The Open Cloud for the GitOps Era.
Stop paying the hyperscaler tax. Deploy upstream Kubernetes and true VPCs on open standards, fully managed via Terraform.
The Engine Room
Technical advantages engineered from bare-metal up for resilience, performance, and true sovereignty.
Hard Multi-Tenancy
True VPCs, Not Just VPS.
Every instance is isolated via KVM hypervisors. Build complex Layer 3 topologies, floating IPs, and private subnets powered by OVN.
Upstream Kubernetes
No Walled Gardens.
Deploy fully compliant, unmodified K8s clusters. Bring your own CNI (Cilium/Calico) and Ingress. You control the control plane.
Ceph NVMe Storage
Distributed by Default.
Cinder CSI is baked into every cluster. When your pod requests a volume, our NVMe Ceph cluster provisions it instantly with LUKS encryption at rest.
All Cloud Services We Provide
From bare-metal virtualization and Ceph NVMe storage to upstream Kubernetes, enterprise databases, and serverless runtimes—100% sovereign, open standards, and fully programmable.
Compute Engine (Nova KVM)
High-performance KVM virtual instances with nested virtualization, custom CPU/RAM flavors, live migration, and automated cloud-init provisioning.
Kubernetes Engine (Magnum & CAPI)
Production-grade, unmodified upstream CNCF Kubernetes clusters provisioned declaratively via Cluster API (CAPO). Bring your own CNI (Calico or Cilium) with native Cinder CSI.
Managed VPCs (Neutron & OVN)
Isolated Layer 3 Virtual Private Clouds powered by OVN Geneve overlay networks, distributed virtual routers (DVR), security groups, and floating IPs.
Block Storage (Ceph Cinder RBD)
Ultra-low latency distributed block volumes backed by all-NVMe Ceph pools, dynamic Kubernetes CSI volume provisioning, thin cloning, and LUKS encryption at rest.
Object Storage (Ceph S3 RGW)
High-durability distributed object store fully compatible with the AWS S3 API, supporting bucket versioning, bucket policies, multi-part uploads, and pre-signed URLs.
Load Balancers (Octavia LBaaS)
Dedicated Amphora load balancers providing high-throughput Layer 4 (TCP/UDP) and Layer 7 (HTTP/HTTPS) routing, automated TLS offloading, and health probes.
Image Registry & OS Library (Glance)
Curated library of cloud-init optimized base images (Ubuntu 24.04/22.04, Debian 12, Rocky Linux 9, Alpine, Windows) plus custom golden snapshot storage.
Secrets KMS (Barbican)
Centralized cryptographic key management service storing TLS certificates, encryption keys, and credentials, powering Cinder LUKS volume encryption.
Managed PostgreSQL (CloudNativePG)
Enterprise PostgreSQL 16 clusters featuring automated failover, streaming replication, continuous WAL archiving to S3, and Point-in-Time Recovery (PITR).
Redis Sentinel HA
Clustered Redis caching with automated 3-node Sentinel quorum election, sub-10s automatic failover, and persistent Ceph RBD storage backing.
Clustered MySQL (Percona PXC)
High-availability Galera MySQL clustering with synchronous multi-master replication, automated node provisioning, and zero data-loss failover.
Document DB (MongoDB Operator)
Managed MongoDB replica sets with automated backup schedules to S3, monitoring exporter integration, and horizontal scale-out architecture.
Managed Messaging (RabbitMQ)
Production AMQP message brokers powered by RabbitMQ Operator, quorum queues, automated mTLS encryption, and Barbican vault credential escrow.
API Gateway (Apache APISIX)
Ultra-high performance dynamic API Gateway delivering traffic routing, automated Let's Encrypt TLS termination, rate limiting, JWT validation, and CORS.
Serverless Compute (OpenFaaS)
Event-driven serverless runtime executing Python 3.12, Node.js 22, and Go micro-functions, featuring integrated Web IDE and scale-to-zero autoscaling.
Artifact Registry (Harbor)
Private container registry supporting OCI images and Helm charts, automated vulnerability scanning with Trivy, image signing, and robot accounts.
Artifactory (Artifact Keeper)
Centralized enterprise package repository supporting 45+ package formats (Docker/OCI, Helm, npm, PyPI, Maven, Go). Features automated upstream pull-through caching, Trivy security scanning, and DependencyTrack SBOM supply chain security.
Identity & IAM (Keystone & 2FA)
Granular multi-tenant RBAC, project domains, OAuth2/OIDC federation, application credentials, and Time-based One-Time Password (TOTP) 2FA security.
Metrics & Dashboards (Grafana)
Full-stack time-series telemetry scraping across all physical hypervisors, Ceph, Kubernetes, and DBaaS, with 20+ rich visual Grafana dashboards.
Log Streaming (Grafana Loki)
Unified log ingestion across all hypervisors, control plane microservices, and tenant workloads with PromQL-compatible LogQL querying.
Metering & FinOps (CloudKitty)
Transparent rating and chargeback engine tracking compute, storage, and egress consumption in real time with customizable pricing rules.
Backup & DR (Velero & Barman)
Continuous data protection with Barman PostgreSQL WAL streaming and Velero Kubernetes volume snapshots synchronized to offsite Ceph S3 buckets.