# Giant Swarm > Giant Swarm is the curated platform engineering stack. We provide battle-tested Kubernetes, observability, security, networking, AI infrastructure, and application management curated from 10+ years of experience and 150+ production clusters. We empower platform teams to provide internal developer platforms that fuel innovation and fast-paced growth — fully managed or expert-supported, 100% open source, zero vendor lock-in. Giant Swarm was founded in 2014 in Cologne, Germany. The platform runs in customer environments (self-hosted) across AWS, Azure, and on-premises infrastructure. Giant Swarm is a CNCF Certified Service Provider and one of the first CNCF AI-Conformance Certified platforms. For a concise index of all pages, see [llms.txt](https://www.giantswarm.io/llms.txt). --- ## Home Source: https://www.giantswarm.io/ ### The Curated Platform Engineering Stack 10+ Years of Production Experience, Ready in Days. Skip the Platform Engineering Assembly Tax. Get battle-tested Kubernetes, observability, security, networking, AI, and application management curated from 10+ years of experience and 150+ production clusters with expert operations or expert support. Key metrics: - 150+ Production Clusters - 10+ Years Experience - €2.5M Customer Savings - CNCF AI-Conformance Certified ### The Platform Engineering Assembly Tax Platform teams spend 6-12 months integrating Kubernetes, observability, security, networking, and AI projects from the CNCF landscape, then need 8-15 specialists costing €1M-€2M annually just to keep it running. - 6-12 months to production (evaluation paralysis, integration hell, trial-and-error) - €1.8M annual ops cost (8-15 specialist engineers just to keep platforms running) - €1M+ hidden opportunity (best engineers fight infrastructure, not building products) ### What You Achieve With Giant Swarm - **Skip the Assembly Tax**: Stop burning months on integration and millions on specialists. Get battle-tested configurations from 150+ production clusters, ready now. - **Keep Full Control**: 100% Open Source, Zero Lock-in. Your infrastructure, your data, your rules. Runs entirely in your environment with full data sovereignty. - **Build Real Knowledge**: We don't just run your platform—we show you how it works. Knowledge transfer is built in, not an expensive add-on. ### Platform Capabilities Every component works standalone or as part of the complete stack: - **AI Infrastructure**: Fair-share GPU scheduling, token-level cost tracking, CNCF AI-Conformance Certified. Production-ready AI infrastructure in days vs. 6-12 months DIY. - **Kubernetes**: Pre-integrated Cilium, Kyverno, Flux, Karpenter. Multi-cloud (AWS, Azure, on-prem) from single control plane. 30-40% cloud cost reduction with intelligent auto-scaling. - **Observability**: Correlated observability (metrics to logs to traces in seconds), self-hosted (data never leaves your environment), predictable pricing (no surprise bills). - **Security**: Clear feedback to developers, pre-configured policies for compliance (PSS, CIS benchmarks), open source stack at a fraction of commercial licensing costs. - **Connectivity**: Deploy app and get HTTPS endpoint once configured, no manual DNS or certificate requests per app. - **Edge/IIoT**: Edge AI visual inspection deployed in 2 days (not 6 months), 10-15% OEE improvement, 16x downtime reduction potential, data stays in factory. - **Developer Portal**: One portal for services, docs, deployments, ownership. GitOps from day one with proven patterns. Developers self-serve. - **AI Orchestration**: Governed agent registry (no shadow AI, only vetted tools), standard protocol (MCP) connecting agents to all infrastructure, open source with full auditability. ### Delivery Models **Fully-Managed**: Zero operational burden. 24/7 proactive monitoring and expert operations. Continuous upgrades and security patches. Best for teams who want maximum focus on product development. **Expert-Supported**: Complete control in your hands. Build in-house knowledge with expert training. No third-party access to production systems. Best for security-conscious teams, regulated industries. Both models include: Production-validated configurations from 150+ clusters, expert knowledge transfer, self-hosted in your environment, 100% open-source (zero vendor lock-in). --- ## Smarter Platform Engineering Source: https://www.giantswarm.io/smarter-platform-engineering ### Faster, Cheaper, Better Platform Engineering Opt for a smarter way to provide, scale, and operate the digital foundation of your business. Our tried-and-tested approach unlocks developer productivity and reduces the cognitive load of your teams, delivering impactful results faster. ### Optimize Costs & Accelerate Value - **Save Costs, Save Time**: Eliminate software and support license fees, ensure efficient resource allocation and cloud cost management, provide an extended platform team at a fraction of the cost of hiring new resources. - **Your Platform Team, Extended**: Ease the operational load of your platform teams. We provide "out-of-the-box" skills and expertise, effectively extending your platform team without the need for sourcing new talent. - **Overcome the Adoption Hurdle**: A "ready-to-go" platform with no vendor lock-in. Self-service capabilities combined with the freedom for developers to customize. ### Empower Developers & Boost Productivity Enable developers to work efficiently and "smarter" by reducing their cognitive load and giving them easy access to the platform capabilities they need. Minimize