platform-eng

Secure Multi-Tenant Kubernetes with Hard Tenant Isolation

Give every tenant a dedicated Kubernetes control plane and Private Nodes for production workloads. Tenants use standard Kubernetes APIs and manage their own CRDs and RBAC inside their tenant cluster.

Trusted by the fastest-growing AI cloud providers
Problem

Why Standard Kubernetes Falls Short

Production tenant isolation requires more than a shared API server and namespace boundary.

Namespace Isolation Is Too Weak

Namespace-only designs share the API server and node-level components between tenants.

Separate Clusters Are Too Expensive

A separate management stack for every tenant increases infrastructure and operational work.

Customers Expect the Cloud Experience

Customers expect self-service access to a Kubernetes environment they can manage without seeing the provider's control plane cluster.

Solution

Tenant Isolation Without the Cost of Dedicated Clusters

vCluster Platform gives every tenant a virtualized control plane and uses Private Nodes as the production default. Tenants manage standard Kubernetes resources inside their own environment while operators retain platform-level control.

Built for Secure Tenant Kubernetes at Scale

vCluster combines isolated tenant control planes, Private Nodes, optional runtime isolation, and standard Kubernetes APIs.

Hardware Isolation

Private Nodes Per Tenant Cluster

Private Nodes dedicate worker capacity, networking, and storage to each production tenant cluster.

  • Per-tenant CNI and storage
  • No shared hardware between tenants
  • Hardware-level isolation by default
Control Plane

Private Control Plane Per Tenant

Every tenant gets its own virtualized Kubernetes control plane, API server, and RBAC boundary.

  • Own API server and etcd per tenant
  • Lightweight control plane
  • No shared control plane risk
Workload Security

Kernel-Level Workload Isolation

vNode uses Linux user namespaces and seccomp filters to provide a stronger runtime boundary for tenant workloads.

  • Seccomp, cgroups, namespaces per workload
  • No VM layer
  • Tenant isolation runtime
Network Security

Hardware Enforced Network Isolation

Netris integration can provide hardware-backed L2 isolation through a separate network environment for each tenant.

  • VLANs and VXLANs per tenant
  • Network automation
  • Hardware-enforced network boundaries
Standards Compliance

CNCF Certified Kubernetes Per Tenant

Tenant clusters use a certified Kubernetes distribution and standard APIs for existing workloads, tools, CRDs, and operators.

  • Standard Kubernetes APIs
  • CNCF-certified per tenant cluster
  • Full CRD and operator support

Why vCluster

This isn’t a side project. Behind every vCluster deployment is 5+ years of deep K8s engineering, security hardening, and battle-tested infrastructure work at massive scale.

100K+
GPUs Powered
50+
GPU Clouds & F500s
<45
Days to Launch
30K
GitHub Stars

Get Started in 3 Steps

1
Schedule a Demo

Talk to our team about your stack

2
Deploy vCluster

Deploy vCluster on your infra in minutes

3
Onboard Your Tenants

Go live with a hyperscaler-grade tenant experience in days

FAQs

How is vCluster different from Kubernetes namespace isolation?

Namespace-only designs share one Kubernetes API server and node-level components. vCluster gives each tenant its own virtualized control plane, API server, and RBAC boundary, with Private Nodes as the production default.

What does Private Nodes mean for tenant security?

Private Nodes assign dedicated worker nodes to one tenant cluster at a time. Each tenant cluster has its own networking and storage configuration, creating a hard infrastructure boundary for production workloads.

Does secure tenant Kubernetes require separate physical clusters?

No separate Kubernetes control-plane servers are required for every tenant. The virtualized control plane runs on the control plane cluster, while Private Nodes provide dedicated worker capacity.

How does vCluster protect against container breakout between tenants?

vNode is a tenant isolation container runtime that uses Linux user namespaces and seccomp filters to strengthen the workload boundary for privileged or untrusted workloads.

Is vCluster Kubernetes fully compatible with existing workloads?

Tenant clusters use a certified Kubernetes distribution and standard Kubernetes APIs. Teams can use kubectl, Helm, Argo, Crossplane, CRDs, and operators against the tenant cluster.

Can vCluster support compliance requirements for secure tenant environments?

vCluster Platform supports air-gapped deployments and FIPS features on supported plans. Private Nodes and optional Netris integration provide additional infrastructure and network controls for regulated environments.

Ready to Launch Secure Tenant Kubernetes

See how vCluster delivers production-grade tenant isolation on your GPU infrastructure.