LINESERVE

Managed Kubernetes — launching in Nairobi, ke-1a

Coming soon

Managed Kubernetes in Kenya

Nobody on a four-person team should be the etcd person.

Kubernetes is not the hard part. The control plane is — certificate rotations, etcd backups you have never restored, a minor upgrade that goes sideways with production on it, and the quiet understanding that one engineer is the only person who knows how any of it was built. Managed Kubernetes runs that layer in ke-1a, in Nairobi, with autoscaling worker pools underneath and clusters opening at KES 2,786 a month plus the resources you use. It is launching soon. Join the waitlist and we will tell you the week it is ready.

Clusters fromKES 2,786/month + resources
  • Launching soon — join the waitlist for early access
  • Managed control plane: API server, scheduler, etcd
  • Clusters in Nairobi, ke-1a
  • Autoscaling worker pools, down to zero when idle
  • Quoted and billed in KES

Launching soon · Billed in KES

Pricing

A cluster fee, plus what your nodes use

Pick a control plane — Basic or Fault Tolerant — then pay only for the vCPU, RAM, storage, and load balancers your worker nodes actually consume. In your currency, no forex.

Basic

Single master node for development, testing, and non-critical workloads.

KES 2,786/mo + resources

Hosted in Nairobi, Dar es Salaam, Lagos & Kampala

  • 1 master node
  • 99.5% control-plane SLA
  • Kubernetes 1.28–1.31
  • Autoscaling worker pools
  • Prometheus & Grafana included
Recommended

Fault Tolerant

3 master nodes with automatic failover — recommended for production.

KES 11,634/mo + resources

Hosted in Nairobi, Dar es Salaam, Lagos & Kampala

  • 3 master nodes, automatic failover
  • 99.95% control-plane SLA
  • Kubernetes 1.28–1.31
  • Autoscaling worker pools
  • Prometheus & Grafana included

Worker node resources

Billed monthly, per unit consumed, on top of the cluster fee.

ResourceUnitPrice /mo
vCPUper vCPUKES 666
RAMper GBKES 306
Local diskper GBKES 19
Network HDDper GBKES 15
Universal SSDper GBKES 23
Fast SSDper GBKES 34
Public IPper IPKES 150
Load balancer — Basicper LBKES 1,638
Load balancer — Basic, redundantper LBKES 3,277
Load balancer — Advanced, redundantper LBKES 6,553

Your monthly total is the cluster fee plus the resources your worker nodes consume. Snapshots, file storage, and traffic beyond the included allowance bill at the same per-GB console rates. Prices exclude VAT; local currency figures are indicative and settled at checkout.

Where the cluster stands

Eight hops per request, all of them inside one building

The reason to run containers is also the reason distance hurts more once you do. A request hits the ingress, reaches a service, which calls two more, which each read from a database and a cache, and something writes an event on the way out. That is one user action and eight network hops before a response exists. Inside ke-1a those hops happen inside one facility in Nairobi. Split across an ocean, the same eight hops eat the entire latency budget before your code has done any work.

Kenya's users are easy to place. The Communications Authority counted 84.09 million active SIM subscriptions in the quarter to March 2026 at 157.7% penetration, with 62.63 million mobile data subscriptions and 50.17 million smartphones connected — Safaricom holding 68.9% of mobile subscriptions and Airtel most of the rest. Whichever network your customer is on, they are in Kenya. So is the cluster. A round trip that starts and finishes inside the Nairobi metro is typically around 2 ms, and Lineserve peers at KIXP, the neutral exchange TESPOK has run since 2002 with 136 networks and 2.9 Tbps of connected capacity.

The alternative route is worth picturing properly. Every Kenyan subsea cable lands at Mombasa — SEACOM, EASSy, TEAMS, PEACE, DARE1 and LION2 — and that capacity is hauled roughly 480 km inland to reach a Nairobi rack. A cluster in Europe means every one of those eight hops crosses that haul and then an ocean, twice, for each user request. Domestic traffic never makes the trip.

