Kubernetes on a European cloud usually needs three kinds of storage: block volumes through the provider’s CSI driver for databases and other stateful pods, a file share when several pods must write to the same volume (ReadWriteMany), and S3-compatible object storage for files, media and backups. STACKIT, IONOS, OVHcloud, Scaleway, Exoscale and enum all run block and object storage in the EU, but they differ in performance classes, snapshot support, online resizing and whether a managed file service exists at all. This guide shows when to use which, and compares the six providers on the points that break real deployments.
Provider facts come from each provider’s own documentation, checked on 2026-10-09. enum is one of the six, and we wrote this guide.
Which storage type should a Kubernetes workload use?
| Workload | Storage type | Kubernetes access mode | Why |
|---|---|---|---|
| PostgreSQL, MySQL, Kafka, Redis with persistence, Elasticsearch | Block storage via CSI | ReadWriteOnce (or ReadWriteOncePod) | Low latency, a real filesystem, one writer |
| CMS uploads, shared build caches, legacy apps that write to a shared directory | File storage (NFS) | ReadWriteMany | Several pods on different nodes write to the same path |
| User uploads, media, exports, logs, static assets | S3 object storage | None; the app talks to the S3 API | Scales without resizing, reachable from anywhere, cheap per GB |
| Cluster and volume backups | S3 object storage with Object Lock | None | Off-cluster copy that an attacker with cluster access cannot delete |
Two Kubernetes details decide most designs. ReadWriteOnce means one node can mount the volume read-write, not one pod; pods on the same node can share it. And a claim can only grow if its StorageClass sets allowVolumeExpansion: true. Both are in the Kubernetes documentation on persistent volumes.
If you can change the application, prefer object storage over ReadWriteMany. An app that writes uploads to S3 can run on any number of nodes, in any zone, and moves between providers with a configuration change (endpoint, keys, region) once the data is copied, not a code change. A shared NFS volume ties you to one provider’s file service and its network setup.
What do European providers offer for Kubernetes storage?
Each cell is what the provider documents for its managed Kubernetes product.
| STACKIT SKE | IONOS Managed Kubernetes | OVHcloud MKS | Scaleway Kapsule | Exoscale SKS | enum Kubernetes Engine | |
|---|---|---|---|---|---|---|
| Block storage CSI driver | Cinder CSI, storage classes ready in the cluster | Pre-installed CSI driver | Cinder CSI, installed by default | Installed by default | Add-on, off by default (exoscale-sbs) | CSI driver with dynamic provisioning; enum’s own CSI driver is on the roadmap for Q4 2026 |
| Storage classes and performance | 5 classes: premium-perf0-stackit, premium-perf1-stackit (default), premium-perf2-stackit, premium-perf4-stackit, premium-perf6-stackit | Default class names not documented; block storage moved to Essential, Balanced and Performance classes in September 2026 (HDD, SSD Standard, SSD Premium kept for compatibility) | High Speed (default), High Speed Gen2 (IOPS scale with size), Classic (not on the Standard plan), plus LUKS-encrypted variants in some regions | sbs-5k (5,000 IOPS) and sbs-15k (15,000 IOPS), NVMe | One class, 5,000 IOPS per volume | One class: NVMe, replicated 3 times synchronously inside one Frankfurt site; no IOPS or throughput figures published |
| Volume snapshots (CSI) | Not documented for SKE; snapshots exist at the IaaS level | No setup guide; its FAQ covers Velero CSI snapshot backups | Yes, csi-cinder-snapclass-in-use-v1 | Yes, VolumeSnapshot | Yes, exoscale-snapshot | Not documented |
| Volume resize | Expansion allowed on all classes | Not stated for the pre-installed class | Expand only, after scaling the workload to zero | Online, grow only (per Scaleway’s CSI driver README) | Offline only; detach first, no shrinking | Online (per enum’s Block Storage page) |
