LINESERVE

Managed Kubernetes — launching in Nairobi, Dar es Salaam & Lagos

Coming soon

Clusters in three countries, without three SREs to run them

We take the API server, the scheduler and etcd. You take a kubeconfig.

Running a control plane properly is specialist work — etcd backups you have rehearsed, certificate rotations that do not take the cluster with them, upgrades on somebody's Saturday. Very few teams can spare a person for it, and almost nobody can spare one per country. Managed Kubernetes runs that layer for you in ke-1a, tz-1a and ng-1a, with autoscaling worker pools underneath and a cluster fee that opens at $27.86 a month plus the resources you use. It is launching soon. Join the waitlist and we will tell you the week it is ready.

Clusters from$27.86/month + resources
  • Launching soon — join the waitlist for early access
  • Managed control plane: API server, scheduler, etcd
  • Clusters in Nairobi, Dar es Salaam or Lagos
  • Autoscaling worker pools, down to zero when idle
  • Priced in USD, or in KES, TZS and NGN where the local entity buys

Launching soon · Local billing in KES, TZS, NGN & UGX

Pricing

A cluster fee, plus what your nodes use

Pick a control plane — Basic or Fault Tolerant — then pay only for the vCPU, RAM, storage, and load balancers your worker nodes actually consume. In your currency, no forex.

Basic

Single master node for development, testing, and non-critical workloads.

$27.86/mo + resources

Hosted in Nairobi, Dar es Salaam, Lagos & Kampala

  • 1 master node
  • 99.5% control-plane SLA
  • Kubernetes 1.28–1.31
  • Autoscaling worker pools
  • Prometheus & Grafana included
Recommended

Fault Tolerant

3 master nodes with automatic failover — recommended for production.

$116.34/mo + resources

Hosted in Nairobi, Dar es Salaam, Lagos & Kampala

  • 3 master nodes, automatic failover
  • 99.95% control-plane SLA
  • Kubernetes 1.28–1.31
  • Autoscaling worker pools
  • Prometheus & Grafana included

Worker node resources

Billed monthly, per unit consumed, on top of the cluster fee.

ResourceUnitPrice /mo
vCPUper vCPU$6.66
RAMper GB$3.06
Local diskper GB$0.19
Network HDDper GB$0.15
Universal SSDper GB$0.23
Fast SSDper GB$0.34
Public IPper IP$1.50
Load balancer — Basicper LB$16.38
Load balancer — Basic, redundantper LB$32.77
Load balancer — Advanced, redundantper LB$65.53

Your monthly total is the cluster fee plus the resources your worker nodes consume. Snapshots, file storage, and traffic beyond the included allowance bill at the same per-GB console rates. Prices exclude VAT; local currency figures are indicative and settled at checkout.

Where the cluster stands

A cluster is a country decision before it is a config decision

Kubernetes makes almost everything portable and one thing stubbornly physical: the machines. Manifests move between clusters in an afternoon. The persistent volumes attached to those manifests hold real data in a real building in a real jurisdiction, and the users hitting the ingress are wherever they are. Choosing a region is choosing both, and it is the decision that is expensive to revisit later.

The east-west traffic inside a cluster is what makes distance compound. A request arrives at the ingress, hits a service, which calls two more, which each read from a database and a cache. That is one user request and eight network hops before a response exists. Inside one region those hops happen in a building and a request that starts and finishes in the same metro is typically a single-digit millisecond round trip. Stretched across an ocean, the same eight hops become the whole latency budget.

Lineserve runs ke-1a in Nairobi, tz-1a in Dar es Salaam and ng-1a in Lagos, on identical resource rates, so the region is chosen on geography and law rather than on price. All three sit in countries where domestic traffic is exchanged locally — Nairobi at the exchange TESPOK has run since 2002, Dar es Salaam at the one Tanzania's service-provider association has run since 2003, Lagos at the national exchange founded in 2006 to stop Nigerian packets being hauled to London. Your ingress is on the same side of the ocean as the people using it.

