platform-eng

Separate Cluster Per Tenant Kubernetes for AI Clouds

Give every tenant its own Kubernetes control plane and RBAC boundary. Private Nodes are the production default for dedicated worker capacity, networking, and storage.

Trusted by the fastest-growing AI cloud providers
Problem

Why Shared Kubernetes Falls Short for External Tenants

Customer-facing Kubernetes needs stronger tenant boundaries than a shared API server and namespace model.

Namespaces Share Control-Plane Components

Namespace-only designs share control-plane and node-level components between tenants.

Separate Physical Clusters Add Operational Work

A separate management stack for every tenant increases infrastructure and operational work.

Shared Components Expand the Blast Radius

Shared control-plane components make configuration mistakes and operational incidents harder to contain within one tenant.

Solution

Separate Cluster Per Tenant Kubernetes With Private Nodes

vCluster Platform gives every tenant a virtualized Kubernetes control plane and uses Private Nodes as the production default. Operators manage tenants, access, templates, capacity, and observability centrally.

Built for Separate Tenant Clusters

Separate cluster per tenant Kubernetes combines a tenant control plane, Private Nodes, standard APIs, and centralized fleet operations.

Tenant Isolation

Separate Control Plane Per Tenant

Each tenant receives its own virtualized API server and RBAC boundary on the control plane cluster.

  • Separate API server and RBAC
  • Lightweight control plane creation
  • No separate control-plane servers
Hardware Isolation

Private Nodes Per Tenant

Private Nodes dedicate worker capacity, networking, and storage to one production tenant cluster at a time.

  • Dedicated worker capacity
  • Tenant-scoped networking and storage
  • Dedicated tenant capacity
Standards Compliance

Standard Kubernetes APIs

Tenant clusters use a certified Kubernetes distribution and standard APIs for existing tools, CRDs, and operators.

  • Standard Kubernetes APIs
  • Helm, CRDs, and operators
  • Existing Kubernetes tools
Self-Service

Cluster Admin Within Each Tenant

Tenants receive cluster-admin inside their own environment without access to the provider's control plane cluster.

  • Cluster admin within the tenant
  • No access to the control plane cluster
  • Tenant-scoped administration
Workload Security

Runtime Isolation With vNode

vNode uses Linux user namespaces and seccomp filters to strengthen the runtime boundary for workloads that need additional isolation.

  • Stronger runtime boundary
  • No additional VM layer
  • Linux user namespace isolation

Why vCluster

This isn’t a side project. Behind every vCluster deployment is 5+ years of deep K8s engineering, security hardening, and battle-tested infrastructure work at massive scale.

100K+
GPUs Powered
50+
GPU Clouds & F500s
<45
Days to Launch
30K
GitHub Stars

Get Started in 3 Steps

1
Schedule a Demo

Talk to our team about your stack

2
Deploy vCluster

Deploy vCluster on your infra in minutes

3
Onboard Your Tenants

Go live with a hyperscaler-grade tenant experience in days

FAQs

What does separate cluster per tenant Kubernetes mean?

Separate cluster per tenant Kubernetes gives each tenant its own API server, controller manager, resource namespace, and RBAC boundary. Tenants use standard Kubernetes APIs without access to the provider's control plane cluster.

How does vCluster create a separate cluster for each tenant?

vCluster runs each tenant control plane as isolated pods on a control plane cluster. Private Nodes then assign dedicated worker capacity to one production tenant cluster at a time.

Why use tenant clusters instead of namespaces?

Namespace-only isolation shares a Kubernetes API server and node-level components. Separate tenant clusters are the production model for external or untrusted tenants that need a stronger boundary.

How quickly can operators create a tenant cluster?

Virtualized control planes are lightweight and can be created quickly. Private Node readiness depends on whether capacity is already available or must be provisioned through an infrastructure driver.

Do tenant clusters support standard Kubernetes tools?

Tenant clusters use a certified Kubernetes distribution and standard APIs. Tenants can use kubectl, Helm, operators, CRDs, and their own RBAC inside the tenant cluster.

How does vCluster Platform manage tenant cluster fleets?

vCluster powers 100K GPUs across 50+ GPU Clouds & Fortune 500s and provides centralized operations for tenant cluster fleets.

Launch Separate Tenant Clusters

See how vCluster Platform supports separate cluster per tenant kubernetes for ai clouds.