this is super ♨️ btw. Love the user of kubernets namespace for isolation on "shared" infra
m
marpaia
05/16/2018, 12:20 AM
namespaces don’t provide much isolation by themselves beyond secrets, but i definitely want to lock down each tenant. it would be great if each customer’s workloads could assume a hostile cluster.
but that is not the case… yet!
c
clippy
05/16/2018, 3:34 AM
I really like what cilium is doing, have you poked at that yet? Seems very promising