General Sovereignty

Who Can Switch It Off

7. Oct 2026

Aarno Aukia, VSHN. October 2026

Most sovereignty conversations are about who can read your data. That question has good answers by now: encryption, data residency, access logs, a data processing agreement naming every subprocessor. The question that gets asked far less often, and that would hurt far more, is who can switch your service off.

Losing confidentiality is bad. Losing the service is worse, because the business stops that afternoon. And the two risks do not have the same owner: your data can stay in Zurich while the decision to keep serving it is made somewhere else entirely.

Four ways a running service stops without anyone touching your data

These are not four versions of one risk. What separates them is how much notice you get: the first stops the service today, the next two hand you a migration on a date you did not choose, and the fourth needs nobody to decide anything at all.

1. Someone orders it off. Days, and no appeal. A provider obeys the law of the jurisdiction it belongs to. Sanctions, export controls and court orders reach the vendor, not the data center, and the customer is rarely a party to the decision. Adobe deactivated every account in Venezuela in October 2019 to comply with a US executive order, three weeks after telling customers, and said at first that it was not permitted to refund prepaid subscriptions before reversing that under public pressure. In May 2025 the chief prosecutor of the International Criminal Court lost access to his Microsoft account after the US sanctioned ICC officials. Microsoft’s president denies that the company suspended services to the court. What the court did next is on the record: in October 2025 it confirmed it is moving some 1,800 workstations to openDesk.

2. The license changes under you. Months, and a bill. This one needs no politics. In December 2020 Red Hat moved CentOS Linux 8’s end of life from May 2029 to December 2021, removing eight years of planned life with twelve months’ notice and breaking no agreement with anyone. Broadcom ended perpetual VMware sales in December 2023 and went subscription-only, and in May 2025 it sent cease-and-desist letters to perpetual licensees whose support had lapsed, requiring them to uninstall every update and patch released after their contract ended. The right to run the software survived. The right to patch it did not, and nobody keeps an unpatched hypervisor in production. Oracle has priced Java SE per employee since January 2023, counted on total headcount rather than on who uses Java: same software, same deployment, a bill computed from the HR system.

3. The product is retired and the vendor is fine. Months, and a migration nobody budgeted. The fear attached to small providers is insolvency, and it is the wrong fear. The ordinary case is a vendor in good health discontinuing a product. Microsoft retired Azure Database for MariaDB on 19 September 2025, announced two years ahead, with new instances blocked eighteen months ahead, and its own documentation says that workloads still running on the retirement date are deleted and their data lost. AWS retired Amazon QLDB on 31 July 2025 with about a year’s notice, and the replacement it recommends has no cryptographic verification, which was the reason to pick QLDB in the first place, so the migration was a redesign. Google retired Cloud IoT Core in August 2023 with twelve months’ notice, saying its partners served those needs better. Azure Blockchain Service stopped accepting new deployments in May 2021 and was switched off that September, four months later. Every one of those vendors is still trading.

4. Nobody decides anything and it stops anyway. The fuse is the obligation to phone home. Software running on your own hardware often has to reach its vendor to keep working, and few teams have looked up how long it lasts without that. Azure Local, which Microsoft positions for sovereign and distributed locations, documents the answer in its own FAQ: if the system does not sync with Azure for 30 consecutive days, its status goes to “Out of policy” and it enters a reduced functionality mode in which existing VMs keep running and new ones cannot be created until it syncs again. Your hardware, your building, your data, and a license to start a VM that renews monthly from a cloud. Microsoft does sell a disconnected edition for permanently offline sites, so the fuse is in the default build and taking it out is a separate purchase. Microsoft 365 is the same mechanism on a shorter fuse. Microsoft’s lifecycle gives a subscription 30 days of normal access past its end date, after which the applications move into what its own documentation calls a read-only, reduced functionality mode: you can look at your documents and not edit them. And it does not take a lapse. In November 2020 Macs worldwide hung when launching applications because Apple’s certificate-status server stopped answering, and the workaround that circulated was to disconnect from the internet.

The database world’s most instructive case belongs to the third category rather than the first. Sun Microsystems bought MySQL in 2008, Oracle bought Sun in 2009, and MySQL’s creator forked the code rather than wait to find out what the new owner would do with it. Oracle did not disappear and MySQL was not discontinued. The fork happened over what the owner might decide, and it was possible because the license permitted it. MariaDB exists because of that.

Why a contract does not settle it

A contract binds your vendor. It does not bind the state that regulates your vendor, and it does not survive the vendor. Contractual protection is worth having, and it is the layer most procurement processes spend all their time on, which is why the gap is so common: the paperwork is thorough about liability and silent about continuity if the counterparty is compelled, acquired or gone.

Data residency has the same shape of gap. It tells you where the bytes are. It tells you nothing about who operates the service, under which law the operating company sits, and who can be ordered to stop. Those are three separate questions, and each one has a different answer for each provider.

What actually reduces the risk

Four questions, in the order they matter:

1. Can anyone withdraw your right to run the software? With a proprietary engine, yes, by changing the terms or ending the product. With an engine under GPLv2 or a comparable license, no. The code you are running stays yours to run, and a fork stays possible, which is the structural reason the MySQL story could have a sequel at all.

2. Who operates it, and under which law? Running software is not the same as owning its license. If the operator is a foreign subsidiary, the operating decisions sit in the parent’s jurisdiction, whatever the data center’s address says.

3. What stops working if you stop paying? This is the sharpest test, and almost nobody runs it. Take the commercial components out on paper and see what is left. If what remains is a database that keeps serving queries, you have an exit. If what remains is nothing, you have a dependency you have been calling a partnership. Then run the same test for reachability instead of payment: what stops working if the vendor cannot be reached for a month? Both answers are in the documentation. Neither is in the contract.

4. Who answers at three in the morning? Independence that nobody can operate is not independence, it is a hobby. The point of sovereignty is continuity, and continuity needs someone contractually obliged to restore service, close enough to your timezone and your language to do it.

What this looks like in practice

Take a MariaDB deployment, which is the example I know best, and separate it into layers:

  • MariaDB Server and Galera Cluster are GPLv2. Free to run in production, with no audit exposure on the database itself. Nobody can withdraw that right, this year or in five years.
  • The connectors are LGPL, so they link into proprietary applications without obliging you to open your own code.
  • MaxScale, the Enterprise Kubernetes Operator, Enterprise Manager and the analytics components are commercial, and come with a subscription.

Run question 3 against that stack. Drop the subscription and the database keeps running: you lose the proxy layer, the hardened builds and the vendor’s support, which are real losses, and you keep serving queries while you decide what to do next. That is what an exit looks like when it is structural rather than contractual.

Then run question 2. The subscription is a commercial relationship with a European vendor. The operations can sit with a Swiss company, under Swiss law, with the infrastructure in a Swiss data center or in your own. Two suppliers, two different kinds of accountability, neither of them able to end the other’s part unilaterally.

This is the arrangement VSHN and MariaDB described at our joint webinar on 1 October, which is recorded and online: MariaDB builds the database and stands behind the engine, VSHN resells the subscription in CHF and runs the platform. A customer signs one Swiss contract and still has the database vendor’s engineers behind it.

The uncomfortable part

Sovereignty bought this way is not free. The commercial components cost money, the operations cost money, and someone has to run the architecture that makes a failover invisible instead of hoping the single node holds. What it buys is the ability to answer a regulator, an auditor or your own board with facts rather than assurances: here is who holds the license, here is who operates it, here is the law the contract sits under, and here is what we keep running if any of them walks away.

The Swiss public sector has started paying that price deliberately, and its decisions are a matter of record. EMBAG has required federal agencies to publish the software they develop or commission as open source since 1 January 2024, which makes Switzerland one of the first countries to put that in law. In June 2026 the Ständerat went further and adopted a motion for an impulse program on digital sovereignty by 30 votes to 7, against the Federal Council’s recommendation; the Nationalrat has not voted yet. The same reasoning applies one layer down, at the database under the application that the business actually runs on.

Where to start

Look at the systems the business cannot lose for a day, and for each one write down five answers: who holds the engine’s license, who operates it, which law the contract sits under, what still runs if you stop paying, and what still runs if nothing can reach the vendor. Most teams can fill in the first three from memory and go quiet on the last two.

If MariaDB is one of those systems, we will do that review with you. VSHN and MariaDB are offering a joint estate check: which versions you run, where they are exposed, what is under support and what is not. It is free and it ends in a written answer, not a quote.

Book a free estate review

If you would rather start with the technology than with your own estate, we are running a hands-on afternoon at the VSHN Tower in Zurich on 19 October with the MariaDB engineers and Michael “Monty” Widenius, who wrote MySQL and MariaDB: a live MaxScale failover, the Enterprise Kubernetes Operator, and migrations. Forty seats.

Reserve a seat for 19 October in Zurich


Sources:

Aarno Aukia

Aarno is Co-Founder of VSHN AG and provides technical enthusiasm as a Service as CTO.

Contact us

Our team of experts is available for you. In case of emergency also 24/7.

Contact us
Events General

Data sovereignty is built, not bought: VSHN at Cloud Native Days Austria 2026

6. Oct 2026

On September 29th, 2026, Aarno Aukia took the stage in Vienna to make a simple argument: you don’t get sovereignty by signing a contract with a hyperscaler. You get it by architecting for it.

Cloud Native Days Austria 2026

Cloud Native Days Austria brought the community together again on September 29th and 30th, 2026, this time in two cinema halls at Cineplexx Wienerberg in Vienna. Two days of talks, hallway conversations and an evening event, aimed at developers, platform engineers and everyone else who runs things on Kubernetes.

We were there and our co-founder and partner Aarno Aukia opened the technical program on day one, right after the opening keynote.

Short on time? Download the slides (PDF) and jump straight into the deck.

Aarno’s Talk: “Data Sovereignty Is Built, Not Bought”

Aarno started with the deal the hyperscalers have been offering for twenty years. The offer: modern managed services – databases, queues, AI – self-service, in minutes. The price: your data moves into their datacenter, and the jurisdiction follows the provider. Or, as Aarno put it: the law follows the provider, not the rack. An executive order can switch your service off. The CLOUD Act can make your data be handed over.

Data has gravity

For many organizations, moving everything into a hyperscaler was never really an option anyway. Health, finance and public-sector data has to stay in controlled environments. Workloads need to stay close to the systems they talk to. And large datasets don’t move on a project timeline. Meanwhile, developers expect exactly what the cloud promises: a managed database, self-service, now.

Mohammad Alavi, CTO of Health Info Net (HIN), the secure network for Swiss healthcare, summed up the stakes: “No financial compensation could ever make up for leaked medical information.”

The common mistake

The reflex answer is: “Let’s move it to a sovereign cloud.” That usually gets you a migration project, a duplicated platform and a new dependency. You changed whom you depend on, not whether you depend.

Aarno pointed to the EU’s EUR 180 million cloud tender from April 2026, the first one scored on sovereignty. Three winners reached SEAL-3, meaning they cannot be blocked by a non-EU third party. Another bidder, offering EU-operated infrastructure built on Google Cloud, landed at SEAL-2. The label said sovereign. The score did not.

Sovereignty as three tests

Instead of trusting labels, Aarno proposed three concrete questions:

  • Location: Can you move where it runs without changing how developers consume it? Provider-specific Terraform fails this test, a Kubernetes service claim passes.
  • Operator: Can you replace who runs it without replacing the technology? A hyperscaler’s managed database fails, an open-source operator with its config in Git passes.
  • Vendor: Can you replace the software without rebuilding? This one needs open source. VMware after Broadcom is the cautionary tale – Redis to Valkey in eight days is the counterexample.

Sovereignty, in short, is what you can still replace tomorrow.

The neutral platform layer

The architecture that passes all three tests puts one platform API between developers and infrastructure. Developers talk to the API; underneath, it can be Cloud A, Cloud B, a private datacenter or the edge. The point isn’t to avoid platforms, it’s to design for change.

That’s exactly how our VSHN Application Catalog (AppCat) works. Developers order managed databases and services as Kubernetes resources. Crossplane on Kubernetes provides the service API, and the services run at cloudscale, Exoscale, Switch or in private clusters – each with its own local Prometheus and Grafana, operated 24/7 where the data is.

Today, AppCat offers PostgreSQL, MariaDB, Redis, Keycloak (with Inventage), Forgejo, Nextcloud and S3 object storage from the underlying infrastructure. Kafka (with Spoud) and OpenBao (with bespinian) are coming next.

