A fully managed Kubernetes cluster on Red Hat OpenShift (OKD).
We run the highly available control plane, the upgrades and the storage, networking, observability and backup plumbing.
Ships with Kubectl, Helm, GitOps & MCP.
EU-owned, in the Netherlands, on 100% renewable power.
No credit card required · Free during the alpha phase
Managed HA control plane · up to 99.99% SLA
A managed cluster, not a managed cage.
Kubernetes became the standard because it solves the operational problems every production platform eventually hits: scaling without a redesign, surviving node and zone failure, and shipping new versions without downtime. Running it yourself, well, is a second full-time platform that has little to do with your product.
The control plane is where self-managed clusters break — etcd quorum, certificate rotation, version-skew rules and upgrades. That is exactly the part we take off your hands. You keep full cluster-admin over everything that runs on top.
$ kubectl get nodes NAME STATUS ROLES AGE VERSION o1-worker-01 Ready worker 63d v1.30.4 o1-worker-02 Ready worker 63d v1.30.4 o1-worker-03 Ready worker 41d v1.30.4 m1-infra-01 Ready infra 41d v1.30.4 cx1-worker-01 Ready worker 27d v1.30.4 gpu-worker-01 Ready worker 18d v1.30.4 # the control plane is managed — you never SSH a # master node or babysit etcd
The control plane is ours; the cluster is yours.
Redundant control-plane nodes with a 3-member etcd quorum and automated leader failover. We patch the API server, rotate certificates and back up etcd — you never touch a master node. Backed by an SLA of up to 99.99% on dedicated tiers.
Independently-sized pools for different workload classes — CPU-bound, memory-bound, GPU or real-time — on shared-hardware VPC nodes or single-tenant bare-metal DPC nodes. Taints, labels and topology are yours to set.
Pods scale on CPU, memory or custom metrics with the standard Horizontal Pod Autoscaler. Node-level cluster autoscaling adds and removes worker nodes automatically as scheduling demand changes — available today.
CNI pod networking and NetworkPolicy, MetalLB load balancing, Ingress and Gateway API, cert-manager TLS, CoreDNS, egress IP and Submariner VPN — every function included, with no per-feature surcharge and no cross-AZ tax.
Dynamically-provisioned PersistentVolumes through standard CSI drivers on Rook Ceph and OpenEBS — block, shared file, S3 object and local NVMe. Portable storage classes you could re-create on any cluster, billed per GB-month.
100% Kubernetes-compatible, pure open source. Helm charts, Operators and GitOps run unchanged, and the whole CNCF landscape installs normally — nothing proprietary to learn or get trapped by.
Cluster, node and workload metrics through an OpenTelemetry-compatible pipeline that also feeds the HPA — one source of truth for dashboards and autoscaling.
Aggregated logs across every namespace and workload for search and retention, with alerting on cluster, node and workload conditions.
Scheduled Velero backups, CSI volume snapshots and cross-region replication to meet your RPO/RTO targets. Backup storage is €0.008/GB-month; replication €0.0465/GB-month.
Managed Kubernetes end to end, with automated upgrades: staged control-plane-first honouring version-skew rules, security patches as they land, failed nodes replaced — coordinated with you, never forced.
Manage cluster creation, upgrade, scaling & deletion yourself — from the web console, API or CLI, in minutes.
Create, upgrade, scale and delete clusters yourself.
Cluster provisioning is self-service through the multi-cluster console, powered by Red Hat Advanced Cluster Management and the Assisted Installer: pick a distribution (OCP, OKD or OKE), a tenancy (VPC or DPC) and your node pools — the platform validates the configuration and installs the cluster for you.
Baseline observability wired in — bring your own stack on top.
Baseline platform observability is wired in; bring your own stack on top, since it is all standard. Run your own Prometheus, Grafana, Loki or OpenTelemetry collector alongside the platform baseline — the API is standard, so your existing observability stack works unchanged.
Security through standard primitives, layered.
Security is enforced across identity, network, workload and data — using the Kubernetes primitives your team already audits against, not proprietary bolt-ons that only we understand.
