Moving off EKS, AKS or GKE to a European provider is rarely a Kubernetes problem. Deployments, Services, Helm charts and GitOps pipelines that use upstream APIs run on any conformant cluster. The work is in the cloud integrations your cluster leans on: pods that get IAM credentials without keys, Ingress objects that turn into an ALB or a Google-managed certificate, Karpenter provisioning nodes, ECR next to the cluster, and the managed databases your services call.
This guide lists those integrations, says what the European providers have for each one, and where you will run something yourself. It covers five European providers plus enum, and only features we could check in each provider’s own documentation on 9 October 2026.
What do teams actually use on EKS, AKS and GKE?
Inventory these before you pick a target.
| What you use | EKS | AKS | GKE |
|---|---|---|---|
| Control plane | Billed per cluster-hour, 99.95% SLA | Free tier without SLA; Standard tier billed per cluster-hour, 99.95% with zones | Billed per cluster-hour, 99.95% for regional clusters |
| L4 load balancer | NLB via AWS Load Balancer Controller | Azure Load Balancer (Standard) | Passthrough Network Load Balancer |
| L7 load balancer | ALB for Ingress and Gateway API | Application Gateway for Containers | GKE Gateway controller, Application Load Balancers |
| Managed TLS certificates | ACM | Key Vault certificates via the App Routing add-on; cert-manager documented for Application Gateway for Containers | Google-managed certificates |
| Block and file storage | EBS CSI, EFS CSI | Azure Disk CSI, Azure Files CSI | Persistent Disk / Hyperdisk CSI, Filestore CSI |
| Pod credentials without keys | EKS Pod Identity, IRSA | Microsoft Entra Workload ID | Workload Identity Federation for GKE |
| Registry | ECR | ACR | Artifact Registry |
| Node autoscaling | Karpenter, EKS Auto Mode, Cluster Autoscaler | Node auto-provisioning (Karpenter), Cluster Autoscaler | Cluster autoscaler, node pool auto-creation, Autopilot |
| Long version support | Extended support, at a higher per cluster-hour rate | LTS on the Premium tier | Extended release channel |
| Secrets | Secrets Store CSI with Secrets Manager | Key Vault provider for Secrets Store CSI | Secret Manager add-on |
| Managed databases, caches, queues | RDS, ElastiCache, SQS | Azure Database, Azure Cache, Service Bus | Cloud SQL, Memorystore, Pub/Sub |
| DNS automation | Route 53 via ExternalDNS | Azure DNS via ExternalDNS | Cloud DNS via ExternalDNS |
| Infrastructure as code | Terraform modules for EKS | Terraform modules for AKS | Terraform modules for GKE |
| Private connectivity | VPN, Direct Connect | VPN Gateway, ExpressRoute | Cloud VPN, Cloud Interconnect |
Checked October 2026.
Pricing pages: EKS, AKS, GKE. SLAs: EKS, AKS, GKE. AKS certificates: App Routing with Key Vault, cert-manager for Application Gateway for Containers.
The rows that cost the most to replace are usually managed databases, workload identity, L7 load balancing with managed certificates, and node autoscaling. Storage and L4 load balancing translate almost one to one.
Which European providers cover which integrations?
Each cell is what the provider documents for its managed Kubernetes product. enum is in the last column.
