
Starlight
Kubernetes microVMs
Kubernetes isolation, without traditional VM overhead.
Run complete Kubernetes clusters on lightweight microVMs. Every controller and worker gets its own kernel and hardware boundary, and your tooling stays exactly the same.
More clusters. More isolation. Same hardware.
Deploy fully isolated Kubernetes clusters fast, on lightweight, secure microVMs.
Real Kubernetes. A real boundary under every node.
Standard Kubernetes API and kubeconfig, not an emulation.
kubectl, Helm, operators, CRDs, and controllers work unchanged.
Every controller and worker runs in its own microVM with its own kernel.
Lighter than traditional virtual machines.
MicroVM-isolated nodes
A kernel of its own, for every node.
Every controller and worker runs inside a dedicated microVM with independent kernels and resource boundaries. A compromised or malfunctioning node stays inside its own machine, and the footprint stays far below conventional VMs.

Standard Kubernetes experience
Kubernetes, unchanged.
Clusters run real Kubernetes distributions rather than translating or emulating the APIs, with k0s and k3s profiles above one shared machine runtime. Your skills, workflows, and tooling carry over as they are.

Durable lifecycle operations
Operations that survive bad timing.
Lifecycle intent is persisted and reconciled after service or host restarts. Requests are idempotent, retries and timeouts are bounded, and cleanup is failure-safe, so interrupted operations stay understandable and recoverable.

OCI node images
Immutable nodes, shipped as OCI images.
Nodes boot from immutable OCI images, versioned and digest-addressed like any container. No drift, no ad hoc patching, and every node traces back to signed, reviewable inputs.

Outcomes
Deploy clusters fast
Describe a cluster through one API and boot controllers and workers as lightweight microVMs, without racking new infrastructure for every boundary.
Boundaries that hold
Clusters and nodes stop sharing a kernel. A compromised or malfunctioning node stays inside its own machine.
Density without sharing
MicroVMs carry far less weight than conventional virtual machines, so isolation stops costing you consolidation.
Nodes you can audit
Every node boots from versioned, digest-addressed images with signed inputs, so each one traces back to reviewed software.
How it works
01
Describe the cluster
Request clusters, controllers, and workers through a versioned API built for portals and automation.
02
Nodes boot as microVMs
Controllers and workers start from immutable images, each in its own machine with its own kernel and resource budget.
03
The cluster comes to you
Nodes join over protected channels behind a stable cluster endpoint, and your kubeconfig works like it always has.
Under the hood
Versioned API contracts
Management, host, and guest interfaces are defined contracts with generated type-safe clients and typed, actionable errors.
Durable operations
Lifecycle intent is persisted and reconciled after restarts: idempotent requests, bounded retries, and failure-safe cleanup.
Secure enrollment
Nodes receive short-lived, role-bound join credentials over protected host-to-guest channels, never through logs, environment variables, or API responses.
Stable cluster endpoints
Stable names and ports stay independent of individual controllers, so control-plane machines can be replaced without touching client configuration.
Decentralized placement
Hosts continuously share a decentralized view of the fleet that guides where clusters and nodes land, with no central scheduler to depend on. Each host stays authoritative for what it finally admits.
Hardened platform, observable by design
Runs on Starlight's hardened OS with SELinux enforcement and FIPS-approved cryptography, with correlated infrastructure telemetry and no workload-log collection by default.
Strong boundaries, high density, high performance.
Scale Kubernetes without scaling risk.
Tell us about your clusters and where they run, and we will walk through what Kubernetes on microVMs looks like in your environment.
