If your team has fewer than two people who can own Kubernetes at 3 a.m., running your own control plane is usually the most expensive option, even when the servers are the cheapest. A managed control plane removes etcd, running the API servers and carrying out control plane upgrades from your list, either at no charge or for a fee billed per cluster-hour, depending on the provider. What it does not remove is everything above the control plane: add-ons, workloads, monitoring and on-call. If nobody on your team wants that pager, the third option is to have someone run production for you, which costs more per month than a standard control plane fee and less than a second hire.
This guide compares the three models task by task, then puts rough numbers on the engineering time. Provider details are as of the date at the top and are updated in place.
The three models
1. Self-run Kubernetes. You rent VMs or bare metal (Hetzner is a frequent choice in Europe) and install Kubernetes yourself with kubeadm, k3s, RKE2 or Talos. Hetzner does not sell a managed Kubernetes product; it maintains an official cloud controller manager and CSI driver so a cluster you build can use Hetzner load balancers and volumes. You own every layer.
2. Managed control plane. The provider runs the Kubernetes API servers, etcd, and the scheduler and controller manager. You get a kubeconfig and worker nodes. This is what EKS, GKE, AKS, IONOS Managed Kubernetes, OVHcloud Managed Kubernetes, Scaleway Kapsule, Exoscale SKS, STACKIT SKE, T Cloud Public CCE and enum Kubernetes Engine sell. What “managed” covers beyond the control plane differs between providers, mostly in who starts version upgrades and how nodes are upgraded.
3. Someone runs production for you. A team outside your company operates the platform: cluster upgrades, monitoring, alerting, on-call, backups, CI/CD. You keep the application code. German providers usually sell this as managed services or a management level on top of the cluster; enum calls it DevOps as a Service. It sits on top of model 1 or 2; somebody still has to provide the cluster.
Who does what
The table below is the core of the decision. “You” means your own engineers.
| Task | Self-run | Managed control plane | Run for you |
|---|---|---|---|
| Control plane availability (API server, etcd quorum) | You | Provider, often with an SLA | Provider |
| etcd backups for control plane recovery | You | Provider (at some providers only on paid tiers) | Provider |
| Restoring your own cluster objects (deleted namespaces, bad deploys) | You | You (Velero or GitOps) | Operations team |
| Control plane version upgrades | You | Provider carries them out; at most providers you decide when a minor upgrade runs | Provider |
| Testing workloads and add-ons against new Kubernetes versions and removed APIs | You | You | Operations team |
| Worker node OS patches and node upgrades | You | Varies: automatic on some, a button or API call you trigger on others | Operations team |
| CVE patching for add-ons (CNI, ingress, cert-manager, CSI) | You | Mostly you; the provider covers what it installs | Operations team |
| Monitoring and alerting for your workloads | You | You | Operations team |
| 24/7 on-call | You | You, for everything above the control plane | Operations team, hours per contract |
| Capacity planning and node pool sizing | You | You (autoscaling helps where the provider offers it, sizing is still a decision) | Operations team, with you |
| Application backups (databases, persistent volumes) | You | You | Operations team, with restore tests |
| Application code, releases, product decisions | You | You | You |
Two things stand out. First, a managed control plane takes over the parts that are hardest to recover when they break (a lost etcd quorum is a bad week), but it leaves most of the day-to-day work with you. A provider’s etcd backup protects its control plane; it does not bring back a namespace you deleted. Second, the “run for you” column only moves work if the contract names it. Read the scope, not the headline.
Kubernetes ships about three minor releases a year, each with about 14 months of patch support. So about three times a year someone has to check manifests, Helm charts and add-ons for removed APIs before the upgrade. At EKS, OVHcloud, Scaleway and Exoscale you also start the minor upgrade yourself. Scaleway upgrades the cluster within 30 days after end of support (version policy). EKS forces an upgrade only when extended support ends (EKS versions). OVHcloud keeps the two most recent unsupported versions running without support and forces an upgrade, with 30 days’ notice, only after that (OVHcloud policy). Exoscale documents no forced upgrade (SKS lifecycle). Falling behind costs money: EKS charges $0.60 instead of $0.10 per cluster-hour for versions in extended support (EKS pricing), GKE adds $0.50 per cluster-hour in the extended period (GKE pricing), and AKS long-term support needs the Premium tier (AKS tiers).
What the control plane costs at common providers
How each provider charges for the control plane, from its own pricing page, and the control plane SLA it publishes, from its SLA or product documentation, both checked on 2026-10-09. Compute (worker nodes, or Pod resources on GKE Autopilot), storage and traffic are billed separately from the control plane at every provider listed here.
