A reliable managed Kubernetes provider is one whose SLA covers the parts your application depends on, whose incidents you can see, and whose engineers answer when production is down. The headline number matters less than its scope: most European providers publish an SLA for the Kubernetes control plane API only, and exclude your worker nodes and pods. Read what is measured, what the credits are worth, and who picks up the phone, then compare.
This guide lists the questions to ask and compares the published SLAs of seven European offers, including ours. It is not a complete market list. The tables reflect each provider’s own pages as of the date at the top and are updated in place.
What does a Kubernetes SLA actually cover?
A managed Kubernetes cluster has three layers that fail in different ways:
- The control plane. The Kubernetes API server, etcd, the scheduler and controllers. If it is down, you cannot deploy, scale or change anything, but running pods usually keep serving traffic.
- The worker nodes. The virtual machines your pods run on. If a node fails, the pods on it go with it until Kubernetes reschedules them.
- Storage and networking. Persistent volumes, object storage, load balancers and NAT. A lost volume or a broken load balancer takes an application down even when the control plane and nodes are healthy.
Most European managed Kubernetes SLAs cover layer 1. STACKIT says so directly: its SKE SLA is violated “if the API server for the cluster can’t be externally accessed,” and its service certificate excludes failures of nodes, volumes and pods. Exoscale excludes the same three. Scaleway measures loss of external connectivity to the API servers. OVHcloud states that its MKS SLA applies to the managed control plane. That is a fair way to define a control plane SLA, but it means a 99.95% figure does not promise that your application is up 99.95% of the time.
For your application’s availability you need the SLAs of the other layers too: compute instances, block storage, object storage and load balancers. Ask for each one, then multiply. Three services at 99.9% each give you a combined floor near 99.7% if any one of them can take you down. If a provider publishes no SLA for a layer, as is the case for worker nodes at several providers including enum, you have no number to multiply.
Published SLAs compared
Control plane and cluster SLAs as published by each provider. “No SLA” means the provider says so for that tier. Where a provider does not publish a detail on the pages we checked, the cell says “not stated.”
| Provider | Offer | Published SLA | What is measured | Service credits | Source |
|---|---|---|---|---|---|
| enum | Kubernetes Engine | 99.9% (called an SLA on the product page, a target in the FAQ) | Kubernetes control plane API | Not published; ask for the contract terms | enum.co/kubernetes-engine |
| STACKIT | Kubernetes Engine (SKE) | 99.9% | API server externally reachable; node, volume and pod failures excluded | 10% (below 99.9%), 20% (below 99.0%), 50% (below 98.5%), 100% (below 95.0%) of the affected service’s invoice; claim within two weeks of the invoice | STACKIT SKE basics, SKE service certificate, General Service Description 2.9 |
| IONOS Cloud | Managed Kubernetes | 99.95% monthly | Defined in the IONOS Cloud SLA | 10% (below 99.95%), 25% (below 99%), 100% (below 95%) | IONOS Cloud SLA (IONOS Cloud GmbH) |
| OVHcloud | Managed Kubernetes (MKS) Standard | 99.99% in a 3-AZ region, 99.9% in a 1-AZ region | Managed control plane | Not stated on the product page | ovhcloud.com |
| OVHcloud | MKS Free | 99.5%, labelled an SLO on the plan card and price list (the page FAQ calls it an SLA) | Managed control plane | None stated | ovhcloud.com |
| Exoscale | SKS Pro | 99.95% monthly | Monthly control plane uptime and Kubernetes API request success rate (non-5xx), each 99.95%; nodes, volumes and pods excluded | 50% (99.95% to 98.3%), 100% (below 98.3%) | Exoscale SKS SLA |
| Exoscale | SKS Starter | No SLA | - | - | exoscale.com/sks |
| Scaleway | Kapsule, Dedicated Control Plane | 99.5% monthly | External connectivity to the API servers, outages of 5+ minutes | 10% (99.0-99.49%), 25% (95.0-98.99%), 50% (below 95%); claim within 30 days with logs | scaleway.com SLA |
| Scaleway | Kapsule, mutualized control plane | No SLA | - | - | scaleway.com SLA |
| T Cloud Public (Deutsche Telekom) | Cloud Container Engine (CCE) | No SLA | The service description sets minimum availability only for compute (ECS), object storage (OBS) and volumes (EVS) | - | T Cloud Public service description |
Checked October 2026.
