Back to Skills

gke-multitenancy

Plans and configures multi-tenancy on GKE. Covers namespace isolation, RBAC planning for teams, resource quotas, LimitRanges, network isolation, and cost allocation. Use when designing GKE multi-tenancy, configuring GKE namespaces, setting up resource quotas, or isolating GKE teams. Don't use for single-tenant cluster configuration or general deployment instructions (use gke-basics or gke-app-onboarding instead).

15,350stars1,203forksUpdated 7/31/2026

Security Assessment

Safe(95/100)
Security Score95/100

About gke-multitenancy

This skill is a reference and configuration guide for planning and implementing multi-tenancy on Google Kubernetes Engine (GKE). It solves the problem of safely sharing a single cluster across multiple teams or environments while controlling access, resource consumption, network exposure, and cost. It presents a decision framework of multi-tenancy models, ranging from soft namespace-per-team isolation to hard cluster-per-team isolation, with a golden-path recommendation to start with namespace-per-team for cost efficiency and escalate only when compliance requires stronger boundaries.

The skill provides concrete, copyable configurations for each layer of isolation: creating and labeling namespaces, defining least-privilege namespace-scoped RBAC Roles and RoleBindings bound to Google Groups, setting ResourceQuotas to cap CPU, memory, pods, and other resources per team, defining LimitRanges with mandatory defaults and maximums per container, and applying default-deny NetworkPolicies with allow rules for intra-namespace traffic and DNS. It also covers cost allocation using namespace labels for billing attribution and enabling GKE cost allocation via gcloud. It references companion skills for deeper RBAC hardening and workload security. It lists read and apply MCP tools such as apply_k8s_manifest, get_k8s_resource, check_k8s_auth, describe_k8s_resource, and delete_k8s_resource.

It targets platform engineers, cluster administrators, and DevOps teams designing enterprise multi-tenant GKE platforms. Typical use cases include onboarding multiple teams onto a shared cluster, isolating dev, staging, and production within one cluster, enforcing least-privilege access, and attributing costs across teams or projects.

FAQ

When should I use this skill versus other GKE skills?

Use it for designing GKE multi-tenancy, configuring namespaces, setting up resource quotas, or isolating teams. It explicitly directs you elsewhere (gke-basics or gke-app-onboarding) for single-tenant clusters or general deployment.

Which multi-tenancy model does it recommend starting with?

Namespace-per-team for cost efficiency, escalating to node-pool-per-team or cluster-per-team only when compliance or stronger isolation requirements demand it.

How does it handle access control?

Through least-privilege, namespace-scoped RBAC Roles and RoleBindings bound to Google Groups, with an explicit principle never to bind to system:authenticated.

Does it cover cost tracking?

Yes, it shows labeling namespaces with cost-center labels and enabling GKE cost allocation via gcloud so costs can be broken down by namespace and label in Cloud Billing.

What is the caveat about LimitRanges?

If you set a min or max in a LimitRange, you must also define corresponding default and defaultRequest values, or pods without explicit resource requests will be rejected by the admission controller.

Install gke-multitenancy

Download and extract the skill files to your .claude/skills/ directory.

Quick Setup:

  1. Copy the skill folder to .claude/skills/
  2. Claude will automatically detect and use the skill

Repository

google/skills