Skip to main content
cloud-news roundup kubernetes hetzner ovhcloud scaleway stackit ionos exoscale cyso thalassa civo gcore aws gcp azure

EU Cloud Provider News Roundup: Late May – Early August 2026

Ten weeks of EU cloud news: a KVM escape (Januscape) forces a fleet-wide patch wave that managed Kubernetes did not absorb, Redis gets replaced by Valkey at STACKIT and IONOS, Kubernetes 1.36 spreads unevenly across providers, sovereignty turns into signed contracts, OVHcloud faces criminal charges in Canada, and Infomaniak announces an IPO.

MR
Michael Raeck
29 min read

Third edition of our EU Cloud Provider News Roundup, covering our tracked providers from May 21 to August 6, 2026. The previous edition ran through May 20 inclusive, so items dated May 20 belong to that edition and are not repeated here — where one is needed as background, it is marked as such.

One deliberate exception: OVHcloud’s Exten post carries a feed date of August 7, one day past our cut-off. It is already public and it is the most consequential infrastructure item of the quarter, so it is included rather than held for October.

Where a provider publishes changelog entries without per-item anchors, we quote the entry title verbatim and give the date, so you can Ctrl-F it on the linked index page.

Correction — August 11, 2026

The version published on August 6 said that no EKS announcement of Kubernetes 1.36 could be found in this window, in both Key Takeaway 4 and the AWS EKS section. That was wrong.

AWS announced Kubernetes 1.36 support for Amazon EKS and Amazon EKS Distro on June 2, 2026in every region where EKS is available, including the GovCloud (US) regions. The EKS release calendar records the same date, with standard support running to August 2, 2027.

That date is well inside our May 21 – August 6 window, and it also reverses the ranking: EKS shipped 1.36 seventeen days before AKS, not after it. The version table, the AWS EKS section and the AKS section have all been corrected below.

The mistake was ours, and the cause is worth naming because it is a repeatable one: we tracked the AWS containers blog for that section and did not check the What’s New feed or the EKS version-lifecycle documentation, which is where AWS actually records version releases. “No announcement found” was a statement about our sources, and we published it as a statement about AWS. Going forward, a “no announcement” claim in this roundup means we checked the provider’s changelog, release notes and announcement feed — or it does not get made.

We re-checked the rest of that table against the same standard. The Scaleway, GKE and AKS rows hold. The STACKIT row does not fail, but it needed rewording: SKE’s public release notes carry no 1.35 or 1.36 entry, and STACKIT publishes its live version list only in the SKE dashboard and behind an authenticated API, so the honest claim is “not announced”, not “still on 1.34”. The Oct 27, 2026 date attached to SKE’s 1.34 is the upstream Kubernetes end-of-maintenance date; STACKIT has not published its own removal date. Both are fixed below.

Key Takeaways

Seven things happened this quarter that should change something you do. If you read nothing else, read the deadline table at the end of this section.

1. A KVM escape forced a fleet-wide patch wave — and managed Kubernetes did not absorb it

CVE-2026-53359 (“Januscape”) hit the hypervisor layer, not the guest kernel. OVHcloud patched tens of thousands of machines in a one-week campaign; Cyso ran preventive emergency maintenance on Jul 7, two weeks ahead of OVHcloud’s Jul 20 write-up.

Last quarter’s Copy.Fail was a node-kernel problem that managed K8s absorbed for you. This one was not.

What it means: your blast radius was decided by your provider’s maintenance window, not your control plane. If a July reboot surprised you, that was why.

2. Sovereignty stopped being editorial and became signed contracts

Last edition, providers were spending editorial budget on the narrative. This quarter it has names attached:

ProviderDealDate
STACKITSovereign cloud JV with KPN (Netherlands)May 28
STACKITBosch Mobility as named customerJul 8
STACKITZscaler sovereign security platformJul 28
CleuraNextcloud EU collaboration suiteJun 30
plusserverTÜV TRUST ITJul 1
plusservermogenius + Link11, sovereign K8s + WAAPJun 18

STACKIT also announced selection as the cloud foundation for the German federal AI platform (BMDS) on May 20, just before this window — per STACKIT’s own announcement; we have seen no independent confirmation of scope or contract value. Gcore put it most bluntly: “AI sovereignty isn’t politics: it’s a sales requirement” (Jun 12).