There is no hyperscale cloud region inside any of the three: the nearest full regions are in South Africa. What these cities have from the large providers is edge, which caches responses and does not schedule pods. A cluster in ng-1a is compute in Nigeria rather than near it — which is the distinction that matters when a customer or a regulator names the country.

3

Countries you can place a cluster in at launch

1.28–1.31

Kubernetes versions at launch

99.95%

Control-plane SLA on Fault Tolerant clusters

0

Hyperscale cloud regions inside Kenya, Tanzania or Nigeria

One cluster per country, not one cluster in the middle

Traffic between Nairobi, Dar es Salaam and Lagos is still commonly carried through Europe, so a cluster placed midway between two of these markets serves neither well. Where you need presence in two countries, the answer at launch is two clusters on one account and one API — with the same manifests, the same Helm charts and the same CI pipeline pointed at a different kubeconfig.

What comes wired in

A CSI driver that provisions HDD, Universal SSD or Fast SSD volumes straight from your PVCs; Services of type LoadBalancer that provision a cloud load balancer; an NGINX ingress controller and Helm from any repository; Prometheus and Grafana with alerting on every cluster. Private clusters — control plane and workers with no public IPs, reached over VPN or a bastion — are part of the first release.

The platform

Everything a production cluster needs

Networking, storage, monitoring, and access control come wired in — so day two looks like day one.

Managed control plane

API server, scheduler, controller manager, and etcd — run, upgraded, and backed up by us.

Autoscaling worker pools

The cluster autoscaler adds and removes nodes with demand, down to zero when idle.

Auto-healing nodes

Unhealthy nodes are detected and replaced automatically, with no manual intervention.

Persistent volumes

A CSI driver provisions HDD, Universal SSD, or Fast SSD volumes straight from your PVCs.

Private clusters

Run control plane and workers with no public IPs, reached over VPN or a bastion host.

Load balancer integration

Services of type LoadBalancer provision cloud load balancers automatically.

Prometheus & Grafana

Built-in monitoring and dashboards on every cluster, with alerting included.

Helm & NGINX ingress

Deploy from any Helm repository, with a built-in NGINX ingress controller for traffic.

Multiple K8s versions

Choose Kubernetes 1.28–1.31 and upgrade through the console with zero downtime.

Regions

Nairobi, Dar es Salaam or Lagos — and what decides it

The rule is unglamorous and it holds nearly everywhere: put the workload in the country whose users and whose records it serves. Per-unit prices are identical in all three regions, so the decision is geography and law rather than cost — and there is no useful midpoint, because traffic between the three cities is still commonly carried through Europe.

ke-1a is for Kenyan users and Kenyan records, and for regional teams whose head office is already in Nairobi. Every Kenyan subsea cable — TEAMS, SEACOM, EASSy, LION2, DARE1 and PEACE — comes ashore at Mombasa, and that capacity is carried roughly 480 km inland to the city where the carriers and the customers are. Domestic traffic never makes that trip: it is exchanged inside Nairobi at KIXP, the neutral exchange TESPOK has run since 2002, with 136 peer networks and 2.9 Tbps of connected capacity. Lineserve peers there.

tz-1a is for Tanzanian users, and it is where moving an origin changes the most: Tanzania has no content-delivery edge of its own, so a Dar es Salaam viewer is served from another country however the CDN is configured. There is no inland haul either — SEACOM, EASSy and SEAS come ashore in the city itself, and Dar es Salaam is a named landing point on 2Africa. Tanzanian networks meet at TIX, run since 2003 by the country's service-provider association, and 13,820 km of state fibre carries one origin on to Mwanza, Arusha and Dodoma.

ng-1a is for scale and for regulated Nigerian workloads. Eight subsea systems land in and around Lagos, among them MainOne, SAT-3, WACS, Equiano and 2Africa, which comes ashore at Lekki. Nigerian networks exchange domestic traffic at IXPN, founded in 2006 to stop domestic packets being hauled to London and now running 13 points of presence across seven states. Lagos also has a date attached: a Central Bank circular directs payment transaction data generated in Nigeria to be stored there from 1 January 2027.

