LINESERVE

Load Balancers — Nairobi (ke-1a), Dar es Salaam (tz-1a) & Lagos (ng-1a) · launching soon

Coming soon

Load Balancers inside Kenya, Tanzania and Nigeria

Three countries no hyperscaler runs a region in. Put the entry point in the one your users are in.

If your customers are in Nairobi, Dar es Salaam or Lagos, the address they connect to is a decision you are already making — usually by accident, in favour of a continent they do not live on. Load Balancers put that entry point in the country: one public address, a pool of backends beside it in the same region, and a member that stops passing its health check leaving the rotation instead of taking the service with it. The same account, API and Terraform provider cover all three regions, so the country becomes a parameter rather than a project. They are launching soon, at a flat monthly price with no per-request charges, indicatively from $15. Join the waitlist and we will tell you when it is ready.

From$15/month
  • Launching soon in three regions — ke-1a Nairobi, tz-1a Dar es Salaam, ng-1a Lagos
  • HTTP, HTTPS, TCP and UDP, with SSL termination at the balancer
  • Health checks pull a failing backend out of the pool automatically
  • Flat monthly pricing, no per-request charges, settled in USD or locally
  • 99.99% uptime SLA, and unlimited transfer to same-region backends

Launching soon · Local billing in KES, TZS, NGN & UGX

Pricing

One flat price, no per-request fees

Pick a size for your traffic. Data transfer between the load balancer and same-region backends is unlimited and included. In your currency, no forex.

Small

$15/mo

Hosted in Nairobi, Dar es Salaam, Lagos & Kampala

  • 10,000 concurrent connections
  • 250 Mbps throughput
  • Up to 20 backends
  • Basic health checks
  • Unlimited same-region transfer
Popular

Medium

$30/mo

Hosted in Nairobi, Dar es Salaam, Lagos & Kampala

  • 50,000 concurrent connections
  • 1 Gbps throughput
  • Up to 50 backends
  • Advanced health checks
  • Unlimited same-region transfer

Large

$50/mo

Hosted in Nairobi, Dar es Salaam, Lagos & Kampala

  • 100,000 concurrent connections
  • 2.5 Gbps throughput
  • Up to 100 backends
  • Health checks with SSL verification
  • Unlimited same-region transfer

Enterprise

$100/mo

Hosted in Nairobi, Dar es Salaam, Lagos & Kampala

  • 250,000+ concurrent connections
  • 5+ Gbps throughput
  • Unlimited backends
  • Custom-script health checks
  • Unlimited same-region transfer

Flat monthly pricing with no hidden fees and no per-request charges. Upgrade or downgrade tiers anytime with zero downtime. Prices exclude VAT; local currency figures are indicative and settled at checkout.

Network

One account, three traffic calendars

Each of these countries produces a different shape of load, and whichever one your customers are in, you inherit that shape whether or not your architecture was built for it.

Kenya's peaks are civic and dated. A general election every five years in August, budget day in June, national exam results on a morning the whole country watches for — single-hour events on top of an ordinary curve, arriving over one dominant carrier that holds 68.9% of 84.1 million active mobile subscriptions. Tanzania's are administrative and seasonal: donor reporting cut-offs, month-start billing across a subscriber base, the tourism season into Arusha and Zanzibar, arriving from four networks of which the largest holds only 32.3%. Nigeria's are the sharpest of the three — ninety seconds of bet placement at kickoff, an eight-week retail peak from late October, a settlement window, a release date — landing from 189.68 million subscriptions concentrated about 86% on two carriers.

What all three share is that no global cloud runs a region in any of them. Amazon's African region is Cape Town; Microsoft's is in South Africa. Nairobi and Lagos carry real edge presence — content delivery, local zones, interconnect — and Dar es Salaam carries none of it, with the nearest content-delivery nodes in Nairobi, Mombasa, Lagos, Johannesburg and Cape Town. Edge terminates a connection and serves a cached copy of something static. It does not run your application, accept a write, or put an entry point in the country when a regulator asks where the request went.

