Secure Multi-Tenant Isolation for Kubernetes | Edera

Multi-Tenant Isolation

Your tenants shouldn't have to trust each other. Now they don't.

Run more customers on less infrastructure without betting your security on it.

See How It Works

Kubernetes namespaces are an organizational boundary, not a security one. Every container shares the same Linux kernel — and that kernel is the attack surface. A container escape gives an attacker a path from one tenant to every other on the node. A kernel panic takes them all down.

Most teams choose cluster-per-tenant. That means doubling your control planes, your patching cycles, your monitoring stacks, and your cloud bill every time you win a new enterprise deal. Your engineers end up managing Kubernetes and cloud sprawl. Your CFO ends up questioning your margins.

Edera is a Type-1 hypervisor that gives each Kubernetes pod its own isolated Linux kernel. We call these zones. When a workload panics, that zone goes down — nothing else does. When a container tries to escape, it hits a hypervisor boundary with no host on the other side. The blast radius of any failure is exactly one workload — by architecture, not by policy. Each workload gets a cryptographic identity via SPIFFE/SPIRE, and true private networking ensures packets never touch the host.

60%

Node Reduction

Cut cluster sprawl, cut cloud spend

<1%

CPU Overhead

VM-level isolation at bare-metal speed

ZERO

Critical findings

Found in Trail of Bits 4-week public audit

7

CVEs Blocked

Eliminated by design, not patching

766ms

Zone startup

2.5x faster than Kata, no VT-x needed

Go Deeper on Multi-Tenant Isolation

How container isolation works in Kubernetes, why shared-kernel boundaries fail in multi-tenant environments, and what structural isolation actually requires.

Multi-Tenant Isolation Questions, Answered

Common questions about container isolation in Kubernetes — how Edera compares to namespaces, Kata Containers, and gVisor, and what changes when every pod runs in its own kernel.

  1. Does Edera reduce Kubernetes infrastructure costs?
    One Edera customer was able to reduce their infrastructure sprawl by 62% using Edera’s secure multi-tenancy, going from 40,000 servers to 15,200 servers.
  2. How does Edera handle a kernel panic?
    One tenant crashes. Everyone else keeps running. That's it. That's the entire answer.
  3. How does Edera differ from namespaces?
    Namespaces set organizational boundaries above the kernel, but they can't stop kernel-level exploits. Edera isolates at the hypervisor, each pod runs in its own zone with a dedicated Linux kernel, no shared attack surface.
  4. How does Edera compare to Kata Containers?
    Both use per-pod kernel isolation. Kata requires hardware virtualization extensions, limiting compatible instance types. Zone startup: Edera 766ms vs. Kata 1,934ms. Edera runs on commodity hardware with no nested virtualization required.
  5. How does Edera compare to gVisor?
    gVisor intercepts syscalls but keeps the host kernel in the trust boundary and supports only 78% of Linux syscalls. Edera removes the host kernel entirely — every syscall runs in the pod's own kernel. No compatibility gaps, no shared attack surface.
  6. What does Edera save on infrastructure?
    Cluster-per-tenant multiplies control planes, patching surfaces, and cloud spend. Customers moving to Edera's secure multi-tenant architecture report up to 60% worker node reduction — without trading away isolation.
  7. What changes does Edera require to deploy?
    Two lines in the pod spec: a runtimeClassName and a kernel annotation. Existing images run unmodified — no CI/CD changes, no image rebuilds, no specialized hardware. Works with EKS, GCP, AKS, on-prem, and bare metal. No change management, no retraining your team, no renegotiating your cloud contract.
  8. What is Edera's trusted computing base?
    Standard containers trust the entire Linux kernel — 30M+ lines of code — as their security boundary. Edera's TCB is the Xen microkernel, written in MISRA C with Rust services. Trail of Bits found zero high or medium severity findings.
  9. How can I learn more about the Trail of Bits public audit of Edera?
    The report on the Trail of Bits penetration test is available in Edera's Trust Center. You can also read more about the process in our blog post on the audit. In their executive summary, Trail of Bits concluded: "The security posture of Edera and its surrounding infrastructure is generally robust, with no medium or high severity findings identified in this audit."

The Multi-Tenancy Gloss

Key terms for understanding container isolation, kernel boundaries, and secure multi-tenancy in Kubernetes — from blast radius and container escapes to how RuntimeClass and hard multi-tenancy actually work.