A Dapr control plane for every team, in one cluster
Namespace isolated Dapr control planes on premises or air-gapped, with security enhanced binaries that stay 100% compatible with the open-source Dapr APIs and SDKs.
Requires a Premium Dapr support plan
Namespace isolation
- Scope a control plane to one namespace or a defined list
- Run multiple control planes side by side in one cluster
- Keep a control plane problem inside the namespaces it serves
Security review ready
- Reduced ClusterRole requirements versus open-source Dapr
- An install option with no CRDs and no ClusterRoles at all
- Published cluster resource requirements to review up front
Backed by Diagrid
- CVE fixes backported to your version, no upstream wait
- 100% compatible with the Dapr APIs and SDKs
- 24/7 support with guaranteed response times
What D3E is
A custom distribution of open-source Dapr, built and tested for organizations running Dapr at scale or under strict security review. The main difference is tenancy.
Open-source Dapr
- One control plane with cluster-wide reach
- Cluster-wide permissions, CRDs, and ClusterRoles
- Fixes arrive with the next upstream release
D3E
- Control planes scoped to a namespace or a list of them
- Minimized permissions, with a CRD and ClusterRole free option
- CVE fixes backported to the version you run
Everything above the installation stays where it is. D3E is a drop-in replacement, so application code, components, and building blocks are unchanged.
Five things D3E gives you
Multi-tenancy across teams
Set each control plane to cover only the namespaces it should serve, so one team's config or upgrade never touches another.
- Target a subset of namespaces for sidecar injection
- Run multiple control planes side by side in one cluster
- Lighter load on the Scheduler and Placement services
A smaller permission footprint
Cluster-wide permissions are where most Dapr rollouts stall in review. D3E installs with a minimized permission set.
- Reduced ClusterRole requirements, plus granular access control
- Cluster resource requirements published for review up front
CVE patches for your version
Critical fixes are backported to custom Dapr versions unavailable in open source.
- No waiting on the next upstream release
- No version jump pulling in unrelated changes
A drop-in replacement
100% compatible with the Dapr APIs and SDKs, installed by Helm chart from the Diagrid registry.
- Application code and component definitions stay as they are
- Migration is a Helm uninstall and install, so schedule it
Enterprise support behind the binaries
24/7 support with guaranteed response times on production issues, backed by a dedicated customer success team.
- Incidents by portal, email, or Slack
- Regular architecture and feature sessions
Four installation options
Pick the isolation model that matches your cluster layout and your security requirements.
Single namespace isolation
One team running all Dapr applications in one namespace
The control plane is scoped to one namespace. Only applications there receive sidecars.
Multi-namespace isolation
Several teams sharing clusters and namespaces, but needing isolated Dapr access
The control plane is scoped to a list of namespaces. Only applications in those namespaces receive sidecars.
Multiple Dapr installations
Teams that need fully separated control planes
Multiple control plane versions run in the same cluster, each isolated to its own namespaces.
ClusterRole and CRD free
Environments that prohibit CRDs and ClusterRoles
Dapr runs in standalone mode with no sidecar injector. Sidecars come from the Diagrid Dapr Injector Helm library chart.
Read the installation guide for the full detail on each option.
Get started with D3E
D3E is available with a Premium Dapr support plan. Talk to the team about your cluster layout, your security requirements, and which installation option fits.