Data sovereignty is built, not bought: VSHN at Cloud Native Days Austria 2026
On September 29th, 2026, Aarno Aukia took the stage in Vienna to make a simple argument: you don’t get sovereignty by signing a contract with a hyperscaler. You get it by architecting for it.

Cloud Native Days Austria 2026
Cloud Native Days Austria brought the community together again on September 29th and 30th, 2026, this time in two cinema halls at Cineplexx Wienerberg in Vienna. Two days of talks, hallway conversations and an evening event, aimed at developers, platform engineers and everyone else who runs things on Kubernetes.
We were there and our co-founder and partner Aarno Aukia opened the technical program on day one, right after the opening keynote.
Short on time? Download the slides (PDF) and jump straight into the deck.

Aarno’s Talk: “Data Sovereignty Is Built, Not Bought”
Aarno started with the deal the hyperscalers have been offering for twenty years. The offer: modern managed services – databases, queues, AI – self-service, in minutes. The price: your data moves into their datacenter, and the jurisdiction follows the provider. Or, as Aarno put it: the law follows the provider, not the rack. An executive order can switch your service off. The CLOUD Act can make your data be handed over.

Data has gravity
For many organizations, moving everything into a hyperscaler was never really an option anyway. Health, finance and public-sector data has to stay in controlled environments. Workloads need to stay close to the systems they talk to. And large datasets don’t move on a project timeline. Meanwhile, developers expect exactly what the cloud promises: a managed database, self-service, now.
Mohammad Alavi, CTO of Health Info Net (HIN), the secure network for Swiss healthcare, summed up the stakes: “No financial compensation could ever make up for leaked medical information.”
The common mistake
The reflex answer is: “Let’s move it to a sovereign cloud.” That usually gets you a migration project, a duplicated platform and a new dependency. You changed whom you depend on, not whether you depend.
Aarno pointed to the EU’s EUR 180 million cloud tender from April 2026, the first one scored on sovereignty. Three winners reached SEAL-3, meaning they cannot be blocked by a non-EU third party. Another bidder, offering EU-operated infrastructure built on Google Cloud, landed at SEAL-2. The label said sovereign. The score did not.
Sovereignty as three tests
Instead of trusting labels, Aarno proposed three concrete questions:
- Location: Can you move where it runs without changing how developers consume it? Provider-specific Terraform fails this test, a Kubernetes service claim passes.
- Operator: Can you replace who runs it without replacing the technology? A hyperscaler’s managed database fails, an open-source operator with its config in Git passes.
- Vendor: Can you replace the software without rebuilding? This one needs open source. VMware after Broadcom is the cautionary tale – Redis to Valkey in eight days is the counterexample.
Sovereignty, in short, is what you can still replace tomorrow.
The neutral platform layer
The architecture that passes all three tests puts one platform API between developers and infrastructure. Developers talk to the API; underneath, it can be Cloud A, Cloud B, a private datacenter or the edge. The point isn’t to avoid platforms, it’s to design for change.
That’s exactly how our VSHN Application Catalog (AppCat) works. Developers order managed databases and services as Kubernetes resources. Crossplane on Kubernetes provides the service API, and the services run at cloudscale, Exoscale, Switch or in private clusters – each with its own local Prometheus and Grafana, operated 24/7 where the data is.
Today, AppCat offers PostgreSQL, MariaDB, Redis, Keycloak (with Inventage), Forgejo, Nextcloud and S3 object storage from the underlying infrastructure. Kafka (with Spoud) and OpenBao (with bespinian) are coming next.
A production database takes ten lines:
yaml
apiVersion: vshn.appcat.vshn.io/v1
kind: VSHNPostgreSQL
metadata:
name: pgsql-app1-prod
spec:
parameters:
size:
plan: standard-2
writeConnectionSecretToRef:
name: postgres-creds
No cloud, no region, no operator, no storage class. What comes back is PostgreSQL with TLS, daily backups, monitoring and a maintenance window. A real production team sets more – service level, three instances for high availability, backup schedule and retention, maintenance window, deletion protection. Every one of those is a decision the team owns. And still nothing in the spec says where it runs.
2,000+ instances in production
AppCat isn’t a concept. It has delivered more than 2,000 managed instances since 2021, in two ways: every Managed OpenShift cluster we run includes it by default – in the customer’s own infrastructure, VMware included, or at a Swiss partner like cloudscale, with SLAs up to 99.99%. And in shared environments, you order AppCat services like SaaS through Servala or use them built into APPUiO.
Customers include finnova, acrevis, HRM Systems, the Swiss Federal Archives, HIN with its 50,000+ healthcare professionals, and Taurus. Sebastien Pasche, VP Engineering at Taurus: “We reduced monthly incidents from twelve to zero and improved our SLA from 99% to 100%.”
Proof: we change the engine, the API stays
The strongest part of the talk: we pass the tests ourselves. In AppCat, kind: VSHNPostgreSQL stayed the same while the PostgreSQL operator underneath was swapped: CloudNativePG became available as an option in September 2025, matured with self-service restore in April 2026, became the default for new instances in May 2026, and StackGres reached end of life on August 31st, 2026. Customers kept their API and planned migrations on their own timeline.

