C
CYSKA
Consulting
EN FR
Navigation
Senior cloud engineers · Europe, Middle East & Africa

Build a sovereign cloud you can operate, evolve and control

Cyska designs, migrates and secures OpenStack and Ceph platforms for organizations that need control over their data, costs and operations. From VMware exit strategy to production operations, you decide at every stage on evidence: a pilot before any programme, a tested rollback before any cutover, and a team able to operate without us.

First response within one business day · NDA available · French and English

NewSovereign AI on OpenStack: GPU opportunity study →
10+ years in critical environments

Hands-on delivery for large organizations, including CAC 40 environments.

OpenStack · Ceph · VMware

Architecture, migration, performance, resilience and production operations.

Europe · Middle East · Africa

Remote or on-site delivery, in French or English, with skills transfer.

Why now

Five decisions infrastructure leaders can no longer postpone

Licensing, regulation, technical debt, skills and now AI workloads are converging at the same time. Each one is manageable; together they call for a trajectory, not a series of emergency projects.

Budget

The VMware licensing shock

Per-core subscription bundles have removed pricing visibility and multiplied virtualization budgets. The question is no longer whether to reduce the dependency, but in what order and at what pace.

Compliance

Sovereignty you can demonstrate

NIS2, DORA, GDPR and sector-specific requirements ask where data lives, who can access it and how you would leave a provider. Open, documented platforms turn those questions into evidence rather than assurances.

Risk

Legacy platforms out of support

An OpenStack cluster several releases behind no longer receives security fixes and blocks every hardware or software renewal. Waiting increases both the exposure and the eventual cost of the migration.

Autonomy

Skills that stay in-house

A platform only your integrator understands is another form of lock-in. Every engagement ends with runbooks, automation and pairing sessions so your team operates without us.

AI

Where your models and their data run

Prompts, training sets and fine-tuned weights are becoming the most sensitive assets in the company, and GPU bills the fastest-growing line. Whether to bring some of it in-house is now a governance question, and it has to be answered with your numbers.

Sovereign AI on OpenStack →
Our services

A clear path from decision to production

Each engagement starts with your operational constraints and ends with documented, testable deliverables your teams can own.

01

Sovereignty & trajectory audit

Assess data location, dependencies, VMware exposure, skills and operational risks before committing budget.

Deliverables: current-state map, gap analysis, target architecture, roadmap and budget assumptions.

02

OpenStack platform engineering

Design, deploy or modernize a highly available OpenStack and Ceph platform ready for production operations.

Deliverables: Kolla-Ansible automation, security baseline, monitoring, runbooks and skills transfer.

03

VMware exit & workload migration

Qualify workloads, run a pilot and industrialize migrations to OpenStack with rollback and cutover plans.

Deliverables: migration factory, tested waves, acceptance reports and production stabilization.

04New · Study

Sovereign AI on OpenStack

Decide with your numbers whether open-weight inference, fine-tuning or private GPU capacity belong on your own OpenStack, then design the platform underneath your models.

Deliverables: opportunity report with a go / no-go, target architecture, multi-year cost model, hardware and licensing checklist, measured pilot plan.

Read more →
How an engagement runs

Four phases, a decision gate after each one

You never commit to the whole programme up front. Each phase ends with evidence and a go / no-go that is yours to make. Durations are indicative and fixed during scoping, never renegotiated mid-way.

01 2–4 weeks

Scoping and audit

Current-state map, dependencies, VMware exposure, release gap, skills and operational risks. Target architecture, roadmap and budget assumptions.

You decide: which trajectory, which perimeter, which budget envelope.
02 4–8 weeks

Representative pilot

Real workloads covering several risk profiles, not one convenient VM. Measured windows, acceptance criteria and a rollback that has actually been exercised.

You decide: go / no-go for the programme, on measured figures.
03 Wave by wave

Industrialized migration

Waves planned by application dependencies and business windows, not by VM count. Each wave has its cutover plan, its rollback and its acceptance record.

