← Back to guides

Replacing EKS, AKS or GKE in Europe: what moves over and what you rebuild

Max Heyer · Updated

Moving off EKS, AKS or GKE to a European provider is rarely a Kubernetes problem. Deployments, Services, Helm charts and GitOps pipelines that use upstream APIs run on any conformant cluster. The work is in the cloud integrations your cluster leans on: pods that get IAM credentials without keys, Ingress objects that turn into an ALB or a Google-managed certificate, Karpenter provisioning nodes, ECR next to the cluster, and the managed databases your services call.

This guide lists those integrations, says what the European providers have for each one, and where you will run something yourself. It covers five European providers plus enum, and only features we could check in each provider’s own documentation on 9 October 2026.

What do teams actually use on EKS, AKS and GKE?

Inventory these before you pick a target.

What you useEKSAKSGKE
Control planeBilled per cluster-hour, 99.95% SLAFree tier without SLA; Standard tier billed per cluster-hour, 99.95% with zonesBilled per cluster-hour, 99.95% for regional clusters
L4 load balancerNLB via AWS Load Balancer ControllerAzure Load Balancer (Standard)Passthrough Network Load Balancer
L7 load balancerALB for Ingress and Gateway APIApplication Gateway for ContainersGKE Gateway controller, Application Load Balancers
Managed TLS certificatesACMKey Vault certificates via the App Routing add-on; cert-manager documented for Application Gateway for ContainersGoogle-managed certificates
Block and file storageEBS CSI, EFS CSIAzure Disk CSI, Azure Files CSIPersistent Disk / Hyperdisk CSI, Filestore CSI
Pod credentials without keysEKS Pod Identity, IRSAMicrosoft Entra Workload IDWorkload Identity Federation for GKE
RegistryECRACRArtifact Registry
Node autoscalingKarpenter, EKS Auto Mode, Cluster AutoscalerNode auto-provisioning (Karpenter), Cluster AutoscalerCluster autoscaler, node pool auto-creation, Autopilot
Long version supportExtended support, at a higher per cluster-hour rateLTS on the Premium tierExtended release channel
SecretsSecrets Store CSI with Secrets ManagerKey Vault provider for Secrets Store CSISecret Manager add-on
Managed databases, caches, queuesRDS, ElastiCache, SQSAzure Database, Azure Cache, Service BusCloud SQL, Memorystore, Pub/Sub
DNS automationRoute 53 via ExternalDNSAzure DNS via ExternalDNSCloud DNS via ExternalDNS
Infrastructure as codeTerraform modules for EKSTerraform modules for AKSTerraform modules for GKE
Private connectivityVPN, Direct ConnectVPN Gateway, ExpressRouteCloud VPN, Cloud Interconnect

Checked October 2026.

Pricing pages: EKS, AKS, GKE. SLAs: EKS, AKS, GKE. AKS certificates: App Routing with Key Vault, cert-manager for Application Gateway for Containers.

The rows that cost the most to replace are usually managed databases, workload identity, L7 load balancing with managed certificates, and node autoscaling. Storage and L4 load balancing translate almost one to one.

Which European providers cover which integrations?

Each cell is what the provider documents for its managed Kubernetes product. enum is in the last column.

