Skip to content

Discussion on Cryostat Deployment in a Namespace #604

Answered by andrewazores
Prasunamadasu asked this question in Q&A
Discussion options

You must be logged in to vote

By deploying both Cryostats into the same Namespace, both of those Cryostats require the create pods/exec in Namespace A Role in order to access them. Therefore, both of these Cryostats grant access to identical sets of users. This is why our recommendation is to place each Cryostat into its own separate Namespace - for security and isolation. If you place each Cryostat into a separate Namespace then you can control which developers have access to each one by using Kubernetes Role assignments for the developers' user accounts and only granting them create pods/exec in the appropriate Namespace that corresponds to the Cryostat instance they should use.

By placing both applications and both…

Replies: 3 comments 4 replies

Comment options

You must be logged in to vote
4 replies
@Prasunamadasu
Comment options

@andrewazores
Comment options

@Prasunamadasu
Comment options

@andrewazores
Comment options

Answer selected by andrewazores
Comment options

You must be logged in to vote
0 replies
Comment options

You must be logged in to vote
0 replies
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Category
Q&A
Labels
None yet
2 participants