Three things stand out. First, free or entry tiers often have no SLA at all (Exoscale Starter, Scaleway mutualized, OVHcloud Free), and T Cloud Public’s CCE has none on any tier, so check which tier a price comparison is quoting. Second, OVHcloud’s 99.99% depends on a three-zone region, which is the only figure in the table backed by a zone-loss design on the product page. Third, credit schedules differ widely: Exoscale credits 50% from the first breach and 100% below 98.3%, IONOS and STACKIT credit 100% below 95%, and Scaleway caps at 50%.
Object storage is the other layer that often takes applications down. Published availability SLAs:
| Provider | Object storage availability SLA | Source |
|---|---|---|
| enum | 99.9% | enum.co/object-storage |
| STACKIT | 99.9% monthly | STACKIT Object Storage service certificate |
| IONOS Cloud | 99.5% monthly | IONOS Cloud SLA (IONOS Cloud GmbH) |
| OVHcloud | 99.99% in 3-AZ regions, 99.9% in 1-AZ regions | ovhcloud.com object storage |
| Exoscale | 99.95% | exoscale.com/sla |
| Scaleway | 99.9% Multi-AZ, 99.0% One Zone-IA and Glacier | scaleway.com Object Storage SLA |
Checked October 2026.
Durability is a separate figure. enum publishes 99.9999999% (nine nines) as a design figure, not as part of an SLA. STACKIT puts 99.999999999% (eleven nines) in its service certificate, and OVHcloud states eleven nines for its multi-zone storage, so both publish a higher durability figure than we do. OVHcloud’s three-zone availability is also higher than ours.
What are service credits worth?
Usually less than the outage costs you. Where credit terms are published, they are credits against the affected service’s monthly bill, not cash. Check whether credits are your only remedy: STACKIT’s service description keeps damages claims open and offsets any credit against them. If your control plane costs a fraction of your cluster bill, a 10% credit on that fraction is small. Read three details:
- The base. Is the credit a share of the control plane fee, the whole cluster, or the account?
- The claim process. Scaleway, for example, asks you to claim within 30 days and send log files. If you do not monitor the API yourself, you cannot prove the outage.
- The measurement interval. An SLA that ignores outages shorter than five minutes will not count a string of three-minute drops.
Treat credits as a signal of how seriously a provider prices its own failure, not as insurance.
If you are a financial entity under DORA, Article 30 deals with service levels in ICT contracts, so ask your provider whether its figures are part of the written contract or only a product page.
This guide is general information, not legal advice. Have your counsel assess your specific situation.
Can you see the incident history?
A public status page with an archive of past incidents tells you more than any SLA. Look for:
- Incidents per component (Kubernetes, object storage, network), not one green dot for the whole company.
- Start time, end time and a written root cause after major incidents.
- Maintenance announced in advance, with the affected region.
IONOS Cloud, for example, publishes its incidents and maintenance on status.ionos.cloud, so you can count Kubernetes incidents over the last year before you sign. Ask any provider without a public history for their incident log for your target region over the last 12 months.
Who answers when production is down?
This is where reliability is felt. When production breaks at night, what matters is whether anyone is contractually on call, and the answer you want before you sign is in writing:
- Response time by severity. “We respond quickly” is not a term. A response time in minutes or hours for a production-down incident, and the hours it applies (business hours or 24/7), is.
- Who responds. A first-line agent who forwards a ticket, or an engineer who can read your cluster’s logs and change the platform.
- What is in scope. Most providers fix their platform, not your in-cluster problems. Know where the line is before the incident, not during it.
- What it costs. Free support often has no guaranteed response time, and 24/7 coverage with a response target is often a paid tier.
Read the actual agreement rather than assume. IONOS Cloud’s support agreement, for example, provides 24/7 support with a response under one hour for malfunctions, though its support staff may not log in to or change your resources.
How are upgrades and maintenance handled?
Kubernetes releases a minor version roughly every four months, and each is supported upstream for about 14 months. A provider’s upgrade policy decides how often your cluster restarts nodes and how much notice you get. Ask:
- Which minor versions are supported, and what happens when yours reaches end of life? IONOS, for example, sends a notification two weeks before a forced update and limits node pool maintenance to a four-hour window.
- Are nodes upgraded one at a time, so replicated workloads keep serving?
- How much notice comes before planned maintenance, and can you choose the window?
A forced upgrade that breaks a deprecated API is an outage you could have planned for. Run your manifests against the next version before the provider’s deadline.
Single zone or multiple zones?