A production database takes ten lines:

yaml

apiVersion: vshn.appcat.vshn.io/v1
kind: VSHNPostgreSQL
metadata:
  name: pgsql-app1-prod
spec:
  parameters:
    size:
      plan: standard-2
  writeConnectionSecretToRef:
    name: postgres-creds

No cloud, no region, no operator, no storage class. What comes back is PostgreSQL with TLS, daily backups, monitoring and a maintenance window. A real production team sets more – service level, three instances for high availability, backup schedule and retention, maintenance window, deletion protection. Every one of those is a decision the team owns. And still nothing in the spec says where it runs.

2,000+ instances in production

AppCat isn’t a concept. It has delivered more than 2,000 managed instances since 2021, in two ways: every Managed OpenShift cluster we run includes it by default – in the customer’s own infrastructure, VMware included, or at a Swiss partner like cloudscale, with SLAs up to 99.99%. And in shared environments, you order AppCat services like SaaS through Servala or use them built into APPUiO.

Customers include finnova, acrevis, HRM Systems, the Swiss Federal Archives, HIN with its 50,000+ healthcare professionals, and Taurus. Sebastien Pasche, VP Engineering at Taurus: “We reduced monthly incidents from twelve to zero and improved our SLA from 99% to 100%.”

Proof: we change the engine, the API stays

The strongest part of the talk: we pass the tests ourselves. In AppCat, kind: VSHNPostgreSQL stayed the same while the PostgreSQL operator underneath was swapped: CloudNativePG became available as an option in September 2025, matured with self-service restore in April 2026, became the default for new instances in May 2026, and StackGres reached end of life on August 31st, 2026. Customers kept their API and planned migrations on their own timeline.

And we’re doing it again, this time with our own control plane. AppCat has run on Crossplane since 2021 and will continue into 2027 and beyond, but we’re moving to Helmetica, an operations framework for any software on Kubernetes that we’re open-sourcing over time. It monitors, backs up and GitOps-manages every service – the same principle as our Puppet framework on VMs. The difference is striking: Redis on Crossplane needed 2,076 lines of Go and shell code to render a Helm chart. Redis on Helmetica takes 320 lines – the upstream chart plus the framework’s shared templates for backup, network, maintenance and credentials. From Helm chart to service in five minutes and every change is a diff you can read.

Sovereignty is now measurable

The EU Cloud Sovereignty Framework scores providers on eight objectives, from SEAL-0 to SEAL-4. Three of them – operational independence, supply chain transparency and the ability to migrate without rebuilding – add up to half the score. And all three are decided by your architecture, not your contract.

Aarno closed with the question that sums it up: The question isn’t which cloud you choose, but whether your architecture still gives you a choice tomorrow. Dependent teams ask for permission. Sovereign teams ship.

In short: data sovereignty is built, not bought.

Get the slides

Want to dig into the details – the three sovereignty tests, the AppCat architecture, the YAML examples and the Helmetica comparison? Download Aarno’s full slide deck from Cloud Native Days Austria as a PDF.

Sovereignty was everywhere

We weren’t the only ones talking about it. Sovereignty, independence and compliance ran through the whole program:

  • Lukas Zainzinger (willhaben) presented a blueprint for reclaiming data sovereignty with an open-source, vendor-agnostic data pipeline from edge to cloud.
  • Niels Claeys (Dataminded) asked what a cloud strategy looks like after the hyperscaler era, from fully on-prem platforms to sovereign control planes and EU cloud alternatives.
  • Dr. Constanze Roedig showed an eBPF-based Kubernetes SOC that runs node-local and can be airgapped, so no data has to leave the cluster.
  • ORF shared how they connect EKS to on-prem hardware with hybrid nodes, Cilium and Crossplane.
  • Artem Lajko and Nick Berthold (iits-consulting) looked behind the curtain of managed Kubernetes with Gardener, Kamaji and Cluster API.
  • On the regulatory side, talks on the EU Cyber Resilience Act and NIS2 in Austria made it clear that compliance is becoming an engineering topic, not just a legal one.

Different angles, same conclusion: the community is no longer asking whether sovereignty matters, but how to build it. That’s exactly the conversation we want to be part of.

Thank you, Vienna

A big thank you to the organizers, volunteers and sponsors of Cloud Native Days Austria for another great edition and to everyone who came by to talk sovereignty, Crossplane and managed services with us.

Want to know how this model could work in your environment? Get in touch – we’re happy to show you.

Markus Speth

Marketing, Communications, People

Contact us

Our team of experts is available for you. In case of emergency also 24/7.

Contact us
General OpenShift Tech

OpenShift 4.22 lets your pods mount container images as volumes

2. Oct 2026

Whenever Red Hat releases a new version of OpenShift, our team works through the release notes and asks one simple question: what does this actually mean for the people running their applications on VSHN Managed OpenShift?

OpenShift 4.22 has been available since June 9th, 2026. It’s based on Kubernetes 1.35 and CRI-O 1.35, and the Red Hat CoreOS (RHCOS) image now uses RHEL 9.8 packages, which bring the latest fixes, enhancements, hardware support and driver updates. VSHN Managed OpenShift clusters currently run 4.21, and we’ve started testing 4.22. Here’s what you can look forward to.

Good news for developers: static data in its own image

Some applications rely on large amounts of static data. With OpenShift 4.22, that data can be distributed in a separate container image and mounted straight into your pods as a volume, opening the door to new ways of structuring applications.

Under the hood, this works with OCI images and artifacts. These let you store and distribute arbitrary files and metadata through OCI-compliant registries, the same kind of registries that hold your container images.

More flexibility with Gateway API

Until now, OpenShift blocked any attempt to install Gateway API resources from the experimental channel. With 4.22, that restriction is gone, which gives you more flexibility in adopting Gateway API.

Behind the scenes: one reboot less, safer updates

Some improvements you won’t notice directly, but they make the platform run more smoothly.

New worker nodes used to start in the generic worker machine config pool and then had to be moved to their actual target pool, which required an extra reboot. With 4.22, new nodes boot directly into their target pool, saving one reboot cycle during provisioning.

OpenShift also keeps a closer eye on the images nodes boot from. On supported infrastructures, the Machine Config Operator checks whether a node’s boot image is too old. If it is, OpenShift blocks cluster updates until the boot image has been updated.

A good release for vSphere users

If your OpenShift runs on VMware vSphere, two features are now generally available:

  • Zones for vSphere host groups: OpenShift failure domains can be mapped to vSphere host groups, enabling seamless use of the high availability offered by a vSphere stretched cluster. The feature was introduced as a technology preview in OpenShift 4.19.
  • Boot image management for worker nodes: the node boot image is now updated automatically during cluster updates. New nodes created afterwards are based on the new version, while existing nodes aren’t affected.

What doesn’t affect you

  • runC is deprecated: OpenShift 4.22 deprecates the runc container runtime for CRI-O. All VSHN Managed OpenShift clusters use CRI-O with the default crun runtime, so this doesn’t affect our clusters.
  • RHCOS 10.2 as technology preview: OpenShift 4.22 supports RHCOS 10.2 as a technology preview. We’ll start testing RHCOS 10 internally, but won’t update any customer clusters until RHCOS 10 is generally available for OpenShift.

What happens next

We’re currently testing OpenShift 4.22, and our plan is to have all clusters running 4.22 before the end of the year.

Want all the details? Our engineers’ summary is in the VSHN Knowledge Base, and Red Hat’s complete OpenShift Container Platform 4.22 release notes cover everything else.

Questions? Get in touch – we’re always happy to talk OpenShift.

Simon Gerber

Simon Gerber is a DevOps engineer in VSHN.

Contact us

Our team of experts is available for you. In case of emergency also 24/7.

Contact us
Events General

Meet Monty Widenius: A Technical Deep Dive into MariaDB Enterprise at the VSHN Tower

23. Sep 2026

VSHN is now an official MariaDB partner. To mark it properly and to give teams already running MariaDB (or considering it) something hands-on, we’re hosting a technical workshop at the VSHN Tower in Zürich, with Michael “Monty” Widenius, the creator of MySQL and MariaDB, joining in person.

When: Monday, October 19, 1:30 PM – 5:00 PM (CEST)
Where: VSHN Tower, Neugasse 6, Zürich
Seats: Limited to 40

This is a hands-on technical session, not a sales pitch. VSHN and MariaDB engineers will walk through what MariaDB Enterprise actually adds on top of Community, and what that looks like running in production, live, not in slides.

What we’ll cover

  • A live demo of MaxScale failover and read-write splitting, paired with Enterprise Monitor for visibility into what’s actually happening under the hood
  • A walkthrough of MariaDB Cloud, including AI agents, managed deployment, and how BYOA and BYOC let you bring your own cloud account or provider, including sovereign and non-hyperscaler clouds, into the picture
  • Where AI is heading for databases: RAG, vector search, and what “AI-native” actually means at the data layer, alongside a look at the current state of open source
  • Monty Widenius on migrations, the MariaDB roadmap, and the wider ecosystem, drawing on two decades of building the database many of you already run

Why this matters now

MariaDB Community deployments tend to grow organically, useful until they’re business-critical, at which point questions about support, patching, licensing, and operational risk stop being optional. This workshop is for the people who actually run these systems: a chance to see what closes the gap between “it works” and “it’s operated properly,” and to ask the engineers building it directly.

About Michael “Monty” Widenius, CTO & Co-Founder, MariaDB

Monty has written 95 percent of the server code in MySQL, the predecessor to MariaDB and was previously co-founder at SkySQL, and the CTO of MySQL AB until its sale to Sun Microsystems (now Oracle). Monty was also the founder of TCX DataKonsult AB, a Swedish data warehousing company. Monty was selected as one of the 100 most influential persons in the Finnish IT market and now devotes his time to product development, attending conferences and educating developers.

Bring your questions

Got something specific you want covered, on MaxScale, MariaDB Cloud, migrations, or anything else? Let us know when you register, and we’ll make sure it’s on the table. The session closes with open Q&A, and there’s an Apéro afterwards with plenty of time to talk shop.

Register now for Monday, October 19, 1:30 PM – 5:00 PM at the VSHN Tower, Zürich

Markus Speth

Marketing, Communications, People

Contact us

Our team of experts is available for you. In case of emergency also 24/7.

Contact us
Events General

Recap Cloud Native Computing Meetup September 2026

16. Sep 2026

Yesterday we hosted our Cloud Native Computing Switzerland Meetup at the VSHNtower in Zürich – the latest edition in a series that has been running for nearly a decade now, with over 3,000 members and more than 50 meetups behind us.

It shows: the group currently holds a 4.6 rating from 338 reviews on Meetup, and yesterday’s edition was another good reminder why people keep coming back. Nice people, great talks, and good conversations over the apéro afterwards.

Thank you to our speakers

Benjamin Koltermann (cenroq AG) – How to: securing your clusters. A hands-on look at how Kubernetes clusters can be attacked despite seemingly secure configurations, and how to close those gaps.

Download slides

Chris Bingham (CTO Switzerland, Fujitsu) – Paddelbuch – How Kiro Changed the Game. An update on paddelbuch.ch, the serverless geospatial system for the Swiss paddle sports community, and how an unexpected conversation at AWS re:Invent 2025 reshaped its technical foundation.

Download slides

Christian Blättler (zeitlos.software) – A swiss, cloud-native Alternative to Vercel and Heroku. A deep dive into Lucity, his open-source take on Vercel/Heroku-style developer experience, built on standard Kubernetes and Helm, with “ejectability” as a hard design constraint.

Download slides

Three very different talks, all tied together by the same cloud-native spirit – and plenty of good discussion in the breaks and afterwards at the apéro.

Talk videos

Videos of all talks are on our YouTube channel: vshn.tv – subscribe to get notified.

Next up: November Meetup at Open Systems

Our next CNC Meetup takes place on November 17, 2026, hosted by Open Systems AG in Zürich. We’re still looking for speakers – if you’ve got a cloud-native project, tool, or story worth sharing, submit your talk proposal at cnc-meetup.ch. We’d love to have you on stage.

Markus Speth

Marketing, Communications, People

Contact us

Our team of experts is available for you. In case of emergency also 24/7.

