platform-eng

Kubernetes Hardware Isolation for AI Workloads

Use Private Nodes backed by dedicated physical servers for Kubernetes hardware isolation. Each tenant also receives its own virtualized control plane and RBAC boundary.

Trusted by the fastest-growing AI cloud providers
Problem

Why Namespace Isolation Is Not Hardware Isolation

Namespace boundaries do not dedicate physical worker capacity to a tenant cluster.

Namespaces Share Cluster Components

Namespace-only designs share the API server and can also share worker nodes between tenants.

Separate Management Stacks Add Work

Building and operating a separate Kubernetes management stack for every tenant increases infrastructure work.

Shared Nodes Create Resource Contention

Shared worker nodes expose workloads to cross-tenant contention for CPU, GPU, memory, network, and storage resources.

Solution

Kubernetes Hardware Isolation With Private Nodes

vCluster Platform uses Private Nodes as the production default. When backed by dedicated physical servers, Private Nodes provide Kubernetes hardware isolation while virtualized control planes avoid separate control-plane servers per tenant.

Built for Kubernetes Hardware Isolation

Kubernetes hardware isolation combines dedicated physical Private Nodes with a separate tenant control plane and optional runtime and network controls.

Hardware Isolation

Dedicated Physical Private Nodes

Assign dedicated physical worker nodes, networking, and storage to one production tenant cluster at a time.

  • Dedicated physical nodes
  • Tenant-scoped networking and storage
  • Dedicated physical capacity
Workload Security

Runtime Isolation With vNode

vNode uses Linux user namespaces and seccomp filters to strengthen the runtime boundary for workloads that need additional isolation.

  • Stronger runtime boundary
  • No additional VM layer
  • Seccomp filters
Network Isolation

Optional Hardware Network Isolation

Metal3 and Netris can place separate tenant network environments on hardware-backed L2 boundaries when configured.

  • Per-tenant network boundaries
  • Netris network environments
  • Hardware-backed L2 isolation
Control Plane

Separate Control Plane Per Tenant

Every tenant cluster receives its own virtualized API server and RBAC boundary on the control plane cluster.

  • Separate API server and RBAC
  • Lightweight control plane creation
  • Tenant-scoped administration
Compliance

Air-Gapped Platform Deployment

vCluster Platform supports air-gapped deployments and FIPS features on supported plans for controlled infrastructure environments.

  • Air-gapped deployment supported
  • FIPS features on supported plans
  • Regulated deployment patterns

Why vCluster

This isn’t a side project. Behind every vCluster deployment is 5+ years of deep K8s engineering, security hardening, and battle-tested infrastructure work at massive scale.

100K+
GPUs Powered
50+
GPU Clouds & F500s
<45
Days to Launch
30K
GitHub Stars

Get Started in 3 Steps

1
Schedule a Demo

Talk to our team about your stack

2
Deploy vCluster

Deploy vCluster on your infra in minutes

3
Onboard Your Tenants

Go live with a hyperscaler-grade tenant experience in days

FAQs

What does Kubernetes hardware isolation mean?

Kubernetes hardware isolation assigns physical worker nodes to one tenant cluster at a time. The tenant's workloads do not share CPU, GPU, memory, networking, or storage components on those dedicated servers with another tenant cluster.

How do Private Nodes provide hardware isolation?

Private Nodes are the production default. When those nodes are dedicated physical servers, they provide the hardware boundary. vCluster also gives each tenant its own virtualized control plane and RBAC boundary.

Does every tenant need separate physical control-plane servers?

Yes. The tenant control plane runs as isolated pods on a control plane cluster, so every tenant does not need separate physical control-plane servers. Production worker capacity remains dedicated through Private Nodes.

How does dedicated hardware affect GPU performance?

Dedicated Private Nodes remove cross-tenant workload placement from those servers. Actual GPU throughput still depends on the hardware, driver stack, network, storage, and workload configuration.

What deployment controls support regulated environments?

vCluster Platform supports air-gapped deployments and FIPS features on supported plans. With Metal3 and Netris configured, separate network environments can provide hardware-backed L2 isolation.

What evidence supports vCluster for GPU infrastructure at scale?

vCluster powers 100K GPUs across 50+ GPU Clouds & Fortune 500s and is validated in the NVIDIA DGX reference architecture.

Achieve Kubernetes Hardware Isolation Today

See how Private Nodes provide Kubernetes hardware isolation for production tenant clusters.