Match isolation to trust: namespaces for friends, node groups for strangers, clusters for regulators.
Soft
Namespace per tenant
- RBAC through access entries and RoleBindings.
- ResourceQuota and LimitRange.
- Default-deny NetworkPolicy.
- Pod Identity per ServiceAccount.
- Pod Security Standards.
Cheapest. Shared control plane and nodes.
Partial hard
Node pool per tenant
- Everything on the left plus taints, tolerations and node affinity.
- Tenants never share a node.
- Dedicated Karpenter NodePool per tenant.
Higher cost from lower bin-packing.
Hard
Cluster per tenant
- Separate control plane and data plane.
- Clear blast-radius and compliance boundary.
- Often one AWS account per tenant too.
Highest cost and operations effort.
Default to soft
For trusted internal teams, namespaces with quotas, policies and per-namespace identity are the standard, least expensive choice.
Escalate for a reason
Move to dedicated nodes or clusters only for untrusted tenants or hard compliance boundaries. Deck 5 covers Capsule, vCluster and sandboxed runtimes.