Contact us
Events General Sovereignty Tech

Navigating Open Source at Scale: Why Swiss Organisations Need a Sovereign Database Strategy

15. Sep 2026

MariaDB is everywhere. It ships in countless Linux distributions, powers cloud-native platforms, and runs quietly behind many of the applications organisations rely on every day. That ubiquity is exactly why MariaDB deserves more attention, not less. When community builds move from “good enough” to business-critical, and AI workloads put new demands on the data layer, the risks add up: unsupported versions, unpatched vulnerabilities, licensing ambiguity, and operational friction.

That’s exactly what we tackled in a joint webinar with MariaDB on October 1st. VSHN co-founder Aarno Aukia spoke with Jonas Schwegler from MariaDB about what digital sovereignty looks like in practice: not as a buzzword, but as an architectural decision for your data layer.

Missed it? The recording is now online.

Watch the recording.

What the recording covers

  • How a unified MariaDB Enterprise architecture with MaxScale zero-downtime failover delivers the reliability that compliance requirements demand
  • Why Swiss-hosted OpenShift operations matter when you need a sovereign foundation for AI: RAG pipelines, native vector search, and agentic workloads, without public cloud lock-in
  • How to consolidate transactional, analytical, and AI workloads in a single engine, eliminating the ETL complexity that comes with running separate systems side by side
  • What it means to have your database estate operated natively within Switzerland, with direct access to MariaDB engineering when you need it

Why this matters now

Open source databases give organisations flexibility and control, but only when they’re managed deliberately. Too often, MariaDB community deployments grow organically until nobody knows exactly which version runs where, whether it’s patched, or what happens when it fails at 3 am. Sovereignty isn’t just about where your data lives. It’s about whether you can truly stand behind the reliability, security, and compliance of the systems that run it.

Meet Monty Widenius at the VSHN Tower

On Monday, October 19th, 2026, from 1:30 to 5:00 pm (CEST), we’re hosting a Technical Workshop together with MariaDB at the VSHN Tower in Zürich. Speakers include MariaDB founder Michael “Monty” Widenius, Jonas Schwegler and Anders Karlsson from MariaDB, and Aarno Aukia and Tobias Brunner from VSHN.

What to expect:

  • A live demo of MaxScale and MariaDB Cloud, including BYOA/BYOC
  • Community vs. Enterprise, side by side
  • A real-world customer case study
  • A Kahoot quiz with a prize
  • A closing apéro with time for questions and networking

Seats are limited to 40 people.

Register now for the workshop.

Markus Speth

Marketing, Communications, People

Contact us

Our team of experts is available for you. In case of emergency also 24/7.

Contact us
Events General

Back Again: VSHN at DINAcon 2026

10. Sep 2026

Update, September 22: Two VSHNeers are now speaking at DINAcon 2026 – see below for details on Tobias’s and Aarno’s talks.

On Wednesday, November 18, 2026, the Swiss digital sustainability community meets again at the Kongresszentrum Bern, for another edition of DINAcon. And this year VSHN isn’t just attending, we’re the Apéro Sponsor.

Why we keep coming back

DINAcon is the only conference in Switzerland dedicated entirely to digital sustainability, organized by the nonprofit association CH Open, of which VSHN has long been a member. It brings together people from IT, public administration, politics and civil society who care about the same question we do: how do we make sure digital infrastructure serves people over the long term, not just the next quarter.

We were there the last years too, and it’s exactly this mix that keeps drawing us back: fewer sales pitches, more real conversations about data protection, open source and digital sovereignty with the people actually shaping policy and practice in Switzerland.

Two VSHN talks, back to back

This year we’re also bringing two speakers to the Hodler Souveränität stage, right after each other.

Tobias Brunner – Furniture, Not Lumber: What Sausages, Furniture and Airplanes Have to Do with Digital Sovereignty (14:10-14:30, English)
Tobias takes an unusual route into a familiar problem: why buying cloud services in Europe and Switzerland still feels so different from buying them at a hyperscaler, even when the underlying stack is open source. Expect sausages, furniture and airplanes as unlikely teachers, and a fresh answer to “but it’s all open source, so what’s the problem?”

Aarno Aukia – Sovereignty Is More Than Data Residency: Eight Dimensions for Sustainable Digital Infrastructure (14:35-14:55, German)
Aarno picks up right where Tobias leaves off. Building on the European Commission’s new Cloud Sovereignty Framework, he breaks digital sovereignty down into eight measurable dimensions, from ownership and jurisdiction to supply chain transparency and environmental impact, and turns them into a practical checklist Swiss organizations can actually use for procurement, architecture and open-source strategy decisions.

Together, the two talks make a nice arc: Tobias on why the sovereignty gap exists and feels the way it does, Aarno on how to measure and close it.

Sponsoring the apéro this year

This time around, we’re stepping up as Apéro Sponsor. Once the last talks wrap up, the conference moves into the evening apéro, and VSHN is covering the drinks. It’s a small thing, but it’s exactly the kind of moment where the best conversations happen: hallway chats turning into real discussions over a glass of wine.

Look out for our logo on site and come find us at the bar. If you’re happy with your drink, you’ll know who to thank. 🙂

What’s on the programme

DINAcon 2026 expects more than 300 participants and over 35 talks across four focus areas: AI, public administration, mobility, and sustainable digitalization. The keynote lineup includes Gina Plat from the Open Source Program Office of the Dutch Ministry of the Interior, Florian Dieminger, Senior Engineering Manager at Firefox Enterprise, and Alexander Smolianitski, Head of Open Source Products at Germany’s Zentrum Digitale Souveränität (ZenDiS).

If you’ve been following the digital sovereignty debate, that lineup will look familiar. It’s the same conversation running through most of the events we’ve been part of this year, and it’s exactly the kind of company we want to keep.

Get your ticket

Tickets are available via Eventfrog.

See you in Bern on November 18. Look for our logo and talk to us!

Markus Speth

Marketing, Communications, People

Contact us

Our team of experts is available for you. In case of emergency also 24/7.

Contact us
General

Buying Operations by the Hour: A Bet Against Automation

5. Sep 2026

In July, ISG published a piece for sourcing executives with a line worth reading twice: an application management agreement can be “contractually alive and commercially obsolete.” Their argument is that contracts signed today may still be running in 2030, by which point embedded agents will be doing work that today is billed as human effort, and a contract that measures value in effort will be measuring the wrong thing.

You do not have to believe any particular forecast about AI for the practical half of that to bite. It already bites, and it has nothing to do with agents:

If you pay for operations by the hour, you have hired someone who isn’t motivated to automate, because their revenue drops every time they automate.

That is not an accusation. It is arithmetic, and it is worth understanding before you sign a three-year contract.

Start with the strongest objection

A good provider automates anyway. Reputation is real, clients talk, and nobody survives in Swiss IT services by billing hours for work a script should do. All true.

But this objection treats automation as an attitude. It is an investment, and somebody has to propose it.

Operational quality almost always comes from work done in advance. An alert that stops firing, an upgrade that runs unattended, a restore that is tested rather than hoped for: behind each of those are engineering hours that have to be spent long before they pay for themselves. Under an hourly model, you pay for those hours, and that is fine. The problem sits one step earlier. The provider is the one who has to propose the work, and every such proposal cuts into their future revenue. So the question is not whether they want to automate. It is why they would ever raise it.

Raising it is their move to make in any case. You see your invoice. They see which recurring manual work lies behind it and which part of that could be scripted. A proposal that was never made leaves no trace: no rejected quote, no line in the minutes, nothing you could pick up in a quarterly review. The automation you are missing is the one you never heard about.

Some providers raise it anyway: to win the next contract, because engineers cannot be hired on demand and freed capacity is the only way to grow, or simply because you do not keep good people by having them repeat the same manual work for years. All real. None of it makes automation revenue-positive under an hourly model, though. Revenue-neutral at best, because the hours saved have to be sold to somebody else. And those motives are not yours. They are not in any contract, and you cannot check whether they still hold.

Three ways to pay for operations

Time and materials

You pay for hours. This rewards presence, and it is honest about what it is: you are buying access to people.

It is the right model when you cannot specify the work in advance, which is exactly why it fits consulting and does not fit a running service.

Per ticket, or per incident

You pay for the volume of incidents. This is worse and more common than it should be because it looks like paying for results. It rewards the provider that handles many tickets efficiently, not the provider whose systems generate few tickets. ISG makes the same point from the buyer’s side: the strongest provider may not be the one that resolves the most tickets fastest, but the one that prevents incidents from becoming tickets at all. A per-ticket contract cannot tell those two apart and pays the first one more.

Fixed fee per instance, per service, or per service level

You pay for a running outcome, priced before anyone knows how much work it will take. Now automation moves to the other side of the ledger. Every incident the provider prevents, every upgrade it automates, every alert it tunes out of existence lowers its own cost of delivery, and it keeps the difference. Your price does not move. Neither does your service level. What changes is what the provider is trying to achieve: fewer incidents, rather than more billable hours. That is the alignment you are buying, and it is worth more than the discount you would have negotiated.

This is the model we use for the running operation. Application operations is priced per application and per service level indicator, from CHF 800 per month, so a bad month for your service does not become a bigger invoice. It is also why we can publish the comparison plainly: matching that 24×7 coverage in-house would require four to six engineers at CHF 150,000 to 200,000 per year each, and we deliver the equivalent for less than the cost of half a full-time engineer. That number is only possible because automation is our margin, not our lost revenue.

Be suspicious of anyone claiming their model has no hourly component at all, including us. Our line runs along the layers, and what draws it is authority rather than technology. Platform and infrastructure, meaning the Kubernetes substrate, the managed data services, and the servers, storage, and network underneath, are patched, change-managed, and backed up inside the fixed price. A platform patch that breaks something is ours to fix, so we apply it without asking. Your container image stays yours, because only your test suite knows whether your product survives a bumped extension. Application-specific engineering you ask for on top, such as CI/CD work, observability, or a business continuity test, is quoted separately, and so is consulting.

The usual objection to that is: then our dependencies are our problem. The workable answer is Renovate in your CI/CD. Updates arrive as pull requests, your tests are the gate, your team merges. Automated from your side without moving the decision.

So the distinction that matters is not whether a provider ever bills by the hour. It is whether keeping your service running is billed by the hour. The incentive works on the fixed layer, and that is the layer where most of the work comes from.

How this looks from the outside

You will not see a provider’s pricing model in their behavior. You will see its symptoms. Monthly change freezes. A Jira ticket to add a DNS record. A four-week lead time on a configuration change that takes ten minutes. Those are the artifacts of a process nobody had a commercial reason to automate, and they are common enough in Swiss enterprise IT that “avoid change freezes” is something buyers type into search engines.

These symptoms are not only about missing automation in the background. They are about who is allowed to press the button. A provider can have the DNS change fully automated internally and still make you file a ticket. Automating internally saves them cost. Giving you self-service deletes a line from the invoice. Under an hourly model, there is no commercial reason to do it, and under per-ticket pricing, there is a reason not to.

Be careful with the causation here: blast radius, segregation of duties, and audit obligations are real reasons to route a production change through a control. The question is not whether a control exists. It is whether it is a guardrail or a queue. A guardrail is a pull request with a policy check, an approval, and an audit trail: your team makes the change itself, and the control clears in minutes. A queue is the same claim without the work behind it. Guardrails cost the provider engineering time once and nothing afterward. Queues bill per occurrence.

The same holds for the change freeze itself. Freezes also come from real risk management, audit windows, and thin test coverage, and a well-run provider can have one for good reasons. The question worth asking, therefore, is not whether the freeze exists. It is whether it has been shrinking. A provider whose economics reward automation can tell you that its manual surface is smaller than it was three years ago, and roughly by how much. A provider billing by the hour has no such trend to report, and will usually not have measured it.

“Fixed price just means they cut corners”

The honest form of this objection is that a provider who is paid the same whether they do the work well or badly will drift toward doing it badly.

The answer is that the service-level agreement prices the downside into the provider’s own accounts. Availability commitments and service credits mean that under-investment shows up as a bill the provider pays itself. That is a real mechanism, and it is the reason fixed-fee operations work at all.

It is also the reason a fixed-price project is not the same thing. A project ends. Once it has been delivered, there is nothing left to hold, no credit to claim, and the operating model afterward is your problem. Continuing operations is the only arrangement in which the provider is still standing there in year three when the shortcut it took in year one surfaces.

Where consulting is exactly right

None of this means “don’t hire consultants.” We sell consulting ourselves at CHF 250 per hour, and we are not about to pretend otherwise.

Hours are the correct instrument for a bounded change: an architecture review, a migration, a platform assessment, training your team. The scope is uncertain, the engagement ends, and paying for effort is the only honest way to price something whose shape you cannot know in advance.

