LINESERVE

Load Balancers — Nairobi, ke-1a · launching soon

Coming soon

Load Balancers in Kenya

Kenya's biggest traffic days are already in the calendar. The time to build for them is before one arrives.

Kenyan traffic is not a smooth curve. It is a general election in August, budget day in June, and the morning national exam results go up — days when a newsroom, a results portal or a lender's callback endpoint takes a quarter's worth of concurrent users inside a few hours, on a date everybody knew months in advance. A load balancer is what stands in front of that: one IP, a pool of Nairobi servers behind it, and a backend that stops passing its health check leaving the pool instead of taking the site with it. Load Balancers land in ke-1a soon, at a flat monthly price with no per-request charges, indicatively from KES 2,000. Join the waitlist and we will tell you when it is ready.

FromKES 2,000/month
  • Launching soon in Nairobi — region ke-1a
  • HTTP, HTTPS, TCP and UDP, with SSL termination at the balancer
  • Health checks pull a failing backend out of the pool automatically
  • Flat monthly pricing in KES, with no per-request charges
  • 99.99% uptime SLA, and unlimited transfer to same-region backends

Launching soon · Billed in KES

Pricing

One flat price, no per-request fees

Pick a size for your traffic. Data transfer between the load balancer and same-region backends is unlimited and included. In your currency, no forex.

Small

KES 2,000/mo

Hosted in Nairobi, Dar es Salaam, Lagos & Kampala

  • 10,000 concurrent connections
  • 250 Mbps throughput
  • Up to 20 backends
  • Basic health checks
  • Unlimited same-region transfer
Popular

Medium

KES 4,000/mo

Hosted in Nairobi, Dar es Salaam, Lagos & Kampala

  • 50,000 concurrent connections
  • 1 Gbps throughput
  • Up to 50 backends
  • Advanced health checks
  • Unlimited same-region transfer

Large

KES 6,500/mo

Hosted in Nairobi, Dar es Salaam, Lagos & Kampala

  • 100,000 concurrent connections
  • 2.5 Gbps throughput
  • Up to 100 backends
  • Health checks with SSL verification
  • Unlimited same-region transfer

Enterprise

KES 13,000/mo

Hosted in Nairobi, Dar es Salaam, Lagos & Kampala

  • 250,000+ concurrent connections
  • 5+ Gbps throughput
  • Unlimited backends
  • Custom-script health checks
  • Unlimited same-region transfer

Flat monthly pricing with no hidden fees and no per-request charges. Upgrade or downgrade tiers anytime with zero downtime. Prices exclude VAT; local currency figures are indicative and settled at checkout.

Network

A Kenyan spike arrives from inside Kenya, all at once

Start with where the traffic comes from, because that decides whether a load balancer helps. Kenya's international capacity lands at Mombasa — SEACOM, EASSy, TEAMS, PEACE, DARE1 and LION2 all come ashore at the coast — and is hauled roughly 480 km inland before it reaches a Nairobi rack. That path matters enormously for a request originating in London and hardly at all for one originating in Kilimani. On the days this page is about, almost none of the requests originate in London.

Nairobi is where Kenyan networks meet each other. KIXP, the neutral exchange TESPOK has run in its current form since February 2002, carries 136 peer networks over 151 connections and 2.9 Tbps of combined capacity across four Nairobi facilities. Lineserve peers there. The single public address a balancer puts in front of your servers is therefore a Nairobi address, reached over a route that stays inside the city — typically a single-digit-millisecond round trip rather than an ocean crossing.

Then the scale of the arrival. The Communications Authority counted 84,090,298 active mobile subscriptions in the quarter to March 2026, at 157.7% penetration, and Safaricom holds 68.9% of them. One dominant network changes the shape of a Kenyan peak: when a results portal opens at 10:00, a very large share of the country arrives over the same carrier, in the same minute, from inside the same country. There is no gentle geographic ramp to hide behind.

That is the case for a pool rather than a machine. Behind one balancer, capacity becomes an addition rather than a rebuild: more backends before the date, fewer after it, with the entry point unchanged and the DNS record untouched. Traffic between the balancer and same-region backends is unlimited and included, so health checks, retries and the fan-out of a spike across your pool never leave the metro.

