

Kubeflow does not implement its own authentication layer. Instead it integrates with identity providers (Dex is frequently used) and translates external identities into Kubernetes users/groups so that RBAC and namespace isolation can enforce policies.

- Review how authentication works in Kubernetes and how RBAC and namespaces enforce access.
- Explain how Kubeflow integrates with identity providers (commonly Dex — https://dexidp.io) to manage user identities.
- Show how users are represented and granted access inside Kubernetes namespaces.
- Demonstrate how Kubeflow Profiles create secure, isolated workspaces for each user backed by dedicated namespaces, resource quotas, and role-based permissions.
- Prevents accidental or malicious access to other users’ notebooks, datasets, or GPUs.
- Enables predictable resource allocation (quotas for CPU, memory, GPU, and storage).
- Gives administrators fine-grained control using RBAC policies and namespace scoping.
Links and references
- Kubernetes Authentication Concepts
- Kubernetes RBAC
- Dex Identity Provider
- Kubeflow Documentation — Multi-User and Profiles
As you continue, keep these terms in mind:
authentication (who you are), authorization (what you can do), and isolation (what resources you can see and use). Kubeflow ties these together so multiple users can safely share a cluster.