* On compliance, the honest version. The platform runs under EU-only data residency with a signed DPA and no US Cloud Act exposure, which is the substantive part of most regulated requirements. We will support PCI-DSS and HIPAA-aligned deployments on dedicated, isolated infrastructure — but we do not claim certifications we do not hold. Tell us your compliance scope and we will tell you precisely what we can and cannot attest to.
A layered platform — every layer a named component.
Hosted control planes on a shared hypervisor layer, your own cluster on top, and two specialised clusters at the sides: one that manages and observes the platform, one that stores your data. Read the stack top-down — the rows map to the figure.
Traffic enters through LoadBalancer services announced to our edge routers over BGP by MetalLB — with standard Ingress and Gateway API on top. Public IPs and load balancing are included, with no per-LB fee.
Deploy any app either in one click from the Marketplace or predefined from your own Git repo: point Argo CD at it and GitOps reconciles your manifests, Helm charts and Operators continuously.
Your own cluster, your choice of distribution: Red Hat OpenShift (OCP), free open-source OpenShift (OKD) or vanilla Kubernetes (OKE). All CNCF-conformant — the same Kubernetes API, kubectl and Helm everywhere.
Worker nodes run as KubeVirt virtual machines under OpenShift MultiCluster Engine; each cluster’s control plane — API server, etcd, web console — runs as pods in a HyperShift hosted control plane. No control-plane nodes to babysit — or pay for.
A centrally managed monitoring & management cluster runs the platform: Argo CD for GitOps, central logging with Loki, central metrics with Observatorium, and security policies enforced through ACM and ACS — coordinated by Red Hat Advanced Cluster Management.
A dedicated storage cluster serves your data: Ceph provides durable block and file volumes; Noobaa provides feature-rich, S3-compatible object storage — replicated, snapshotted and backed up independently of your compute.
One platform, five named layers — nothing proprietary; every component is open source you can inspect.
Run and on-call for the platform layer — the undifferentiated heavy lifting.
Standard Kubernetes, fully in your hands — with full cluster-admin.
The same stack underneath every tier. A managed cluster runs the identical cloud-native foundation as our Virtual Private Cloud and Dedicated Private Cloud — the only difference is the isolation and dedication of the compute beneath it. Run on shared-hardware VPC nodes, or on single-tenant bare-metal DPC nodes for regulated and high-security workloads. You are never re-platforming to move between them.
What teams build on a managed cluster.
Multi-tenant products needing elastic scaling, zero-downtime releases and EU data residency for their own regulated customers.
GPU-backed training and inference on NVIDIA nodes via OpenDataHub, with training data kept inside the EU.
Service-mesh-ready estates with discovery, mTLS, traffic policy and per-service observability.
A golden-path IDP for product teams — self-service namespaces, templates and GitOps on a shared, governed cluster.
Pipelines running as containerised workloads on on-demand cx1 capacity, isolated per team by namespace and quota.
Stateful brokers and stream processors on durable NVMe with elastic worker pools and persistent volumes.
Gateway-fronted backends with rate limiting, mTLS and horizontal autoscaling on standard ingress.
Resell or operate fleets of isolated clusters for your own customers, federated with Submariner across regions.
Finance, healthcare and government platforms on EU-sovereign, single-tenant infrastructure with a signed DPA — subject to your compliance scope.
The operational and commercial differences you can verify.
EU-owned infrastructure under Dutch jurisdiction — not a US hyperscaler's "European region", which stays subject to the US Cloud Act regardless of where the data sits. No Cloud Act exposure, EU-only data residency and a signed Data Processing Agreement.
Networking functions are included free, storage is a published €/GB-month, and annual commitments take 10% off. No per-feature surcharges, and no egress tax — the line item that quietly consumes 15–40% of a typical hyperscaler bill.
Hosted in the Netherlands on 100% renewable solar energy, with server heat reused to warm nearby buildings and peak-shaving to ease grid congestion. Sustainability with a mechanism behind it, not a logo.
Open Kubernetes and GitOps are portable: pick up your manifests, Helm charts and Operators and run them on any conformant cluster. The EU Data Act makes switching support a legal requirement, not a courtesy.
