Install any skill in seconds. Free to start, no credit card required.
Get Started Free →Configure RBAC and namespace isolation for CoreWeave multi-team GPU access. Use when managing team permissions, isolating GPU quotas, or implementing namespace-level access control. Trigger with phrases like "coreweave rbac", "coreweave permissions", "coreweave namespace isolation", "coreweave team access".
.claude/skills/jeremylongshore-coreweave-enterprise-rbac/SKILL.md| Test case | Without → With | Effect | Δ tokens | Δ turns |
|---|---|---|---|---|
| case-01 | ✗→✓ | ▲ Improved | 1% | 0% |
| case-02 | ✗→✓ | ▲ Improved | -12% | 0% |
| case-03 | ✗→✓ | ▲ Improved | 1% | 0% |
| case-05 | ✗→✓ | ▲ Improved | -27% | 0% |
| case-09 | ✗→✓ | ▲ Improved | -38% | 0% |
> Community-contributed. Not affiliated with, endorsed by, or sponsored by CoreWeave, Inc. CoreWeave is a registered trademark of CoreWeave, Inc.
CoreWeave runs GPU workloads on Kubernetes, so RBAC maps directly to K8s namespace isolation and ResourceQuotas. Each team gets a dedicated namespace with GPU limits, storage caps, and network policies. This prevents noisy-neighbor problems where one team's training job starves another's inference service. SOC 2 and HIPAA workloads require namespace-level audit logging and team-scoped API key rotation.
| Role | Permissions | Scope | |------|------------|-------| | Cluster Admin | Full CKS control, namespace creation, quota management | All namespaces | | Team Lead | Deploy workloads, manage team API keys, adjust pod limits | Own namespace | | ML Engineer | Launch jobs, access PVCs, view logs | Own namespace | | Inference Operator | Deploy/scale inference endpoints, read metrics | Own namespace | | Viewer | Read-only pod status, logs, GPU utilization metrics | Own namespace |
typescriptimport { KubeConfig, RbacAuthorizationV1Api } from '@kubernetes/client-node'; async function checkNamespaceAccess(user: string, namespace: string, verb: string, resource: string): Promise<boolean> { const kc = new KubeConfig(); kc.loadFromDefault(); const rbac = kc.makeApiClient(RbacAuthorizationV1Api); const review = { apiVersion: 'authorization.k8s.io/v1', kind: 'SubjectAccessReview', spec: { user, resourceAttributes: { namespace, verb, resource } } }; const result = await rbac.createSubjectAccessReview(review); return result.body.status?.allowed ?? false; }
typescriptasync function assignTeamNamespace(team: string, group: string, gpuLimit: number): Promise<void> { await kubectl(`create namespace ${team}`); await kubectl(`create resourcequota ${team}-gpu --namespace=${team} --hard=requests.nvidia.com/gpu=${gpuLimit}`); await kubectl(`create rolebinding ${team}-access --namespace=${team} --clusterrole=edit --group=${group}`); console.log(`Namespace ${team} created with ${gpuLimit} GPU quota bound to ${group}`); } async function revokeAccess(team: string, binding: string): Promise<void> { await kubectl(`delete rolebinding ${binding} --namespace=${team}`); }
typescriptinterface CoreWeaveAuditEntry { timestamp: string; user: string; namespace: string; action: 'gpu_request' | 'deploy' | 'scale' | 'delete' | 'quota_change'; resource: string; gpuCount?: number; result: 'allowed' | 'denied'; } function logAccess(entry: CoreWeaveAuditEntry): void { console.log(JSON.stringify({ ...entry, cluster: process.env.CW_CLUSTER_ID })); }
| Issue | Cause | Fix | |-------|-------|-----| | Forbidden: GPU quota exceeded | Namespace quota reached | Increase ResourceQuota or free idle pods | | RoleBinding not found | Group name mismatch with IdP | Verify AD/OIDC group name matches RoleBinding subject | | Namespace not found | Team namespace not provisioned | Run namespace creation script before role assignment | | SubjectAccessReview denied | Missing ClusterRole binding | Check if ClusterRole exists and verb is permitted |
See coreweave-security-basics.
