Skip to content
Databasezy

Isolation

Your neighbours cannot see you

Tiers never share a cluster. Inside a cell, every instance gets its own Kubernetes namespace with a default-deny network policy, its own credentials, its own volume and its own backup prefix.

Isolation, step by step

  1. Step 01

    Your plan picks the cell

    Free instances run in free cells, paid instances in standard cells, and secure placement in a HIPAA cell in a separate account.

  2. Step 02

    One namespace per instance

    The operator renders the database, a resource quota and a default-deny network policy into a namespace of its own.

  3. Step 03

    Only the gateway gets in

    Client traffic reaches a pod only through the gateway route for that instance. Other tenants have no network path.

  4. Step 04

    Policies are tested

    A hostile-neighbour suite tries to reach another tenant and to escape the namespace, and expects every attempt to be denied.

What you get

  • Physical tier separation

    Free, standard and HIPAA cells are separate clusters with their own keys and storage. A busy free cell cannot slow a paid one.

  • Default-deny networking

    Each instance namespace starts with no ingress or egress beyond DNS. Backups, migrations and the gateway get narrow, named exceptions.

  • Admission policies

    Kyverno rejects privileged containers, host paths, images outside the allow-list, mounted service-account tokens and Ingresses to internal ports.

  • Per-instance credentials

    Generated inside the cell by the operator. The control plane stores only a reference, never the secret.

  • Dedicated node pools

    Move an instance onto nodes reserved for your org with the dedicated-node placement (Team and Enterprise).

  • Org-scoped API

    Every API lookup resolves through your org. Asking for another org's resource returns 404, never its data.

Try it

Placement is set per instance at create time.

shell
# Shared standard cell (default)
zb instances create --engine postgres --size s1 --name api-db

# Nodes reserved for your org (Team and Enterprise)
zb instances create --engine postgres --size m4 --placement dedicated-node --name ledger

Plan availability

Generated from the same plan catalogue that billing and the API use.

  • Free

    $0 /mo
    Included

    Free cell, own namespace per instance

  • Solo

    $25 /mo
    Included

    Standard cell, own namespace per instance

  • Team

    $599 /mo
    Included

    Standard cell, plus dedicated nodes and the HIPAA cell

  • Enterprise

    Custom
    Included

    Standard cell, plus dedicated nodes and the HIPAA cell

Namespace isolation and default-deny networking apply on every plan, including Free.

Compare every plan on the pricing page

Questions

Does the free tier share infrastructure with paid instances?

No. Free instances run in separate free cells. Upgrading moves the instance to a standard cell.

Can Databasezy staff read my data?

Our operator and provisioner have no exec and no volume read path. Staff can only reach data through a time-boxed support grant that you issue.

How is isolation verified?

An automated hostile-neighbour test runs against a live cluster and fails if a pod in one instance namespace can reach another tenant or if any admission policy lets an escape hatch through.

Create your first database

A free instance, no card. Upgrade when you outgrow it; nothing converts silently.