distractions, provide streamlined access to essential tools, and free up more time for innovation. ### Ensure Reliability & Future-Proof Innovation - Industry-leading 90-second response time and 24/7 proactive support - "You build it, you run it" approach combining rapid issue resolution with continuous platform improvements - Locked-down environments by default with continuous security improvements without sacrificing speed ### The Giant Swarm Journey 1. **Onboarding**: Developer productivity unlocked — hit the ground running with a ready-to-go platform 2. **Week One**: Reduce the operational burden — 90-second response times and 24/7 support 3. **Transformation**: Your platform team extended — access unlimited expertise from the engineers who build it 4. **Optimization**: Reliability becomes standard — immediate issue resolution, zero service disruptions 5. **Acceleration**: Smarter resource utilization — eliminate license fees and reduce costs 6. **Elevation**: Knowledge transfer amplified — hands-on learning from platform experts 7. **Innovation**: Full speed ahead — modular building blocks deliver new capabilities at the speed of your business --- ## The Giant Swarm Advantage Source: https://www.giantswarm.io/giant-swarm-advantage ### Leapfrog Your Platform Engineering Giant Swarm gives your engineering team something your competitors don't have: the freedom to focus entirely on building what's next, while we handle the complexity that holds others back. Key facts: - Serving millions of users daily across global platforms - Processing billions of transactions monthly - 99.99% platform availability - 24/7 enterprise support worldwide ### Time to Value: Days, Not Years We combine deep platform expertise with your team's domain knowledge to amplify your engineering capabilities. ### True Partnership We're the battle-tested platform engineering team you'd spend years trying to hire and train — already here, aligned with your goals, ready to deliver value on day one. - **Speed Without Compromise**: Modular building blocks for rapid capability deployment without sacrificing stability - **Security at the Core**: Locked-down environments by default, continuous security improvements - **Reliability You Can Trust**: 90-second response times backed by hands-on support - **Low Maintenance**: Streamlined platform that makes testing, fixes, and enhancements straightforward --- ## Platform Team Enablement Source: https://www.giantswarm.io/platform-team-enablement ### Empowering Platform Teams Transform your platform engineering from a support function to a strategic innovation driver. Provide platform services faster, better, and cheaper than ever before. ### Typical Platform Team Challenges | Governance | Cost | Adoption | Security | Reliability | |---|---|---|---|---| | Uncontrolled cluster sprawl | Low utilization of resources | Teams avoiding central platform | Insight paralysis | Lack of confidence | | Maintenance overload | No consolidated view across teams | Lift and shift of monoliths | Avoidable manual effort | No real-time failover | | Multiple platforms | Lacking confidence to optimize | Heterogeneous stacks per team | Vast team permissions | No Disaster Recovery | Our research shows that 80% of companies can improve in at least two of these areas. ### Engagement Models | | Advice | Support | 24x7 | |---|---|---|---| | **Results** | Expert recommendations | Massive improvement to a component | Perfect setup to focus on delivering value | | **Approach** | Assessments, Workshops, Trainings | Open Source technology, implementation and backup | Open Source Platform as a Service | | **Duration** | Days | Weeks to Months | Ongoing Partnership | | **Areas** | Infrastructure as Code, Kubernetes Fleet Management, Observability, Security, Developer Experience, Cost Optimization, Disaster Recovery, Hybrid Cloud, AI Workloads | ### How to Get Started 1. **Inspiration**: Explore new possibilities — envision what's possible when your platform becomes a true innovation catalyst 2. **Discovery**: Uncover your challenges — deep analysis reveals high-impact areas for greatest returns 3. **Planning**: Design your transformation — collaborative approach ensures buy-in from all stakeholders 4. **Agreement**: Establish clear parameters — transparent framework creates accountability 5. **Execution**: Achieve lasting results — focus on knowledge transfer ensures long-term improvements --- ## About Us Source: https://www.giantswarm.io/about-us ### Empowering developers to build applications that run our world We're passionate about providing organizations with a reliable cloud-native developer platform to drive high innovation rates and rapid growth. ### Origin Story Back in 2011, the founders were running Adcloud, processing 10k+ transactions per second and competing with Google. They went all-in on microservices. When existing PaaS solutions couldn't handle their scaling needs, they built their own infrastructure — but managing it ate up one-third of their engineering time. In 2014, they created Giant Swarm — the comprehensive solution they wished they'd had. They took all their battle scars from building and running infrastructure at scale and turned them into something that lets developers actually focus on developing. Giant Swarm GmbH is headquartered at C/O Startplatz, Im Mediapark 5, 50670 Cologne, Germany. The company is fully remote. --- ## Industrial IoT Source: https://www.giantswarm.io/industrial-iot ### Turbocharge your Industrial IoT Initiative The Giant Swarm Industrial Internet of Things (IIoT) Platform empowers industries to overcome the challenges of modern manufacturing by leveraging cutting-edge cloud native technologies. Built on Kubernetes and designed for industrial use cases, it provides a secure, scalable, and resilient foundation that integrates seamlessly with existing infrastructure from edge devices to the cloud. ### Main Challenges in Smart Manufacturing - Reduce operational costs while improving efficiency - Bring disparate tools and devices into a cohesive system - Scale operations across multiple locations - Enable real-time data insights and analytics ### Key IIoT Platform Benefits - **Unified Platform for Maximum Efficiency**: Eliminate operational inefficiencies caused by siloed systems. Integrates all factories into a single ecosystem. - **Focus on Business Value, Not Infrastructure**: Giant Swarm handles complexities of infrastructure setup, management, and 24/7 platform operations. - **Cost Savings and Reduced Latency**: Process data at the edge, saving bandwidth costs and improving decision-making speed. - **Open Source Foundation**: Avoids vendor lock-in and rising costs. Flexible design ensures sustainability. - **Enhanced Security & Compliance**: Robust, multi-layered security measures. Compliance with industry standards. - **Accelerate Time-to-Market**: Launch smart factory initiatives in weeks, not years. ### How the Giant Swarm IIoT Platform Works Unified platform ensures seamless management across all infrastructures through a single GitOps-managed interface. - **Intelligent Edge and Cloud Integration**: Modular architecture ensures seamless transition between on-premises operations and cloud-based analytics. - **Cloud Native Developer Platform**: More than just Kubernetes — a fully-fledged cloud native developer platform with enterprise-grade security, observability, and connectivity. - **Data Connectivity and Integration**: Integrates with factory-floor devices and data hubs. Reference architecture incorporates Cybus Connectware, compatible with HiveMQ Edge and others. - **Messaging and Data Streaming**: Robust data transport enabling data forwarding to cloud-based solutions. Supports Kafka, Azure Arc, and AWS cloud services. ### Proven Results - TIME TO MARKET: 12 months faster - DOWNTIME: 16x less - COST SAVINGS: 7-digit savings - DEPLOYMENT FREQ.: 1,000x higher --- ## Modernization & Scaling Source: https://www.giantswarm.io/modernization-and-scaling ### Cloud Modernization and Scaling Our customers spend less time managing platforms and more time building what matters. Infrastructure shouldn't be your bottleneck. ### Start Strong, Scale Smart Build a clean, modern environment alongside your existing one. Validate the new platform, migrate workloads at your own pace, and avoid the complexity of retrofitting existing clusters. Teams get a production-ready foundation in weeks, not months. ### Grow Without the Pain The platform supports growth without sacrificing control. Teams get independence while you maintain security and standards. Automated workflows and proven patterns help scale confidently. ### Turn Operations Into Opportunity Giant Swarm handles the operational load so teams can focus on innovation. The platform automates the routine while experts help tackle the strategic. Concrete examples include Vertical Pod Autoscaling and Horizontal Pod Autoscaling. ### Built for Your World The platform runs seamlessly across cloud and on-premises environments through a CAPI-based approach. True infrastructure abstraction — same consistent experience regardless of where you run workloads. No lock-in, no compromise. ### Partnership That Delivers - **Experience That Matters**: Practical solutions based on years of running production platforms - **Collaboration That Works**: Direct Slack access to the engineers who build and run the platform - **Innovation You Can Trust**: Proven open source foundations with enterprise-ready capabilities --- ## Developer Platforms Source: https://www.giantswarm.io/developer-platforms ### Cloud Native Developer Platforms For over a decade, some of Europe's most demanding enterprises have trusted Giant Swarm to build and run their developer platforms. Giant Swarm handles the complexity in your environment, so your teams can focus on what matters. ### The Power of Golden Paths Giant Swarm helps platform engineers design and implement golden paths that reflect specific company standards, security requirements, and operational needs. Developers follow these proven patterns automatically, ensuring consistency across teams and projects. ### Enterprise Foundation - **Technical Foundation That Scales**: GitOps drives everything. Cluster API manages workloads consistently across AWS, Azure, Google Cloud, and private cloud. API-first architecture enables deep integration with existing tools. - **Built for Production**: Security and observability are core platform features. Every component from RBAC to audit trails is configured based on real production experience. Integrated monitoring, multi-tenancy, and hybrid cloud support. ### Complete Partnership Platform engineering is a team sport. Giant Swarm engineers work alongside your platform team as a seamless extension of your organization through direct Slack collaboration. 99.9% uptime while your platform team focuses on strategic initiatives. ### FAQ: Internal Developer Platforms **What is an IDP?