mirror of
https://github.com/rancher/rancher-docs.git
synced 2026-09-28 22:18:52 +00:00
Clarify projects and namespaces
This commit is contained in:
@@ -10,8 +10,13 @@ aliases:
|
|||||||
- /rancher/v2.x/en/tasks/projects/create-project/
|
- /rancher/v2.x/en/tasks/projects/create-project/
|
||||||
---
|
---
|
||||||
|
|
||||||
|
A namespace is a Kubernetes concept that allows a virtual cluster within a cluster, which is useful for dividing the cluster into separate "virtual clusters" that each have their own access control and resource quotas.
|
||||||
|
|
||||||
|
A project is a group of namespaces, and it is a concept introduced by Rancher. Projects allow you to manage multiple namespaces as a group and perform Kubernetes operations in them. You can use projects to support multi-tenancy, so that a team can access a project within a cluster without having access to other projects in the same cluster.
|
||||||
|
|
||||||
This section describes how projects and namespaces work with Rancher. It covers the following topics:
|
This section describes how projects and namespaces work with Rancher. It covers the following topics:
|
||||||
|
|
||||||
|
- [About namespaces](#about-namespaces)
|
||||||
- [About projects](#about-projects)
|
- [About projects](#about-projects)
|
||||||
- [The cluster's default project](#the-cluster-s-default-project)
|
- [The cluster's default project](#the-cluster-s-default-project)
|
||||||
- [The system project](#the-system-project)
|
- [The system project](#the-system-project)
|
||||||
@@ -19,7 +24,40 @@ This section describes how projects and namespaces work with Rancher. It covers
|
|||||||
- [Pod security policies](#pod-security-policies)
|
- [Pod security policies](#pod-security-policies)
|
||||||
- [Creating projects](#creating-projects)
|
- [Creating projects](#creating-projects)
|
||||||
- [Switching between clusters and projects](#switching-between-clusters-and-projects)
|
- [Switching between clusters and projects](#switching-between-clusters-and-projects)
|
||||||
- [Namespaces](#namespaces)
|
|
||||||
|
# About Namespaces
|
||||||
|
|
||||||
|
A namespace is a concept introduced by Kubernetes. According to the [official Kubernetes documentation,](https://kubernetes.io/docs/concepts/overview/working-with-objects/namespaces/)
|
||||||
|
|
||||||
|
> Kubernetes supports multiple virtual clusters backed by the same physical cluster. These virtual clusters are called namespaces. [...] Namespaces are intended for use in environments with many users spread across multiple teams, or projects. For clusters with a few to tens of users, you should not need to create or think about namespaces at all.
|
||||||
|
|
||||||
|
Namespaces provide the following functionality:
|
||||||
|
|
||||||
|
- **Providing a scope for names:** Names of resources need to be unique within a namespace, but not across namespaces. Namespaces can not be nested inside one another and each Kubernetes resource can only be in one namespace.
|
||||||
|
- **Resource quotas:** Namespaces provide a way to divide cluster resources between multiple users.
|
||||||
|
|
||||||
|
Within Rancher, a project can contain multiple namespaces, making it possible to organize and isolate resources within the project.
|
||||||
|
|
||||||
|
If you don't have a need for more than the default namespace, you also do not need more than the **Default** project in Rancher.
|
||||||
|
|
||||||
|
If you require another level of organization beyond the **Default** project, you can create more projects in Rancher to isolate namespaces, applications and resources.
|
||||||
|
|
||||||
|
You can assign resources at the project level so that each namespace in the project can use them. You can also bypass this inheritance by assigning resources explicitly to a namespace.
