Skip to content

Kubernetes application platform

Managed control plane on 3 DCs, GPU node groups, console addons.

A platform team building its application platform in Switzerland assembles five blocks in one tenant: the managed cluster to run workloads, Registry as a Service for images, Vault as a Service for secrets, the VPC for network isolation, and the Monitoring Agents addon for observability. The team keeps kubectl, Helm and its own GitOps; Hidora SA operates the control plane and the nodes’ Talos OS. The service itself, its managed scope and its price: managed Kubernetes.

  • Cluster
  • Node groups
  • Addons
ISO 27001
3 DC
SLA 99.99%

For platform teams and IT leadership: CNCF-certified Kubernetes, operated by Hidora SA, no US parent. kubectl, Helm and GitOps stay. API and console today; Terraform and Cluster API integration in preparation. Engineer support FR/EN. nFADP framework. The 14-day trial includes GPUs.

ISO/IEC 27001, certified by SQSKubernetes Certified Service ProviderCertified Kubernetes
  1. 01

    Cluster

    Hidora SA control plane on each DC (Geneva, Gland, Lucerne), 32 CHF/month. Talos nodes, Certified Kubernetes Hosted.

  2. 02

    Node groups

    Hikube automatically distributes workers on each DC, including GPU node groups (L4, L40S, A100-80, RTX 6000 Pro, H100, H200).

  3. 03

    Addons

    Optional in the console (Cert-Manager, Ingress NGINX, GPU Operator, Flux CD, Velero…). Cilium, CoreDNS and VPA are always on.

  4. 04

    Trial

    14 days, GPUs included. Request a trial, or talk to an engineer.

In detail

A sovereign Kubernetes platform is not only a managed control plane. It is the cluster, registry, VPC, secrets and observability under the same law. On Hikube, Hidora SA operates the control plane in Switzerland, on Geneva, Gland and Lucerne. Workers, PVCs, Registry as a Service and Vault as a Service stay in the tenant. Nothing replicates to the EU or the United States. A US group’s Zurich region does not offer that legal basis: the CLOUD Act remains. Platform teams keep kubectl, Helm, Flux or Argo. The Hikube API and the console create clusters, node groups and GPUs. Support is French and English. The 14-day trial includes GPUs. nFADP framework. This is not a PaaS that hides Kubernetes. Product detail: managed Kubernetes.

Two distinct CNCF programmes, both already listed on the landscape. Hikube Managed Kubernetes is Certified Kubernetes Hosted: the cluster you run is CNCF-conformant Kubernetes, not a house fork. Hidora SA is a Kubernetes Certified Service Provider (KCSP): the operator that holds the control plane is a certified provider. Both listings are on the CNCF landscape, not a house badge. Clusters run on Talos. This is not CNCF AI Conformance: we do not claim it.

Talos Linux exists only to run Kubernetes. Ubuntu or Rocky with kubelet still has SSH, a package manager and a general-purpose OS to patch: nodes drift, the attack surface grows. Talos is immutable. No SSH or admin shell on the node. Config goes through an API. Less drift, image upgrades instead of apt. kubectl and Helm do not change: the cluster stays standard Kubernetes, CNCF certified. That is already the base of Hikube clusters, not an option.

Yes. Hidora SA operates the control plane with replicas on Geneva, Gland and Lucerne. etcd follows the three sites: you do not install the API servers, watch quorum or trigger failover. The managed control plane is published at 32 CHF/month. A control plane that survives the loss of one site is not enough for the application on its own: Hikube spreads the workers; topology spread and PDBs for pods stay on your side. The guide the three-datacenter procedure and the article the high-availability architecture cover quorum; RPO and SLA credit are not published.

Yes. Workers run in your tenant, as node groups. Hikube distributes them automatically across Geneva, Gland and Lucerne: you do not choose the DC. Kubernetes does not spread pods by itself: a three-replica Deployment can pin all three in the same DC. Topology spread and PodDisruptionBudget stay yours. Without those constraints, a correctly operated Hikube cluster will not show the published HA class at application level. That is the usual managed Kubernetes split, stated plainly.

