Project Lightning Talk: Capsule: Launching Multi-Tenancy to New Kubernetes Hor... Dario Tranchitella

Dario Tranchitella

KubeCon + CloudNativeCon Europe 2025 · Project Lightning Talk

Overview

Dario Tranchitella, the creator of Project Capsule, delivered an insightful lightning talk at KubeCon EU, introducing Capsule as a pivotal solution for managing multi-tenancy within Kubernetes environments. This open-source project, now a part of the Cloud Native Computing Foundation (CNCF), addresses a critical challenge faced by organizations operating Kubernetes at scale: how to allow multiple independent teams or "tenants" to share a single Kubernetes cluster securely and efficiently, without sacrificing isolation or escalating operational complexity.

Watch on YouTube

Visual summary for Project Lightning Talk: Capsule: Launching Multi-Tenancy to New Kubernetes Hor... Dario Tranchitella by Dario Tranchitella
Visual summary for Project Lightning Talk: Capsule: Launching Multi-Tenancy to New Kubernetes Hor... Dario Tranchitella by Dario Tranchitella

Key moments

  1. 0:00 Introduction to Capsule and multi-tenancy problem
  2. 0:40 Capsule's solution: virtual slices for Kubernetes multi-tenancy
  3. 1:30 Capsule's operational model: tenant definition and self-service
  4. 2:00 Capsule as a policy engine using Kubernetes primitives
  5. 2:50 Introducing Capsule Proxy for simplified namespace access
  6. 3:40 Capsule's real-world adoption by DoD, TomTom, and ASML
  7. 4:20 Join the Capsule community: maintainers and adopters needed

Project Lightning Talk: Capsule: Launching Multi-Tenancy to New Kubernetes Horizons

Speakers: Dario Tranchitella, Creator, Project Capsule

Conference: KubeCon EU

YouTube: https://www.youtube.com/watch?v=02dSHShBVuk

Overview

Dario Tranchitella, the creator of Project Capsule, delivered an insightful lightning talk at KubeCon EU, introducing Capsule as a pivotal solution for managing multi-tenancy within Kubernetes environments. This open-source project, now a part of the Cloud Native Computing Foundation (CNCF), addresses a critical challenge faced by organizations operating Kubernetes at scale: how to allow multiple independent teams or "tenants" to share a single Kubernetes cluster securely and efficiently, without sacrificing isolation or escalating operational complexity.

The core problem Capsule aims to solve revolves around the dichotomy of Kubernetes cluster management for multiple users. Organizations often find themselves choosing between two suboptimal extremes: either deploying a multitude of small, dedicated Kubernetes clusters for each team, leading to significant "cluster sprawl" and high operational overhead, or consolidating all tenants into a single, massive cluster, which risks becoming a single point of failure and makes robust isolation incredibly difficult. Capsule offers an elegant middle ground, enhancing Kubernetes' native capabilities by introducing a Tenant definition, thereby creating virtual, isolated slices of a single cluster.

This innovative approach allows cluster administrators to define clear boundaries and policies for different tenant groups, empowering them with self-service capabilities while maintaining overall cluster stability and security. By leveraging and extending Kubernetes primitives, Capsule provides a framework for robust multi-tenancy that balances the need for resource efficiency with strong isolation, making it a valuable addition to the cloud-native ecosystem for organizations grappling with scalable and secure multi-user Kubernetes deployments.

Background

▶ Watch: Introduction to Capsule and multi-tenancy problem (0:00)

The landscape of Kubernetes adoption has seen a significant shift towards larger, more complex deployments, often serving diverse internal teams or external customers. This evolution has brought the concept of multi-tenancy to the forefront, presenting a fundamental operational and security challenge. Historically, organizations have approached multi-tenancy in Kubernetes through two primary, often problematic, strategies.

