KUBENEST Book a call

Managed Kubernetes · your hardware

We run Kubernetes
for you, on the
servers you own.

Kubernetes only works if someone installs it properly, upgrades it without taking your product down, patches the machines underneath, and proves the backups actually restore. That is a full-time specialist job.

KubeNest is that job, as a subscription. One fixed monthly price, on hardware you already own, for less than the cost of hiring one platform engineer.

Delivered with Concinnity Solutions. Runs on your infrastructure — we never hold your kubeconfig.

kubenest install --bundle 1.4 \
  --hosts 10.0.1.11,10.0.1.12,\
          10.0.1.13
k3s v1.31.4          ready
traefik + gateway    ready
cert-manager         ready
openebs local-pv     ready
velero               ready
upgrade controller   ready

That is the whole install. Everything your applications need to run — networking, certificates, storage, backup — set up together and tested as one thing.

The short version.

What is it?

A team that runs your Kubernetes, on your servers.

We install a complete, tested platform on machines you already own — in one command, usually in an afternoon. Then we keep it running: upgrades, security patches, backups and monitoring, with a report every month showing what we did.

What does it fix?

The job nobody wants to own.

Kubernetes on its own doesn't run anything. You also need networking, certificates, storage and backup — chosen, wired together, and kept compatible with each other forever. That work usually lands on one or two people, who then can't take a holiday.

Why not the alternatives?

They solve a smaller problem than you think.

Amazon and Google run the small part in the middle and leave the rest to you, on their hardware. Rancher gives you a dashboard, not a maintained platform. Hiring costs more and walks out of the door when the person does. The long answer is here.

How do I get it?

Try it first, or just call us.

There's a free edition you can download and install today, without talking to anyone. When you want it run for you, it's thirty minutes on a call, a fixed monthly price in writing, and we take over. No procurement marathon, no twelve-month commitment before you've seen it work.

You're already paying for this. Just not on an invoice.

Nobody budgets for "keeping the platform alive", so the cost shows up somewhere else. In three places, usually:

  • In salary.

    The median US platform engineer earns $131,607 in base pay1 — before benefits, payroll taxes and recruitment fees, and before the six months it takes them to become genuinely productive. Most companies need more than one, to cover holidays and illness.

  • In delay.

    Upgrades get postponed because nobody is confident they're safe. You fall several versions behind, and then the upgrade genuinely is dangerous — so it gets postponed again.

  • In risk.

    Backups get configured once and never tested. You find out whether they work on the worst day of the year, in front of your customers.

We replace all three with a fixed monthly price and a report you can hand to your board.

One platform engineer, per year
$131,607
US median base pay; most teams need two for cover
What a managed control plane buys
$74/mo
per cluster2 — everything above it is still your job
Time from decision to running platform
1 day
against roughly six months of building it yourself3
  1. 1. Platform Engineer median base salary, United States, $131,607 (middle 50%: $121,693–$140,161), updated 1 August 2026 — Salary.com. Indeed reports a higher $160,126 average including bonuses.
  2. 2. Amazon EKS charges $0.10 per hour per cluster for the control plane, about $74 a month — CloudZero, EKS pricing (2026). Compute, storage, load balancers, NAT and data transfer are billed separately and dominate the bill at any real scale.
  3. 3. Install time is our own figure, measured on customer hardware.

01 — What we install

One version number for the whole thing.

You don't choose components and hope they work together. We ship a set we have already tested as a unit, and we upgrade it as a unit. You run Platform 1.4 — one number you can put in a compliance document, not eight moving parts installed on different Tuesdays.

If something in that set has a security problem, patching it is our job.

Example KubeNest Platform bundle contents and pinned versions
Component Pinned In plain English
k3sv1.31.4Kubernetes itself
Traefik + Gateway APIv3.3Lets the internet reach your apps
cert-managerv1.17Keeps your HTTPS certificates valid
OpenEBS Local PVv4.2Fast disk for databases and files
Velerov1.15Backups, and proof they restore
system-upgrade-controllerv0.14Upgrades machines without downtime
kuredv1.16Reboots servers one at a time, safely
KubeNest agentv1.4Tells us when something needs attention

Example bundle. Exact versions are published per release with a test report.

Ubuntu only, on purpose Your servers, your cloud, your rack Optional: observability · secrets · replicated storage · HA

Free edition

Don't take our word for it. Install it.

You can download KubeNest and put it on your own servers today, without speaking to anyone and without a purchase order. It's the same installer we use — the same tested set of components, the same single command.

Where the free edition stops

  • Runs a limited number of machines — plenty for a proof of concept, not for a fleet.
  • You install and upgrade it yourself, on your own schedule.
  • No pre-flight upgrade checks, restore drills or OS patching — that automation is the paid product.
  • Nobody watching it, and no monthly report. If it breaks at 3am, it's yours.

The free edition proves the install works. The subscription is what stops you having to think about it again.

02 — What we do after it's running

Installing it is the easy day.

Every team we spoke to said the same thing, and none of them said "deployment". The problem was the year afterwards: upgrades, patches, and finding out too late that the backup had never been restored.