The mistake is a category error, not a supplier error. It is buying a continuing operation as an open-ended stream of hours, and then wondering in year two why the same alert keeps firing. Design the change as a project. Buy the operation as a service. Our own partner network runs on precisely this split: consultancies design and build the platform, and we operate it, because carrying 24/7 operations inside a consulting business quietly eats the consulting margin.

The exit question almost nobody asks

Here is the sharpest thing in the ISG piece. Every exit clause you have ever read covers the data. ISG’s version is one step further: can the customer retain the intelligence embedded in the operating model?

After three years of operation, the valuable artifact is not the database dump. It is everything that was learned about running your workload: the runbooks, the alerting thresholds tuned against your actual traffic, the upgrade procedure that survived contact with your extensions, the restore drill, the infrastructure definitions. If all of that lives in a provider’s proprietary tooling, then your exit right entitles you to your data and a fresh start from zero. You will rebuild three years of operational knowledge, and you will rediscover it the same way it was discovered the first time: one incident at a time.

So ask the question directly: is the automation that runs my service open source, and do I get it?

For us the answer has a good shape because the tooling is public. Project Syn and Commodore, which configure and operate the clusters, AppCat, which defines the managed services themselves, and K8up, which runs the backups, are public on GitHub under BSD-3-Clause and Apache-2.0. Your team or a new provider can read exactly how your service is operated, and run the same tooling, without asking us. What operates your service is not a black box you rent, it is a GitOps repository that belongs to you. What exactly changes hands at the end of a contract belongs in the contract rather than in a blog post, but a provider whose automation is proprietary cannot give you a good answer, no matter how the clause is worded.

Where a human still has to decide

ISG’s other useful correction: “human in the loop” is too generic to mean anything. The better question is which decisions require a named human, and it should be answered in writing before the operating model changes, rather than after accountability is disputed.

Reasonable candidates: approving a release into production, granting a security exception, accepting production risk, and calling a major incident. Ask your provider to name theirs. Be suspicious of an answer that is a slogan, and be more suspicious of a provider claiming its operations are autonomous. Ours are not. They are automated, which is a different and more auditable claim, and for a regulated organization, it is the one that survives an audit.

What to ask before you sign

  1. Does my price move with the hours you spend, or with the service I receive?
  2. If you cut your effort on my account by half next year, who keeps the difference?
  3. What do you measure besides availability and time to repair? Anything about prevention?
  4. When I leave, do I get my data, or my data and the automation that ran it?
  5. Is that automation open source, or yours?
  6. Which decisions will always require a named human on your side, and which on mine?
  7. Which parts of this are a bounded project, and which are a continuing operation? Are they priced differently?
  8. How much of what you do for me today was manual three years ago? What changed, and can you show me the trend?
  9. What can my team change without you, and has that list grown or shrunk over the last two years?

ISG is right that the greatest risk is not applications that manage themselves. It is signing a long-term agreement that cannot adapt when they do. The nearer-term version is simpler and needs no forecast at all: do not sign an operations contract that pays your provider not to automate.


VSHN operates open-source infrastructure for regulated Swiss organizations since 2014. We are Switzerland’s first CNCF Kubernetes Certified Service Provider, a Red Hat Premier Certified Cloud and Service Provider, and ISO 27001 certified. The running operation is priced per application and per service level, not by the hour. Get a cost estimate for operating your application.


Sources:

Aarno Aukia

Aarno is Co-Founder of VSHN AG and provides technical enthusiasm as a Service as CTO.

Contact us

Our team of experts is available for you. In case of emergency also 24/7.

Contact us
Events General

More than 50 meetups and counting: the Cloud Native Computing Switzerland meetup returns on 15 September

5. Aug 2026

VSHN has been organising the Cloud Native Computing Switzerland meetup for nearly a decade now. What started as a small group of people trying to make sense of cloud-native technologies and Kubernetes has grown into one of the largest cloud-native communities in the country: over 3,000 members, more than 50 meetups, and a steady stream of people who show up for the talks and stay for the apéros.

The next edition happens on Tuesday, 15 September 2026 at the VSHNtower in Zürich. Register on Meetup while there is still room.

What the meetup is – and what it is not

The CNC Meetup is a neutral place for the Swiss tech community, not an event for sales pitches. We at VSHN, or other companies, provide the room and the apéro and take care of the logistics. The stage, however, belongs to everyone who has something worthwhile to contribute about running things in production. Our speakers so far have come from startups, banks and universities, from cloud providers and from one-person open-source projects.

Entry is free, everyone is welcome from complete newcomers to CNCF maintainers, and the talks are recorded and published on vshn.tv so the content outlives the evening.

Three talks on Tuesday, 15 September 2026

How to: securing your clusters by Benjamin Koltermann (cenroq AG) takes the attacker’s perspective. Everyone wants secure Kubernetes clusters, hardly anyone really achieves it. Benjamin shows how clusters get compromised despite configurations that look solid on paper, and how you can find those gaps before somebody else does.

Paddelbuch: How Kiro Changed the Game by Chris Bingham, CTO Switzerland at Fujitsu, continues a story he started here in 2024: paddelbuch.ch, a serverless geographic information system for the Swiss paddle sports community. Then Kiro came along, and an unexpected conversation at re:Invent 2025 completely changed its technical foundation.

A swiss, cloud-native alternative to Vercel and Heroku by Christian Blättler (zeitlos.software) goes deep into Lucity, his open-source PaaS built on standard Kubernetes and Helm with one hard constraint: you can eject at any time. No database of its own, no CRDs, the entire state is derived from Kubernetes. Ejecting therefore means downloading a Helm chart instead of running a data migration.

All abstracts and the detailed timetable are on the event page.

Practical details

When: Tuesday, 15 September 2026, 15:00 to 18:00, doors open at 14:30 Where: VSHNtower, Neugasse 6, 8005 Zürich Cost: Free, apéro included Register: on Meetup

Our event space has a limited capacity and the last few editions filled up quite quickly, so better register today. And if you have registered but cannot make it, please cancel your registration. That frees up your slot for someone on the waiting list. The recordings land on vshn.tv afterwards, and we will add them to this post once they are online.

We expect all participants to follow VSHN’s Conference Code of Conduct.

Want to speak or sponsor?

Nearly a decade of meetups only happens because people keep volunteering to stand in front of the room. If you are working on something cloud-native and want to talk about it, or if your company would like to sponsor a future edition: send us your idea at cnc-meetup.ch. We are always looking for interesting talks!

Markus Speth

Marketing, Communications, People

Contact us

Our team of experts is available for you. In case of emergency also 24/7.

Contact us
Events General

Back again: VSHN at Swiss Cloud Native Day 2026

4. Aug 2026

On September 17, the Swiss Cloud Native community heads up the Gurten again, for the sixth edition of the Swiss Cloud Native Day. And as in previous years, VSHN is on the sponsor list. We wouldn’t want to miss it.

Why we keep coming back

The Cloud Native Day is not a trade show. It’s organized by the nonprofit association bernerit.rocks, carried by a lot of voluntary work and made for the people who actually run these technologies in production. 250 participants, one day, two tracks, and a funicular up the mountain. Show your conference ticket and the ride on the Gurtenbahn is free.

It’s exactly this mix of engineers, hallway conversations and good mountain air that makes an event we’re glad to support. That’s why we’re back as a sponsor.

Come and see us at our booth

You’ll find the VSHN team at our booth in the Uptown area, right next to one of the two session rooms. Drop by between talks, have a coffee with us and tell us what you’re building.

Good reasons to stop by:

  • You run Kubernetes and want to compare notes on the unspectacular parts: upgrades, backups, on-call, day two.
  • You’re curious how we operate managed services on Swiss infrastructure, for customers who care where their data lives.
  • You just want to say hi to the people behind the VSHN logo. That’s just as welcome. 🙂

Our talk

VSHN also has a sponsor talk at the conference. We’ll announce time, room and topic closer to the event, so take a look at the schedule or simply ask us at the booth.

If you follow the sovereignty debate in Swiss IT, you’ll quickly notice that it runs through this year’s entire programme: confidential computing, the paradox of cloud sovereignty, supply chain security. A good year to have that conversation in person.

It’s also the question behind Servala, the sovereign app store we’ve been building since 2025. What that looks like in practice, and where it still falls short, is something we’re happy to discuss with you at the booth.

And then there’s the evening

The day ends at 17:45 with the closing session, followed by drinks and a party in the Pavillon until 22:00. Bern, a mountain, and the Cloud Native community in good spirits. If you stay only for the talks, you’re missing half of it.

Get your ticket

Tickets are available at cloudnativeday.ch. The organizers also offer discounted tickets for people who contribute to the conference’s diversity or have a lower income. A short message to tickets@cloudnativeday.ch is enough.

See you on the Gurten on September 17. Look out for the Uptown area, the coffee and our logo.

Markus Speth

Marketing, Communications, People

Contact us

Our team of experts is available for you. In case of emergency also 24/7.

Contact us
Events General

Liene at Open Source in Finance Forum London 2026

15. Jul 2026

At the Open Source in Finance Forum London 2026, I took the stage to share lessons from operating a regulated digital asset platform on open, cloud-native infrastructure. The talk was part of the Fluxnova & Platform Automation track and ran on Thursday, June 25, 2026.

The talk

Operating Digital Asset Platforms on Open Infrastructure: Lessons From Regulated Production

Digital asset platforms operate under demanding conditions: strict security requirements, high availability expectations, and increasing regulatory scrutiny. At the same time, engineering teams need to retain the flexibility to evolve their systems as the digital asset ecosystem keeps developing. This was a real-life use case: what worked for us, and what didn’t.

You can find the full slide deck here.

The full recording of the talk is available here.

Two worlds that don’t normally talk to each other

I opened by explaining why I’m the one telling this story. I’ve lived the same tension from two different angles: highly regulated healthcare on one side, fluid open-source ecosystems on the other. Digital asset platforms sit exactly at that intersection – regulated discipline meets open-source speed.

Why digital assets are a different operational challenge

Three pressures make this space harder than typical cloud-native infrastructure:

  • Digital assets are bearer instruments – downtime doesn’t just mean a bad SLA, it means real money at risk.
  • The regulatory ground keeps moving: FINMA today in Switzerland, MiCA rolling out across Europe.
  • The asset universe itself keeps expanding – from crypto to tokenized securities to NFTs to CBDCs – and the platform has to evolve without breaking what’s already live.

As one of our partners, Taurus, put it: “We run on OpenShift, they run on OpenShift – we speak the same language.”

Three patterns we see across regulated financial infrastructure

Pattern 1: Stable core, agile edge. The clearest example is acrevis Bank, where a proven, regulated core banking system (Finnova) stays untouched, while a cloud-native layer on APPUiO/OpenShift, built with Lagoon, iterates fast at the edge – connected through a VPN/API gateway. This isn’t a Strangler Fig pattern. The interface between the two layers is exactly where governance lives. A digital asset platform is, by design, an agile edge – which is why Taurus’s 30+ bank customers all connect digital-asset capability at the edge of a stable core.

Pattern 2: Delegate platform ops, own your core. Everyone focuses on their own layer: banks focus on their business, Finnova focuses on banking software, VSHN focuses on platform operations. After Taurus moved to managed OpenShift, they were operating across 30+ institutions, 9 countries, and 3 continents, with several reclaimed FTEs redirected from platform maintenance to product and global expansion. Delegating platform ops also concentrates the compliance burden onto whoever can carry it best – which is why VSHN holds ISO 27001 and ISAE 3402 Type 2, and operates under FINMA guidelines.

Pattern 3: Evolutionary migration, not big bang. Taurus didn’t start with a fully managed enterprise platform – they grew into it in three deliberate stages: vanilla Kubernetes in 2018, then OKD (community OpenShift), and today, managed Red Hat OpenShift on VSHN. Each step was right for that stage of their growth. The lesson: you don’t need the full managed stack on day one, but you do need to design the handoff path from the start.

Operational practices that make financial-grade infra real

A few practices came up as non-negotiable in this space: biweekly zero-downtime upgrades as policy, not aspiration – because deferred upgrades quietly become security debt and compliance risk. Self-healing infrastructure isn’t just about reliability, it’s a compliance primitive. And certified operators beat DIY, even for something as well-understood as Elasticsearch – using ECK gives you a clean audit trail with no unsupported modifications.

