CAPSULE BY CLASTIX

Kubernetes Multi-Tenancy, Simplified.

Capsule enables platform teams to deliver secure self-service Kubernetes from a shared cluster. Built on native Kubernetes, it provides tenant isolation, governance, and guardrails, without introducing another management layer or Kubernetes distribution.

CNCF Donated
Community Sandbox Project
Apache 2.0
Free to use

Developers

Self-service kubectl access

Team ATeam BTeam C

Capsule Tenant

Isolation · Governance · Guardrails

Capsule Control Plane

Policy enforcement · RBAC delegation

Shared Kubernetes Cluster

Native Kubernetes experience

Self-ServiceGovernanceIsolationNative K8s UX

KEY BENEFITS

True Multi-Tenancy

Strong isolation for teams and workloads on a shared cluster without dedicated cluster overhead.

Governed Self-Service

Give teams autonomy within policies and boundaries defined by the platform team.

Native Kubernetes Experience

No additional APIs, custom binaries, or proprietary workflows. Standard kubectl throughout.

Faster Platform Delivery

Reduce cluster sprawl while increasing developer velocity and operational efficiency.

THE PROBLEM

Cluster Sprawl Doesn’t Scale.

As Kubernetes adoption grows, every team eventually requests its own cluster. More clusters mean more cost, more operations, and more complexity. Namespaces alone don’t provide the isolation, governance, and self-service capabilities modern platform teams require.

Dedicated Clusters

  • High cost
  • Operational overhead
  • Cluster sprawl
  • Inconsistent governance
  • Slow onboarding

Namespaces Only

  • Limited isolation
  • Difficult delegation
  • Weak governance
  • Manual policy enforcement
  • Poor developer experience

THE CAPSULE APPROACH

Multi-Tenancy Built Into Kubernetes.

Capsule introduces the Tenant abstraction to Kubernetes. Each team receives its own isolated operational space while platform teams retain governance and visibility across the shared cluster.

  • Tenant API
  • Delegated Administration
  • Resource Boundaries
  • Policy Enforcement
  • Namespace Isolation

Team A

Team B

Team C

Capsule Tenant Layer

Namespace · RBAC · Quota · NetworkPolicy

Shared Kubernetes Cluster

WHO BENEFITS

Better for Platform Teams.Better for Developers.

Platform Teams

  • Fewer clusters to manage
  • Consistent governance
  • Delegated administration
  • Policy enforcement
  • Reduced operational burden

Developers

  • Native kubectl experience
  • Self-service namespaces
  • Faster onboarding
  • No platform ticket queues
  • Greater autonomy

Security Teams

  • Strong isolation boundaries
  • RBAC delegation
  • Auditability
  • Network policies
  • Compliance guardrails

The Organisation

  • Reduced cluster sprawl
  • Improved developer productivity
  • Faster delivery
  • Lower operational costs
  • Platform standardisation

CAPABILITIES

Everything You Need To Run A Multi-Tenant Platform.

Tenant API

First-class Tenant CRD for declarative multi-tenancy configuration.

Namespace Isolation

Hard boundaries between tenants with automatic namespace management.

RBAC Delegation

Delegate namespace admin rights to tenant owners without cluster-admin.

Policy Enforcement

Admission webhooks enforce tenant boundaries at the API server.

OPEN SOURCE TRUST

Open Source. CNCF Sandbox.Production Ready.

Capsule is an open-source project built by Clastix and adopted by organisations building multi-tenant Kubernetes platforms worldwide. Built with the community, for the community.

2.3k+
GitHub Stars
80+
Contributors
500+
Community Members
CNCF
Sandbox Project

BUILT BY CLASTIX

Need Help Building Your Platform?

The engineers behind Capsule help organisations design, implement, and operate production-grade multi-tenant Kubernetes platforms.

Speak with our team

Architecture Advisory

Platform architecture review and multi-tenancy strategy design tailored to your organisation.

Platform Design

End-to-end design of your internal developer platform built on Capsule.

Training & Enablement

Hands-on workshops for platform and development teams to accelerate adoption.

Enterprise Support

SLA-backed support from the engineers who built Capsule.

SUPPORT FROM CLASTIX

Run Capsule independently. Or with the team that built it.

Capsule is free and open source. You can deploy it, run it, and scale it entirely on your own. When you want a direct line to the engineers who built it — for production support, architecture guidance, or hands-on deployment help — Clastix is here.

Clastix Care: Ongoing Support

SLA-backed support from the engineers who built Capsule.

Optional
  • SLA with defined response times by incident severity
  • Private channel – direct access to Clastix engineers
  • Monthly office hours with the Clastix team
  • Upgrade support and stable release guidance
  • Architecture review for your specific deployment

Ongoing product support under a support agreement.

Clastix Ready: One-Off Service

Hands-on help getting Capsule into production.

Optional
  • Installation and configuration in your environment
  • Architecture design for your multi-tenancy use case
  • Team training and knowledge transfer
  • Production readiness review
  • Tenant policies, quotas, isolation and RBAC

One-off engagements scoped to your needs.

Speak with our team

Build Your Multi-Tenant Kubernetes Platform With Capsule.

Join platform teams around the world using Capsule to build secure, governed, self-service Kubernetes platforms.

Multi-tenancy without cluster sprawl. Native Kubernetes experience. Open source by design.