You decide: pace, order and exceptions, wave after wave.
04 4–6 weeks

Stabilization and handover

Observability tuned on real traffic, runbooks and automation handed over through pairing sessions, architecture documentation updated. The platform no longer depends on us.

You decide: whether to keep us on call, or not.
Our commitments

The risks we take off your plate

Migrations fail on governance more often than on technology. These rules are written into every engagement and are non-negotiable on our side.

  • ✓No cutover without a rollback that has been tested on the pilot; the source stays intact until acceptance is signed.
  • ✓Open-source building blocks only (OpenStack, Ceph, KVM, OVN): no proprietary layer between you and your platform, reversibility by design.
  • ✓Everything we build is yours: automation, runbooks, dashboards and documentation are delivered in your repositories, not ours.
  • ✓No extrapolated figures: outage windows, throughput and costs are measured on your pilot before being written into any plan.
  • ✓Senior engineers only, in French or English, remote or on site; NDA available before the first exchange.
  • ✓A weekly steering note for the sponsor: decisions taken, risks open, next gate. No surprise at the end of a phase.
OpenStack Deployment & Modernization

Next-generation OpenStack deployment and legacy upgrades

We deploy production-ready, highly available OpenStack clusters with Kolla-Ansible across multiple availability zones, and move your workloads from legacy releases (e.g. Rocky) to current versions with minimal disruption. The detailed procedures live in our technical guides.

1. Next-generation deployment (Kolla-Ansible)

Multi-AZ · HA

A platform you can operate from day one: automated, documented and transferable, with observability built in rather than added later.

  • ✓Versioned Kolla-Ansible automation: inventory, globals, passwords under encrypted version control
  • ✓Highly available control plane, Ceph storage, OVN networking, two or more availability zones
  • ✓API validation, monitoring and runbooks delivered with the platform, then transferred to your team
Technical guide: deploy and upgrade with Kolla-Ansible →

2. Migrating a legacy OpenStack

Legacy ➔ Supported

When several releases separate you from the current version, a side-by-side platform with workload migration is safer than an in-place upgrade. We keep downtime to a minimum with two approaches:

Option A: Shared Ceph cluster, zero data copy

Both OpenStack clouds see the same Ceph pool: volumes are released by the legacy Cinder and adopted by the new one without copying their data blocks. The cutover window is measured during the pilot and includes Cinder checks, instance reconstruction and acceptance testing.

Option B: Snapshot, export and import

For isolated storage backends: volumes are snapshotted, exported as images, transferred and recreated on the target cluster, wave by wave.

A practical approach to sovereign cloud transformation

End-to-end support to design, operate and modernize your infrastructure while keeping strategic control, resilience and long-term flexibility wherever sovereignty and compliance matter. We deliver reusable playbooks and scripts, rely on open-source tooling and avoid vendor lock-in throughout the transformation. Our consultants are senior experts with years of experience in demanding enterprise environments, including CAC 40 companies.

OpenStack Private & Public Cloud

Design, Kolla Automation & Ceph

Deployment and operation of OpenStack clouds via Kolla-Ansible. Optimization of Ceph distributed storage, Neutron/OVN software-defined networking, and Nova/Cinder high availability.

  • ✓ Automated deployments (Kolla-Ansible multinode, multi-AZ)
  • ✓ OpenStack VM migrations across versions (legacy to a maintained release)
  • ✓ Ceph RBD administration
VMware Enterprise Hypervisors

Operations & Interoperability

Proven expertise across VMware vSphere, ESXi, vCenter, and vSAN environments. Hybridisation with open source solutions and licensing cost optimization.

  • ✓ Operational continuity (MCO)
  • ✓ Failover and disaster recovery strategy (RTO/RPO)
  • ✓ VM extraction and conversion to and from vSphere
Migration scenarios

Move workloads in both directions, with rollback

Most programmes go from VMware to OpenStack. Some workloads travel the other way after a merger or into a hybrid landing zone. Either way, the method is the same: qualify, pilot, industrialize, keep the source intact until acceptance.