The results speak for themselves: after the move, Taurus went from around 12 customer-impacting incidents per month to zero, with SLA achievement moving from 99% to 100%, driven by 24/7 managed ops, direct Red Hat escalation, and certified operators.

The honest part: what didn’t work

True to VSHN form, I didn’t stop at the success story. A few open questions I’d probe harder with hindsight: did the OKD-to-managed-OpenShift migration happen too late, and what did that interim period actually cost? How do you keep consistency at global scale when multi-geography compliance means different partners in different regions? How do you balance a stable biweekly platform cadence against an ecosystem that moves faster than most enterprise software cycles? And what should an RFP really screen for beyond technical specs – agility, escalation paths, and a willingness to co-design rather than just execute?

Highlights from the forum

A few things stood out over the two days in London beyond my own talk.

Platforms matter, whatever the industry. Whether you’re running infrastructure for finance, healthcare, or somewhere else entirely, the underlying challenges don’t really change. Security, availability, compliance, and the need to move fast without breaking production – these are the same conversations regardless of the label on the regulator’s letterhead.

Open source adoption in regulated industries is accelerating. A few years ago, “open source” and “regulated production” felt like they belonged in different rooms. Not anymore. Banks once feared open source; now their most critical infrastructure runs on it. The appetite for open, auditable, vendor-independent infrastructure in finance is growing quickly, and the questions from the audience reflected that shift – people aren’t asking if anymore, they’re asking how.

AI was everywhere, but it wasn’t everything. Unsurprisingly, AI featured heavily across the sessions. But the forum was a good reminder that solid tooling and honest conversations between people are still what actually gets regulated infrastructure into production. AI can help, but it doesn’t replace the groundwork.

Thank you, London

Thanks to the Linux Foundation and the Open Source in Finance Forum orgnisers for putting together two days of sharp, practical conversation. It’s encouraging to see how seriously the finance sector is now engaging with open source and cloud-native approaches for genuinely critical infrastructure.

Financial-grade open infrastructure isn’t about replacing what works – it’s about building the right fast layer alongside it, and handing the platform to people who live and breathe it. If you’re operating regulated platforms and thinking about how open infrastructure fits into that picture, let’s talk.

Liene Luksika

Product Manager

Contact us

Our team of experts is available for you. In case of emergency also 24/7.

Contact us
General Open Source Press Sovereignty

Sovereign Public Health Infrastructure: The Public Health Authority of Frankfurt Becomes a Global Red Hat Success Story

7. Jul 2026

A German Public Sector Story with Global Reach

We have exciting news to share: Red Hat has published a new global customer success story featuring the Public Health Authority of Frankfurt am Main (Gesundheitsamt Frankfurt am Main) – and VSHN as the platform engineering partner behind it.

After HIN (Health Info Net) became a global Red Hat success story earlier this year, this is now the second time within a few months that a VSHN customer project has been recognized on Red Hat’s global stage. And once again, the topic at the center of it is digital sovereignty in healthcare.

But this story adds a new dimension: it shows how sovereign, open source, cloud-native infrastructure works in the public sector – built for one of the largest public health authorities in Germany, funded by the EU, and shared openly for others to reuse.

Why This Project Matters

The Gesundheitsamt Frankfurt am Main is one of the largest public health authorities in Germany, with 300 employees across 8 departments. Its mission covers everything from pre-school health screenings and vaccination programs to hygiene inspections and public health emergencies.

During the COVID-19 pandemic, a structural problem became painfully visible: the 25 public health authorities in the state of Hesse were working with heterogeneous systems, workflows, and configurations. Sharing data between organizations was difficult – which made tracking infection chains harder than it needed to be.

The answer was not another isolated IT project. With support from the Public Health Authority of Frankfurt am Main, the state health ministry secured EUR 24 million in EU funding to modernize the digital infrastructure of public health in Hesse.

The result is GA-Lotse: an open source platform developed by cronn GmbH and run by VSHN as a managed service on Red Hat OpenShift.

Federated by Design: Sovereignty Down to the Municipality

What makes GA-Lotse special is its architecture. Instead of enforcing a single way of working on 25 different authorities, the team designed a federated, multitenant system.

Each district in Hesse operates its own customizable instance of the platform – with full ownership of its own applications and sensitive data. No private or unauthorized data is shared between departments. At the same time, the state can generate anonymized, aggregated reports for evidence-based decision making.

“We handle people’s most private and sensitive data – their individual health records. This requires strict compliance with data protection and privacy laws, so we have a high bar for data security,”

says Bianca Kastl, Product Owner at the Public Health Authority of Frankfurt am Main.

The platform was built with zero trust architecture and a modular design:

  • 21 modules and 8 separate PostgreSQL databases from the VSHN marketplace
  • Redis for caching and Keycloak for identity and access management
  • A service mesh with standard applications for user management, communication, and calendars
  • Passkeys instead of passwords and nontraceable IDs to prevent unauthorized data access
  • Hosting on Exoscale, a European cloud provider, for GDPR compliance and data sovereignty

Personal IDs are separated from medical records, and all data collected for reporting is anonymized and encrypted. A citizen getting a vaccination can be confident that the team cannot see their full medical history.

From Tender to Production in 3 Months

Public sector IT projects are not exactly famous for their speed. This one was different.

The tender was awarded in August 2024 – and the platform went live just 3 months later. The partnership between VSHN, Red Hat, and Exoscale allowed the team to deliver the platform in days and spend the remaining time on deployment, integration, and testing. That speed was not just nice to have: delivery within a year was a hard requirement to secure the EU funding.

“GA-Lotse and VSHN share a common foundation: openness, transparency, collaboration, open source, cloud-native technology, and the highest regulatory standards. I’m proud to support the digital transformation of such a vital part of our society together with our partners.”

says Aarno Aukia, Co-Founder of VSHN.

A key factor: the public health authorities did not need to become Kubernetes experts. VSHN manages the platform and provides Day 2 operations, so the teams can focus on their actual work.

“Thanks to VSHN and Red Hat, we don’t need to train our teams to carry out complex Kubernetes infrastructure management. They can focus on serving their departments and leave maintenance and development to the experts.”

says Bianca Kastl.

Real Impact on Public Health

GA-Lotse is not a pilot project. It is in production and used by several regions across Hesse today.

Applications like the preschool health screening module replace paper-based processes and help carry out 7,000 health checks and 45,000 dental screenings per year more efficiently. Parents can book preschool health assessments digitally. Hygiene inspections of clinical and corporate settings are scheduled and tracked on the platform.

“Instead of changing how people work, we built a platform that works for them. This real-world solution reflects the realities of the public health system and makes it more efficient.”

says Kastl.

And there is one more aspect we find remarkable: the organization published the solution as open source, including on openCode.de – a first for the German public health sector. Other public health authorities can benefit from the same platform, without starting from scratch.

“Together, we are setting new standards for innovation, digital transformation, and digital sovereignty in public health,”

says Prof Dr. Peter Tinnermann, Head of the Public Health Authority of Frankfurt am Main.

What This Means Beyond Hesse

For us, this success story confirms a pattern we see across Europe: digital sovereignty is moving from theory to practice – and the public sector is leading some of the most ambitious projects.

GA-Lotse demonstrates that sovereign infrastructure for the public sector is achievable today:

  • Open source instead of proprietary lock-in
  • European cloud hosting instead of dependency on hyperscalers
  • Federated data ownership instead of centralized data silos
  • Managed platform operations instead of building scarce Kubernetes expertise in every authority
  • Code published openly instead of duplicated public spending

Together with the HIN story from Switzerland, this shows that sovereign, cloud-native healthcare infrastructure is not a niche experiment anymore. It is running in production, in two countries, serving citizens every day.

A huge thank you to the Public Health Authority of Frankfurt am Main, cronn GmbH, Red Hat, and Exoscale for the excellent collaboration – and to all VSHNeers who made this project possible.

Download the Case Study

Public Health Authority of Frankfurt standardizes on Red Hat with VSHN

Learn More

👉 Red Hat Case Study

👉 HIN: Digital Sovereignty Made in Switzerland

👉 What is digital sovereignty?

👉 VSHN Public Health Authority of Frankfurt Success Story

Markus Speth

Marketing, Communications, People

Contact us

Our team of experts is available for you. In case of emergency also 24/7.

Contact us
General Sovereignty

Why “Buy European” Isn’t Enough: What Switzerland Should Actually Do About Digital Sovereignty

29. Jun 2026

When the EU published its Cloud Sovereignty Framework and awarded EUR 180 million in cloud contracts to four European providers in April 2026, it looked like a clear win for digital sovereignty. But at the Swiss Software Festival 2026 in Basel, UCL economist Cecilia Rikap offered a sharper analysis: geographic sovereignty is necessary but insufficient. The deeper problem is what she calls epistemic capture. “Epistemic” means relating to knowledge and how we define categories. The idea is simple: the fox helped design the henhouse. Hyperscalers shape the rules, definitions, and categories of the sovereignty game even when they appear to lose.

I spoke at the same event about Switzerland’s engineering advantage in the AI era, and I want to connect Rikap’s academic argument to what I see every day operating infrastructure for regulated Swiss organizations: the gap between sovereignty as policy and sovereignty as engineering practice.

The sovereignty framework worked. Sort of.

The EU’s SEAL framework scored providers on eight dimensions. Three pure-European providers achieved SEAL-3. Proximus, whose consortium included Google Cloud (via the S3NS joint venture with Thales), scored only SEAL-2. The framework correctly penalized hyperscaler involvement. We analyzed the framework and scored VSHN against it, a useful exercise for any provider serious about sovereignty.

What matters most about this framework is not the scores themselves. It is that sovereignty is no longer a binary, emotional debate (“are we sovereign or not?”). It is now measurable across eight dimensions that you can discuss, plan, and prioritize. That changes the conversation from ideology to engineering.

But Rikap’s point is that Microsoft, Google, and Amazon were ready for this framework before it was published. They had already structured joint ventures, local subsidiaries, and partnership models designed to score well on sovereignty assessments. The framework didn’t catch them off guard. They helped shape the environment in which it was written.

This is epistemic capture: when the entities being regulated influence the categories, definitions, and priorities of the regulation itself. The result is sovereignty frameworks that address the symptoms (data location, legal jurisdiction) without touching the root cause (control over the technology stack and its development trajectory).

What epistemic capture looks like in practice

Google, Amazon, and Microsoft collectively control roughly 65% of the global cloud market, plus the undersea cables connecting it. Rikap described AI as a “Trojan horse”: organizations adopt AI services that run on hyperscaler infrastructure, creating dependencies that go deeper than where data is stored:

  • Black-box models: you use the API without access to the model weights, training data, or architecture decisions. Your AI strategy depends on a vendor you cannot audit.
  • Ecosystem lock-in: once your data pipeline, ML training, and inference run on a hyperscaler’s stack, switching means rebuilding, not just migrating.
  • Data gravity: AI models need data, data attracts services, services attract more data. This self-reinforcing loop makes AI one of the biggest centralizing forces our industry has seen. The data is already there, the ecosystem of tools is already there, and every new integration makes the next one harder to place elsewhere.
  • Standards capture: hyperscalers fund and staff the standards bodies that define cloud-native computing. The “neutral” standards often embed assumptions that favor their architectures.

A European company running Mistral AI on Azure is not sovereign just because Mistral is French. The AI model sits inside an ecosystem controlled by Microsoft, subject to US law, dependent on Nvidia hardware supply chains.

“Buy European” and “buy Swiss” miss the point

Rikap explicitly warned against replacing US Big Tech with European Big Tech. SAP, Siemens, and Mistral being European does not make them sovereign alternatives in any meaningful sense. They operate the same business models (platform dominance, proprietary lock-in, rent extraction) just with a different flag.

The same logic applies to “buy Swiss.” Switzerland has genuine structural advantages for sovereignty (more on that below), but a Swiss flag on the invoice is not sovereignty. A Swiss company reselling Azure with a local support contract does not give you operational independence. A Swiss SaaS vendor running on AWS eu-central-1 does not protect you from the CLOUD Act. The question is not where the vendor is headquartered. It is whether you can replace the vendor without replacing the technology.

China’s approach (state-orchestrated AI industrialization) is also not a model. As Rikap noted, it “reproduces the logics of US-led predatory ecosystems without challenging them.” Techno-nationalism is not sovereignty, whether the nation is the US, China, or Switzerland.

