Sovereign Cloud Compass
Everyday SDLC/DevOps (CI/CD, registry, secrets, K8s)

Everyday SDLC/DevOps (CI/CD, registry, secrets, K8s)

Why important?

Teams need a build and run pipeline: build, deploy, rollback, secrets, containers. Without it, time to production and operating costs rise.

How measured?

Scale 0–5 + N/A:
  • 0 = Core DevOps services missing
  • 1 = Very limited (basics only), lots of self-building
  • 2 = Partly available, important building blocks missing
  • 3 = DevOps core (CI/CD, registry, secrets, Kubernetes) available for the core scope
  • 4 = Strongly integrated + good developer experience, broad scope
  • 5 = Very comprehensive + mature + reliably evidenced (docs/evidence)
  • N/A = no reliable evidence

Validation questions (RFP)

  • Which golden-path patterns exist? CI/CD references? Container registry (SLA, scanning, RBAC)? Secrets/key management? Managed Kubernetes features (autoscaling, upgrades, multi-AZ)?

Scores comparison

Providers Score
AWS European Sovereign Cloud 5.0
Microsoft Sovereign Cloud 5.0
OVHcloud Public Cloud (inkl. SecNumCloud) 4.0
Oracle EU Sovereign Cloud 4.0
Scaleway 4.0
IONOS Cloud 3.0
STACKIT 3.0
T Cloud Public 3.0
pluscloud open 3.0
Exoscale 3.0
Delos Cloud 3.0
noris Sovereign Cloud 3.0
SysEleven OpenStack Cloud 3.0
Cloud Temple Trusted Cloud 3.0 PaaS OpenShift (SecNumCloud-qualified) with integrated CI/CD. Kubernetes available. Marketplace for software. No native container registry or secrets manager documented as a separate service.
Infomaniak Public Cloud 3.0 Managed Kubernetes (KaaS). No native container registry as a service. No native secrets manager. CI/CD possible via K8s integrations. Jelastic Cloud for PaaS-like deployments.
UpCloud 2.0
Hetzner Cloud 2.0