---
title: "Multitenancy"
description: "Policies for enforcing namespace isolation and multi-tenant Kubernetes cluster standards. Require resource quotas, network policies, and namespace-level guardrails."
diataxis: reference
applies_to:
  product: "kyverno"
audience: ["platform-engineer","devsecops"]
last_updated: 2026-03-25
url: https://docs.nirmata.io/docs/policy-sets/multitenancy/
---


Kyverno policies for enforcing multi-tenant cluster security and isolation standards.

## What's Covered

- **Namespace resource quotas** — Require ResourceQuota on every namespace
- **LimitRange enforcement** — Ensure default limits are set per namespace
- **Network isolation** — Require a default-deny NetworkPolicy in each namespace
- **Tenant labeling** — Enforce required labels for tenant identification

All multitenancy policies are available in the [Nirmata policy library on GitHub](https://github.com/nirmata/kyverno-policies/tree/main/multitenancy-benchmarks).


