Full Stack · Fully Managed · Open Source

Managed Private
Cloud Services

A complete private cloud platform — compute, orchestration, storage, networking, and observability — deployed on your hardware and operated by our engineers. Every component is open source. Every layer is included.

At a Glance

What's Included

Everything you need to run private infrastructure — nothing you need to operate yourself.

Infrastructure

OpenStack IaaS with full API access. KVM compute, Ceph storage, OVN/Cilium networking. HA control plane. Bare-metal provisioning via Ironic.

Platform

Upstream Kubernetes with Cilium networking. Helm, GitOps, and multi-tenancy. Container platform ready for production workloads from day one.

Operations

24/7 monitoring and alerting. Automated upgrades. Security patching. Backup and disaster recovery planning. Capacity reviews. Incident response.

Layer 01

Compute — KVM & OpenStack

The foundation of your private cloud. OpenStack provides the API-driven infrastructure layer — virtual machines, networks, block storage, identity, and image management — running on KVM hypervisors across your physical hardware.

The control plane is deployed in a highly available configuration with no single point of failure. All core OpenStack services are monitored, patched, and upgraded as part of the managed service.

Core Services

  • Nova — VM lifecycle, live migration, host aggregates
  • Neutron — virtual networking, security groups, floating IPs
  • Cinder — block storage backed by Ceph RBD
  • Keystone — identity, RBAC, LDAP/AD integration
  • Glance — image management and distribution
  • Horizon — web dashboard for tenant self-service
  • Ironic — bare-metal provisioning for GPU or HPC nodes
  • Octavia — load balancing as a service

Compute Stack

Hypervisor

KVM · libvirt · QEMU

Orchestration

Nova · Placement · Heat

Identity & Access

Keystone · Barbican · LDAP

Dashboard

Horizon · CLI · Full API access

No per-VM licensing: OpenStack is Apache 2.0 licensed. There are no per-core fees, no per-socket charges, and no licence renewals. You pay for management — not for the software running on your own hardware.

Kubernetes Stack

Runtime

Upstream Kubernetes · containerd · CRI

Networking

Cilium eBPF · MetalLB · Ingress NGINX

Delivery

Helm 3 · Argo CD · Flux CD

Security

Vault · Cert-Manager · Kyverno · OPA

Why Cilium? Cilium replaces iptables with eBPF programs running directly in the Linux kernel. This provides L3/L4/L7 network policy enforcement, transparent encryption, and deep observability — with significantly better performance than legacy CNI plugins.

Layer 02

Orchestration — Kubernetes

Production-grade Kubernetes deployed on your private cloud or bare-metal infrastructure. Upstream Kubernetes — not a vendor fork — with Cilium eBPF networking, GitOps-driven deployments, and a full platform engineering layer.

Multi-tenant namespaces, automated certificate management, secret management via HashiCorp Vault, and a GitOps pipeline with Argo CD or Flux. Your developers get a self-service platform. Your security team gets policy enforcement and audit trails.

Platform Capabilities

  • Multi-cluster support for workload isolation and geo-redundancy
  • Zero-trust network policies at L3, L4, and L7
  • GitOps: declarative cluster state with auditable change history
  • Secrets management with automatic rotation
  • Image scanning and admission policy enforcement
  • CIS benchmark hardening applied by default
  • Managed upgrades between Kubernetes minor versions
Layer 03

Storage — Ceph

Ceph provides unified distributed storage across your entire private cloud — block storage for VMs, S3-compatible object storage for applications, and shared filesystems for legacy workloads. All on commodity hardware, all fully replicated.

Ceph is the storage backbone of the largest OpenStack deployments in the world — CERN, Deutsche Telekom, Bloomberg, and dozens of national research networks run it at petabyte scale. We deploy and operate it as an integrated part of your managed private cloud.

