<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom" xmlns:dc="http://purl.org/dc/elements/1.1/">
  <channel>
    <title>DEV Community: krit garg</title>
    <description>The latest articles on DEV Community by krit garg (@kritgarg).</description>
    <link>https://dev.to/kritgarg</link>
    <image>
      <url>https://media2.dev.to/dynamic/image/width=90,height=90,fit=cover,gravity=auto,format=auto/https:%2F%2Fthepracticaldev.s3.amazonaws.com%2Fi%2F99mvlsfu5tfj9m7ku25d.png</url>
      <title>DEV Community: krit garg</title>
      <link>https://dev.to/kritgarg</link>
    </image>
    <atom:link rel="self" type="application/rss+xml" href="https://dev.to/feed/kritgarg"/>
    <language>en</language>
    <item>
      <title>Building a Kubernetes Lab for 500 Students — How Should We Handle Access Control?</title>
      <dc:creator>krit garg</dc:creator>
      <pubDate>Sat, 10 Oct 2026 06:55:00 +0000</pubDate>
      <link>https://dev.to/kritgarg/building-a-kubernetes-lab-for-500-students-how-should-we-handle-access-control-4lfb</link>
      <guid>https://dev.to/kritgarg/building-a-kubernetes-lab-for-500-students-how-should-we-handle-access-control-4lfb</guid>
      <description>&lt;p&gt;I'm working on a university infrastructure project, and I'd love some feedback from people who have experience managing Kubernetes in multi-user environments.&lt;/p&gt;

&lt;p&gt;We're trying to build a shared cloud lab where around 500 students can deploy applications, experiment with DevOps tools, and learn by working with real infrastructure — without accidentally breaking each other's work.&lt;/p&gt;

&lt;p&gt;Think of it as a small internal developer platform for a university.&lt;/p&gt;

&lt;h3&gt;
  
  
  The problem we're trying to solve
&lt;/h3&gt;

&lt;p&gt;We want students to be able to:&lt;/p&gt;

&lt;ul&gt;
&lt;li&gt;Deploy and manage their own applications.&lt;/li&gt;
&lt;li&gt;Access their environments through a central portal.&lt;/li&gt;
&lt;li&gt;Use cluster resources within defined limits.&lt;/li&gt;
&lt;li&gt;Explore shared resources where appropriate, without modifying or deleting other students' workloads.&lt;/li&gt;
&lt;/ul&gt;

&lt;p&gt;Administrators should be able to manage users and permissions centrally.&lt;/p&gt;

&lt;p&gt;One of our biggest concerns is isolation. We don't want a student's mistake to take down another student's application or database.&lt;/p&gt;

&lt;h3&gt;
  
  
  Our current approach
&lt;/h3&gt;

&lt;p&gt;We're moving toward a Kubernetes-managed environment rather than provisioning individual VMs for students.&lt;/p&gt;

&lt;p&gt;Here's what we're considering:&lt;/p&gt;

&lt;ul&gt;
&lt;li&gt;
&lt;strong&gt;Kubernetes:&lt;/strong&gt; Runs and manages student workloads.&lt;/li&gt;
&lt;li&gt;
&lt;strong&gt;Keycloak:&lt;/strong&gt; Central identity management and SSO.&lt;/li&gt;
&lt;li&gt;
&lt;strong&gt;Kubernetes RBAC:&lt;/strong&gt; Controls what users can do inside the cluster.&lt;/li&gt;
&lt;li&gt;
&lt;strong&gt;Cloudflare Tunnel:&lt;/strong&gt; Already part of our remote-access setup.&lt;/li&gt;
&lt;li&gt;
&lt;strong&gt;Teleport:&lt;/strong&gt; Something we're evaluating for controlled infrastructure access.&lt;/li&gt;
&lt;/ul&gt;

&lt;p&gt;We're still figuring out how these pieces should fit together, and whether we need all of them.&lt;/p&gt;

&lt;h3&gt;
  
  
  Where I need advice
&lt;/h3&gt;

&lt;p&gt;&lt;strong&gt;1. Namespace strategy&lt;/strong&gt;&lt;/p&gt;

&lt;p&gt;For 500 students, would you create a separate namespace for every student, use shared namespaces for specific activities, or adopt a hybrid approach?&lt;/p&gt;

&lt;p&gt;&lt;strong&gt;2. Permissions and isolation&lt;/strong&gt;&lt;/p&gt;

&lt;p&gt;We want students to see certain shared resources while preventing them from modifying or deleting other students' workloads. How would you structure RBAC to achieve this?&lt;/p&gt;

&lt;p&gt;&lt;strong&gt;3. Keycloak vs. Kubernetes authentication&lt;/strong&gt;&lt;/p&gt;

&lt;p&gt;What's a practical way to connect Keycloak to Kubernetes authentication and authorization? Would you use an OIDC-based setup, an intermediary platform, or something else?&lt;/p&gt;

&lt;p&gt;&lt;strong&gt;4. Do we actually need Teleport?&lt;/strong&gt;&lt;/p&gt;

&lt;p&gt;We already use Cloudflare Tunnel for remote access. I'm trying to understand what Teleport would add to our setup and whether that additional complexity is justified.&lt;/p&gt;

&lt;p&gt;&lt;strong&gt;5. Resource management&lt;/strong&gt;&lt;/p&gt;

&lt;p&gt;What would you recommend for limiting CPU, memory, storage, and potentially GPU usage across hundreds of student workloads? Are ResourceQuota and LimitRange enough for a first version?&lt;/p&gt;

&lt;h3&gt;
  
  
  What would you do differently?
&lt;/h3&gt;

&lt;p&gt;We're trying to keep the first version practical rather than building an unnecessarily complicated platform.&lt;/p&gt;

&lt;p&gt;If you've managed a shared Kubernetes cluster, built an internal developer platform, or handled access control for a university or lab environment, I'd really appreciate your perspective.&lt;/p&gt;

&lt;p&gt;&lt;strong&gt;What architecture would you choose for this use case, and what mistakes should we avoid before onboarding hundreds of students?&lt;/strong&gt;&lt;/p&gt;

&lt;p&gt;I'd especially appreciate real-world experiences and trade-offs over purely theoretical recommendations.&lt;/p&gt;

&lt;p&gt;Thanks!&lt;/p&gt;

</description>
      <category>architecture</category>
      <category>devops</category>
      <category>infrastructure</category>
      <category>kubernetes</category>
    </item>
  </channel>
</rss>