The first strategy involves creating a dedicated Kubernetes cluster for each tenant. While this provides strong isolation—each tenant has its own control plane and data plane—it quickly leads to cluster sprawl. Managing dozens or even hundreds of independent clusters incurs substantial operational overhead, including patching, upgrades, monitoring, and maintaining consistent configurations across all environments. This "pain," as described by Tranchitella, consumes significant engineering resources and can introduce configuration drift, potentially leading to security vulnerabilities or performance inconsistencies.

The alternative strategy is to host all tenants within a single, monolithic Kubernetes cluster. This approach initially appears more resource-efficient, as it avoids the overhead of managing multiple control planes. However, without robust mechanisms for isolation and resource governance, a single cluster can become a "huge single point of failure." In such an environment, misconfigurations, resource exhaustion, or security incidents in one tenant's workload can potentially impact others, leading to service disruptions or unauthorized access. Achieving true isolation for network, compute, and storage resources, alongside granular access control, becomes an intricate and error-prone task using only native Kubernetes features.

Project Capsule emerged to address this critical gap, seeking to find the "perfect balance," as Tranchitella metaphorically put it, "with a grain of salt." It aims to intercept the need for a solution that avoids both the excessive operational burden of cluster sprawl and the inherent risks of an inadequately isolated single large cluster. Capsule's approach is to enhance Kubernetes' inherent capabilities, providing a framework that enables secure, efficient, and self-service multi-tenancy without resorting to the extremes. As an open-source project that has achieved CNCF affiliation, Capsule builds upon the community's collective expertise to deliver a standardized and robust solution for this pervasive challenge.

Key Findings

▶ Watch: Capsule's operational model: tenant definition and self-service (1:30)

Project Capsule's primary contribution is its innovative approach to Kubernetes multi-tenancy, centered around the introduction of the Tenant as a first-class, cluster-scoped resource. This core abstraction allows for the logical segmentation of a single Kubernetes cluster into multiple isolated virtual clusters, each managed by a distinct tenant.

The key findings and contributions of Project Capsule include:

  • Tenant Definition as a Cluster-Scoped Resource: Capsule introduces a custom resource definition (CRD) for the Tenant. This Tenant object is a cluster-scoped resource, meaning it's defined once at the cluster level and serves as the central source of truth for all tenant-related configurations, owners, and policies. This design makes Capsule inherently GitOps compliant, enabling declarative management of multi-tenancy.
  • Self-Service Namespace Creation: A significant benefit of Capsule is its ability to empower tenants with self-service capabilities. Once a Tenant is defined by the cluster administrator, the respective tenant users (e.g., "Atrades" or "Harkonnen" in Tranchitella's Dune analogy) can autonomously create and manage their own namespaces within the boundaries of their assigned tenant. This shifts the operational burden from cluster administrators to the tenants themselves for day-to-day namespace management.
  • Policy Engine and Automatic Reconciliation: Capsule functions as a powerful policy engine. It allows cluster administrators to define comprehensive policies at the tenant level, which are then automatically enforced across all namespaces belonging to that tenant. These policies can include crucial constraints such as the maximum number of pods, the maximum number of namespaces, Role-Based Access Control (RBAC) rules, Resource Quotas, and Limit Ranges. The Capsule operator continuously reconciles these policies, ensuring consistent enforcement.
  • Leveraging Kubernetes Primitives: Rather than reinventing the wheel, Capsule intelligently leverages and enhances existing Kubernetes primitives. It integrates seamlessly with native Kubernetes features like RBAC, Resource Quotas, Limit Ranges, and Network Policies. This means that the isolation and governance mechanisms provided by Capsule are built upon the well-understood and robust foundations of Kubernetes itself, extending their scope to the tenant level.
  • Resource Replication: Capsule provides mechanisms for replicating resources across namespaces within a tenant. A common use case highlighted is the replication of secrets, such as credentials for container registries (e.g., Docker Hub or Harbor). This ensures that all namespaces within a tenant have consistent access to necessary shared resources without manual duplication or complex synchronization logic.
  • Capsule Proxy for Tenant-Scoped API Access: To provide a truly isolated experience, Capsule introduces the Capsule Proxy. This is an ACL proxy that sits in front of the Kubernetes API server. Its primary function is to filter API requests, ensuring that tenants only see and interact with their allocated resources (e.g., their own namespaces) when using standard kubectl commands. This solves the common multi-tenancy problem where kubectl get namespace would otherwise list all namespaces in the cluster, potentially exposing information to unauthorized tenants.

