Skip to content
OpenSmartRoute
Skillv1.0.0

coreweave-enterprise-rbac

Configure RBAC and namespace isolation for CoreWeave multi-team GPU access. Use when managing team permissions, isolating GPU quotas, or implementing namespace-level access control. Trigger with phras

by jeremylongshore(0) 0 installs
Free
Sign in to install

Free account. Installing gives you the manifest plus copy-paste snippets.

See reviews

About

Imported from jeremylongshore/tons-of-skills-marketplace (plugins/saas-packs/coreweave-pack/skills/coreweave-enterprise-rbac/SKILL.md). Install upstream with npx skills add jeremylongshore/tons-of-skills-marketplace --skill coreweave-enterprise-rbac. Copyright stays with the author (MIT).

CoreWeave Enterprise RBAC

Community-contributed. Not affiliated with, endorsed by, or sponsored by CoreWeave, Inc. CoreWeave is a registered trademark of CoreWeave, Inc.

Overview

CoreWeave runs GPU workloads on Kubernetes, so RBAC maps directly to K8s namespace isolation and ResourceQuotas. Each team gets a dedicated namespace with GPU limits, storage caps, and network policies. This prevents noisy-neighbor problems where one team's training job starves another's inference service. SOC 2 and HIPAA workloads require namespace-level audit logging and team-scoped API key rotation.

Prerequisites

  • A verified human or workload identity group from the organization identity provider.
  • Cluster-admin approval for namespace, quota, and RoleBinding changes.
  • A team owner, approved GPU quota, and data-classification decision for the namespace.

Instructions

  1. Create a namespace per team and apply ResourceQuota and NetworkPolicy before granting workload permissions.
  2. Bind an IdP group to the smallest suitable ClusterRole; do not bind individual users or reuse a cluster-wide edit role without a documented exception.
  3. Run a SubjectAccessReview for the intended verbs and resources, then retain the redacted decision and audit entry with the access request.
  4. Review bindings and service-account tokens on a regular schedule; remove access promptly when a team, project, or incident requires it.

Role Hierarchy

Role Permissions Scope
Cluster Admin Full CKS control, namespace creation, quota management All namespaces
Team Lead Deploy workloads, manage team API keys, adjust pod limits Own namespace
ML Engineer Launch jobs, access PVCs, view logs Own namespace
Inference Operator Deploy/scale inference endpoints, read metrics Own namespace
Viewer Read-only pod status, logs, GPU utilization metrics Own namespace

Permission Check

import { KubeConfig, RbacAuthorizationV1Api } from '@kubernetes/client-node';

async function checkNamespaceAccess(user: string, namespace: string, verb: string, resource: string): Promise<boolean> {
  const kc = new KubeConfig();
  kc.loadFromDefault();
  const rbac = kc.makeApiClient(RbacAuthorizationV1Api);
  const review = { apiVersion: 'authorization.k8s.io/v1', kind: 'SubjectAccessReview',
    spec: { user, resourceAttributes: { namespace, verb, resource } } };
  const result = await rbac.createSubjectAccessReview(review);
  return result.body.status?.allowed ?? false;
}

Role Assignment

async function assignTeamNamespace(team: string, group: string, gpuLimit: number): Promise<void> {
  await kubectl(`create namespace ${team}`);
  await kubectl(`create resourcequota ${team}-gpu --namespace=${team} --hard=requests.nvidia.com/gpu=${gpuLimit}`);
  await kubectl(`create rolebinding ${team}-access --namespace=${team} --clusterrole=edit --group=${group}`);
  console.log(`Namespace ${team} created with ${gpuLimit} GPU quota bound to ${group}`);
}

async function revokeAccess(team: string, binding: string): Promise<void> {
  await kubectl(`delete rolebinding ${binding} --namespace=${team}`);
}

Audit Logging

interface CoreWeaveAuditEntry {
  timestamp: string; user: string; namespace: string;
  action: 'gpu_request' | 'deploy' | 'scale' | 'delete' | 'quota_change';
  resource: string; gpuCount?: number; result: 'allowed' | 'denied';
}

function logAccess(entry: CoreWeaveAuditEntry): void {
  console.log(JSON.stringify({ ...entry, cluster: process.env.CW_CLUSTER_ID }));
}

RBAC Checklist

  • Each team has a dedicated namespace with ResourceQuota
  • GPU limits set per namespace to prevent resource starvation
  • RoleBindings use AD/OIDC groups, not individual users
  • Network policies isolate namespace traffic
  • API keys scoped to team namespace, rotated quarterly
  • Viewer role assigned to finance/management for cost visibility
  • Audit logging enabled for all GPU allocation events

Error Handling

Issue Cause Fix
Forbidden: GPU quota exceeded Namespace quota reached Increase ResourceQuota or free idle pods
RoleBinding not found Group name mismatch with IdP Verify AD/OIDC group name matches RoleBinding subject
Namespace not found Team namespace not provisioned Run namespace creation script before role assignment
SubjectAccessReview denied Missing ClusterRole binding Check if ClusterRole exists and verb is permitted

Output

  • An isolated team namespace with an enforced GPU quota and network boundary.
  • Least-privilege group bindings with a recorded access review and audit trail.
  • A repeatable revocation path for a compromised identity or completed project.

