agentsclimarketplace

Coreweave enterprise rbac

Skill jeremylongshore/claude-code-plugins-plus-skills/plugins/saas-packs/coreweave-pack/skills/coreweave-enterprise-rbac

425 plugins, 2,810 skills, 200 agents for Claude Code. Open-source marketplace at tonsofskills.com with the ccpi CLI package manager.

Install
npx -y skills add jeremylongshore/claude-code-plugins-plus-skills --skill coreweave-enterprise-rbac

Assembled from the repository path, not quoted from the project. Check it against their README if it does not work.

What its author says it does

Copied from the file, not written here

'Configure RBAC and namespace isolation for CoreWeave multi-team GPU access.

The file declares its own license as MIT. That is the author’s claim about this one file, and it is not the same thing as the license GitHub reports for the repository, which is listed with the other numbers below.

SKILL.md

4.5 KB, as published. Nobody here has run it

CoreWeave Enterprise RBAC

Community-contributed. Not affiliated with, endorsed by, or sponsored by CoreWeave, Inc. CoreWeave is a registered trademark of CoreWeave, Inc.

Overview

CoreWeave runs GPU workloads on Kubernetes, so RBAC maps directly to K8s namespace isolation and ResourceQuotas. Each team gets a dedicated namespace with GPU limits, storage caps, and network policies. This prevents noisy-neighbor problems where one team's training job starves another's inference service. SOC 2 and HIPAA workloads require namespace-level audit logging and team-scoped API key rotation.

Role Hierarchy

RolePermissionsScope
Cluster AdminFull CKS control, namespace creation, quota managementAll namespaces
Team LeadDeploy workloads, manage team API keys, adjust pod limitsOwn namespace
ML EngineerLaunch jobs, access PVCs, view logsOwn namespace
Inference OperatorDeploy/scale inference endpoints, read metricsOwn namespace
ViewerRead-only pod status, logs, GPU utilization metricsOwn namespace

Permission Check

import { KubeConfig, RbacAuthorizationV1Api } from '@kubernetes/client-node';

async function checkNamespaceAccess(user: string, namespace: string, verb: string, resource: string): Promise<boolean> {
  const kc = new KubeConfig();
  kc.loadFromDefault();
  const rbac = kc.makeApiClient(RbacAuthorizationV1Api);
  const review = { apiVersion: 'authorization.k8s.io/v1', kind: 'SubjectAccessReview',
    spec: { user, resourceAttributes: { namespace, verb, resource } } };
  const result = await rbac.createSubjectAccessReview(review);
  return result.body.status?.allowed ?? false;
}

Role Assignment

async function assignTeamNamespace(team: string, group: string, gpuLimit: number): Promise<void> {
  await kubectl(`create namespace ${team}`);
  await kubectl(`create resourcequota ${team}-gpu --namespace=${team} --hard=requests.nvidia.com/gpu=${gpuLimit}`);
  await kubectl(`create rolebinding ${team}-access --namespace=${team} --clusterrole=edit --group=${group}`);
  console.log(`Namespace ${team} created with ${gpuLimit} GPU quota bound to ${group}`);
}

async function revokeAccess(team: string, binding: string): Promise<void> {
  await kubectl(`delete rolebinding ${binding} --namespace=${team}`);
}

Audit Logging

interface CoreWeaveAuditEntry {
  timestamp: string; user: string; namespace: string;
  action: 'gpu_request' | 'deploy' | 'scale' | 'delete' | 'quota_change';
  resource: string; gpuCount?: number; result: 'allowed' | 'denied';
}

function logAccess(entry: CoreWeaveAuditEntry): void {
  console.log(JSON.stringify({ ...entry, cluster: process.env.CW_CLUSTER_ID }));
}

RBAC Checklist

  • Each team has a dedicated namespace with ResourceQuota
  • GPU limits set per namespace to prevent resource starvation
  • RoleBindings use AD/OIDC groups, not individual users
  • Network policies isolate namespace traffic
  • API keys scoped to team namespace, rotated quarterly
  • Viewer role assigned to finance/management for cost visibility
  • Audit logging enabled for all GPU allocation events

Error Handling

IssueCauseFix
Forbidden: GPU quota exceededNamespace quota reachedIncrease ResourceQuota or free idle pods
RoleBinding not foundGroup name mismatch with IdPVerify AD/OIDC group name matches RoleBinding subject
Namespace not foundTeam namespace not provisionedRun namespace creation script before role assignment
SubjectAccessReview deniedMissing ClusterRole bindingCheck if ClusterRole exists and verb is permitted

Resources

Next Steps

See coreweave-security-basics.

Keep looking

Skills are one crate of 328,083. Ordering is by how many stacks a row turns up in, so the top of any crate is what has actually been picked rather than what has the most stars.