Secure Managed Kubernetes

Our managed and fully-operated Kubernetes solution, run by our senior experts. Its benefits: security, reversibility, and an all-in-one service managed by our responsive, close-knit teams.

Distributed high-availability architecture across 3 AZs
Tailored sizing and performance suited to your business applications
Advanced Kubernetes customization
Compatible with all storage options: network, local or shared
Secure Zero Trust access via Teleport and network flow security (Ingress + optional WAF)
Integration with your CI/CD and middleware: databases, messaging, IAM, SIEM, logs, search...
GitOps deployment (FluxCD) and Cloud Native monitoring
A group of Enix mascot monkeys referencing the A-Team from the action agency
A managed and fully-operated Kubernetes service, wherever you need it

Secure Managed Kubernetes (SMK) is a complete and industrialized Kubernetes solution, tailored to your needs, and operated by our teams.

Built on Talos Linux and enhanced with our Enix “secret sauce”, a suite of additional open-source and/or in-house components, to operate Kubernetes at scale over time.

Background dot icons

Secure Managed Kubernetes (SMK) on the environment of your choice


	Icon representing full control over your data on your on-premise infrastructure

On-premise

Installation, configuration and management of our SMK solution on your own infrastructure, bare metal or virtualized. We fully operate the service while you retain complete control over your infrastructure and sensitive data.


	Icon with the Enix logo representing our private, dedicated hosting

Enix Hosting

Deployment and management of your private, dedicated platform in our 3 French datacenters (latency < 0.5ms). Enix is your single point of contact for hosting and Kubernetes management, so you can focus on your applications and business services.


	Icon representing deployment on public or private third-party clouds

Third-party cloud

Deployment with a hosting provider or third-party cloud, bare metal or virtualized: with our FR cloud partners (OVHcloud, Scaleway, Outscale), or on international clouds (AWS, Azure, GCP, Hetzner, Infomaniak...). Hybrid or multi-cloud deployments possible.

When should you adopt SMK?

Modernize your platforms
Move your applications to containers by adopting SMK, deployed on the most suitable environment.
Cloud repatriation
Replace your managed K8s in the public cloud to take back control of your platform, with a dedicated, tailored solution, on-premise or in a private cloud.
The Enix mascot practicing karate on the Kubernetes logo
Delegate operational management
Adopt an all-in-one K8s solution, managed by a single French hosting and managed-services provider.
Optimize your K8s platform
Move your existing Kubernetes platform to a more robust, more secure SMK solution, with controlled costs.

What sets SMK apart from other Kubernetes solutions

Icon representing the security of the SMK solution

Security

SMK is built on an immutable, ultra-secure OS with a minimal attack surface and native encryption. We add network flow security (Ingress + optional WAF), K8s policies with Kyverno, and a Zero Trust approach via Teleport.
Icon representing SMK's operational excellence

Operational excellence

SMK goes further than managed solutions - it’s also fully operated. As production experts, we guarantee maximum service availability and proximity via our direct Level 3 support on a dedicated messaging channel.
Icon representing AI and GPU workloads on SMK

AI & GPU workloads

SMK runs your AI models in production at scale: optimized management of costly GPUs, intelligent autoscaling, high availability and minimal latency, even under massive request volumes.
Icon representing the portability of the SMK solution

Portability

SMK is built on a standard Kubernetes architecture and an open-source foundation, with no configurations or integrations specific to a cloud provider. If needed, SMK clusters can easily be migrated to another environment.
Icon representing SMK's cost control

Costs

SMK has no license costs; we offer a managed-service rate with a fixed recurring amount and projectable costs, with a 12- to 36-month commitment. The rate is based on the number and size of clusters, the number of middlewares and integrations, and the level of support (business hours, extended hours, or 24/7).
Icon representing the technical control SMK offers compared to cloud provider solutions

More control than cloud provider managed K8s

Access to the OS for debugging and low-level optimizations, full access to workers, control over upgrades (schedule, versions), no configuration drift.
Kubernetes logo

Key components of our solution

SMK is built on a collection of components carefully developed or selected by Enix, automatically deployed and activated depending on the type of underlying infrastructure.

Logos of kuberouter, calico, cilium, traefik

Network

CNI based on Cilium (eBPF) for intra-cluster connectivity, external (L4) and internal (L7, Traefik recommended) load balancing.

Logos of rook, openebs, minio, longhorn

Storage

Network disk volumes (SAN, Ceph RBD), local disk volumes (OpenEBS ZFS LocalPV) and shared volumes (CephFS), depending on your performance and resilience needs.

Logos of kyverno, falco, aquasecurity, certmanager

Security & resilience

Kyverno for Kubernetes policies, Cert Manager for PKI management (local or external), Kube-image-keeper for image management, Teleport for secure access.

Logos of gitlab, flux, argo

Configuration

Automated, cloud native deployment, deployment or integration with your CI/CD, industrialized GitOps methodology, ensuring traceability, reproducibility and reversibility.

Logos of prometheus, thanos, jaeger, eck

Observability

Prometheus and its many exporters, Node Problem Detector, x509 exporter for tracking TLS certificate expiration.