** An Internal Developer Platform is a curated self-service layer that empowers developers to deploy, operate, and manage applications without waiting on operations or wrestling with infrastructure. Teams adopt IDPs to minimize cognitive load, enforce security and governance without slowing teams down, standardize how software is shipped, and shorten the path from idea to production. **Key features**: Golden paths, Git-based workflows (GitOps), RBAC, multi-cluster and multi-cloud support, secrets and identity management, built-in observability, declarative policy enforcement. **Build vs. buy vs. open-source?** It depends on internal capabilities and desired speed to value. Many teams start with open source or a commercial base and evolve into a hybrid model. **How to measure success**: Deployment frequency, lead time for changes, MTTR, platform adoption, reduction in support tickets, developer satisfaction. --- ## Hybrid & Multi-Cloud Source: https://www.giantswarm.io/hybrid-and-multi-cloud-solution ### Transform Your Multi-Cloud Strategy Cloud providers promise innovation but deliver complexity and lock-in. Giant Swarm offers a different path. ### The Business Impact - **Freedom to Innovate**: Open source approach delivers true cloud flexibility with instant production readiness. Proven when adidas seamlessly shifted 200 developers between teams overnight. - **Unified Control**: GitOps-first approach — define everything once in a central location. Automation handles provisioning, updates, and state management across every cloud, cluster, and workload. - **Enterprise Scale**: Built on pure upstream open source technology. Cluster API creates powerful synergies between public and private clouds while minimizing cloud-specific code. ### The Technical Foundation - **Developer Experience**: Unified developer portal enables instant environment provisioning with automation handling cloud-specific configurations behind the scenes. - **Network Architecture**: Cilium across all clouds delivers superior functionality compared to native solutions like AWS CNI. Consistent capabilities, efficient management, simplified troubleshooting. - **Open Source Core**: Every feature built on pure upstream open source, ensuring the platform evolves with the community rather than locking into proprietary solutions. --- ## Customers Overview Source: https://www.giantswarm.io/customers ### Where Leading Enterprises Build Their Digital Future Giant Swarm serves enterprises across multiple industries: - **Retail & Ecommerce**: Handle Black Friday traffic like a quiet Sunday morning. Infrastructure for millions of customers clicking 'buy'. - **Telecommunications**: Platforms for connecting millions of lives at millisecond speeds. - **Manufacturing**: Powering Industry 4.0 — turning century-old processes into digital-first operations. Core capabilities across all customers: Infrastructure at Scale, Automated Excellence, Developer Experience, Enterprise Security. --- ## Customer: adidas Source: https://www.giantswarm.io/customers/adidas ### Revolutionizing Digital Retail adidas' journey into cloud native technologies and Kubernetes began in late 2015, driven by a strategic shift towards microservices and agile software development. #### Key Metrics - 3-4 releases per day (continuous deployment enables rapid innovation) - 50% reduction in load times (enhanced performance delivers superior customer experiences) - 100,000 CI/CD builds monthly (robust automation supports massive development operations) #### The Story adidas scaled their online retail from €40 million to €4 billion through their revolutionary ecommerce platform — achieving 100x growth. During 2020, they increased ecommerce sales by 53% year-over-year. Beginning with three core pillars — technology, operations, and evolution — adidas mapped the best path forward. The collaboration with Giant Swarm continues to drive innovation and value, enabling adidas to focus on their core mission. **Industry:** Fashion | **Location:** Germany | **Founded:** 1949 | **Employees:** 59,000 **Use Cases:** Web-Scale, Mobile, Internal Services, Big Data **Cloud Type:** Hybrid Cloud **Challenges:** Velocity, Scaling, Resiliency, Monitoring **Giant Swarm Customer since:** 2017 > "These guys are really amazing and know their stuff in and out. Specifically, in the area of containers and Kubernetes and everything around this, I've never met a more knowledgeable partner." — Daniel Eichten, VP Enterprise Architecture, adidas --- ## Customer: Vodafone Source: https://www.giantswarm.io/customers/vodafone ### Cloud Native Transformation at Scale Vodafone Group Services was struggling with an old, monolithic platform that had incurred high levels of complexity and interdependency, along with a substantial upgrade deficit. They could no longer maintain it without operational and security risks. Giant Swarm provided a highly automated management cluster to manage Kubernetes and the cloud native stack, wrapped in a service that increased Vodafone's peace of mind during cloud adoption. The partnership eased the ramp-up of cloud native architecture with available portability and no lock-in, providing an easy pivot in case of failure. Vodafone Group Services GmbH has created a blueprint for building and maintaining cloud native projects. This blueprint is now being adopted throughout Vodafone Group, especially with Kubernetes projects moving from experimental phase to production. > "We could not move a business-critical system on to something we were unfamiliar with, so we partnered with someone who knows how to run containers at scale." — Markus van Laak, Principal Manager Digital Enablers, Vodafone **About Vodafone:** Vodafone Group is one of