Namespace isolation

Namespaces organise resources and are not a security boundary on their own.

They separate names, not capabilities. Without network policy, role bindings and resource limits deliberately applied, workloads in different namespaces can frequently reach each other and the same nodes. Treating a namespace as a tenancy boundary without those additions is a common and incorrect assumption.

Checked against the primary source.

More on Containers & Kubernetes