Distance behaves badly here too. Paths between African networks have long been hauled north to Europe and handed back rather than exchanged on the continent, which is why a request from Lagos to Nairobi has commonly taken longer than the same request from Lagos to London, and why Cape Town is an international deployment from all three countries. What each city does have is its own exchange and its own landings. Nairobi has KIXP, with 141 peer networks and 2.9 Tbps of capacity, where Lineserve peers. Dar es Salaam exchanges Tanzanian traffic at TIX with 798G connected, in a city where SEACOM, EASSy and SEAS come ashore. Lagos has IXPN across 13 points of presence, peak domestic traffic past 2 Tbps by March 2026, behind eight subsea landings.

Put the balancer in the region its backends are in and a request from a user in that country reaches the entry point over domestic infrastructure — typically a single-digit-millisecond in-metro round trip rather than an ocean crossing — and the fan-out to the pool never leaves the city.

0

Hyperscale cloud regions in Kenya, Tanzania or Nigeria

3

Lineserve regions — ke-1a, tz-1a and ng-1a

2.9 Tbps

Capacity connected at KIXP, Nairobi (PeeringDB)

2 Tbps

Peak domestic traffic exchanged at IXPN, Lagos (March 2026)

One balancer per region, by design

A load balancer serves a pool of backends in its own region, and traffic between the two is unlimited and included — which is what keeps the price flat and the health checks free. Teams that want more than one of the three run a balancer in each and steer between them at the DNS layer, where the TTLs, the weights and the failover policy stay under their own control.

The question a security review actually asks

Not which cloud, but which country. Ask where the machine terminating your users' TLS physically stands, and where its access logs are written. If the answer for customers in Nairobi, Dar es Salaam or Lagos is Frankfurt, Cape Town or northern Virginia, then the entry point is a foreign dependency for domestic traffic — and the fix at launch is a region code rather than a rewrite.

Pricing & payment

In dollars from anywhere, or on the local entity's invoice

A balancer is priced as one flat monthly figure per balancer, with no per-request charge and no metered fee for traffic to same-region backends. The dollar figures below are indicative launch pricing — the shape of the bill rather than an amount payable today — and each currency has its own price list rather than a conversion applied when the page loads.

Four sizes, one flat monthly figure

Small is indicatively $15 a month for 10,000 concurrent connections and 250 Mbps across up to 20 backends. Medium is $30 for 50,000 connections and 1 Gbps. Large is $50 for 100,000 connections and 2.5 Gbps. Enterprise is $100 for 250,000-plus connections, 5-plus Gbps and unlimited backends — the same tiers in each of the three regions.

Card or bank transfer, in USD

From outside the three countries you are quoted, invoiced and settled in US dollars, whichever region you deploy into. Card suits a single balancer in front of a staging pool; transfer is the rail procurement is already configured for once a deployment is real, including a year taken up front at ten months for twelve on eligible services.

Or let the local entity carry it

If your Kenyan, Tanzanian or Nigerian subsidiary should hold the cost, switch it to that market and it settles in KES, TZS or NGN. Kenya and Tanzania add M-Pesa alongside bank transfer and card; Nigeria settles in Naira by bank transfer or card. A local finance team gets a local invoice, and the tax line follows the country: 16% in Kenya, 18% in Tanzania, 7.5% in Nigeria.

The waitlist costs nothing

No card, no commitment. Tell [email protected] which regions you would deploy into, how many backends, and which protocols matter, and that shapes what ships first.

Displayed prices exclude VAT, which is calculated and shown separately at checkout, and local-currency figures are indicative until launch. For a written quotation against a purchase order, [email protected].

The platform

Everything between your users and your servers

Termination, health checks, persistence, and protection — handled at the edge of your stack so your backends just serve.

Automatic failover

Failing backends drop out of the pool instantly and traffic reroutes to healthy servers — no manual intervention.

Smart health checks

Probe backends over HTTP, HTTPS, TCP, or ICMP with custom intervals, timeouts, and recovery thresholds.

