Diagrid
Diagrid Dapr Distribution for Enterprise

A Dapr control plane for every team, in one cluster

Namespace isolated Dapr control planes on premises or air-gapped, with security enhanced binaries that stay 100% compatible with the open-source Dapr APIs and SDKs.

Requires a Premium Dapr support plan

Namespace isolation

  • Scope a control plane to one namespace or a defined list
  • Run multiple control planes side by side in one cluster
  • Keep a control plane problem inside the namespaces it serves

Security review ready

  • Reduced ClusterRole requirements versus open-source Dapr
  • An install option with no CRDs and no ClusterRoles at all
  • Published cluster resource requirements to review up front

Backed by Diagrid

  • CVE fixes backported to your version, no upstream wait
  • 100% compatible with the Dapr APIs and SDKs
  • 24/7 support with guaranteed response times

What D3E is

A custom distribution of open-source Dapr, built and tested for organizations running Dapr at scale or under strict security review. The main difference is tenancy.

Open-source Dapr

  • One control plane with cluster-wide reach
  • Cluster-wide permissions, CRDs, and ClusterRoles
  • Fixes arrive with the next upstream release

D3E

  • Control planes scoped to a namespace or a list of them
  • Minimized permissions, with a CRD and ClusterRole free option
  • CVE fixes backported to the version you run

Everything above the installation stays where it is. D3E is a drop-in replacement, so application code, components, and building blocks are unchanged.

Five things D3E gives you

Multi-tenancy across teams

Set each control plane to cover only the namespaces it should serve, so one team's config or upgrade never touches another.

  • Target a subset of namespaces for sidecar injection
  • Run multiple control planes side by side in one cluster
  • Lighter load on the Scheduler and Placement services

A smaller permission footprint

Cluster-wide permissions are where most Dapr rollouts stall in review. D3E installs with a minimized permission set.

  • Reduced ClusterRole requirements, plus granular access control
  • Cluster resource requirements published for review up front

CVE patches for your version

Critical fixes are backported to custom Dapr versions unavailable in open source.

  • No waiting on the next upstream release
  • No version jump pulling in unrelated changes

A drop-in replacement

100% compatible with the Dapr APIs and SDKs, installed by Helm chart from the Diagrid registry.

  • Application code and component definitions stay as they are
  • Migration is a Helm uninstall and install, so schedule it

Enterprise support behind the binaries

24/7 support with guaranteed response times on production issues, backed by a dedicated customer success team.

  • Incidents by portal, email, or Slack
  • Regular architecture and feature sessions

Four installation options

Pick the isolation model that matches your cluster layout and your security requirements.

01

Single namespace isolation

One team running all Dapr applications in one namespace

The control plane is scoped to one namespace. Only applications there receive sidecars.

02

Multi-namespace isolation

Several teams sharing clusters and namespaces, but needing isolated Dapr access

The control plane is scoped to a list of namespaces. Only applications in those namespaces receive sidecars.

03

Multiple Dapr installations

Teams that need fully separated control planes

Multiple control plane versions run in the same cluster, each isolated to its own namespaces.

04

ClusterRole and CRD free

Environments that prohibit CRDs and ClusterRoles

Dapr runs in standalone mode with no sidecar injector. Sidecars come from the Diagrid Dapr Injector Helm library chart.

Read the installation guide for the full detail on each option.

Get started with D3E

D3E is available with a Premium Dapr support plan. Talk to the team about your cluster layout, your security requirements, and which installation option fits.