Skip to main content
Version: v0.36

Build for Production

vClustervClusterAn open-source software product that creates and manages tenant clusters within Kubernetes infrastructure. vCluster provides tenant isolation capabilities while reducing infrastructure costs.Related: Tenant cluster, Control plane cluster lets you provision isolated tenant clusters on your existing infrastructure without a separate physical cluster per tenant. This section maps the common production architectures to concrete implementation paths. Choose the one that matches what you are building and follow it from initial design to a running, operated platform.

Need to evaluate vCluster first?

Start with a quick start to prove the deployment model in your environment, then return here to plan production.

Choose your worker node model first

Shared and private nodes are a security boundary decision, locked at deployment time. Before you pick a path below, run through Choose a worker node model to confirm which one your offering requires.

What are you building?​

Find the goal that matches your platform, then choose the desired outcome. The linked production path takes you from architecture decisions through Day 2 operations.

Offer AI or Kubernetes infrastructure to customers​

Desired outcomeStart hereWorker-node guidance
Serve models through managed endpoints while your team operates the Kubernetes infrastructureInference Provider: Managed Model ServingPrivate nodes for dedicated or customer-controlled serving. Shared nodes may suit provider-owned models with API-only access
Give customers isolated, GPU-backed Kubernetes environments through your productAI Cloud: Managed Kubernetes ServicePrivate nodes for external customer workloads
Give each enterprise customer a dedicated cluster stack for node-level, regulated, or sovereign isolationSingle-Tenant Per CustomerPrivate nodes for node-level customer isolation

Build a platform for internal teams​

Desired outcomeStart hereWorker-node guidance
Standardize governed GPU environments across production, development, and experiment tiersEnterprise AI FactoryPrivate nodes for production. Shared nodes for trusted development and experiment tiers
Give trusted engineering teams long-running, isolated Kubernetes environmentsInternal Kubernetes PlatformShared nodes for trusted team workloads only
Give each CI/CD pipeline an ephemeral, isolated Kubernetes environment with automatic cleanupCI/CD PlatformShared nodes for trusted pipeline workloads only

Operate compute across providers or locations​

Desired outcomeStart hereWorker-node guidance
Manage GPU capacity from multiple compute sources through one operations layerDistributed Compute AggregationPrivate nodes for dedicated tenant capacity at each site
Manage tenant workloads at distributed edge sites from a central control planeEdge DistributionPrivate nodes for dedicated tenant capacity at edge sites

Not sure where to start? Use Choose a worker node model to decide between shared and private nodes. If no production path fits, review Architecture and Building a GPU cloud platform.

What production-ready means​

A production vCluster platform delivers:

  • Tenant isolationTenant IsolationThe capability to host multiple separate users, teams, or workloads on the same infrastructure while providing strong isolation between them. vCluster delivers tenant isolation through dedicated control planes, isolated resource namespaces, and optional private nodes per tenant.Related: Tenant cluster: every customer or team sees only their own cluster and workloads. Node level isolation requires private nodes
  • Repeatable provisioning: new tenant clusters deploy from a defined template, not from manual steps. When each environment also needs the same ordered set of applications, use Stacks to standardize that software layer
  • A worker node model matched to your isolation needs: private nodes for tenants with cluster, scheduler, or workload execution access, or shared nodes for trusted internal tenants or a provider-operated offering where you own all workloads. A dedicated node pool scopes placement within shared nodes. It doesn't provide private-node isolation. See Choose a worker node model.
  • Governed access: who can create, access, and administer tenant clusters, enforced through Platform policies
  • Durable control planes: HA, data store, and backup procedures defined before tenants depend on the system
  • Operational readiness: monitoring, upgrade, restore, and incident response procedures documented and tested

Connect quick start results to production paths​

Each quick start validates a specific deployment model. Use this table to connect what you proved to the production path that extends it.

If you completedYou have provenProduction paths to consider
Docker (vind)Local development, testing, or CI cluster behaviorUse vind to validate cluster behavior, then choose a production path for deployment.
Shared NodesTenant clusters on an existing Kubernetes clusterInternal Kubernetes Platform, CI/CD Platform, or Enterprise AI Factory (shared tier)
Private NodesTenant clusters with dedicated worker nodesInference Provider, AI Cloud, Enterprise AI Factory (production tier), Distributed Compute Aggregation, Single-Tenant Per Customer, or Edge Distribution
StandaloneControl plane cluster on bare metal or VMsInference Provider, AI Cloud, Distributed Compute Aggregation, Enterprise AI Factory (on-premises), or Edge Distribution

Day 2 operations reference​

Common operations that apply across all paths.

OperationRead next
Monitor Platform and tenant workloadsFleet Observability, other architectures
Back up and restore tenant clustersSnapshots, restore, Velero
Back up and restore PlatformBackup and restore Platform, Platform database
Upgrade Platform and tenant clustersUpgrade vCluster, upgrade Platform, lifecycle policy
Rotate certificatesCertificate rotation
Manage private worker nodesManage private nodes, Auto Nodes
Scale and recover the platformPlatform HA, multi-region Platform
Troubleshoot incidentsvCluster troubleshoot, debug commands, Platform troubleshooting