Skip to main content

Cloud Infrastructure (IaaS)

The Okustera Cloud Infrastructure platform delivers sovereign, carrier-grade, programmable infrastructure primitives engineered to run high-performance enterprise workloads, containerized platforms, and mission-critical stateful systems.

Powered by upstream OpenStack (Nova, Neutron, Cinder, Glance, Keystone, Magnum) and Ceph NVMe storage fabrics, Okustera provides open-standard APIs, predictable pricing, and zero proprietary lock-in.


Core Infrastructure Services​

Kubernetes Service (/cloud/kubernetes)​

Production-ready upstream Kubernetes clusters orchestrated declaratively via OpenStack Magnum and Cluster API (CAPI). Features:

  • Automated node pool scaling and worker groups.
  • Zero-Downtime Rolling Surge Upgrades (maxSurge: 1, maxUnavailable: 0) and Cluster-Level Blue/Green Deployments.
  • Integrated Cilium CNI with transparent WireGuard mesh encryption and OpenStack Cinder CSI.
  • Measured boot and tenant security hardware powered by Virtual TPM 2.0 (swtpm).

Compute Instances (/cloud/compute)​

High-performance virtual machines powered by OpenStack Nova and KVM hypervisors:

  • High-density CPU-optimized, general-purpose, and memory-optimized flavors.
  • Dynamic cloud-init user data customization.
  • Secure SSH keypair injection and live disk resizing.
  • Anti-affinity and soft-anti-affinity server groups.

Virtual Private Cloud (VPC) Networking (/cloud/networking)​

Fully software-defined networking built on OpenStack Neutron and OVN (Open Virtual Network):

  • Isolated multi-tenant Layer 2/3 virtual networks and subnets.
  • Distributed virtual routing (DVR) and NAT gateways.
  • Stateful distributed firewall security groups.
  • Elastic Floating Public IPv4 and IPv6 allocation.

Load Balancers (/cloud/loadbalancer)​

High-availability Layer 4 and Layer 7 load balancing powered by OpenStack Octavia:

  • Active-standby redundant amphora worker instances with dedicated VIPs.
  • HTTP, HTTPS, TCP, and UDP listeners with TLS termination.
  • Health monitors (HTTP GET, TCP ping) and Round Robin/Least Connections balancing.

Persistent Block Storage (/cloud/storage)​

Enterprise NVMe block storage powered by OpenStack Cinder and Ceph:

  • Sub-millisecond latency NVMe-backed storage pools.
  • Live volume attachment, multi-attach capabilities, and online volume expansion.
  • Instantaneous volume snapshots and cross-region backups.
  • Dynamic CSI storage classes for Kubernetes (csi-cinder-sc-retain).

S3 Object Storage (/cloud/s3)​

Globally accessible, 100% AWS S3-compatible object storage powered by Ceph RADOS Gateway (RGW):

  • Standard S3 API compatibility with AWS CLI, AWS SDKs, and Terraform.
  • Interactive Cloud Portal Object Browser with drag-and-drop file uploads.
  • Multi-part uploads, lifecycle tiering, and object versioning.
  • Server-side encryption and IAM presigned URL generation.
  • Geo-replicated buckets and zero egress penalty pricing.

Image Catalog & Custom Images (/cloud/images)​

Centralized operating system catalog powered by OpenStack Glance:

  • Certified public cloud images (Ubuntu 24.04, Debian 12, Rocky Linux 9, CirrOS).
  • Self-service custom QCOW2 and RAW image uploads via URL or file upload.
  • Creating reusable custom images from instance snapshots.

Tenant Resource Quotas (/cloud/quotas)​

Authoritative resource governance across 9 platform dimensions:

  • Default allocation profiles for vCPUs, RAM, storage terabytes, Nova VMs, volumes, databases, functions, DAGs, and routes.
  • Real-time utilization telemetry rendered in the Cloud Portal Dashboard.
  • FinOps automated soft quota freezes upon reaching 100% monthly budget limits.

Multi-Region Geographic Scaling​

Scale workloads seamlessly across autonomous sovereign datacenters (RegionOne, RegionTwo):

  • Autonomous Regional Planes: Each region maintains independent control planes (Nova, Neutron, Cinder, Kubernetes, Barbican KMS).
  • Strict National Sovereignty: Pin workloads to specific countries to guarantee 100% in-country data residency without cross-border telemetry leakage.
  • Learn more about multi-region governance in Sovereign Compliance & Multi-Region.

Infrastructure as Code (IaC)​

All Okustera Cloud IaaS resources can be provisioned and managed declaratively using the official HashiCorp Terraform provider:

terraform {
required_providers {
okustera = {
source = "okustera/okustera"
version = "~> 1.0.0"
}
}
}

# Example: S3 Bucket with Versioning
resource "okustera_s3_bucket" "production_media" {
name = "company-production-media"
versioning = true
quota_gb = 500
}

Learn more in the Terraform Provider Documentation.