Technical Deep Dive

▶ Watch: Capsule as a policy engine using Kubernetes primitives (2:00)

Project Capsule's technical architecture is founded on the principle of extending Kubernetes' native capabilities through custom resources and operators to achieve robust multi-tenancy. At its heart is the Tenant custom resource, a cluster-scoped object that serves as the administrative boundary for a group of namespaces.

The workflow begins with the cluster administrator defining a Tenant object. This definition is GitOps compliant, meaning it can be managed declaratively through version control systems. The Tenant resource specifies key attributes, including the owners of the tenant and potentially other metadata relevant for policy enforcement or resource replication. For instance, a Tenant might define that "Atrades" is an owner, giving them specific administrative privileges within their tenant's scope.

Once a Tenant is established, the Capsule operator takes over. This operator continuously watches for changes to Tenant resources and new namespaces being created. When a tenant user creates a new namespace, Capsule automatically assigns it to their pre-defined tenant. This is where Capsule's policy engine comes into play. The operator leverages Kubernetes primitives to apply and enforce policies defined at the tenant level across all associated namespaces.

Role-Based Access Control (RBAC) is a critical component. Capsule automatically generates and manages RBAC roles and role bindings to ensure that tenant users only have access to their own namespaces and resources within those namespaces. For example, a tenant administrator might have full control over their tenant's namespaces but no visibility or control over namespaces belonging to other tenants or the cluster-wide resources.

Resource Quotas and Limit Ranges are also automatically applied and reconciled by Capsule. The Tenant definition can specify aggregate resource quotas for the entire tenant, such as a maximum amount of CPU, memory, or persistent storage that all namespaces within that tenant can collectively consume. Similarly, Limit Ranges can be applied to ensure that individual pods or containers within a tenant's namespaces adhere to specified minimum and maximum resource requests and limits, preventing resource starvation or runaway resource consumption.

Network Policies are another vital primitive enhanced by Capsule. While the talk doesn't detail specific Network Policy generation, the framework implies that tenant-specific network policies can be defined, ensuring that traffic flow is restricted to within a tenant's boundaries or to explicitly allowed external services, further enhancing isolation.

A powerful feature is resource replication. Capsule can replicate specific resources, such as Kubernetes Secret objects, across all namespaces within a given tenant. This is particularly useful for shared credentials, such as those required to access container registries like Docker Hub or Harbor. Instead of manually creating and synchronizing these secrets in every namespace, an administrator can define a global or tenant-scoped secret, and Capsule ensures it's available where needed, simplifying application deployment and management for tenants.

The Capsule Proxy is a crucial architectural component for providing a seamless and secure multi-tenant user experience. It acts as an ACL proxy positioned in front of the Kubernetes API server. When a tenant user executes a kubectl command, the request first goes through the Capsule Proxy. The proxy inspects the request and the user's identity, then filters the response from the API server to show only the resources relevant and accessible to that specific tenant. For example, when a tenant user runs kubectl get namespaces, the Capsule Proxy ensures they only see the namespaces belonging to their tenant, rather than all namespaces in the cluster. Tranchitella noted that the Capsule Proxy has undergone "evolutions" and even had some "CVAs" (security vulnerabilities) in the past, highlighting the complexity and security-critical nature of this component. This underscores the need for continuous security audits and updates for such a foundational piece of multi-tenancy infrastructure.

Finally, Capsule is designed as a framework that integrates with the broader cloud-native ecosystem. It supports popular tools for application delivery like Flux CD and Argo CD, allowing tenants to deploy and manage their applications declaratively within their isolated environments. This ecosystem integration reinforces Capsule's role as an enabler for modern GitOps practices in a multi-tenant context.