3. Redis is being replaced by Valkey

STACKIT launched a Valkey-based Key Value Store and deprecated Redis on the same day (Aug 1). IONOS took In-Memory DB v2, Valkey-backed, to GA (Jun 8 API, Jul 27 DCD) and stopped new v1 clusters.

What it means: if you run managed Redis on an EU provider, you have a migration on your roadmap whether you planned one or not.

4. Kubernetes 1.36 spread unevenly — and the spread is the story

Platform1.36 status in this window
EKSGA Jun 2, all regions incl. GovCloud (US)
AKSGA + Long Term Support, no preview flag (Jun 19)
ScalewayReleased Jul 7
GKERapid-channel default through July
STACKIT SKENo 1.35 or 1.36 announced; removed 1.33 on Jul 8, auto-upgrading to 1.34

Upstream released 1.36 on April 22.

On STACKIT specifically: 1.33 was deprecated on Jun 9 and removed on Jul 8 at 08:00 UTC, with remaining clusters auto-upgraded to 1.34 in their maintenance window. Neither the SKE release notes nor the aggregated STACKIT release notes carry a 1.35 or 1.36 availability entry through August 6 — and STACKIT does announce new minors there, which is how 1.34 arrived in December 2025. But note the limit of that evidence: STACKIT publishes its live version list only in the SKE dashboard and the authenticated provider-options API, so “not announced” is the strongest claim the public record supports, not “not available”. If you need certainty, the dashboard is the only source of truth.

Upstream 1.34 reaches end of maintenance on October 27, 2026. That is an upstream date, not a STACKIT one — SKE removed 1.33 ten days after its upstream EOL, and has not yet published a removal date for 1.34.

What it means: the honest version is not “everyone shipped 1.36”. All three hyperscalers landed it within two months of upstream; at least one major EU provider is two minors behind. If you pick managed K8s on version currency, that gap is the number to ask about.

5. Encryption and post-quantum became table stakes

Scaleway shipped post-quantum signature algorithms in Key Manager (Jun 25) and SSE-KMS (Jun 3). Exoscale shipped encryption at rest (Jun 2) and KMS (Jul 2). Thalassa launched KMS (Jun 11) and Secrets Manager (Jun 15). Four providers, one quarter, the same primitives — these no longer differentiate anyone.

6. No new EU price hikes — and a few cuts

After Q1’s OVHcloud/Scaleway/Hetzner wave, nobody raised list prices. Going the other way: Exoscale cut A40 GPUs by 30% (Jun 1) and ran archival storage at 77% off (Jul 6, temporary); UpCloud added GPU spot pricing (Jul 6). netcup published a pricing-pressure explainer (Jul 3) without raising anything.

What it means: the hardware-cost story is still real — the pass-through has paused, not ended.

7. OVHcloud is facing criminal charges in Canada

On Jul 31, OVH Groupe and its Canadian subsidiary confirmed charges for failure to comply with a production order and obstruction of justice, and said they will contest them vigorously. Whatever the merits, a European provider fighting a foreign lawful-access order will end up in a lot of sovereignty sales decks.

Deadlines from this quarter

DateWhat happensWho
Sep 14, 2026enableCustomCATrust retires; scaling and cert updates failAKS
Sep 15, 2026Llama 3.1 405B removed — HTTP 400, no fallbackIONOS
Oct 1, 2026GET /v1/datacenters → HTTP 410; server_types* fields droppedHetzner
Oct 27, 2026Kubernetes 1.34 upstream end of maintenance (SKE removal date not yet published)STACKIT SKE
Aug 1, 2027All Redis instances decommissionedSTACKIT
Jul 1, 2027SQL Server Flex API v2/v3alpha removedSTACKIT
Jun 14, 2027”No channel” clusters removed, auto-enrolled to StableGKE

Hetzner

No pricing news this quarter — instead, the most aggressive API deprecation cycle Hetzner has run in years. If you automate against the Cloud API, this section is your homework.

Two separate Datacenter removals are in flight — do not confuse them.

