The user expresses concern about Exoscale's lack of private clusters and API IP allowlisting, which are critical for security in regulated environments. They suggest these features should be added.
Been testing EU managed k8s providers one by one for [eucloudcost.com](http://eucloudcost.com), Exoscale SKS was next. Posted about [OVHcloud last week](https://www.reddit.com/r/devops/comments/1rmp4f9/handson_with_ovhcloud_managed_kubernetes/) and some fine Redditor was kind enough to offer me a promo code for Exoscale. So here we are with €150 of free credit. Short version: the DX is genuinely good. Cluster up in under 2 minutes, load balancer IP in 6 seconds, support answered a ticket on a trial account in 6 minutes. You also get to pick your CNI (Cilium or Calico) which none of the other EU providers I tested offer. Also IOPS is nice, FIO benchmarks are in the writeup, roughly 4000 combined IOPS on random 4K RW. Then I looked at the security model. No private clusters, no API IP allowlisting, kubelet open to 0.0.0.0/0 because control plane CIDRs are not published. Coming from regulated environments this is a hard no for me. OVHcloud solves this with vRack, Exoscale just does not have an answer here yet (unfortunately). Also no default StorageClass out of the box, and I was confused about this. Full OpenTofu reference repo if you want a starting point: [https://github.com/mixxor/opentofu-kubernetes-exoscale](https://github.com/mixxor/opentofu-kubernetes-exoscale) Full writeup in the comments. Anyone running Exoscale SKS in prod? Did I miss something on protecting the k8s API? Do you like this content? And who should be next?