KAMAJI OPEN SOURCE

The open-source Kubernetes control plane manager.

Kamaji is a production ready Kubernetes operator that runs tenant control planes as pods inside a single management cluster, instead of on dedicated machines. Each tenant gets a full, independent Kubernetes cluster with genuine cluster-admin access. The management cluster handles the operational complexity.

Built by Clastix. CNCF-conformant Kubernetes clusters. Running in production at OVHcloud, Rackspace and NVIDIA.

  • 1,955

    GitHub stars

  • 69 releases

    Latest Mar 2026

  • CNCF-conformant Kubernetes

    Conformant tenant clusters

  • Apache 2.0

    Free to use

Running 12 clusters with other approaches takes 39 control plane VMs, 123 in total. With Kamaji the same 12 clusters take 3 control plane VMs, 87 in total.

Estimate your Kubernetes infrastructure savings

Model the cost impact of consolidating Kubernetes control planes with Kamaji.

Open ROI Calculator

THE CONTEXT

There are several ways to run multi-tenant Kubernetes, each with its own trade-offs.

HOW IT WORKS

Two CRDs. One controller. Tenant control planes automated.

Kamaji extends your management cluster with two Custom Resource Definitions (CRDs). Bring your existing infrastructure automation or a Cluster API provider for worker provisioning and broader infrastructure lifecycle.

Go to ROI Calculator

16s

provision a control plane

10s

upgrade

60%

hardware saving

Any infra

worker nodes

WHAT KAMAJI TAKES CARE OF

The hard parts of running Kubernetes control planes at scale. Handled.

Running hosted control planes at scale means solving five hard problems – repeatedly, reliably, at every new tenant. Kamaji solves all five so your team focuses on what runs on the clusters, not on what keeps them alive.

WITHOUT KAMAJIWITH KAMAJI
1

Provision, update, and delete control planes declaratively.

Declare a TenantControlPlane resource. Kamaji provisions the API server, controller manager, and scheduler pods and keeps them reconciled to your desired state continuously. Drift is detected and corrected automatically.

16 seconds to a running control plane

2

One datastore for many control planes – without etcd sprawl.

Kamaji consolidates state across tenant control planes using shared etcd with prefix isolation per tenant, or kine with MySQL, PostgreSQL, or NATS. No dedicated etcd per tenant. No RAFT odd-instance requirement for smaller deployments.

Up to 60% hardware resource saving

3

Certificates generated, rotated, and renewed – automatically.

Every tenant control plane has its own certificate infrastructure. Kamaji generates all certificates at provisioning time, rotates them before expiry, and regenerates kubeconfigs automatically. Nothing to schedule. Nothing to forget.

Zero manual certificate operations

4

Upgrade any tenant control plane without mixed-version serving.

Update the version field in your TenantControlPlane spec. Kamaji orchestrates a Blue/Green upgrade – the new version is ready before the old one is removed. Tenants never serve mixed Kubernetes versions during rollout.

10 seconds per upgrade · zero mixed-version window

5

Worker nodes from anywhere – cloud, on-prem, bare metal, edge.

Kamaji generates the kubeconfig for each tenant control plane automatically. Workers join from any network. Konnectivity handles reverse tunnels for nodes with non-routable IPs – workers at the edge or behind NAT connect without custom networking.

Any infrastructure · Konnectivity built in

KAMAJI & KUBERNETES SECURITY POSTURE

The security case for separating every control plane. By architecture.

Kubernetes CVEs are proliferating, and the shared-cluster model has a structural problem: a compromised workload can reach the control plane governing every other tenant. Kamaji contributes toward Kubernetes Security Posture Management (KSPM) by addressing this at the architectural level – each tenant has an independent Kubernetes API and isolated datastore keyspace. Operators can choose shared or dedicated datastore infrastructure according to the required failure and isolation boundary.

IN PRODUCTION

Trusted in production by organisations operating Kubernetes at scale.

Kamaji is trusted in production by organisations where reliability, tenant isolation, and operational efficiency are non-negotiable.