All three give a buyer based elsewhere the same pair of things: a request from a user in the city reaches a machine in that city, typically in single-digit milliseconds, and the records it touches sit under one named country's law.

Live

Kenya

Nairobi

~2 ms

typical, within metro · Data stays in Kenya

Live

Tanzania

Dar es Salaam

~6 ms

typical, within metro · Data stays in Tanzania

Live

Nigeria

Lagos

~4 ms

typical, within metro · Data stays in Nigeria

Live

Uganda

Kampala

~3 ms

typical, within metro · Data stays in Uganda

Expansion zonesSouth Africa · za-1aGhana · gh-1a

Use cases

Built for what you're building

Microservices

Run service meshes with built-in discovery, load balancing, and rolling deploys.

CI/CD pipelines

Host Jenkins, GitLab runners, or Argo CD close to your team, scaling with each build.

Batch & ML workloads

Queue batch jobs and training runs on autoscaling pools that shrink when idle.

Dev environments

Give every team an isolated namespace — one cluster, clean boundaries, less sprawl.

How it works

From zero to cluster in four steps

1

Pick region, version & cluster type

Choose your region, a Kubernetes version, and Basic or Fault Tolerant control plane.

2

Add worker pools

Size pools in vCPU, RAM, and storage, and set autoscaler bounds per pool.

3

Deploy with your tools

Download the kubeconfig, then kubectl apply or helm install like any cluster.

4

Let it run

The autoscaler tracks demand and auto-healing replaces bad nodes — day and night.

Uptime SLA

99.9%

  • Service credits applied automatically when we miss the SLA
  • Measured monthly, per region, on network and power availability
  • Tier III colocation facilities across all live regions

Support

You are on a different continent from your infrastructure

That is the real reservation, and it is answerable with what exists. Architecture, quotes, contracts, a data processing agreement, the registered names and tax identifiers that have to appear on your invoices: [email protected], in writing, in a thread you can forward to your own legal and finance people. Running services are driven from the console, the API and the ticket system on your account. Two phone lines are published for the region — +254 119 039 063 in Kenya and +255 761 847 121 in Tanzania.

Scheduling across the distance is the practical problem, and the arithmetic is friendlier than it looks. Nairobi and Dar es Salaam run on East Africa Time, UTC+3; Lagos on West Africa Time, UTC+1. Neither observes daylight saving, so the gap between your clock and theirs moves only when your own clocks change, and a window agreed in June still means what you thought it meant in December. From London, Nairobi is three hours ahead in winter and two in summer, and Lagos an hour ahead in winter and level in summer. From New York in July, a 09:00 call is 14:00 in Lagos.

Most of what would be a phone call elsewhere is a call you make yourself. Building, resizing, rebooting, snapshotting and rebuilding an instance are API and console operations that behave identically at three in the morning your time or theirs, and a browser console reaches a machine that has lost its own networking. What needs a person in the building is a physical fault — and that person is there already.

Why Lineserve

Managed here beats self-managed anywhere

Running your own control plane on VMs means patching, etcd backups, and 2 a.m. failovers. Running on a distant hyperscaler means forex bills and latency. This is the third option.

CapabilityLineserveSelf-managed / global cloud
Control plane run and upgraded for you
Billing in KES, TZS, NGN & UGX
Single-digit local latency
Data stays in-country
Autoscaling worker poolsSometimes
Support in your timezone
No card or forex required

What it will cost

A cluster fee, then the resources the pods actually asked for

Two numbers make up a Kubernetes bill here, and keeping them separate is what makes the second one predictable. The first is the cluster management fee: Basic, a single master node suited to development, testing and non-critical workloads, at $27.86 a month behind a 99.5% control-plane SLA; or Fault Tolerant, three master nodes with automatic failover, at $116.34 behind a 99.95% SLA. Production goes on Fault Tolerant. Everything else is a judgement call about how much a broken control plane would cost you on a Tuesday.

