Clusterward
Digital sovereignty

Digital sovereignty: your applications in Europe, under your control

Clusters, databases and buckets are created in your Scaleway project in Paris or Amsterdam. The control plane runs in the EU, operated by a German company. And everything Clusterward creates keeps working without Clusterward.

Provisioning profile in the cockpit: Scaleway project with region, verified permissions and the clusters created from it
Simplified view in the Clusterward cockpit: provisioning profile with verified permissions and resources
Illustration: a simplified view. The product shows more details and options.
In brief

What digital sovereignty means at Clusterward

Digital sovereignty means that you decide where your data lives, who can access it and whether you can switch providers. Clusterward gives a concrete answer to all three questions: your infrastructure is created in your own Scaleway project in an EU data center, with your IAM key. The control plane is operated by BitKollegen GmbH on Scaleway in the EU, in a workspace with its own database and its own key. And because Clusterward only creates standard Kubernetes objects, Scaleway resources and Cloudflare records, your applications keep running without Clusterward.

At a glance

Data centers
Scaleway Paris or Amsterdam, your choice per cluster
Ownership
All resources in your Scaleway project
Control plane
Operated in the EU by BitKollegen GmbH
Credentials
Encrypted with your workspace key, never readable
Exit
Standard objects, JSON export, backups in your project
Contract
GDPR data processing agreement on request
What lives where

How your data travels

  1. 01

    Your project

    You create a Scaleway project and store its IAM key as a provisioning profile.

  2. 02

    Your region

    You choose Paris or Amsterdam per cluster; databases and buckets follow the cluster.

  3. 03

    Your nodes

    Provisioned clusters get nodes without a public IP and an API allowlist limited to your address range.

  4. 04

    Your data

    Databases on the private network only, buckets with their own key and policy.

  5. 05

    Your backups

    Dumps and archives in a bucket in your workspace, with your retention policy.

  6. 06

    Your exit

    If you cancel, clusters and applications keep running in your project.

What’s included

What sovereignty means in practice at Clusterward

Not a statement of intent, but properties you can verify in the Scaleway console.

EU data centers

Scaleway operates its data centers in Paris, Amsterdam and Warsaw. Clusterward provisions clusters in Paris or Amsterdam; databases and buckets are created in the same region.

Your project, your key

Everything is created with your project’s IAM key and belongs to your Scaleway account. The key is verified before it is stored, kept encrypted and never displayed; you can rotate or revoke it at any time.

Workspace with its own database

Your control plane data lives in a dedicated database with its own data key and its own backup bucket. No tables shared with other customers.

Secure by default

Private nodes, API allowlist, databases without a public endpoint, hardened pods, mandatory 2FA and an audit log. None of it has to be switched on after the fact.

No lock-in

Clusterward creates standard Kubernetes objects, Scaleway resources and DNS records. You can carry on working with kubectl and the Scaleway console at any time. There is no proprietary runtime. You can export the entire configuration as a JSON file whenever you like.

Contractual basis

A GDPR data processing agreement is available on request. The operator is BitKollegen GmbH, a German company with ISO 27001 certification.

Who operates what

The parties involved

  • Scaleway

    French cloud provider, data centers in the EU, your contractual partner for the infrastructure.

  • BitKollegen GmbH

    Operator of Clusterward, headquartered in Germany, ISO 27001 certified.

  • Cloudflare

    Optional for DNS zones and proxying; only if you register zones.

  • GitHub

    Optional for builds on GitHub runners; alternatively, Kaniko builds in your cluster.

What changes

US hyperscaler with a platform layer, or Clusterward on Scaleway

Facts

What lives where

Every row can be verified in the Scaleway console or in the cockpit.

DataLocationOwner
Applications and clustersKapsule in Paris or AmsterdamYour Scaleway project
DatabasesManaged Database, private network, same regionYour Scaleway project
Files and uploadsObject Storage, same regionYour Scaleway project
Container imagesContainer Registry, same regionYour Scaleway project
Backups from offboardingsBucket in your workspaceYour workspace
Control plane dataWorkspace database on Scaleway in the EUYour workspace, operated by BitKollegen
DNS recordsCloudflare, if zones are registeredYour Cloudflare account
Database backupsScaleway Managed Database, your regionYour Scaleway project
Further reading

Dig deeper

How the workspace keeps your control plane data separate is explained under Your own workspace. Roles, mandatory 2FA, the audit log and encrypted credentials are covered in Security & access.

Cluster provisioning shows how a cluster is created in your project, secure by default. We answer questions about the DPA and contracts via Contact.

Related pages

What goes with it

FAQ

Frequently asked questions about digital sovereignty

  • In your own Scaleway project, in the region you choose per cluster: Paris or Amsterdam. Databases, buckets and the registry are created in the same region as the cluster. Your workspace’s control plane data is also stored on Scaleway in the EU.

Can’t find your question? Write to us – we usually reply on the same business day.

Ask a question

Discuss sovereignty in detail

In the demo, we show where each resource is created, who owns it and what an exit looks like. Questions about the DPA and compliance are welcome.