| Provider | Control plane fee model | Control plane SLA |
|---|---|---|
| Hetzner | No managed Kubernetes; you run the control plane on your own VMs | None (self-run) |
| IONOS Managed Kubernetes | Free | 99.95% for the Kubernetes API |
| OVHcloud Managed Kubernetes, Free plan | Free | 99.5% SLO |
| OVHcloud Managed Kubernetes, Standard plan | Per cluster-hour | 99.99% in 3-AZ regions, 99.9% in 1-AZ regions |
| Scaleway Kapsule, mutualized | Free | None |
| Scaleway Kapsule, Dedicated | Per hour, priced by control plane size, 30-day minimum commitment | 99.5% |
| Exoscale SKS, Starter | Free | None |
| Exoscale SKS, Pro | Per cluster-hour | 99.95% |
| STACKIT SKE | Per cluster-hour | 99.9% for the API server |
| T Cloud Public CCE | Smallest non-HA cluster free; HA and larger clusters per hour | None for CCE (service description 4.2 covers only ECS, OBS and EVS) |
| AWS EKS | Per cluster-hour, higher rate on extended version support | 99.95% for the API endpoint, 99.99% with Provisioned Control Plane |
| Google GKE | Per cluster-hour; a monthly free tier credit covers one zonal or Autopilot cluster | 99.95% regional and Autopilot in most regions (99.9% in Stockholm and Mexico), 99.5% zonal |
| Microsoft AKS, Free tier | Free | None (no financially backed SLA) |
| Microsoft AKS, Standard and Premium tiers | Per cluster-hour (Premium adds long-term support) | 99.95% with availability zones, 99.9% without |
| enum Kubernetes Engine | Included, highly available control plane per cluster | 99.9% for the control plane API; contract terms and credits not published |
Checked October 2026.
Pricing pages: Hetzner, IONOS, OVHcloud, Scaleway, Exoscale, STACKIT SKE, T Cloud Public service description, AWS EKS, Google GKE, Microsoft AKS, enum. SLA sources: IONOS SLA, OVHcloud Managed Kubernetes, Scaleway SLA, Exoscale SKS SLA, STACKIT SKE, AWS EKS SLA, GKE SLA, AKS tiers, enum Kubernetes Engine.
A few honest notes on this table. IONOS, OVHcloud (Standard plan), Exoscale (Pro), AWS EKS, GKE (regional and Autopilot) and AKS (Standard with availability zones) all publish a higher control plane SLA than enum’s 99.9%, and AWS, Google and OVHcloud run far more regions and zones. enum runs production in a single zone in Frankfurt (fra-a), with the control plane spread across three failure domains on that site; there are no multi-zone or regional clusters, and a Berlin region is available on request only. enum’s 99.9% covers the control plane API, not worker nodes, and its credit terms are in the contract, not published. Free tiers without an SLA (Scaleway mutualized, Exoscale Starter, AKS Free) are fine for testing; Exoscale itself positions Starter for testing and Pro for workloads where SLAs matter. Where a control plane fee applies, compare a month of it with one engineer-day, about €340 at the €7,500 a month assumed below.
A rough cost model
On the same hardware, compute costs about the same in all three models, because your workloads need the same CPU and memory. The provider you pick changes the compute bill more than the operating model does, so the model below leaves compute out and compares only fees and engineering time. Node prices differ a lot between providers: enum’s per-node prices (pricing) are higher than Hetzner’s cloud servers (Hetzner Cloud), and enum offers general-purpose x86 node types only (no CPU- or memory-optimised shapes), with GPU nodes on request.
Assumptions (change them and the result moves):
- One production cluster, around ten worker nodes, a typical SaaS stack (ingress, cert-manager, a database operator or managed database, Prometheus-style monitoring).
- A platform engineer costs €90,000 a year all-in (salary, employer contributions, equipment), so €7,500 a month. For reference, Indeed Germany lists an average DevOps engineer salary of €68,988 gross, from about 1,200 reported salaries (as of 4 October 2026). Senior engineers who can own production cost more: gehalt.de puts DevOps engineers with nine or more years at €86,425 gross, which comes to roughly €100,000 to €115,000 all-in.
- Hiring adds a recruiting fee (enum’s DevOps as a Service page assumes €15,000 per hire) and on-call allowances. Rest-period rules (§ 5 ArbZG) mean a night call-out usually pushes back the next working day.
- Self-run takes one engineer six to eight weeks to build to a production standard, then 0.5 to 1 FTE to keep current.
- A managed control plane cuts the build to one or two weeks (node pools, add-ons, monitoring) and the ongoing share to 0.25 to 0.5 FTE.
- When someone runs production for you, your side shrinks to coordination, around 0.1 FTE.
| Self-run | Managed control plane | Run for you (enum, as an example) | |
|---|---|---|---|
| One-time build | about €10,400 to €13,800 | about €1,700 to €3,500 | Onboarding as quoted, including the move to enum |
| Control plane fee per month | €0 (plus three small VMs) | €0, or your provider’s per cluster-hour fee | Included in the platform |
| Engineering time per month | €3,750 to €7,500 | €1,875 to €3,750 | About €750 |
| Operations fee per month | none | none | From €2,500, excl. VAT |
| Total per month, ongoing | €3,750 to €7,500 | €1,875 to €3,750, plus any control plane fee | From about €3,250, plus platform usage |
| 24/7 on-call | No, unless you staff a rotation | No, unless you staff a rotation | Available; on-call hours are set in the contract and affect the price |
The build figures use 52 weeks a year, so one engineer-week costs about €1,730. enum’s DevOps as a Service runs platforms on enum: if you are on another provider today, moving to enum Kubernetes Engine in Frankfurt is part of the onboarding, and platform usage is billed separately from the €2,500. Operations offers vary widely in scope and price, from cluster-level monitoring bundled with hosting to full workload operations with CI/CD. Compare scope line by line, not the headline price.