No hyperscaler runs a full cloud region in Kenya; the nearest are in South Africa. What Nairobi has from the large providers is edge — caching and interconnect, with the scheduling and the pods in another country. A cluster in ke-1a is compute in Kenya rather than near it, which is the distinction that matters when a customer, a regulator or a security review names the country.

84.09M

Active mobile subscriptions in Kenya (CA, Q3 FY2025/26)

136

Networks peering at KIXP, Nairobi (PeeringDB)

1.28–1.31

Kubernetes versions at launch

99.95%

Control-plane SLA on Fault Tolerant clusters

What comes wired in

A CSI driver that provisions HDD, Universal SSD or Fast SSD volumes straight from your PVCs. Services of type LoadBalancer that provision a cloud load balancer. An NGINX ingress controller and Helm from any repository. Prometheus and Grafana with alerting on every cluster. Private clusters — control plane and workers with no public IPs, reached over VPN or a bastion — from the first release rather than a later tier.

The team you would otherwise have to hire

Nairobi's market for senior platform engineers is competitive, and the people who have genuinely run etcd in production are a short list who are mostly employed. That is the honest reason managed Kubernetes exists: not because the software is hard to install, but because keeping it healthy for three years is a role, and most Kenyan teams need that role less than one full-time person's worth.

The platform

Everything a production cluster needs

Networking, storage, monitoring, and access control come wired in — so day two looks like day one.

Managed control plane

API server, scheduler, controller manager, and etcd — run, upgraded, and backed up by us.

Autoscaling worker pools

The cluster autoscaler adds and removes nodes with demand, down to zero when idle.

Auto-healing nodes

Unhealthy nodes are detected and replaced automatically, with no manual intervention.

Persistent volumes

A CSI driver provisions HDD, Universal SSD, or Fast SSD volumes straight from your PVCs.

Private clusters

Run control plane and workers with no public IPs, reached over VPN or a bastion host.

Load balancer integration

Services of type LoadBalancer provision cloud load balancers automatically.

Prometheus & Grafana

Built-in monitoring and dashboards on every cluster, with alerting included.

Helm & NGINX ingress

Deploy from any Helm repository, with a built-in NGINX ingress controller for traffic.

Multiple K8s versions

Choose Kubernetes 1.28–1.31 and upgrade through the console with zero downtime.

Regions

Nairobi is home. The other two are there when you need them.

ke-1a is in Nairobi, and for a Kenyan business that is most of the argument. Your customers arrive on Safaricom, on Faiba, on Zuku, on Poa — 2.65 million fixed subscriptions and 84.1 million active SIMs, nearly all of them inside the country. Lineserve peers at KIXP, the neutral exchange TESPOK runs across four Nairobi facilities, so traffic between your instance and another of its 136 networks is handed over a few kilometres away. A round trip that starts and finishes inside the metro is typically around 2 ms.

That matters because of where Kenya's bandwidth comes ashore. Every international subsea cable lands at Mombasa — SEACOM, EASSy, TEAMS, PEACE, DARE1 and LION2 — and the capacity is hauled roughly 480 km inland before it reaches a Nairobi rack. Anything leaving the country still makes that trip. Domestic traffic takes the other route entirely, exchanged in Nairobi between networks in the same city, and choosing ke-1a decides which of those two journeys your checkout depends on.

Dar es Salaam and Lagos sit on the same account, the same API and the same shilling invoice. Open tz-1a when you start selling into Tanzania and want the data held there under Tanzanian law, or ng-1a when Lagos becomes a market rather than a pin on a map. They are also where a copy goes when you want one outside Kenya — a standby database, a backup bucket — which makes disaster recovery a configuration change instead of a second supplier.

