---
title: "Fleets and platform governance"
chapter: "11"
---

# Fleets and platform governance

A fleet logically groups clusters so teams can apply multi-cluster capabilities
and consistent governance.

## Fleet capabilities

Fleets support Config Sync, Policy Controller, team management, multi-cluster
traffic, fleet Workload Identity, Cloud Service Mesh, and centralized views.
Some capabilities assume namespace, service, or identity sameness across
clusters. Treat those assumptions as architecture decisions.

## Platform team product

The platform should offer paved roads:

- approved cluster/project blueprints;
- namespace and identity onboarding;
- secure workload templates;
- shared Gateway, DNS, certificate, and observability patterns;
- CI/CD and Artifact Registry;
- policy with clear errors and exceptions;
- cost allocation and quotas;
- runbooks, SLOs, support, and version lifecycle.

## Config Sync and Policy Controller

Config Sync reconciles declarative configuration from Git, OCI, or Helm sources.
Policy Controller evaluates and enforces constraints. Roll policy out in audit
or dry-run mode, then canary clusters, then wider enforcement. One wrong global
policy can stop every deployment.

## Cluster count

Use one cluster where teams can safely share and isolation is adequate. Add
clusters for environment, regulatory, region, version, failure, or strong
tenant boundaries. Do not create one cluster per team without measuring the
operational and cost impact.

Official source: [GKE fleets](https://cloud.google.com/kubernetes-engine/fleet-management/docs/fleet-concepts).
