Skip to main content

Modern
Infrastructure.

Design, deploy and operate. From cloud to data center.

Connect public and private cloud, Kubernetes and enterprise networks with software delivery and ongoing operations.

Public & Private CloudKubernetes & DeliveryNetwork & Operations
Conceptual architecture · Adapted to your organization

Public Cloud

A cloud foundation built for expansion

Design landing zones with team boundaries, networking and resource policies, then deploy on your chosen cloud.

Amazon Web Services

Design accounts and landing zones with AWS Organizations and Control Tower. Provision VPCs, EKS, compute and storage through infrastructure as code.

Organizations · Control Tower · VPC · EKS

Microsoft Azure

Structure management groups, subscriptions and Azure Policy around team boundaries. Deploy VNets and AKS with Microsoft Entra ID integration.

Azure Policy · Entra ID · VNet · AKS

Google Cloud

Design organizations, folders and projects with IAM and Shared VPC. Deploy GKE, compute and storage connected to existing systems.

IAM · Shared VPC · GKE · Cloud Storage

Oracle Cloud Infrastructure

Define compartments and IAM policies to separate organizational resources. Deploy VCNs, OKE, compute and storage for your workloads.

Compartments · IAM · VCN · OKE

AWS · AzureGoogle Cloud · Oracle
Service architecture overview

Private Cloud

Design, deploy and configure Proxmox VE or OpenStack for your workloads.

Start with the workloads your organization needs to run. Select the platform, scale and features together, covering compute, storage and networking with agreed acceptance tests.

Proxmox VEOpenStack

On smaller screens, scroll horizontally to compare both platforms.

Design and deployment scope
ScopeProxmox VEOpenStack
Best fitFor teams consolidating VMs and containers with centralized virtualization management.For organizations building a cloud with resource provisioning through dashboards or APIs.
Design & installationReview hardware readiness, install Proxmox VE and configure KVM, LXC and workload resources.Plan controller, compute and storage roles. Review hardware and networking before installing the selected services.
Compute & VMDesign the cluster and configure VM migration between nodes, allowing capacity for maintenance and growth.Deploy Nova for compute and Glance for VM images. Define instance sizes and test launches using organizational images.
StorageConfigure Ceph where appropriate or integrate local/shared storage, then validate performance against workloads.Deploy Cinder with a supported storage backend. Test volume creation, attachment and detachment against workload scenarios.
NetworkSeparate management, VM and storage networks. Configure VLANs, bonding, SDN and firewall rules within scope.Configure Neutron networks, subnets and routers, connecting virtual networks to physical infrastructure with agreed traffic paths.
Availability & ValidationConfigure HA for critical workloads with spare capacity and failover tests. HA does not replace backups.Design control-plane availability within scope. Validate VM, network and volume workflows, plus agreed failure scenarios before acceptance.
Additional configurationBackup & RecoveryConfigure backup schedules and retention, integrate Proxmox Backup Server where selected and test restores before acceptance.Dashboard & API IntegrationIntegrate Keystone and Horizon with installed services. Verify service endpoints and test dashboard and API access.
ReferencesDocumentation: Proxmox VEDocumentation: OpenStack

A scale that fits your organization

Choose a starting point, then size the system around workloads and availability requirements.

Small

Initial deployment · Internal apps · Dev/test

Compute nodes · Example range
1–3 nodes
Suggested platform
Proxmox VE

A fit for initial VM and container consolidation. For HA, plan at least 3 cluster nodes, spare capacity and suitable storage.

A compact deployment with essential services, storage, networking and backups matched to the workload.

Medium

Production · Multiple applications

Compute nodes · Example range
4–16 nodes
Suggested platform
Proxmox VE / OpenStack

Choose Proxmox VE for centralized virtualization, or OpenStack for self-service and API-driven resource provisioning.

Cluster design with spare capacity, separate system and storage networks, and scoped HA configuration and testing.

Large

Multiple teams · Phased expansion

Compute nodes · Example range
17+ nodes
Suggested platform
OpenStack / Proxmox VE

Consider OpenStack for multi-team self-service cloud and automation. Proxmox VE remains an option for virtualization-focused workloads.

Capacity and failure-domain planning, networking and storage designed for growth, with load validation before expansion.