What actual sovereignty requires

If geographic origin and national champions are insufficient, what does genuine sovereignty look like? Based on Rikap’s analysis and what I see operating production infrastructure for Swiss banks, healthcare providers, and government agencies, three conditions matter:

1. Open-source foundations

Open source is the only technology model where you can verify what the software does, modify it to your needs, and switch operators without rebuilding. The Linux Foundation’s 2025 survey found 83% of companies see open source as valuable for their future. Thomas Wüst (ti&m CEO), also speaking at SSF 2026, described how ti&m migrated their own corporate systems to an open-source stack after seeing vendor lock-in costs escalate.

This is not idealism. It is risk management. When HashiCorp changed Terraform’s license and sold to IBM, the community forked OpenTofu under the Linux Foundation within months. When Atlassian forced Jira customers from Server to Data Center to Cloud, Wüst shared that ti&m saw their license costs rise roughly 900% between 2023 and 2027. Open source makes these forced migrations structurally impossible.

The EU and Switzerland are both moving toward open source as state policy. The Swiss Ständerat accepted a motion for a digital sovereignty impulse program in June 2026. Switzerland already has EMBAG, a federal law in force since 2024, requiring the government to open-source all custom software development unless there is a specific reason not to. The EU’s open-source strategy positions open source as central to technological sovereignty. These are not niche positions. They are emerging consensus.

2. Operational control, not just data location

The EU framework gets this partially right with its “Operational Sovereignty” dimension (SOV-4). But the common market interpretation is “European staff operating in European data centers.” That misses the point.

Operational control means: can you replace the operator without replacing the technology? If your managed Kubernetes runs on Red Hat OpenShift or upstream Kubernetes with documented APIs, you can switch operators. If it runs on Amazon EKS, Azure AKS, or Google GKE, you are using a proprietary control plane with cloud-specific integrations that do not transfer. The Kubernetes API is portable. The managed wrappers around it are not.

This is not a theoretical concern. If you are under FINMA regulation, you must document a process to exit any provider within 12 months, or you are not compliant. Portability is not optional for regulated Swiss organizations. It is a legal requirement.

This is what I mean by “who controls the runtime,” the question I built my SSF keynote around. AI is making code generation nearly free. The marginal cost of writing software is collapsing. But the complexity shifted: it moved to architecture, platforms, and security. The layer that decides your independence is no longer the application code. It is the platform underneath it.

Switzerland has a structural advantage here. The combination of regulated industries (which demand hybrid architectures), open-source fluency, and trusted regional cloud providers (Cloudscale, Exoscale) creates a practical multi-cloud ecosystem where operational portability is the default, not the exception. We have been building this kind of infrastructure at VSHN since 2014, not because sovereignty was fashionable, but because our customers in banking, healthcare, and government required it.

3. Governance over geography

Rikap’s strongest argument: sovereignty is a question of governance and democratic accountability, not territory or nationality. Who decides the technology roadmap? Who has access to the data? What recourse do users have when the platform changes?

For organizations evaluating cloud providers, this translates into concrete questions:

  • Is the provider’s source code auditable?
  • Can you run the same stack with a different operator?
  • What happens to your data and operations if the provider is acquired?
  • Are pricing and terms governed by a stable legal framework (Swiss law, EU law) or by a vendor’s quarterly earnings pressure?

Swiss law provides strong answers to several of these: no CLOUD Act, EU adequacy decision for data protection, stable commercial law. But Swiss law alone is not enough if the technology stack underneath is controlled by a US corporation. Governance requires both legal and technical independence.

The Swiss opportunity, and the Swiss gap

Switzerland is well positioned, but position is not the same as action. At SSF 2026, the recurring theme across all keynotes was that Swiss IT understands sovereignty but has not scaled sovereign alternatives fast enough.

The numbers tell the story. Over 70% of Swiss companies invest less than 5% of their IT budget in AI (ti&m/HSLU AI Maturity Study 2026). Meanwhile, Penny Schiffer from UBS shared that the bank already has over 300 AI use cases live in production and appointed its first Chief AI Officer. The gap between leaders and the majority is widening, and with it the risk that the majority becomes dependent on hyperscaler AI services by default rather than by choice.

The practical next step is not to wait for regulation or national champions. It is to build on what already exists: open-source software, Swiss-operated infrastructure, and engineering teams with the judgment to design platforms that no single vendor controls.

Switzerland has been building precision machinery for centuries. The next machine to build is the sovereign platform: open-source, multi-cloud, operationally portable, and governed by Swiss law. The components exist. The engineering talent exists. What is missing is the decision to assemble them.

The question is not which cloud you choose. It is whether your architecture gives you that choice tomorrow. If you are a dependent, you have to ask permission. If you are sovereign, you can ship.


VSHN operates open-source infrastructure for regulated Swiss organizations since 2014. We are Switzerland’s first CNCF Kubernetes Certified Service Provider, a Red Hat Premier Partner, and a Linux Foundation Silver Member. Our managed services run on Swiss cloud providers with Swiss law, open-source foundations, and no hyperscaler dependency. Book a consultation to discuss your sovereignty requirements.

Aarno Aukia

Aarno is Co-Founder of VSHN AG and provides technical enthusiasm as a Service as CTO.

Contact us

Our team of experts is available for you. In case of emergency also 24/7.

Contact us
Events General Sovereignty

Switch Cloud Forward Forum Day 2026 Recap

Sovereign cloud, real-world use cases, and a room full of Swiss higher education decision-makers

On June 23rd, VSHN was at the Cloud Forward Forum Day 2026 in Bern – an event organized by Switch for IT leaders, procurement specialists, and strategists from Swiss universities and research institutions. The topic: how to make public cloud work for Swiss higher education, without sacrificing sovereignty, compliance, or flexibility.

VSHN showed up twice – once with a use case from the health sector, and once on stage with a short elevator pitch. Here’s what the day looked like.

The bigger picture: AI, sovereignty, and the pressure to modernize

The day opened with a keynote from Marc Stampfli (NVIDIA), framing the current moment as an industrial revolution driven by intelligence – and raising the question of what sovereignty means when AI infrastructure is concentrated in a handful of global providers. It set the tone for everything that followed: institutions want to move fast, but not at the cost of control over their data.

Elevator pitches: fast takes, sharp angles

The mid-morning elevator pitch session gave a handful of speakers three minutes each to make their case. VSHN CEO Aarno Aukia took the stage with a single, sharp argument: sovereignty is no longer a philosophy – it’s a procurement criterion with a price tag attached.

His reference point was a EUR 180M cloud contract awarded by the EU Commission in April 2026, scored across eight sovereignty dimensions – supply chain (20%), strategic (15%), operational (15%), and technology (15%) among the highest-weighted. The real-world consequence: the Thales/Google joint venture cost Proximus a full SEAL level compared to pure-European competitors. Sovereignty now translates directly into contract wins and losses.

VSHN self-scores at SEAL-3 – the same level as the EU’s three strongest winners in that procurement. For an audience of Swiss higher education decision-makers thinking about cloud vendor selection, the message landed at exactly the right moment.

HIN: sovereign cloud for health data, built on Exoscale and VSHN

The morning use case session that resonated most with VSHN’s work came from Mohammad Alavi of Health Info Net (HIN). HIN is one of Switzerland’s largest providers in the health sector, and Mohammad walked the audience through a challenge many institutions share: how do you build a modern, scalable cloud platform for sensitive data when regulations are incomplete and the stakes are high?

HIN’s answer was to fill the regulatory gap themselves – setting their own principles for security and data privacy, then building a sovereign cloud platform together with Swiss partners Exoscale and VSHN. The result is a platform that not only hosts HIN’s own services securely, but also enables HIN community members to run their own applications on the same infrastructure.

It’s a strong example of what platform engineering can unlock in regulated industries: not just compliance, but genuine capability for others to build on top. Read the full story in our HIN success story.

Other use cases from the day

The afternoon sessions rounded out the picture with a range of perspectives. AWS, Sparkle, and Netcloud explored privacy and compliance as enablers of sovereignty. SoftwareOne made the case for Google Workspace as a practical complement to Microsoft 365 in higher education environments. And the Switch Cloud session featured an experience report from FHNW and Swiss Learning Hub on deploying Evento – a campus management system used by many Swiss universities of applied sciences – into the Switch Cloud, including the stumbling blocks and early-adopter lessons that came with it.

Bechtle also presented an AI-powered data access project from the Universitäre Altersmedizin FELIX PLATTER in Basel, where Azure OpenAI Services and Microsoft Fabric are being used to let researchers query clinical data using natural language – an example of how AI is finding its way into very practical, regulated workflows.

What we took away

Cloud Forward is a focused event – not a big trade show, but a room where Swiss higher education institutions compare notes on real decisions. The recurring theme across sessions was that sovereignty isn’t just a compliance checkbox: it’s a design principle that shapes architecture, partner selection, and long-term flexibility.

That’s exactly the kind of platform thinking VSHN brings to customers like HIN – and the conversation we want to keep having with Swiss institutions navigating the same challenges.

Curious how a sovereign, Kubernetes-based cloud platform could work for your organization? Let’s talk.

Markus Speth

Marketing, Communications, People

Contact us

Our team of experts is available for you. In case of emergency also 24/7.

Contact us
Events General

Swiss Software Festival Basel 2026 Recap

25. Jun 2026

The Swiss Software Festival was back in Basel on June 24th 2026 – and the second edition delivered on everything the first promised, and much more. Around 650 people gathered at uptownBasel in Arlesheim to talk about software, platforms, and the forces fundamentally reshaping our industry: AI and Sovereignty. VSHN was back as a Matterhorn Sponsor, and didn’t just attend – we once again actively helped shape the program.

A festival that has found its rhythm

The second edition of any event is always a litmus test. The first year runs on excitement. The second shows whether there’s really something behind it. The Swiss Software Festival 2026 answered that question clearly: more attendees, more energy, and a program that genuinely feels well thought through. At uptownBasel in Arlesheim, there was life from the very first moment – with conversations in the hallways that carried on well into the evening.

Outside it was unusually hot for a June day in Basel. Anyone looking to cool down knew where to go: the joint VSHN and Red Hat booth was the most refreshing spot in the building. A good reason to stop by, strike up a conversation, and find out what we’re building right now.

Aarno on the main stage: digital sovereignty is not optional

VSHN founder Aarno Aukia took the plenary stage to make the case for digital sovereignty – not as a compliance obligation, but as a genuine architectural decision every engineering team faces today. In a world where AI pulls organizations toward convenience and speed, Aarno’s keynote was a sobering counterpoint: the question of where your platform runs, who controls it, and whether you can trust it is no longer just a legal question. It’s an engineering question.

Aarno also joined a panel discussion that went even deeper – into the tensions between open ecosystems and sovereign infrastructure. The questions were pointed, a sign that the topic is no longer abstract for most teams in the room.

Watch Aarno’s keynote:

Tech Track 2: Platform Engineering under pressure

VSHN’s Markus Speth chaired Tech Track 2 – Platform Engineering and Software Architecture – together with co-chairs Andreas from ti&m and Florian from Abacus Research. The track covered two full sessions on the two forces currently pulling platform engineering in opposite directions: AI and Sovereignty.

AI wants speed and flexibility. Digital sovereignty wants control and transparency. Your platform is caught in the middle.

The morning session focused on AI-native platforms: what does it mean when software rewrites itself, when agents gain access to infrastructure, and where is the competency gap quietly growing? Eficode, White Duck, Noser Engineering, and Adobe brought hands-on experience from systems where AI isn’t a feature – it’s part of the foundation. Both sessions closed with open discussion rounds that the audience engaged with intensely. A big thank you to all participants and the many great questions!

The afternoon put sovereignty and openness center stage as genuine architectural decisions. VSHN’s Tobias Brunner opened with a talk you won’t forget quickly: “Furniture, not lumber: what sausages, furniture and airplanes have to do with digital sovereignty.” The analogy landed perfectly – a memorable and surprisingly precise way to explain why not all sovereignty promises are worth the same, and what it really means to build on infrastructure you can trust. Speakers from PHOENIQS, Abacus Research, and ti&m rounded out the session with different perspectives on why open infrastructure decisions carry consequences that go far beyond vendor lock-in.

We were especially pleased to see Mohammad Alavi from HIN (Health Info Net) – a VSHN customer – speak in the festival’s dedicated Sovereignty Track. Watching a customer take the stage to share real-world sovereignty challenges in the Swiss healthcare sector was one of the highlights of the day, and a reminder that this conversation is anything but abstract for the organizations we work with.

