vCluster Platform v4.12 + vCluster v0.37 - Launch and scale complete tenant environments

vCluster Platform 4.12 and vCluster 0.37 move beyond tenant clusters to the complete environments around them. Define reusable environments with Stacks, run them on broader infrastructure, protect them with stronger recovery, and operate them through GitOps and fleet observability.
Deploy complete application environments with Stacks
With Stacks, platform teams can turn a collection of application components into a reusable, self-service building block. Define an environment once, expose the parameters its users should control, and deploy it consistently to a tenant cluster or control plane cluster. Teams can install a Stack from those available to them, add it during tenant-cluster creation, or declare it through vcluster.yaml so its lifecycle follows the cluster.
Stacks coordinate more than installation. Applications without dependencies can deploy concurrently, while dependent tasks wait for health gates and can consume values captured from earlier tasks. Each application remains a long-lived installation with its own status and logs, while the Stack provides an aggregate view and keeps ownership and cleanup tied to the deployment. Teams retain one durable place to understand and manage the complete environment through day-2 operations.
The underlying StackTemplate and StackInstance custom resources define the reusable offering and each deployment. They can be made of any combination of AppInstance or ArgoCDApplication. This provides the managed application foundation, replacing the older Task and HelmRelease installation path.

Deploy Run:ai with a certified Stack
Platform 4.12 includes certified NVIDIA Run:ai Stacks, giving platform teams a ready-to-use path for deploying Run:ai as a complete tenant environment. The bundled templates coordinate registry setup, ingress, TLS, NVIDIA GPU components, the Run:ai control plane, tenant registration, and cluster agents in reusable, dependency-aware workflows. Teams can deploy these components consistently while retaining the status, logs, lifecycle management, and cleanup provided by Stacks.
For hard multitenancy at the Run:ai control-plane layer, the dedicated model gives each tenant an independent Run:ai control plane and GPU Operator lifecycle. For trusted soft-multitenant environments, the central model installs the shared host foundation once and reuses its Run:ai control plane and GPU Operator while keeping registration and runtime resources separate for each tenant. Both bundled tenant templates use shared control plane cluster nodes by default; node labels control scheduling, not runtime isolation. Add private nodes when node-level tenant isolation is required.

Argo CD and Fleet Observability now included in the Free tier
The rollout of Stacks expands Platform’s Argo CD-based application workflows. Alongside that work, the Argo CD integration and Fleet Observability, previously starting at the Dev tier, are now included in the Free tier. Anyone running vCluster Platform can register tenant clusters and control plane clusters with Argo CD and monitor them through the bundled Fleet Observability stack without a paid license. See the Argo CD integration and Fleet Observability docs for setup steps.
Protect environments with stronger snapshot recovery
Complete environments need dependable recovery as well as repeatable deployment. Before a restore begins, vCluster verifies that it can access the requested snapshot. Expired or invalid S3 credentials now fail before the control plane is restarted, so an unsuccessful recovery attempt does not create unnecessary downtime.
Teams can also better protect snapshots at rest. S3-backed snapshots support server-side encryption, including customer-managed KMS keys, while object-store credentials are stored in a Kubernetes Secret instead of being embedded in the control-plane Pod specification.
Scheduled snapshot coverage now includes Azure Blob Storage alongside existing S3-compatible paths. Platform can also configure and manage automatic snapshots for standalone tenant clusters, bringing scheduled protection into the same workflow used for other Platform-managed clusters. vCluster can convert embedded-etcd snapshots when restoring into another supported backing store, including deployed etcd or a supported external database target. Together, these changes make snapshots a more dependable and flexible recovery mechanism across supported datastores and storage providers.

Breaking Changes
App deployment APIs have changed
Platform removes the Task API, HelmRelease API, the legacy virtual cluster API group, and the related chartinfos, clusters/charts, and projects/charts discovery endpoints as part of the move to long-lived AppInstance resources. Automation that installs apps through Tasks or HelmReleases, or discovers charts through those endpoints, must migrate to AppInstance and the new app APIs.
Standalone snapshot credentials must be stored in the Platform project namespace
For standalone tenant clusters, snapshots.auto.storage.<provider>.credential.secretNamespace is no longer supported. Platform always resolves the Secret named by secretName from the same project namespace as the VirtualClusterInstance. Before upgrading, copy or recreate affected S3, OCI, or Azure credential Secrets in that namespace, then remove secretNamespace from the virtual cluster configuration or template. Pod-based tenant clusters are unaffected.
Before upgrading a standalone tenant cluster:
snapshots:
auto:
storage:
type: s3
s3:
credential:
secretName: aws-cred
secretNamespace: backup-secrets For standalone tenant clusters in Platform 4.12:
snapshots:
auto:
storage:
type: s3
s3:
credential:
secretName: aws-cred The aws-cred Secret must exist in the Platform project namespace containing the VirtualClusterInstance. Apply the same change to OCI or Azure credentials that set secretNamespace.
Kubernetes Version
This release uses Kubernetes 1.36 by default (v1.36.0).
Additional improvements
Restore CSI VolumeSnapshot synchronization. vCluster again syncs
VolumeSnapshotandVolumeSnapshotContentresources to the host cluster andVolumeSnapshotClassresources into the tenant cluster. This corrects an unintentional removal in v0.36 that affected customers using CSI snapshot resources. The separate removal of snapshot-managed volume backup and restore is unchanged.Run private-node workloads on more infrastructure. Platform adds KubeVirt CSI for stateful workloads, GPU and PCI passthrough, Netris-backed networking for Metal3, and Kube-OVN load balancing and pod routing.
Let Argo CD-managed tenant clusters sleep. Argo CD polling no longer resets the inactivity timer for onboarded tenant clusters, allowing sleep mode to suspend clusters that would otherwise appear continuously active.
Set properties per node pool. Static and dynamic node pools can override provider-level properties for the NodeClaims they create, giving platform teams more control over different pools without duplicating the provider configuration.
Meter GPU usage across more accelerator vendors. Platform now counts AMD, Intel—including Gaudi—AWS Neuron, and Google TPU accelerators alongside NVIDIA and reports usage by vendor and resource type. Existing environments using non-NVIDIA accelerators may report a higher billable GPU total after upgrading.




