MANAGED KUBERNETES

Ship managed Kubernetes as a product.

Give every customer and every internal team a real, conformant Kubernetes cluster, with its own control plane, its own nodes, and its own admin rights, on infrastructure you own and operate.

Powering managed Kubernetes for AI clouds and AI factories
THE PROBLEM

Managed Kubernetes is easy to demo and brutal to operate.

OPTION A
A namespace is not a cluster

Tenants need their own CRDs, operators, and API versions.

OPTION B
A cluster each does not scale

Every control plane is another thing to patch, monitor, and pay for.

EITHER WAY
Your platform is showing

kubectl get nodes exposes your nodes, your agents, and everyone else’s infrastructure.

You need cluster-grade isolation with namespace-grade economics.

A virtualized control plane per tenant. One fleet and one pool of hardware for you.

Isolation Model

Virtual control planes, real isolation.

Choose the control plane deployment model that fits your infrastructure.

Control Planes as Pods
Deploy vCluster Standalone on a few bare metal CPU machines as your Control Plane Cluster
  • Faster spin up time
  • Less resources needed
  • Manage tenant control planes the Kubernetes-native way
Control Planes on VMs
Connect any VM provisioning tool to vCluster Platform or let vCluster Platform spin up a KubeVirt cluster
  • OS-level separation between every tenant
  • Built for strict compliance requirements
  • Works with KubeVirt or any VM provisioner

Choose the workload isolation model that matches your security and cost requirements.

Private Nodes
Reserve physical nodes, including GPUs, exclusively per tenant
  • Dedicated nodes with no hardware sharing between tenants
  • Full GPU memory isolation, no noisy-neighbor interference
  • Meets the strictest compliance and data residency requirements
Shared Nodes
Run tenant workloads on shared infra with namespace-level guardrails
  • Maximum tenant density on shared infrastructure
  • Namespace isolation with network policies and resource quotas
  • Lower cost per tenant
Harden control plane pods and workloads

Combine with vNode for runtime-level isolation, or pair with gVisor or Kata Containers. Blocks container escapes and kernel exploits at the node level.

TENANT VISIBILITY

Your tenants see only their cluster.
Nothing else.

Most Kubernetes platforms expose control plane nodes, platform agents, and other tenants’ infrastructure to every tenant. vCluster virtualizes the control plane entirely, reducing your risk as a platform operator and giving your tenants the clean, isolated experience they’d get from a hyperscaler.

TENANT EXPERIENCE

A cluster that behaves like a cluster.

No shims, no restricted API subset, no “you can’t install that here.”

Conformant Kubernetes

kubectl, Helm, Argo CD, and every operator, unmodified.

Their own control plane

Dedicated api-server, scheduler, and datastore per tenant.

Admin rights, safely

Install CRDs, register webhooks, hold cluster-admin.

Version choice per tenant

Different Kubernetes versions side by side.

Private nodes, including GPUs

Dedicated bare metal or GPU nodes. No noisy neighbors.

Their networking and storage

On private nodes, their own CNI and CSI.

OPERATOR EXPERIENCE

Fleet operations that stay flat as you add tenants.

Your hundredth tenant should cost what your tenth did.

Provision in seconds

Seconds, not the tens of minutes a full cluster takes.

One console for the fleet

Every tenant cluster in one console. RBAC, SSO, and audit built in.

Density that tracks real usage

Pack many control planes onto one cluster. Sleep the idle ones.

Upgrades you control

Roll versions per tenant, per cohort, or fleet-wide.

Quotas, cost, and chargeback

Per-tenant limits and usage data, GPU hours included.

API and GitOps first

Every cluster is a Kubernetes resource. Terraform, Argo CD, your portal.

FLEET MANAGEMENT

Your fleet is a Git repo, not a runbook.

vCluster Platform registers every tenant cluster with Argo CD or Akuity automatically.

Clusters register themselves

Reference a connector by name. Delete the cluster and Platform deregisters it.

Applications ship with the cluster

ArgoCDApplication and ArgoCDApplicationTemplate live in the tenant’s own vcluster.yaml. Workloads land on day 0.

One template, the whole fleet

Define once, reference everywhere. A version bump reaches every cluster on the next sync.