IntegrationSTACKIT SKEOVHcloud MKSScaleway KapsuleExoscale SKSIONOS Managed Kubernetesenum Kubernetes Engine
CNCF Certified KubernetesYesYesYesYesYesUpstream Kubernetes; not listed
Control plane priceBilled per cluster-hourFree plan; Standard plan billed per cluster-hourMutualized free; dedicated tiers billed per hour by size, 30-day minimumStarter free; Pro billed per cluster-hourFreeIncluded
Control plane SLA99.9% (API server)Standard: 99.99% (3-AZ), 99.9% (1-AZ); Free: 99.5% SLOPaid tiers 99.5%; Mutualized nonePro 99.95%; Starter none99.95% (Kubernetes API)99.9% (Kubernetes API); credit terms not published
Zones per clusterNode pools can span the region’s three AZsStandard: 3 AZs in Paris and Milan; 1 AZ elsewhereMulti-AZ node pools; control plane reached through the region’s primary zoneOne zone per clusterNot documented; control plane geo-redundant within GermanyOne zone (fra-a); control plane replicated across three failure domains in one site
Service type LoadBalancerL4 network load balancerL4 load balancer (Octavia)Scaleway Load Balancer, HTTP and TLS termination via annotationsL4 network load balancerStatic public IP on one node, no external load balancerL4 load balancer (TCP, UDP), IPv4 included; client IP not preserved yet
Managed L7 / Gateway APIALB Ingress controller in private preview, on request onlyNative GatewayClass announced, not shippedNo managed Ingress or GatewayNone foundSeparate ALB product, no Kubernetes controller foundNone; run your own Ingress or Gateway controller
Block storage CSIYes, defaultYes, defaultYes, pre-installedAdd-on, off by defaultYes, pre-installedYes, NVMe PersistentVolumes; no snapshots documented
S3-compatible object storageYesYesYesYesYesYes
First-party registryYes, described as betaYes (Harbor-based)YesMarketplace offering run by a third partyYes, Frankfurt onlyNo
Managed databasesManaged PostgreSQL and moreManaged PostgreSQL and moreManaged PostgreSQL and moreManaged PostgreSQL and moreManaged PostgreSQL and moreNone; run an operator such as CloudNativePG
Node autoscalingCluster autoscalerCluster autoscalerPool autoscalingManaged Karpenter add-on (Pro, GA since March 2026); upstream cluster autoscaler you deploy yourselfCluster autoscaler, minimum one nodeNo; you size node pools yourself
Pod credentials without keysYes, workload identity via OIDC token exchangeNot documentedNot documentedNot documentedNot documentedNo; pods use scoped object storage access keys
Patch upgradesAutomatic in your maintenance windowAutomatic by default, policy configurableOpt-in auto-upgrade to the latest patch, in your maintenance windowOpt-in auto-upgradeWeekly maintenance window replaces nodes; version changes only at end of life, to the next active minorApplied by enum
Minor upgradesYou trigger; forced at end of lifeYou trigger; versions past end of support keep running without SLA, and the oldest is force-upgraded with 30 days’ noticeYou trigger; forced within 30 days of end of supportYou triggerYou trigger; forced at end of lifeRun by enum, node by node
CertificationsBSI C5 Type 2 (SKE in scope), ISO 27001BSI C5 Type 2; ISO 27001 incl. MKS; SecNumCloud not for MKSISO 27001; SecNumCloud in qualificationBSI C5 Type 2, ISO 27001BSI C5 Type 1 (May 2026, service scope not published); ISO 27001 on IT-Grundschutz incl. Managed KubernetesNone yet; ISO 27001 targeted Q4 2026, C5 in 2027
European locations for KubernetesGermany, AustriaFrance, Germany, Italy, Poland, UKFrance, Netherlands, Poland, ItalyGermany, Austria, Switzerland, Bulgaria, Croatia (8 zones; Madrid announced)Germany (Frankfurt)Frankfurt (one zone)
HQGermany (Schwarz Group)FranceFrance (iliad Group)Switzerland (A1 Telekom Austria Group)Germany (United Internet)Germany

Checked October 2026.

Pricing pages: STACKIT, OVHcloud, Scaleway (30-day minimum: Kapsule FAQ), Exoscale, IONOS, enum.

Sources for the rows that change most often. Conformance: cncf/k8s-conformance. Zones: STACKIT topologies, OVHcloud MKS regions, Scaleway multi-AZ clusters, Exoscale SKS limits, IONOS Managed Kubernetes FAQ. Managed PostgreSQL: STACKIT, OVHcloud, Scaleway, Exoscale, IONOS. Certifications: STACKIT, OVHcloud C5 and ISO scope, Scaleway, Exoscale, IONOS. Autoscaling: Exoscale Karpenter GA. Upgrades: OVHcloud EOS/EOL policy, Scaleway version policy, IONOS maintenance.

The SLA row covers the control plane or Kubernetes API only, not worker nodes or volumes. enum does not publish SLA credit terms; they come with the contract. OVHcloud runs managed Kubernetes in far more European regions than enum; IONOS Managed Kubernetes, like enum, runs in Europe only in Frankfurt. enum clusters are set up on request today; self-service cluster creation is planned for Q4 2026.

The HQ row is not the whole ownership picture. Exoscale contracts under Swiss law (terms), and A1 Telekom Austria Group is majority owned by América Movil of Mexico (A1 shareholder structure). OVHcloud has a US affiliate, OVH US LLC (OVH US FAQ). IONOS sells in the US through IONOS Cloud USA Inc. (IONOS US). enum GmbH is a German company in Cologne with no US parent and no US company in its structure. Whether US law such as the CLOUD Act can reach a provider depends on its group structure.

This guide is general information, not legal advice. Have your counsel assess your specific situation.

Workload identity: the integration most teams underestimate

On EKS a pod gets an IAM role through Pod Identity or IRSA. On AKS it is Entra Workload ID, on GKE Workload Identity Federation. In every case the pod presents its projected service account token and receives short-lived cloud credentials. No access key sits in a Secret.