Demo / Proof of Concept

▶ Watch: Capsule's real-world adoption by DoD, TomTom, and ASML (3:40)

While Dario Tranchitella's KubeCon EU talk was an "elevator pitch" and a lightning talk, it did not feature a live, step-by-step demonstration of Project Capsule in action. Instead, the speaker effectively served as a proof-of-concept by highlighting real-world adoption and the diverse ways organizations are leveraging Capsule to solve their specific multi-tenancy challenges. These adopter stories serve as compelling evidence of Capsule's practical utility and robust capabilities.

One significant adopter mentioned is a DoD agency from the US. This agency is utilizing Capsule specifically to decrease cluster sprawl. By deploying smaller, more manageable Kubernetes clusters and then using Capsule to create virtual slices for different tenants within these clusters, they achieve the necessary isolation without incurring the massive operational overhead of managing a dedicated physical cluster for every single team or project. This demonstrates Capsule's effectiveness in optimizing resource utilization and simplifying cluster operations at a large scale.

TomTom Engineering presents another compelling use case. They have implemented Capsule to establish a clear contract with their developers. This contract dictates that developers only need to focus on deploying their applications using tools like Kustomize, abstracting away the underlying Kubernetes infrastructure complexities. Capsule ensures that developers operate within their defined boundaries, managing their namespaces and resources in a self-service manner, while the platform team maintains control over the overarching cluster policies and resource allocation. This highlights Capsule's role in fostering developer autonomy while maintaining platform governance.

Finally, ASML is leveraging Capsule to create a platform for data engineers. Data engineering workloads often have unique resource requirements and security considerations. By using Capsule, ASML can provide isolated environments tailored to the needs of different data engineering teams, ensuring they have the necessary resources and permissions without interfering with other teams or compromising the overall cluster stability. This illustrates Capsule's adaptability to specialized workloads and its ability to facilitate complex platform builds.

These varied adoption scenarios from diverse organizations—ranging from government agencies to engineering firms and specialized platforms—collectively underscore Capsule's versatility and its proven ability to deliver on its promise of efficient, secure, and manageable multi-tenancy in Kubernetes environments.

Defensive Implications

▶ Watch: Join the Capsule community: maintainers and adopters needed (4:20)

Project Capsule introduces several significant defensive implications for organizations operating Kubernetes clusters, primarily by enhancing isolation, streamlining policy enforcement, and mitigating operational risks associated with multi-tenancy.

Firstly, Capsule directly addresses cluster sprawl, which is a significant operational and security burden. By enabling multiple tenants to share fewer, larger clusters, organizations can reduce the sheer number of Kubernetes control planes and nodes they need to manage. This consolidation inherently reduces the attack surface, as there are fewer distinct environments to secure, patch, and monitor. Fewer clusters mean less configuration drift, more consistent security policies, and a more manageable inventory for security teams.

Secondly, Capsule dramatically strengthens isolation between tenants. By leveraging and extending Kubernetes primitives like RBAC, Resource Quotas, Limit Ranges, and Network Policies, Capsule ensures that each tenant operates within clearly defined boundaries. RBAC policies prevent unauthorized access between tenants, while Resource Quotas and Limit Ranges protect against resource exhaustion attacks or "noisy neighbor" issues where one tenant's excessive consumption impacts others. The ability to automatically apply and reconcile these policies across all namespaces within a tenant ensures consistent enforcement and reduces the likelihood of manual misconfigurations.

The Capsule Proxy is a critical defensive component. By acting as an ACL proxy in front of the Kubernetes API server, it enforces tenant-scoped visibility and access. This prevents tenants from enumerating or interacting with resources outside their designated virtual cluster, a common requirement for multi-tenant security. The mention of past "CVAs" (security vulnerabilities) in the Capsule Proxy, while indicating challenges, also highlights the project's commitment to addressing and hardening this critical security layer. Defenders must pay close attention to the security posture of the Capsule Proxy itself, ensuring it is always running the latest patched versions and is properly configured to prevent any bypasses. Regular security audits and penetration testing of the Capsule deployment are crucial.