SSL/TLS termination

TLS 1.2 and 1.3 with SNI for multiple certificates, automatic renewal, and encryption offloaded from your backends.

Four balancing algorithms

Round Robin, Least Connections, Source IP Hash, and Weighted Round Robin — match the algorithm to the workload.

Session persistence

Cookie-based or source-IP sticky sessions keep stateful clients pinned to the same backend.

DDoS protection built in

Rate limiting and connection throttling at the balancer, before traffic ever reaches your servers.

IPv4 & IPv6

Full dual-stack support on every load balancer, at every tier.

Real-time monitoring

Live traffic, connection counts, backend health, and access logs with request-level detail.

API & Terraform

Create and manage balancers from a REST API or the Terraform provider — wired into your CI/CD.

Regions

Nairobi, Dar es Salaam or Lagos — and what decides it

The rule is unglamorous and it holds nearly everywhere: put the workload in the country whose users and whose records it serves. Per-unit prices are identical in all three regions, so the decision is geography and law rather than cost — and there is no useful midpoint, because traffic between the three cities is still commonly carried through Europe.

ke-1a is for Kenyan users and Kenyan records, and for regional teams whose head office is already in Nairobi. Every Kenyan subsea cable — TEAMS, SEACOM, EASSy, LION2, DARE1 and PEACE — comes ashore at Mombasa, and that capacity is carried roughly 480 km inland to the city where the carriers and the customers are. Domestic traffic never makes that trip: it is exchanged inside Nairobi at KIXP, the neutral exchange TESPOK has run since 2002, with 141 peer networks and 2.9 Tbps of connected capacity. Lineserve peers there.

tz-1a is for Tanzanian users, and it is where moving an origin changes the most: Tanzania has no content-delivery edge of its own, so a Dar es Salaam viewer is served from another country however the CDN is configured. There is no inland haul either — SEACOM, EASSy and SEAS come ashore in the city itself, and Dar es Salaam is a named landing point on 2Africa. Tanzanian networks meet at TIX, run since 2003 by the country's service-provider association, and 13,820 km of state fibre carries one origin on to Mwanza, Arusha and Dodoma.

ng-1a is for scale and for regulated Nigerian workloads. Eight subsea systems land in and around Lagos, among them MainOne, SAT-3, WACS, Equiano and 2Africa, which comes ashore at Lekki. Nigerian networks exchange domestic traffic at IXPN, founded in 2006 to stop domestic packets being hauled to London and now running 13 points of presence across seven states. Lagos also has a date attached: a Central Bank circular directs payment transaction data generated in Nigeria to be stored there from 1 January 2027.

All three give a buyer based elsewhere the same pair of things: a request from a user in the city reaches a machine in that city, typically in single-digit milliseconds, and the records it touches sit under one named country's law.

Live

Kenya

Nairobi

~2 ms

typical, within metro · Data stays in Kenya

Live

Tanzania

Dar es Salaam

~6 ms

typical, within metro · Data stays in Tanzania

Live

Nigeria

Lagos

~4 ms

typical, within metro · Data stays in Nigeria

Live

Uganda

Kampala

~3 ms

typical, within metro · Data stays in Uganda

Expansion zonesSouth Africa · za-1aGhana · gh-1a

Use cases

Built for what you're building

Web applications

Spread HTTP and HTTPS traffic across your web servers for high volume with zero downtime.

APIs & microservices

A single entry point routing requests across API instances and containerized services.

Database read scaling

Balance read queries across replicas while writes go straight to the primary.

Gaming & streaming

Low-latency TCP and UDP balancing for player connections and high-bandwidth media.

How it works

In front of your traffic in three steps

1

Create a load balancer

Pick a region and a size tier — live in under 60 seconds from the console or API.

2

Add backends & health checks

Point it at your servers, choose an algorithm, and set the health check that fits.

3

Point your DNS at it

One record change and traffic flows through — failover and monitoring are already on.

