Sovereign Kubernetes: why open source is the better choice

Kubernetes has become the standard for organizations that take containerization seriously. But behind that standard lies a question that is asked far less often in practice: who owns the platform on which your Kubernetes environment runs?

Kubernetes itself is open source. The layers around it: ,management, distribution and support, are not always. And that is exactly where a tension arises. You choose Kubernetes to remain independent from a single vendor. Then you end up on a managed platform that quietly limits that independence again.

The question that is usually not asked: is your Kubernetes platform itself sovereign, or is it only your data?

Written by
Tim Geerdinck
&
Posted on
26
-
08
-
2026
2024
Written by
Tim Geerdinck
&
Posted on
26
-
08
-
2026
2024

Two forms of lock-in nobody talks about

When it comes to digital sovereignty, a lot of attention is paid to data residency. Where do your workloads run, and which jurisdiction and legislation apply to them? Rightly so, but that is not the complete story. A platform can run entirely in the Netherlands and still be under foreign control. Not through the data, but through the technology itself.

Two forms of dependency often remain overlooked:

1. Architectural lock-in

A large part of the market talks about open source, while continuing to build on proprietary environments. Once you have migrated, you cannot simply migrate back without rebuilding parts of the environment. The standard is open, but the platform is not.

2. Jurisdictional lock-in

Support, updates and license management often run through a US-based parent company. The US CLOUD Act theoretically gives the US government access to data and systems, even when the infrastructure is physically located in the Netherlands. This is no longer a fringe issue. It is exactly the type of dependency that becomes relevant within the context of NIS2 and the upcoming Data Act.

Both forms of dependency often remain invisible until an incident, audit or geopolitical shock occurs. That is when it becomes clear how much control you actually had.

What a sovereign Kubernetes platform is

A sovereign Kubernetes platform is a Kubernetes environment in which the source code, operational control, hosting, management and licensing structure all remain outside the reach of non-European jurisdictions.

Open source is not a marketing term here, but an architectural prerequisite. Without open standards, freedom of migration is a promise, not a property.

That is exactly why Fundaments chose SUSE as the foundation for its Managed Kubernetes platform.

Why does SUSE make a difference?

SUSE is a European company built on open source, without the hidden agenda that can sometimes lie behind ‘open’ platforms from hyperscalers. Rancher is CNCF-certified: not a proprietary dialect of Kubernetes, but the standard itself, with enterprise-grade management around it.

That is an important point. Sovereignty and enterprise-grade capabilities are often presented as opposites, as if you have to choose between control and maturity. That is a false dilemma.

Open source is not the amateur alternative to closed-source platforms. It is often the more mature choice. The code is auditable, the architecture is not dependent on a single vendor, and continuity does not end the moment a US headquarters makes a strategic change of direction.

Fundaments brings this platform to market with SUSE as Managed Kubernetes. Managed from Dutch datacenters, by Dutch engineers and without the SaaS abstraction layer that, on many platforms, quietly takes control away from you.

This means you know exactly where the boundaries of your own control lie and where those of Fundaments begin.

Sovereignty is not a destination

Honesty matters here. Building a sovereign Kubernetes platform is not a box you tick once and then forget about. Compliance frameworks for government and healthcare continue to evolve. A platform that meets the requirements today must be reassessed tomorrow.

At Fundaments, we treat this as an ongoing journey, not a one-time project. Today’s architecture is the starting point for tomorrow’s next step, not the end point.

‘We are 100% compliant’ is easier to sell. But it is rarely accurate. At Fundaments, we prefer the honest message over the easy one.

The real question for IT decision-makers

Not: does your Kubernetes platform run in the Netherlands? But: who is in control when it really matters, technically, legally and operationally?

That is a fundamentally different question. And the answer determines whether sovereignty is a marketing claim or an architectural property.

Would you like to know how your current Kubernetes environment measures up against that question? Fundaments is happy to think along with you.

No items found.