Safespring Kubernetes Engine runs containerized applications on Safespring infrastructure. The service includes self-service provisioning and a managed control plane.
Organizations use the service when data location, jurisdiction, and operational boundaries must be explicit, including environments with GDPR, compliance, and digital sovereignty requirements.
Engineering teams get a Kubernetes environment without operating the control plane. The organization keeps decisions about jurisdiction, security posture, and platform direction inside its own governance.
Deploy anywhere
No vendor lock-in
Cloud-native technologies
Digital sovereignty
100% renewable energy
You are in control
Architecture and service boundary
Safespring Kubernetes Engine sets a service boundary before the first cluster is created. Safespring runs the control plane. Your team creates clusters in the portal and then owns the workloads and application configuration inside the cluster. API-based cluster provisioning is under development.
What this means in practice
The service includes:
- cluster creation through the Safespring portal
- API-based cluster provisioning, which is under development
- a managed control plane
- Talos Linux as the node operating system
- Cilium, Gateway API, and Traefik support for networking and traffic handling
- a documented split between Safespring’s platform responsibility and your team’s application responsibility
Technical characteristics
Create clusters in the portal
Teams create clusters in the Safespring portal. API-based cluster provisioning is under development. Safespring operates the control plane as part of the service. This reduces the internal platform work needed before a Kubernetes environment can be used.
The foundation reduces operational drift
Talos Linux provides an immutable, Kubernetes-focused node base. OIDC-based access, Cilium networking, and a defined service boundary make the platform easier to review and operate.
Workloads can use storage, traffic handling, and GPU nodes
Cinder CSI provides persistent volumes. Cilium Gateway API and Traefik support traffic handling. GPU-capable worker nodes are available for workloads that need them.
The service is delivered from Safespring data centers in Sweden and Norway and runs on 100% renewable energy. It is for organizations that need control over jurisdiction, data location, and supplier dependency.
Go deeper before technical evaluation
When you want to validate architecture, responsibility boundaries, and the operating model, these are the most useful next steps.
Talk to us about your needs
Contact us
Do you have questions about how this service can support your modernization, governance, sustainability, or digital sovereignty goals? Contact us for an initial discussion about your needs, target state, and next steps.
Call
+46 855 10 73 70
Mail
hello@safespring.com