platform-eng

Tenant Isolation for AI Cloud Providers

Define tenant boundaries from machines to workloads. vMetal provisions infrastructure, and vCluster combines separate tenant control planes with dedicated Private Nodes and optional vNode runtime isolation.

Trusted by the fastest-growing AI cloud providers
Problem

Isolation Without Compromise Is Hard

Standard Kubernetes forces a painful tradeoff between security, performance, and cost.

Namespace Isolation Is Too Weak

Tenants can see platform internals they should not: cluster-wide agents, other tenants' nodes and pods.

Separate Clusters Are Too Expensive

Provisioning full physical clusters per tenant destroys density, slows onboarding, and kills margins.

Container Breakout Remains a Risk

AI workloads running untrusted code on shared GPUs create real exposure to cross-tenant data leaks.

Solution

Full Stack Tenant Isolation at Bare Metal Speed

vMetal manages infrastructure below separate tenant control planes. Private Nodes dedicate workers, Netris can segment supported networks, and vNode adds runtime hardening. Each layer addresses a different tenant boundary. Lintasarta runs 170+ tenant clusters in production.

Built for Strong Tenant Isolation at Scale

Every layer of the stack is designed to give tenants hard boundaries without sacrificing GPU performance or operational efficiency.

Workload Security

Kernel-Native Isolation for Every Tenant

vNode uses Linux user namespaces and seccomp to restrict workload privileges and system calls. It adds runtime hardening for tenant isolation without a guest kernel or hypervisor, complementing dedicated workers rather than allocating GPUs.

  • Linux user namespaces and seccomp
  • No guest kernel or hypervisor
  • Helps limit workload breakout
Control Plane

Lightweight Tenant Kubernetes Control Planes

Each tenant has an independent Kubernetes API, data store and RBAC boundary. Lightweight control-plane hosting reduces dedicated server requirements for tenant isolation; Private Nodes keep production workers tenant-specific.

  • Independent tenant API and data store
  • Tenant-scoped scheduling on Private Nodes
  • No dedicated control-plane servers per tenant
Node Isolation

Dedicated Worker Nodes Per Tenant

Private Nodes dedicate worker capacity to one tenant cluster, with its own CNI and storage configuration. For tenant isolation, select physical servers or VMs according to the required infrastructure boundary.

  • Dedicated worker nodes per tenant
  • Tenant-owned CNI and storage configuration
  • Physical servers or supported VMs
Defense in Depth

Layered Tenant Incident Boundaries

Combine separate tenant APIs, dedicated Private Nodes and vNode runtime hardening for tenant isolation. These boundaries help limit tenant incidents; infrastructure patching, least privilege and application security remain part of the deployment.

  • Separate tenant API boundaries
  • Dedicated production worker capacity
  • Runtime hardening complements infrastructure controls
Network Security

Hardware-Enforced Network Isolation

Tenant-owned CNI configuration and supported Netris integrations provide separate network controls for tenant isolation. Ethernet segmentation can use VLANs, VRFs and ACLs; InfiniBand isolation uses fabric partitions rather than Ethernet constructs.

  • Tenant-owned worker network configuration
  • Netris integration for supported fabrics
  • Explicit segmentation and access policies

Why vCluster

This isn’t a side project. Behind every vCluster deployment is 5+ years of deep K8s engineering, security hardening, and battle-tested infrastructure work at massive scale.

100K+
GPUs Powered
50+
GPU Clouds & F500s
<45
Days to Launch
30K
GitHub Stars

Get Started in 3 Steps

1
Schedule a Demo

Talk to our team about your stack

2
Deploy vCluster

Deploy vCluster on your infra in minutes

3
Onboard Your Tenants

Go live with a hyperscaler-grade tenant experience in days

FAQs

What is tenant isolation in Kubernetes and why does it matter for AI clouds?

Tenant isolation in Kubernetes means keeping each customer's workloads, data and control plane resources separated from other tenants on the same infrastructure. For AI clouds running GPU workloads, weak isolation creates real risks: container escapes, data leaks and noisy-neighbor GPU contention. Strong tenant isolation needs separation at the control plane, workload runtime and network layers at the same time, which namespace-level partitioning alone can't provide.

How is vCluster's tenant isolation different from Kubernetes namespaces?

Namespaces divide resources within a Kubernetes cluster, but share its API and cluster-wide administrative scope. RBAC, quotas and network policies remain useful controls. vCluster adds a separate tenant API and data store, with Private Nodes dedicating production workers. This reduces dependencies between tenant environments while platform administrators still manage the underlying infrastructure and its failure domains.

Does strong tenant isolation require sacrificing GPU performance?

Dedicated Private Nodes remove cross-tenant workload placement from those workers. Bare metal avoids a hypervisor layer, but this is not a throughput or latency guarantee. GPU drivers, workload configuration, network fabrics and storage can still influence performance. vNode adds runtime hardening using the Linux kernel; benchmark the selected stack against the workload and service levels you intend to offer.

What isolation options does vCluster provide for different security requirements?

vCluster offers an isolation spectrum. Private Nodes are the recommended production model, giving tenants dedicated worker nodes with their own CNI and CSI. Shared Nodes, with namespace and quota boundaries, suit internal dev, test and CI/CD by trusted teams. Dedicated VMs add kernel separation for regulated environments, and vNode layers workload isolation on top of any of these. You can match isolation strength to each tenant without changing your platform architecture.

Can vCluster help prevent container breakout attacks in isolated tenant GPU environments?

vNode uses Linux user namespaces and seccomp to restrict workload privileges and system calls, helping prevent container breakout. It uses the underlying Linux kernel rather than a separate guest kernel. Add it as runtime hardening alongside dedicated Private Nodes, patching and least-privilege policies. Validate kernel, container runtime, GPU access and workload compatibility; it is not a replacement for GPU allocation or application authorization.

Is vCluster's tenant isolation proven at GPU cloud scale?

vCluster Labs software powers 100K+ GPUs and 1M+ CPUs, serving 50+ GPU clouds & Fortune 500s combined. In production, Lintasarta operates 170+ tenant clusters, while Boost Run completed its managed Kubernetes launch in under 45 days from the decision. These named deployments provide scale and launch examples for teams evaluating the platform for their own infrastructure.

See Tenant Isolation in Action

Learn how AI cloud providers enforce strong tenant isolation at bare metal speed.