Uptime SLA

99.9%

  • Service credits applied automatically when we miss the SLA
  • Measured monthly, per region, on network and power availability
  • Tier III colocation facilities across all live regions

Support

You are on a different continent from your infrastructure

That is the real reservation, and it is answerable with what exists. Architecture, quotes, contracts, a data processing agreement, the registered names and tax identifiers that have to appear on your invoices: [email protected], in writing, in a thread you can forward to your own legal and finance people. Running services are driven from the console, the API and the ticket system on your account. Two phone lines are published for the region — +254 119 039 063 in Kenya and +255 761 847 121 in Tanzania.

Scheduling across the distance is the practical problem, and the arithmetic is friendlier than it looks. Nairobi and Dar es Salaam run on East Africa Time, UTC+3; Lagos on West Africa Time, UTC+1. Neither observes daylight saving, so the gap between your clock and theirs moves only when your own clocks change, and a window agreed in June still means what you thought it meant in December. From London, Nairobi is three hours ahead in winter and two in summer, and Lagos an hour ahead in winter and level in summer. From New York in July, a 09:00 call is 14:00 in Lagos.

Most of what would be a phone call elsewhere is a call you make yourself. Building, resizing, rebooting, snapshotting and rebuilding an instance are API and console operations that behave identically at three in the morning your time or theirs, and a browser console reaches a machine that has lost its own networking. What needs a person in the building is a physical fault — and that person is there already.

Why Lineserve

Managed beats maintaining your own proxy

Running NGINX or HAProxy on a VPS means one more machine to patch, monitor, certify, and fail over — and it's usually the single point of failure in front of everything else.

CapabilityLineserveSelf-run NGINX/HAProxy
No proxy VM to run or patch
Automatic failoverSometimes
Managed SSL with auto-renewal
Upgrade capacity with zero downtime
Billing in KES, TZS, NGN & UGX
Support in your timezone
Data stays in-country

Data residency

The region code decides which law follows the request

Terminating TLS at the balancer moves part of your architecture forward: the certificate lives there, the user's connection ends there, and an access log with request-level detail is written there. That makes the entry point a residency decision in its own right, and each of the three regions answers to a different regime.

Kenya's Data Protection Act, No. 24 of 2019 is administered by the Office of the Data Protection Commissioner, and section 4(b) reaches a controller with no Kenyan establishment that processes the personal data of people in Kenya — so moving a server abroad moves the data and leaves the obligation. Section 48 makes transfers out conditional on safeguards demonstrated to the Data Commissioner or another listed ground, and Regulation 26 requires processing in Kenya, or a serving copy held there, for six named purposes including elections, public finance administration and basic education.

Tanzania is stricter about the border itself. Under the Personal Data Protection Act, 2022, personal data leaves the country on a permit from the Personal Data Protection Commission, and the Regulation 20 application asks for the recipient, the categories of data, the purpose and duration and the security arrangements at the destination. Prior authorisation finishes when a regulator says so rather than when you do.

Nigeria adds a date. The Nigeria Data Protection Act 2023 governs transfers under section 41, and the Central Bank's circular of 15 June 2026 directs that payment transaction data generated in Nigeria be stored and managed in Nigeria, with full compliance from 1 January 2027, across banks, mobile money operators, fintechs, switching companies and payment service providers. Deploy the entry point in ng-1a and that part of the path is in the country. The assessment, the evidence and the sign-off stay with your compliance function.

A second region is a decision, not a default

All three regions sit on one account and one API, which makes standby and replication a configuration rather than a project. Make the call deliberately: a copy of Kenyan, Tanzanian or Nigerian personal data in another country is a cross-border transfer under that country's rules. Application images, build artefacts and non-personal telemetry raise no such question.

What the buildings are

The regions sit inside carrier-neutral, Tier III data centres run by specialist facility operators, with Lineserve running its own hardware and network inside them. A security questionnaire asks two separate questions — which country the building stands in, and who has physical access to the machine — and both have a straight answer.

What a region supplies is location: data residency for Kenya's Data Protection Act, Tanzania's Personal Data Protection Act and Nigeria's Data Protection Act respectively. The controller obligations stay with you.