Compute node ranges are illustrative Zotect starting points, not platform limits. Dedicated controller, storage and backup machines are additional. Actual sizing depends on CPU, RAM, storage, workloads and availability requirements. A single node does not provide host-level HA, and node count alone does not guarantee HA.

Kubernetes

From the first cluster to daily operations

Design, deploy, upgrade and operate Kubernetes around your applications and teams, with workload-driven capacity planning.

Design & Deployment

Design control planes, worker pools, networking and persistent storage. Deploy clusters with RBAC, ingress and backup procedures.

Control Plane · CNI · CSI · RBAC

Upgrade & Maintenance

Review API, add-on and workload compatibility before upgrades. Plan maintenance windows, backups and recovery procedures.

Version Review · Add-on Compatibility · Recovery Plan

Scale Out & Autoscaling

Expand worker nodes and configure pod and node autoscaling. Review requests, limits and platform constraints before enabling policies.

HPA · Cluster Autoscaler · Karpenter where applicable

MA, Operations & Support

Manage patches, capacity and incidents within the agreed service scope. Maintain runbooks and transfer knowledge to your operators.

Cluster Health · Capacity Review · Runbooks

Kubernetes clusterConceptual topology: the control plane schedules application pods across three worker nodes. Highlighted replicas illustrate workload scaling, not live cluster metrics.Control PlaneAPI · Scheduler · ControllersSchedule podsWorker 1PodPodPodPodkubelet · runtimeWorker 2PodPodPodPodkubelet · runtimeWorker 3PodPodPodPodkubelet · runtimeApplication podsScale replicas
Service architecture overview

Platform Engineering & DevOps

A shared path from code to production

Give development teams a repeatable delivery path, from CI/CD to understanding application behavior after deployment.

CI/CD & GitOps

Design build, test and deploy pipelines with approval and rollback steps. Separate environments and keep configuration changes traceable.

GitLab CI · GitHub Actions · Argo CD

Infrastructure as Code

Provision resources and configuration from reviewed code. Create reusable modules and templates aligned with organizational standards.

Terraform · OpenTofu · Ansible · Helm

Logging & Monitoring

Bring application and infrastructure logs and metrics together. Build dashboards and actionable alerts for incident investigation.

Prometheus · Grafana · Loki · OpenSearch

Application Performance Monitoring

Instrument applications with APM and distributed tracing. Correlate request latency, errors and logs across services.

OpenTelemetry · Tempo · Jaeger

Source → Build → ReleaseObserve & Improve
Service architecture overview

Enterprise Network & Zero Trust

Connect every site with deliberate access

Design networks from offices to data centers, with access boundaries based on users, devices and services.

SME

Design office LANs, Wi-Fi and firewalls. Separate staff, guest and critical-system networks, with remote access.

LAN · Wi-Fi · Firewall · VPN

Enterprise

Connect headquarters and branches over WAN or SD-WAN. Define identity-based access, NAC and segmentation around organizational policies.

SD-WAN · NAC · ZTNA · Segmentation

Data Center

Design spine–leaf fabrics, routing and resilient paths for servers and storage. Separate management and workload networks, then test failover.

Spine–Leaf · BGP · EVPN/VXLAN · Redundancy

Identity & SegmentationSME → Enterprise → Data Center
Service architecture overview

Monitoring & Operations

Visibility with a clear response path

Connect monitoring to response, with defined ownership, escalation and an agreed operating scope.

Network Operations Center

Monitor availability, networks and capacity. Triage incidents, notify owners and track resolution within the service scope.

Availability · Alert Triage · Escalation

Security Operations Center

Collect and analyze security events against defined use cases. Triage suspicious activity and coordinate incident response with your team.

Security Logs · SIEM · Incident Response

Managed Services

Manage patches, backups, capacity and planned changes. Report service status and review improvements with your team.

Patch & Backup · Change Management · Service Review

Service hours, SLAs, contact channels and response responsibilities are agreed before the service starts.

NOC · SOCRespond · Maintain · Improve
Service architecture overview

Connect your foundation to enterprise AI

Bring cloud, networking and operations together as the foundation for GPU clusters and model serving.

Start with your systems. Define what comes next.

Tell us about your cloud, clusters or networks to scope deployment, improvement or ongoing operations.

Talk to our infrastructure team