And the Lego goes to…

No VSHN event appearance is complete without a Lego giveaway. This time we raffled a Lego Harry Potter set – and the winner is Daniel Haß. Congrats Daniel, enjoy the build! 🧱

See you next year

The Swiss Software Festival is establishing itself on the Swiss tech calendar. It doesn’t aim to be a huge conference – it aims to be a good one. With 650 attendees, a carefully curated program, a truly great venue, and compelling conversations, it succeeds.

Thanks to Swiss Made Software for a fantastic second edition, and to everyone who stopped by the booth, attended Tech Track 2, or caught Aarno and Tobias on stage.

See you in 2027!

Markus Speth

Marketing, Communications, People

Contact us

Our team of experts is available for you. In case of emergency also 24/7.

Contact us
Events General

Win tickets to Swiss Software Festival 2026

15. Jun 2026

The Swiss Software Festival is back for its second edition – and this year, we are giving away tickets. Read on to find out how to win, and what VSHN is bringing to Basel on June 24th 2026.

Back in Basel: Swiss Software Festival returns for its second edition

When the Swiss Software Festival launched last year, it immediately established itself as one of the most relevant gatherings for the Swiss software industry – a full-day event bringing together engineers, software architects, product leaders, and decision-makers under one roof. VSHN was there from the start as a Matterhorn sponsor, and the first edition delivered on its promise: great talks, real conversations, and a crowd genuinely invested in the future of software in Switzerland.

This year, the festival returns to Basel for its second edition, with up to 700 attendees expected and an even stronger program spanning plenary sessions, leadership panels, and dedicated tech tracks. We are proud to be a Matterhorn sponsor again – and this time, VSHN is not just attending but actively shaping what happens on stage.

Win tickets to Swiss Software Festival 2026

To share the excitement with our community, we are giving away 5 festival tickets. To enter the draw, simply subscribe to VSHN News, our monthly newsletter, below. That’s it.

Winners will be drawn on Wednesday, June 17th at 4 pm CEST. The competition closes at that moment, so make sure you are subscribed before then.

Subscribe to VSHN News to win

Update: the winners have been drawn and they are informed, congratulations!

What VSHN is doing at the festival

Beyond sponsoring, VSHN is deeply embedded in this year’s festival – from the Advisory Board, where Aarno serves as a member, to the plenary stage, the tech tracks, and the track chair role.

Aarno Aukia – keynote on digital neutrality

Aarno Aukia takes the plenary stage for the closing session, Digital Sovereignty: What’s next? His keynote is titled Digital Neutrality: Switzerland’s Engineering Advantage in the AI Era. Digital sovereignty has moved from a niche concern to a mainstream political and business priority – and Switzerland has a distinctive position in that debate. Aarno will lay out what that means in practice, followed by a leadership panel featuring voices from Microsoft, BSI Software, DeepCloud, Xelon, and the Swiss National Council.

Tobias Brunner – talk on platforms and ecosystems

Tobias Brunner speaks in Tech Track 2: Platform Engineering & Software Architecture. His talk, From platforms to ecosystems – why software innovation is a team sport, explores how platform thinking is maturing beyond infrastructure tooling. Building a platform is one thing – turning it into a thriving ecosystem where teams, partners, and products can grow together is another challenge entirely, and one that sits at the heart of what VSHN does every day.

Markus Speth – track chair Tech Track 2

Markus Speth is serving as Track Chair for Tech Track 2: Platform Engineering & Software Architecture. The track covers the full stack of modern platform engineering – from Kubernetes-based control planes and internal developer platforms to distributed AI workloads and multi-cloud runtime strategies. It is exactly the terrain VSHN operates in, which is why we were glad to help shape it.

About Swiss Software Festival 2026

The Swiss Software Festival is conceived and organized by Swiss Made Software and takes place in Basel. Now in its second year, the festival has quickly become a fixture in the Swiss tech calendar – a place where the people building Switzerland’s digital future come to exchange ideas, challenge assumptions, and find their next collaborators. With up to 700 attendees and a program built around both leadership perspectives and deep technical content, it is a rare event that works equally well for engineers and executives.

Don’t miss your chance to join us there – subscribe to VSHN News before June 17th at 4 pm for a chance to win your ticket.

We promise you no ads or any other nonsense – just exciting news about VSHN and the VSHNeers.

Markus Speth

Marketing, Communications, People

Contact us

Our team of experts is available for you. In case of emergency also 24/7.

Contact us
General Open Source Sovereignty

Open Source as State Policy: What the EU Strategy and the Swiss Ständerat Vote Mean for IT Decision-Makers

12. Jun 2026

In the span of a few weeks, two policy signals landed that reinforce each other. The European Commission published a new open-source strategy positioning open source as central to EU technological sovereignty. Days later, the Swiss Ständerat accepted a motion for an impulse program on digital sovereignty by 30 to 7, against the Bundesrat’s recommendation. Both name the same mechanism: open-source technology as infrastructure for sovereign, independent digital states.

For Swiss organizations choosing technology stacks and cloud providers, the direction is now unmistakable.

What the EU strategy says

The Commission’s open-source strategy pursues four goals:

  1. Technological sovereignty through open source: scaling European open alternatives to non-EU proprietary solutions, including in digital identity wallets and public services.
  2. Ecosystem development: supporting startups, establishing stewardship frameworks, creating a maintenance instrument for critical open-source projects, and investing in skills.
  3. Public administration leadership: developing open-source procurement guidelines and strengthening the Commission’s Open Source Programme Office (OSPO).
  4. Standards and international cooperation: integrating open-source communities into EU standardization efforts.

The strategy takes a full lifecycle approach: from research through long-term maintenance. It explicitly names the goal of reducing dependence on non-EU technologies and increasing European control over “critical digital infrastructure, including software and hardware systems.”

This is not an abstract policy paper. It follows the EUR 180 million sovereign cloud procurement in April, where open-source technology was one of eight scored sovereignty dimensions. Open source is moving from “nice to have” to procurement criterion.

What the Ständerat decided

On June 10, the Ständerat accepted motion 22.3221 by Heidi Z’graggen (Die Mitte, Uri) calling for an impulse program to strengthen Swiss digital sovereignty. The motion demands seed funding for pilot projects in four areas:

  • Digital infrastructure
  • Open-source technologies
  • Cybersecurity
  • Artificial intelligence

Z’graggen argued that digital sovereignty is “ein zentraler Pfeiler sowohl staatlicher als auch wirtschaftlicher Handlungsfähigkeit” (a central pillar of state and business capability). She emphasized this is time-limited stimulus, not permanent state expansion: “Investitionen in offene, souveräne Technologien stärken unsere Innovationskraft, reduzieren Abhängigkeiten, schaffen Wertschöpfung” (investments in open, sovereign technologies strengthen innovation, reduce dependencies, create value).

The Parldigi parliamentary group backed the motion, citing the geopolitical situation and open source’s cost-saving potential.

Federal President Guy Parmelin recommended rejection, arguing existing strategies and funding instruments (including the “Digitale Schweiz 2026” program) already address digital sovereignty. The Ständerat disagreed, 30 to 7.

The motion now goes to the Nationalrat.

Switzerland already has the legal foundation

What makes the Ständerat vote notable is that Switzerland already has open-source legislation. The EMBAG (Bundesgesetz über den Einsatz elektronischer Mittel zur Erfüllung von Behördenaufgaben), in force since January 1, 2024, establishes:

  • Open Source by default: the federal administration must release self-developed software as open source.
  • Open Government Data: administrative data must be made accessible for free use.
  • Interoperability and open standards: interfaces must be documented and standards can be made binding.

The EMBAG was championed by National Council members Gerhard Andrey and Andri Silberschmidt, and Ständerat member Matthias Michel. When it passed, Switzerland became one of the first countries worldwide to mandate open-source publication of government software.

But a law that mandates release of government-built software is not the same as a program that funds new sovereign infrastructure. The EMBAG says “publish what you build.” The Z’graggen motion says “invest in building more.” The two are complementary: the legal framework exists, but the Ständerat believes implementation needs an impulse.

Two signals, one direction

Read together, the EU strategy and the Swiss vote point to the same conclusion:

EU Open Source StrategySwiss Ständerat Motion
ScopeEU-wide policy frameworkSwiss federal impulse program
MechanismProcurement criteria, OSPOs, maintenance fundingSeed funding for pilot projects
Open source roleCore sovereignty instrumentOne of four priority areas
StatusPublished strategyAccepted by Ständerat (30:7), Nationalrat pending
Legal basisBuilds on Cyber Resilience Act, Interoperable Europe ActBuilds on EMBAG (in force since 2024)

The convergence is not coincidental. Both respond to the same pressures: dependence on US hyperscalers, the CLOUD Act, supply chain risks exposed by geopolitical shifts, and the realization that digital sovereignty requires more than data residency. It requires control over the software stack.

What this means for Swiss organizations

Open source is becoming a compliance expectation, not just a technical preference. The EU scores it in cloud procurement. Switzerland mandates it in government software. Both are moving toward procurement frameworks that favor open, auditable technology over proprietary lock-in.

Public sector demand will grow. If the Nationalrat passes the Z’graggen motion, federal funding for open-source pilot projects will follow. Organizations positioned to deliver sovereign, open-source infrastructure, and to help public sector clients adopt it, have a structural advantage.

The EMBAG creates upstream supply. As the federal administration releases more open-source software, the ecosystem of Swiss-built, Swiss-maintained open-source components grows. This benefits private sector organizations that build on the same stack.

Geopolitical risk is now a board-level topic. Z’graggen’s core argument (dependence on foreign technology providers endangers long-term competitiveness) is the same argument regulated industries have been making for two years. The Ständerat vote gives it political legitimacy beyond the compliance department.

Where VSHN fits

VSHN has operated on the thesis that open source and sovereignty are inseparable since its founding. Every service in the VSHN Application Catalog runs on open-source software (PostgreSQL, MariaDB, Redis, Keycloak, GitLab, OpenBao, Forgejo), operated by a Swiss team on Swiss infrastructure.

The policy direction confirmed by both Brussels and Bern validates this approach:

  • Technology sovereignty: 100% open-source stack, active contributor to CNCF projects (K8up, Crossplane providers), Project Syn, and APPUiO.
  • EMBAG alignment: VSHN’s entire toolchain is open source and auditable. Government clients adopting VSHN services remain EMBAG-compliant without additional effort.
  • Operational sovereignty: Swiss 24/7 operations team, infrastructure-agnostic deployment (customer chooses provider), no foreign vendor dependency.

For organizations evaluating their technology stack against the direction set by EU and Swiss policy, the question is: does your infrastructure depend on a foreign vendor’s proprietary platform, or is it built on open, sovereign technology that you control?

Sources

Aarno Aukia

Aarno is Co-Founder of VSHN AG and provides technical enthusiasm as a Service as CTO.

Contact us

Our team of experts is available for you. In case of emergency also 24/7.

Contact us
Events General

Cloud Native Zürich 2026 Recap

Another great edition of Cloud Native Zürich is behind us. Across the two interconnected venues, Abaton and Soho Zürich, more than 400 attendees – platform engineers, Kubernetes practitioners, developers, operators, and open source enthusiasts – came together for a day of learning, networking, and discussion across four tracks, including a dedicated Sovereignty Track for the first time.

VSHN was proud to participate once again as a Silver Sponsor, while Servala sponsored the Sovereignty Track.

VSHN booth with Legos 🙂

If you stopped by our booth, thank you for the great conversations – on Kubernetes and OpenShift, platform engineering, digital sovereignty, Servala, APPUiO, Codey, and the European cloud native ecosystem more broadly. And yes, the LEGO sets found new owners again this year. 🙂

On stage

Beyond the booth, we were also happy to actively contribute to the program this year:

Tobias Brunner gave a talk on how Servala came to be – from an internal observation at VSHN that our managed services lacked the marketplace experience customers were used to from the hyperscalers, to where Servala is heading as a growing ecosystem of cloud providers, software vendors, managed service providers, and implementation partners.

Aarno Aukia spoke about running LLMs the cloud-native way – building an open-source LLM stack on Kubernetes with tools like Kubeflow, vLLM, LiteLLM, and llm-d, and why that matters for sovereignty, compliance, and long-term operational control.

And in the new Sovereignty Track, Markus Speth was track lead and moderated a panel discussion with perspectives from across the ecosystem – an implementation partner, a cloud provider, a managed service provider, a software vendor, and civil society. We wrote a separate recap of that panel, which you can find here: Digital sovereignty – perspectives from the ecosystem.

