Share the Cluster, Keep the Boundaries: Kubernetes Multi-Tenancy with Capsule
Oliver Bähler
11:30 - 11:45
Cave
Running a Kubernetes cluster for every team or customer creates clear boundaries, but it also multiplies control planes, upgrades, integrations, and operational effort. At the other end of the spectrum, simply assigning namespaces maximizes resource sharing but leaves platform teams to solve delegation, policy consistency, resource governance, and tenant visibility. Virtual control planes and API mediation layers provide additional choices, each with different trade-offs. This session maps the Kubernetes multi-tenancy spectrum and shows where Project Capsule fits. Capsule is a CNCF Sandbox project that introduces a lightweight Tenant abstraction on top of standard Kubernetes, grouping namespaces under common ownership and guardrails. Tenant Owners can create and manage namespaces within their assigned slice, while platform administrators retain control over permissions, resource budgets, policy rules, and shared resources. Teams keep the native Kubernetes API experience, while the platform remains declarative and independent of a particular Kubernetes distribution.