Live

Kenya

Nairobi

~2 ms

typical, within metro · Data stays in Kenya

Live

Tanzania

Dar es Salaam

~6 ms

typical, within metro · Data stays in Tanzania

Live

Nigeria

Lagos

~4 ms

typical, within metro · Data stays in Nigeria

Live

Uganda

Kampala

~3 ms

typical, within metro · Data stays in Uganda

Expansion zonesSouth Africa · za-1aGhana · gh-1a

Use cases

Built for what you're building

Microservices

Run service meshes with built-in discovery, load balancing, and rolling deploys.

CI/CD pipelines

Host Jenkins, GitLab runners, or Argo CD close to your team, scaling with each build.

Batch & ML workloads

Queue batch jobs and training runs on autoscaling pools that shrink when idle.

Dev environments

Give every team an isolated namespace — one cluster, clean boundaries, less sprawl.

How it works

From zero to cluster in four steps

1

Pick region, version & cluster type

Choose your region, a Kubernetes version, and Basic or Fault Tolerant control plane.

2

Add worker pools

Size pools in vCPU, RAM, and storage, and set autoscaler bounds per pool.

3

Deploy with your tools

Download the kubeconfig, then kubectl apply or helm install like any cluster.

4

Let it run

The autoscaler tracks demand and auto-healing replaces bad nodes — day and night.

Uptime SLA

99.9%

  • DDoS filtering is included, not an upsell
  • Service credits applied automatically when we miss the SLA
  • Measured monthly, per region, on network and power availability

Support

A Nairobi number, and East Africa Time all year

Kenya has its own line: +254 119 039 063. Alongside it are [email protected] and the ticket system, and Lineserve Limited keeps an office on Utalii Lane, View Park Towers, in the Nairobi CBD. A supplier with a street address in your own city is a different kind of counterparty from a web form and a billing address in another hemisphere.

Kenya runs on East Africa Time, UTC+3, and has never observed daylight saving. That reads like trivia until you are the one holding the phone. Business hours here mean the same thing in January and in July; nothing slides by an hour twice a year because another country changed its clocks. When your checkout starts throwing 502s at 09:20 on a Tuesday, it is 09:20 for whoever picks up — an ordinary working morning in the same city, rather than the small hours of somebody's Monday night, eight time zones west.

The other half of local support is vocabulary, not hours. The person you reach knows what a Safaricom callback is, what KIXP has to do with the trace you are staring at, and why your finance team wants a KRA PIN on the invoice. None of that has to be explained before the actual problem can be. Buy from somewhere that has never sold into Kenya and the first twenty minutes of every serious ticket go on describing the country.

Why Lineserve

Managed here beats self-managed anywhere

Running your own control plane on VMs means patching, etcd backups, and 2 a.m. failovers. Running on a distant hyperscaler means forex bills and latency. This is the third option.

CapabilityLineserveSelf-managed / global cloud
Control plane run and upgraded for you
Billing in KES
Single-digit local latency
Data stays in Kenya
Autoscaling worker poolsSometimes
Support in your timezone
No card or forex required

What it will cost

A cluster fee in shillings, then the resources your pods asked for

Two numbers make a Kubernetes bill here, and keeping them apart is what makes the second one predictable. The cluster management fee comes first: Basic, a single master node for development, testing and non-critical workloads, opens at KES 2,786 a month behind a 99.5% control-plane SLA. Fault Tolerant, three master nodes with automatic failover, opens at KES 11,634 behind a 99.95% SLA. Production belongs on Fault Tolerant; everything else is a judgement about what a broken control plane costs you on a Tuesday afternoon.

Worker resources are the second number, billed per unit consumed: KES 666 per vCPU and KES 306 per GB of RAM a month, node-local disk at KES 19 per GB, and persistent volumes at KES 15 per GB for Network HDD, KES 23 for Universal SSD and KES 34 for Fast SSD. A public IP is KES 150. Load balancers run KES 1,638 for a Basic, KES 3,277 for a Basic with automatic failover and KES 6,553 for an Advanced redundant one. Nothing is bundled into a node size somebody else chose, which is what makes a pool you scale down actually get cheaper.

