Creates one hardened multi-tenant Kubernetes namespace: Pod Security Admission labels, default-deny NetworkPolicy plus named exceptions, ResourceQuota, LimitRange, a non-automounting ServiceAccount, an optional registry Secret passed as a sensitive variable, and namespaced Roles/RoleBindings.
namespacetenantlabelsannotationspod_security_enabledpod_security_levelpod_security_versionresource_quota_enabledresource_quota_hardlimit_range_enabledcontainer_default_limitscontainer_default_requestscontainer_maxcontainer_minpvc_maxpvc_minnetwork_policy_enableddns_namespaceallow_same_namespace_trafficallowed_ingress_namespacesmodule "x" {
source = "./terraform-module-kubernetes-namespace"
}
This page is the working piece. The full pack has everything below.
One terraform apply = 7 hardened objects per tenant namespace. 12 resource blocks, 29 inputs (7 with validation), 13 outputs, 6 copy-paste examples - and none of them default to open network
A rival module on this exact shelf sells at $3 today (measured on the shelf we are entering). No hourly-rate or consultant comparison is quoted here because we have not measured one.
Send it to me