Who it is for

Fronting in-country infrastructure from outside the country

The reader here is usually not in Nairobi, Dar es Salaam or Lagos. Their customers are, and that is what makes the entry point worth moving.

SaaS with a serious in-country user base

A product headquartered elsewhere, with enough Kenyan, Tanzanian or Nigerian customers that their experience is a retention number rather than a rounding error. The usual shape is a regional pool of application servers with a balancer in front, deployed per country from the same Terraform as everywhere else — so a new market is a module invocation rather than a new runbook.

Payments and fintech expanding into the three markets

Webhook receivers, API gateways held to sub-second expectations, ledger and reconciliation services, KYC stores. Two things drive the region choice at once: the callback originates in-country, and the regulator has an opinion about where the record sits — most explicitly in Nigeria, where payment transaction data carries a 1 January 2027 date.

Media, streaming and content platforms

Origin storage plus egress, with a release date that behaves like a scheduled stampede and long-lived connections rather than short ones. TCP and UDP balancing across an origin pool in the country keeps those bytes off the subsea path for domestic viewers, with a CDN in front for everyone else.

Development programmes and international NGOs

Country platforms for health, education and monitoring — form servers taking submissions from field teams on mobile data, reporting dashboards that surge at a grant deadline. These systems hold personal data about beneficiaries in a country with its own regulator, which is why the entry point and the pool usually belong in the same country as the programme.

Enterprise standby and disaster recovery

A second site inside a country you already serve, sized small and grown when it is needed. A balancer in each region, with the switch made at the DNS layer under your own policy, is the pattern most teams end up with — deliberate, testable, and owned by the people who would have to run it at 03:00.

ISVs, agencies and resellers

One buyer, many client deployments, and a patching window that has to stop being an event. A pool behind one address means taking a backend out of rotation, working on it, and letting the health check decide when it is fit to serve again — from an API rather than a console.

Cloud servers, VPS, dedicated hardware, object storage and colocation are live in all three regions today and are what a balancer will sit in front of. Load Balancers themselves are launching soon — join the waitlist through [email protected].

Before launch

Where your entry point is today

A cloud load balancer on another continent

The most common shape by far: backends that have already moved into the country, behind an entry point that stayed where the account was created. Every domestic request then leaves the country to reach the thing that sends it back in — twice per round trip, on the day of the year it can least afford to. It also means the TLS termination point, and the logs it writes, sit under a different country's law from the data behind it. The fix at launch is an entry point in the same region as the pool.

Self-run NGINX or HAProxy on a VPS

The other majority case, and it holds until the machine that is running your proxy needs patching during your busiest week. It is one instance to monitor, certify and fail over, sitting in front of everything else — the cheapest component in the stack and the single point of failure at the same time. A managed balancer takes that off the rota. The preparation that pays before launch costs nothing: interchangeable backends, sessions out of local memory, and a health endpoint on each machine that answers honestly.

Three questions settle most of it, for any provider including this one. Which country is the machine physically in? Is domestic traffic exchanged inside that country? And what does the uptime SLA pay when it is missed, and who claims it?

FAQ

Questions, answered

It sits in front of your servers on a single IP and distributes incoming traffic across them. If a backend fails, traffic reroutes to healthy servers automatically — better availability, better performance, no single point of failure.

A flat monthly rate per size tier — Small, Medium, Large, or Enterprise. Data transfer between the load balancer and backends in the same region is unlimited and included. No per-request charges, no hidden fees.

Yes. Backends can be Lineserve Cloud Servers, VPS, dedicated servers, Kubernetes nodes — or servers hosted anywhere else, as long as the load balancer can reach them over the network.

Upload certificates to the load balancer and it terminates SSL/TLS for you, offloading encryption from your backends. TLS 1.2 and 1.3 are supported, with SNI for serving multiple certificates from one load balancer and automatic renewal.

