The challenge
Modern operations increasingly depend on real-time software and AI at the edge — in vehicles, sensors, command posts, and deployed systems. But the environments that need it most are exactly the ones where a central cloud cannot be assumed. In denied, degraded, intermittent or limited (DDIL) conditions, infrastructure that requires constant reach-back to a central control plane is a liability.
At the same time, cleared personnel are scarce. An architecture that needs a large operations team per site does not scale to a distributed force.
How we help
The platform is built on a Kubernetes-in-Kubernetes architecture that separates a sovereign control core from the clusters it manages, so operations stay automated and resilient across intermittently connected sites.
Core — sovereign command
The management platform runs on your secure, sovereign private cloud or air-gapped bare metal. This is where clusters are provisioned, policies enforced, and workloads governed before deployment — under your control, with no foreign root access.
Fog — autonomous resilience
Deployed in mobile command centres, local control planes keep full orchestration running on-site. If communications are jammed, the fog layer keeps managing local systems autonomously; when the link returns, state resynchronises with the core. This is what “DDIL by design” means in practice.
Edge — tactical workloads
Containerised workloads and AI inference run directly on edge nodes and soldier-/vehicle-borne systems, with over-the-air updates delivered through your own pipeline to counter evolving conditions.
On the scale figures. Published vendor figures cite managing thousands of clusters from a single management cluster with a very small team. Treat these as vendor claims; your density depends on workload, hardware, and environment. We would rather scope this against your real estate than quote a headline number.
Outcomes
- A small cleared team operates a large, distributed fleet.
- Sites keep running through connectivity loss and resynchronise cleanly.
- No foreign dependency in the control plane, and nothing that has to phone home.
- A migration path in, not a lock-in: import existing clusters, keep your tooling.
Grounding: this is the same sovereign definition applied to operations — open code, self-hosted, no foreign root access.
