The Open Source Discovery Point showcases open-source components developed within the IPCEI-CIS ecosystem. This tool provides visibility into OSS components functionalities, repositories, licences, and architecture domains across participating initiatives, supporting interoperability, collaboration, and knowledge sharing within the European cloud-edge ecosystem.

Add your IPCEI-CIS OSS component

The AI Trust Platform enables organizations to register AI assets once and maintain continuous, automated EU AI Act compliance - centralizing transparency, monitoring, and documentation in one place, with automatic requirements updates, gap analysis, and mitigation proposals.
  • Centralized Compliance Infrastructure: Provides shared, reusable compliance capabilities — transparency, monitoring, documentation, and oversight — across AI systems.
  • Automated Regulatory Tracking: Continuously tracks EU AI Act requirements and proactively surfaces gaps and mitigation proposals, reducing the need for manual ex-post remediation.
  • Compliance-by-Design: Embeds compliance mechanisms directly into the AI development lifecycle, enabling scalable and consistent implementation across all registered AI systems.
  • Proactive Stakeholder Notifications: Automatically notifies responsible stakeholders whenever the compliance status of an AI system changes, ensuring accountability without manual follow-up.
CobaltCore is a cloud-native IaaS platform combining Kubernetes-native orchestration with OpenStack-influenced services to deliver a modern cloud distribution for cloud-native and traditional workloads alike. It ensures backward compatibility for stateful VMs and traditional network configurations. Compute, storage, and networking lifecycles are fully managed through Kubernetes APIs and wired together by feature-rich services covering every operational concern of a modern data center, enabling production-grade deployments at any scale within weeks, from bare metal up.
  • Automated Lifecycle: Compute, storage, networking, and AI hardware lifecycles are fully automated through IronCore Bare Metal Management and Kubernetes-native operators - from bare metal provisioning to day-2 operations.
  • Gardener Extensions: Gardener and GardenLinux extensions provide coordinated control-plane maintenance for the KVM hypervisor and storage fleet, ensuring reliable and non-disruptive updates at any scale.
  • Greenhouse Integration: Operational concerns are seamlessly integrated with the Greenhouse Operations Platform and Heureka Security Posture Management, giving operators a unified view across the entire data center.
The Open Crypto Broker moves cryptographic operations into a managed environment, enabling governance and policies over which algorithms are allowed. It provides a unified interface for crypto operations to help workloads become crypto-agile.
  • Simplified Crypto Consumption: Simplifies consumption of cryptographic operations by providing a unified, profile-based interface to diverse underlying crypto implementations.
  • Governance & Algorithm Control: Manages and controls allowed cryptographic operations, enabling organizations to enforce policies over which algorithms may be used.
  • Crypto-Agility: Helps cryptographic workloads become crypto-agile, making it straightforward to swap algorithms in response to new standards or Post-Quantum Cryptography requirements.
Garden Linux is a minimal, immutable, API-driven operating system layer for automated, Kubernetes-centric platforms. It is not a general-purpose Operating System targeting all possible use-cases & scenarios.
  • Lightweight & Optimized Container OS: Minimal footprint container OS designed for Kubernetes nodes and container base images, with an easy-to-use build system.
  • Advanced Security & Auditability: Features immutable root filesystems, a hardened LTS kernel, secure boot, remote attestation, and built-in security modules like SELinux and AppArmor.
  • Compliance & Future-Ready: Meets industry standards including CIS and DISA STIG, and integrates emerging Post-Quantum Cryptography algorithms.
  • Cross-Platform & Multi-Cloud: Provides ready-made images for major cloud providers and on-premises environments, reducing integration effort.
  • State-of-the-Art Technology: Fully systemd-based architecture ensuring modern, robust system management and repeatable, auditable builds.
  • Qualified Baseline: All ApeiroRA components will be streamlined and qualified on Garden Linux only, providing a single, fully supported OS baseline across the entire stack.
