What is Capsule in Kubernetes? Multi-Tenant Control for K8s

Capsule (Kubernetes)

Capsule is a multi-tenant Kubernetes operator that enables efficient and secure workload isolation by grouping namespaces into lightweight virtual clusters called Tenants.

History

Capsule was created by Clastix to address the need for true multi-tenancy in Kubernetes without relying on heavyweight virtual clusters or multiple control planes. First introduced as an open-source project around 2020, Capsule has gained adoption among organizations needing fine-grained control, policy enforcement, and delegation in multi-team Kubernetes environments.

Value Proposition

Capsule provides a scalable and cost-effective way to enable multi-tenancy in Kubernetes by:

This makes it ideal for organizations that want to avoid the complexity of managing separate clusters while maintaining strong security and operational boundaries.

Challenges

While Capsule simplifies multi-tenancy, it introduces some challenges:

Key Features

Types of Tenancy Models Capsule Supports

How to Use Capsule

Step 1: Install Capsule

kubectl apply -f https://github.com/clastix/capsule/releases/latest/download/install.yaml

Verify the Capsule components:

kubectl get pods -n capsule-system

Step 2: Create a Tenant

Create a YAML file like tenant-dev.yaml:

apiVersion: capsule.clastix.io/v1alpha1
kind: Tenant
metadata:
  name: dev-team
spec:
  owners:
    - kind: User
      name: dev-user

Apply it:

kubectl apply -f tenant-dev.yaml

Step 3: Create Namespaces under the Tenant

Use Capsule’s admission controller to assign namespaces:

kubectl create namespace dev-ns
kubectl label namespace dev-ns capsule.clastix.io/tenant=dev-team

Only users assigned to the dev-team tenant will be able to access this namespace (depending on RBAC).

Step 4: Enforce Quotas and Policies

Add resource quotas per tenant:

apiVersion: v1
kind: ResourceQuota
metadata:
  name: tenant-quota
  namespace: dev-ns
spec:
  hard:
    pods: "20"
    requests.cpu: "4"
    requests.memory: 16Gi

Capsule also supports enforcing:

Cloud Providers Supporting Capsule

Capsule is Kubernetes-native and cloud-agnostic. It runs on any CNCF-compliant Kubernetes distribution, including:

Similar Concepts