Managed Kubernetes on Red Hat OpenShift

Enterprise Kubernetes

A fully managed Kubernetes cluster on Red Hat OpenShift (OKD).
We run the highly available control plane, the upgrades and the storage, networking, observability and backup plumbing.
Ships with Kubectl, Helm, GitOps & MCP.
EU-owned, in the Netherlands, on 100% renewable power.

Vendor backed (Red Hat) High-Available Managed Upgrades Reliable Storage No egress tax

No credit card required  ·  Free during the alpha phase

Managed Kubernetes Cluster

Managed HA control plane · up to 99.99% SLA

  • Distribution
    • OKE - Vanilla Kubernetes
    • OKD - Free Open-Source OpenShift
    • OCP - Red Hat OpenShift
  • Tenancy
    • VPC - VM workers
    • DPC - Bare-Metal workers
  • Control planeWebconsole, API, CLI, MCP
  • Node PoolsCPU, GPU, Memory & Network optimized hardware
  • Storage
    • Fast local NVMe storage
    • Durable Ceph Network storage
  • Networking
    • Private Subnets (VxLAN)
    • Public Load-Balancers (BGP)
  • Support
    • Platinum - 24/7 TAM + Red Hat
    • Gold - 8/5 TAM + DevOps
    • Silver - 8/5 Ticket
    • None - AI + Public Forum

Overview

A managed cluster, not a managed cage.

Kubernetes became the standard because it solves the operational problems every production platform eventually hits: scaling without a redesign, surviving node and zone failure, and shipping new versions without downtime. Running it yourself, well, is a second full-time platform that has little to do with your product.

The control plane is where self-managed clusters break — etcd quorum, certificate rotation, version-skew rules and upgrades. That is exactly the part we take off your hands. You keep full cluster-admin over everything that runs on top.

  • Scale without redesign — add and shed capacity behind one declarative API, instead of bespoke provisioning scripts.
  • Survive failure automatically — reschedule and self-heal across node and zone failure, so a dead host is an event, not an outage.
  • Ship without downtime — health-gated rollouts with instant rollback when a release misbehaves.
  • One scheduler for the fleet — place and connect thousands of containers by declared intent, not by hand.
  • Many services, one fabric — service discovery, traffic policy and a service mesh across microservices, datastores and queues.
bash — kubectl
$ kubectl get nodes
NAME            STATUS   ROLES    AGE   VERSION
o1-worker-01    Ready    worker   63d   v1.30.4
o1-worker-02    Ready    worker   63d   v1.30.4
o1-worker-03    Ready    worker   41d   v1.30.4
m1-infra-01     Ready    infra    41d   v1.30.4
cx1-worker-01   Ready    worker   27d   v1.30.4
gpu-worker-01   Ready    worker   18d   v1.30.4

# the control plane is managed — you never SSH a
# master node or babysit etcd

Key features

The control plane is ours; the cluster is yours.

Highly available control plane

Redundant control-plane nodes with a 3-member etcd quorum and automated leader failover. We patch the API server, rotate certificates and back up etcd — you never touch a master node. Backed by an SLA of up to 99.99% on dedicated tiers.

Worker node pools

Independently-sized pools for different workload classes — CPU-bound, memory-bound, GPU or real-time — on shared-hardware VPC nodes or single-tenant bare-metal DPC nodes. Taints, labels and topology are yours to set.

Scaling at both levels

Pods scale on CPU, memory or custom metrics with the standard Horizontal Pod Autoscaler. Node-level cluster autoscaling adds and removes worker nodes automatically as scheduling demand changes — available today.

Networking, built in and free

CNI pod networking and NetworkPolicy, MetalLB load balancing, Ingress and Gateway API, cert-manager TLS, CoreDNS, egress IP and Submariner VPN — every function included, with no per-feature surcharge and no cross-AZ tax.

Persistent storage & data services

Dynamically-provisioned PersistentVolumes through standard CSI drivers on Rook Ceph and OpenEBS — block, shared file, S3 object and local NVMe. Portable storage classes you could re-create on any cluster, billed per GB-month.

Open-standard Kubernetes

100% Kubernetes-compatible, pure open source. Helm charts, Operators and GitOps run unchanged, and the whole CNCF landscape installs normally — nothing proprietary to learn or get trapped by.

Metrics & monitoring

Cluster, node and workload metrics through an OpenTelemetry-compatible pipeline that also feeds the HPA — one source of truth for dashboards and autoscaling.