Support tiers from AI-plus-forum through 8/5 ticket and 8/5 TAM to 24/7 TAM with Red Hat escalation — the same engineers who operate the platform, not a first-line queue.
Control-plane availability scales with tier, up to a contractual 99.99% on dedicated infrastructure — backed by redundant control-plane nodes, an etcd quorum and NVMe-oF storage with configurable IOPS.
The detail a platform engineer actually evaluates.
| Distribution | Red Hat OpenShift — OKD |
| Kubernetes versions | Any version, supported |
| Control-plane topology | 3-node HA, etcd quorum, managed kube-apiserver |
| Container runtime | runc |
| CNI | OVN-Kubernetes |
| CSI | Rook Ceph (RBD / FS / RGW), OpenEBS local NVMe |
| Load balancing | MetalLB (Layer 2 / BGP) |
| Ingress | Standard Ingress + Gateway API, cert-manager TLS |
| Storage classes | NVMe local, Ceph block / file / S3 |
| Networking | Dual-stack IPv4 / IPv6, NetworkPolicy, Submariner VPN |
| Backup / DR | Velero, CSI snapshots, cross-region replication |
| Node families | cx1 compute · m1 memory · n1 network · o1 universal · GPU optional · ARM Roadmap |
| Worker sizing | cx1 1–32 vCPU · m1 up to 256 GB RAM · n1 4–64 vCPU · o1 0.5–128 GB |
| Tenancy | Shared-hardware (VPC) or single-tenant bare-metal (DPC) |
| API access | Full standard Kubernetes API + REST & GitOps automation |
| Control-plane SLA | Up to 99.99% (tier-dependent) |
| Region | Netherlands (EU), 100% renewable-powered |
Every networking function is implemented with a standard, named component and included at no extra charge. There is no per-feature surcharge and no cross-AZ tax.
| Function | Implementation | Price |
|---|---|---|
| Pod networking & policy | CNI plugin (NetworkPolicy default-deny capable) | Included |
| Load balancing | MetalLB (Layer 2 / BGP) | Included |
| Ingress / HTTP routing | Standard Ingress + Gateway API, TLS via cert-manager | Included |
| Service mesh Optional | Istio (mTLS, traffic policy, telemetry) | Included |
| DNS | CoreDNS in-cluster, External-DNS for public records | Included |
| NAT / egress | Egress IP / egress router | Included |
| Site-to-site & cross-cluster VPN | Submariner | Included |
| Private subnets / segmentation | Network attachments + NetworkPolicy | Included |
| Public / floating IPv4 | MetalLB-advertised address | € 3.00 / mo |
| BYO-IP / BYO-ASN (BGP) | MetalLB BGP peering | € 50.00 / mo |
| Data egress | No per-GB metering | No egress tax |
Dual-stack IPv4 / IPv6 throughout. Prices in EUR, ex VAT; 10% discount on annual commitment. See the pricing page for current rates.
| Storage class | Implementation (CSI) | Best for | Price |
|---|---|---|---|
| Local NVMe | OpenEBS LocalVolume | Latency-sensitive — databases, brokers | € 0.044 / GB-mo |
| Block (RWO) | Rook Ceph RBD | General-purpose persistent volumes | € 0.044 / GB-mo |
| Shared file (RWX) | Rook Ceph FS | Shared volumes across pods | € 0.044 / GB-mo |
| S3 object | Ceph ObjectBucketClaim | Artifacts, backups, data lakes | € 0.044 / GB-mo |
| Cross-region replication | Ceph VolumeReplication | Geo-redundancy / DR | € 0.0465 / GB-mo |
| Backup & snapshots | Velero + CSI snapshots | Scheduled backup to meet RPO/RTO | € 0.008 / GB-mo |
All classes are dynamically provisioned and expandable. NVMe-oF with configurable IOPS available on dedicated tiers. Prices ex VAT.
