DEV Community

Cover image for Building a Kubernetes Lab for 500 Students — How Should We Handle Access Control?
krit garg
krit garg

Posted on

Building a Kubernetes Lab for 500 Students — How Should We Handle Access Control?

I'm working on a university infrastructure project, and I'd love some feedback from people who have experience managing Kubernetes in multi-user environments.

We're trying to build a shared cloud lab where around 500 students can deploy applications, experiment with DevOps tools, and learn by working with real infrastructure — without accidentally breaking each other's work.

Think of it as a small internal developer platform for a university.

The problem we're trying to solve

We want students to be able to:

  • Deploy and manage their own applications.
  • Access their environments through a central portal.
  • Use cluster resources within defined limits.
  • Explore shared resources where appropriate, without modifying or deleting other students' workloads.

Administrators should be able to manage users and permissions centrally.

One of our biggest concerns is isolation. We don't want a student's mistake to take down another student's application or database.

Our current approach

We're moving toward a Kubernetes-managed environment rather than provisioning individual VMs for students.

Here's what we're considering:

  • Kubernetes: Runs and manages student workloads.
  • Keycloak: Central identity management and SSO.
  • Kubernetes RBAC: Controls what users can do inside the cluster.
  • Cloudflare Tunnel: Already part of our remote-access setup.
  • Teleport: Something we're evaluating for controlled infrastructure access.

We're still figuring out how these pieces should fit together, and whether we need all of them.

Where I need advice

1. Namespace strategy

For 500 students, would you create a separate namespace for every student, use shared namespaces for specific activities, or adopt a hybrid approach?

2. Permissions and isolation

We want students to see certain shared resources while preventing them from modifying or deleting other students' workloads. How would you structure RBAC to achieve this?

3. Keycloak vs. Kubernetes authentication

What's a practical way to connect Keycloak to Kubernetes authentication and authorization? Would you use an OIDC-based setup, an intermediary platform, or something else?

4. Do we actually need Teleport?

We already use Cloudflare Tunnel for remote access. I'm trying to understand what Teleport would add to our setup and whether that additional complexity is justified.

5. Resource management

What would you recommend for limiting CPU, memory, storage, and potentially GPU usage across hundreds of student workloads? Are ResourceQuota and LimitRange enough for a first version?

What would you do differently?

We're trying to keep the first version practical rather than building an unnecessarily complicated platform.

If you've managed a shared Kubernetes cluster, built an internal developer platform, or handled access control for a university or lab environment, I'd really appreciate your perspective.

What architecture would you choose for this use case, and what mistakes should we avoid before onboarding hundreds of students?

I'd especially appreciate real-world experiences and trade-offs over purely theoretical recommendations.

Thanks!

Top comments (1)

Collapse
 
suppdevbot profile image
DEV SUPPORTS •

You need to verify your account.

Enter fullscreen mode Exit fullscreen mode

tr.ee/dev-to