Strong agree. Everyone wants actual isolation, but tbh I’m not sure k8s is the best abstraction for the job. It’s so complex and leaves so much room for error. One config gone wrong or one missed patch and it’s game over for your cluster.
You’d need to hire a perfectionist to set up your cluster perfectly and then maintain it for eternity and at that point might as well just build your own orchestrator you trust. And have a team continually pass it down.
It’s a trade-off invest in one of the few people in the world who can actually create a secure cluster or hire folks who can schedule VMs on different nodes. It’s not rocket science, just code.
Kubernetes was not made with security in mind. It was an after thought and as such you will continually be a hamster in a wheel sweating your ass off unless you build your own with hard multi-tenancy in the design.
Chances are if you do hire one of the experts they’ll just wind up building their own orchestrator anyways. I know because I did and it only took a few weeks versus playing catch up with k8s upstream and config management for the rest of my life.
Also chances are you don’t actually need hard multi-tenancy (you only need that if you are running apps for unknowns... like a lamda) and in that case do whatever you want, just don’t open your cluster to the public internet.
Missing some Tweet in this thread?
You can try to force a refresh.

Like this thread? Get email updates or save it to PDF!

Subscribe to jessie frazelle 👩🏼‍🚀
Profile picture

Get real-time email alerts when new unrolls are available from this author!

This content may be removed anytime!

Twitter may remove this content at anytime, convert it as a PDF, save and print for later use!

Try unrolling a thread yourself!

how to unroll video

1) Follow Thread Reader App on Twitter so you can easily mention us!

2) Go to a Twitter thread (series of Tweets by the same owner) and mention us with a keyword "unroll" @threadreaderapp unroll

You can practice here first or read more on our help page!

Did Thread Reader help you today?

Support us! We are indie developers!


This site is made by just three indie developers on a laptop doing marketing, support and development! Read more about the story.

Become a Premium Member and get exclusive features!

Premium member ($30.00/year)

Too expensive? Make a small donation by buying us coffee ($5) or help with server cost ($10)

Donate via Paypal Become our Patreon

Thank you for your support!