Running Isolated VirtualClusters With Kata & Cluster API - Chris Hein & Eric Ernst, Apple, Inc
Description:
Explore a cutting-edge approach to achieving hard multi-tenancy in Kubernetes environments through this conference talk by Chris Hein and Eric Ernst from Apple, Inc. Discover how to leverage Cluster API Nested with VirtualCluster running inside a Kubernetes cluster, utilizing Kata runtime for workload isolation and virtual networking. Learn about the benefits of this architecture, including per-tenant Kubernetes control planes, CRDs, Admission Webhooks, Cluster level RBAC, and Aggregate APIServers, while reducing overall maintenance burden. Gain insights into sandboxed runtimes, hard multi-tenancy, scaling Kubernetes, Cluster API, and multi-cluster Kubernetes implementations. Understand the growing need for multi-tenant and zero-trust deployments in Kubernetes environments and how this solution addresses these challenges.
Running Isolated VirtualClusters with Kata and Cluster API