The load balancer probes each backend over HTTP, HTTPS, TCP, or ICMP on an interval you set. Servers that fail their threshold are removed from the pool automatically and re-added once they recover.

Sticky sessions route a returning client to the same backend — essential for apps that keep session state locally. Choose cookie-based or source-IP persistence per load balancer.

Round Robin for evenly matched servers, Least Connections for long-lived connections, Source IP Hash to pin clients to a server, and Weighted Round Robin to send more traffic to bigger machines.

Yes. Upgrade or downgrade anytime with zero downtime — your configuration, certificates, and backend pools carry over unchanged.

They are in build and there is no public date yet. Nairobi (ke-1a), Dar es Salaam (tz-1a) and Lagos (ng-1a) are the regions in view for the first release. Join the waitlist through [email protected] and you will hear from us when there is something to point at.

Indicative launch pricing runs from $15 a month for Small, $30 for Medium, $50 for Large and $100 for Enterprise — flat monthly figures per balancer, with no per-request charges. Those numbers are indicative until launch and exclude VAT.

Early access is being allocated by workload rather than by queue position. Tell [email protected] which regions you would deploy into, how many backends, which protocols, and the peak you are sizing for, and that conversation is how a place is reserved.

Not yet. Load Balancers are launching soon, and this page shows what they will look like when they land. Cloud servers, VPS, dedicated hardware, object storage and colocation in all three regions are live now and are what a balancer will sit in front of.

ke-1a in Nairobi, tz-1a in Dar es Salaam and ng-1a in Lagos — the same three regions, the same tiers, on one account and one API.

A load balancer serves a pool of backends in its own region, which is what the included unlimited same-region transfer covers. For a presence in more than one of the three, run a balancer in each region and steer between them at the DNS layer, where the failover policy stays under your control.

HTTP, HTTPS, TCP and UDP, dual-stack on IPv4 and IPv6 at every tier, across Round Robin, Least Connections, Source IP Hash and Weighted Round Robin. Session persistence is available as cookie-based or source-IP sticky sessions where a client has to stay pinned to one backend.

Yes. TLS 1.2 and 1.3 with SNI for multiple certificates, automatic renewal, and the encryption work taken off your backends.

Health checks probe your backends over HTTP, HTTPS, TCP or ICMP with intervals, timeouts and recovery thresholds you set. A backend that stops passing drops out of the pool and traffic reroutes to the healthy ones, with no manual intervention, and it returns to rotation once it passes again.

Yes — balancers are created and managed from a REST API and a Terraform provider as well as the console, which is what makes a per-region deployment a parameter rather than a separate runbook.

In US dollars, by card or bank transfer, whichever region you deploy into. If your local subsidiary should carry the cost instead, switch that market on and it settles in KES, TZS or NGN — with M-Pesa available in Kenya and Tanzania alongside bank transfer and card.

Because none of them runs a region in Kenya, Tanzania or Nigeria. Amazon's African region is Cape Town and Microsoft's is in South Africa, so the entry point lands outside the country your users and your regulator are in. Lagos and Nairobi carry edge presence, which caches static content rather than terminating your application's traffic in-country.

The one the region is in. A balancer in ke-1a holds its certificate, connections and access logs in Nairobi under Kenya's Data Protection Act; tz-1a in Dar es Salaam under Tanzania's Personal Data Protection Act; ng-1a in Lagos under Nigeria's Data Protection Act. That is data residency; your own controller obligations travel with you.

No. The price is a flat monthly figure for the tier, and transfer between the balancer and same-region backends is unlimited and included. Tiers move up or down without downtime.

Make the backends interchangeable. Configuration out of the image, sessions out of local memory, a health endpoint on each machine that reports whether it can actually serve, and a known answer to how long a cold backend takes to become useful. Do that before launch and putting a balancer in front is a DNS change on the day.

Put a load balancer in front of it — soon

Load Balancers are launching soon. Talk to us to reserve early access and pricing in your local currency, with no card to start.

Launching soon · 99.99% uptime SLA · Local billing in KES, TZS, NGN & UGX