Of the European providers checked here, only STACKIT documents the same pattern: a webhook injects a projected token that is exchanged for a short-lived STACKIT API token, enabled per service account with an annotation (STACKIT workload identity). OVHcloud, Scaleway, Exoscale and IONOS document OIDC only for human logins, and enum has no workload identity, so on all five a pod that talks to object storage uses an access key. A customer asked for workload identity federation in OVHcloud’s public roadmap repository on 1 October 2026; the request is still open (OVHcloud roadmap issue).

What this means in practice:

  • Inventory every workload that gets cloud credentials: service accounts annotated with eks.amazonaws.com/role-arn, azure.workload.identity/client-id or iam.gke.io/gcp-service-account, EKS Pod Identity associations (aws eks list-pod-identity-associations), and GKE IAM bindings to PROJECT_ID.svc.id.goog principals. Pod Identity and the GKE principal bindings leave no annotation on the ServiceAccount (EKS Pod Identity, GKE Workload Identity). Each is a place where a static key will appear.
  • Give each workload its own scoped storage user or API key instead of one shared key. On enum, object storage supports per-user IAM policies today.
  • Deliver keys through an external secrets store (Vault or OpenBao with the External Secrets Operator is common) and rotate them on a schedule.
  • If a workload calls AWS or Google APIs that stay where they are, you can keep federation by pointing that cloud’s OIDC trust at your new cluster’s service account issuer. For AWS and Azure this only works if the issuer’s OIDC discovery document and keys are publicly reachable (AWS, Microsoft). Google also accepts an uploaded copy of the cluster’s JWKS, which you re-upload when the signing keys rotate (Google). STACKIT documents a per-cluster serviceAccountIssuer URL with a public OIDC discovery endpoint. For the other providers here, ask whether the issuer URL is publicly reachable before you plan on it.

Load balancers, Ingress and certificates

L4 maps cleanly. A Service of type LoadBalancer gets a provider load balancer on STACKIT, OVHcloud, Scaleway, Exoscale and enum. IONOS is the exception: it reserves a static public IP and attaches it to one worker node rather than creating an external load balancer, which matters for failover planning. On enum the load balancer does not preserve the client source IP yet; if your application logs or filters by client IP, plan for that.

L7 is where EKS, AKS and GKE users notice the gap. An Ingress with ALB annotations or a Gateway using gke-l7-global-external-managed has no direct equivalent on the European side today. STACKIT’s ALB Ingress controller is in private preview, available on request and not recommended for production (STACKIT); OVHcloud has announced a native GatewayClass; and Scaleway’s load balancer can terminate TLS through Service annotations. For production, plan on running your own Gateway API or Ingress controller (Envoy Gateway, Traefik, Contour or Cilium) behind the L4 load balancer, with cert-manager and Let’s Encrypt for certificates. Do not start new clusters on the community ingress-nginx controller, which the Kubernetes project retired in March 2026 (Kubernetes blog). Rewrite ALB and GKE-specific annotations and ingressClassName values; they are ignored elsewhere.

Storage: what translates and what does not

Block storage is a StorageClass swap. Every provider above has a CSI driver; on Exoscale you enable it as an add-on. Change storageClassName in your claims, and move data with Velero or application-level dumps, not by copying volumes. enum documents no volume snapshots, so back up volumes with Velero or at the application level.

If you use KMS-encrypted EBS, Azure Disk or Persistent Disk volumes, check volume encryption and customer-managed keys at the target. STACKIT (KMS), OVHcloud (KMS), Scaleway (Key Manager) and Exoscale (KMS, available since July 2026) sell a key management service. enum encrypts volumes at rest on every storage device but has no customer-managed keys or KMS.

File storage (EFS, Azure Files, Filestore) was out of scope for this check. If you depend on ReadWriteMany volumes, ask each provider directly. enum has no file storage.

Object storage is S3-compatible at all six. Code using the AWS SDK usually keeps working after an endpoint and credential change; with SDK releases from 2025 onward you may also need to set checksum calculation to when_required, and on some providers the region or path-style addressing (AWS SDK data integrity settings). GCS and Azure Blob code needs an S3 client. Bucket policies, lifecycle rules and Object Lock support differ by provider, so test the ones you use.

Managed databases

Most teams on EKS, AKS or GKE also run RDS, Cloud SQL or Azure Database, and these often take longer to move than the cluster. STACKIT, OVHcloud, Scaleway, Exoscale and IONOS sell managed PostgreSQL and other engines (sources under the provider table). enum has no managed database, cache or queue. On enum you run PostgreSQL in the cluster with an operator such as CloudNativePG, on NVMe block storage, and you own backups and failover.

