Clusterward
Control plane for Scaleway

Run Kubernetes on Scaleway – without your own platform team.

Clusterward is the control plane for Scaleway: provision Kapsule clusters, deploy SaaS applications from Git, a container image or a Helm chart, and onboard new customers via pipeline – with database, bucket, domain and certificate. One cockpit, your Scaleway project.

Clusterward at a glance: one cockpit for clusters, deployments, databases, domains, customer pipelines, secrets, monitoring and backups on your Scaleway project
Clusterward at a glance: eight areas, one cockpit, your Scaleway projectIllustration with sample values.
In brief

What is Clusterward?

Clusterward is the control plane for Scaleway: provision Kubernetes clusters, databases, Object Storage, DNS and certificates from one cockpit, deploy applications from Git, a container image or a Helm chart, and onboard new customers via pipeline – all in your own Scaleway project.

Who it’s for

SaaS vendors, agencies and platform operators who want to stay on Scaleway – without their own platform team.

More about our solutions

What’s included

Kapsule, managed Postgres & MySQL, Object Storage, Cloudflare DNS, cert-manager, Helm – controlled, not abstracted.

All features

Alternative to

Qovery, Heroku and DIY scripting. All resources stay in your project, even after you cancel.

See the comparisons

Who’s behind it

BitKollegen GmbH from Hannover. Clusterward runs as SaaS: your own workspace on your own subdomain, no installation required.

More about the company
Built on standards you already know

No proprietary stack, no abstraction layer – Kubernetes, Helm and Scaleway as you know them.

Clusterward drives the tools your team already uses. Everything it creates is visible in kubectl, the Scaleway console and Cloudflare – and you can keep running it without Clusterward at any time.

  • Scaleway Kapsule

    Managed Kubernetes with Private Network, Public Gateway and nodes without public IPs.

  • Kubernetes & Helm

    Deployments as standard objects, Helm charts from the template library, no proprietary format.

  • Managed Postgres & MySQL

    Scaleway RDB with a private endpoint, one database and role per service.

  • Scaleway Object Storage

    S3-compatible buckets with their own IAM key and bucket policy per application.

  • cert-manager

    Let's Encrypt per host or a managed wildcard certificate for all subdomains.

  • Cloudflare DNS

    DNS records created automatically, proxy switchable per host, real client addresses in the cluster.

  • Kaniko & GitHub Actions

    Container builds in the cluster or on GitHub’s runners, with the image verified in the registry before rollout.

  • ingress-nginx & Envoy Gateway

    Ingress or Gateway API; timeouts, rate limits, basic auth and CORS per service.

One customer, one run

33 seconds to a live customer.

That’s what the first onboarding on clusterward.app looked like: five steps, each individually retryable, each with its own way back. No script, no ticket, no weekend.

What the log shows is a real run: the pipeline creates every resource in your Scaleway project, records the IDs immediately and can therefore pick up exactly where it failed – or tear everything down again in reverse order.

How tenant pipelines work
tenant-pipeline · first onboarding
  1. done:
    databaseDatabase and its own role on the managed Postgres instanceWay back: Dump to the bucket, only then drop
  2. done:
    bucketBucket with its own IAM key and bucket policyWay back: Deleted only if the bucket is empty
  3. done:
    domainDNS record in the Cloudflare zone; the wildcard certificate applies immediatelyWay back: Only its own record is removed
  4. done:
    workloadHelm release with deployment, ingress and secrets from the variable busWay back: Undeploy; the namespace stays clean
  5. done:
    http_checkReachability of the new addressWay back: Waits and reports, never aborts on its own
Customer live, every step timestamped33 s
What Clusterward takes care of

From an empty Scaleway project to a running customer – without your own ops team.

Every feature is a deliberate switch. Nothing touches your infrastructure until you approve it.

Shipping applications

From the repository to a reachable address with a certificate.

  • Deployments

    Git, container image or Helm chart. Built with Kaniko in the cluster or with GitHub Actions, rolled out with a health check, restarted without a rebuild. Environment variables encrypted, “Restart pending” visible.

  • API & CI

    API tokens with role, application scope and expiry date. Deploys from GitHub Actions, every action in the audit log under the token’s name.

  • Networking & ingress

    ingress-nginx or Envoy Gateway; timeouts, rate limits, CORS and basic auth per service. Controller switches without downtime, real client IP.

  • DNS & certificates

    Register Cloudflare zones and create records automatically – but only ever touch its own. Let's Encrypt per host or a managed wildcard certificate for all subdomains.

Data & storage

Everything that has to last – separated per service and backed up.

  • Managed databases

    Postgres and MySQL, private connectivity only. One database with its own role per service, read-only users for BI, imports from other systems – and a dump in the bucket before every drop.

  • Object Storage

    Buckets on Scaleway Object Storage with their own IAM key per application, bucket policies and public or private visibility. Import from third-party S3 buckets, archive on offboarding – never a blind deletion.

