Cloud Infrastructure (IaaS)
The Okustera Cloud Infrastructure platform delivers sovereign, carrier-grade, programmable infrastructure primitives engineered to run high-performance enterprise workloads, containerized platforms, and mission-critical stateful systems.
Powered by upstream OpenStack (Nova, Neutron, Cinder, Glance, Keystone, Magnum) and Ceph NVMe storage fabrics, Okustera provides open-standard APIs, predictable pricing, and zero proprietary lock-in.
Core Infrastructure Services
Kubernetes Service (/cloud/kubernetes)
Production-ready upstream Kubernetes clusters orchestrated declaratively via OpenStack Magnum and Cluster API (CAPI). Features:
- Automated node pool scaling and worker groups.
- Zero-Downtime Rolling Surge Upgrades (
maxSurge: 1, maxUnavailable: 0) and Cluster-Level Blue/Green Deployments. - Integrated Cilium CNI with transparent WireGuard mesh encryption and OpenStack Cinder CSI.
- Measured boot and tenant security hardware powered by Virtual TPM 2.0 (
swtpm).
Compute Instances (/cloud/compute)
High-performance virtual machines powered by OpenStack Nova and KVM hypervisors:
- High-density CPU-optimized, general-purpose, and memory-optimized flavors.
- Dynamic cloud-init user data customization.
- Secure SSH keypair injection and live disk resizing.
- Anti-affinity and soft-anti-affinity server groups.
Virtual Private Cloud (VPC) Networking (/cloud/networking)
Fully software-defined networking built on OpenStack Neutron and OVN (Open Virtual Network):
- Isolated multi-tenant Layer 2/3 virtual networks and subnets.
- Distributed virtual routing (DVR) and NAT gateways.
- Stateful distributed firewall security groups.
- Elastic Floating Public IPv4 and IPv6 allocation.
Load Balancers (/cloud/loadbalancer)
High-availability Layer 4 and Layer 7 load balancing powered by OpenStack Octavia:
- Active-standby redundant amphora worker instances with dedicated VIPs.
- HTTP, HTTPS, TCP, and UDP listeners with TLS termination.
- Health monitors (HTTP GET, TCP ping) and Round Robin/Least Connections balancing.
Persistent Block Storage (/cloud/storage)
Enterprise NVMe block storage powered by OpenStack Cinder and Ceph:
- Sub-millisecond latency NVMe-backed storage pools.
- Live volume attachment, multi-attach capabilities, and online volume expansion.
- Instantaneous volume snapshots and cross-region backups.
- Dynamic CSI storage classes for Kubernetes (
csi-cinder-sc-retain).
S3 Object Storage (/cloud/s3)
Globally accessible, 100% AWS S3-compatible object storage powered by Ceph RADOS Gateway (RGW):
- Standard S3 API compatibility with AWS CLI, AWS SDKs, and Terraform.
- Interactive Cloud Portal Object Browser with drag-and-drop file uploads.
- Multi-part uploads, lifecycle tiering, and object versioning.
- Server-side encryption and IAM presigned URL generation.
- Geo-replicated buckets and zero egress penalty pricing.
Image Catalog & Custom Images (/cloud/images)
Centralized operating system catalog powered by OpenStack Glance:
- Certified public cloud images (Ubuntu 24.04, Debian 12, Rocky Linux 9, CirrOS).
- Self-service custom QCOW2 and RAW image uploads via URL or file upload.
- Creating reusable custom images from instance snapshots.
Tenant Resource Quotas (/cloud/quotas)
Authoritative resource governance across 9 platform dimensions:
- Default allocation profiles for vCPUs, RAM, storage terabytes, Nova VMs, volumes, databases, functions, DAGs, and routes.
- Real-time utilization telemetry rendered in the Cloud Portal Dashboard.
- FinOps automated soft quota freezes upon reaching 100% monthly budget limits.
Multi-Region Geographic Scaling
Scale workloads seamlessly across autonomous sovereign datacenters (RegionOne, RegionTwo):
- Autonomous Regional Planes: Each region maintains independent control planes (Nova, Neutron, Cinder, Kubernetes, Barbican KMS).
- Strict National Sovereignty: Pin workloads to specific countries to guarantee 100% in-country data residency without cross-border telemetry leakage.
- Learn more about multi-region governance in Sovereign Compliance & Multi-Region.
Infrastructure as Code (IaC)
All Okustera Cloud IaaS resources can be provisioned and managed declaratively using the official HashiCorp Terraform provider:
terraform {
required_providers {
okustera = {
source = "okustera/okustera"
version = "~> 1.0.0"
}
}
}
# Example: S3 Bucket with Versioning
resource "okustera_s3_bucket" "production_media" {
name = "company-production-media"
versioning = true
quota_gb = 500
}
Learn more in the Terraform Provider Documentation.