  1. Datacenters properties removed from Primary IPs and Servers (Jul 1, already done): the datacenter property is gone from the request body and response of Servers and Primary IPs, as announced back on 16 December 2025.
  2. Datacenter endpoints deprecated (Jun 2, removal 1 October 2026): GET /v1/datacenters and GET /v1/datacenters/{id} will return HTTP 410 Gone after that date. The same October 1 deadline drops the datacenter.server_types* and recommendation response fields, replaced by server_types.locations.available / .recommended.

So: the property removal has already broken anything that read it; the endpoint removal is the one still on your calendar.

Load Balancer Types deprecation metadata (Jun 5): New structured deprecation info; the old boolean deprecated field is itself now deprecated.

EC2-compatible metadata routes deprecated (Jun 30) → removed (Aug 1). Five weeks from deprecation to removal. If you had tooling that pointed AWS-shaped metadata clients at Hetzner, it broke on August 1.

Primary IP assignee_type returns unassigned (Aug 1): The change flagged in the April changelog and in our last edition shipped on schedule. Unassigned Primary IPs no longer report server.

DNS zone TTL and PTR now required on change (Jul 8): Omitting the TTL when changing an RRSet’s TTL is deprecated, as is omitting DNS pointers on change. Silent-default behaviour is going away.

Load Balancer idle timeout in the Console (Jun 29): The API-only setting from April is now clickable.

Image lifecycle: Fedora 42 unavailable for new servers (Jun 30), openSUSE 15 unavailable for new servers (Jul 30). Also on Jul 30, Hetzner documented the unified GET /actions/{action_id} endpoint that replaces the per-resource action endpoints deprecated in April.

OVHcloud

The busiest quarter of any provider we track — one legal crisis, one large security operation, and a genuinely interesting storage-engine story.

Building Exten: OVHcloud’s own NVMe block storage engine (feed-dated Aug 7 — one day past our window, included deliberately; see the note at the top): OVHcloud acquired Exten and is replacing Ceph with an in-house NVMe block storage engine written in C++ and Go, targeting higher performance at lower cost. Ceph remains in place today. This is the most consequential infrastructure post from any EU provider this quarter — block storage performance is where OVHcloud has historically lost benchmark comparisons.

OVHcloud confirms intent to contest Canadian charges (Jul 31): See takeaways above.

CVE-2026-53359 (Januscape) patch campaign: lessons learned (Jul 20): A one-week correction operation across the entire KVM fleet, written up with the patching strategy and the customer-impact tradeoffs. Read this one even if you’re not an OVHcloud customer — it’s the best public account of how a large EU provider handles a hypervisor CVE.

Platform engineering for AI: does your Kubernetes platform scale? (Jul 20): Cites the CNCF 2025 survey — 82% of container users run Kubernetes in production, only 7% deploy AI models daily. The argument is that the gap is platform tooling, not Kubernetes.

Manila CSI (RWX) on Managed Kubernetes (Jul 16): ReadWriteMany shared persistent storage for MKS. A real gap closed for stateful workloads.

What’s new in VMware Cloud Foundation 9.x (Jul 19): Single package, core-based licensing. OVHcloud is still working the Broadcom-refugee angle hard.

Practical guides worth bookmarking rather than reading now: Langfuse on MKS for LLM cost tracking (Jul 23), Rancher on MKS (Jun 30), Cosign image signing with OVHcloud KMS (Jun 22), and a Landing Zone design with Sopra Steria (Jun 29). A new VPS 2027 range landed Jun 17.

Scaleway

Roughly 40 changelog items in ten weeks — the highest volume of any EU provider we track. Rather than transcribe them, here are the ones that change a decision. Everything below is a verbatim entry title on the Scaleway changelog; Ctrl-F the title.

  • “VPC Peering is now in General Availability” (Jun 23) plus “Transitive peering for VPCs is now opt-in” (Jun 23). The opt-in flip is the important half: transitive peering that used to be implicit now is not, so a peering topology built before Jun 23 may route differently than the same topology built after it. Check yours.
  • “Network ACLs are now in General Availability” (Jun 3). With VPC Peering GA, Scaleway finally has a complete VPC segmentation story.
  • “Conditional writes and Terraform state locking are now supported” (May 26). Native state locking on S3-compatible storage removes the DynamoDB-shaped hole in Terraform-on-Scaleway setups — you can drop the external lock table.
  • “Kubernetes 1.36 released” (Jul 7) and “File Storage is now in General Availability” (Jul 16).
  • “FinOps API now available in Beta” (Jun 3). Programmatic cost data; the prerequisite for chargeback that does not involve scraping invoices.
  • “Deprecation of legacy operating systems” (Jul 29), “Serverless Containers v1beta1 deprecated” (Jul 13), “Deprecation - Serverless models” (Jul 2). Three deprecations in four weeks — worth one audit pass rather than three.