Centralised logging

Aggregated logs across every namespace and workload for search and retention, with alerting on cluster, node and workload conditions.

Backup & disaster recovery

Scheduled Velero backups, CSI volume snapshots and cross-region replication to meet your RPO/RTO targets. Backup storage is €0.008/GB-month; replication €0.0465/GB-month.

Cluster lifecycle

Managed Kubernetes end to end, with automated upgrades: staged control-plane-first honouring version-skew rules, security patches as they land, failed nodes replaced — coordinated with you, never forced.

Self-service cluster provisioning

Manage cluster creation, upgrade, scaling & deletion yourself — from the web console, API or CLI, in minutes.

Self-service provisioning

Create, upgrade, scale and delete clusters yourself.

Cluster provisioning is self-service through the multi-cluster console, powered by Red Hat Advanced Cluster Management and the Assisted Installer: pick a distribution (OCP, OKD or OKE), a tenancy (VPC or DPC) and your node pools — the platform validates the configuration and installs the cluster for you.

  • Create a production-ready cluster in minutes — no tickets, no waiting
  • Assisted-install validation catches misconfigurations before they cost you time
  • Upgrade, scale node pools and delete clusters from the same view
  • Everything the console does, the API and CLI do too — automate whole fleets
The multi-cluster Clusters view on the GRN.CLOUD hub console with cluster list, sets and pools tabs and self-service Create cluster and Import cluster actions
The Clusters view on our hub console (Red Hat Advanced Cluster Management) — create or import a cluster in a few clicks; cluster sets, pools and placements when you grow to a fleet.

Monitoring

Baseline observability wired in — bring your own stack on top.

Grafana dashboard showing cluster, node and workload metrics from the OpenTelemetry-compatible pipeline on a managed GRN.CLOUD cluster
Cluster, node and workload metrics in Grafana. The OpenTelemetry-compatible pipeline is wired in as the platform baseline.

Bring your own observability

Baseline platform observability is wired in; bring your own stack on top, since it is all standard. Run your own Prometheus, Grafana, Loki or OpenTelemetry collector alongside the platform baseline — the API is standard, so your existing observability stack works unchanged.

Security

Security through standard primitives, layered.

Security is enforced across identity, network, workload and data — using the Kubernetes primitives your team already audits against, not proprietary bolt-ons that only we understand.

  • RBAC across clusters, namespaces and resources, with full audit logging
  • Identity integration via OAuth / OIDC — bring your own IdP
  • Kubernetes Secrets with encryption at rest; external secret stores supported
  • TLS everywhere, issued and rotated automatically via cert-manager
  • Default-deny micro-segmentation with standard NetworkPolicy
  • Pod Security Standards enforced at the namespace level
  • Audit logging of privileged and API actions
  • Hardware and kernel isolation on single-tenant DPC node pools
  • Image & supply-chain scanning Roadmap
  • Private clusters with no public API exposure
  • PCI-DSS, HIPAA, NIS2 & ISO compliance as optional add-ons (contact sales)*
Red Hat Advanced Cluster Security dashboard showing policy violations by severity and cluster, compliance status and risky deployments
Policy violations, compliance and risk in Red Hat Advanced Cluster Security — ACS and ACM governance run on the management cluster as part of the managed platform.

* On compliance, the honest version. The platform runs under EU-only data residency with a signed DPA and no US Cloud Act exposure, which is the substantive part of most regulated requirements. We will support PCI-DSS and HIPAA-aligned deployments on dedicated, isolated infrastructure — but we do not claim certifications we do not hold. Tell us your compliance scope and we will tell you precisely what we can and cannot attest to.

Architecture

A layered platform — every layer a named component.

Hosted control planes on a shared hypervisor layer, your own cluster on top, and two specialised clusters at the sides: one that manages and observes the platform, one that stores your data. Read the stack top-down — the rows map to the figure.

Users · Internet your customers · your engineers Gateway MetalLB · BGP load-balancing GRN-MANAGED Management Cluster GRN-MANAGED Argo CDGitOps delivery Lokicentral logging Observatoriumcentral metrics ACM + ACSpolicies · security Storage Cluster GRN-MANAGED Cephdurable block · file NoobaaS3 object storage Customer Cluster OCP · OKD · OKE — 100% Kubernetes · you get cluster-admin CORE MODULES GRN-MANAGED Argo CD cert-manager Kyverno MetalLB YOUR APPS · PODS — GITOPS + MARKETPLACE podyour workload podyour workload podyour workload YOU OPERATE Hypervisor GRN-MANAGED KubeVirt (MultiCluster Engine)worker nodes as VMs HyperShift — hosted control planeAPI · etcd · web console https · tcp/udp data flow PV · S3 GitOps · policies metrics · logs . web console · API data flow management flow

Gateway

MetalLB · BGP load-balancing
GRN-managed

Traffic enters through LoadBalancer services announced to our edge routers over BGP by MetalLB — with standard Ingress and Gateway API on top. Public IPs and load balancing are included, with no per-LB fee.

