Built for GPU Clouds That Need Real Isolation
A virtual control plane for Kubernetes that spans every layer, from bare metal provisioning to tenant cluster orchestration to workload-level security.
Core Technology
Virtual Control Planes Per Tenant Cluster
Each tenant gets a dedicated Kubernetes virtual control plane running as a pod (own API server, etcd, and scheduler) spinning up in seconds on shared GPU infrastructure with near-zero overhead.
Tenant clusters launch in seconds
Full API server and etcd per tenant
No additional physical machines required
Standards Compliance
CNCF-Certified K8s Per Tenant
Every tenant cluster is a fully conformant, CNCF-certified Kubernetes control plane: 100% API compatibility. Tenants run standard tooling, operators, and CRDs without hitting proprietary limitations.
100% Kubernetes API compatibility
Standard tooling works out of the box
Named in the NVIDIA DGX SuperPOD reference architecture
Hardware Isolation
Dedicated Physical Nodes Per Tenant
Private Nodes, the production default, give each tenant fully dedicated physical GPU nodes with their own CNI and CSI. No shared compute, no noisy-neighbor risk: complete hardware separation within the virtual control plane model.
Dedicated GPU nodes per tenant
Own CNI and CSI per environment
Complete hardware separation per tenant
Workload Security
Kernel-Native Isolation Without VM Overhead
vNode adds kernel-native workload isolation using seccomp, cgroups, namespaces, and AppArmor, preventing container breakouts at bare metal GPU performance. Because no hypervisor layer is introduced, bare metal GPU performance is fully preserved for each workload.
Container breakout protection built in
No hypervisor overhead on GPU workloads
Pairs with control plane isolation layer
Platform Operations
Central Fleet Management Across Tenants
Manage all tenant clusters from a single control plane via UI, CLI, and API. SSO, quotas, templates, and auto-sleep are built in, so platform teams operate hundreds of tenant environments without custom tooling.
Single pane across all tenant clusters
SSO, quotas, and templates built in
Boost Run launched managed K8s in 45 days