Private clusters included

A tenant’s API server never has to be reachable from Argo CD.

# vcluster.yaml
# the cluster and what runs in it, together
argoCD:
  applications:
    name: monitoring
    target: vcluster
    template:
      name: base-observability
    name: gpu-operator
    target: vcluster
    template:
      name: nvidia-gpu-operator
# app-template.yaml
# defined once, referenced by every tenant
kind: ArgoCDApplicationTemplate
metadata:
  name: base-observability
spec:
  template:
    spec:
      source:
        repoURL: "https://github.com/acme/charts"
        targetRevision: "main"
        path: observability
      syncPolicy:
        automated:
          prune: true
          selfHeal: true
Bump targetRevision once. Every tenant picks it up on the next sync.
DAY 2 AND BEYOND

Nothing breaks on day one.
It breaks on day two hundred.

Launch is the easy part. What decides whether a managed Kubernetes offering survives is the load that accumulates behind it.

Every tenant needs a control plane, nodes, and a network.
Virtualized control planes in seconds, private nodes attached per tenant.
Nodes fail, tenants resize, someone needs a restore.
Add, drain, and retire nodes per tenant. Snapshot and restore one cluster.
Tenants sit on different versions and nobody agrees on a window.
Roll versions per tenant or per cohort. HA control planes self-heal.
Config drift, no per-tenant audit trail, unclear cost per customer.
One vcluster.yaml in Git. Per-tenant metrics, audit, and usage.

“Do we spend multiple millions getting a Kubernetes stack up and running on our own, or do we partner with a firm that has actually done this before?”

Harry Georgakopoulos

Harry Georgakopoulos
COO, Boost Run

PROOF

The best in the industry trust vCluster.

NVIDIA Preferred Cloud Service Provider delivering enterprise-grade GPU infrastructure across multiple U.S. data centers.

SOC 2
ISO 27001
ISO 27701
HIPAA
View case study
<45

Days from decision
to production launch

0

New platform engineering
hires required

Boost Run took a GPU-native managed Kubernetes service to market on bare metal, using the Private Nodes model for dedicated GPU isolation per tenant and Netris for automated tenant-level network isolation. Tenants can run GPU Operator, Ray, KServe, AI schedulers, and their own CRDs inside their isolated cluster.

Private Nodes
Netris network isolation
GPU Operator
Ray
KServe
Custom CRDs

Speed to market is everything in the GPU cloud space. Partnering with vCluster was a deliberate strategic decision.

Andrew Karos

Andrew Karos
CEO, Boost Run

Launch a Managed Kubernetes Platform on Bare Metal in 2 Weeks
Guide
Launch a Managed Kubernetes Platform on Bare Metal in 2 Weeks

Learn how to ship a production-ready managed Kubernetes platform with strong isolation, GPU scheduling, and enterprise-grade operations from day one.

Automate Network Isolation for Hard Multi-Tenant Kubernetes
SOLUTION
Automate Network Isolation for Hard Multi-Tenant Kubernetes

vCluster and Netris integrate Kubernetes and network automation.

vCluster Guide to Achieve ClusterMAX™ Platinum Rating
GUIDE
vCluster Guide to Achieve ClusterMAX™ Platinum Rating

Learn how to deliver enterprise-grade Kubernetes for AI workloads and improve ClusterMAX™ rating.

THE SAME MACHINERY

Managed Kubernetes is the first product, not the only one.

Same control plane virtualization, same isolation model, same fleet tooling. Same vcluster.yaml, same Argo CD templates, same Platform console. The next cluster type is a template, not a platform rebuild.

Slurm Clusters

Tenants see only their own partition and jobs.

BETA
Run:AI Clusters

Tenants see only their own projects and jobs.

AVAILABLE
Ray Clusters

Tenants see only their own head node and workers.

AVAILABLE
Inference Clusters

Dynamo, llm-d, and more.

SOON
One API no matter what the hardware underneath demands

Add new server vendors, NIC types, or GPU generations without changing how clusters get built. The provisioning layer is future-proofed too.

Launch your managed Kubernetes platform.

Talk to a Kubernetes expert and get a live walkthrough built around your infrastructure and your tenants.