Apps — GitOps & Marketplace

Argo CD · your Git repo · one-click apps
You operate

Deploy any app either in one click from the Marketplace or predefined from your own Git repo: point Argo CD at it and GitOps reconciles your manifests, Helm charts and Operators continuously.

Customer Cluster

OCP · OKD · OKE — 100% Kubernetes
GRN-managed

Your own cluster, your choice of distribution: Red Hat OpenShift (OCP), free open-source OpenShift (OKD) or vanilla Kubernetes (OKE). All CNCF-conformant — the same Kubernetes API, kubectl and Helm everywhere.

Hypervisor

KubeVirt (MultiCluster Engine) · HyperShift HCP
GRN-managed

Worker nodes run as KubeVirt virtual machines under OpenShift MultiCluster Engine; each cluster’s control plane — API server, etcd, web console — runs as pods in a HyperShift hosted control plane. No control-plane nodes to babysit — or pay for.

Management Cluster

A centrally managed monitoring & management cluster runs the platform: Argo CD for GitOps, central logging with Loki, central metrics with Observatorium, and security policies enforced through ACM and ACS — coordinated by Red Hat Advanced Cluster Management.

Storage Cluster

A dedicated storage cluster serves your data: Ceph provides durable block and file volumes; Noobaa provides feature-rich, S3-compatible object storage — replicated, snapshotted and backed up independently of your compute.

One platform, five named layers — nothing proprietary; every component is open source you can inspect.

Who runs what

What GRN operates

Run and on-call for the platform layer — the undifferentiated heavy lifting.

  • HA control plane: API server, scheduler, controller-manager and etcd, patched and backed up
  • Managed version upgrades and security patching of nodes and the control plane
  • The CNI, MetalLB, ingress, storage (Ceph / OpenEBS) and backup (Velero) plumbing
  • The in-cluster image registry
  • Node provisioning, replacement of failed hardware and capacity on request
  • The 99.99% control-plane SLA, on dedicated tiers, with named senior engineers

What you operate

Standard Kubernetes, fully in your hands — with full cluster-admin.

  • You have full cluster-admin access
  • Your workloads: Deployments, StatefulSets, Jobs, CRDs and Operators
  • Namespaces, RBAC bindings, network policies and resource quotas
  • Your GitOps pipeline (Argo CD / Flux) and CI
  • Application-level autoscaling, rollout strategy and observability dashboards

The same stack underneath every tier. A managed cluster runs the identical cloud-native foundation as our Virtual Private Cloud and Dedicated Private Cloud — the only difference is the isolation and dedication of the compute beneath it. Run on shared-hardware VPC nodes, or on single-tenant bare-metal DPC nodes for regulated and high-security workloads. You are never re-platforming to move between them.

Common use cases

What teams build on a managed cluster.

SaaS platforms

Multi-tenant products needing elastic scaling, zero-downtime releases and EU data residency for their own regulated customers.

AI & machine learning

GPU-backed training and inference on NVIDIA nodes via OpenDataHub, with training data kept inside the EU.

Microservices

Service-mesh-ready estates with discovery, mTLS, traffic policy and per-service observability.

Internal developer platforms

A golden-path IDP for product teams — self-service namespaces, templates and GitOps on a shared, governed cluster.

CI/CD & build platforms

Pipelines running as containerised workloads on on-demand cx1 capacity, isolated per team by namespace and quota.

Data & event streaming

Stateful brokers and stream processors on durable NVMe with elastic worker pools and persistent volumes.

API platforms

Gateway-fronted backends with rate limiting, mTLS and horizontal autoscaling on standard ingress.

MSP / multi-cluster fleets

Resell or operate fleets of isolated clusters for your own customers, federated with Submariner across regions.

Regulated workloads

Finance, healthcare and government platforms on EU-sovereign, single-tenant infrastructure with a signed DPA — subject to your compliance scope.

Benefits

The operational and commercial differences you can verify.