  • Volumes & snapshots

    Persistent volumes per service on Scaleway Block Storage, scheduled snapshots with retention. Data survives every deploy; a volume disappears only after a confirmed snapshot.

  • Backups & recovery

    Back up databases, volumes and chart disks; bring back earlier versions with a click.

Cluster & operations

A cluster that is secure from day one, and a clear view of it in daily operations.

  • Cluster provisioning

    Secure by default: Private Network, Public Gateway, nodes without public IPs, API access only from your CIDR. Ingress controller, cert-manager and metrics are installed right along with it.

  • Operations & updates

    Configuration check between cockpit and cluster, Kubernetes and add-on upgrades from the cockpit, live status of nodes and pods, notifications via webhook, Slack, Teams or email – once per event.

  • Logs & monitoring

    Logs from all instances, 30 days of usage and uptime checks with alerting – without an agent in the cluster.

  • Notifications

    Failed deployments, sites that are down and expiring certificates via Slack, Teams, webhook or email.

Customers & security

Onboard and offboard customers by pipeline, with tightly limited access.

  • Tenant pipelines

    Onboarding as building blocks: plug database, bucket, domain and workload together in the designer, with values flowing through the variable bus. Retry, rollback and offboarding with backup included.

  • Security & access

    Mandatory 2FA, roles with application scope, secrets write-only and never in logs, every change in the audit log under a real name, IP allowlist per workspace.

  • Secrets

    Write-only secrets, stored in the Scaleway Secret Manager if you wish. Rotations are detected and the service restarts. External Secrets Operator as an add-on.

How you go live

Five steps, one cockpit

  1. 01

    Provision a cluster

    Store an IAM key as a profile, fill in the wizard, and your Kapsule cluster comes up securely configured.

  2. 02

    Create an application

    Repository, build and environment – the namespace is set once and stays stable.

  3. 03

    Deploy a service

    Add a domain, create a database in one step, follow the rollout with its health check.

  4. 04

    Onboard tenants

    Build a pipeline in the designer, enter customer data, let preflight check for collisions, start the run.

  5. 05

    Operate

    Configuration check, Kubernetes and add-on upgrades, backups with restore, notifications via webhook or email.

Alternative to Qovery, Heroku and DIY

What changes day to day

Qovery charges $2,999 per month for three clusters and $399 for each additional one. Clusterward costs €299 for ten clusters – a tenth of the price for three times as many, with unlimited users instead of twenty.

See the detailed comparison with Qovery
Shared-pods SaaS

One process, many workspaces – each with its own database and its own key.

You get your own cockpit on a subdomain. No other workspace sees what’s inside it – and whatever you provision lives in your Scaleway project.

  • Your own control plane database, data key and backup bucket

  • Your cockpit at ihre-firma.clusterward.app with a wildcard certificate

  • IP allowlist per workspace, with Cloudflare addresses correctly recognized

  • Onboarding and offboarding via the same pipeline you use for your customers

Explore the workspace model

At a glance

Isolation
Database, key and bucket per workspace
Encryption
AES-256-GCM, secrets write-only
Access
Named users, mandatory 2FA, roles with application scope
Backups
Database backups with restore, dump before every drop
Location
Scaleway, EU data centers, your project
Pricing

One price per cluster tier. Everything else is included.

Three plans, tiered by number of clusters only: 2, 10 or unlimited. Applications, tenants and users are unlimited on every plan. Cancel monthly, no setup fee – you pay for Scaleway resources directly.

  • Starter

    Up to 2 clusters

    €99/ month
    • 2 clusters
    • Unlimited applications, tenants and users
    • Deployments, databases, DNS & certificates
    • Tenant pipelines and provisioning source
    • Notifications, volumes & snapshots
    • Email support
  • Recommended

    Team

    Up to 10 clusters

    €299/ month
    • 10 clusters
    • Unlimited applications, tenants and users
    • Deployments, databases, DNS & certificates
    • Tenant pipelines and provisioning source
    • Notifications, volumes & snapshots
    • Priority support
  • Platform

    Unlimited clusters

    €799/ month
    • Unlimited clusters
    • Unlimited applications, tenants and users
    • Deployments, databases, DNS & certificates
    • Tenant pipelines and provisioning source
    • Notifications, volumes & snapshots
    • SLA with response times
Frequently asked questions

What teams want to know before they start

Anything else? Write to us or book a demo.

  • Yes. You store an IAM key from your Scaleway project as a provisioning profile; Clusterward verifies it before saving and creates Kapsule clusters, managed databases, the container registry and buckets exclusively in that project. The resources belong to you, appear in your Scaleway console and are billed directly by Scaleway. Clusterward keeps no copy of your data, only the control information.

Can’t find your question? Write to us – we usually reply on the same business day.

Ask a question

Ready for your first cluster?

From an empty Scaleway project to your first deployment in 30 minutes – we’ll show you live, using your own use case.