| ReadWriteMany / file | STACKIT File Storage (managed NFS, GA since February 2026), EU01 only, NFS CSI driver installed by you | Network File Storage (NFSv4.2, GA), NFS driver installed by you; its Kubernetes FAQ says the integration is on request | Public Cloud File Storage via Manila CSI; also Enterprise File Storage, NAS-HA, Cloud Disk Array | File Storage with its own CSI driver (sfs-standard), GA in Paris since July 2026; needs the scw-filestorage-csi cluster tag and nodes of a qualified instance type (e.g. POP2, BASIC3) | No managed file service; NFS on a volume or an S3 bucket via Mountpoint CSI | No file storage product |
| S3-compatible object storage | Yes, Germany (EU01) and Austria (EU02) | Yes, Frankfurt, Berlin, Logroño | Yes, with versioning and Object Lock | Yes, Paris, Amsterdam, Warsaw, Milan | Yes, Object Storage (SOS) in 8 European zones | Yes, Frankfurt only, with versioning and Object Lock |
| Velero documented | Yes, how-to with the AWS plugin; file-system backup for volumes | FAQ on Velero CSI snapshot timeouts; no setup guide | Yes, with CSI snapshots | Yes, tutorial backs up cluster objects; volume data needs extra setup | No built-in backup or Velero guide; Exoscale’s backup page names Veeam Kasten (SKS is Veeam Ready since Feb 2026) and K8up | No Velero guide; point velero-plugin-for-aws at the enum S3 endpoint with a custom s3Url and test a backup to a locked bucket first |
Checked October 2026. Check each provider’s pricing page for current prices: STACKIT, IONOS, OVHcloud, Scaleway, Exoscale, enum.
What the table means in practice:
- Performance tiers: STACKIT, OVHcloud, Scaleway and IONOS let you pick a class per volume, so a busy database and a log volume can sit on different classes. Exoscale and enum have one class. enum’s is NVMe with throughput and operations included in €0.10 per GB a month, with no per-disk or IOPS fees. Per GB it is not the cheapest: IONOS Balanced SSD lists €0.07 per GB per 30 days (IONOS prices), OVHcloud High Speed about €0.087 per GB a month (OVHcloud prices) and Scaleway’s 5K IOPS class €0.000130 per GB an hour, about €0.095 a month (Scaleway prices).
- ReadWriteMany: STACKIT (EU01 only), IONOS (Kubernetes integration on request), OVHcloud and Scaleway (Paris only) have a managed file service you can mount from Kubernetes. Exoscale and enum do not. On those two, move the shared files to object storage or run RWX storage yourself. A single NFS server pod on a block volume is a single point of failure; Longhorn and Rook CephFS give replicated RWX volumes inside the cluster, which you then operate.
- Snapshots: OVHcloud, Scaleway and Exoscale document CSI VolumeSnapshots. STACKIT SKE and enum do not document them, and IONOS mentions them only in an FAQ on Velero timeouts. Where they are not documented, back up volume contents with Velero’s file-system backup or, for databases, with the database’s own backup tool.
- Resizing: on OVHcloud and Exoscale a resize means downtime for the pod. Plan sizes with headroom there.
How should block storage be set up for databases?
- Pick the class per workload. A primary database with heavy random writes belongs on the fastest class; WAL archives and logs do not. On providers where IOPS scale with volume size (OVHcloud High Speed Gen2), a larger volume is sometimes the cheapest way to get more IOPS.
- Check the attach limits. STACKIT allows 24 volumes per node, OVHcloud 100 per node, Scaleway 16 per instance (boot volume included), Exoscale 5 per instance. enum does not publish a per-node limit. A node pool of small machines running many StatefulSets hits these first.
- Mind the zones. In OVHcloud’s 3-AZ regions a volume is only reachable from nodes in its own zone. A pod with a zonal volume can only be scheduled in that volume’s zone; if the zone fails, the pod stays Pending. Use
WaitForFirstConsumerso volumes are created where the pod is first scheduled, and replicate at the application level. - Replicate the database, not just the disk. Replicated block storage survives a failed disk or host. It does not survive
DROP TABLEor a bad migration. Run a database operator with streaming replicas and point-in-time recovery to object storage (CloudNativePG and pgBackRest both write to S3).