Sovereign & secure

EU-owned infrastructure under Dutch jurisdiction — not a US hyperscaler's "European region", which stays subject to the US Cloud Act regardless of where the data sits. No Cloud Act exposure, EU-only data residency and a signed Data Processing Agreement.

Affordable & transparent

Networking functions are included free, storage is a published €/GB-month, and annual commitments take 10% off. No per-feature surcharges, and no egress tax — the line item that quietly consumes 15–40% of a typical hyperscaler bill.

Sustainable

Hosted in the Netherlands on 100% renewable solar energy, with server heat reused to warm nearby buildings and peak-shaving to ease grid congestion. Sustainability with a mechanism behind it, not a logo.

No lock-in by construction

Open Kubernetes and GitOps are portable: pick up your manifests, Helm charts and Operators and run them on any conformant cluster. The EU Data Act makes switching support a legal requirement, not a courtesy.

Named senior engineers

Support tiers from AI-plus-forum through 8/5 ticket and 8/5 TAM to 24/7 TAM with Red Hat escalation — the same engineers who operate the platform, not a first-line queue.

Contractual SLA

Control-plane availability scales with tier, up to a contractual 99.99% on dedicated infrastructure — backed by redundant control-plane nodes, an etcd quorum and NVMe-oF storage with configurable IOPS.

Technical highlights

The detail a platform engineer actually evaluates.

DistributionRed Hat OpenShift — OKD
Kubernetes versionsAny version, supported
Control-plane topology3-node HA, etcd quorum, managed kube-apiserver
Container runtimerunc
CNIOVN-Kubernetes
CSIRook Ceph (RBD / FS / RGW), OpenEBS local NVMe
Load balancingMetalLB (Layer 2 / BGP)
IngressStandard Ingress + Gateway API, cert-manager TLS
Storage classesNVMe local, Ceph block / file / S3
NetworkingDual-stack IPv4 / IPv6, NetworkPolicy, Submariner VPN
Backup / DRVelero, CSI snapshots, cross-region replication
Node familiescx1 compute · m1 memory · n1 network · o1 universal · GPU optional · ARM Roadmap
Worker sizingcx1 1–32 vCPU · m1 up to 256 GB RAM · n1 4–64 vCPU · o1 0.5–128 GB
TenancyShared-hardware (VPC) or single-tenant bare-metal (DPC)
API accessFull standard Kubernetes API + REST & GitOps automation
Control-plane SLAUp to 99.99% (tier-dependent)
RegionNetherlands (EU), 100% renewable-powered

Networking functions & pricing

Every networking function is implemented with a standard, named component and included at no extra charge. There is no per-feature surcharge and no cross-AZ tax.

FunctionImplementationPrice
Pod networking & policyCNI plugin (NetworkPolicy default-deny capable)Included
Load balancingMetalLB (Layer 2 / BGP)Included
Ingress / HTTP routingStandard Ingress + Gateway API, TLS via cert-managerIncluded
Service mesh OptionalIstio (mTLS, traffic policy, telemetry)Included
DNSCoreDNS in-cluster, External-DNS for public recordsIncluded
NAT / egressEgress IP / egress routerIncluded
Site-to-site & cross-cluster VPNSubmarinerIncluded
Private subnets / segmentationNetwork attachments + NetworkPolicyIncluded
Public / floating IPv4MetalLB-advertised address€ 3.00 / mo
BYO-IP / BYO-ASN (BGP)MetalLB BGP peering€ 50.00 / mo
Data egressNo per-GB meteringNo egress tax

Dual-stack IPv4 / IPv6 throughout. Prices in EUR, ex VAT; 10% discount on annual commitment. See the pricing page for current rates.

Storage classes & pricing

Storage classImplementation (CSI)Best forPrice
Local NVMeOpenEBS LocalVolumeLatency-sensitive — databases, brokers€ 0.044 / GB-mo
Block (RWO)Rook Ceph RBDGeneral-purpose persistent volumes€ 0.044 / GB-mo
Shared file (RWX)Rook Ceph FSShared volumes across pods€ 0.044 / GB-mo
S3 objectCeph ObjectBucketClaimArtifacts, backups, data lakes€ 0.044 / GB-mo
Cross-region replicationCeph VolumeReplicationGeo-redundancy / DR€ 0.0465 / GB-mo
Backup & snapshotsVelero + CSI snapshotsScheduled backup to meet RPO/RTO€ 0.008 / GB-mo

All classes are dynamically provisioned and expandable. NVMe-oF with configurable IOPS available on dedicated tiers. Prices ex VAT.