The second is worker resources, billed per unit consumed: $6.66 per vCPU and $3.06 per GB of RAM a month, node-local disk at $0.19 per GB, and persistent volumes at $0.15 per GB for Network HDD, $0.23 for Universal SSD and $0.34 for Fast SSD. A public IP is $1.50. Load balancers are $16.38 for a Basic, $32.77 for a Basic with automatic failover and $65.53 for an Advanced redundant one. Nothing is bundled into a node size you did not choose, which means a pool you scale down actually gets cheaper.

That structure is the reason autoscaling is worth turning on rather than admiring. Pools scale with demand and down to zero when idle, so a batch pool that runs for four hours a night is billed for four hours a night rather than for a machine that sat warm. At launch this is the number to model: cluster fee plus steady-state pool plus whatever the peak actually costs for the hours it lasts.

Tax sits on top and depends on which entity buys: 16% VAT in Kenya, 18% in Tanzania, 7.5% in Nigeria, each shown separately at checkout rather than folded into the rate. The international market is quoted and settled in US dollars by card or bank transfer, and where your Kenyan, Tanzanian or Nigerian subsidiary should be the buyer instead, the same plan carries that country's own price list.

Reserve pricing while you still have a budget cycle

Tell [email protected] the cluster tier, the rough pool shape and the regions you would use, and the team will put launch pricing in writing against your account. Procurement usually needs a number long before an engineering team needs a cluster.

Two clusters cost two cluster fees

Worth saying plainly, because it changes the architecture: presence in two countries means two control planes and two management fees. For many teams the right shape at launch is one Fault Tolerant cluster in the country that matters most and one Basic cluster in the second, rather than two of everything.

Prices exclude VAT and are the launch price list rather than an amount payable today. Worker resources bill per unit consumed, and annual billing is ten months for twelve on eligible plans.

Data residency

The manifests are portable. The volumes are not.

It is easy to think of a cluster as stateless and therefore as a residency non-question. Then you list the PersistentVolumeClaims. The uploads bucket mirror, the Postgres a team ran with a Helm chart, the queue that holds message bodies, the logs with user identifiers in them, the registry cache with your own artefacts. All of it is data, all of it sits on disks in one building, and all of it is in whichever country you picked when you created the cluster.

Kenya. The Data Protection Act, 2019 applies to anyone processing the personal data of data subjects located in Kenya, whether or not they are established there, and sections 48 and 49 attach conditions to sending that data abroad. Regulation 26 of the 2021 General Regulations is narrower and sharper: for civil registration and identity, elections, public finance systems, a designated protected computer system, basic education, or primary and secondary healthcare, at least one serving copy of that personal data belongs in a data centre located in Kenya. A cluster in ke-1a is where that copy runs.

Tanzania. Under the Personal Data Protection Act, 2022 personal data leaves the country on a permit from the Personal Data Protection Commission, applied for in advance with the recipient, the categories, the purpose, the duration and the destination's security arrangements set out. Prior authorisation is a different animal from a self-assessment, and it runs on the regulator's timetable. Keeping the volumes in tz-1a is the version where the question does not arise.

Nigeria. Section 41 of the Nigeria Data Protection Act 2023 governs transfers out of the country. Alongside it, a Central Bank circular of 15 June 2026 directs that payment transaction data generated in Nigeria be stored and managed in Nigeria, with full compliance from 1 January 2027, across banks, mobile money operators, fintechs, switching companies and payment service providers. If a pod in your cluster writes settlement records, the cluster's country is now a dated requirement rather than a preference.

Choosing the region is what a hosting provider supplies. Data in ke-1a is held in Nairobi under Kenyan law, in tz-1a in Dar es Salaam under Tanzanian law, in ng-1a in Lagos under Nigerian law, and it does not leave without your instruction. Your own obligations as controller are unchanged — they are simply shorter when nothing crossed a border.

Where your backups go is part of the answer

Velero snapshots, database dumps and object storage mirrors are exactly the kind of thing that quietly ends up in a bucket on another continent because that is where the credentials already pointed. Object storage runs per-region endpoints in all three countries, so a backup target inside the same country is a configuration line rather than a project.