A strong keynote

We were also looking forward to seeing keynote speaker Thomas Zurbuchen live again – always a highlight, and a reminder that the questions our industry is grappling with are part of much bigger conversations.

Data centres in space?

Thomas Zurbuchen also briefly raised the idea of operating data centres in space. He suggested that the economics could shift in the coming years – on the one hand due to rising energy costs on Earth, and on the other hand due to declining costs and efficiency gains in “getting payloads into space”.

The assessments of this idea diverged significantly afterwards. While it attracted a lot of attention, both the underlying economic assumptions and the claim that such systems would be “safer” in space than on Earth were discussed in further conversations during the aperitif and were viewed quite critically from different perspectives.

But actually, it would be quite a funny thought – just imagine someone saying “I quickly have to change a disk” and watching the engineer get launched into space… 🙂

Thanks to the organizers

A big thank you to the Cloud Native Zürich organizing team for putting together another excellent event – the level of detail, the community spirit, and the quality of the program keep getting better every year. If you couldn’t make it, or want to revisit a talk you missed, recordings will be published on the official Cloud Native Zürich channels – keep an eye on cloudnativezurich.ch for updates.

Want to be part of the ecosystem?

If digital sovereignty, sovereign managed services, or the broader Servala ecosystem are topics on your mind – check out Servala, and feel free to get in touch if you’d like to become part of our growing ecosystem of cloud providers, software vendors, and implementation partners.

See you next year!

Markus Speth

Marketing, Communications, People

Contact us

Our team of experts is available for you. In case of emergency also 24/7.

Contact us
General Sovereignty

Digital sovereignty – perspectives from the ecosystem

Yesterday at Cloud Native Zürich 2026, we had the chance to moderate a panel discussion in the Sovereignty Track titled “Digital Sovereignty – Perspectives from the Ecosystem.” Five panelists, five very different angles on the same topic – and a room full of people who were interested in Digital Sovereignty.

Setting the scene

The panel didn’t happen in isolation. It came at the end of a morning packed with sovereignty content: David Sterz opened the track making the case that Europe’s cloud future should be distributed by design rather than mirroring the centralized hyperscaler model. Our own Tobias Brunner followed with a talk that connected Swiss sausages (“Cervelat”) to sovereignty – and made a convincing case for why “it’s all open source anyway” is not the same as sovereignty. Pascal Stöckli then introduced Zentrum SDS, the new “Souveräne Digitale Schweiz” initiative bringing together 32 founding organizations from federal authorities, cantons, and Swiss IT companies.

By the time the panel started, the room had already heard that digital sovereignty is distributed, political, operational, and – apparently – has something to do with Cervelat. The panel’s job was to pull these threads together from the perspective of the people actually building, running, and governing this ecosystem.

Five seats, five perspectives

We deliberately put together a panel that covered the ecosystem end to end:

  • Lena Fuhrimann (bespinian) – the implementation partner’s perspective, working directly with organizations migrating to cloud native technologies and helping them balance innovation, agility, and control.
  • Roman Bachmann (Switch) – the cloud provider’s perspective. Switch operates digital infrastructure for Swiss universities and research institutions and is itself owned by the institutions it serves – sovereignty by design, in a sense.
  • Tobias Brunner (VSHN) – the managed service provider’s perspective, on what it actually takes to make digital sovereignty operational: running production systems around the clock, not just writing about it.
  • Simon Reber (Red Hat) – the software vendor’s perspective, on how open source contributes to flexibility, interoperability, and sovereignty – and where the limits of that argument are.
  • David Sommer (Digitale Gesellschaft) – the civil society perspective, broadening the conversation from technology toward democratic rights, political will, and a digital society that works for everyone.
  • Markus Speth (VSHN) – moderator

What we explored

Before diving into the discussion, we asked the audience a simple question: how many of you have used the term “digital sovereignty” in the past six months? Not surprisingly, almost every hand went up.

From there, we asked each panelist for their own definition – and got five genuinely different answers, ranging from technical and operational framings to questions of control, resilience, and democratic values. No single definition won, which was rather the point.

The discussion then moved into more concrete territory: how sovereignty shows up in day-to-day project work working with customers, what it means for a cloud provider to be “sovereign by design”, what it takes to run sovereign infrastructure in production 24/7 rather than on a slide, whether open source is sufficient on its own or just one part of the equation, and where the real blockers sit – in technology, in budgets, or in how organizations make decisions.

We also didn’t shy away from some of the harder numbers floating around this debate: the gap between what European IT leaders say they want to spend on local cloud alternatives and what they actually spend, and the sheer scale difference between hyperscaler investment and the European alternatives currently on the table.

A few things that stuck with us

Reflecting on the discussion afterwards, a few themes stood out:

Digital sovereignty is not a binary state. There’s no certificate that flips an organization from “not sovereign” to “sovereign” – it’s a spectrum across multiple dimensions, and frameworks like the EU Cloud Framework are starting to emerge specifically to measure that.

It’s also about more than where data physically lives. Control, portability, transparency, skills, governance, and legal jurisdiction all play a role – often a bigger one than location alone.

Complete sovereignty, in the sense of controlling everything end to end, is neither realistic nor desirable. Trace any dependency chain far enough and you eventually hit hardware, raw materials, and global supply chains that no single organization – or country – fully controls. The more useful goal is understanding your dependencies and making conscious choices about them.

And perhaps most importantly: sovereignty isn’t something any single company, vendor, or government can solve alone. It needs the whole ecosystem – providers, vendors, open source communities, public institutions, and civil society – all working together.

Which brings us back to a question we asked at the start: is “sovereignty” even the right word? Maybe what most organizations are really after is resilience, autonomy, or freedom of choice, or simply the ability to make their own decisions without having to ask someone else for permission first.

One phrase from our preparation for this panel stayed with us: “sovereignty is a bridge, not a bunker”. The goal isn’t isolation – it’s the freedom to choose your own path while staying connected to a broader ecosystem.

Unfortunately, our time on stage ran out far too quickly. There were so many more angles we could have explored – and judging by the energy in the room, the audience felt the same way.

We’re already thinking about a follow-up session to dig deeper into some of these threads.

Watch the full discussion

The recording of the full panel discussion will be published soon – we’ll share the link as soon as it’s available, so you can hear all five perspectives directly from the panelists themselves.

A big thank you to Lena, Roman, Tobias, Simon, and David for a genuinely thoughtful discussion.

Thanks to the organizers of Cloud Native Zürich

A big thank you to the organizers for putting together another great edition of Cloud Native Zürich. We were happy to be involved as sponsors again – VSHN as a Silver Sponsor, and Servala sponsoring the Sovereignty Track at Cloud Native Zürich 2026.

As part of the track, our colleague Tobias Brunner also held a talk on Servala earlier in the day – we’ll be publishing that recording soon as well, so stay tuned.

If you’re curious about what Servala is and how sovereign, multi-provider managed services on Kubernetes can look in practice – check out Servala – Sovereign App Store, and feel free to get in touch if you’d like to become part of our growing ecosystem.

Also check out our full Cloud Native Zürich 2026 Recap.

Markus Speth

Marketing, Communications, People

Contact us

Our team of experts is available for you. In case of emergency also 24/7.

Contact us
General Press Servala Sovereignty

Switch joins Servala as Cloud Service Provider to strengthen Switzerland’s digital sovereignty

10. Jun 2026

Switch joins Servala as Cloud Service Provider to strengthen Switzerland’s digital sovereignty

Press release: Zurich, Switzerland – June 10th, 2026

VSHN and Switch are pleased to announce a new partnership: Switch is joining Servala as a Cloud Service Provider (CSP), expanding its ecosystem of sovereign managed services in Switzerland.

The Switch foundation is a key pillar of Switzerland’s digital sovereignty. As the operator of the Swiss National Research and Education Network (NREN), Switch connects universities, and research institutions nationwide and beyond. In addition to its network backbone, Switch provides digital identity solutions, cyber security, cloud services, procurement and collaboration services to research and education institutions – forming a cornerstone of digital innovation in academia.

With around 180 employees and decades of experience, Switch plays a central role in providing secure, reliable, and high-performance digital platforms and critical infrastructure for the Swiss education and research community.

By joining Servala, Switch is extending its portfolio of cloud services to include access to a growing ecosystem of cloud-native managed services. These services can be deployed and operated in a standardised, automated, and production-ready way – aligned with the needs of universities and research institutions that require reliability, scalability, compliance, and long-term sustainability.

ROMAN BACHMANN, Head of Cloud & IT, ad interim, Switch: “By integrating Servala, we are responding to our customers’ frequent requests to be able to provision a managed database, cache or queue at the touch of a button. This way, we are expanding our Switch Cloud service portfolio with key services that are indispensable in modern software development.”

The partnership comes at a time of increasing demand for sovereign digital infrastructure in Switzerland. Organisations are looking for alternatives that combine modern cloud capabilities, providing local control, transparency, and independence from global hyperscalers at the same time.

This is where Servala comes in.

Servala connects Swiss cloud providers, software vendors, and service operators into a collaborative ecosystem. This model allows for greater flexibility, resilience, and innovation – while keeping data and operations under local control.

Servala creates shared value across the entire community:

  • Universities and research institutions gain access to modern, production-ready services tailored to their needs
  • Organisations retain freedom of choice and avoid vendor lock-in
  • Swiss providers collaborate and combine their expertise instead of operating in isolation
  • The Swiss education area is strengthened through local innovation and trusted partnerships

TOBIAS BRUNNER, Product Manager & Partner, VSHN: “What excites me most about this partnership is the shared values. Switch and VSHN have both built their reputation on trust, reliability, and a long-term perspective – not on lock-in. By joining Servala, Switch helps us demonstrate that Swiss providers can collaborate and innovate together, for the benefit of the entire ecosystem.”

For Switch, this partnership marks a step towards evolving its service offering to include cloud-native platforms and managed services. For VSHN and the broader Servala ecosystem, Switch is a strong new partner deeply rooted in the Swiss education and research sector.

Both organisations have already started working on an initial Servala minimum viable product (MVP) tailored to the Switch community. Early interest from universities and research institutions highlights the demand for sovereign, easy-to-access services.

About Servala
Servala is the sovereign application platform connecting cloud providers, software vendors, managed service providers and implementation partners to deliver cloud-native services without vendor lock-in. Built on open standards and designed for interoperability, Servala enables organizations to deploy and operate applications across multiple clouds and on-premises environments in a consistent and automated way.

At its core, Servala is not a single provider, but an ecosystem. It brings together Swiss and European partners who combine their infrastructure, software and operational expertise to deliver fully managed services. This collaborative model ensures transparency, flexibility and long-term independence for customers.

With a strong focus on digital sovereignty, Servala allows organizations to retain full control over their data, workloads and technology choices while benefiting from modern platform engineering practices, automation and scalable operations.

Servala was initiated by VSHN and is developed in close collaboration with ecosystem partners. The platform brings together services operated by multiple providers, including VSHN and other independent partners.

About Switch
Switch is the digitalisation partner for Swiss universities. The foundation collaborates with educational and research institutions to develop secure and future-oriented digital platforms and critical infrastructure. Its activities are focused on strengthening cyber security, the universal use of digital identities and sovereign cloud solutions. Switch has also operated and protected domain names ending in .ch and .li since the early days of the Internet. The non-profit foundation employs around 180 people in Zurich and Lausanne.

About VSHN
VSHN – The DevOps Company – transforms software into reliable online services by automating and operating application workloads. As Switzerland’s leading Managed Service Provider, VSHN specializes in DevOps, Kubernetes, OpenShift, and cloud-native operations, enabling organizations to run business-critical applications reliably, securely, and at scale.

VSHN provides platform engineering, 24/7 operations, and fully managed services across public cloud, private cloud, and on-premises environments – without operating its own infrastructure. Through solutions like Managed OpenShift, APPUiO, Application Catalog, and Servala, VSHN helps organizations simplify operations, avoid vendor lock-in, and retain full control over their workloads.

Founded in 2014 and 100% self-owned, VSHN serves over 350 customers and partners across 16 cloud platforms worldwide. With ISO 27001 certification, FINMA-aligned operations, and ISAE 3402 Type 2 audits, VSHN ensures the highest security and compliance standards.

Markus Speth

Marketing, Communications, People

Contact us

Our team of experts is available for you. In case of emergency also 24/7.

Contact us