# Configure namespace policy and global cluster settings

Set cluster-wide values and namespace policy in a module passed to
`kix.buildCluster`:

<Snippet {...clusterSettings} />

The cluster-wide settings in this example have distinct jobs:

* `clusterDomain` is used when Kix derives service FQDNs.
* `clusterLabels` adds the given labels to every managed resource.
* `k8sVersion` lets package compatibility checks evaluate against the intended
  Kubernetes version.

The `namespaces.apps` block configures the generated `apps` Namespace. Its
`labels` and `annotations` are added to that Namespace. `resourceQuota` is the
`hard` map for a generated ResourceQuota named `apps-quota`.

Add instances beneath the same namespace key. Kix also creates a Namespace for
an instance namespace that has no explicit `namespaces` block, but the explicit
block is where its policy belongs.

The `instances._platform.storage` entry in the snippet is an exception. A
namespace key beginning with `_` groups cluster-scoped instances without
creating a Kubernetes namespace. Kix creates no Namespace, ResourceQuota, or
default-deny policy for the group, and cluster scorecard rules skip it. Use
this form only when every resource in the instance is cluster-scoped, as the
storage provider's StorageClass is here. Use an ordinary name for anything
that needs a real namespace.

## Check the cluster

Run the normal pre-deploy checks:

<Command {...check} />

To inspect the generated Namespace and ResourceQuota, render the cluster as
JSON. The excerpt shows the two relevant resources from the complete build:

<Command {...namespaceResources} />

Check the generated resources again after changing a quota or a shared label.
This catches invalid package configuration and Kubernetes schema problems
before deployment.