Kubernetes that can't drift.
Upgrades that don't hurt.
KubeAid is one way to run Kubernetes anywhere — AWS, Azure, Hetzner or your own metal — installed, upgraded and proven from Git.
Day 2 is where Kubernetes gets expensive.
Installing a cluster is an afternoon. Keeping it patched, compliant and boring for years is the real work.
Upgrades postponed until they're risky
Version jumps pile up until nobody wants to be the one who touches the cluster.
Drift you can't see
Manual hotfixes in production quietly diverge from what Git says is running.
CVE churn without end
Every chart you run needs watching, patching and re-testing — every single week.
How KubeAid runs your clusters
If it's not in Git, it doesn't exist.
- GitKubeAid + your private config, versioned in Git
- ArgoCDPulls the desired state from Git
- Cluster APIProvisions and upgrades your clusters
- WorkloadsApps deployed and kept in sync
- DriftLive state diverged from Git
- ReconcileArgoCD restores the declared state
From laptop to cluster in two commands.
kubeaid-cli is a single binary. It generates your config, provisions the cluster and hands everything to ArgoCD — from then on, Git runs it.
Built to operate, not just install.
Provision anywhere
Cluster API deploys the same way on AWS, Azure, Hetzner cloud or bare metal — on-prem and air-gapped included. Major upgrades run on a shadow cluster first, so switchover is an event you schedule, not a risk you take.
Shadow-cluster upgrades · air-gap support
Operate from Git
Every change is a commit. ArgoCD applies it when you say so — auto-sync is off by default — and anything changed outside Git is flagged as drift. Secrets are encrypted before they ever leave your machine.
118 charts, updated weekly · sealed-secrets
Prove everything
kube-prometheus monitoring, Teleport access control and Git history for every deployment. Velero-backed disaster recovery restores a cluster in 15 minutes. Rollback is a revert. Auditors get answers, not archaeology.
Velero DR — RTO 15 min · RPO < 5 min
Compliance by default.
Security and operational defaults are mapped to ISO 27001:2022 and cover GDPR and NIS2 goals, with DORA and CIS 18 in scope. Least-privilege NetworkPolicies, OPA policies and supply-chain scanning are standard — the same hardened setup that has passed independent penetration tests with zero findings.
Run it yourself, or run it with us.
KubeAid is AGPL-3.0 and free forever. Subscriptions add Obmondo operations per server — cancel anytime, with expense ceilings so costs stay predictable. Maintenance is shared across customers running the same stack, so nobody pays for the same work twice.
- Full platform, nothing gated
- AGPL-3.0 licensed
- Community support on GitHub
| Basic | Bronze | Most popularSilver | Gold | Platinum | |
|---|---|---|---|---|---|
| Price | €29/server·mo | €129/server·mo | €165/server·mo | €199/server·mo | €265/server·mo |
| Response / SLA | Monitoring, alerts & live chat | 1-business-day response | 4-hour response, business hours | 2-hour response, 24×7 | 1-hour response, 24×7 |
| Service level |
Prices per server per month. Volume discounts, consultation hours and expense ceilings — see the full calculator.
Open the price calculatorSovereignty you can exit-test.
Everything KubeAid ships is AGPL-3.0 open source, and your config lives in your Git repository — clusters even run air-gapped. Cancel the subscription and keep everything: config, charts, monitoring. That is the exit test hyperscalers fail. And because roughly 90% of the platform work is shared across customers as open source, nobody builds compliance alone.
AGPL-3.0 · air-gap proven · ~90% of the work shared as open source
FAQ
Yes. The full platform is AGPL-3.0 with nothing gated behind a paid edition. Subscriptions add operations, response times and support — not features.
A Git host, a target to deploy to (a cloud account or your own servers), and the bootstrap script. It sets up ArgoCD and your private config repository from the KubeAid template.
Major cluster upgrades run on a shadow Kubernetes setup — a parallel cluster where the upgrade is tested before traffic switches over. You schedule the switchover; nothing is upgraded in place.
No. Everything is standard Kubernetes plus Git, the code is AGPL-3.0, your config lives in your repository, and any subscription can be cancelled at any time.
Yes. KubeAid supports air-gapped operation of clusters — everything needed to set up or fully recover a cluster is kept in your repositories.
Talk to the people who'll run it.
A 30-minute call with an Obmondo engineer who operates clusters for a living — not a sales deck.