That structure is why the autoscaler is worth turning on rather than admiring. Pools grow with demand and shrink to zero when idle, so a nightly batch pool is billed for the hours it ran. Model it as three lines: the cluster fee, the steady-state pool, and what the peak costs for the hours the peak lasts. For an election night or a month-end run, the third line is measured in hours rather than months.

These are Kenyan figures from a Kenyan price list rather than a dollar rate converted when the page loads, which is what makes a twelve-month forecast possible. VAT sits on top: Kenya's rate on digital and hosting services is 16%, administered by the KRA, calculated and shown separately at checkout rather than folded into the rate. Send [email protected] your KRA PIN and registered name when you join the waitlist and the billing account is configured once instead of corrected later.

Reserve pricing while you still have a budget cycle

Tell [email protected] the cluster tier and the rough pool shape and the team will put launch pricing in writing against your account. Procurement almost always needs a number long before engineering needs a cluster, and a written quotation is easier to get before a launch than during one.

Where a cluster stops being the cheap answer

Worth saying plainly: for a single application with steady traffic, a cloud server or a VPS is less machinery and less money, and both are live in ke-1a today. Kubernetes earns its cluster fee when you have many services, many clients, or a workload whose shape changes by the hour. If that is not you yet, the honest advice is to wait for the second product rather than the launch of this one.

Prices exclude VAT; 16% is added at checkout. Figures are indicative launch pricing rather than an amount payable today, worker resources bill per unit consumed, and annual billing is ten months for twelve on eligible plans.

Data residency

The manifests are portable. The volumes are in a building.

It is easy to file a cluster under stateless and move on. Then you list the PersistentVolumeClaims: the Postgres a team installed with a Helm chart, the uploads directory, the queue holding message bodies, the logs carrying phone numbers and national ID references, the registry cache. All of it is data on disks in one building, in whichever country the cluster was created in.

Kenya's Data Protection Act, No. 24 of 2019 reaches you whether or not you are established here — section 4 applies it to anyone processing the personal data of data subjects located in Kenya. Sections 48 and 49 attach conditions and paperwork to sending that data out of the country, with sensitive personal data needing consent and confirmed safeguards, and the Data Commissioner able to prohibit, suspend or condition a transfer. Keep the volumes in ke-1a and that work does not arise for what is on them.

Regulation 26 of the 2021 General Regulations is the narrow clause that turns preference into requirement. For six named strategic-interest purposes — civil registration and identity management, the conduct of elections, systems administering public finances, a computer system designated as protected under the Computer Misuse and Cybercrimes Act, basic education, and primary or secondary healthcare — at least one serving copy of that personal data belongs in a data centre located in Kenya. Where your workload is on that list, the cluster's country is decided for you. Where it is not, the argument is the ordinary one about distance and law.

Create the cluster in ke-1a and the worker nodes, their volumes and their backups are in Nairobi, under Kenyan law, and do not leave without your instruction. That is data residency for Kenya's Data Protection Act. Registration with the ODPC, your records of processing and your own assessments stay yours as controller — a shorter pile of work when nothing crossed a border.

Point the backup target at the same country

Velero snapshots, database dumps and object storage mirrors are the classic way data quietly ends up on another continent, because that is where the credentials already pointed. Lineserve object storage runs a per-region endpoint in Nairobi, so a backup target inside Kenya is a configuration line rather than a project.

Non-personal state can go anywhere

Container images, build artefacts, Helm charts and telemetry stripped of identifiers raise none of these questions. Drawing that line explicitly in your own architecture is worth an afternoon — the cost of treating every byte as sensitive is a system your own team cannot operate.

Who runs here

The Kenyan teams a managed control plane is actually for

Not every workload needs Kubernetes. These are the ones where it is already the right answer and the control plane is the part nobody has time for.

Agencies and ISVs with many client workloads

Nairobi's agency and freelance scene is the main reseller channel in this market — one buyer, many client sites, and a long tail of small services that would be uneconomic as individual VMs. One cluster, a namespace per client, resource quotas at the boundary, and pools that scale on the aggregate rather than the worst case. The whole model only works at agency margins if the control plane is somebody else's job.

