Skip to content
kix /docs
Install the CLI

Reference Cluster module

namespaces

Configure Namespace metadata, quotas, network policies, and Pod Security Admission.

Kix creates a Namespace resource for each namespace used by an instance. Add a namespaces.<name> entry to configure that resource or to create a namespace before it contains an instance.

namespaces.apps = {
labels.owner = "application-team";
annotations."example.com/contact" = "[email protected]";
podSecurity = "restricted";
resourceQuota = {
requests.cpu = "4";
requests.memory = "8Gi";
};
networkPolicies.default-deny = {
podSelector = { };
policyTypes = [ "Ingress" "Egress" ];
};
};
FieldTypeDefaultEffect
labelsattribute set of strings{ }Additional Namespace labels. Kix also writes kubernetes.io/metadata.name and app.kubernetes.io/managed-by.
annotationsattribute set of strings{ }Namespace annotations.
resourceQuotanull or attribute setnullCreates ResourceQuota/<namespace>-quota with this value as spec.hard.
networkPoliciesattribute set{ }Creates one Kubernetes NetworkPolicy per entry, named <namespace>-<entry>, with the entry value as spec.
podSecuritynull, privileged, baseline, or restrictednullSets the pod-security.kubernetes.io/enforce label.

Package metadata also contributes to Pod Security Admission. Kix takes the most permissive meta.podSecurity requested by an instance in the namespace. An explicitly configured namespace level that is stricter than a package requires is an evaluation error. When package declarations exist, their most permissive value is rendered; a more permissive namespace value does not raise it further.

The networkPolicies field writes standard Kubernetes NetworkPolicy objects directly. It is separate from cluster.networkPolicy, which derives policies from package dependencies through the configured policy provider.

See meta.podSecurity for the package declaration.