Air-gapped Kubernetes, managed like a cloud

The whole platform runs inside your perimeter, control plane included, with no dependency on anything hosted outside. Teams still self-serve managed Kubernetes, PostgreSQL and VMs, and nothing about your workloads leaves the site.

Entire platform inside your perimeter, no uplink requiredCNCF-conformant clusters, upgrades and autoscaling includedSame console and API as the hosted model
On-premises model, total isolation
Console and APIyour teams
Control planeoperated by you
No uplinknothing leaves
edgeContinuum
Managed KubernetesCNCF conformant
Managed PostgreSQLhighly available
VMson your OpenStack
Your hardware, your data, your perimeter

Disconnected usually means back to manual

Air-gapped environments normally pay for isolation twice: once in the network design, and again in the operating model, because the tools that make Kubernetes pleasant assume a hosted control plane, a registry on the internet and an update path through it. So classified sites, ships, factories and defence estates end up with hand-built clusters and change windows. edgeContinuum is designed the other way round. In the on-premises model the entire platform runs inside your perimeter, so air-gapped Kubernetes is the same product as the hosted one: the same console, the same API, the same managed services, with no dependency on a control plane you do not own.

What isolation does not cost you

Hand-built clusters, upgraded in change windows
Managed CNCF-conformant clustersHosted or dedicated control planes, autoscaling node pools, in-place upgrades and self-healing, driven from declared desired state.
Tickets for every database and VM
Self-service catalog inside quotasManaged PostgreSQL with high availability, and VMs with image catalogs, networks, routers and firewall rules, requested by the teams that need them.
A separate toolchain for the secure estate
One platform, both modelsSaaS and on-premises are the same product and the same API, so moving between them is a deployment choice rather than a migration.
Central control that dies with the link
Local reconciliation per facilityAn agent at each site pulls its desired state and reconciles locally, so provisioning, healing and restarts continue during link loss and resync afterwards.
What crosses the boundary

Nothing, by design

In the on-premises model there is no hosted component in the path: the console, the API and the control plane all run on your infrastructure, operated by your team. Workloads, data and platform metadata stay inside the perimeter, and access within the platform is governed by the organizations, projects, roles and quotas you define.

Control plane on your hardwareNo hosted dependencyPlatform IAMEU-built
ComponentWhere it runsStatusAccess
Console and APIYour perimeterActivePlatform IAM
Control planeYour perimeterActiveYour operators
Managed servicesYour OpenStackHealthyProject scoped
No outbound dependencyData never leaves
Regulated and remote

Built for sites that stand alone

The same design that serves classified estates serves ships, plants and points of presence: regions are autonomous, so a site is never one WAN outage away from being unmanageable. Combine that with a curated catalog and private application templates and a disconnected site still feels like a cloud to the people using it.

Autonomous regionsPrivate app templatesHundreds of sitesResync after outage

Total isolation

Whole platform in your perimeter, no uplink required.

Agent per facility

Desired state pulled and reconciled locally.

Private templates

Your own applications as one-click products.

Sovereignty

Your hardware, your data, supported from the EU.

Frequently asked questions

What leaves our perimeter in the on-premises model?
Nothing. The console, the API and the control plane run on your infrastructure, and workloads and metadata stay inside your perimeter. There is no dependency on a hosted control plane.
How do clusters get upgraded without an internet connection?
The platform holds the desired state for each site and the agent at that site reconciles it locally, including cluster upgrades, node pool changes and healing. Your operators control when new versions are introduced into the environment.
Is it the same product as the hosted model?
Yes. Same console, same API, same managed services. Moving between SaaS and on-premises is a deployment choice, not a migration, and pricing does not change with the model.
What happens when a site loses its link?
Running workloads and local management keep working, because reconciliation happens at the site. When connectivity returns the site resyncs with the control plane.
Can teams still self-serve in a classified environment?
That is the point of running the platform inside the perimeter: teams get projects, quotas and a catalog, so clusters, databases and VMs are requested in the console instead of through a ticket queue.

See it running inside your perimeter

Book a call to walk through the on-premises model with our engineers, or request a free trial and start against a lab OpenStack.