Fintechs and digital lenders with bursty traffic

Disbursement runs, repayment deadlines, salary week. The load arrives in shapes you can predict to the day but not to the hour, and the services behind it — scoring, KYC, webhook receivers taking callbacks from inside Kenya, the ledger — each want to scale independently. That is precisely the problem Kubernetes solves, and a Fault Tolerant control plane is the part you do not want failing in the middle of a disbursement.

Newsrooms on election night

Nairobi's media sector has a traffic curve that is flat with cliffs in it: a result, a verdict, a budget, a death. Autoscaling worker pools are the difference between a live blog that holds and one that is remembered for going down. Set the bounds in advance, let the autoscaler take the peak, and give the capacity back the next morning — billed for the hours it existed.

Microservices that outgrew a single VM

The common Kenyan path: one Django or Laravel monolith, then a couple of services broken out, then a message queue, then six repositories and a deploy process that only one person understands. Rolling deploys, service discovery and health checks are the point at which a cluster stops being over-engineering and starts being less work than what you have.

CI/CD and internal platforms

GitLab runners, Argo CD, Jenkins agents, staging environments per branch. Build capacity is the textbook autoscaling workload — heavy for twenty minutes after a merge, idle overnight — and running it in Nairobi puts the runners in the same country as the registry they push to and the cluster they deploy into.

SACCO and enterprise batch windows

Month-end, statement generation, a dividend run that needs real capacity for three days and nothing for the rest of the month. A pool with an autoscaler floor of zero costs nothing while it waits, which is a different economic shape from hardware bought for the peak and idle for twenty-seven days.

Data and reporting pipelines

Scheduled ETL into a warehouse, model training runs, nightly aggregation jobs. Queue them onto a pool that scales up for the run and back down afterwards, close to the databases they read from — because a pipeline that pulls a day of transactions across an ocean pays for that ocean every single night.

Customer references are available under NDA — ask [email protected] or call +254 119 039 063 and the team will arrange one against the workload you are buying for.

Migrating

What moving a cluster here will look like at launch

From a control plane you run yourself

kubeadm on three VMs works, right up until the afternoon it does not — a certificate expires, etcd needs a restore rather than a restart, an upgrade goes sideways with production on it. At launch that layer is run, upgraded and backed up for you: API server, scheduler, controller manager and etcd, with unhealthy nodes detected and replaced automatically and version upgrades between 1.28 and 1.31 run through the console. Your manifests do not change. What changes is that the person who currently knows how the cluster was built stops being a single point of failure for the company.

From a managed cluster on another cloud

Kubernetes is the portable part, and the standard tools do the work: kubectl, Helm and Velero. Export the namespaces, replace any provider-specific annotations and storage classes with the CSI classes here, re-issue the ingress, run both clusters until the new one is healthy, then move DNS. The parts that need real thought are stateful — what happens to the volumes and how long a write pause your service can survive. Migration planning is included at no extra charge and it is better done before the service opens than after, so the cluster you get on day one is already the right shape.

There is one question that settles where a cluster really is, and it is worth asking of every provider you shortlist, this one included: which building are the worker nodes in, and in which country is that building? For ke-1a the answer is Nairobi.

FAQ

Questions, answered

A service where we run the Kubernetes control plane for you — API server, scheduler, controller manager, and etcd — and handle upgrades, backups, and availability. You deploy and manage your applications; we keep the cluster healthy.

Basic clusters run a single master node and suit development, testing, and non-critical workloads, with a 99.5% control-plane SLA. Fault Tolerant clusters run 3 master nodes with automatic failover on a 99.95% SLA — recommended for production.

You pay the monthly cluster management fee (Basic or Fault Tolerant) plus the worker-node resources you actually consume — vCPU, RAM, storage, and load balancers. Scale worker pools up or down anytime; you only pay for what you use.