Deliver fully-managed Kubernetes clusters at scale everywhere with your own Gardener installation. A robust, scalable, and production-hardened, certification-ready open-source system managing Kubernetes clusters across many infrastructure providers — embodying open standards and interoperability as a bootstrap building block in ApeiroRA.
  • Homogeneous Multi-Cloud Experience: Gardener's extension mechanism and multi-region seed cluster deployment deliver a consistent, homogeneous and scalable Kubernetes setup across cloud providers. It abstracts infrastructure complexity, streamlining operations and boosting developer productivity.
  • High Availability & Resource Efficiency: Gardener's hosted control planes pattern ensures resilient control planes with automatic recovery and live migration options for demanding scenarios. Its dynamic scaling algorithms optimize resource usage, reducing downtime and lowering TCO.
  • Simplified Fleet Management: Gardener simplifies operations by enabling administrators to manage multiple shoot clusters from a single garden cluster, streamlining updates, scaling, and monitoring.
Greenhouse is a Kubernetes-based day-2 operations platform providing a set of opinionated tools and operational processes for managing cloud-native infrastructure at scale.
  • Team & Access Management: Manages organizational groups as Teams with fine-grained access control to and ownership of resources.
  • Unified Operations Dashboard: Provides a single dashboard for infrastructure, alerting, security, compliance, and organizational management across a fleet of Kubernetes clusters.
  • Preconfigured Tool Suite: Ships a set of preconfigured and integrated tools auto-deployed across clusters, covering observability, security, and compliance out of the box.
  • Plugin API: An extensible plugin API allows teams to integrate self-developed solutions on top of the Greenhouse platform machinery.
We leverage the power of Digital Twins by treating the data center like a manufacturing environment. All relevant data flows into that Digital Twin, allowing immersive visualization and smart decision-making through forecasts and AI.
  • Digital Twin with Asset Administration Shell: Creates a Digital Twin of the data center using the Asset Administration Shell standard, providing a structured and interoperable representation of all physical assets.
  • Immersive Data Center Access: Provides immersive VR and desktop access to the data center, enabling better monitoring, planning, and decision-making for infrastructure operations.
  • Operational & Environmental Data Ingestion: Ingests real-time operational and environmental data into the Digital Twin, ensuring an up-to-date and accurate representation of data center state.
  • Energy-Workload Transparency: Links compute workloads to their energy consumption, enabling data-driven sustainability management and capacity planning.
  • Sustainability & Transparency: Increases transparency across the data center footprint and improves sustainability through AI-powered forecasts and actionable insights.
  • Improved Interoperability: Built on open standards to ensure interoperability across heterogeneous data center environments and vendor ecosystems.
  • Modular Open-Source Components: Open-source application with modular components applicable beyond data center management, enabling reuse across other infrastructure domains.
The bare metal management and automation in IronCore is designed to provide a comprehensive solution for managing physical servers in a Kubernetes-native way. It leverages the power of Kubernetes Custom Resource Definitions (CRDs) to automate server lifecycle from discovery to day-2 operations.
  • Discovery: Automatically detect and register bare metal servers, ensuring seamless integration into the infrastructure.
  • Provisioning: Deploy and configure servers using Ignition, automating OS installation and server setup.
  • Day-2 Operations: Manage BIOS, firmware, and hardware inventory declaratively, keeping the fleet compliant and up to date without manual intervention.
  • 3rd Party Integrations: Seamlessly integrate with existing vendor-specific management tools.
  • Kubernetes Support: Run Kubernetes on bare metal servers with support for Cluster API and Gardener.
The IronCore IaaS layer exposes a unified, declarative API for managing compute, storage, and networking resources using modular, pluggable providers. It integrates natively with Gardener, CSI, CCM, and Cluster API for cloud-native workloads.
  • Compute: Pluggable providers support diverse environments, with KVM via libvirt as the default compute backend.
  • Storage: Block, shared, and object storage are backed by default with Ceph, a cloud-natively automated, vendor-neutral storage solution.
  • Networking: Declarative networking resources are managed through the IronCore API.