Sovereign Kubernetes: why open source is the better choice

Kubernetes has become the standard for organizations that are serious about working with containers. But behind that standard lies a question that is rarely asked in practice: who owns the platform on which your Kubernetes environment runs?

Kubernetes itself is open source. The layer around it—the management, distribution, and support—is often not. And that is exactly where tension arises. You choose Kubernetes to remain independent from a single vendor. Then, you end up on a managed platform that subtly limits that independence again.

The question that usually goes unasked: is your Kubernetes platform itself sovereign, or is it just your data?

Written by
Tim Geerdinck
&
Posted on
26
-
08
-
2026
2024
Written by
Tim Geerdinck
&
Posted on
26
-
08
-
2026
2024

Two forms of lock-in that no one mentions

When discussing digital sovereignty, there is a lot of talk about data residency. Where do your workloads run, and which jurisdiction and legislation do they fall under? This is valid, but the story is incomplete. A platform can run entirely in the Netherlands and still be under foreign control. Not through the data, but through the technology itself.

Two forms of dependency often remain underexposed:

1. Architectural lock-in

A large part of the market talks about open source while building on closed environments. Once you have migrated, you cannot simply migrate back without rebuilding parts of the environment. The standard is open, but the platform is not.

2. Jurisdictional lock-in

Support, updates, and license management often run through an American parent company. In theory, the Cloud Act gives the US government access to data and systems, even when the infrastructure is physically located in the Netherlands. This is no longer a fringe case. It is exactly the type of dependency that becomes relevant under NIS2 and the upcoming Data Act.

Both forms of dependency often remain invisible until an incident, audit, or geopolitical shock occurs. Only then does it become clear how much control you actually had.

What a sovereign Kubernetes platform is

A sovereign Kubernetes platform is a Kubernetes environment where the source code, operational control, hosting, management, and licensing structure all fall outside the sphere of influence of non-European jurisdictions.

In this context, open source is not a marketing term, but an architectural requirement. Without open standards, migration freedom is a promise, not a feature.

That is exactly why Fundaments chose SUSE as the foundation for its Managed Kubernetes platform.

Why does SUSE do this differently?

SUSE is a European company built on open source, without the hidden agendas sometimes found behind the 'open' platforms of hyperscalers. Rancher is CNCF-certified: not a proprietary dialect of Kubernetes, but the standard itself, with enterprise-grade management built around it.

That is an important point. Sovereignty and enterprise-grade are often presented as opposites, as if you have to choose between control and maturity. That is a false dilemma.

Open source is not the amateur alternative to closed-source platforms. In fact, it is often the more mature choice. The code is auditable, the architecture is not dependent on a single vendor, and continuity doesn't end the moment a US headquarters decides on a strategic pivot.

Fundaments brings this platform to market with SUSE as Managed Kubernetes. Managed from Dutch data centers, by Dutch engineers, and without the SaaS abstraction layer that invisibly strips away control on many other platforms.

As a result, you know exactly where the boundaries of your own control lie and where those of Fundaments begin.

Sovereignty is not a final destination

Honesty is part of this. Building a sovereign Kubernetes platform is not a checkbox you tick and then you're done. Compliance frameworks for government and healthcare are constantly evolving. A platform that meets the requirements today must be re-evaluated tomorrow.

At Fundaments, we treat this as an ongoing journey, not a one-off project. Today's architecture is the starting point for tomorrow's improvements, not the end point.

'We are 100% compliant' is easier to sell. But it is rarely true. At Fundaments, we prefer the honest message over the easy one.

The real question for IT decision-makers

Not: does your Kubernetes platform run in the Netherlands? But: who has control when it matters, technically, legally, and operationally?
That is a fundamentally different question. And the answer determines whether sovereignty is a marketing claim for you or an architectural feature.

Do you want to know how your current Kubernetes environment scores on that question? Get in touch with us; we would be happy to think along with you.

No items found.