Examples

Confirm a deployment identity can create Jobs only in its team namespace before releasing a workload:

kubectl auth can-i create jobs.batch \
  --as=system:serviceaccount:research:trainer \
  --namespace=research
kubectl auth can-i create jobs.batch \
  --as=system:serviceaccount:research:trainer \
  --namespace=production

The expected result is yes only for research. If the second check is allowed, remove the over-broad binding, re-run both checks, and preserve the redacted audit record before resuming deployments.

Resources

Next Steps

See coreweave-security-basics.

Use it

Copy one of these into your project. Installing also returns the manifest and these snippets.

yaml
targets:
  - https://api.opensmartroute.ai/api/v1/registry/jeremylongshore-tons-of-skills-marketplace-coreweave-ent-b84313/manifest   # or paste the manifest below

Manifest

An Open Capability Manifest: the router reads it to know what this does, what it costs and when to pick it.

jeremylongshore-tons-of-skills-marketplace-coreweave-ent-b84313.ocm.jsonjson
{
  "ocm": "1",
  "id": "jeremylongshore-tons-of-skills-marketplace-coreweave-ent-b84313",
  "kind": "skill",
  "name": "coreweave-enterprise-rbac",
  "description": "Configure RBAC and namespace isolation for CoreWeave multi-team GPU access. Use when managing team permissions, isolating GPU quotas, or implementing namespace-level access control. Trigger with phrases like \"coreweave rbac\", \"coreweave permissions\", \"coreweave namespace isolation\", \"coreweave team access\".",
  "publisher": "jeremylongshore",
  "version": "1.0.0",
  "capabilities": {
    "domains": [
      "general"
    ],
    "tags": [
      "skill-md",
      "saas",
      "gpu-cloud",
      "kubernetes",
      "inference",
      "coreweave",
      "skills-sh"
    ],
    "languages": [
      "en"
    ]
  },
  "quality_prior": 0.6,
  "examples": [
    "Configure RBAC and namespace isolation for CoreWeave multi-team GPU access. Use when managing team permissions, isolating GPU quotas, or implementing namespace-level access control. Trigger with phrases like \"coreweave rbac\", \"coreweave permissions\", \"coreweave namespace isolation\", \"coreweave team access\"."
  ],
  "primary": false,
  "metadata": {
    "source": {
      "provider": "skills.sh",
      "repository": "https://github.com/jeremylongshore/tons-of-skills-marketplace",
      "path": "plugins/saas-packs/coreweave-pack/skills/coreweave-enterprise-rbac/SKILL.md",
      "ref": "HEAD",
      "url": "https://github.com/jeremylongshore/tons-of-skills-marketplace/blob/HEAD/plugins/saas-packs/coreweave-pack/skills/coreweave-enterprise-rbac/SKILL.md",
      "key": "jeremylongshore/tons-of-skills-marketplace/plugins/saas-packs/coreweave-pack/skills/coreweave-enterprise-rbac/SKILL.md"
    },
    "compatibility": "Designed for Claude Code",
    "allowed_tools": [
      "Read,",
      "Write,",
      "Edit,",
      "Bash(kubectl:*),",
      "Grep"
    ],
    "license": "MIT"
  },
  "instructions": "# CoreWeave Enterprise RBAC\n\n> **Community-contributed.** Not affiliated with, endorsed by, or sponsored by CoreWeave, Inc. CoreWeave is a registered trademark of CoreWeave, Inc.\n\n## Overview\n\nCoreWeave runs GPU workloads on Kubernetes, so RBAC maps directly to K8s namespace isolation and ResourceQuotas. Each team gets a dedicated namespace with GPU limits, storage caps, and network policies. This prevents noisy-neighbor problems where one team's training job starves another's inference service. SOC 2 and HIPAA workloads require namespace-level audit logging and team-scoped API key rotation.\n\n",
  "cost": {
    "context_tokens": 1399
  }
}

Fetch it by URL: GET /api/v1/registry/jeremylongshore-tons-of-skills-marketplace-coreweave-ent-b84313/manifest?version=1.0.0

Reviews

Star ratings from people who tried it. One review per account; edit yours any time.

No reviews yet. Install it, try it, and be the first to rate it.