We check before we upgrade

Before anything moves, we scan what you're actually running for anything the new version will remove — and we stop the upgrade if we find it. An upgrade that succeeds and takes your product offline has not helped anybody.

  • We check your apps first, then upgrade
  • We stop at every stage if something looks wrong
  • Rolling back is tested, not theoretical
  • It happens in your maintenance window, not ours

We test your backups

A backup nobody has restored is not a backup, it's a hope. On a schedule, we restore yours somewhere safe, check it came back correctly, throw it away, and record a pass or a fail with a date on it.

We patch the machines too

Kubernetes upgrades get all the attention. Unpatched servers are what actually gets you breached. We patch the operating system and restart machines one at a time, so nothing goes down while we do it.

We notice before you do

Our agent calls out to us — it opens no ports and needs no firewall changes. Certificates about to expire, disks filling up, machines that have dropped out, patches missed, backups not tested lately. If a cluster goes quiet, that is itself an alert.

03 — Why not just…

The honest comparison.

Some of these are good products, and for some companies they're the right answer. Here's where each one stops.

…use Amazon, Google or Microsoft?

Their managed Kubernetes runs the coordination layer in the middle — a genuinely hard part, and a small one. Everything your applications actually touch is still yours to choose, connect and maintain, and it all runs on their hardware in their region. If that's fine for you, use them. If data residency, cost at scale, or servers you already own say otherwise, you still need everything we do.

…use Rancher? It's free.

Rancher is a good control panel, and looking at your clusters was never the hard part. It doesn't decide which networking, storage, certificate or backup tools you run, and it doesn't promise they'll survive the next upgrade together. That assembly and testing is the actual work. Rancher's automated maintenance features are a paid tier anyway.

…use Omni or Talos?

Well-built products. They also require their own operating system on your machines, so if you run Ubuntu today that's a migration project before you get any benefit at all. We install onto the servers you already have, as they are.

…hire a platform engineer?

You can, and past a certain size you should. It costs more than this, takes months to recruit and months more to become useful, and the knowledge leaves the building when they do. We're a team rather than a person, under a contract, with the work written down and handed over.

…carry on doing it ourselves?

Plenty of teams do, and it works — right up until a certificate expires while the person who set it up is on holiday, or an upgrade needs a maintenance window nobody wants to own. If you're reading this page, you probably already know which one of those is coming.

04 — No lock-in

You can fire us and keep everything.

Everything we install is standard open source that thousands of companies already run. There is no KubeNest-only technology holding your systems together.

If you stop paying us, nothing switches off. Your clusters keep running exactly as they are, and any competent engineer — yours or someone else's — can take over. You're buying the assembly, the testing and the upkeep. Not a trap.

KubeNest itself is commercial software. Everything it installs is not.

Who buys this.

Agencies, MSPs and consultancies

Sell managed Kubernetes without building the team first.

Run KubeNest for your clients and see all of them in one place. You keep the relationship and the margin. We keep the platform tested, the upgrades safe and the restores proven — and give you the monthly evidence to put in front of your clients.

Companies running their own servers

Get cloud-grade operations without moving to the cloud.

Data that can't leave the country, costs that stop making sense at scale, or hardware you've already bought — whatever keeps you off the big providers, you still need someone to run the platform layer. That's us.

The questions you'd ask.

What does this actually cost?
A fixed monthly fee based on how many clusters and machines you run, quoted after a short call and written into the agreement. It is designed to sit well below the cost of hiring for the same work. There is no per-node licence that surprises you when you grow.
Can we try it ourselves before committing?
Yes. The free edition is a real download you can install on your own hardware today, with no call and no purchase order. It is capped on how many machines it will run, and it leaves out the automation we do for you — upgrade checks, restore drills, patching and monitoring. Use it to satisfy yourself that the install works and the components are what we say they are.
Do you need access to our systems?
We never hold the keys to your cluster. Our agent makes an outgoing connection to report on health — no incoming ports, no VPN, no firewall exceptions, and you can see exactly what it sends. Where we do need hands-on access for a change, it's granted for that piece of work and logged.
What exactly does support cover?
Defined hours and a defined number of clusters, written into the agreement. We would rather tell you the boundary up front than promise round-the-clock coverage we can't honour. Delivery and first-line support run with Concinnity Solutions.
What happens if KubeNest goes out of business?
Your clusters carry on running. Everything installed is standard open source, so any competent engineer can take over. That is the main reason we built it this way rather than with our own proprietary components.
Is KubeNest itself open source?
No — KubeNest is commercial software, and everything it installs is open source. Where procurement requires it, source access under a commercial licence is available.
Does our team still deploy our own applications?
Yes. Your developers deploy exactly as they would on any Kubernetes, and nothing we do gets in their way. We look after the platform underneath so that they don't have to think about it.

Bring the servers.
We'll bring the rest.

Thirty minutes on a call: what you're running now, what's causing you trouble, and whether any of this is worth your time. No slides, and no obligation to go further.

  • A 30-minute call We work out together whether this fits. Often it doesn't, and we'll say so.
  • A written quote A fixed monthly price and a clear scope, usually within a week.
  • We install and take over Running on your hardware, with a monthly report from then on.