Security primitives arrived in a cluster: “SSE-KMS encryption is now available for Object Storage” (Jun 3), “TLS enforcement via bucket policies is now available” (Jun 23), “New post-quantum asymmetric signature algorithms” (Jun 25). Audit Trail expanded across June and July to cover Cockpit, InterLink, ClickHouse, Serverless SQL and Generative APIs, then gained “Native Splunk integration for Audit Trail” (Aug 6).

On the blog, The Scaleway Manifesto for Data & AI Sovereignty in Europe (Jun 26) anchors a five-part VivaTech 2026 takeaways series on regulation, adoption, European scale, the AION programme, and what “AI-native cloud” means.

STACKIT

The strongest enterprise-logo quarter of any EU provider, and a serious security-product build-out. Titles below are verbatim entries on the STACKIT release notes.

  • “STACKIT ALB WAF is now generally available” (Aug 4), after “STACKIT ALB WAF available in preview” (Jul 23). Coraza engine, managed OWASP Core Rule Set, per-listener Layer 7 inspection, and — the genuinely useful part — a JSON abstraction over SecLang so custom rules do not require raw SecLang. Stable v1 API and Terraform at GA; Portal UI is explicitly post-GA, so this is an infrastructure-as-code-first launch. WAF records ship under the component="waf" label alongside Envoy logs.
  • “Newly Available: Key Value Store based on Valkey” and “STACKIT Redis Deprecation” (both Aug 1). Redis decommissioning across all instances: August 1, 2027.
  • “Kubernetes version 1.33 is getting deprecated in SKE” (Jun 9): removed Jul 8 at 08:00 UTC, with remaining clusters auto-upgraded to 1.34 during their maintenance window. See the version table in Key Takeaway 4 for what SKE has and has not announced since.
  • “STACKIT Unified Firewall is now Generally Available” (Jul 7), aggregating ACLs and public IPs at project level.
  • “Important Update: IP Address Changes for STACKIT API Regions EU01 & EU02” (Jun 5). If you allowlist egress to STACKIT’s API gateways, this one silently breaks CI. Highest-consequence, lowest-visibility item in the quarter.
  • “Advanced identity management features for SKE clusters” (Jun 12): SSO via STACKIT IdP and Workload Identity, replacing long-lived kubeconfig distribution.
  • “General Availability of STACKIT Telemetry Router (GA)” (Jun 2) — the migration target for the legacy Audit Log API we flagged last edition.
  • “STACKIT Server - Microsoft 2011 UEFI Root CA certificate expires on 24 June 2026” (Jun 11): Secure Boot VMs need the new certificate present or they do not boot.

Deprecations to diary: “STACKIT MariaDB 10.6 is deprecated” (Jul 1) and the SQL Server Flex API v2/v3alpha1/v3alpha2 deprecation (Jul 10, removal after Jul 1, 2027). Also shipped: Logs pattern extraction (Jul 24), a purchasable Advanced Support plan (Jul 20), Gemma 4 replacing Gemma 3 in AI Model Serving (Jul 14), openSUSE Leap 16.0 (Jun 23), and the Automation Service in beta (Jun 30).

IONOS

Quiet on the blog, busy in the release notes — and almost everything is a v1 → v2 migration you do not get to opt out of. IONOS publishes per-month release note pages, so these are deep-linked.

The pattern across three database products is identical: v2 API reaches GA, the DCD stops letting you create v1, existing v1 clusters become “Legacy Clusters” with a reduced operation set. It happened to In-Memory DB (v2 API GA Jun 8, DCD Jul 27 — now Valkey-backed, and the resource renamed from ReplicaSet to Cluster), PostgreSQL (DCD Jun 26, migration guide Jul 21) and MariaDB (v2 API GA Jul 6, across all nine regions). MariaDB v1 clusters will be migrated automatically — that is convenient right up until it happens during your peak week. The MariaDB v2 API is a real improvement: Bearer-JWT auth, PITR via restoreFromBackup, 1–365 day retention, and logsEnabled/metricsEnabled controls.

