank you letter is not from your management. Oh, no.

It's from your cloud provider and they thank you for meeting your their next quarter revenue target. And you know that's absolutely bad, like you have to do something because the cost has been all over the place. And that's where we come in. It's a project capsule. It's where one namespace is absolutely not enough, but entire cluster is just way too much for you. And what we do

is we introduce the the the concept called the tenant, which wraps around multiple namespaces. The idea is like the developers work within this boundary, like where they have everything they need to, like we completely isolated from the from the rest of the the tenants. And you take you take a stop at the challenges like resource pools where the developers need set of resources, you give them per

tenant, and it's up to them to how they going to consume them. You also have the tenant configurations where you set guidelines how this, again, as administrator set the guidelines how they going to consume And in the end what you achieve is like a very, very good level of multi-tenancy where the developers can self-serve them, like it's absolutely what a cheap cost, so if you have a

look now like how the architecture like for a very high overview looks like, you can see we started very simple, like we use mostly Kubernetes primitives. So, we start to replicate, like you define a capsule configurations, which takes care of application of native permissions like user groups, service accounts, air back, everything like related to it. It also replicates network policies or policies like from CNCF projects like

Calico and Cilium. And then you have the the the newest addition, of course, is the the resource pools that we recently released, which takes care of the encapsulating the the resources that a tenant can consume so they cannot go over the their quotas. And then you have like the full circle close where the tenant owners, they also can define like their for their tenants policies, configuration on

a on a tenant level. And then, of course, you have the developers who are like just the users. In the end they can create namespaces. So, this is pretty much it. And it since it's a part of the CNCF, it's very, very important to play well with the with the others. So, we integrate very well with Argo CD. We are fully GitOps compliant for CD, Rancher, Velero,

everything that you can name on on the CNCF landscape, we integrate with it. So, we strive to to integrate with them. We also want to do a shout-out to one of our local adopters, it's Odyssey North and Kubermatic. And for the organizations that also require a little bit more strict guide like enterprise support, like we have also two companies that also contributors that provide this, it's Qualitics

and Pixie Labs. And if you're generally interested in multi-tenancy, it's a very, very interesting topic, especially in the Kubernetes space. You can meet us at our project pavilion, which will be on the Wednesday from 14:00 to 17:00 in the in the afternoon. It will be P13A. So, you're going to find us there. We're going to have a like in more in details demo because it's quite big

project, so. And yeah, you can also join us on Kubernetes Slack on the /capsule. You can find us on the projectcapsule.dev and on GitHub. And with that I want to thank you and have a nice one. Thank you, buddy.