Course Hive
Search

Welcome

Sign in or create your account

Continue with Google
or
Multi-Tenant Kubernetes Gateway API: Stop Cross-Team Outages with Secure Namespace Isolation
Play lesson

Kubernetes Gateway API Zero to Hero (With NGINX Gateway Fabric) - Multi-Tenant Kubernetes Gateway API: Stop Cross-Team Outages with Secure Namespace Isolation

5.0 (0)
8 learners

What you'll learn

This course includes

  • 2 hours of video
  • Certificate of completion
  • Access on mobile and TV

Summary

Keywords

Full Transcript

Multi-Tenant Kubernetes Gateway API with Zero Cross-Team Traffic Breaks When multiple teams share a Kubernetes cluster, traffic management becomes the most fragile part of the platform. One routing change can accidentally break another team’s application, even when nobody intended to. In this video, I build a production-grade multi-tenant Gateway API setup with: - One shared Gateway - Multiple tenant namespaces - Platform-owned TLS - Tenant-owned routing - Zero cross-team interference Github Repo: https://github.com/NikKumar811/kubernetes-basics-to-advanced/tree/main/gateway-api-demo/phase-3-production/multi-tenant What You’ll Learn: ✔️ How real platforms design multi-tenant Gateway API architectures ✔️ Why HTTP exists only for certificate automation ✔️ How to terminate TLS once at the platform level ✔️ How namespace labels prevent accidental outages ✔️ How teams safely attach HTTPRoutes without touching infra Architecture Highlights - Single shared Gateway - Two listeners: HTTP (port 80): cert-manager only HTTPS (port 443): real tenant traffic - SAN TLS certificate owned by the platform - Namespace-level route isolation using selectors - Gateway API instead of Ingress ▬▬▬▬▬▬▬ Timestamps ▬▬▬▬▬▬▬ 00:00 - Why Multi-Tenant Traffic Breaks Kubernetes Clusters 00:26 - The Real Multi-Tenant Gateway API Architecture 01:27 - Creating Tenant & Platform Namespaces (Isolation First) 03:09 - Deploying Applications for Tenant A & Tenant B 05:24 - Deploying a Shared Gateway (HTTP Only for Cert Automation) 07:51 - Issuing SAN TLS Certificates with cert-manager & Gateway API 12:29 - Enabling HTTPS Listener with Namespace-Level Guardrails 15:29 - Tenant-Owned HTTPRoutes (Safe Routing Without Interference) 20:14 - Final Architecture Review & Key Takeaways Demo Walkthrough 1. Tenant A & Tenant B run isolated workloads 2. Both use the same Gateway & TLS certificate 3. Each team controls only its own HTTPRoute 4. No team can break another team’s traffic 🔗 Watch Related Playlists: - Kubernetes: https://www.youtube.com/playlist?list=PL-K2rw28HIwZVMo9CtbV0wDu548SN0h9Y - Github Actions: https://www.youtube.com/playlist?list=PL-K2rw28HIwYfq7SqYnBzAxlUhcYP7ldM - Ansible: https://www.youtube.com/playlist?list=PL-K2rw28HIwaavCXTYEWF4mP431KmKtEY - AWX: https://www.youtube.com/playlist?list=PL-K2rw28HIwbTtijpBMrOaHdnWGXdOkYa - AI: https://www.youtube.com/playlist?list=PL-K2rw28HIwaSvmI8oFeSQDl4cVTdxaGQ ▬▬▬▬▬▬ Connect with me ▬▬▬▬▬▬ LinkedIn: https://www.linkedin.com/in/kumar-nikhil811/ Website: https://techinik.com Medium: https://medium.com/@kumarnikhil811 #kubernetes #gatewayapi #devops #platformengineering #k8s #kubernetesnetworking

Course Hive

Continue this lesson in the app

Install CourseHive on Android or iOS to keep learning while you move.

FAQs

Course Hive
Download CourseHive
Keep learning anywhere