An environment for Kubernetes training
The lab topology follows from the scope of the exercises. For work with Deployment, Service and Ingress, a shared cluster with a separate namespace for each participant is usually enough. Exercises involving the control plane, worker nodes or cluster failures require separate clusters or sets of VMs.
A namespace organises objects and sets the scope of some policies, but it is not a security boundary on its own. Participants still share the API server, the nodes, storage and cluster-scoped resources. We restrict access with RoleBinding, and the use of CPU, memory and object counts with ResourceQuota and LimitRange. NetworkPolicy works only if the CNI plugin in use supports it.
Before launch we run through the whole set of exercises from a participant account. The test covers registry access, PVC provisioning, DNS, Ingress, resource limits and Helm operations. Separately, we verify the environment reset and confirm that a participant cannot read objects in other namespaces or create cluster-scoped resources.
Configuration
Each participant receives their own namespace, ServiceAccount, RoleBinding and kubeconfig. ResourceQuota and LimitRange enforce the agreed requests and limits. The Kubernetes, kubectl and Helm versions match the course materials, and images are pulled in advance from the appropriate registry. We enable StorageClass, IngressClass and NetworkPolicy only when they appear in the scenario.
Technical scope
The scope may cover Deployment, StatefulSet, ConfigMap, Secret, probes, Service, Ingress and PVC. Participants diagnose a rollout through Events, logs and the state of Pod and EndpointSlice objects. In the Helm part they analyse the rendered manifest, override values and roll back a specific release.
Outcome and limitations
A shared baseline removes differences in API versions and client configuration. RBAC, quota and NetworkPolicy limit how participants affect one another, but they do not provide isolation equivalent to a separate cluster. Tasks that require cluster-admin are carried out only in a dedicated environment.