How do you back up Kubernetes to S3 with Object Lock?
Velero is the common tool. It stores cluster resources and volume data in an S3 bucket through velero-plugin-for-aws, which accepts a custom s3Url for non-AWS endpoints. Check the plugin’s provider compatibility table: some endpoints need checksumAlgorithm changed, which can conflict with Object Lock, so test a backup to a locked bucket first. For volumes Velero has two paths:
- CSI snapshot data movement takes a CSI snapshot and copies its data to the bucket. It needs a CSI driver with VolumeSnapshot support (Velero docs).
- File-system backup reads the volume through the node agent with Kopia. It works on most volume types, including NFS (not hostPath), for volumes mounted by a running pod, and is the fallback where snapshots are not documented. Velero notes it is less consistent than snapshots, because files are not read at the same point in time (Velero docs). STACKIT’s own Velero guide uses this path.
Then make the bucket immutable. With Object Lock in Compliance mode, nobody can delete or overwrite a backup until its retention period ends, including someone holding your cluster admin credentials or your S3 keys. We walk through the modes in How to ransomware-proof S3 backups with Object Lock.
Velero has one caveat here, and its own documentation states it: Velero has no explicit support for immutable storage, and since 1.11 backups may not work as expected on it. On AWS S3 Object Lock it works because locking applies to object versions, so Velero can still write new versions of its metadata. Test the same setup on your provider. When Velero deletes an expired backup, the locked old versions stay. Set the retention period slightly longer than your Velero TTL, and add a lifecycle rule that expires noncurrent versions once the lock has passed and removes expired delete markers. Check that your provider supports both rules. Otherwise the bucket grows forever.
Keep at least one backup copy outside the cluster’s site, in another region or with another provider. On enum, the cluster, its volumes and Object Storage all run in one Frankfurt site, so an off-site copy means a second provider. Object Lock protects locked versions, but someone holding your keys can still write new versions and add delete markers (AWS documentation), so restore from locked versions, not from the current listing.
Also enable Object Lock when you create the bucket. Several providers, enum among them, do not allow it on an existing bucket. Our S3-compatible object storage comparison lists which providers support Object Lock, lifecycle rules and retention limits.
Which object storage service is a good choice for companies in Germany?
For a company that wants data in Germany under a European operator, STACKIT (EU01), IONOS (Frankfurt, Berlin), OVHcloud (Frankfurt), Exoscale (Frankfurt, Munich) and enum (Frankfurt) all run S3-compatible object storage in German data centres. The choice turns on the bill shape and certifications:
- Certification required today: STACKIT and Exoscale state BSI C5 on their sites. IONOS holds a C5:2020 Type 1 attestation for 33 services without publishing which, so ask whether object storage is in scope. enum’s ISO 27001 certification is in progress (target Q4 2026) and C5 is on the roadmap for 2027.
- Heavy downloads: egress pricing decides. OVHcloud does not charge for outgoing traffic; IONOS includes an allowance.
- Small and medium buckets next to a cluster: look for no minimums and no request fees. enum bills €0.02 per GB stored and €0.025 per GB out, with no request fees and no minimum.
The full comparison of price models, Object Lock details and regions is in S3-compatible object storage in Europe.
Where enum fits
enum Block Storage is NVMe-backed and replicated: every write lands synchronously on three independent failure domains inside one Frankfurt site before it is acknowledged, and volumes are encrypted at rest on every storage device. According to the Block Storage page, it attaches to enum Kubernetes Engine through a CSI driver with dynamic provisioning and online resizing, at €0.10 per GB a month with no per-operation fees. enum’s own CSI driver is on the roadmap for Q4 2026. Each node includes a 100 GB system disk. enum Object Storage sits on the same platform, erasure-coded across failure domains in Frankfurt and designed for 99.9999999% durability, with versioning, Object Lock, lifecycle expiry rules and presigned URLs.