“Kamaji enabled us to build a scalable and highly automated Kubernetes-as-a-Service platform. The combination of a multi-tenant architecture & direct access to Clastix’s engineering team allowed us to tailor the solution to our needs and accelerate service delivery for our customers.”

Maurizio Venturelli

Solution Architect · TINEXT CLOUD

“Delivering Kubernetes resources efficiently and securely can be a challenge, particularly at hyperscale and at the edge. Combining CLASTIX Kamaji and Rancher Prime by SUSE gives organizations the power to optimize, secure, and manage large and diverse, multi-tenant Kubernetes landscapes.”

Terry Smith

Director of Global Partner Solutions · SUSE

“Clastix Capsule and Kamaji, integrated with Rancher, have enabled us to scale our cloud services easily and efficiently, and we couldn’t be more thrilled with the results.”

Vito Pietrapertosa

Head of Managed Services · ReeVo

“We are running the open-source project Kamaji within our Rackspace Spot platform today, and the results are impressive.”

Kevin Carter

Director · Rackspace

“Kamaji works exactly as expected: it’s simple, efficient, scalable, and I especially appreciate how Clastix has always been available for technical discussions and support.”

Jérémie Monsinjon

Head of Containers · OVHcloud

“Kamaji’s innovative architecture enables us to provide scalable, efficient, and secure Kubernetes services, offering our customers a high-quality experience similar to that provided by global hyperscalers.”

Benny Sumitro

Director of Cloud Services · Datacomm

THE TEAM BEHIND KAMAJI

Kamaji: Built by Clastix. Proven in production. Open source by design.

Clastix created Kamaji and continues to lead its development. The same engineers who maintain the project contribute to the open-source community, support production deployments, and help customers design and operate Kubernetes at scale. Run Kamaji independently, or partner with the team behind it through Clastix’s services. The choice is yours.

European Company

Built and maintained by a European team with deep expertise in Kubernetes infrastructure, platform engineering, and enterprise operations.

CNCF-conformant Kubernetes

Built with upstream Kubernetes components and kubeadm; tenant clusters are designed for standard Kubernetes conformance.

Production Support Available

Work directly with the engineers who build Kamaji for architecture guidance, deployment support, troubleshooting, and long-term operations.

SUPPORT FROM CLASTIX

Run Kamaji independently. Or with the team that built it.

Kamaji is free and open source. You can deploy it, run it, and scale it entirely on your own. When you want a direct line to the engineers who built it – for production support, architecture guidance, or hands-on deployment help – Clastix is here.

Clastix Care: Ongoing Support

SLA-backed support from the engineers who built Kamaji.

Optional
  • SLA with defined response times by incident severity
  • Private channel – direct access to Clastix engineers
  • Monthly office hours with the Kamaji team
  • Upgrade support and stable release guidance
  • Architecture review for your specific deployment

Ongoing product support under a support agreement.

Clastix Ready: One-Off Service

Hands-on help getting Kamaji into production.

Optional
  • Installation and configuration in your environment
  • Architecture design for your multi-tenancy use case
  • Custom datastore configuration and migration
  • Team training and knowledge transfer
  • Production readiness review

One-off professional services such as architecture, implementation, migration and training.

THE NATURAL NEXT STEP

Kamaji is the foundation. kMetal is the complete platform built on top.

Kamaji gives you full control over your hosted control plane infrastructure. When you are ready to add a management layer – self-service provisioning, multi-tenant governance, fleet management, operational tooling, and a management UI – kMetal builds on Kamaji and provides all of it. Including Clastix Care, included from day one.

Not a replacement. A natural progression. Your Kamaji architecture is preserved.

Kamaji
What it isOpen-source control plane manager
Management layerYou build it
Self-service UINot included
Fleet managementNot included
Clastix CareOptional
Best forTeams who want to design their own system
kMetal
What it isFull platform built on Kamaji
Management layerIncluded
Self-service UIIncluded
Fleet managementIncluded
Clastix CareIncluded
Best forTeams who need the complete operating model
See how kMetal builds on Kamaji

Ready to run Kamaji?

Deploy it independently, explore the documentation, or work directly with the Clastix engineers to set your team up for success.

Kamaji is free and open source with the option to pair with Clastix paid services.