Isolation
Your neighbours cannot see you
Tiers never share a cluster. Inside a cell, every instance gets its own Kubernetes namespace with a default-deny network policy, its own credentials, its own volume and its own backup prefix.
How it works
Isolation, step by step
- Step 01
Your plan picks the cell
Free instances run in free cells, paid instances in standard cells, and secure placement in a HIPAA cell in a separate account.
- Step 02
One namespace per instance
The operator renders the database, a resource quota and a default-deny network policy into a namespace of its own.
- Step 03
Only the gateway gets in
Client traffic reaches a pod only through the gateway route for that instance. Other tenants have no network path.
- Step 04
Policies are tested
A hostile-neighbour suite tries to reach another tenant and to escape the namespace, and expects every attempt to be denied.
What you get
-
Physical tier separation
Free, standard and HIPAA cells are separate clusters with their own keys and storage. A busy free cell cannot slow a paid one.
-
Default-deny networking
Each instance namespace starts with no ingress or egress beyond DNS. Backups, migrations and the gateway get narrow, named exceptions.
-
Admission policies
Kyverno rejects privileged containers, host paths, images outside the allow-list, mounted service-account tokens and Ingresses to internal ports.
-
Per-instance credentials
Generated inside the cell by the operator. The control plane stores only a reference, never the secret.
-
Dedicated node pools
Move an instance onto nodes reserved for your org with the dedicated-node placement (Team and Enterprise).
-
Org-scoped API
Every API lookup resolves through your org. Asking for another org's resource returns 404, never its data.
Try it
Placement is set per instance at create time.
# Shared standard cell (default)
zb instances create --engine postgres --size s1 --name api-db
# Nodes reserved for your org (Team and Enterprise)
zb instances create --engine postgres --size m4 --placement dedicated-node --name ledgerPlan availability
Generated from the same plan catalogue that billing and the API use.
- Included
Free
$0 /moFree cell, own namespace per instance
- Included
Solo
$25 /moStandard cell, own namespace per instance
- Included
Team
$599 /moStandard cell, plus dedicated nodes and the HIPAA cell
- Included
Enterprise
CustomStandard cell, plus dedicated nodes and the HIPAA cell
Namespace isolation and default-deny networking apply on every plan, including Free.
Questions
Does the free tier share infrastructure with paid instances?
No. Free instances run in separate free cells. Upgrading moves the instance to a standard cell.
Can Databasezy staff read my data?
Our operator and provisioner have no exec and no volume read path. Staff can only reach data through a time-boxed support grant that you issue.
How is isolation verified?
An automated hostile-neighbour test runs against a live cluster and fails if a pod in one instance namespace can reach another tenant or if any admission policy lets an escape hatch through.
Related features
-
Secure hosting
HIPAA-ready placement you turn on per database, under a signed BAA, with dedicated nodes and per-org keys.
Learn more about Secure hosting -
Network security
TLS on every connection, per-instance IP allow-lists, optional mTLS and support access only with your grant.
Learn more about Network security -
Teams and roles
Roles that mean something, project-scoped access, budgets, approval requests and SSO on Team and Enterprise.
Learn more about Teams and roles
Start today
Create your first database
A free instance, no card. Upgrade when you outgrow it; nothing converts silently.