From Europe. For Europe.
Dr. Daniel Gerber
26 August 2026
Tarook is a CNCF-certified Kubernetes distribution with end-to-end lifecycle management. It can roll out, operate and scale highly available clusters: on bare metal, OpenStack and Proxmox.
Project leads
Written in
Nix Ansible Terraform Python
License
Apache-2.0
Where to find it
Context
Challenges
As soon as high availability and scalability are required, setting up a cluster turns into a lot of work.
Tools, versions and recommendations keep changing; keeping track of them takes effort.
Solution
Scalability and high availability are built in; rising demands do not call for a rebuild.
Tarook takes Kubernetes and its accompanying services through their lifecycle and ships regular updates.
Where it fits
Provisioning, management and scaling follow the same procedure on bare metal, OpenStack & Proxmox.
Certified by the CNCF for Kubernetes 1.34 to 1.36 and interoperable with other certified distributions.
Kubernetes on OpenStack or bare metal, driven from a single central configuration.
Nix-based configuration, a choice of storage solutions and its own load balancer as an alternative to Octavia.
keepalived and HAProxy secure the Kubernetes endpoint.
Certificates and access rights are managed automatically through HashiCorp Vault.
k8s-core runs the kubeadm cluster, the k8s-supplements round out production operation.
NVIDIA support for compute-intensive workloads, including AI training.
NGINX Ingress, Cert-Manager, Flux, Prometheus, Rook/Ceph, Calico and etcd backups are built in.
Fully open source; development and changes are publicly traceable.
Krake is an orchestrator for containerised and virtualised workloads across multi-cloud, private cloud and on-premises — distributed by the metrics you choose: ecological, technical or economic.
Project leads
Written in
Python Jinja
License
Apache-2.0
Where to find it
Context
Challenges
Managing containers across distributed infrastructure calls for orchestration that spans them all.
Compute-intensive workloads, AI above all, drive up energy costs and CO₂ emissions.
Solution
One interface for distributed Kubernetes clusters, across sites and automated.
Weighting follows configurable metrics such as performance, cost, energy and security.
Where it fits
From the local development environment to the distributed production system, from the microservice to AI training.
Distributed Kubernetes clusters are managed through a central abstraction layer.
Microservice-based components; your own developments can be plugged into the orchestration pipeline.
Orchestration of Kubernetes workloads across different clusters and sites.
Placement follows configurable metrics such as latency, energy and cost, as well as parameters you define yourself.
Labels and constraints give fine-grained control over which workloads run on which clusters.
Both stateless and stateful workloads are orchestrated, from the microservice to the database system.
Kubernetes clusters are provisioned and scaled automatically at different infrastructure providers.
Awarded in the Open Source category, nominated by the expert jury and chosen in the public vote.
Yake is a GitOps-driven installer and lifecycle manager for Gardener. Flux continuously reconciles the running system with the declarative configuration in Git — deployment and upgrade are the same routine operation.
Project leads
Written in
Go Go Template Shell Mustache
License
Apache-2.0
Where to find it
Context
Challenges
Provisioning, lifecycle management and day-2 operations take time before the first cluster is up.
Running it demands familiarity with many components, which makes adoption harder.
Solution
Scripts generate a base configuration that would otherwise have to be assembled by hand, step by step.
The GitOps workflow keeps the installation declarative; changes are traceable and repeatable.
Where it fits
For organisations running Gardener as their own Kubernetes control plane instead of consuming it as a service.
Upgrade guides describe the move between versions and keep the effort of staying current low.
The helper scripts build a running base installation out of the repository.
The entire Gardener installation lives in Git as configuration, and is traceable because of it.
Upgrade guides walk you through each version change.
One control plane for the self-hosted Gardener installation, managed in one place.
Yaook offers fully automated and free OpenStack lifecycle management for provisioning and operating your own cloud infrastructure.
Project leads
Written in
Python Cue Shell Jinja
License
Apache-2.0
Where to find it
Context
Challenges
As a cloud grows, the control plane has to grow with it without availability suffering.
Special-case settings for hardware, networks and services pile up and become hard to keep track of.
