Sovereignty & trajectory audit
Assess data location, dependencies, VMware exposure, skills and operational risks before committing budget.
Deliverables: current-state map, gap analysis, target architecture, roadmap and budget assumptions.
Cyska designs, migrates and secures OpenStack and Ceph platforms for organizations that need control over their data, costs and operations. From VMware exit strategy to production operations, you decide at every stage on evidence: a pilot before any programme, a tested rollback before any cutover, and a team able to operate without us.
First response within one business day · NDA available · French and English
NewSovereign AI on OpenStack: GPU opportunity study →Hands-on delivery for large organizations, including CAC 40 environments.
Architecture, migration, performance, resilience and production operations.
Remote or on-site delivery, in French or English, with skills transfer.
Licensing, regulation, technical debt, skills and now AI workloads are converging at the same time. Each one is manageable; together they call for a trajectory, not a series of emergency projects.
Per-core subscription bundles have removed pricing visibility and multiplied virtualization budgets. The question is no longer whether to reduce the dependency, but in what order and at what pace.
NIS2, DORA, GDPR and sector-specific requirements ask where data lives, who can access it and how you would leave a provider. Open, documented platforms turn those questions into evidence rather than assurances.
An OpenStack cluster several releases behind no longer receives security fixes and blocks every hardware or software renewal. Waiting increases both the exposure and the eventual cost of the migration.
A platform only your integrator understands is another form of lock-in. Every engagement ends with runbooks, automation and pairing sessions so your team operates without us.
Prompts, training sets and fine-tuned weights are becoming the most sensitive assets in the company, and GPU bills the fastest-growing line. Whether to bring some of it in-house is now a governance question, and it has to be answered with your numbers.
Sovereign AI on OpenStack →Each engagement starts with your operational constraints and ends with documented, testable deliverables your teams can own.
Assess data location, dependencies, VMware exposure, skills and operational risks before committing budget.
Deliverables: current-state map, gap analysis, target architecture, roadmap and budget assumptions.
Design, deploy or modernize a highly available OpenStack and Ceph platform ready for production operations.
Deliverables: Kolla-Ansible automation, security baseline, monitoring, runbooks and skills transfer.
Qualify workloads, run a pilot and industrialize migrations to OpenStack with rollback and cutover plans.
Deliverables: migration factory, tested waves, acceptance reports and production stabilization.
Decide with your numbers whether open-weight inference, fine-tuning or private GPU capacity belong on your own OpenStack, then design the platform underneath your models.
Deliverables: opportunity report with a go / no-go, target architecture, multi-year cost model, hardware and licensing checklist, measured pilot plan.
Read more →You never commit to the whole programme up front. Each phase ends with evidence and a go / no-go that is yours to make. Durations are indicative and fixed during scoping, never renegotiated mid-way.
Current-state map, dependencies, VMware exposure, release gap, skills and operational risks. Target architecture, roadmap and budget assumptions.
Real workloads covering several risk profiles, not one convenient VM. Measured windows, acceptance criteria and a rollback that has actually been exercised.
Waves planned by application dependencies and business windows, not by VM count. Each wave has its cutover plan, its rollback and its acceptance record.
Observability tuned on real traffic, runbooks and automation handed over through pairing sessions, architecture documentation updated. The platform no longer depends on us.
Migrations fail on governance more often than on technology. These rules are written into every engagement and are non-negotiable on our side.
We deploy production-ready, highly available OpenStack clusters with Kolla-Ansible across multiple availability zones, and move your workloads from legacy releases (e.g. Rocky) to current versions with minimal disruption. The detailed procedures live in our technical guides.
A platform you can operate from day one: automated, documented and transferable, with observability built in rather than added later.
When several releases separate you from the current version, a side-by-side platform with workload migration is safer than an in-place upgrade. We keep downtime to a minimum with two approaches:
Both OpenStack clouds see the same Ceph pool: volumes are released by the legacy Cinder and adopted by the new one without copying their data blocks. The cutover window is measured during the pilot and includes Cinder checks, instance reconstruction and acceptance testing.
For isolated storage backends: volumes are snapshotted, exported as images, transferred and recreated on the target cluster, wave by wave.
End-to-end support to design, operate and modernize your infrastructure while keeping strategic control, resilience and long-term flexibility wherever sovereignty and compliance matter. We deliver reusable playbooks and scripts, rely on open-source tooling and avoid vendor lock-in throughout the transformation. Our consultants are senior experts with years of experience in demanding enterprise environments, including CAC 40 companies.
Deployment and operation of OpenStack clouds via Kolla-Ansible. Optimization of Ceph distributed storage, Neutron/OVN software-defined networking, and Nova/Cinder high availability.
Proven expertise across VMware vSphere, ESXi, vCenter, and vSAN environments. Hybridisation with open source solutions and licensing cost optimization.
Most programmes go from VMware to OpenStack. Some workloads travel the other way after a merger or into a hybrid landing zone. Either way, the method is the same: qualify, pilot, industrialize, keep the source intact until acceptance.
Two industrialized paths: direct conversion with virt-v2v, which injects VirtIO drivers and writes Cinder volumes straight from vCenter, or a fully controlled export, conversion and Glance import for air-gapped environments and bulk waves.
For isolated VMs, a Glance snapshot is converted to the VMDK format vSphere expects and registered through vCenter. For multi-terabyte disks, the Ceph RBD image is converted in one pass, with no intermediate file, and cutover windows are sized on measured throughput.
For production environments, we combine Prometheus for metrics collection, Grafana for dashboards, and Alertmanager for alert routing so operations teams detect issues faster, keep control of service health, and respond with clarity and confidence.
Collects node, service, Ceph, and OpenStack metrics with scrapes and alert rules.
Hosts labelled by role (controller, compute, Ceph) so every signal is attributable.
Builds operational dashboards for CPU, memory, storage latency, API throughput, and instance health.
Dashboards provisioned as code and versioned with the platform, not built by hand.
Routes critical alerts to Slack, email, or incident tooling based on severity and service ownership.
Every alert has an owner and an escalation path; grouping prevents notification storms.
It is contained by design: the target platform is built alongside the existing one, workloads move in waves after a pilot, and the source stays intact until acceptance. A failed wave is rolled back, logged and fed into the next plan; it does not become an outage.
Scoping takes a few weeks and produces a roadmap with budget assumptions. The pilot then replaces assumptions with measured windows and throughput; that is when the programme cost becomes reliable. We do not publish generic figures because they would be wrong for your estate.
No. The qualification produces an eligibility matrix: what migrates directly, what needs remediation first, what is rebuilt on the target, what is retired or kept where it is. Exceptions become explicit programme decisions instead of late surprises.
That you can answer three questions with evidence: where the data is, who can access it, and how you would leave. Open-source components, documented APIs, infrastructure you own or choose, and a reversibility plan written before the first workload moves. We do not sell a label; we deliver the architecture and the controls auditors ask for.
Your team. Automation, runbooks, observability and acceptance records are delivered in your repositories and transferred through pairing sessions. Keeping us on call afterwards is an option, never a dependency.
Need a cloud platform with stronger autonomy, better governance, and measurable resilience? Contact our team directly.