About this project
vCluster is an open-source engine for creating tenant clusters: fully isolated Kubernetes environments that each run their own API server, controller manager, data store, CRDs and RBAC. It is a CNCF Certified Kubernetes distribution and Kubernetes AI Conformant. Tenants get admin rights inside their own cluster while holding minimal permissions on the underlying host cluster.
Deployment options
- Shared Nodes: tenant clusters share the host cluster's nodes; workloads run as pods in a namespace, using pseudo nodes for maximum density.
- Dedicated Nodes: tenant clusters use labeled node pools on the host cluster, giving isolated compute while still reusing the host's CNI, CSI and platform stack.
- Private Nodes (v0.27+): external nodes join the tenant cluster with their own CNI, CSI and networking, via a token-based process; nodes can also join over an encrypted VPN overlay (v0.30+).
- Standalone (v0.29+): the control plane runs as a self-contained binary on bare metal or VMs, with no host Kubernetes cluster required.
- Auto Nodes (v0.28+): Karpenter-powered provisioning and deprovisioning of private nodes across cloud, hybrid and bare metal, with per-pool node profiles (v0.36+).
- vind (v0.32+): a complete tenant cluster running in Docker containers on a single host, with no Kubernetes dependency, created via the CLI with --driver docker.
Key capabilities
- Dedicated control plane per tenant: API server, controller manager and data store, providing full Kubernetes API isolation rather than namespace-level rules.
- GPU-aware scheduling: Dynamic Resource Allocation with resource claims, claim templates and device classes, plus in-place pod resizing.
- Resource syncing in shared/dedicated modes: bidirectional sync of pods, services, secrets, configmaps, CRDs and Gateway API objects.
- Integrations: cert-manager, external-secrets, KubeVirt, Istio and metrics-server.
- High availability: multiple replicas with leader election; embedded etcd or external databases such as PostgreSQL, MySQL and RDS.
- Snapshot and restore to S3, OCI, Azure Blob or local storage; sleep mode to pause inactive clusters (Platform feature).
- Node VPN (Platform) for encrypted overlay networking across sites, networks and clouds.
Getting started
Install the CLI with brew install loft-sh/tap/vcluster, then run vcluster create my-vcluster --namespace team-x and use kubectl normally inside the tenant cluster. A running Kubernetes cluster and configured kubectl are prerequisites. For local use without Kubernetes, vcluster create my-vcluster --driver docker runs a tenant cluster in Docker. A browser-based trial is available on Killercoda, and a free tier allows unlimited tenant clusters up to 64 CPUs and 32 GPUs with the Platform UI.
Ecosystem and use cases
The project targets AI clouds, AI factories, internal GPU platforms, distributed inference, sovereign clouds, bare metal Kubernetes, software vendors and cost consolidation. It is positioned as the open-source foundation for a broader stack that includes vNode for runtime isolation, vMetal for bare metal GPU provisioning and Netris for network isolation. Slurm, Ray, Run:ai, inference and agent sandbox cluster types are delivered through vCluster Platform, while this repository is the underlying engine. The README cites production use at organizations including Adobe, CoreWeave, NVIDIA, Nebius, Lintasarta, Atlan and Deloitte, and lists many conference talks and case studies.
Comments
0 Rating appears after 10 ratings
Sign in to join the discussion.