Solution
The controller pattern from Kubernetes: label changes take effect during operation, with no downtime.
Options are bound to node labels. Contradictions are rejected rather than merged.
Where it fits
Usable in any environment that runs Kubernetes.
Yaook can be used to operate SCS-compliant OpenStack.
Runs in Kubernetes and uses its features; supports IPv4-only, IPv6-only and dual-stack.
The operators take over ongoing operation, such as replacing failed nodes and version upgrades.
Data-modifying operations happen only on explicit instruction, and only where there is no alternative.
Almost every component can be placed via labels and taints.
All cluster-internal communication is TLS-encrypted and managed by the Cert Manager.
The OpenStack services you need can be picked one by one, from a minimal to a complete installation.
Every container image can be replaced with one of your own.
Yaook is fully open source; development and changes are publicly traceable.
Seconlay is an Infrastructure-as-a-Service layer built in Rust for secure tenant isolation: a deliberately minimal trusted computing base, with a control plane kept strictly apart from the data plane.
Project leads
Written in
Rust Nix Go
License
EUPL-1.2
Where to find it
Context
Challenges
Safely separating other people's workloads on the same hardware remains difficult with classic IaaS.
Physical separation makes up for complexity and poor auditability, and it costs money.
Solution
Implemented in Rust, with a deliberately small trusted computing base.
Control plane and data plane are strictly separated, for elevated security requirements.
Benefits
A cluster spans several machines and stays available when individual nodes fail.
A declarative API, self-healing behaviour and a Terraform provider.
Arko is a standardised monitoring platform for hybrid clouds: the state of systems and applications across private and public environments at a glance, with drill-down analyses that find the fault instead of merely showing it.
Project leads
Written in
Jsonnet Go Template Shell
License
Apache-2.0
Where to find it
Context
Challenges
The state of Azure, Google and on-premises is spread across several consoles.
Monitoring on an open source basis should be possible without being tied to a single vendor.
Solution
🟢 green, 🟠 orange, 🔴 red - a three-step colour code shows whether anything needs doing.
Each level shows only the metrics that matter at that level.
Where it fits
From the overview down to the single container, details can be opened up step by step.
Preconfigured dashboards for more than twenty platforms and applications.
Notifications can be delivered over more than ten channels.
🟢 green, 🟠 orange, 🔴 red - a three-step colour code shows the status at each level.
Each level shows only the metrics that matter at that level.
Four levels, from the overview to the single container.
Utilisation figures and log messages are shown on a shared timeline.
Public cloud and on-premises systems appear in one common view.
Built on Grafana, Prometheus and Loki; no vendor lock-in is created.
IXpect watches the peering LANs of internet exchanges continuously. It analyses BUM traffic to spot misconfigurations and attacks, pulls in the routers' configuration data, and reports what it finds in one place.
Project leads
Written in
Rust Nix Python Jinja
License
GPL-2.0
Where to find it
Context
Challenges
A faulty configuration at the network edge disturbs the routing between all networks at the IXP.
Such faults degrade performance, are hard to pin down and often go unnoticed.
Solution
IXpect evaluates the BUM traffic in the peering LAN; misconfigurations and attacks leave conspicuous patterns there.
Incidents are logged and, depending on severity, reported by email, Matrix or HTTP callout.
Benefits
The analyses of arpwatch, IXP-watch and ndmon are brought together in a single tool.
The network parameters are taken from the existing IXP Manager; there is no second set of data to keep.
When the Bitnami images were restricted, Arko and Tarook lost their foundation. The community build pulls Thanos straight from upstream and is rebuilt daily.
Commercial SONiC is platform-bound, licence-bound and not open source. ALASCA is putting together an open and documented community build.
Scales GitLab runners on OpenStack. Worker instances are created and torn down again in step with the pipeline load.
Open source CI software from the upstream project, run on our own infrastructure and independent of Microsoft and GitLab.
“Creating synergies with the Cloud and AI Development Act to benefit from the demand for European chips arising from the growth of sectors such as data centres, cloud service providers and AI gigafactories.” Chips Act 2.0 — European Commission