IONOS CLOUD MCP Server GA (Jun 9): Read-only MCP access across Compute Engine, Object Storage, Cloud DNS, Certificate Manager, Billing and Activity Log, running locally and listed on the official MCP registry. First provider we track to ship a production MCP server. Read-only is the right call for a first release, and it means the blast radius of pointing an agent at it is bounded.

Also: Monitoring Service in the DCD (Jun 16) with Central Monitoring activation no longer API-only, Kafka 4.0.0 support (Jul 1), Nextcloud Workspace raised to 300 seats (Jun 19), and a Marketplace product approval process for partners (Aug 6).

Exoscale

Small changelog, high signal-to-noise, and the only provider we track that cut prices this quarter. Titles are verbatim entries on the Exoscale changelog.

  • “GPU: A40 (GPU3) price reduction - 30% off from June 2026” (Jun 1) and “Archival Storage: Cold Data at 77% Off (Temporary Price Program)” (Jul 6). Note “temporary” on the second — do not re-plan a retention policy around a price that has an end date nobody has published.
  • “Encryption at Rest for Compute and Block Storage” (Jun 2), “Exoscale Key Management Service (KMS) is now available” (Jul 2), “SOS: Block SSE-C Encryption per Bucket” (May 29).
  • “SKS: GPU MIG partitioning support” (Jul 21), with a walkthrough on the blog (Jul 2). MIG on managed K8s is the cheapest way to stop paying for a whole A100 to serve one small model.
  • “AI: Dedicated Inference is Now Generally Available” (Jun 15) and “Manage Exoscale infrastructure with Crossplane” (Jun 17).

Blog highlights: Inside an LLM: from prompt to tokens (Jun 15) and Scaling Prometheus with Thanos (Jun 10).

Cyso

Cyso spent the quarter on the regulatory story, plus one incident write-up worth reading.

Preventive emergency maintenance: Januscape (CVE-2026-53359) explained (Jul 7): The customer-facing side of the same KVM flaw OVHcloud wrote up on Jul 20. Two providers, two weeks apart, one root cause — Cyso led with the maintenance notice, OVHcloud with the post-mortem.

Digital sovereignty just grew teeth: what the 2026 EU cloud rules mean for where you run your workloads (Jul 19) and EU Tech Sovereignty Package: what it means for cloud in Europe (May 31). If you need to brief a non-technical stakeholder on why this is suddenly a procurement question, these two are the clearest summaries any provider published this quarter.

We asked students to test our European cloud against Azure (Jul 6): Independent benchmarks, published by the vendor — read with appropriate salt, but the methodology is disclosed.

Also: container scanning beyond image vulnerabilities (Jul 6), VMware-to-KVM migration factors (Jun 2) — the continuation of last edition’s VMware-exit thread — and Cyso at Slush 2026 (Aug 4).

Thalassa Cloud

The smallest provider we track, shipping at a pace that embarrasses several larger ones — six launches in six weeks, all on the Thalassa blog.

“Thalassa Cloud Launches Key Management Service in Early Access” (Jun 11), “Secrets Manager now available in Early Access” (Jun 15), “Authoritative DNS now in Early Access” (Jun 18), “Exporting audit logs for compliance and security review” (Jun 25), and “Browser OIDC login for tcloud CLI” (Jul 7).

Two worth singling out: “Expose workloads with Gateway API and kgateway on Thalassa Cloud Kubernetes” (Jun 22) — Gateway API as the primary ingress story rather than a bolted-on controller, matching where AKS went this quarter — and “Kubernetes Cluster provisioning, without hardcoded secrets” (May 27). For a provider this size, shipping KMS, Secrets Manager and audit export in one month is the compliance-checklist bloc that usually decides whether they clear procurement at all.

Civo

Civo pivoted hard from sovereignty polemics to GPU product marketing this quarter.

Why we reserved 2,016 Vera Rubins (and what it took) (May 26). We flagged Vera Rubin as a thing to watch last edition; Civo committed — this is the follow-through on the May 20 preview post covered there.