An HA control plane replicated inside one data centre survives a server failure. It does not survive the loss of that data centre. A control plane spread across three availability zones does, which is why OVHcloud’s three-zone SLA is higher than its single-zone one. OVHcloud’s three-zone regions in Europe are Paris and Milan, and persistent volumes in a three-zone cluster stay in the zone they were created in.
Ask each provider where the control plane replicas run (same rack, same building, different buildings) and whether your node pools can span zones. Then decide what you need: many SaaS teams run well in one zone with backups in a second region, while others are contractually bound to survive a site failure.
Where enum fits
We are one of the options above, so here are our terms and limits as published.
enum Kubernetes Engine has a 99.9% SLA for the Kubernetes control plane API. Object storage, block storage, load balancers and NAT carry the same 99.9% SLA. We have not published the service credit schedule, an SLA for worker nodes or a maintenance notice period, so by this guide’s own test, ask us for the contract terms before you rely on the figure. The HA control plane is included in the price. We support the three most recent Kubernetes minor releases, apply patch releases for you, and run minor upgrades node by node. Status and incident history are public at enumstatus.com, hosted outside enum’s own infrastructure so it stays up when enum does not.
Every account includes support on working days at no extra cost, without a guaranteed response time. Enterprise Support, priced on request, adds a named engineer, 24/7 handling of critical incidents with response times down to 15 minutes, and regular architecture reviews. The exact times go into the contract.
On the limits: production runs in one region, Frankfurt, in one availability zone (fra-a) in a Tier III+ facility. The control plane replicas run in separate failure domains inside that facility. They survive a server failure, not the loss of the facility, and a site outage takes down the control plane, nodes, volumes and object storage together. Berlin is listed as a second region on request, but it is not a running failover target today, and nothing replicates across regions. We have no volume snapshots or backup service, so keep off-site backups with another provider. Our ISO 27001 certification is in progress with a Q4 2026 target, and BSI C5 is on the roadmap for 2027. The facility’s ISO 27001 is the operator’s, not ours. Clusters are set up on request today, and self-service cluster creation follows in Q4 2026. enum was founded in November 2024, so our public incident history is short and every other provider in the table has a longer track record. Several run more regions, and OVHcloud runs three-zone regions.
What our customers report: scanmetrix reports 99.95% availability since migrating, after 97% at its previous provider, and meinMPP’s incident response went from up to 12 hours to under 15 minutes after enum took over operations and on-call (DevOps as a Service). If reliability is what you are shopping for, the Kubernetes Engine page has the published figures (ask us for the contract terms) and Enterprise Support the response times.
FAQ
What is a good SLA for managed Kubernetes in Europe? For a production control plane, 99.9% to 99.95% is the common range among European providers, with Scaleway’s dedicated control plane at 99.5% and OVHcloud at 99.99% in three-zone regions. More important than the number is that it is a contractual SLA, not an SLO, and that you know which layer it measures.
Does a control plane SLA mean my application is covered? No. Control plane SLAs measure the Kubernetes API. STACKIT and Exoscale, for example, exclude node, volume and pod failures explicitly. Your application also depends on compute, storage and load balancer SLAs.
Do free Kubernetes tiers have an SLA? Usually not. Exoscale SKS Starter and Scaleway’s mutualized control plane have no SLA, and OVHcloud MKS Free lists 99.5% as an SLO on its plan card. T Cloud Public’s CCE has no SLA on any tier.
How do I compare support between cloud providers? Ask for the response time for a production-down incident in writing, the hours it applies, whether an engineer responds, and what it costs. Many free support tiers guarantee no response time, but some do: IONOS Cloud’s support agreement sets under one hour for malfunctions, 24/7.
Is a multi-zone control plane necessary? Only if you must survive the loss of a whole data centre without manual failover. Many SaaS teams run in one zone with off-site backups; regulated or contractually bound workloads may need three zones. enum runs in one zone today.
Sources
Checked 2026-10-09: enum Kubernetes Engine, enum Object Storage, enum Networking, enum Enterprise Support, STACKIT SKE basics, STACKIT SKE service certificate, STACKIT General Service Description, STACKIT Object Storage service certificate, IONOS Cloud SLA, IONOS Cloud support agreement, IONOS Managed Kubernetes FAQ, OVHcloud Managed Kubernetes, OVHcloud MKS regions, OVHcloud MKS known limits, OVHcloud Object Storage, Exoscale SLA, Exoscale SKS SLA, Exoscale SKS, Scaleway Kapsule Dedicated Control Plane SLA, Scaleway Object Storage SLA, T Cloud Public service description, DORA (Regulation (EU) 2022/2554).