You create several node groups in the cluster: CPU for the base, GPU for inference or training. Worker autoscaling follows load. GPU node groups use the published NVIDIA catalogue: L4, L40S, A100-80, RTX 6000 Pro, H100, H200. They are in the 14-day trial. The GPU Operator (optional addon) installs drivers and the device plugin. HAMi, also optional, shares one card across pods and requires the GPU Operator. Card detail: the GPU catalog.

Always in the cluster, you do not tick them: Cilium (eBPF CNI, networking and security), CoreDNS (cluster DNS), Vertical Pod Autoscaler (adjusts pod resources). Optional CLUSTER ADDONS in the console: Cert-Manager (automatic SSL/TLS certificates), Ingress NGINX (NGINX Ingress controller), Gateway API (Kubernetes Gateway API CRDs, experimental channel, we say so plainly), GPU Operator (NVIDIA GPU management), HAMi (GPU virtualisation, share one card across pods, requires GPU Operator), Flux CD (GitOps), Monitoring Agents (logs and metrics), Ouroboros (fixes hairpin NAT for ingress-nginx with PROXY protocol, requires Ingress NGINX), Velero (Kubernetes backup and restore). Cluster admins can override Helm values for those optional addons in the console. That is the technical lever for the platform team, addon by addon.

Hidora SA operates the control plane, Talos on the nodes, Cilium, CoreDNS, VPA, the three DCs and FR/EN engineer support. You keep kubectl, Helm, workloads, GitOps, node-group sizing, topology spread, PDBs, and optional addon config (including Helm overrides in the console). Registry, VPC and Vault stay in the same tenant if you use them. Terraform and Cluster API integration in preparation: today the Hikube API and the console create the cluster. This is not a PaaS that hides Kubernetes, and not a cluster you have to install by hand.

Platform teams that want certified Kubernetes, not an opaque PaaS. GitOps (Flux in the console, or Argo you install). GPU inference and training in Switzerland, on dedicated node groups. Line-of-business workloads already containerised that must stay under Swiss law (nFADP). Exit from a hyperscaler Europe region whose parent remains American. This is not the first step of a VMware exit still on VMs: that path is the VMware exit.

Monitoring Agents (optional addon) collect logs and metrics in the cluster. A stack you can run in the tenant (Grafana, VictoriaMetrics, VictoriaLogs): metrics do not default to a US SaaS. Chart detail is in the docs.

Yes. Keep Helm, Flux or Argo. Flux CD is an optional addon in the console. The Hikube API and the console manage the cluster (node groups, addons, kubeconfig); Git manages workloads. Terraform and Cluster API integration in preparation: they are not live today. kubectl stays.

Frequently asked questions

Hidora SA is a KCSP. Hikube Managed Kubernetes is Certified Kubernetes Hosted (CNCF). Both listings are on the CNCF landscape. Clusters run on Talos Linux. This is not CNCF AI Conformance.

Yes, through exclusive Swiss hosting. Hidora SA operates the control plane on Geneva, Gland and Lucerne. Cluster, registry, VPC, Vault and observability stay in the tenant. No EU/US replication, no US parent. kubectl, Helm and GitOps stay. GPUs included in the 14-day trial. nFADP framework.

The managed Kubernetes control plane is published at 32 CHF/month. Workers and GPUs bill on usage, per catalogue SKUs. The 14-day trial, no credit card, includes GPUs.

Yes, in the console, for optional CLUSTER ADDONS. That is the cluster admin lever: overrides are set addon by addon, in the console.

Terraform and Cluster API integration in preparation. Today: Hikube API and console. kubectl, Helm and S3 clients stay.

No. The Gateway API addon installs Kubernetes Gateway API CRDs on the experimental channel. We say so plainly. Ingress NGINX remains the classic Ingress option, also optional.

Not if you stay on Hikube Registry as a Service and Vault as a Service. Pulling images from ECR or GHCR, or storing secrets in a US KMS, breaks cluster sovereignty. The platform is built to keep everything in the same Swiss tenant.

Engineer support is in French and English, from Geneva. German is not a support language.

Create your account

An engineer opens your tenant within 24 business hours, then you work self-serve in the console.

By submitting, you agree that Hidora processes this request (privacy policy). Optional marketing below.

Your request is handled in our HubSpot CRM; platform workloads themselves stay in Switzerland.

Ready to run on 100% Swiss infrastructure?

14-day trial, no credit card. GPUs included.