Against the hyperscalers, on the axes that matter

An objective capability comparison against the major managed-Kubernetes services and against running it yourself. Subjective claims ("faster", "simpler") are left out — only things you can check.

Capability GRN.CLOUD Hyperscaler managed Kubernetes Do it yourself
Amazon EKSAzure AKSGoogle GKESelf-hosted
Standard Kubernetes API
Pricing transparencyPublished €/GB, flat tiers~ complex~ complex~ complexYour cost
Egress / cross-AZ feesNetworking includedPer-GB + cross-AZPer-GB + cross-AZPer-GB + cross-AZYour cost
Infrastructure controlHigh~ abstracted~ abstracted~ abstractedTotal
Genuine EU sovereignty (non-US-owned) Netherlands US-owned US-owned US-ownedDepends on your DC
Control-plane SLAUp to 99.99%99.95% / 99.99%99.95% (with AZs)99.95% (regional)You operate it
Single-tenant bare-metal option DPC nodes~ dedicated hosts~ dedicated hosts~ sole-tenant
100% renewable-powered~ varies by region~ varies by region~ varies by regionDepends on your DC
Enterprise supportAdd-on, named engineersPaid tiersPaid tiersPaid tiersDIY / 3rd-party

yes · ~ partial · no. Compiled from public product & pricing pages, June 2026; vendor features change — check current vendor docs before relying on a comparison.

FAQ

The questions an engineer actually asks.

Where is the line between what you manage and what I manage?

We own the control plane, node provisioning, upgrades, security patching and the storage, networking and backup plumbing, under SLA. You own your workloads, namespaces, RBAC, network policies, GitOps pipeline and application autoscaling — with full cluster-admin. Anything on our pager is listed explicitly in the "What GRN operates" card above.

Can I migrate from EKS, AKS or GKE?

Yes. Standard manifests, Helm charts and Operators run on OpenShift with minimal change; you re-point pipelines and re-create storage and ingress with the equivalent resources. Our engineers help you move.

How are upgrades handled, and can you force one on me?

We support any Kubernetes version and apply security patches as they land. Minor-version upgrades are scheduled with you, run control-plane-first to honour version-skew rules, and never silently push you onto a release your Operators haven't certified against.

Do Helm, Operators and GitOps just work?

Yes. Helm charts and release workflows run unchanged; Operators install and reconcile normally; and GitOps works out of the box — we operate Argo CD for you, or run your own Flux.

How does scaling work — pods and nodes?

Pods scale on CPU, memory or custom metrics with the standard Horizontal Pod Autoscaler. Node-level cluster autoscaling adds and removes worker nodes automatically as scheduling demand changes — available today.

Can I bring my own container registry?

Yes. Pull from any standard OCI registry — your own Harbor, a hyperscaler registry or a public one — with standard image pull secrets. Nothing forces you onto a GRN registry.

Is GPU supported?

Yes. Optional NVIDIA GPU worker pools are available for AI/ML training and inference via OpenDataHub, all within EU data residency.

What about private networking and private clusters?

Private subnets, NAT egress and site-to-site / cross-cluster VPN via Submariner are included free. Fully private clusters with no public API exposure are on the roadmap — ask us where that stands for your deployment.

How is backup and disaster recovery handled?

Scheduled Velero backups, CSI volume snapshots and cross-region replication, sized to your RPO/RTO targets. Backup storage is €0.008/GB-month and cross-region replication €0.0465/GB-month.

What is the SLA?

The control-plane SLA scales with tier, up to a contractual 99.99% on dedicated infrastructure — backed by redundant control-plane nodes, an etcd quorum and NVMe-oF storage with configurable IOPS.

How does pricing work — and is there an egress charge?

Networking functions (firewall, load balancer, ingress, TLS, DNS, NAT, VPN) are included free; storage is €0.044/GB-month and backup €0.008/GB-month, with 10% off on annual commitment. There is no per-GB egress tax.

Is it really sovereign, or "sovereignty-washing"?

Genuinely EU-owned infrastructure under Dutch jurisdiction — not a US hyperscaler's "European region", which remains subject to the US Cloud Act regardless of where the bytes live. EU-only residency, a signed DPA, and no US ownership in the chain.

Run production Kubernetes on a sovereign, renewable cloud.

Deploy a managed Red Hat OpenShift (OKD) cluster with a highly available control plane — or talk to our engineers about moving your existing workloads.

100% renewable energy · EU data residency · No US Cloud Act exposure · Any Kubernetes version