Autoscaling and upgrades

If you run Karpenter on EKS or node auto-provisioning on AKS, expect less on most European providers. Exoscale offers a managed Karpenter add-on on its Pro plan. STACKIT, OVHcloud, Scaleway and IONOS have the cluster autoscaler or per-pool autoscaling with fixed node pools. enum has no cluster autoscaling today; you size node pools for your peak. Node types on enum are general purpose x86 (AMD EPYC), plus reserved GPU nodes on request, with no ARM, CPU-optimised or memory-optimised types, so Graviton or spot node pools have no direct equivalent.

On upgrades, the hyperscalers let you pay for long support windows. European providers offer no paid extended support; most follow roughly the upstream window and move clusters off expired versions, each on its own schedule (see the table). Budget for a minor upgrade roughly every few months and test it in staging first.

How to plan the move

  1. Export every annotation, CRD and controller that names a cloud (kubectl get ingress,gateway,httproute,svc,sa,pvc,storageclass,deploy,sts,ds,cronjob -A -o yaml, grepped for aws, alb, ecr, azure, gke, gcr.io, pkg.dev, cloud.google; then list EKS Pod Identity associations and GKE IAM bindings, which live outside the cluster).
  2. Sort each into: works unchanged, swap for a provider equivalent, or run yourself. Include managed databases, DNS automation, Terraform and private connectivity in the list.
  3. Pick the provider on the “run yourself” list you can live with, not on control plane price.
  4. Stand up the new cluster next to the old one, move one non-critical service, and switch DNS last.

FAQ

Can I move from EKS, AKS or GKE without changing application code? Usually yes. Manifests and Helm charts that use upstream APIs run unchanged on conformant Kubernetes. What changes is cloud-specific configuration: annotations, StorageClasses, registry URLs and how pods get credentials. Managed databases and queues are a separate move.

Which European provider has workload identity like IRSA or GKE Workload Identity? Of the providers checked here, STACKIT documents it for SKE. On the others, enum included, plan for scoped access keys delivered through a secrets store.

Is there a European equivalent of the AWS ALB or GKE Gateway? Not as a GA integration with Kubernetes at the providers checked. Run your own Gateway API or Ingress controller behind the provider’s L4 load balancer and use cert-manager for certificates.

Do I need a European container registry? If images should stay in the EU, yes. STACKIT, OVHcloud, Scaleway and IONOS have first-party registries. On Exoscale, use the third-party 8gears registry from its marketplace or run Harbor yourself. On enum, run Harbor yourself or use a registry from another European provider.

Is the control plane free on European providers? On some. IONOS includes it, OVHcloud, Scaleway and Exoscale have free tiers without the paid tier’s SLA, STACKIT charges per cluster, and enum includes a highly available control plane with 99.9% for the Kubernetes API. enum’s SLA credit terms are not published and come with the contract.

Where enum fits

enum Kubernetes Engine runs upstream Kubernetes in Frankfurt with a highly available control plane per cluster included, NVMe block storage, S3-compatible object storage and L4 load balancers on one bill in euros. Know the limits before you plan on it:

  • One region and one zone (fra-a). The control plane is replicated across three failure domains in one site; there are no multi-AZ clusters.
  • No registry, no workload identity, no cluster autoscaling, no managed databases, caches or queues, and no L7 load balancer.
  • No secrets manager and no managed monitoring or logging. Fine-grained IAM roles and cluster audit logs are planned for Q4 2026.
  • No client IP preservation on load balancers yet, no NAT gateway with a stable egress IP yet, and no VPN or private interconnect. VPC is in preview.
  • No Terraform provider or ExternalDNS provider yet; both are planned for Q4 2026. enum DNS is free and has a cert-manager webhook.
  • Clusters are set up with our team rather than self-service until Q4 2026, and the public API is read-only for clusters.
  • General purpose x86 nodes, plus reserved GPU nodes on request. No volume snapshots documented, and no customer-managed keys.
  • Not listed as CNCF Certified Kubernetes. No ISO 27001 or C5 yet, and no published sub-processor list.
  • Included support runs on working days; 24/7 response for critical incidents comes with Enterprise Support.

If those gaps are acceptable for your workloads, see enum Kubernetes Engine, the migration process and the comparisons with AWS and GKE.

Build on enum.
Start today.

Sign up and use object storage and DNS right away, or talk to us about Kubernetes.