Capsule helps several teams share one Kubernetes cluster without handing every team unrestricted control. It groups namespaces into tenants, gives each tenant owners, and lets platform administrators set limits on what those owners can create and manage. It is useful when teams need some self-service while the platform retains common controls. Those tenants still share the cluster and its API; they are not independent Kubernetes clusters.
Chart ownership
The Capsule project documents its capsule chart at oci://ghcr.io/projectcapsule/charts/capsule and an HTTP chart repository at https://projectcapsule.github.io/charts. Its installation guide identifies Helm as the supported installation method and distinguishes the OCI distribution from the legacy repository.
Before adoption
Review tenant ownership, namespace permissions, resource quotas and the admission webhooks that enforce them. Confirm the certificate-management prerequisites for the selected chart configuration. Introduce tenant rules gradually and verify that legitimate workloads still start when limits are reached. Plan webhook availability and an emergency repair path. Evaluate hostile-workload isolation separately; namespace organization alone is not evidence of an adequate security boundary.
Use the official installation guide and tenant quickstart to evaluate the operating model.
Sources & further reading
Spotted something that needs another look?
Help improve this page →