The rest of the quarter was B300 launch content (intro Aug 2, B300 vs B200 Aug 5). The one worth reading is GPU cloud for non-AI workloads (Aug 6), arguing that AI-reserved GPU capacity is now cheap enough to justify for rendering and simulation — a real cost argument if you have HPC workloads parked on CPU.

Also: CivoStack Enterprise vs. FlexCore (Aug 4), Konstruct updates (Aug 1), and survey data on UK geopolitical cloud risk (Jun 10).

UpCloud

SDN Firewall for Private Networks (Jul 23): Firewalling inside the SDN rather than per-server. Spot pricing for GPU Servers (Jul 6). Workspaces in open beta (Jun 24). File Storage in new locations (Jun 18). New Developer API documentation in beta (Jun 8).

Contabo

New VPS portfolio: Core, Performance and Max Performance (Jul 29): A three-tier restructure of the VPS lineup. If you buy Contabo on price-per-core, re-check the mapping before your next order.

Also on Jul 29: US West moved to a new Seattle data center, plus control-panel changes. 500,000 VPS hosted (Jun 16). The rest of Contabo’s output is high-volume SEO content, not news.

Gcore

The most consistent sovereign-AI narrative of the quarter, backed by infrastructure claims rather than only positioning. All items are on the Gcore blog.

“Gcore introduces Global Inference Routing accelerated by NVIDIA Dynamo” (Jul 22) extends earlier single-deployment Dynamo work — which Gcore claims delivered up to 6× GPU throughput and 2× lower latency by separating prefill and decode — into cross-region request routing. Vendor-reported numbers; benchmark before you believe them.

“AI sovereignty isn’t politics: it’s a sales requirement” (Jun 12) is the sharpest framing anyone published this quarter: the claim is that sovereignty has become the first checkpoint in public-sector and regulated-industry deals, ahead of price and performance. If true, it reprices every EU provider’s roadmap.

Operational proof points beat the thought leadership here: “How Gcore kept Armenia’s election broadcast online” (Jul 8) and “How various audiences viewed the World Cup via Gcore” (Jul 24) are the sort of load evidence CDN buyers actually weigh. Also: a Melious AI CDN/DNS migration story (Jul 20), a Graphiant sovereign-connectivity partnership (Jul 13), the Gcore Connect Luxembourg forum (held Jul 6–7, recapped Jul 27, with Nokia, Dell and VAST), and a Sifted Top 100 France & Benelux 2026 listing.

plusserver

Three press releases, all pointing the same direction.

Sovereign Kubernetes with integrated web security (Jun 18): Joint offering with mogenius and Link11 combining managed K8s with Web Application and API Protection (WAAP).

plusserver and TÜV TRUST IT partner for secure cloud and AI transformation (Jul 1).

Study: German companies would accept technical compromises for digital sovereignty (Jul 28): Commissioned with CIO and Computerwoche. Vendor-funded, but it’s the only quantified German-market data point published this quarter.

Infomaniak

Infomaniak announces its planned listing on the Swiss stock exchange (Jul 29): The largest corporate-structure news from any EU provider this quarter. Notable because it comes two months after Infomaniak secured its independence and “DNA” for the long term via a foundation structure (May 20, just before this window) — a foundation-plus-listing combination explicitly designed to prevent acquisition. If sovereignty ownership structure matters to your procurement, this is the model to study.

Data hosted in Europe by a US company: is it truly sovereign? (May 22): Direct attack on the “EU region” marketing claim.

Cleura

EU sovereign collaboration suite and strategic partnership with Nextcloud (Jun 30): Cleura’s OpenStack platform plus Nextcloud as a Microsoft 365 alternative. This is the same play STACKIT is running with its own partners — European IaaS plus European collaboration software, sold as one procurement item.

Other providers


AWS EKS

Kubernetes 1.36 plus a heavy quarter of EKS Auto Mode work.