And we’re doing it again, this time with our own control plane. AppCat has run on Crossplane since 2021 and will continue into 2027 and beyond, but we’re moving to Helmetica, an operations framework for any software on Kubernetes that we’re open-sourcing over time. It monitors, backs up and GitOps-manages every service – the same principle as our Puppet framework on VMs. The difference is striking: Redis on Crossplane needed 2,076 lines of Go and shell code to render a Helm chart. Redis on Helmetica takes 320 lines – the upstream chart plus the framework’s shared templates for backup, network, maintenance and credentials. From Helm chart to service in five minutes and every change is a diff you can read.
Sovereignty is now measurable
The EU Cloud Sovereignty Framework scores providers on eight objectives, from SEAL-0 to SEAL-4. Three of them – operational independence, supply chain transparency and the ability to migrate without rebuilding – add up to half the score. And all three are decided by your architecture, not your contract.
Aarno closed with the question that sums it up: The question isn’t which cloud you choose, but whether your architecture still gives you a choice tomorrow. Dependent teams ask for permission. Sovereign teams ship.
In short: data sovereignty is built, not bought.

Get the slides
Want to dig into the details – the three sovereignty tests, the AppCat architecture, the YAML examples and the Helmetica comparison? Download Aarno’s full slide deck from Cloud Native Days Austria as a PDF.
Sovereignty was everywhere
We weren’t the only ones talking about it. Sovereignty, independence and compliance ran through the whole program:
- Lukas Zainzinger (willhaben) presented a blueprint for reclaiming data sovereignty with an open-source, vendor-agnostic data pipeline from edge to cloud.
- Niels Claeys (Dataminded) asked what a cloud strategy looks like after the hyperscaler era, from fully on-prem platforms to sovereign control planes and EU cloud alternatives.
- Dr. Constanze Roedig showed an eBPF-based Kubernetes SOC that runs node-local and can be airgapped, so no data has to leave the cluster.
- ORF shared how they connect EKS to on-prem hardware with hybrid nodes, Cilium and Crossplane.
- Artem Lajko and Nick Berthold (iits-consulting) looked behind the curtain of managed Kubernetes with Gardener, Kamaji and Cluster API.
- On the regulatory side, talks on the EU Cyber Resilience Act and NIS2 in Austria made it clear that compliance is becoming an engineering topic, not just a legal one.
Different angles, same conclusion: the community is no longer asking whether sovereignty matters, but how to build it. That’s exactly the conversation we want to be part of.

Thank you, Vienna
A big thank you to the organizers, volunteers and sponsors of Cloud Native Days Austria for another great edition and to everyone who came by to talk sovereignty, Crossplane and managed services with us.
Want to know how this model could work in your environment? Get in touch – we’re happy to show you.