Multi-tenant Kubernetes namespaces created hardened by default: Pod Security Admission labels, ResourceQuota, LimitRange, default-deny NetworkPolicy with DNS still working, no-automount ServiceAccount, namespace-scoped RBAC, and one audit_evidence output for the reviewer.
namespacescommon_labelscommon_annotationspod_security_versiondns_namespacedns_pod_labelsdeployer_subjectsviewer_subjectsdeployer_can_read_secretsimage_pull_secretimage_pull_secret_namemodule "x" {
source = "./terraform-module-kubernetes"
}
This page is the working piece. The full pack has everything below.
9 environment x workload presets. 14 Kubernetes objects per tenant, from two words per tenant.
Checkable without trusting us: the module validates against the real provider schema (terraform validate passed with hashicorp/kubernetes), and the four kubectl commands in the README verify every promise against your own cluster
Buy the full version — $3