the world's leading telecoms and technology service providers with extensive experience in connectivity, convergence, and the Internet of Things. --- ## Customer: Vaillant Source: https://www.giantswarm.io/customers/vaillant ### Rolling out IoT at high-speed The IoT field represents a new growth frontier for Vaillant Group, where software is the product. Their goal is to harness data intelligently from heating appliances to deliver added customer value through safe, reliable, and user-friendly API services. This enables Vaillant to evolve beyond one-time sales to provide ongoing data-driven services. In the 18 months following their cloud native stack launch, Vaillant's IoT team successfully deployed three major applications, demonstrating remarkable transformation speed. Speed was crucial in building the cloud native infrastructure with a six-month timeline. While initially planning Kubernetes on Azure, evaluation revealed ACS was reaching end-of-life and AKS lacked required functionality. The solution emerged as vanilla Kubernetes on Azure with Giant Swarm's fully managed solution. Despite a mid-project technology change, the API developer program launched on schedule. **About Vaillant:** The Vaillant Group is a global market and technology leader in heating, ventilation and air-conditioning technology. For over 140 years, they have followed a strategy designed to achieve sustainable and profitable growth, with 10 sites in six European countries and China. --- ## Customer: Service Layers Source: https://www.giantswarm.io/customers/service-layers ### Focusing on Core Competence Rather than double the size of the company with cloud native experts, Service Layers integrated Giant Swarm into its business model from day one, ensuring each partner focuses on their core expertise. Traditional IAM projects required 6-36 months. However, customers now expected delivery in weeks. Microservices and CI/CD offered a path to faster delivery, centered on public cloud and containerized applications using Kubernetes. The impact was immediate. After a two-week setup, Service Layers now deploys to integrators in 20 minutes to 72 hours — a dramatic improvement from the previous 2-3 month timeline. New features reach the market within weeks, requiring no localization or customization branches. **About Service Layers:** Founded in 2017 as part of the iC Consult Group, Service Layers combines the group's knowledge in IAM architecture, implementation, and operation of IAM services, offering custom-fit identity access management services for medium-sized and large enterprises. --- ## Documentation: Introduction Source: https://docs.giantswarm.io/overview/introduction/ Giant Swarm's mission is to empower customers to build their own cloud-native developer platform. When development organizations grow and their environments expand, they face exponentially growing complexity in managing the lifecycle and operations of their applications and services. Giant Swarm believes a flexible, unified cloud-native developer platform plays a crucial role in growing development organizations efficiently — reducing cognitive load on development teams while enabling more centralized security and governance management. ### Our platform, your platform Giant Swarm doesn't offer a generic solution. Instead, it uses cloud-native technology to give platform teams the tools to build a developer platform that perfectly matches their company's specific requirements. The approach gives you the ability to define team-specific policies, flexible application delivery processes, or different traffic routing setups. Templates can be tailored to team needs while ensuring excellent visibility and control. ### Working with our customers Get started quickly with the fully open-source, production-ready platform — no vendor lock-in, no commercial license. Giant Swarm collaborates daily with customer engineers to create customized solutions. The team takes full responsibility for keeping platform components healthy, operating and monitoring them continually, offering upgrades and support. Even when customer applications don't work as expected, Giant Swarm assists until they do. --- ## Documentation: Architecture Source: https://docs.giantswarm.io/overview/architecture/ Giant Swarm's cloud-native developer platform integrates open-source components that work together to provide a seamless experience for managing the lifecycle of containerized applications. The platform is based on Kubernetes and designed to be cloud-agnostic, allowing deployment on any supported cloud provider, including on-premises. ### Platform Architecture Layers - **Interfaces**: How administrators, developers and automation access the platform (deploy applications, monitor health, use capabilities) - **Capabilities**: Features like application deployment, autoscaling, security, observability - **Infrastructure**: Kubernetes-based platform managing clusters on AWS, Azure, VMware (on-premises) or hybrid ### Platform API Built on Kubernetes and Cluster API, an open source Kubernetes sub-project that standardizes cluster lifecycle management across different cloud providers. The platform API is the regular Kubernetes API of the central management cluster — your interface for deploying workload clusters and applications. Use kubectl, GitOps, or any Kubernetes-compatible tooling. ### GitOps Giant Swarm uses GitOps as a first-class citizen with the Flux operator, ensuring all changes are version-controlled, auditable, and easily reversible. ### Developer Portal Based on