platform-eng

Namespace Per Customer Kubernetes With Tenant Isolation

Move beyond namespace per customer Kubernetes for production tenants. vCluster gives each customer a separate Kubernetes control plane and uses Private Nodes for dedicated worker capacity.

Trusted by the fastest-growing AI cloud providers
Problem

Where Namespace Per Customer Kubernetes Falls Short

Namespace per customer Kubernetes shares control-plane and often worker-node components between customers.

Namespaces Share the API Server

Namespaces share the Kubernetes API server and cluster-level components between customers.

Separate Management Stacks Add Work

A separate management stack for every customer increases infrastructure and operational work.

Custom Isolation Requires Ongoing Work

Building custom tenant isolation requires ongoing work across access, capacity, networking, observability, and lifecycle operations.

Solution

Separate Tenant Clusters for Production Customers

vCluster Platform gives each customer a separate tenant cluster with its own virtualized control plane. Private Nodes provide dedicated production worker capacity while operators retain central policy and fleet control.

Move Beyond Namespace Per Customer Kubernetes

Move beyond namespace per customer Kubernetes with separate tenant control planes, Private Nodes, and centralized operations.

Hardware Isolation

Private Nodes Per Customer

Private Nodes dedicate worker capacity, networking, and storage to one production customer cluster at a time.

  • Dedicated worker capacity
  • Dedicated customer capacity
  • Tenant-scoped networking and storage
Control Plane

Separate Control Plane Per Customer

Each customer receives a separate virtualized API server and RBAC boundary on the control plane cluster.

  • Separate API server and RBAC
  • Lightweight control plane creation
  • Separate RBAC boundary
Standards Compatibility

Standard Kubernetes APIs

Tenant clusters use a certified Kubernetes distribution and standard APIs for existing tools, CRDs, and operators.

  • Standard Kubernetes APIs
  • Helm, CRDs, and operators
  • Existing Kubernetes tools
Workload Security

Runtime Isolation With vNode

vNode uses Linux user namespaces and seccomp filters to strengthen the runtime boundary for workloads that need additional isolation.

  • Linux user namespace isolation
  • No additional VM layer
  • Stronger runtime boundary
Compliance

Air-Gapped Platform Deployment

vCluster Platform supports air-gapped deployments and FIPS features on supported plans for controlled environments.

  • Air-gapped deployment support
  • FIPS features on supported plans
  • Regulated deployment patterns

Why vCluster

This isn’t a side project. Behind every vCluster deployment is 5+ years of deep K8s engineering, security hardening, and battle-tested infrastructure work at massive scale.

100K+
GPUs Powered
50+
GPU Clouds & F500s
<45
Days to Launch
30K
GitHub Stars

Get Started in 3 Steps

1
Schedule a Demo

Talk to our team about your stack

2
Deploy vCluster

Deploy vCluster on your infra in minutes

3
Onboard Your Tenants

Go live with a hyperscaler-grade tenant experience in days

FAQs

When is namespace per customer Kubernetes insufficient?

Namespace per customer Kubernetes shares one API server and node-level components across customers. That model fits trusted internal teams, but external or untrusted production tenants need a stronger control-plane and worker-node boundary.

How does vCluster strengthen customer isolation?

vCluster gives each customer a separate virtualized API server and RBAC boundary. Private Nodes are the production default and dedicate worker capacity, networking, and storage to one tenant cluster at a time.

Can customers receive cluster-admin access?

Yes. Customers can receive cluster-admin inside their own tenant cluster, including control of CRDs and RBAC, without access to the provider's control plane cluster or another tenant environment.

What deployment controls support regulated environments?

vCluster Platform supports air-gapped deployments and FIPS features on supported plans. Compliance still depends on the customer's complete deployment, configuration, and operating controls.

How quickly can operators create a customer cluster?

Virtualized control planes are lightweight and can be created quickly. Private Node readiness depends on whether worker capacity is available or must be provisioned.

How does vCluster Platform manage customer cluster fleets?

vCluster powers 100K GPUs across 50+ GPU Clouds & Fortune 500s and provides centralized operations for tenant cluster fleets.

Stop Relying on Namespace Isolation

See how vCluster Platform supports namespace per customer kubernetes with tenant isolation.