Amazon EKS and Amazon EKS Distro now support Kubernetes 1.36 (Jun 2): Six weeks after upstream, in all EKS regions including GovCloud (US), and the first of the three hyperscalers to ship the minor. Standard support runs to August 2, 2027, extended support to August 2, 2028, per the EKS release calendar. Two upgrade blockers are worth reading before you move: the gitRepo volume type is permanently disabled — the API still accepts such Pods, the kubelet refuses to run them — and StrictIPCIDRValidation is on by default, so manifests carrying leading zeros (010.0.0.5) or non-canonical CIDRs (192.168.0.5/24) are rejected on create and update. Existing stored objects are ratcheted through; new writes are not.

Amazon EKS Rollback for cluster upgrades (Jul 1): Safe rollback of a cluster upgrade. This is the feature that changes upgrade risk calculus for anyone who has been pinning versions out of fear.

EKS control plane egress through your VPC (Jun 22): Control-plane traffic routed through customer VPC. Matters for egress inspection and for regulated environments.

ARC zonal shift support for EKS Auto Mode and Karpenter (Jul 23) adds zonal evacuation; full request and response compliance logging (Jul 7) is the one to know about if you are on an audit trail requirement. Auto Mode internals were documented in two posts (Jun 23, Aug 5), alongside Argo CD private Git repository access (Jul 13) and Istio Ambient Mesh support (Jun 9). All on the AWS containers blog.

GKE

Kubernetes 1.36 in the Rapid channel: 1.36.0-gke.4681000 became the Rapid default on Jul 16, then 1.36.2-gke.1498000 on Jul 24 and 1.36.2-gke.2064000 on Jul 30. GKE is still the fastest to land new minors.

Surge upgrade limit raised to 100 nodes (Jul 7): maxSurge + maxUnavailable can now total 100 on Standard clusters. Large fleets can drain upgrade windows much faster.

“No channel” clusters deprecated (Jun 10): Removal on June 14, 2027; unenrolled clusters get moved to Stable automatically. If you deliberately pinned out of release channels, you have a year to plan.

Dataplane V2 moves to CNI 1.1.0 (Jul 14): Self-managed Istio or in-cluster unmanaged Cloud Service Mesh users must upgrade their CSM CNI to 1.23 or nodes may stick in NetworkPluginNotReady. This is the sharpest edge in the GKE notes this quarter.

Cloud Storage FUSE sidecar mount failures (Jun 23): Volumes may fail to mount when the metadata service isn’t ready as the sidecar initializes, on 1.34.1-gke.3899001 and later affected versions. Supersedes an earlier May 29 note about Workload Identity timeouts at pod startup.

Also: mixed-protocol LoadBalancer Services GA (Jul 27, in 1.36.2-gke.1498000+), ReadWriteMany via Filestore (Jun 30), and a heads-up that Ubuntu node images in 1.37+ won’t pre-install vulkan-tools (Jul 20).

Azure AKS

Kubernetes 1.36 GA and Long Term Support (Jun 19 release): No preview flag needed to create or upgrade to 1.36, and it lands as an LTS version. AKS was seventeen days behind EKS on the minor itself, but ahead of GKE’s Rapid default and of every EU provider we track — and it is the only one of the five to offer 1.36 as a Long Term Support version. If you have been waiting on an LTS target to standardise a fleet on, this is it.

AKS on bare metal in public preview (Jun 2): Zero-touch provisioning on Azure Local small form factor hardware. The edge/on-prem story that pairs with the Arc series from last quarter.

Automatic zone placement in public preview (Jun 1): AKS picks the availability zones for a node pool per region and VM SKU instead of making you hardcode them. Also in that release: Prepared Image Specification (preconfigured node images with container images baked in, for faster ready-state) and full caching mode for Ephemeral OS disks (node keeps running when remote storage is unavailable).

App Routing Gateway API GA (Jun 10), with managed Gateway API via the Istio-based add-on (Jun 15). Gateway API is now the default ingress direction on both AKS and the EU providers shipping it.

Retirements to diary: enableCustomCATrust preview property retires September 14, 2026 — after that the node-pool field no longer enables Custom CA trust, and scaling or certificate updates on affected clusters will fail. Windows Server Annual Channel node pools can no longer be created, and Flatcar Container Linux for AKS is retired for new clusters (both from the Jul 17 release). Windows Server 2022 retirement was extended to June 30, 2028, with node images removed June 30, 2029 — but it is unsupported on Kubernetes 1.37+.