| Integration | STACKIT SKE | OVHcloud MKS | Scaleway Kapsule | Exoscale SKS | IONOS Managed Kubernetes | enum Kubernetes Engine |
|---|---|---|---|---|---|---|
| CNCF Certified Kubernetes | Yes | Yes | Yes | Yes | Yes | Upstream Kubernetes; not listed |
| Control plane price | Billed per cluster-hour | Free plan; Standard plan billed per cluster-hour | Mutualized free; dedicated tiers billed per hour by size, 30-day minimum | Starter free; Pro billed per cluster-hour | Free | Included |
| Control plane SLA | 99.9% (API server) | Standard: 99.99% (3-AZ), 99.9% (1-AZ); Free: 99.5% SLO | Paid tiers 99.5%; Mutualized none | Pro 99.95%; Starter none | 99.95% (Kubernetes API) | 99.9% (Kubernetes API); credit terms not published |
| Zones per cluster | Node pools can span the region’s three AZs | Standard: 3 AZs in Paris and Milan; 1 AZ elsewhere | Multi-AZ node pools; control plane reached through the region’s primary zone | One zone per cluster | Not documented; control plane geo-redundant within Germany | One zone (fra-a); control plane replicated across three failure domains in one site |
| Service type LoadBalancer | L4 network load balancer | L4 load balancer (Octavia) | Scaleway Load Balancer, HTTP and TLS termination via annotations | L4 network load balancer | Static public IP on one node, no external load balancer | L4 load balancer (TCP, UDP), IPv4 included; client IP not preserved yet |
| Managed L7 / Gateway API | ALB Ingress controller in private preview, on request only | Native GatewayClass announced, not shipped | No managed Ingress or Gateway | None found | Separate ALB product, no Kubernetes controller found | None; run your own Ingress or Gateway controller |
| Block storage CSI | Yes, default | Yes, default | Yes, pre-installed | Add-on, off by default | Yes, pre-installed | Yes, NVMe PersistentVolumes; no snapshots documented |
| S3-compatible object storage | Yes | Yes | Yes | Yes | Yes | Yes |
| First-party registry | Yes, described as beta | Yes (Harbor-based) | Yes | Marketplace offering run by a third party | Yes, Frankfurt only | No |
| Managed databases | Managed PostgreSQL and more | Managed PostgreSQL and more | Managed PostgreSQL and more | Managed PostgreSQL and more | Managed PostgreSQL and more | None; run an operator such as CloudNativePG |
| Node autoscaling | Cluster autoscaler | Cluster autoscaler | Pool autoscaling | Managed Karpenter add-on (Pro, GA since March 2026); upstream cluster autoscaler you deploy yourself | Cluster autoscaler, minimum one node | No; you size node pools yourself |
| Pod credentials without keys | Yes, workload identity via OIDC token exchange | Not documented | Not documented | Not documented | Not documented | No; pods use scoped object storage access keys |
| Patch upgrades | Automatic in your maintenance window | Automatic by default, policy configurable | Opt-in auto-upgrade to the latest patch, in your maintenance window | Opt-in auto-upgrade | Weekly maintenance window replaces nodes; version changes only at end of life, to the next active minor | Applied by enum |
| Minor upgrades | You trigger; forced at end of life | You trigger; versions past end of support keep running without SLA, and the oldest is force-upgraded with 30 days’ notice | You trigger; forced within 30 days of end of support | You trigger | You trigger; forced at end of life | Run by enum, node by node |
| Certifications | BSI C5 Type 2 (SKE in scope), ISO 27001 | BSI C5 Type 2; ISO 27001 incl. MKS; SecNumCloud not for MKS | ISO 27001; SecNumCloud in qualification | BSI C5 Type 2, ISO 27001 | BSI C5 Type 1 (May 2026, service scope not published); ISO 27001 on IT-Grundschutz incl. Managed Kubernetes | None yet; ISO 27001 targeted Q4 2026, C5 in 2027 |
| European locations for Kubernetes | Germany, Austria | France, Germany, Italy, Poland, UK | France, Netherlands, Poland, Italy | Germany, Austria, Switzerland, Bulgaria, Croatia (8 zones; Madrid announced) | Germany (Frankfurt) | Frankfurt (one zone) |
| HQ | Germany (Schwarz Group) | France | France (iliad Group) | Switzerland (A1 Telekom Austria Group) | Germany (United Internet) | Germany |
Checked October 2026.
Pricing pages: STACKIT, OVHcloud, Scaleway (30-day minimum: Kapsule FAQ), Exoscale, IONOS, enum.
Sources for the rows that change most often. Conformance: cncf/k8s-conformance. Zones: STACKIT topologies, OVHcloud MKS regions, Scaleway multi-AZ clusters, Exoscale SKS limits, IONOS Managed Kubernetes FAQ. Managed PostgreSQL: STACKIT, OVHcloud, Scaleway, Exoscale, IONOS. Certifications: STACKIT, OVHcloud C5 and ISO scope, Scaleway, Exoscale, IONOS. Autoscaling: Exoscale Karpenter GA. Upgrades: OVHcloud EOS/EOL policy, Scaleway version policy, IONOS maintenance.
The SLA row covers the control plane or Kubernetes API only, not worker nodes or volumes. enum does not publish SLA credit terms; they come with the contract. OVHcloud runs managed Kubernetes in far more European regions than enum; IONOS Managed Kubernetes, like enum, runs in Europe only in Frankfurt. enum clusters are set up on request today; self-service cluster creation is planned for Q4 2026.
The HQ row is not the whole ownership picture. Exoscale contracts under Swiss law (terms), and A1 Telekom Austria Group is majority owned by América Movil of Mexico (A1 shareholder structure). OVHcloud has a US affiliate, OVH US LLC (OVH US FAQ). IONOS sells in the US through IONOS Cloud USA Inc. (IONOS US). enum GmbH is a German company in Cologne with no US parent and no US company in its structure. Whether US law such as the CLOUD Act can reach a provider depends on its group structure.