Non-personal state travels freely

Container images, build artefacts, Helm charts and telemetry stripped of identifiers raise none of these questions and can live wherever your pipeline is happiest. It is worth drawing that line explicitly in your own architecture, because the cost of treating everything as sensitive is a system nobody can operate.

Who this is for

Small platform teams with more countries than people

Managed Kubernetes is aimed squarely at teams for whom the control plane is a cost they cannot justify and cannot avoid. These are the shapes that come up most from outside these three markets.

A platform team of three, and a fourth country to serve

You already run clusters where your company is. A customer contract now requires workloads inside Kenya, Tanzania or Nigeria, and nobody on the team is available to become that region's on-call. A managed control plane there means the new country costs you a kubeconfig and a pipeline target rather than a hire.

A SaaS vendor deploying per-tenant into a regulated customer

The bank, the insurer or the telco wants your product in their country and their auditor wants to know where the volumes are. Same Helm chart, same values file, different region — and a residency answer that fits on one line of a security questionnaire.

An agency or MSP with many client workloads

Dozens of small services with wildly different traffic, all of which would be uneconomic as individual VMs. One cluster, one namespace per client, resource quotas at the boundary, and worker pools that scale with the aggregate rather than the worst case. The control plane being someone else's job is what makes the model work at agency margins.

Bursty consumer traffic in a market you do not sit in

A match kickoff, an exam window, a festive-season sale, a breaking news hour. The pattern is a flat baseline and a violent, scheduled peak, which is what the autoscaler is for — pools grow when the demand arrives and shrink back afterwards, and you are billed for the vCPU and RAM those hours actually used.

Batch, ETL and model training on a schedule

Pipelines that need real capacity for a few hours and none for the rest of the day. A pool with an autoscaler floor of zero costs nothing while it is idle, which is a different economic shape from a reserved cluster sitting warm for a nightly job.

CI runners close to the artefacts they build

GitLab runners, Argo CD, Jenkins agents — placed in the same country as the registry they push to and the cluster they deploy into. It removes an ocean from the middle of every pipeline run, and it keeps build artefacts under the same jurisdiction as the thing they are built for.

Customer references are available under NDA. Tell [email protected] the country and the workload shape and the team will point you at the closest match.

Migrating

What moving a cluster here will look like at launch

From a managed cluster on another cloud

This is the easy direction, because Kubernetes is the portable part. kubectl, Helm and Velero all work directly: export the namespaces, review anything that reaches for a provider-specific annotation or a proprietary storage class, point the CSI driver at HDD, Universal SSD or Fast SSD instead, re-issue the ingress, and cut DNS when both are healthy. The parts that need real thought are stateful: what happens to the volumes, how the data gets there, and how long a write pause your service can survive. Migration planning is included at no extra charge and it is worth doing before launch, so the cluster you get on day one is already the right shape.

From a control plane you run yourself

kubeadm on three VMs works, right up until the afternoon it does not. What changes here is who is holding the pager when a certificate expires, when etcd needs a restore rather than a restart, when a minor upgrade goes sideways with production on it. At launch the control plane — API server, scheduler, controller manager and etcd — is run, upgraded and backed up by us, unhealthy nodes are detected and replaced automatically, and version upgrades between 1.28 and 1.31 run through the console. Your manifests are unchanged. Your weekends are the deliverable.

Migration planning and assistance are included at no extra charge. Send [email protected] your current version, the rough pool shape and what your volumes hold, and the team will map the move before the service opens.

FAQ

Questions, answered

A service where we run the Kubernetes control plane for you — API server, scheduler, controller manager, and etcd — and handle upgrades, backups, and availability. You deploy and manage your applications; we keep the cluster healthy.

Basic clusters run a single master node and suit development, testing, and non-critical workloads, with a 99.5% control-plane SLA. Fault Tolerant clusters run 3 master nodes with automatic failover on a 99.95% SLA — recommended for production.