Our premium managed service included in SMK

Maintenance and security

Maintenance in operational condition (MCO): preventive and corrective maintenance, functional and security updates.

360° monitoring

Monitoring, metrics and alerting based on proven open source tools: Prometheus, Thanos, Robusta, Grafana, AlertManager…

Close, responsive support

Dedicated Slack channel with our engineers, direct Level 3, no complex escalation matrix. Support during business hours, extended hours, or 24/7, in French or English.

Maximum availability

Guaranteed 99.99% service availability rate, with contractual GTI/GTR (response/resolution time) commitments based on incident severity.

Enhanced security and resilience

DRP/BCP, replication and backup, Cloud Native and highly-available Kubernetes architectures, data protection and compliance (ISO 27001, GDPR).

Secure governance and access

Remote access via Teleport (2FA/Yubikey, no SSH keys, full traceability), integration possible with your IAM (LDAP, OpenID, Active Directory, Keycloak…).

They've already chosen Secure Managed Kubernetes

Logo institut_pasteur
Logo foussier
Logo yousign
Logo imio
Logo skaleet
Logo tdf
Logo oodrive
Logo sellsy
Logo jamespot
Logo jalios
Logo origamimarketplace
Logo gespro
Logo apitech
Logo evenizer
Logo svp
Logo ezytail
Logo octopusmind
Logo blackbit

A few numbers in production

Icon representing the speed our Kubernetes experts bring 20+

Kubernetes experts in the field

Icon representing security built into our clusters from the start 300+

Clusters deployed, across 800+ hosts

Icon representing the security of our managed clusters 200+

Managed and secured clusters


FAQ - Frequently Asked Questions

Managed and fully-operated Kubernetes refers to a service where a provider runs your entire Kubernetes platform for you: deployment, security, updates and 24/7 monitoring. Secure Managed Kubernetes (SMK) is Enix’s solution for this: built on Talos Linux (an ultra-secure immutable OS), it can be deployed on-premise, at Enix, or on a third-party cloud, and is fully operated by our teams (control plane and workers included). You no longer have to worry about your Kubernetes platform, and can focus on your applications and business services.
With a managed Kubernetes service from a cloud provider, the provider hosts and operates the control plane for you - you configure it through their API and interfaces, but without access to the underlying infrastructure - and you remain responsible for managing the worker nodes and your applications. You remain tied to that specific cloud’s infrastructure, configuration options and conventions: limited access to worker OS, older Kubernetes versions and upgrades imposed on their schedule, reduced portability. SMK allows for advanced Kubernetes configurations tailored to your needs, it’s a fully managed solution operated by our teams (not just managed) and deployable on-premise, on our infrastructure, or with any cloud provider alike (on bare metal or VM). Our engineers have full access to the OS and workers for debugging or low-level optimization, and you benefit from direct Level 3 managed support, with no escalation matrix.
Yes. Whether your current Kubernetes platform runs on-premise or with a cloud provider, our teams handle the migration to SMK: project scoping, data synchronization, progressive workload cutover, and support before, during and after the migration. Thanks to a standard Kubernetes architecture, the migration doesn’t require rewriting your manifests or applications.
Talos Linux (talos.dev) is an immutable Linux operating system, purpose-built to run Kubernetes clusters. It strips away unnecessary layers (very few binaries, no SSH access), is fully driven by a declarative YAML configuration, and guarantees that a failed node can be rebuilt identically. We built SMK on top of the Talos foundation to drastically reduce the attack surface of your clusters, eliminate configuration drift, and simplify security audits — while remaining 100% standard Kubernetes. Talos is open source; we chose it among the very first adopters, but it now has a large community, including major French companies that have built their own Kubernetes services on it.
SMK has no license fees: you pay a fixed, predictable monthly recurring amount for a service fully managed and operated by our teams. The price depends on three factors: infrastructure operated (number and size of clusters, CPU/GPU, multi-AZ), expertise mobilized (integrated middlewares, complexity of usage) and the level of support (business hours, business hours + weekends, or 24/7). Discounts are available from the second cluster onward, on dev clusters, and for longer commitments (24 to 36 months). Contact us for a quote tailored to your context.
Yes, if you choose an on-premise or Enix-hosted deployment: our 3 datacenters are located in the Paris region (Ile-de-France), and your data never leaves French territory. Our managed service is ISO 27001 certified and GDPR compliant, with a strict access control policy (Zero Trust via Teleport, 2FA, full traceability). If you opt for a third-party cloud and have sovereignty requirements, we recommend deploying SMK on the FR clouds of our partners OVHcloud (Elite partner), Scaleway (Premium partner), and Outscale.
SMK includes a premium managed service with support during business hours (HO), business hours + weekends (HOWE), or 24/7 depending on the criticality of your workloads, via a dedicated Slack channel directly with our senior engineers, with no escalation matrix. We guarantee a 99.99% service availability rate, with contractual response time (GTI) and resolution time (GTR) commitments: for example, a 15-minute GTI and a 2-hour GTR for a major incident during business hours, extending up to 30 minutes / 4 hours outside business hours.
Want to know more about SMK for your organization?
Contact us