> ## Documentation Index
> Fetch the complete documentation index at: https://notes.kodekloud.com/llms.txt
> Use this file to discover all available pages before exploring further.

# Section Introduction

> Explains how Kubeflow uses external authentication, RBAC, and Profiles to provide secure multi-user isolation and per-user namespaces on Kubernetes

Before we start working with [Kubeflow](https://learn.kodekloud.com/user/courses/kubeflow) as a machine learning platform, we first need to understand how user access and security are managed inside a [Kubernetes](https://learn.kodekloud.com/user/courses/kubernetes-for-the-absolute-beginners-hands-on-tutorial) environment.

Imagine an organization where multiple data scientists, ML engineers, and researchers share the same Kubernetes cluster. Without proper authentication and isolation, permissions and resources quickly become chaotic: users might access each other's notebooks or datasets, GPUs and storage are hard to allocate securely, and administrators have little control over who can do what.

<Frame>
  <img src="https://mintcdn.com/kodekloud-c4ac6d9a/MGkgrGfKHDtoCnUb/images/Kubeflow/Profiles-and-Multi-Tenancy/Section-Introduction/shared-kubernetes-cluster-no-auth-isolation.jpg?fit=max&auto=format&n=MGkgrGfKHDtoCnUb&q=85&s=7fa6131f92c110820e71c2b4ef63c369" alt="A slide titled &#x22;The Problem&#x22; showing data scientists, ML engineers, and researchers sharing a Kubernetes cluster labeled &#x22;No auth / No isolation.&#x22; The diagram highlights issues: users can access each other's notebooks and data, GPUs and storage are hard to manage, and there is no permission control." width="1920" height="1080" data-path="images/Kubeflow/Profiles-and-Multi-Tenancy/Section-Introduction/shared-kubernetes-cluster-no-auth-isolation.jpg" />
</Frame>

Modern ML platforms run many users on shared Kubernetes infrastructure, so they must provide secure authentication, isolated user workspaces, role-based access control (RBAC), and multi-user isolation to operate safely and predictably.

<Frame>
  <img src="https://mintcdn.com/kodekloud-c4ac6d9a/MGkgrGfKHDtoCnUb/images/Kubeflow/Profiles-and-Multi-Tenancy/Section-Introduction/secure-auth-user-workspaces-rolebased-isolation.jpg?fit=max&auto=format&n=MGkgrGfKHDtoCnUb&q=85&s=c4d0bf552d0c40805505d155465dae88" alt="A presentation slide titled &#x22;The Problem&#x22; showing four colored panels for Secure Authentication, User-Specific Workspaces, Role-Based Access Control, and Multi-User Isolation, each with a simple icon and brief explanatory text." width="1920" height="1080" data-path="images/Kubeflow/Profiles-and-Multi-Tenancy/Section-Introduction/secure-auth-user-workspaces-rolebased-isolation.jpg" />
</Frame>

Kubernetes authentication verifies identities and establishes who is making requests to the API server. RBAC and namespaces are then used to enforce what those authenticated users may do and which resources they can access. Kubeflow builds on these primitives: it delegates identity management to an identity provider (commonly Dex — [https://dexidp.io](https://dexidp.io)), maps identities to Kubernetes subjects, and uses Kubeflow Profiles to provision per-user isolated workspaces.

<Callout icon="lightbulb" color="#1CB2FE">
  Kubeflow does not implement its own authentication layer. Instead it integrates with identity providers (Dex is frequently used) and translates external identities into Kubernetes users/groups so that RBAC and namespace isolation can enforce policies.
</Callout>

<Frame>
  <img src="https://mintcdn.com/kodekloud-c4ac6d9a/MGkgrGfKHDtoCnUb/images/Kubeflow/Profiles-and-Multi-Tenancy/Section-Introduction/kubernetes-authentication-kubeflow-dex-profiles.jpg?fit=max&auto=format&n=MGkgrGfKHDtoCnUb&q=85&s=3d00e6db000605da1b61d5cf255e4fb7" alt="A presentation slide titled &#x22;What We Will Cover&#x22; with a vertical timeline of four numbered topics. The topics list authentication in Kubernetes, how Kubeflow manages users securely, the role of Dex in authentication, and Kubeflow profiles/namespace isolation." width="1920" height="1080" data-path="images/Kubeflow/Profiles-and-Multi-Tenancy/Section-Introduction/kubernetes-authentication-kubeflow-dex-profiles.jpg" />
</Frame>

In this lesson/article we will:

* Review how authentication works in [Kubernetes](https://learn.kodekloud.com/user/courses/kubernetes-for-the-absolute-beginners-hands-on-tutorial) and how RBAC and namespaces enforce access.
* Explain how [Kubeflow](https://learn.kodekloud.com/user/courses/kubeflow) integrates with identity providers (commonly Dex — [https://dexidp.io](https://dexidp.io)) to manage user identities.
* Show how users are represented and granted access inside Kubernetes namespaces.
* Demonstrate how Kubeflow Profiles create secure, isolated workspaces for each user backed by dedicated namespaces, resource quotas, and role-based permissions.

Why this matters

* Prevents accidental or malicious access to other users’ notebooks, datasets, or GPUs.
* Enables predictable resource allocation (quotas for CPU, memory, GPU, and storage).
* Gives administrators fine-grained control using RBAC policies and namespace scoping.

Key concepts at a glance:

| Concept | Kubernetes primitive | How Kubeflow uses it |
| - | - | - |
| Authentication | External identity provider (OIDC/Dex) | Delegates login to Dex; maps identities to Kubernetes subjects |
| Authorization | RBAC (Roles & RoleBindings) | Grants permissions to users/groups for actions inside namespaces |
| Isolation | Namespaces + resource quotas | Kubeflow Profiles provision per-user namespaces with quotas and bindings |

Links and references

* [Kubernetes Authentication Concepts](https://kubernetes.io/docs/reference/access-authn-authz/authentication/)
* [Kubernetes RBAC](https://kubernetes.io/docs/reference/access-authn-authz/rbac/)
* [Dex Identity Provider](https://dexidp.io)
* [Kubeflow Documentation — Multi-User and Profiles](https://www.kubeflow.org/docs/components/multi-user-overview/)

<Callout icon="lightbulb" color="#1CB2FE">
  As you continue, keep these terms in mind: `authentication` (who you are), `authorization` (what you can do), and `isolation` (what resources you can see and use). Kubeflow ties these together so multiple users can safely share a cluster.
</Callout>

<CardGroup>
  <Card title="Watch Video" icon="video" cta="Learn more" href="https://learn.kodekloud.com/user/courses/kubeflow/module/ba7a7596-0520-4e6b-b3ff-5838082881a0/lesson/42b98ed9-c6d7-48b8-bd1e-6525c55b2c86" />
</CardGroup>


This documentation is built and hosted on [Mintlify](https://mintlify.com), a developer documentation platform.