This guide is general information, not legal advice. Have your counsel assess your specific situation.
Workload identity: the integration most teams underestimate
On EKS a pod gets an IAM role through Pod Identity or IRSA. On AKS it is Entra Workload ID, on GKE Workload Identity Federation. In every case the pod presents its projected service account token and receives short-lived cloud credentials. No access key sits in a Secret.
Of the European providers checked here, only STACKIT documents the same pattern: a webhook injects a projected token that is exchanged for a short-lived STACKIT API token, enabled per service account with an annotation (STACKIT workload identity). OVHcloud, Scaleway, Exoscale and IONOS document OIDC only for human logins, and enum has no workload identity, so on all five a pod that talks to object storage uses an access key. A customer asked for workload identity federation in OVHcloud’s public roadmap repository on 1 October 2026; the request is still open (OVHcloud roadmap issue).
What this means in practice:
- Inventory every workload that gets cloud credentials: service accounts annotated with
eks.amazonaws.com/role-arn,azure.workload.identity/client-idoriam.gke.io/gcp-service-account, EKS Pod Identity associations (aws eks list-pod-identity-associations), and GKE IAM bindings toPROJECT_ID.svc.id.googprincipals. Pod Identity and the GKE principal bindings leave no annotation on the ServiceAccount (EKS Pod Identity, GKE Workload Identity). Each is a place where a static key will appear. - Give each workload its own scoped storage user or API key instead of one shared key. On enum, object storage supports per-user IAM policies today.
- Deliver keys through an external secrets store (Vault or OpenBao with the External Secrets Operator is common) and rotate them on a schedule.
- If a workload calls AWS or Google APIs that stay where they are, you can keep federation by pointing that cloud’s OIDC trust at your new cluster’s service account issuer. For AWS and Azure this only works if the issuer’s OIDC discovery document and keys are publicly reachable (AWS, Microsoft). Google also accepts an uploaded copy of the cluster’s JWKS, which you re-upload when the signing keys rotate (Google). STACKIT documents a per-cluster
serviceAccountIssuerURL with a public OIDC discovery endpoint. For the other providers here, ask whether the issuer URL is publicly reachable before you plan on it.
Load balancers, Ingress and certificates
L4 maps cleanly. A Service of type LoadBalancer gets a provider load balancer on STACKIT, OVHcloud, Scaleway, Exoscale and enum. IONOS is the exception: it reserves a static public IP and attaches it to one worker node rather than creating an external load balancer, which matters for failover planning. On enum the load balancer does not preserve the client source IP yet; if your application logs or filters by client IP, plan for that.
L7 is where EKS, AKS and GKE users notice the gap. An Ingress with ALB annotations or a Gateway using gke-l7-global-external-managed has no direct equivalent on the European side today. STACKIT’s ALB Ingress controller is in private preview, available on request and not recommended for production (STACKIT); OVHcloud has announced a native GatewayClass; and Scaleway’s load balancer can terminate TLS through Service annotations. For production, plan on running your own Gateway API or Ingress controller (Envoy Gateway, Traefik, Contour or Cilium) behind the L4 load balancer, with cert-manager and Let’s Encrypt for certificates. Do not start new clusters on the community ingress-nginx controller, which the Kubernetes project retired in March 2026 (Kubernetes blog). Rewrite ALB and GKE-specific annotations and ingressClassName values; they are ignored elsewhere.
Storage: what translates and what does not
Block storage is a StorageClass swap. Every provider above has a CSI driver; on Exoscale you enable it as an add-on. Change storageClassName in your claims, and move data with Velero or application-level dumps, not by copying volumes. enum documents no volume snapshots, so back up volumes with Velero or at the application level.
If you use KMS-encrypted EBS, Azure Disk or Persistent Disk volumes, check volume encryption and customer-managed keys at the target. STACKIT (KMS), OVHcloud (KMS), Scaleway (Key Manager) and Exoscale (KMS, available since July 2026) sell a key management service. enum encrypts volumes at rest on every storage device but has no customer-managed keys or KMS.
File storage (EFS, Azure Files, Filestore) was out of scope for this check. If you depend on ReadWriteMany volumes, ask each provider directly. enum has no file storage.
Object storage is S3-compatible at all six. Code using the AWS SDK usually keeps working after an endpoint and credential change; with SDK releases from 2025 onward you may also need to set checksum calculation to when_required, and on some providers the region or path-style addressing (AWS SDK data integrity settings). GCS and Azure Blob code needs an S3 client. Bucket policies, lifecycle rules and Object Lock support differ by provider, so test the ones you use.