Versions 1.28 through 1.31, with new versions added shortly after upstream release. You upgrade your cluster through the console with zero downtime.

Yes. Enable the cluster autoscaler, set minimum and maximum node counts, and it adds or removes worker nodes automatically as your workload demands.

Yes. Create a cluster where the control plane and worker nodes have no public IP addresses, and reach it through a VPN or bastion host for maximum security.

Our CSI driver provisions volumes automatically when you create PersistentVolumeClaims. Choose HDD, Universal SSD, or Fast SSD storage classes to match your performance needs.

Yes. Every cluster ships with built-in Prometheus monitoring and Grafana dashboards. Container logs can flow to our logging service or your own backend.

Yes. Standard tools like kubectl, Helm, and Velero work directly, and our team assists with migration planning at no extra charge.

It is in build and not open for orders. Rather than publish a date that moves, we tell the waitlist directly — email [email protected] or call +254 119 039 063 with the workload you have in mind and you will hear when the first release is ready.

Not yet. What you can do now is size the cluster and the pools with us, get launch pricing in writing against your account, and be in the first group given access. Cloud servers, VPS and dedicated hardware in ke-1a are live today if you need capacity in Nairobi before then.

In ke-1a, our Nairobi region. Control plane, worker nodes and their persistent volumes all sit there, in the same region already running cloud servers, VPS, dedicated hardware and object storage.

Basic runs a single master node and suits development, testing and non-critical workloads, on a 99.5% control-plane SLA at KES 2,786 a month. Fault Tolerant runs three master nodes with automatic failover on a 99.95% SLA at KES 11,634. Production belongs on Fault Tolerant.

The monthly cluster management fee plus the worker resources you consume — KES 666 per vCPU, KES 306 per GB of RAM, KES 19 per GB of node-local disk, persistent volumes from KES 15 per GB, public IPs at KES 150 and load balancers from KES 1,638. Scale pools up or down and the resource line follows.

No. Those figures are indicative launch pricing and nothing bills until the service opens. If your budget cycle needs a number sooner, ask [email protected] for a written quotation against your account.

No. Displayed prices exclude VAT. Kenya's rate on digital and hosting services is 16%, administered by the KRA, calculated and shown separately at checkout.

1.28 through 1.31 at launch, upgraded through the console, with new versions added shortly after upstream release.

Yes. Set minimum and maximum node counts per pool and the cluster autoscaler adds and removes nodes with demand, down to zero on pools that are idle — which is what makes a nightly batch pool cost what the night cost.

Yes — control plane and worker nodes with no public IP addresses, reached over VPN or a bastion host, from the first release.

A CSI driver provisions them from your PersistentVolumeClaims, with HDD, Universal SSD and Fast SSD storage classes. Those volumes are created in ke-1a and stay in Nairobi.

Yes. Prometheus and Grafana dashboards ship on every cluster with alerting included, and container logs can flow to our logging service or to a backend you already run.

Yes. Worker nodes and their volumes sit in ke-1a and are not moved out of the country without your instruction, which gives you data residency for Kenya's Data Protection Act. Point your backup target at the Nairobi object storage endpoint and the whole path stays in-country.

Often, no — and it is worth being blunt about it. One application with steady traffic runs better and cheaper on a cloud server or a VPS, both live in ke-1a today. Kubernetes earns its cluster fee when you have many services, many clients, or a load whose shape changes by the hour.

Yes, at no extra charge, and preferably before launch. Send your current version, the rough pool shape, your storage classes and what the volumes hold to [email protected].

Email [email protected], call +254 119 039 063, or use the contact form, with the cluster tier and pool shape you would use. No card, no commitment — it puts you in the first group given access and gets launch pricing written against your account.

Ship on Kubernetes, skip the control plane

Managed Kubernetes is launching soon. Talk to us to reserve early access and pricing in your local currency, with no card to start.

Launching soon · 99.95% control-plane SLA on Fault Tolerant · Billed in KES