VMware ESXi ➔ OpenStack

VMware exit

Two industrialized paths: direct conversion with virt-v2v, which injects VirtIO drivers and writes Cinder volumes straight from vCenter, or a fully controlled export, conversion and Glance import for air-gapped environments and bulk waves.

  • ✓Eligibility matrix: direct migration, remediation first, rebuild or retire
  • ✓Windows and Linux drivers, UEFI/BIOS, IP and MAC continuity handled before cutover
  • ✓Source VM kept intact on vSphere until acceptance is signed

OpenStack ➔ VMware ESXi

Hybrid / reverse

For isolated VMs, a Glance snapshot is converted to the VMDK format vSphere expects and registered through vCenter. For multi-terabyte disks, the Ceph RBD image is converted in one pass, with no intermediate file, and cutover windows are sized on measured throughput.

  • ✓Guest prepared for VMware paravirtual hardware before the last shutdown
  • ✓Firmware, MAC addresses and disk order preserved on the target VM
  • ✓OpenStack instance kept stopped but intact: restarting it is the rollback
Monitoring & Alerting

Resilient sovereign cloud platforms with observability by design

For production environments, we combine Prometheus for metrics collection, Grafana for dashboards, and Alertmanager for alert routing so operations teams detect issues faster, keep control of service health, and respond with clarity and confidence.

Prometheus

Collects node, service, Ceph, and OpenStack metrics with scrapes and alert rules.

Hosts labelled by role (controller, compute, Ceph) so every signal is attributable.

Grafana

Builds operational dashboards for CPU, memory, storage latency, API throughput, and instance health.

Dashboards provisioned as code and versioned with the platform, not built by hand.

Alertmanager

Routes critical alerts to Slack, email, or incident tooling based on severity and service ownership.

Every alert has an owner and an escalation path; grouping prevents notification storms.

What we put in place

  • ✓A coverage matrix: which service, which signal, which threshold, which team.
  • ✓Symptom-first alerting: API availability, instance spawn failures and Ceph health before raw CPU or disk figures.
  • ✓Noise reduction on OpenStack hosts so that virtual interfaces and container bridges stop polluting dashboards.
Technical guide: Prometheus, Alertmanager and Node Exporter tuning →

Typical outcomes for our clients

  • ✓Faster incident detection on OpenStack controllers, compute nodes, and Ceph storage daemons.
  • ✓Dashboards that show API latency, instance spawn failures, and storage health in a single view.
  • ✓Alert routing by service, severity, and escalation chain so the correct team receives the signal quickly.
FAQ

The questions sponsors ask before signing

What is the risk to production during the migration?

It is contained by design: the target platform is built alongside the existing one, workloads move in waves after a pilot, and the source stays intact until acceptance. A failed wave is rolled back, logged and fed into the next plan; it does not become an outage.

How long does it take, and when do we know the real cost?

Scoping takes a few weeks and produces a roadmap with budget assumptions. The pilot then replaces assumptions with measured windows and throughput; that is when the programme cost becomes reliable. We do not publish generic figures because they would be wrong for your estate.

Do we have to leave VMware entirely?

No. The qualification produces an eligibility matrix: what migrates directly, what needs remediation first, what is rebuilt on the target, what is retired or kept where it is. Exceptions become explicit programme decisions instead of late surprises.

What does “sovereign” guarantee in practice?

That you can answer three questions with evidence: where the data is, who can access it, and how you would leave. Open-source components, documented APIs, infrastructure you own or choose, and a reversibility plan written before the first workload moves. We do not sell a label; we deliver the architecture and the controls auditors ask for.

Who operates the platform afterwards?

Your team. Automation, runbooks, observability and acceptance records are delivered in your repositories and transferred through pairing sessions. Keeping us on call afterwards is an option, never a dependency.

Start Your Sovereign Cloud Project

Need a cloud platform with stronger autonomy, better governance, and measurable resilience? Contact our team directly.