The last row is what the totals hide. Half an engineer is not an on-call rotation. One person carrying the pager every night burns out or leaves, and a rotation that lets people sleep needs several engineers who know the cluster. Once you price that in, the self-run column roughly doubles. That is why the comparison usually turns on “do we need 24/7?” rather than on the fee.
Read the model the other way round too. If you already have two or three platform engineers who like this work, self-run on cheap hardware can be the lowest total cost, and you keep full control of every component. Compare the control plane fee with the cost of a migration before you move for the fee alone.
Hire a DevOps engineer or hand over operations?
Hiring makes sense when:
- Kubernetes is part of what you sell, or your platform is unusual enough that outside operators would spend most of their time learning it.
- You need someone in the building for architecture decisions every week, not a monthly review.
- You can hire two or more people, so the knowledge does not leave with one resignation.
Handing over operations makes sense when:
- Your engineers are product engineers and every hour on ingress controllers is an hour not shipped.
- You need documented operations (changes, access, incidents) for customer audits or NIS2 and DORA questionnaires, and nobody owns that today.
- You want a response time written into a contract, not a best-effort promise from the one person who knows the setup.
Handing over operations does not hand over accountability for your platform. If NIS2 or DORA applies to you, ask your counsel how an outside operator fits into your ICT supply-chain obligations, and whether you need a data processing agreement under GDPR Art. 28.
Many teams land in between: a managed control plane, one engineer who owns the platform, and an outside team for nights and weekends. Check that the outside team can work in your repositories and that you keep full access, so the arrangement is easy to undo.
This guide is general information, not legal advice. Have your counsel assess your specific situation.
Where enum fits
enum Kubernetes Engine is the managed control plane model: upstream Kubernetes, a highly available control plane per cluster at no extra charge, patch releases applied by enum and minor upgrades run node by node, with nodes billed by the hour in euros. Clusters are available on request today; self-service cluster creation is planned for Q4 2026.
Its limits, plainly:
- One region and one zone in production (Frankfurt, fra-a). No multi-zone or regional clusters.
- No cluster or node autoscaling. You size node pools for your peak.
- General-purpose x86 node types only (gp-1 to gp-32); no CPU- or memory-optimised or ARM nodes. Reserved GPU nodes are available on request.
- No volume snapshots, backup service or managed databases. Back up persistent volumes and databases yourself (for example with Velero), or have DevOps as a Service run backups and restore tests.
- The 99.9% covers the control plane API, not worker nodes. Credit terms are in the contract, not published.
- Included support covers working days. 24/7 for critical incidents comes with Enterprise Support (price on request) or with DevOps as a Service, with on-call hours set per contract.
- Fine-grained IAM roles, a customer audit log for clusters and a Terraform provider are planned for Q4 2026.
- enum holds no ISO 27001 yet (target Q4 2026) and no BSI C5 (planned for 2027). The Frankfurt data centre’s ISO 27001 and EN 50600 certifications belong to the facility operator.
If you want enum’s engineers to run the platform as well (upgrades, monitoring, CI/CD, security updates, incident response), DevOps as a Service starts at €2,500 a month excluding VAT, with platform usage billed separately and response times down to 15 minutes depending on the service level. It runs platforms on enum, so the migration is part of the onboarding. Details are on the Kubernetes Engine page and the pricing page.
FAQ
Is managed Kubernetes cheaper than running it yourself? The control plane is free or billed per cluster-hour at the providers above. Whether the total is cheaper depends mostly on engineering time and on compute prices, which differ more between providers than between operating models. If a managed control plane saves a quarter of an engineer, that is about €1,875 a month on the assumptions above; compare it with the fee. If you already have a staffed platform team, the saving is smaller.
What does “managed” actually include? At every provider listed here: running the API servers and etcd, and carrying out control plane upgrades. At most of them (EKS, OVHcloud, Scaleway, Exoscale) you decide when a minor upgrade runs. Providers that force an upgrade do so only after support ends, some well after, and Exoscale documents no forced upgrade. Node upgrades, add-ons and monitoring vary by provider. Your workloads, their backups and on-call for them stay with you unless you buy operations on top.
Do I still need a DevOps engineer with managed Kubernetes? For a single small cluster, often not full-time, but someone has to own deployments, monitoring, version upgrades and incidents. Either that is an engineer on your team or it is an outside operations team under contract.
How many engineers does 24/7 on-call take? More than one. Google’s SRE guidance puts the minimum for a single-site rotation at eight engineers. That cost is the biggest gap between self-run and handing operations over.
Can we move from self-run to managed later? Yes, if you stay on upstream Kubernetes. Manifests, Helm charts and GitOps pipelines move between conformant clusters. The work is in storage and data, load balancer and ingress annotations, how pods get cloud credentials, container registries and the DNS cutover. See how migration works.