Furthermore, Capsule's approach facilitates centralized policy enforcement and auditability. Defining policies at the Tenant level through cluster-scoped CRDs provides a single, auditable source of truth for how resources are allocated and permissions are granted across an entire multi-tenant environment. This simplifies compliance efforts and allows security teams to verify that policies are consistently applied, rather than having to inspect individual namespaces or clusters.

Finally, by empowering tenants with self-service namespace creation within pre-defined boundaries, Capsule reduces the reliance on cluster administrators for routine tasks. This can decrease the potential for human error in granting permissions or allocating resources, as the automated Capsule operator handles these aspects based on the tenant definition. This shift towards automated governance enhances the overall security posture by reducing manual intervention points.

In summary, defenders should view Capsule as a strategic tool for implementing robust, scalable, and auditable multi-tenancy in Kubernetes. While it significantly improves the security landscape by design, careful attention must still be paid to the security of the Capsule components themselves, particularly the Capsule Proxy, and to the comprehensive definition of tenant policies.

Key Takeaways

  • Solves Kubernetes Multi-Tenancy Challenges: Project Capsule effectively addresses the dilemma of cluster sprawl versus single points of failure by introducing a robust multi-tenancy solution for Kubernetes.
  • Virtual Cluster Slices: It enables the creation of isolated "virtual slices" or virtual clusters within a single physical Kubernetes cluster through the Tenant custom resource definition.
  • Leverages Kubernetes Primitives: Capsule builds upon and enhances existing Kubernetes features like RBAC, Resource Quotas, Limit Ranges, and Network Policies for strong isolation and policy enforcement.
  • Empowers Self-Service for Tenants: Tenants gain the ability to create and manage their own namespaces and resources within pre-defined boundaries, fostering developer autonomy while maintaining administrative control.
  • Capsule Proxy for Secure Access: The Capsule Proxy is a critical component that provides tenant-scoped API access, ensuring users only interact with their authorized resources and enhancing security.
  • Open Source and CNCF Project: As a CNCF project with a growing community and diverse adopters (including a DoD agency, TomTom, and ASML), Capsule offers a well-supported and evolving solution for multi-tenant Kubernetes.

About the Speaker(s)

Dario Tranchitella is the creator of Project Capsule, an open-source initiative focused on bringing robust multi-tenancy capabilities to Kubernetes. His passion for the project was evident during his KubeCon EU lightning talk, where he expressed his happiness at presenting Capsule, noting it was his "first open source project" and had since achieved CNCF affiliation. Tranchitella's work with Capsule stems from the practical challenges encountered when managing multiple tenants within shared Kubernetes clusters, driving him to develop a solution that balances operational efficiency with strong isolation.

Reviews

Dr. Zero (Offensive Security Researcher) — STRONG ACCEPT

Dario Tranchitella's lightning talk on Project Capsule delivers a robust, Kubernetes-native solution to the pervasive multi-tenancy problem. By introducing a 'Tenant' CRD and an intelligent Capsule Proxy, it elegantly balances isolation with operational efficiency, allowing organizations to avoid both cluster sprawl and single-point-of-failure monolithic clusters. This is a genuinely impactful defensive innovation for platform teams struggling with secure, scalable multi-tenant environments.

Heather Calloway (CISO) — STRONG ACCEPT

Dario Tranchitella's lightning talk on Project Capsule delivers a clear, unsentimental view of a pervasive problem in cloud-native operations: managing multi-tenancy without succumbing to either cluster sprawl or a vulnerable monolithic environment. Capsule offers a robust, open-source solution that directly addresses governance, risk, and operational efficiency, leveraging Kubernetes primitives to create secure, isolated tenant spaces. Its adoption by diverse organizations, including a DoD agency, serves as compelling evidence of its real-world impact and value for security leaders navigating complex Kubernetes deployments.

→ Top-rated talks at KubeCon + CloudNativeCon Europe 2025

All talks from KubeCon + CloudNativeCon Europe 2025