VanillaCore

VanillaStack


Introducing VanillaStack

VanillaStack is a distributed cloud stack: multiple Kubernetes clusters, orchestrated as one platform. A load balancer cluster handles all ingress by defined rules. A management cluster provides centralized access to metrics, logs, and operations. Child clusters run your workloads, communicate over a mesh network, and are rolled out from a dedicated management dashboard.

VanillaStack topology: load balancer cluster for ingress, management cluster with dashboard and agents, child clusters over a mesh network, VPN-only developer access, runs on OpenStack, Proxmox, VMware, private clouds, and on-premises

The architecture is hub-and-spoke, built to minimize any blast radius. Child clusters are rolled out and managed through Cluster API and related technologies, directly from the dashboard, so an operations team does not need deep infrastructure knowledge for day-to-day work. East-west traffic between clusters is regulated by network rules. Developers reach child clusters via VPN only. The whole stack runs on OpenStack, Proxmox, VMware, private clouds, and on-premises. 100% open source, no vendor lock-in.

Operations, with AI Where It Helps

The management dashboard is where the platform is operated, and it can do more than classic tooling:

  • Optional AI for predictive operations and analysis, local models first
  • Local agents in the management cluster and in every child cluster maintain and partially operate their environments
  • VanillaBrain integration for runbooks and operations recipes
  • A curated application catalog: prepared workloads, for example GovStack building block implementations, rolled out by operations teams without deep platform expertise

The VanillaStack management dashboard: observability, cluster lifecycle via Cluster API, curated app catalog, AI operations, local agents, and VanillaBrain runbooks

Operations also feed back into VanillaBrain: changes, deployments, and incidents become organizational knowledge that your team and your agents can query later. If frontier LLMs are used at all, they never see internal cluster information: VanillaStack contains an MCP server that strips and cleans all internals before anything leaves the platform. Confidential data stays inside.

Proven in Production

This is not a concept paper. VanillaStack runs the GovStack assembly platform and several enterprise environments. It is stable, proven, and built around two goals: minimizing any blast radius, and making cloud-native technology operable without requiring deep operational and infrastructural knowledge from your team.

Talk to us about VanillaStack

Why VanillaStack?

VanillaStack is a platform to roll out an indefinite amount of Kubernetes Clusters and Virtual Machines, to run any kind of workload.

Kubernetes-as-a-Service, based on Standards

Use VanillaStack to roll out Kubernetes, K3S, Rancher. VanillaStack uses Cluster-API to run a diverse array of Kubernetes-Distributions. No lock-in, no bias. Each installation can have their own separate Storage based upon Rook / Ceph or Longhorn, MinIO, or any other Kubernetes-compatible storage layer. And it can be setup either as standalone hyperconverged setup, or by utilizing the VanillaStack-storage layer.

Infrastructure-as-a-Service, scalable and resilient

VanillaStack deploys KubeVirt-VMs, and uses Rook / Ceph to provision storage. In any Namespace, a huge amount of Virtual Machines can be deployed to run Kubernetes-Clusters, Edge-Distributions, or any workload directly on a VM. As Kubernetes has a very thin footprint and allows for unprecedented scaling, while providing unparalleled resilience, it renders old-fashioned and traditional IaaS-Layers obsolete.

Ready for Day-2-Operations and Integration

As VanillaStack is built upon best-practices for operations and cloud-platforms, it always includes an Identity-and-Access-Management (IAM)-Layer, as well as several Operations- and Infrastructure-tools, such as Prometheus and Grafana for Monitoring and Centralized Metrics, Loki for Centralized Logging, Harbor as Container Registry, and Wireguard for secure access to the platform via VPN.

Platform-Agnostic, no questions asked

VanillaStack is platform-agnostic. It literally can run everywhere - on old and cheap machines in a Homelab, in a Server-Room, on commodity infrastructure in a professional data-centre, on Private Clouds, and on Public Clouds, such as AWS, Azure or Google Cloud. Or on any combination of these, as Multi- or Hybrid-Cloud-Setup.

Full Tenant-Separation, no compromises

Use VanillaStack to deploy multiple, completely separate tenants on the same physical foundation. Each Tenant is physically separated from other tenants on both the Network- as well as Infrastructure-Layers. This allows to utilize the underlying infrastructure to its maximum, without compromising on security!

Free and Open-Source, and frugal as well

VanillaStack is based on Open-Source components only and is provided as Open-Source as well. Also, the whole platform can be downloaded and used free of charge, as we believe in the power of Free and Open-Source Software. VanillaStack does not require any specific hardware - just use commodity hardware to enjoy full performance and full control.

Own Your Stack!

Discover how to build and run sovereign cloud-native, open-source & AI solutions. Drop us an email or schedule a call.

VanillaStack Use-Cases

VanillaStack is versatile, and be deployed to fit a multitude of Use-Cases - all based upon a purely Open-Source- and Vendor-Agnostic Stack!

On-Premises

Use VanillaStack in your On-Premises Environment to allow for easy deployment of multiple clusters and for abstraction of Infrastructures using Virtual Machines. Run it as IaaS-Stack, CaaS-Stack, or everything in-between, and leverage modern technologies!

Private Cloud

VanillaStack is the perfect match for your Private Cloud-Environment, as it abstracts the infrastructures, can easily grow, allows for great performance, and is free and frugal - specifically compared to tradition IaaS-Stacks, such as VMWare or OpenStack!

Public Cloud

Use VanillaStack to abstract your Workloads from the underlying Cloud Environment, be it Azure, AWS, Google Cloud or any other Public Cloud. VanillaStack ensures these environments to be merely IaaS-Layers, effectively preventing from any Vendor-Lock-Ins!

Development

VanillaStack helps you speeding up your Development, as you don't have to care and to worry about provisioning Resources or the actual underlying Infrastructure anymore. Get insights and central log access using the Operations Stack, and focus on the actual work!

Operations

Run multiple, independent environments on the same platform. Leverage the built-in Operations Tools, such as Prometheus, Grafana, Loki, Tempo to gain centralized insights while maintaining strict tenant-separation. Enjoy GitOps, and be ready for Day-2-Operations!

Public Hand and Enterprise

VanillaStack helps you bringing Workloads, Processes, and Integrations to life - with full abstraction between environments, multi- and hybrid-cloud capabilities, built-in security and resilience, unparalleled scalability, and the power of Open-Source!

VanillaStack Services

We support our customers in setting up, running, and maintaining VanillaStack, as well as developing solutions based upon VanillaStack:

  • Solution Architecture
  • Solution Design
  • Automation
  • Roll-Out
  • Hosting
  • Operations
  • Maintenance
  • Integration of Hardware
  • Software Architecture
  • Software Development
  • Scaling and Resilience

Our Architects, Engineers, and Operations Teams are experts in VanillaStack - on any On-Premises-, Private Cloud- or Public Cloud-environment! Reach out to us to discuss your requirements!

Other Supported Stacks

Apart from VanillaStack, we also support these alternative stacks with our services and hosting offerings:

Our Architects, Engineers, and Operations Teams are experts in any of these stacks. We are able to design them, roll them out and operate them on any On-Premises-, Private Cloud- or Public Cloud-environment. Reach out to us to discuss your requirements!