Managed databases
Most teams on EKS, AKS or GKE also run RDS, Cloud SQL or Azure Database, and these often take longer to move than the cluster. STACKIT, OVHcloud, Scaleway, Exoscale and IONOS sell managed PostgreSQL and other engines (sources under the provider table). enum has no managed database, cache or queue. On enum you run PostgreSQL in the cluster with an operator such as CloudNativePG, on NVMe block storage, and you own backups and failover.
Autoscaling and upgrades
If you run Karpenter on EKS or node auto-provisioning on AKS, expect less on most European providers. Exoscale offers a managed Karpenter add-on on its Pro plan. STACKIT, OVHcloud, Scaleway and IONOS have the cluster autoscaler or per-pool autoscaling with fixed node pools. enum has no cluster autoscaling today; you size node pools for your peak. Node types on enum are general purpose x86 (AMD EPYC), plus reserved GPU nodes on request, with no ARM, CPU-optimised or memory-optimised types, so Graviton or spot node pools have no direct equivalent.
On upgrades, the hyperscalers let you pay for long support windows. European providers offer no paid extended support; most follow roughly the upstream window and move clusters off expired versions, each on its own schedule (see the table). Budget for a minor upgrade roughly every few months and test it in staging first.
How to plan the move
- Export every annotation, CRD and controller that names a cloud (
kubectl get ingress,gateway,httproute,svc,sa,pvc,storageclass,deploy,sts,ds,cronjob -A -o yaml, grepped foraws,alb,ecr,azure,gke,gcr.io,pkg.dev,cloud.google; then list EKS Pod Identity associations and GKE IAM bindings, which live outside the cluster). - Sort each into: works unchanged, swap for a provider equivalent, or run yourself. Include managed databases, DNS automation, Terraform and private connectivity in the list.
- Pick the provider on the “run yourself” list you can live with, not on control plane price.
- Stand up the new cluster next to the old one, move one non-critical service, and switch DNS last.
FAQ
Can I move from EKS, AKS or GKE without changing application code? Usually yes. Manifests and Helm charts that use upstream APIs run unchanged on conformant Kubernetes. What changes is cloud-specific configuration: annotations, StorageClasses, registry URLs and how pods get credentials. Managed databases and queues are a separate move.
Which European provider has workload identity like IRSA or GKE Workload Identity? Of the providers checked here, STACKIT documents it for SKE. On the others, enum included, plan for scoped access keys delivered through a secrets store.
Is there a European equivalent of the AWS ALB or GKE Gateway? Not as a GA integration with Kubernetes at the providers checked. Run your own Gateway API or Ingress controller behind the provider’s L4 load balancer and use cert-manager for certificates.
Do I need a European container registry? If images should stay in the EU, yes. STACKIT, OVHcloud, Scaleway and IONOS have first-party registries. On Exoscale, use the third-party 8gears registry from its marketplace or run Harbor yourself. On enum, run Harbor yourself or use a registry from another European provider.
Is the control plane free on European providers? On some. IONOS includes it, OVHcloud, Scaleway and Exoscale have free tiers without the paid tier’s SLA, STACKIT charges per cluster, and enum includes a highly available control plane with 99.9% for the Kubernetes API. enum’s SLA credit terms are not published and come with the contract.
Where enum fits
enum Kubernetes Engine runs upstream Kubernetes in Frankfurt with a highly available control plane per cluster included, NVMe block storage, S3-compatible object storage and L4 load balancers on one bill in euros. Know the limits before you plan on it:
- One region and one zone (fra-a). The control plane is replicated across three failure domains in one site; there are no multi-AZ clusters.
- No registry, no workload identity, no cluster autoscaling, no managed databases, caches or queues, and no L7 load balancer.
- No secrets manager and no managed monitoring or logging. Fine-grained IAM roles and cluster audit logs are planned for Q4 2026.
- No client IP preservation on load balancers yet, no NAT gateway with a stable egress IP yet, and no VPN or private interconnect. VPC is in preview.
- No Terraform provider or ExternalDNS provider yet; both are planned for Q4 2026. enum DNS is free and has a cert-manager webhook.
- Clusters are set up with our team rather than self-service until Q4 2026, and the public API is read-only for clusters.
- General purpose x86 nodes, plus reserved GPU nodes on request. No volume snapshots documented, and no customer-managed keys.
- Not listed as CNCF Certified Kubernetes. No ISO 27001 or C5 yet, and no published sub-processor list.
- Included support runs on working days; 24/7 response for critical incidents comes with Enterprise Support.
If those gaps are acceptable for your workloads, see enum Kubernetes Engine, the migration process and the comparisons with AWS and GKE.