Backstage, serving as the central hub for accessing all platform services and resources. Provides an intuitive interface for documentation, project management, and tool access. ### Observability Based on Grafana's LGTM stack. Collectors store metrics, logs, and traces in central storage. Managed Grafana instance on the management cluster provides centralized view, alerts, dashboards, and troubleshooting. Pre-installed dashboards for infrastructure and cluster health. ### Single Sign-On SSO simplifies authentication using existing identity providers (Google Workspaces, Microsoft Entra ID). Kubernetes RBAC for fine-grained access policies and permissions. ### Network and Connectivity Kubernetes built-in networking with Cilium CNI extended capabilities. Network policies for traffic control and security. Supports routing, load balancing, ingress/egress capabilities. ### Platform Security Kyverno as policy engine for establishing, enforcing, and automating security policies. Falco and Trivy for intrusion detection, vulnerability scanning, and automated threat response. ### Cost Management Autoscaling and resource optimization to adjust resources based on demand. Solution engineers help add visibility and control over resource usage and expenses. ### Automatic Cluster Management Based on Cluster API and operators. Automated provisioning, scaling, upgrading, and deletion of clusters. Special capabilities such as private clusters and custom routing. ### Cloud Resources Provisioning Crossplane included in the platform API enables managing external cloud resources (databases, queues, buckets) using Kubernetes-native APIs. --- ## Documentation: Fleet Management Source: https://docs.giantswarm.io/overview/fleet-management/ Supported cloud providers and management of clusters on the Giant Swarm platform. Orchestrating a large-scale microservices platform poses significant challenges, especially when juggling multiple infrastructure providers, regions, clusters and environments. Giant Swarm provides abstractions to manage and tackle this complexity effectively. ### Capabilities - **Multi-environment support**: Flexibly provide developers with various environments across different regions and infrastructures, adapted to your organization's needs. - **Robust configuration management**: Bullet-proof configuration management for clusters, environments, and workloads. Structured platform configuration with multiple control layers from a single repository, adhering to GitOps principles. - **Standardized cluster lifecycle management**: Giant Swarm leverages Cluster API (Kubernetes sub-project, with Giant Swarm engineers as regular contributors). Adds enterprise-grade features, out-of-the-box configuration, and battle-tested versioned packages for production-ready clusters. Cluster lifecycle managed as code. ### Cloud-Native Technologies - **Kubernetes**: De facto standard for container orchestration, cloud-agnostic - **Cluster API**: Kubernetes sub-project for declarative cluster creation, configuration, and management - **Flux**: GitOps for the platform — manage all infrastructure and configuration in a single source of truth Sub-sections: Cluster management, App management, Multi-tenancy. --- ## Documentation: Observability Source: https://docs.giantswarm.io/overview/observability/ The observability platform provides visibility into the Giant Swarm platform, your cluster fleet, and application workloads. ### What you can do with observability - **Monitor your systems**: Continuously collect and analyze metrics for performance and health - **Centralize your logs**: Capture detailed records of system and application events in one place - **Trace your requests**: Follow requests through distributed systems, identify bottlenecks - **Visualize your data**: Dashboards, visualizations, and alerts. Start with ready-made dashboards or create your own - **Get notified with alerts**: Alerting rules for important events, avoiding repetitive dashboard checks - **Work securely with multi-tenancy**: Isolate sensitive data for the right teams and departments ### Technology Stack (all open source) - **Mimir**: Horizontally scalable, multi-tenant time series database for long-term metric storage - **Loki**: Horizontally scalable log aggregation system with LogQL queries - **Tempo**: Distributed tracing backend with OpenTelemetry support and TraceQL - **Grafana**: Visualization tool for metrics, logs, and traces. Integrates with Mimir, Loki, Tempo, and other data sources - **Alertmanager**: Alert routing, grouping, and silencing. Supports email, Slack, PagerDuty, and more - **Alloy**: OpenTelemetry collector for metrics, logs, and traces from workload clusters Sub-sections: Alert management, Configuration, Dashboard management, Data management. --- ## Documentation: Security Source: https://docs.giantswarm.io/overview/security/ Giant Swarm clusters follow a secure-by-default ideology — every cluster starts with a production-ready security posture. ### Capabilities - **Policy enforcement**: Fine-grained security policies including Kubernetes RBAC, Network Policies, Pod Security Standards (PSS), and custom policies via Kyverno - **Image scanning and provenance**: Scan container images for vulnerabilities, identify improperly handled secrets, verify image authenticity before deployment - **Runtime anomalies**: Detect and respond to abnormal behavior during runtime (unexpected process executions, file system changes, network connections) - **Log alerting**: Set up alerts based on log data for timely detection and response