Shared cluster. Dedicated guarantees.

Multi-tenancy is how you sell capacity nobody has contracted. It pays off only when every tenant gets an environment you can put in a contract: a boundary their auditor can verify, performance you can commit to, and dedicated hardware where the deal demands it. All inside one cluster.

The single-tenant reflex

Why a single-tenant default costs you

Arrow
Uncontracted capacity is the actual risk: Installed capacity depreciates on schedule whether or not it is sold, and around 20% of the hours you do sell are lost to execution-idle inside the running job. Multi-tenancy puts that residue in front of buyers in the shapes smaller customers actually purchase.
Arrow
The boundary is concrete, not a promise: InfiniBand partition keys on the fabric, per-tenant network segmentation, and namespaces with per-tenant credentials and quotas in Ceph and VAST. What tenants keep sharing is worth naming too: control plane, subnet manager, storage back end, and the power and cooling of one room. Those are the surfaces we harden, and your security team should hear the list from us rather than assemble it themselves.
Arrow
Single-tenant stays on the menu: Where a contract demands dedicated hardware, you dedicate nodes or a rack to one tenant, with the same control plane, onboarding and billing. It becomes a premium you price deliberately, not a default that leaves the cluster idle.
Arrow
Residency is a property of the cluster: A cluster stands in one building, under one jurisdiction. You decide which tenants it serves, and nothing moves a tenant onto hardware you did not put them on. Sharing a platform never means sharing a jurisdiction.
Isolation layers

Where tenants could collide, and what stops them

Arrow
Fabric: Your tenants share one InfiniBand fabric and are separated on it by partition keys. A tenant's adapters join only the partitions you assign, and the subnet manager enforces it, so cross-tenant traffic is not filtered after the fact — it has nowhere to form.
Arrow
Network: Each tenant runs in its own segment and address space. East-west traffic between tenants is denied by default rather than cleaned up afterwards, and the data plane enforcing it runs in user space on VPP.
Arrow
Storage: Ceph and VAST are namespaced per tenant, with credentials and quotas issued per tenant. A tenant sees its own namespace and nothing else, the same rule across block, object and file.
Arrow
Accelerator: Two modes, and the SKU decides which. For training and reserved capacity the device is assigned whole to one tenant for the life of the lease: no timesharing, so no cross-tenant contention for device memory or bandwidth. Whether a node is ever split between two tenants — which would put both either side of one NVLink domain — is never; a node goes to one tenant whole, and device memory is wiped before the next lease, and the same answer states what happens to device memory between leases. You get both before the contract, because they belong in a security review. For inference sold per token the boundary moves up to the model server: requests are isolated and metered per tenant, the service level stated in latency percentiles.
Arrow
Identity and audit: Your tenants get accounts, organisations, roles and policies in the shape AWS established, so their engineers already know it. Placements, quota changes and access decisions are logged per tenant and exportable, so their auditor reads records rather than assurances.
What you can put in an SLA

Commitments you can pass to a tenant

You commit per tenant environment inside a cluster, and Genesis Grid holds the line underneath. We commit what the software can hold: control plane, portal and meter. Availability of a tenant environment is a product of your facility, your hardware and this software, so it is agreed per deployment against the estate we survey with you.

99.9 %

availability Genesis commits for control plane, portal and meter

under 15 minutes

control plane, portal and metering downtime during a platform upgrade

72 hours

notice before a node is cordoned for maintenance

Svg

The questions your risk team will ask

What happens when one tenant tries to take the whole cluster?
Substrack Icon

It cannot. Each tenant runs against a committed quota and bursts only into headroom nobody reserved, never into capacity another tenant is guaranteed. The oversubscribing tenant queues or buys more, and the others see nothing.

How is the InfiniBand fabric itself partitioned?
Plus Icon

By partition keys — and what decides whether that is hard is who may set them. A boundary that holds only while the tenant behaves is not a boundary, so where enforcement sits — adapter, switch port, subnet manager — is all three: the subnet manager assigns, adapter and switch port enforce, and your network team gets it in writing before anything is signed. The subnet manager itself runs on management nodes inside your control plane, never on tenant nodes. It surprised NVIDIA's own engineers when we showed them.

How exactly is tenant data separated in storage?
Plus Icon

By namespace. Ceph and VAST each carry per-tenant namespaces, and every tenant gets its own credentials and quotas against them. That is what the platform enforces, across block, object and file. Anything beyond it — key management, encryption, retention — is a choice you make on top and should describe to your tenants as your own, not as something the stack does for you.

Does multi-tenancy cost my tenants performance?
Plus Icon

What differs between tenants is what they bought. For reserved capacity the accelerator is assigned whole and the quota is committed; for inference sold per token the service level is stated in latency percentiles. The scheduler reserves against the guarantee rather than the average, so a busy cluster does not change what a tenant contracted for.

Who carries the SLA when something breaks?
Plus Icon

The contract with your tenant stays yours, and Genesis Grid gives you the enforcement and the evidence underneath it. Platform commitments are agreed per deployment, so you never promise upward more than the stack below holds.

Your hardest tenant contract
Test the isolation model against it
Arrow