---
canonical: https://enum.co/kubernetes-engine
locale: en
---

**Flagship Product**

# enum Kubernetes Engine.

Sovereign Managed Kubernetes for teams that need hyperscaler-grade engineering without US jurisdiction. Self-service, HA control plane included, production-ready in minutes.

enum Kubernetes Engine (EKE) is a self-service Kubernetes platform operated entirely in Germany under EU law. It runs upstream, unmodified Kubernetes with an isolated, highly available control plane per cluster included at no extra charge, private-by-default clusters, and full GDPR data sovereignty from a German GmbH.


### Why enum Kubernetes Engine?

Hyperscaler-grade Kubernetes, operated in Germany under EU law

- **HA Control Plane Included**: Every cluster gets an isolated, highly available control plane across independent failure domains, with automatic failover and zero-downtime upgrades. No per-cluster-hour charge.
- **Upstream Kubernetes, No Fork**: Standard upstream Kubernetes with best-practice tooling. Existing manifests, Helm charts, and GitOps pipelines port over unchanged.
- **Self-Service via API and CLI**: Provision clusters through enumctl, the REST API, or Terraform. Sensible defaults, no infrastructure assembly. First cluster in minutes, not days.
- **European Sovereignty by Design**: German GmbH, German data centers in Frankfurt, German and EU law only. No US parent, no US subprocessors, no transatlantic data flows.

### Ideal for

- Regulated workloads under GDPR, NIS2, or DORA
- SaaS and FinTech platforms needing EU-only data flows
- Microservices architectures requiring high availability
- CI/CD pipelines with GitOps workflows
- Teams migrating from AWS EKS, Google GKE, or Azure AKS

### Frequently Asked Questions


**What is a GDPR-compliant Managed Kubernetes solution from Germany?**
A GDPR-compliant Managed Kubernetes solution from Germany is a Kubernetes platform operated by a German company in German data centers under German and EU law only, with no US parent and no US subprocessors. enum Kubernetes Engine runs in Frankfurt, includes an HA control plane per cluster, and is operated by enum GmbH under exclusive German jurisdiction with no CLOUD Act exposure.

**Is enum Kubernetes Engine NIS2 and DORA ready?**
Yes. enum is a German GmbH operating in a German Tier III+ data center under German and EU law, with no US subprocessors and no transatlantic data flows. That structure aligns with NIS2 supply-chain requirements and DORA ICT third-party risk rules. NIS2 and DORA readiness is a structural property of where the company and data sit, not a separate certification.

**How does enum Kubernetes Engine differ from AWS EKS and Google GKE?**
enum includes a highly available control plane per cluster at no per-cluster-hour charge, provisions clusters private by default with host-based NAT, and bills load balancing at flat fees. AWS EKS and Google GKE bill the control plane per cluster-hour and leave NAT, private networking, and load balancing as separate paid components. All three run upstream Kubernetes, so manifests and Helm charts port over.

**Is enum subject to the US CLOUD Act?**
No. enum GmbH is a German company with no US entity in its corporate structure, so it is not subject to the US CLOUD Act or FISA Section 702. Selecting an EU region at a US-headquartered provider does not remove that exposure, because the corporate jurisdiction of the company holding the data is what counts.

**What does Managed Kubernetes cost at enum?**
Compute is billed per hour with optional one to three year commitment discounts. Block storage is billed per GB per month. The HA control plane is included at no extra charge, host-based NAT is included, and load balancing is a flat monthly fee with an IPv4 address included. All prices are in euros and exclude VAT.

**How fast is a cluster provisioned, and how does provisioning work?**
A cluster is ready in minutes through self-service. You provision it via the enumctl CLI, the REST API, or Terraform, with sensible defaults so no manual infrastructure assembly is needed. Clusters are private by default and run upstream Kubernetes, so existing manifests and GitOps pipelines work without changes.

**In which regions does enum operate Kubernetes?**
enum operates its primary Kubernetes region in Frankfurt, Germany, in a Tier III+ data center, with further European regions on the roadmap. All regions run on enum's own infrastructure and own network (AS215998), inside the European Union.

**Can I migrate from AWS EKS or GKE to enum?**
Yes. enum runs upstream, unmodified Kubernetes, so standard manifests, Helm charts, and GitOps workflows port over without code changes. enum object storage is S3-API compatible, so rclone, aws-cli, and the AWS SDKs work as-is. Migration support is available if you need help with the cutover.

### enum vs. AWS EKS

What is included versus what costs extra.

| Feature | enum | AWS EKS |
|---|---|---|
| HA Control Plane | Included per cluster, no per-cluster-hour charge | Billed per cluster-hour, managed control plane provisioned per cluster |
| Outbound NAT | Host-based NAT included | NAT Gateway billed per hour per AZ plus per-GB data processing |
| Load Balancer | Flat monthly price, includes IPv4 | Per hour plus LCU charges plus per-GB processing |
| Private Cluster | Default, no configuration needed | Manual setup of subnets, NAT, VPC endpoints |
| NVMe Storage | 100 GB included per node | EBS volumes billed separately |
| Data Sovereignty | German GmbH, German data centers, GDPR-native | US company subject to US CLOUD Act |

enum includes the highly available control plane per cluster at no per-cluster-hour charge, provisions clusters private by default with host-based NAT, and bills load balancing at a flat monthly fee with an IPv4 address included. AWS EKS provisions a managed control plane per cluster billed per cluster-hour, and leaves private networking, NAT gateways, and VPC endpoints as separate line items you assemble and pay for individually.


### Sovereignty, by construction

Hyperscaler-grade engineering does not require US jurisdiction.

- **German GmbH, German law**: enum is operated by enum GmbH, registered in Cologne (HRB 121362), under German and European law only. No US parent company, no US subprocessors.
- **Data in Frankfurt, no US flows**: All infrastructure runs in a Tier III+ data center in Frankfurt, Germany. No transatlantic data flows, no Schrems II exposure.
- **No US CLOUD Act**: Because enum has no US entity, it is not subject to the US CLOUD Act or FISA Section 702. Selecting an EU region at a US provider does not change the jurisdiction of the company holding the data.
- **NIS2 and DORA ready**: German company, German data centers, German contracts. Structurally aligned with NIS2 and DORA requirements for regulated workloads.

enum operates its own Autonomous System (AS215998, registered with RIPE NCC) with its own IP address ranges and direct peering at European Internet Exchanges. The company is a CNCF Silver Member and a Linux Foundation member. Control over the network, the corporate jurisdiction, and the physical data location all sit inside the European Union.


### Technical Specifications

Enterprise-grade Kubernetes built for production workloads

- **Availability SLA**: 99.9% (Guaranteed uptime)
- **HA Control Plane**: Included (Per cluster, no per-cluster-hour charge)
- **Data Location**: Frankfurt (German Tier III+ data center)
- **Kubernetes**: Upstream (No fork, always current. Best practice tooling included)
- **Networking**: eBPF (Kernel-level, fast, observable)
- **Node OS**: Immutable (Minimal attack surface)
- **Block Storage**: NVMe (Fast, redundant, persistent. 100 GB included per node)
- **Latest Gen CPUs**: AMD EPYC (High-performance compute)
- **Rolling Upgrades**: Zero-downtime (Automatic, no interruption)
