CoreWeave Enterprise RBAC
SkillDev tools'Configure RBAC and namespace isolation for CoreWeave multi-team GPU
Use CoreWeave Enterprise RBAC in Claude, ChatGPT or Ahel Desktop
Free. Sign in, add CoreWeave Enterprise RBAC and connect your AI. About a minute.
Also: Claude Code · Cursor · Codex
Then ask your AI: use the CoreWeave Enterprise RBAC skill
Details
Instructions available. Your AI can read the instructions. Execution depends on the setup they require.
Account requirements not reviewed. Check the skill instructions before use; Ahel provides instructions and does not run this skill.
No other account needed.
Add Ahel to your AI once: Claude, ChatGPT, Cursor, Claude Code or Codex. Then ask it to use this.
What this skill tells your AI
The instructions your AI receives, as published by jeremylongshore/tons-of-skills-marketplace in skills/.curated/coreweave-enterprise-rbac/SKILL.md and read by Ahel’s review.
Community-contributed. Not affiliated with, endorsed by, or sponsored by CoreWeave, Inc. CoreWeave is a registered trademark of CoreWeave, Inc.
Overview
CoreWeave runs GPU workloads on Kubernetes, so RBAC maps directly to K8s namespace isolation and ResourceQuotas. Each team gets a dedicated namespace with GPU limits, storage caps, and network policies. This prevents noisy-neighbor problems where one team's training job starves another's inference service. SOC 2 and HIPAA workloads require namespace-level audit logging and team-scoped API key rotation.
Prerequisites
- A verified human or workload identity group from the organization identity provider.
- Cluster-admin approval for namespace, quota, and RoleBinding changes.
- A team owner, approved GPU quota, and data-classification decision for the namespace.
Instructions
- Create a namespace per team and apply ResourceQuota and NetworkPolicy before granting workload permissions.
- Bind an IdP group to the smallest suitable ClusterRole; do not bind individual
users or reuse a cluster-wide
editrole without a documented exception. - Run a SubjectAccessReview for the intended verbs and resources, then retain the redacted decision and audit entry with the access request.
- Review bindings and service-account tokens on a regular schedule; remove access promptly when a team, project, or incident requires it.
Role Hierarchy
| Role | Permissions | Scope |
|---|---|---|
| Cluster Admin | Full CKS control, namespace creation, quota management | All namespaces |
| Team Lead | Deploy workloads, manage team API keys, adjust pod limits | Own namespace |
| ML Engineer | Launch jobs, access PVCs, view logs | Own namespace |
| Inference Operator | Deploy/scale inference endpoints, read metrics | Own namespace |
| Viewer | Read-only pod status, logs, GPU utilization metrics | Own namespace |
Permission Check
import { KubeConfig, RbacAuthorizationV1Api } from '@kubernetes/client-node';
async function checkNamespaceAccess(user: string, namespace: string, verb: string, resource: string): Promise<boolean> {
const kc = new KubeConfig();
kc.loadFromDefault();
const rbac = kc.makeApiClient(RbacAuthorizationV1Api);
const review = { apiVersion: 'authorization.k8s.io/v1', kind: 'SubjectAccessReview',
spec: { user, resourceAttributes: { namespace, verb, resource } } };
const result = await rbac.createSubjectAccessReview(review);
return result.body.status?.allowed ?? false;
}
Role Assignment
async function assignTeamNamespace(team: string, group: string, gpuLimit: number): Promise<void> {
await kubectl(`create namespace ${team}`);
await kubectl(`create resourcequota ${team}-gpu --namespace=${team} --hard=requests.nvidia.com/gpu=${gpuLimit}`);
await kubectl(`create rolebinding ${team}-access --namespace=${team} --clusterrole=edit --group=${group}`);
console.log(`Namespace ${team} created with ${gpuLimit} GPU quota bound to ${group}`);
}
async function revokeAccess(team: string, binding: string): Promise<void> {
await kubectl(`delete rolebinding ${binding} --namespace=${team}`);
}
Audit Logging
interface CoreWeaveAuditEntry {
timestamp: string; user: string; namespace: string;
action: 'gpu_request' | 'deploy' | 'scale' | 'delete' | 'quota_change';
resource: string; gpuCount?: number; result: 'allowed' | 'denied';
}
function logAccess(entry: CoreWeaveAuditEntry): void {
console.log(JSON.stringify({ ...entry, cluster: process.env.CW_CLUSTER_ID }));
}
RBAC Checklist
- Each team has a dedicated namespace with ResourceQuota
- GPU limits set per namespace to prevent resource starvation
- RoleBindings use AD/OIDC groups, not individual users
- Network policies isolate namespace traffic
- API keys scoped to team namespace, rotated quarterly
- Viewer role assigned to finance/management for cost visibility
- Audit logging enabled for all GPU allocation events
Error Handling
| Issue | Cause | Fix |
|---|---|---|
Forbidden: GPU quota exceeded | Namespace quota reached | Increase ResourceQuota or free idle pods |
RoleBinding not found | Group name mismatch with IdP | Verify AD/OIDC group name matches RoleBinding subject |
Namespace not found | Team namespace not provisioned | Run namespace creation script before role assignment |
SubjectAccessReview denied | Missing ClusterRole binding | Check if ClusterRole exists and verb is permitted |
Output
- An isolated team namespace with an enforced GPU quota and network boundary.
- Least-privilege group bindings with a recorded access review and audit trail.
- A repeatable revocation path for a compromised identity or completed project.
Examples
Confirm a deployment identity can create Jobs only in its team namespace before releasing a workload:
kubectl auth can-i create jobs.batch \
--as=system:serviceaccount:research:trainer \
--namespace=research
kubectl auth can-i create jobs.batch \
--as=system:serviceaccount:research:trainer \
--namespace=production
The expected result is yes only for research. If the second check is allowed,
remove the over-broad binding, re-run both checks, and preserve the redacted audit
record before resuming deployments.
Resources
Next Steps
See coreweave-security-basics.
Signals
- GitHub stars
- 3k
- Forks
- 415
- Last commit
- Oct 2026
Advanced
- Item type
- skill
- Key
coreweave-enterprise-rbac- Source
- github.com/jeremylongshore/tons-of-skills-marketplace
github.com/jeremylongshore/tons-of-skills-marketplace
Related picks
Skill · mattpocock
The pick for TypeScripttypescript-pro
Skill · jeffallan
The pick for TypeScriptazure-kubernetes
Skill · microsoft
The pick for Kubernetesdt-obs-kubernetes
Skill · dynatrace
The pick for Kubernetesinfra-containers-kubernetes
Skill · agents-inc
The pick for Kubernetesteach
Skill · mattpocock
More in Dev tools