Kubernetes operations

Kubernetes that can't drift.
Upgrades that don't hurt.

KubeAid is one way to run Kubernetes anywhere — AWS, Azure, Hetzner or your own metal — installed, upgraded and proven from Git.

118maintained Helm charts
Weeklychart & security updates
15 mindisaster-recovery RTO
≤ 1 hresponse time, 24×7

Day 2 is where Kubernetes gets expensive.

Installing a cluster is an afternoon. Keeping it patched, compliant and boring for years is the real work.

  • Upgrades postponed until they're risky

    Version jumps pile up until nobody wants to be the one who touches the cluster.

  • Drift you can't see

    Manual hotfixes in production quietly diverge from what Git says is running.

  • CVE churn without end

    Every chart you run needs watching, patching and re-testing — every single week.

The GitOps loop

How KubeAid runs your clusters

If it's not in Git, it doesn't exist.

  1. GitKubeAid + your private config, versioned in Git
  2. ArgoCDPulls the desired state from Git
  3. Cluster APIProvisions and upgrades your clusters
  4. WorkloadsApps deployed and kept in sync
  5. DriftLive state diverged from Git
  6. ReconcileArgoCD restores the declared state
Quick start

From laptop to cluster in two commands.

kubeaid-cli is a single binary. It generates your config, provisions the cluster and hands everything to ArgoCD — from then on, Git runs it.

you@laptop — bashLive

Built to operate, not just install.

Provision anywhere

Cluster API deploys the same way on AWS, Azure, Hetzner cloud or bare metal — on-prem and air-gapped included. Major upgrades run on a shadow cluster first, so switchover is an event you schedule, not a risk you take.

Shadow-cluster upgrades · air-gap support

Operate from Git

Every change is a commit. ArgoCD applies it when you say so — auto-sync is off by default — and anything changed outside Git is flagged as drift. Secrets are encrypted before they ever leave your machine.

118 charts, updated weekly · sealed-secrets

Prove everything

kube-prometheus monitoring, Teleport access control and Git history for every deployment. Velero-backed disaster recovery restores a cluster in 15 minutes. Rollback is a revert. Auditors get answers, not archaeology.

Velero DR — RTO 15 min · RPO < 5 min

Inspection

Compliance by default.

Security and operational defaults are mapped to ISO 27001:2022 and cover GDPR and NIS2 goals, with DORA and CIS 18 in scope. Least-privilege NetworkPolicies, OPA policies and supply-chain scanning are standard — the same hardened setup that has passed independent penetration tests with zero findings.

ISO 27001:2022GDPRNIS2DORACIS 18
Fares

Run it yourself, or run it with us.

KubeAid is AGPL-3.0 and free forever. Subscriptions add Obmondo operations per server — cancel anytime, with expense ceilings so costs stay predictable. Maintenance is shared across customers running the same stack, so nobody pays for the same work twice.

Free zoneCommunityFree forever
  • Full platform, nothing gated
  • AGPL-3.0 licensed
  • Community support on GitHub
Star on GitHub
Managed fares€ / server · month
Basic€29/server·moMonitoring, alerts & live chat
Bronze€129/server·mo1-business-day response
SilverMost popular€165/server·mo4-hour response, business hours
Gold€199/server·mo2-hour response, 24×7
Platinum€265/server·mo1-hour response, 24×7

Prices per server per month. Volume discounts, consultation hours and expense ceilings — see the full calculator.

Open the price calculator
Digital sovereignty

Sovereignty you can exit-test.

Everything KubeAid ships is AGPL-3.0 open source, and your config lives in your Git repository — clusters even run air-gapped. Cancel the subscription and keep everything: config, charts, monitoring. That is the exit test hyperscalers fail. And because roughly 90% of the platform work is shared across customers as open source, nobody builds compliance alone.

AGPL-3.0 · air-gap proven · ~90% of the work shared as open source

FAQ

Yes. The full platform is AGPL-3.0 with nothing gated behind a paid edition. Subscriptions add operations, response times and support — not features.

A Git host, a target to deploy to (a cloud account or your own servers), and the bootstrap script. It sets up ArgoCD and your private config repository from the KubeAid template.

Major cluster upgrades run on a shadow Kubernetes setup — a parallel cluster where the upgrade is tested before traffic switches over. You schedule the switchover; nothing is upgraded in place.

No. Everything is standard Kubernetes plus Git, the code is AGPL-3.0, your config lives in your repository, and any subscription can be cancelled at any time.

Yes. KubeAid supports air-gapped operation of clusters — everything needed to set up or fully recover a cluster is kept in your repositories.

Talk to the people who'll run it.

A 30-minute call with an Obmondo engineer who operates clusters for a living — not a sales deck.