The limits:
- One production region with one zone (
fra-ain Frankfurt; Berlin on demand). Redundancy is across failure domains inside one site, so off-site backups need a second provider. - One block storage class, and per GB it costs more than the cheaper classes at IONOS, OVHcloud and Scaleway.
- No IOPS or throughput figures published. enum states median 4K latency: under 1 ms for reads, about 1 ms for writes.
- No volume snapshots documented. Back up volumes with Velero file-system backup or database-native backups.
- No managed file storage for ReadWriteMany.
- No customer-managed encryption keys or KMS yet.
- No published block storage SLA: enum targets 99.9%, and SLA terms and credits are available from sales, not published.
- Included support runs on working days; 24/7 response for critical incidents comes with Enterprise Support.
- Clusters are set up on request until self-service cluster creation ships in Q4 2026.
Details are on the Block Storage, Object Storage and Kubernetes Engine pages.
FAQ
Which Kubernetes storage options are hosted in the EU? All six providers in this guide run block storage for Kubernetes and S3-compatible object storage in EU data centres: STACKIT in Germany and Austria, IONOS in Germany (Kubernetes in Frankfurt; object storage also in Spain), OVHcloud, Scaleway and Exoscale in several EU countries, and enum in Frankfurt. Managed file storage for ReadWriteMany is available at STACKIT (EU01), IONOS (on request), OVHcloud and Scaleway (Paris only).
Can I use ReadWriteMany volumes on European managed Kubernetes? Yes, on providers with a file service: STACKIT File Storage, OVHcloud Public Cloud File Storage via Manila CSI, IONOS Network File Storage (Kubernetes integration on request), and Scaleway File Storage in Paris. Keep block volumes for single-writer workloads. On Exoscale and enum, use object storage or run RWX storage such as an NFS server, Longhorn or Rook CephFS yourself.
Does Velero work with European S3 providers? Yes. Velero’s AWS plugin accepts a custom S3 endpoint. STACKIT, OVHcloud and Scaleway publish Velero guides for their Kubernetes products; Scaleway’s covers cluster objects only. If you lock the bucket with Object Lock, plan for locked old versions that outlive deleted backups.
Do I need volume snapshots if I run Velero? Not strictly. File-system backup copies volume contents without snapshots, but it reads files while they change, so a running database may restore inconsistently. For databases, use native backups to S3 (CloudNativePG, pgBackRest) or Velero backup hooks that quiesce the database. Use CSI snapshots where the provider documents them; they give a crash-consistent point in time.
Is block storage on enum replicated? Yes. Every write is replicated synchronously across three independent failure domains in one Frankfurt site before it is acknowledged. That protects against a failed disk or server, not against losing the site, and enum does not document volume snapshots, so keep backups with a second provider.
Sources
Checked on 2026-10-09.
- Kubernetes: Persistent volumes
- Velero: Backup reference, immutability, File system backup, CSI snapshot data movement, Backup hooks, velero-plugin-for-aws
- AWS: S3 Object Lock
- In-cluster RWX: Longhorn RWX volumes, Rook CephFS
- STACKIT: SKE storage, SKE storage classes, File Storage with SKE, release notes, Object Storage, Velero with SKE
- IONOS: Prices, Managed Kubernetes, Managed Kubernetes locations, Managed Kubernetes FAQ, September 2026 release notes, Mount an NFS volume, Network File Storage overview, Network File Storage use cases, Object Storage
- OVHcloud: Prices, Known limits, Persistent volumes, Volume snapshots, Resizing volumes, Public Cloud File Storage, Object Storage, Velero with MKS
- Scaleway: Managing storage in Kapsule, Block Storage FAQ, Kubernetes storage tutorial, CSI driver, File Storage with Kubernetes, File Storage instance types, Storage prices, File Storage, Object Storage, Velero with Kapsule
- Exoscale: Block Storage CSI, Block Storage overview, storage options, Mountpoint for S3 on SKS, Object Storage, Backup
- enum: Block Storage, Object Storage, Kubernetes Engine