| Case | Status | Duration (ms) | Turns | Tokens | Tool calls | ||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| Without | With | Δ | Without | With | Δ | Without | With | Δ | Without | With | Δ | ||
case-01 | fail→pass | 14,474 | 10,352 | -28% | 1 | 1 | 0% | 3,300 | 3,325 | +1% | 0 | 0 | — |
case-02 | fail→pass | 13,670 | 6,944 | -49% | 1 | 1 | 0% | 2,905 | 2,560 | -12% | 0 | 0 | — |
case-03 | fail→pass | 11,305 | 7,590 | -33% | 1 | 1 | 0% | 2,529 | 2,556 | +1% | 0 | 0 | — |
case-04 | pass→pass | 11,974 | 3,698 | -69% | 1 | 1 | 0% | 2,196 | 1,583 | -28% | 0 | 0 | — |
case-05 | fail→pass | 11,193 | 2,617 | -77% | 1 | 1 | 0% | 2,055 | 1,490 | -27% | 0 | 0 | — |
case-06 | pass→pass | 7,980 | 4,111 | -48% | 1 | 1 | 0% | 1,403 | 1,608 | +15% | 0 | 0 | — |
case-07 | pass→pass | 6,698 | 3,056 | -54% | 1 | 1 | 0% | 1,303 | 1,463 | +12% | 0 | 0 | — |
case-08 | pass→pass | 10,538 | 5,981 | -43% | 1 | 1 | 0% | 1,871 | 1,951 | +4% | 0 | 0 | — |
case-09 | fail→pass | 13,766 | 3,234 | -77% | 1 | 1 | 0% | 2,321 | 1,450 | -38% | 0 | 0 | — |
case-10 | fail→pass | 11,625 | 7,850 | -32% | 1 | 1 | 0% | 2,051 | 2,457 | +20% | 0 | 0 | — |
case-11 | pass→pass | 9,736 | 4,117 | -58% | 1 | 1 | 0% | 1,616 | 1,639 | +1% | 0 | 0 | — |
case-12 | pass→fail | 11,636 | 10,206 | -12% | 1 | 1 | 0% | 2,155 | 2,801 | +30% | 0 | 0 | — |
case-13 | pass→pass | 12,949 | 6,239 | -52% | 1 | 1 | 0% | 2,423 | 2,048 | -15% | 0 | 0 | — |
case-14 | pass→pass | 14,338 | 7,246 | -49% | 1 | 1 | 0% | 2,450 | 2,278 | -7% | 0 | 0 | — |
case-15 | fail→pass | 6,738 | 3,409 | -49% | 1 | 1 | 0% | 1,085 | 1,240 | +14% | 0 | 0 | — |
case-16 | pass→pass | 8,615 | 2,980 | -65% | 1 | 1 | 0% | 1,472 | 1,492 | +1% | 0 | 0 | — |
case-17 | pass→pass | 4,933 | 1,705 | -65% | 1 | 1 | 0% | 748 | 1,260 | +68% | 0 | 0 | — |
case-18 | pass→pass | 11,266 | 5,057 | -55% | 1 | 1 | 0% | 2,360 | 2,027 | -14% | 0 | 0 | — |
case-19 | pass→pass | 13,767 | 11,559 | -16% | 1 | 1 | 0% | 2,702 | 3,195 | +18% | 0 | 0 | — |
case-20 | pass→pass | 16,516 | 12,400 | -25% | 1 | 1 | 0% | 3,210 | 3,485 | +9% | 0 | 0 | — |
case-21 | pass→pass | 16,287 | 12,706 | -22% | 1 | 1 | 0% | 2,989 | 3,347 | +12% | 0 | 0 | — |
case-22 | fail→pass | 10,869 | 2,397 | -78% | 1 | 1 | 0% | 2,007 | 1,298 | -35% | 0 | 0 | — |
case-23 | pass→pass | 7,477 | 3,158 | -58% | 1 | 1 | 0% | 1,475 | 1,629 | +10% | 0 | 0 | — |
DecimalAI ran this skill against gemini-3.6-flash twice over the same eval suite — once with the skill loaded and once without — and compared the two runs case by case. 23 cases were attempted. The headline lift of +30 percentage points is the difference between those two pass rates over the 23 comparable cases. 1 case got worse with the skill loaded, and it is included in that figure.
Without the skill loaded, the model failed this case. With it loaded, the same prompt on the same model passed. This is one improved case from the latest verified run; every case, including any that regressed, is in the table above.
Other measured skills in the registry, with their headline benchmark lift.