One behavioural change to catch: Azure Service Mesh revision asm-1-30 switches new installs from privileged init containers to Istio CNI (Jun 19 notes) — upgrades are unaffected, new installs are not. Also: Azure Container Linux for AKS announced alongside the Flatcar retirement (Jun 8), plus AI content on Dynamo-Grove multi-node inference (Jun 2) and streaming vLLM model weights from Blob Storage (Jul 13).


The model you deploy on is becoming a moving target

One thread runs through four providers this quarter and deserves pulling out, because it changes how you should treat a managed inference endpoint.

IONOS added Qwen3.5 397B A17B (Jul 14), Qwen3.5 9B (Jul 22) and FLUX.2-Klein-4B (Jun 17) to its Model Hub — and deprecated Llama 3.1 405B (Aug 6) with removal on September 15, 2026. After that date the model ID does not fall back to a successor; it returns HTTP 400 “Invalid model name”. STACKIT did the same thing more gently, replacing Gemma 3 with Gemma 4 (Jul 14). Scaleway added GLM 5.2 (Jun 26) after Gemma 4, Qwen3.6 and Mistral Medium 3.5 in May. Exoscale took Dedicated Inference to GA (Jun 15).

The pattern: EU inference catalogues now churn on roughly a quarterly cycle, and at least one provider will hard-fail your requests rather than silently reroute them. That is arguably the correct behaviour — a silent substitution changes your outputs without telling you — but it means a pinned model ID is a dependency with an expiry date, not a constant. Two practical consequences. First, treat model IDs like pinned container tags: inventory them, and own the upgrade. Second, if portability matters, the question to ask a provider is not “which models do you have” but “what is your deprecation notice period, and do you fail loud or substitute quietly”. IONOS gave about six weeks and fails loud.

If it would be useful to see which models are actually available across the EU providers we track — and what a forced migration costs when a 405B model retires — tell us; it is the obvious next thing to build on top of this roundup.

What We’re Watching in September

  • IONOS removes Llama 3.1 405B on September 15. Requests fail with HTTP 400, not degrade. Migrate to Qwen3.5 397B A17B before then — and see the section above on why this is a pattern, not a one-off.
  • AKS enableCustomCATrust retires September 14. Clusters still setting it will hit scaling and certificate-update failures.
  • The Valkey migration wave. STACKIT’s Redis decommission is a year out (Aug 1, 2027) and IONOS is auto-migrating MariaDB v1 clusters. Watch whether Scaleway, OVHcloud and Exoscale follow with their own Redis-to-Valkey moves — the licensing pressure is identical for all of them.
  • Hetzner’s October 1 Datacenter endpoint removal. GET /v1/datacenters and /v1/datacenters/{id} start returning HTTP 410 Gone, and the datacenter.server_types* / recommendation response fields get dropped. Distinct from the datacenter property removal that already landed on July 1 — that one has broken your tooling if it was going to. Terraform providers and custom tooling both need an audit before October.
  • OVHcloud’s Exten rollout. Ceph is still the production block storage; the interesting question is when Exten reaches customer-visible volumes and what it does to OVHcloud’s block storage benchmarks and pricing.
  • The Canadian case against OVHcloud. A European provider contesting a foreign lawful-access order is a live test of exactly the argument the whole EU sovereignty pitch rests on.
  • Whether the price pause holds. Hostinger’s “infrastructure crunch” note and netcup’s pricing explainer both say hardware cost pressure has not eased. Nobody raised prices in this window; that is not the same as nobody planning to.
  • Sovereign collaboration bundles. Cleura + Nextcloud and STACKIT + partners are both selling “European IaaS plus European productivity software” as a single procurement. Expect more of these before year end.

This is the third edition of our EU Cloud Provider News Roundup. The previous edition covered late February through May 2026, and the first covered January and early February.

Compare pricing across all providers mentioned above with our Kubernetes price calculator.

M
Michael Raeck

Cloud infrastructure nerd. Building tools to make Kubernetes less painful and more affordable in Europe. Running Talos clusters on Hetzner for fun.

READY TO COMPARE?

Find the Best Kubernetes Pricing

Configure your exact cluster requirements and compare real-time prices across 25+ European providers.

Open Calculator

Open Source Pricing Data

All pricing data is open source and community-maintained

View on GitHub