Skip to main content
Version: 2.0

CloudSpaces

A CloudSpace is your team's own Kubernetes environment inside KubeOpera. Under the hood it's a vCluster: a full Kubernetes control plane running inside a host cluster. You get the experience of your own cluster — your own API server, namespaces and resources — without anyone having to build one.

Every tenant gets a default CloudSpace when they sign up. Create more whenever you want separate environments: staging and production, a sandbox per team, a space per customer project.

What's in a CloudSpace​

  • A complete Kubernetes API — its own API server, scheduler and etcd, separate from the host cluster and every other CloudSpace.
  • Standard Kubernetes resources — Deployments, Services, Ingresses, HPAs, ConfigMaps, Secrets and PersistentVolumeClaims all work as usual.
  • Private networking and DNS — services reach each other inside the CloudSpace and are only exposed to the outside through an Ingress.
  • Flux — so your apps are delivered by GitOps.
  • Your own App Advisor — an AI advisor that watches your apps and suggests improvements (see App Advisor).

The host cluster supplies the worker nodes, networking and the infrastructure that runs the CloudSpace itself.

CloudSpace lifecycle​

Each CloudSpace is backed by a Tenant resource that tenant-controller reconciles:

PhaseMeaning
PendingWaiting to start.
ProvisioningInstalling the vCluster.
InstallingFluxThe vCluster is up; Flux and the App Advisor are being installed.
ReadyEverything is healthy and ready for apps.
FailedSomething went wrong — the reason is shown and provisioning is retried.
DeletingThe CloudSpace and everything in it are being removed.

Working with CloudSpaces​

View your CloudSpaces​

Open Resources → Cloud Spaces (/cloudspaces). Each card shows the space's name, status, quota and usage, and links to its apps.

Create a CloudSpace​

In the dashboard: Cloud Spaces → New Space, then choose a name and a CPU and memory quota.

Or with the API:

POST /cloudspaces
Content-Type: application/json

{
"space_name": "prod-eu",
"cpu": 4,
"memory": 8192
}

Any user in your tenant with permission to manage CloudSpaces can create one.

Size a CloudSpace​

A CloudSpace's quota caps the CPU and memory its workloads can request, as well as its control plane. Set it when you create the space and change it at any time from the space's settings. Under the hood, the quota is applied as a Kubernetes ResourceQuota inside the vCluster together with the control plane's own limits:

spec:
quota:
cpu: "4" # total CPU for workloads in this CloudSpace
memory: "8Gi" # total memory for workloads in this CloudSpace

When a deployment would exceed the quota, it's rejected with a clear message rather than left pending.

Connect with kubectl​

Download the kubeconfig for any vCluster in your CloudSpace from the space's page (Access → Download kubeconfig) or from the API:

GET /api/v1/cloudspaces/{cloudSpaceId}/vclusters/{name}/kubeconfig

The route includes the vCluster's name because a CloudSpace can contain more than one vCluster. You can download it if you have access to the CloudSpace.

kubectl --kubeconfig ./my-cloudspace.kubeconfig get pods -A

Platform administrators can also read it directly from the host cluster:

kubectl get secret tenant-<cloudSpaceID>-kubeconfig -n kubeopera-system \
-o jsonpath='{.data.kubeconfig}' | base64 -d > ./my-cloudspace.kubeconfig

Delete a CloudSpace​

danger

Deleting a CloudSpace permanently removes its vCluster and every app and piece of data inside it. This can't be undone.

From the space's settings select Delete, and confirm by typing the space's name. Or:

DELETE /api/v1/cloudspaces/{id}

The request returns immediately and the CloudSpace shows Deleting while tenant-controller uninstalls the vCluster, confirms its host namespace is fully gone, and removes its kubeconfig. If cleanup stalls — for example on a volume that won't release — the CloudSpace shows what's blocking it so an administrator can resolve it.

CloudSpace or namespace?​

A CloudSpace is not a namespace. A namespace groups resources inside one control plane; a CloudSpace is a control plane.

NamespaceCloudSpace
Kubernetes APISharedYour own
API server and etcdSharedYour own
Cluster-wide resources (CRDs, ClusterRoles)Shared with everyoneYours alone
RBAC isolationPartialComplete
Best forGrouping resources inside one environmentIsolating teams, customers or environments

Inside a CloudSpace you can still create as many namespaces as you like.

Next steps​