An objective capability comparison against the major managed-Kubernetes services and against running it yourself. Subjective claims ("faster", "simpler") are left out — only things you can check.
| Capability | GRN.CLOUD | Hyperscaler managed Kubernetes | Do it yourself | ||
|---|---|---|---|---|---|
| Amazon EKS | Azure AKS | Google GKE | Self-hosted | ||
| Standard Kubernetes API | ✓ | ✓ | ✓ | ✓ | ✓ |
| Pricing transparency | Published €/GB, flat tiers | ~ complex | ~ complex | ~ complex | Your cost |
| Egress / cross-AZ fees | Networking included | Per-GB + cross-AZ | Per-GB + cross-AZ | Per-GB + cross-AZ | Your cost |
| Infrastructure control | High | ~ abstracted | ~ abstracted | ~ abstracted | Total |
| Genuine EU sovereignty (non-US-owned) | ✓ Netherlands | ✕ US-owned | ✕ US-owned | ✕ US-owned | Depends on your DC |
| Control-plane SLA | Up to 99.99% | 99.95% / 99.99% | 99.95% (with AZs) | 99.95% (regional) | You operate it |
| Single-tenant bare-metal option | ✓ DPC nodes | ~ dedicated hosts | ~ dedicated hosts | ~ sole-tenant | ✓ |
| 100% renewable-powered | ✓ | ~ varies by region | ~ varies by region | ~ varies by region | Depends on your DC |
| Enterprise support | Add-on, named engineers | Paid tiers | Paid tiers | Paid tiers | DIY / 3rd-party |
✓ yes · ~ partial · ✕ no. Compiled from public product & pricing pages, June 2026; vendor features change — check current vendor docs before relying on a comparison.
The questions an engineer actually asks.
We own the control plane, node provisioning, upgrades, security patching and the storage, networking and backup plumbing, under SLA. You own your workloads, namespaces, RBAC, network policies, GitOps pipeline and application autoscaling — with full cluster-admin. Anything on our pager is listed explicitly in the "What GRN operates" card above.
Yes. Standard manifests, Helm charts and Operators run on OpenShift with minimal change; you re-point pipelines and re-create storage and ingress with the equivalent resources. Our engineers help you move.
We support any Kubernetes version and apply security patches as they land. Minor-version upgrades are scheduled with you, run control-plane-first to honour version-skew rules, and never silently push you onto a release your Operators haven't certified against.
Yes. Helm charts and release workflows run unchanged; Operators install and reconcile normally; and GitOps works out of the box — we operate Argo CD for you, or run your own Flux.
Pods scale on CPU, memory or custom metrics with the standard Horizontal Pod Autoscaler. Node-level cluster autoscaling adds and removes worker nodes automatically as scheduling demand changes — available today.
Yes. Pull from any standard OCI registry — your own Harbor, a hyperscaler registry or a public one — with standard image pull secrets. Nothing forces you onto a GRN registry.
Yes. Optional NVIDIA GPU worker pools are available for AI/ML training and inference via OpenDataHub, all within EU data residency.
Private subnets, NAT egress and site-to-site / cross-cluster VPN via Submariner are included free. Fully private clusters with no public API exposure are on the roadmap — ask us where that stands for your deployment.
Scheduled Velero backups, CSI volume snapshots and cross-region replication, sized to your RPO/RTO targets. Backup storage is €0.008/GB-month and cross-region replication €0.0465/GB-month.
The control-plane SLA scales with tier, up to a contractual 99.99% on dedicated infrastructure — backed by redundant control-plane nodes, an etcd quorum and NVMe-oF storage with configurable IOPS.
Networking functions (firewall, load balancer, ingress, TLS, DNS, NAT, VPN) are included free; storage is €0.044/GB-month and backup €0.008/GB-month, with 10% off on annual commitment. There is no per-GB egress tax.
Genuinely EU-owned infrastructure under Dutch jurisdiction — not a US hyperscaler's "European region", which remains subject to the US Cloud Act regardless of where the bytes live. EU-only residency, a signed DPA, and no US ownership in the chain.
Deploy a managed Red Hat OpenShift (OKD) cluster with a highly available control plane — or talk to our engineers about moving your existing workloads.
100% renewable energy · EU data residency · No US Cloud Act exposure · Any Kubernetes version