Operations
Multi-tenancy
54 / 69

Match isolation to trust: namespaces for friends, node groups for strangers, clusters for regulators.

Soft

Namespace per tenant

  • RBAC through access entries and RoleBindings.
  • ResourceQuota and LimitRange.
  • Default-deny NetworkPolicy.
  • Pod Identity per ServiceAccount.
  • Pod Security Standards.

Cheapest. Shared control plane and nodes.

Partial hard

Node pool per tenant

  • Everything on the left plus taints, tolerations and node affinity.
  • Tenants never share a node.
  • Dedicated Karpenter NodePool per tenant.

Higher cost from lower bin-packing.

Hard

Cluster per tenant

  • Separate control plane and data plane.
  • Clear blast-radius and compliance boundary.
  • Often one AWS account per tenant too.

Highest cost and operations effort.

Default to soft

For trusted internal teams, namespaces with quotas, policies and per-namespace identity are the standard, least expensive choice.

Escalate for a reason

Move to dedicated nodes or clusters only for untrusted tenants or hard compliance boundaries. Deck 5 covers Capsule, vCluster and sandboxed runtimes.