Hostzero Logo

EKS Exit • Private Cloud Kubernetes

Managed Kubernetes in Germany

Dedicated Kubernetes clusters in our Frankfurt data center — fully managed, sovereign, exit-ready. The private-cloud alternative to EKS and GKE, without egress bills, US jurisdiction or noisy neighbors.

Dedicated clusters — no noisy neighbors

Frankfurt, Germany

GDPR & KRITIS-ready

24/7 managed operations

No hyperscaler lock-in

Exposed instances

Initial situation

Hyperscaler Kubernetes bills you for your own growth

EKS and GKE look cheap per cluster — until egress, load balancers, NAT gateways and support tiers land on the same invoice, and your user data sits under US jurisdiction. For EU companies in regulated industries the question is no longer just cost: it is who controls the platform your business runs on. Dedicated Kubernetes in Germany answers both — predictable pricing on isolated infrastructure, under German law, on open standards you can leave with.

  • Fully isolated clusters — dedicated VLANs, optional dedicated hardware
  • Predictable monthly cost — no egress or per-API-call surprises
  • GDPR, KRITIS, DiGA and ISO-27001-oriented operations
  • Exit-ready: vanilla Kubernetes, open standards, your workloads stay portable

The offer

What "Managed Kubernetes"
means at Hostzero

We run your clusters 24/7

Updates & security patches handled

99.9% availability SLA

Your workloads stay in Germany

No lock-in — vanilla Kubernetes, export anytime

Why teams move their Kubernetes to us

Dedicated by Design

Your own cluster on isolated VLANs — optionally on hardware reserved exclusively for you. No shared control planes, no noisy neighbors, full control over resources.

Sovereign & Compliant

Frankfurt data center, German law, GDPR-native. Built for regulated industries: KRITIS, DiGA/healthcare and ISO-27001-oriented operations with documented processes.

Exit-Ready Architecture

Vanilla Kubernetes on open standards — no proprietary managed-service glue. Take your manifests and workloads anywhere, anytime. That is the point.

Hyperscaler Kubernetes vs dedicated clusters in Germany — the honest comparison

CriterionEKS / GKEHostzero Managed Kubernetes

Cost model

Cluster fee + egress + LB/NAT + support tier

Fixed monthly price per cluster

Support

Ticket tiers

Direct engineer access

Data jurisdiction

US CLOUD Act applies

German law, Frankfurt DC

Infrastructure

Shared, multi-tenant

Dedicated, isolated VLANs, optional dedicated hardware

Elastic burst scale

Excellent — minutes to hundreds of nodes

Planned capacity; hardware scaling in days, not minutes

Ecosystem integrations

Deep (IAM, S3, Lambda…)

Open-source stack (Keycloak, Ceph, Prometheus…)

Compliance for KRITIS/DiGA

Your responsibility to prove

Built into operations & documentation

Who is on call at 2 a.m.

You (or premium support tier)

Our engineers

Lock-in

Managed-service glue accumulates

Vanilla Kubernetes — export anytime

Operating models

Three models — from root access to 24/7 operations

Every cluster is dedicated. Choose who operates it. All prices are net, fixed monthly — no egress, no per-API fees.

KubeCore Root — Self-Managed

KubeCore Root — Self-Managed

Dedicated cluster, full root access
Isolated VLANs & network segmentation
High-performance storage backend (Ceph/ZFS)
You operate, we host
from 100 € /month for a three-node cluster • priced by resources
Request offer
Smart Managed

Smart Managed

Security & feature updates
Preconfigured monitoring (Prometheus)
Technical contact for operations & optimization
Your team focuses on workloads
from 199 € /month for a three-node cluster • priced by resources
Request offer
Add-on

Enterprise Managed — 24/7 Operations

24/7 support & incident response99.9% SLAMonitored backups & recoveryDedicated contact, operational ownership — for KRITIS/DiGA-grade platforms. Priced individually — from 350 € net /month • fixed quote after assessment.
Request offer

Open Source

We build Kubernetes tooling in the open — meet KubePress

Hostzero develops and maintains KubePress, an open-source Kubernetes operator for WordPress: declarative, GitOps-ready deployments of the world’s most-used CMS on any cluster. It is the same engineering discipline we apply to every customer platform — published, documented, reusable. Alongside it: our open-source Keycloak Operator for identity on Kubernetes.

wordpress-site.yaml
apiVersion: crm.hostzero.de/v1
kind: WordPressSite
metadata:
  name: wp--client-site
  namespace: kubepress
spec:
  siteTitle: client-site
  adminUserSecretKeyRef: wp--client-site
  database:
    createNew: true
  wordpress:
    image: wordpress:latest
    replicas: 1
    storageSize: 10Gi
  ingress:
    host: client-site.example.com
    tls: true

Security & Compliance

Built for regulated industries — KRITIS, DiGA, ISO 27001

KRITIS

BSI-compliant hardening of critical infrastructure (IT-SiG 2.0)

DiGA / Healthcare

BfArM-compliant infrastructure for digital health applications

ISO 27001

Certification-ready ISMS processes and documentation

GDPR

Data-protection-compliant architecture, audit-proof logging

Supply-chain security & image scanning (Trivy, SBOM)

Zero-trust networking with Cilium/eBPF

Automated PKI & mTLS (cert-manager)

Immutable audit logs & monitoring (Loki, Prometheus)

Onboarding

From EKS or bare metal to your cluster — without a big-bang cutover

01

Assessment

Workloads, storage, network, compliance requirements — and which operating model fits

02

Platform build

Dedicated cluster in Frankfurt: VLANs, storage, monitoring, backups wired in

03

Migration

Workloads move namespace by namespace; your current platform stays as fallback

04

Operation

Per your model: from root handover to 24/7 managed with SLA

Why teams choose Hostzero for Kubernetes

We run open-source infrastructure in production every day — Kubernetes, Proxmox, Ceph, Keycloak — for customers and for ourselves, from Frankfurt.

15+ Years Open Source

Enterprise open-source experience since before Kubernetes existed — network security on Juniper/Linux, SELinux, and production clusters we run for ourselves and our customers.

Compliance in Practice

KRITIS, DiGA and ISO-27001 environments are our daily work — including the documentation and audit trail that certifications actually require.

Direct Engineer Access

No ticket tiers, no middlemen — you talk to the people who run your platform.

In production

Enterprise training infrastructure — running on our clusters.

Diligram AG runs high-availability training infrastructure for enterprise customers worldwide — on managed Kubernetes clusters we operate from Frankfurt. Everything below the application is our job: platform, monitoring, backups, on-call. Their team ships the product.

"We run high-availability training infrastructure for enterprise customers worldwide. Hostzero takes care of everything below the application — and it just works. Since we moved, we haven’t had to think about infrastructure."

Uwe Placzek, Diligram AG (Managed Kubernetes / e-learning platform)

FAQ

Frequently Asked Questions

Start now

Ready to own your Kubernetes platform?

Talk to an engineer — 30 minutes, no sales pitch. Tell us your workloads and compliance requirements, and we will tell you honestly which operating model fits — or whether staying on EKS is the right call for you.