Storage Services

  • RBD — block storage for OpenStack VMs (Cinder backend)
  • RGW — S3-compatible object storage with bucket policies
  • CephFS — POSIX-compliant shared filesystem (Manila backend)
  • Erasure coding for cost-efficient archival storage
  • Automated rebalancing and self-healing on disk failure
  • Encryption at rest with per-OSD or per-pool keys

Storage Stack

Block

Ceph RBD · Cinder · Snapshot · Clone

Object

Ceph RGW · S3 API · Swift API · Bucket policies

Filesystem

CephFS · Manila · NFS export

Operations

OSD management · Rebalancing · Scrubbing · Encryption

No IOPS charges: Unlike cloud block storage services that bill per provisioned IOPS tier, Ceph performance scales with your hardware. Add more OSDs, get more throughput. The only cost is the physical disks — which you already own.

Networking Stack

Virtual Networking

OVN · Open vSwitch · Neutron · VXLAN

Container Networking

Cilium eBPF · Hubble · WireGuard encryption

Load Balancing

Octavia · HAProxy · MetalLB · Keepalived

DNS & Routing

Designate · CoreDNS · FRRouting · BGP

Layer 04

Networking — Cilium & OVN

Two networking layers, each purpose-built for its domain. OVN handles virtual networking for OpenStack — tenant isolation, floating IPs, security groups, and VXLAN overlays. Cilium handles Kubernetes networking with eBPF — L3/L4/L7 policy enforcement, transparent encryption, and deep observability.

Both are fully managed. Neutron and Cilium configurations, load balancer health, BGP peering, and DNS resolution are all monitored and maintained as part of the service.

Networking Services

  • Tenant network isolation (VXLAN/VLAN/flat)
  • Floating IPs and NAT gateway
  • Load balancing as a service (Octavia)
  • DNS as a service (Designate)
  • Zero-trust Kubernetes network policies
  • WireGuard-based transparent pod encryption
  • BGP peering for external connectivity
Layer 05

Observability — Prometheus & Grafana

Every component of your private cloud is instrumented. Prometheus collects metrics from OpenStack services, Ceph OSDs, Kubernetes pods, and system-level resources. Grafana provides dashboards. Alertmanager routes critical alerts to our on-call engineers.

You get full read access to all dashboards and can build your own. We handle the alerting pipeline, escalation, and incident response. Logs are collected via Fluentd and stored in OpenSearch for search and forensic analysis.

Observability Services

  • Metrics collection across all infrastructure layers
  • Pre-built dashboards for OpenStack, Ceph, Kubernetes
  • Alerting with escalation paths and on-call rotation
  • Centralized logging with structured search
  • Uptime and SLA tracking
  • Capacity trend analysis and forecasting

Observability Stack

Metrics

Prometheus · Thanos · Node Exporter · ceph_exporter

Visualization

Grafana · Pre-built dashboards · Custom panels

Alerting

Alertmanager · PagerDuty · Slack · Email

Logging

Fluentd · OpenSearch · Kibana

Operations

Managed Day-2 Operations

Deployment is week one. Operations is year one through year ten.

Upgrades

Rolling upgrades across OpenStack releases, Kubernetes minor versions, and Ceph releases. Tested in staging. Applied with zero or minimal downtime. Rollback plans prepared before every upgrade.

Backup

Control plane configuration, Ceph cluster state, Kubernetes etcd snapshots, and critical service data — all backed up continuously. Recovery procedures documented and tested quarterly.

DR Planning

Disaster recovery design for your specific topology. Single-site HA, multi-site replication, or active-passive failover. RTO and RPO targets defined, documented, and validated through regular DR drills.

Security Patching

OS-level, OpenStack, and Kubernetes security patches applied on a regular cadence. Critical CVEs addressed within 24 hours. All patches tested before production rollout.

Capacity Planning

Proactive monitoring of compute, storage, and network utilization. Trend analysis and forecasting. Scale-out recommendations with lead time — before capacity becomes an incident.

Incident Response

Our engineers respond to infrastructure incidents directly — not a ticket queue. Root cause analysis for every significant event. Post-incident reports within 48 hours.

Get Started

Private Cloud Without the Operational Overhead

Tell us about your infrastructure requirements — hardware, workloads, compliance constraints. We'll design a managed private cloud that fits your environment and your budget.