Skip to main content
Kubernetes

Managed Kubernetes Switzerland

We run Kubernetes for you as a platform, so you do not have to operate a cluster yourself. The base is the same everywhere: on Natron Cloud, on your hardware, on Azure (AKS) and Google Cloud (GKE), or on your own hypervisor. It consists of upstream Kubernetes, Cilium with WireGuard encryption, and Ceph or your cloud's storage. We align governance, multi-tenancy and integrations with your organisation.

Upstream KubernetesCiliumArgo CDVeleroF5 NGINXRook Ceph
Your Pods
web
2c · 4Gi
api
1c · 2Gi
worker
0.5c · 1Gi
Managed by Natron
Control Plane
API Server
etcd
Scheduler
Controller Manager
Networking & Ingress
Ingress Controller
ClusterIP Services
LoadBalancer
Network Policies
Worker Nodes & Monitoring
cpu58%
mem69%
platform services
cert-managerIngress ControllerMonitoring StackCilium CNIVelero Backups
External SecretsArgoCDKyverno
Custom IntegrationsMultitenancy
Persistent Storage
PersistentVolumeClaim
StorageClass
Rook Ceph RBD
NFS RWX
ceph · nvme · 3x replicated

Choose Your Kubernetes Tier

Each tier builds on the previous one and adds more managed components.

Basic

Base Features
Cluster Management & Updates
CNI (Cilium OSS)
Platform Observability Stack
Grafana OSS, Prometheus, Alertmanager, Loki
Ingress Controller & Cert-Manager
Velero Backups
Premium Features
External Secrets Operator
ArgoCD
Kyverno
Enterprise: Non-Standard & Customer-Specific
Non-Standard Observability Integration
Non-Standard Networking Integration
Non-Standard Storage Integration
Non-Standard Backup Integration

Premium

Base Features
Cluster Management & Updates
CNI (Cilium OSS)
Platform Observability Stack
Grafana OSS, Prometheus, Alertmanager, Loki
Ingress Controller & Cert-Manager
Velero Backups
Premium Features
External Secrets Operator
ArgoCD
Kyverno
Enterprise: Non-Standard & Customer-Specific
Non-Standard Observability Integration
Non-Standard Networking Integration
Non-Standard Storage Integration
Non-Standard Backup Integration

Enterprise

Base Features
Cluster Management & Updates
CNI (Cilium OSS)
Platform Observability Stack
Grafana OSS, Prometheus, Alertmanager, Loki
Ingress Controller & Cert-Manager
Velero Backups
Premium Features
External Secrets Operator
ArgoCD
Kyverno
Enterprise: Non-Standard & Customer-Specific
Non-Standard Observability Integration
Non-Standard Networking Integration
Non-Standard Storage Integration
Non-Standard Backup Integration

Flexible Pricing

You pay by consumption, so the bill follows your usage. Get in touch for a quote.

More Than a Cluster

We design multi-tenant platforms on top of your managed Kubernetes. We build each solution design for the teams and requirements of your organisation.

Multitenancy & Isolation

We design your platform for multiple teams, with namespace isolation, resource quotas, network policies and role-based access control.

Governance & Compliance

We build policy enforcement, audit logging and regulatory requirements into your platform.

Custom Integrations

When standard integrations aren't enough, we build custom observability pipelines, specific storage backends, non-standard network topologies or backup strategies into your platform.

A customer on their migration

oliver_oswald
Before partnering with Natron, we managed our Kubernetes clusters in-house. Migrating to Natron’s comprehensive Kubernetes stack has enabled us to manage our applications more effectively, consolidate container deployments on a centralized, automated platform, and use our internal resources more strategically.
Oliver Oswald

Oliver Oswald

CTO, Apps with love

Frequently asked questions

What does "managed" include?

Every cluster ships with the same base: Cilium, cert-manager, the Prometheus and Grafana stack, Loki and Velero. On top of that we do patching, Kubernetes upgrades, backups, monitoring and on-call, and you talk to the engineers who run it.

Do you manage only the control plane or the whole stack?

The whole stack. Hyperscaler offerings stop at the control plane; ingress, certificates, observability, backup, policies and GitOps are still your work. We run all of it and add the add-ons of your tier, such as Argo CD, External Secrets and Kyverno.

Where can the cluster run?

On Natron Cloud (our default), on your hardware as Natron Flex Stack, on Azure (AKS), on Google Cloud (GKE), or on your own hypervisor on-premise. The base is identical; storage and load balancing adapt to the target.

Which SLA applies?

Availability of 99.5 percent on Standard and 99.9 percent on Enterprise with high availability. Support from best effort to a 4-hour response at 5x13, 7x24 on request. Details are on the service levels page.

How do upgrades work?

Dependency updates go through Renovate with a seven-day minimum age and manual approval, then dev, staging and production in that order. Node upgrades run one node at a time with drain and health checks. You see every change in Git.

Which add-ons are included?

Basic: cluster management, Cilium, observability stack, ingress with cert-manager and Velero. Premium adds External Secrets, Argo CD and Kyverno. Enterprise adds non-standard observability, networking, storage and backup integrations.

How does multi-tenancy work?

Namespaces per team with resource quotas, network policies enforced by Cilium, Kyverno policies as guard rails in the Premium and Enterprise tiers, RBAC mapped to your identity provider, and an Argo CD instance per cluster for deployments. The tenancy toolkit page shows the design.

Can we migrate existing clusters?

Yes. We take over self-managed clusters or consolidate several into one platform. Workloads move via GitOps, data via Velero or database-native tools, and both environments run in parallel until you sign off.

Services on Kubernetes

These managed services run on our Kubernetes platform, either as part of a tier or as an optional extension.