Full-Stack GPU Cluster Tenant Isolation
GPU cluster isolation spans the tenant control plane, dedicated Private Nodes, optional runtime isolation, and optional hardware network isolation.
Hardware Isolation
Private Nodes Per Tenant Cluster
Private Nodes assign dedicated worker nodes with tenant-scoped networking and storage to each production tenant cluster.
Per-tenant CNI and storage
No cross-tenant workload placement
Hardware-level security boundary
Control Plane
Virtualized Control Planes Per Tenant
Each tenant receives its own virtualized Kubernetes control plane, API server, and RBAC boundary.
Own API server and etcd per tenant
Lightweight control plane
Isolated blast radius per tenant
Workload Security
Kernel-Native Workload Isolation
vNode adds a tenant isolation runtime using Linux user namespaces and seccomp filters for workloads that need a stronger runtime boundary.
Network Isolation
Hardware-Enforced Network Boundaries
Netris integration can place each tenant network environment on a separate hardware-backed L2 boundary.
Compliance
Air-Gapped and FIPS Deployments
vCluster Platform supports air-gapped deployments and FIPS features on supported plans for regulated deployment patterns.
Air-gapped deployment support
FIPS features on supported plans
Sovereign and regulated environments