Skip to content

Configure namespace policy and global cluster settings

This content is for the v0.1 version. Switch to the latest version for up-to-date documentation.

Set cluster-wide values and namespace policy in a module passed to kix.buildCluster:

how-to/composition/cluster.nix (L21–L45)
clusterDomain = "cluster.example";
clusterLabels."platform.example.com/environment" = "development";
k8sVersion = "1.31";
namespaces.apps = {
labels."platform.example.com/tier" = "application";
annotations."platform.example.com/owner" = "platform";
resourceQuota = {
"requests.cpu" = "2";
"requests.memory" = "2Gi";
};
};
instances.apps.storefront = {
inherit package;
config.message = "Storefront configuration";
};
instances.apps.widget = {
package = customResourcePackage;
};
instances._platform.storage = {
package = storageProvider;
};

View source on GitHub ↗

The cluster-wide settings in this example have distinct jobs:

  • clusterDomain is used when Kix derives service FQDNs.
  • clusterLabels adds the given labels to every managed resource.
  • k8sVersion lets package compatibility checks evaluate against the intended Kubernetes version.

The namespaces.apps block configures the generated apps Namespace. Its labels and annotations are added to that Namespace. resourceQuota is the hard map for a generated ResourceQuota named apps-quota.

Add instances beneath the same namespace key. Kix also creates a Namespace for an instance namespace that has no explicit namespaces block, but the explicit block is where its policy belongs.

The instances._platform.storage entry in the snippet is an exception. A namespace key beginning with _ groups cluster-scoped instances without creating a Kubernetes namespace. Kix creates no Namespace, ResourceQuota, or default-deny policy for the group, and cluster scorecard rules skip it. Use this form only when every resource in the instance is cluster-scoped, as the storage provider’s StorageClass is here. Use an ordinary name for anything that needs a real namespace.

Run the normal pre-deploy checks:

Run in kix-examples/
❱ kix check how-to-composition
 TOOL         RESULT  DETAILS                                                       
 eval         pass    15 manifests evaluated                                        
 kubeconform  pass    skipped (this validation tool is not yet integrated with Kix) 
 pluto        pass    skipped (this validation tool is not yet integrated with Kix) 
 kyverno      pass    skipped (this validation tool is not yet integrated with Kix) 
 scorecard    pass    0 errors, 0 warnings, 0 info

To inspect the generated Namespace and ResourceQuota, render the cluster as JSON. The excerpt shows the two relevant resources from the complete build:

Run in kix-examples/ Output excerpt
❱ kix build how-to-composition --output json
[
  {
    "kind": "Namespace",
    "name": "apps",
    "labels": {
      "app.kubernetes.io/managed-by": "kix",
      "kubernetes.io/metadata.name": "apps",
      "platform.example.com/tier": "application"
    },
    "annotations": {
      "kix.run/depends-on": "requires:kda3jwwkcfas7vfwl370cz40wafpbxgb",
      "kix.run/identity-hash": "k2bga9v0b2s1dbzi64nhmlk25v68yxj6",
      "kix.run/package": "_cluster",
      "kix.run/package-namespace": "_cluster",
      "platform.example.com/owner": "platform"
    },
    "hard": null
  },
  {
    "kind": "ResourceQuota",
    "name": "apps-quota",
    "labels": {
      "app.kubernetes.io/managed-by": "kix"
    },
    "annotations": {
      "kix.run/identity-hash": "kda3jwwkcfas7vfwl370cz40wafpbxgb",
      "kix.run/package": "_cluster",
      "kix.run/package-namespace": "_cluster"
    },
    "hard": {
      "requests.cpu": "2",
      "requests.memory": "2Gi"
    }
  }
]

Check the generated resources again after changing a quota or a shared label. This catches invalid package configuration and Kubernetes schema problems before deployment.