to security incidents - **Advanced network capabilities**: Internal traffic encryption, mutual TLS (mTLS) for service-to-service communication ### Cloud-Native Technologies - **Kyverno**: Policy enforcement — define and enforce security policies across all clusters, including image signature verification - **Trivy**: Vulnerability scanning, exposed secrets detection, insecure configuration detection, and benchmarks - **Falco**: Runtime security monitoring for Kubernetes, real-time detection of suspicious activities - **Prometheus and Grafana**: Log alerting, metrics collection, and customizable dashboards - **Cilium**: DNS-based network policies and traffic encryption Sub-sections: Platform Security, Secure access to clusters, Domain allowlist, Sharing secrets, Kernel settings. --- ## Documentation: Connectivity Source: https://docs.giantswarm.io/overview/connectivity/ Public or private access to your workload applications through ingress. Secure connections between distributed applications or microservices through an API gateway. ### Capabilities - **Public and private clusters**: Choose publicly available or closed API and ingress endpoints - **Network policies**: Granular control over cluster network traffic between pods - **Ingress traffic management**: API gateway, ingress controllers, or native load balancers for external traffic routing - **Egress proxy add-on**: Control outbound traffic with an egress proxy - **Scalable container network**: Cilium high-performance CNI for reliable, secure pod communication - **Internal DNS**: CoreDNS and node local DNS for scalable service discovery - **Encrypted traffic**: mTLS encryption for all traffic between services - **DNS configuration management**: Declarative DNS records within the cluster - **Resilience**: Circuit breakers, retries, timeouts, and rate limiting ### Cloud-Native Technologies - **Kubernetes**: Foundation for container communication and networking - **Cilium**: Container network interface for reliable, secure communication - **Kong**: Open-source API gateway for efficient API traffic management - **ingress-nginx**: Ingress controller for external traffic routing - **CoreDNS**: Flexible DNS server for service discovery - **Node Local DNS**: Scalable DNS extension for speed and reliability - **External DNS**: Manage DNS records for external services --- ## Documentation: Developer Portal Source: https://docs.giantswarm.io/overview/developer-portal/ Giant Swarm's Backstage-based developer portal is the engineer's front end to the platform. Self-service user interface provided as plugins for Backstage, so engineers find all the information they need in an accessible, user-friendly place. Sub-sections: - **Introduction**: Overview of the Backstage-based developer portal - **Accessing the developer portal**: How to find your Giant Swarm developer portal URL and log in - **App deployments**: Overview of all app deployments across clusters and installations - **Clusters**: Access cluster lists and cluster details - **Customizing**: Adapt the developer portal to your requirements (URL, GitOps links, Labels, Annotations, Catalog) --- ## Documentation: Continuous Deployment Source: https://docs.giantswarm.io/overview/continuous-deployment/ Continuous Deployment (CD) enables teams to deliver features, fixes, and updates fast and reliably. ### Capabilities - **Pull-based deployments**: GitOps methodology with pull-based approach for managing application deployments. Desired state always reflected in deployed applications. - **Secret management**: External Secrets Operator (ESO) integrates with many secret management solutions. Secrets securely stored and injected into applications. - **Infrastructure as Code**: Declarative provisioning and management of cloud infrastructure and services, promoting consistency, repeatability, and scalability. ### Cloud-Native Technologies - **FluxCD**: GitOps automated synchronization of Git repositories with Kubernetes clusters - **Flux Operator**: Extends Flux with self-service capabilities, deployment windows, and preview environments for GitHub, GitLab, and Azure DevOps pull requests - **External Secrets Operator**: Integrates with AWS Secrets Manager, Azure Key Vault, HashiCorp Vault, and more - **Crossplane**: Kubernetes-native APIs for infrastructure and service management --- ## Documentation: Getting Started Source: https://docs.giantswarm.io/getting-started/ Step-by-step customer journey to build your cloud-native developer platform: 1. **Prepare your provider infrastructure**: Set up your infrastructure provider (AWS, Azure, VMware Cloud Director, VMware vSphere) to run Giant Swarm management and workload clusters 2. **Access to the platform API**: How engineers can access the platform API to provision workload clusters or deploy applications 3. **Create a first workload cluster**: Configure and provision your first workload cluster using the platform API 4. **Install an application**: Add capabilities by deploying applications from the catalog 5. **Control the application connectivity**: Understand basic connectivity and options for exposing your app 6. **Observe your clusters and apps**: Start monitoring with Giant Swarm's observability platform — metrics, logs, distributed tracing, custom dashboards, and alerts 7. **Set up your AI agent**: Learn how to use Muster and mcp-kubernetes to interact with management clusters through AI assistants like GitHub Copilot or Cursor --- ## Documentation: Full Table of Contents Source: https://docs.giantswarm.io/ ### Overview - Introduction - Architecture (Operational layers, Authentication, AWS architecture) - Developer portal (Introduction, Access, App deployments, Clusters, Customizing) - Fleet management (Cluster management, App management, Multi-tenancy) - Continuous deployment - Security (Platform Security, Secure access, Domain allowlist, Sharing secrets, Kernel settings) - Connectivity - Observability (Alert management, Configuration, Dashboard management, Data management) ### Getting Started - Prepare your provider infrastructure (AWS, Azure, VMware Cloud Director, VMware vSphere) - Access to the platform API - Create a first workload cluster - Install an application - Control the application connectivity - Observe your clusters and apps - Set up your AI agent ### Tutorials - Access management (Authentication, Authorization, OIDC, IAM roles, Azure Workload Identity) - Fleet management (Scaling workloads, GPU workloads, Job management with KubeRay, App management, Cluster management) - Connectivity (Ingress, Gateway API, External DNS, CoreDNS) - Container registries - Continuous deployment (GitOps, FluxCD, Base templates, Workload clusters, Environments, Tooling, Managing apps) - Observability (Network monitoring) - Security (Cluster access control, External Secrets Operator, Policy enforcement, TLS certificates, Policy API) - Storage (Persistent volumes) ### Reference - Platform API (CRDs, Cluster app charts, K8s annotations, K8s labels, Chart metadata) - kubectl-gs CLI (Installation, get/template/update commands, GitOps commands, FAQ, Telemetry) ### Support - Overview - Training catalog - Incident process ### Changes and Releases --- ## Blog Source: https://www.giantswarm.io/blog Giant Swarm publishes insights on Kubernetes, cloud native, platform engineering, and IIoT. Topics include: Tech, Inside, Team, Product, 8 on K8s, Tutorial, GitOps, Platform Engineering, Observability, Cluster API, Container Image Building, Cost Optimization, Docker, History, Autoscaling, Developer Tools, Security, Smart Factory, AI, Edge. ### Recent Posts - **The future is modular: what a decade of running Kubernetes taught us about platforms** (Feb 13, 2026) — After a decade running production Kubernetes, Giant Swarm evolved to a modular platform model. - **Treat the edge like infrastructure, not an exception** (Feb 3, 2026) — When teams struggle with Kubernetes at the edge, it's rarely the cluster itself that's failing — it's the context. - **Infrastructure for AI is finally getting a standard** (Nov 11, 2025) — AI has exploded into production; infrastructure standards are now emerging. - **The Gateway API shift: how Kubernetes networking actually works at scale** (Oct 27, 2025) — Kubernetes networking evolution from Ingress API to Gateway API. - **Making Grafana remember: our journey to persistence with Grafana and PostgreSQL** (Oct 7, 2025) — Moving from stateless GitOps-managed Grafana to persistent UI-driven dashboard management. - **Open source is fueling the world: from developer's tool to strategic asset** (Aug 22, 2025) — Open source software as ubiquitous technology powering everything from web servers to cloud infrastructure. - **GitOps in hybrid factory environments: simplifying deployments, hardening operations** (Aug 14, 2025) — Managing infrastructure across factory sites, edge locations, and hybrid cloud environments with GitOps. - **Why Giant Swarm isn't "Just Ops"** (Jul 8, 2025) — The shift in how companies think about infrastructure beyond just running Kubernetes clusters. - **What works in Industrial IoT: lessons from real-world smart factories** (Jun 30, 2025) — Real-world lessons from the paradox of modern factory digital transformation. --- ## Community & Resources ### Giant Swarm & Friends Source: https://www.giantswarm.io/gsfriends Community program and events for the Giant Swarm ecosystem. ### Events Source: https://www.giantswarm.io/events Conferences and meetups where Giant Swarm participates and speaks. ### Partners Source: https://www.giantswarm.io/partners Technology and consulting partners in the Giant Swarm ecosystem. ### Podcasts Source: https://www.giantswarm.io/podcasts Giant Swarm podcast episodes covering Kubernetes, cloud native, and platform engineering topics. ### Webinars Source: https://www.giantswarm.io/webinars Recorded and upcoming webinars on platform engineering, Kubernetes, and cloud native technologies. ### GitHub Source: https://github.com/giantswarm Open source projects and repositories. Notable projects include Muster (AI orchestration for Kubernetes). --- ## Company Information **Company**: Giant Swarm GmbH **Founded**: 2014 **Headquarters**: C/O Startplatz, Im Mediapark 5, 50670 Cologne, Germany **Work Model**: Fully remote **Contact**: hello@giantswarm.io **Website**: https://www.giantswarm.io **Documentation**: https://docs.giantswarm.io **GitHub**: https://github.com/giantswarm **LinkedIn**: https://www.linkedin.com/company/giant-swarm/ **YouTube**: https://www.youtube.com/user/GiantSwarm **Bluesky**: https://bsky.app/profile/giantswarm.io **Certifications**: CNCF Certified Service Provider, CNCF AI-Conformance Certified **Supported Cloud Providers**: AWS, Azure, VMware vSphere, VMware Cloud Director (on-premises/hybrid) **Key Open Source Technologies Used**: Kubernetes, Cluster API, Flux/FluxCD, Cilium, Kyverno, Falco, Trivy, Grafana, Mimir, Loki, Tempo, Alloy, Kong, ingress-nginx, CoreDNS, External DNS, Crossplane, External Secrets Operator, Backstage, Karpenter **Careers**: https://www.giantswarm.io/careers **Privacy Policy**: https://www.giantswarm.io/privacy-policy