Managing Namespaces and Workspace Associations in Tanzu Mission Control Self-Managed
search cancel

Managing Namespaces and Workspace Associations in Tanzu Mission Control Self-Managed

book

Article ID: 436872

calendar_today

Updated On:

Products

VMware vSphere Kubernetes Service

Issue/Introduction

Administrators may want to reorganize their environment by moving namespaces between workspaces or detaching them to change how policies are applied.

 

Unfortunately, namespaces cannot be detached from a workspace, and can only be deleted. 

Environment

Tanzu Mission Control Self-Managed (TMC-SM)

Cause

Managed namespaces are created through the TMC-SM UI or API. These are created and owned by TMC.

Unmanaged namespaces are existing namespaces that are discovered by TMC when a cluster is attached. Unmanaged namespaces are owned by the guest cluster.

 

 

Resolution

In TMC, all namespaces—whether managed or unmanaged—must follow the "No Orphan" Rule. Because governance policies (IAM, Security, Image Registry, etc.) are enforced at the Workspace level, TMC requires every namespace to be associated with a workspace to maintain a valid security posture. Once a namespace has been attached to a workspace, however, the namespace cannot be detached.