You pay the monthly cluster management fee (Basic or Fault Tolerant) plus the worker-node resources you actually consume — vCPU, RAM, storage, and load balancers. Scale worker pools up or down anytime; you only pay for what you use.

Versions 1.28 through 1.31, with new versions added shortly after upstream release. You upgrade your cluster through the console with zero downtime.

Yes. Enable the cluster autoscaler, set minimum and maximum node counts, and it adds or removes worker nodes automatically as your workload demands.

Yes. Create a cluster where the control plane and worker nodes have no public IP addresses, and reach it through a VPN or bastion host for maximum security.

Our CSI driver provisions volumes automatically when you create PersistentVolumeClaims. Choose HDD, Universal SSD, or Fast SSD storage classes to match your performance needs.

Yes. Every cluster ships with built-in Prometheus monitoring and Grafana dashboards. Container logs can flow to our logging service or your own backend.

Yes. Standard tools like kubectl, Helm, and Velero work directly, and our team assists with migration planning at no extra charge.

It is in build and not open for orders. Rather than publish a date that moves, we tell the waitlist directly — email [email protected] with the regions and workloads you have in mind and you will hear when the first release is ready.

Not yet. What you can do now is size the cluster and the pools with us, get launch pricing in writing, and be in the first group given access. Teams with a migration ahead of them get the most from starting that early.

ke-1a in Nairobi, tz-1a in Dar es Salaam and ng-1a in Lagos — the three regions already live for cloud servers, VPS, dedicated hardware and object storage.

Basic runs a single master node and suits development, testing and non-critical workloads, on a 99.5% control-plane SLA at $27.86 a month. Fault Tolerant runs three master nodes with automatic failover on a 99.95% SLA at $116.34. Production belongs on Fault Tolerant.

The monthly cluster management fee plus the worker resources you consume — $6.66 per vCPU, $3.06 per GB of RAM, $0.19 per GB of node-local disk, persistent volumes from $0.15 per GB, public IPs at $1.50 and load balancers from $16.38. Scale pools up or down and the resource line follows.

No. Those are launch figures and nothing bills until the service opens. If your budget cycle needs a quotation before then, ask [email protected] for one against your account.

1.28 through 1.31 at launch, with upgrades run through the console. New versions follow shortly after upstream release.

Yes. Set minimum and maximum node counts per pool and the cluster autoscaler adds and removes nodes with demand, down to zero on pools that are idle.

Yes — control plane and worker nodes with no public IP addresses, reached over VPN or a bastion host. That is part of the first release rather than a later tier.

A CSI driver provisions them from your PersistentVolumeClaims, with HDD, Universal SSD and Fast SSD storage classes to match the workload. Those volumes live in the region you created the cluster in.

Yes. Prometheus and Grafana dashboards ship on every cluster with alerting included, and container logs can flow to our logging service or to a backend you already run.

Yes. Worker nodes and their volumes sit in the region you selected — Nairobi, Dar es Salaam or Lagos — and are not moved out of that country without your instruction. Route your backups to the same country's object storage endpoint and the whole path stays in one jurisdiction.

That is the wrong shape here, and the reason is physics rather than policy: traffic between these three cities is still commonly carried through Europe, so a stretched control plane would be making an intercontinental round trip to reach half its nodes. Two clusters on one account and one API is the pattern, with the same manifests deployed to each.

It is upstream Kubernetes on standard tooling — kubectl, Helm and Velero — so your manifests and your state move out the way they moved in. Confirming that before you commit is a reasonable thing to do with any managed platform, this one included.

Yes, at no extra charge, and preferably before launch. Send your current version, pool shape, storage classes and what your volumes hold to [email protected].

Email [email protected] or use the contact form with the regions, the cluster tier and the rough pool shape you would use. No card, no commitment — it puts you in the first group given access and gets launch pricing written against your account.

Ship on Kubernetes, skip the control plane

Managed Kubernetes is launching soon. Talk to us to reserve early access and pricing in your local currency, with no card to start.

Launching soon · 99.95% control-plane SLA on Fault Tolerant · Local billing in KES, TZS, NGN & UGX