|
||||||
|
|
||||||
|
You can assign the following resources directly to namespaces:
|
||||||
|
|
||||||
|
- [Workloads]({{<baseurl>}}/rancher/v2.x/en/k8s-in-rancher/workloads/)
|
||||||
|
- [Load Balancers/Ingress]({{<baseurl>}}/rancher/v2.x/en/k8s-in-rancher/load-balancers-and-ingress/)
|
||||||
|
- [Service Discovery Records]({{<baseurl>}}/rancher/v2.x/en/k8s-in-rancher/service-discovery/)
|
||||||
|
- [Persistent Volume Claims]({{<baseurl>}}/rancher/v2.x/en/k8s-in-rancher/volumes-and-storage/persistent-volume-claims/)
|
||||||
|
- [Certificates]({{<baseurl>}}/rancher/v2.x/en/k8s-in-rancher/certificates/)
|
||||||
|
- [ConfigMaps]({{<baseurl>}}/rancher/v2.x/en/k8s-in-rancher/configmaps/)
|
||||||
|
- [Registries]({{<baseurl>}}/rancher/v2.x/en/k8s-in-rancher/registries/)
|
||||||
|
- [Secrets]({{<baseurl>}}/rancher/v2.x/en/k8s-in-rancher/secrets/)
|
||||||
|
|
||||||
|
>**Note:** Although you can assign role-based access to namespaces in the base version of Kubernetes, you cannot assign roles to namespaces in Rancher. Instead, assign role-based access at the project level.
|
||||||
|
|
||||||
|
For more information, see [Namespaces]({{<baseurl>}}/rancher/v2.x/en/project-admin/namespaces/).
|
||||||
|
|
||||||
# About Projects
|
# About Projects
|
||||||
|
|
||||||
@@ -158,24 +196,3 @@ Alternatively, you can switch between projects and clusters using the main menu.
|
|||||||
|
|
||||||
- To switch between clusters, open the **Global** view and select **Clusters** from the main menu. Then open a cluster.
|
- To switch between clusters, open the **Global** view and select **Clusters** from the main menu. Then open a cluster.
|
||||||
- To switch between projects, open a cluster, and then select **Projects/Namespaces** from the main menu. Select the link for the project that you want to open.
|
- To switch between projects, open a cluster, and then select **Projects/Namespaces** from the main menu. Select the link for the project that you want to open.
|
||||||
|
|
||||||
# Namespaces
|
|
||||||
|
|
||||||
Within Rancher, you can further divide projects into different [namespaces](https://kubernetes.io/docs/concepts/overview/working-with-objects/namespaces/), which are virtual clusters within a project backed by a physical cluster. Should you require another level of organization beyond projects and the `default` namespace, you can use multiple namespaces to isolate applications and resources.
|
|
||||||
|
|
||||||
You can assign resources at the project level so that each namespace in the project can use them. You can also bypass this inheritance by assigning resources explicitly to a namespace.
|
|
||||||
|
|
||||||
Resources that you can assign directly to namespaces include:
|
|
||||||
|
|
||||||
- [Workloads]({{< baseurl >}}/rancher/v2.x/en/k8s-in-rancher/workloads/)
|
|
||||||
- [Load Balancers/Ingress]({{< baseurl >}}/rancher/v2.x/en/k8s-in-rancher/load-balancers-and-ingress/)
|
|
||||||
- [Service Discovery Records]({{< baseurl >}}/rancher/v2.x/en/k8s-in-rancher/service-discovery/)
|
|
||||||
- [Persistent Volume Claims]({{< baseurl >}}/rancher/v2.x/en/k8s-in-rancher/volumes-and-storage/persistent-volume-claims/)
|
|
||||||
- [Certificates]({{< baseurl >}}/rancher/v2.x/en/k8s-in-rancher/certificates/)
|
|
||||||
- [ConfigMaps]({{< baseurl >}}/rancher/v2.x/en/k8s-in-rancher/configmaps/)
|
|
||||||
- [Registries]({{< baseurl >}}/rancher/v2.x/en/k8s-in-rancher/registries/)
|
|
||||||
- [Secrets]({{< baseurl >}}/rancher/v2.x/en/k8s-in-rancher/secrets/)
|
|
||||||
|
|
||||||
>**Note:** Although you can assign role-based access to namespaces in the base version of Kubernetes, you cannot assign roles to namespaces in Rancher. Instead, assign role-based access at the project level.
|
|
||||||
|
|
||||||
For more information, see [Namespaces]({{< baseurl >}}/rancher/v2.x/en/project-admin/namespaces/).
|
|
||||||
|
|||||||
Reference in New Issue
Block a user