84.1M

Active mobile subscriptions in Kenya (CA, Q1 2026)

68.9%

Safaricom share of mobile subscriptions (CA, Q1 2026)

136

Networks peering at KIXP, Nairobi (PeeringDB)

2.9 Tbps

Combined KIXP capacity, four Nairobi facilities

The Kenyan traffic calendar

A general election every five years in August. Budget day in June. National exam results, released on a date the whole country watches for. Each is a single-day, single-hour event on top of an ordinary load, and each is known about a year ahead. The number that decides the architecture is the peak on one Tuesday morning, not the monthly average — and the sites that carry those peaks are newsrooms, results portals and civic platforms whose readers judge them entirely on that one morning.

Month-end has a shape too

Kenya's other recurring peak is financial rather than civic. Digital lenders see disbursement and repayment cluster around payday and the last days of the month; SACCOs run month-end closes and dividend runs; billers and schools take fee payments in waves at the start of a term. That is a repeating, predictable surge twelve times a year rather than once every five, and it lands on the endpoints least able to shrug it off.

Pricing & payment

What it will cost, in shillings

Load Balancers are priced the same way as everything else on this platform: a flat monthly figure per balancer, in Kenya Shillings, with no per-request charge and no metered fee for traffic to same-region backends. The KES figures below are indicative launch pricing — the shape of the bill rather than an amount payable today — and they are set on Kenya's own price list rather than converted from a dollar rate at the moment the page loads.

Four sizes, one flat monthly figure

Small is indicatively KES 2,000 a month for 10,000 concurrent connections and 250 Mbps across up to 20 backends. Medium is KES 4,000 for 50,000 connections and 1 Gbps. Large is KES 6,500 for 100,000 connections and 2.5 Gbps. Enterprise is KES 13,000 for 250,000-plus connections, 5-plus Gbps and unlimited backends. You size for the Tuesday, not the Sunday.

M-Pesa, bank transfer or card — all in KES

At launch a Kenyan customer will settle a balancer the way they settle a VPS today: in shillings, by M-Pesa and other mobile money, by bank transfer, or by card. Nothing converts, and no bank adds a foreign-transaction fee to it.

Traffic to your backends is included

Transfer between the balancer and backends in the same region is unlimited. Health checks every few seconds across a pool, retries and the fan-out of a spike to twenty machines all sit inside the flat figure, which is what makes it forecastable rather than a starting bid.

The waitlist costs nothing

No card, no commitment. Tell [email protected] what you would put behind a balancer and which month matters most to you — an election cycle, a results window, a month-end run — and that shapes what ships in ke-1a first.

Displayed prices exclude VAT; Kenya's standard rate on this class of service is 16% and it is calculated and shown separately at checkout. Local-currency figures are indicative until launch. For a written quotation against a purchase order, [email protected].

The platform

Everything between your users and your servers

Termination, health checks, persistence, and protection — handled at the edge of your stack so your backends just serve.

Automatic failover

Failing backends drop out of the pool instantly and traffic reroutes to healthy servers — no manual intervention.

Smart health checks

Probe backends over HTTP, HTTPS, TCP, or ICMP with custom intervals, timeouts, and recovery thresholds.

SSL/TLS termination

TLS 1.2 and 1.3 with SNI for multiple certificates, automatic renewal, and encryption offloaded from your backends.

Four balancing algorithms

Round Robin, Least Connections, Source IP Hash, and Weighted Round Robin — match the algorithm to the workload.

Session persistence

Cookie-based or source-IP sticky sessions keep stateful clients pinned to the same backend.

DDoS protection built in

Rate limiting and connection throttling at the balancer, before traffic ever reaches your servers.

IPv4 & IPv6

Full dual-stack support on every load balancer, at every tier.

Real-time monitoring

Live traffic, connection counts, backend health, and access logs with request-level detail.

API & Terraform

Create and manage balancers from a REST API or the Terraform provider — wired into your CI/CD.

Regions

Nairobi is home. The other two are there when you need them.

ke-1a is in Nairobi, and for a Kenyan business that is most of the argument. Your customers arrive on Safaricom, on Faiba, on Zuku, on Poa — 2.65 million fixed subscriptions and 84.1 million active SIMs, nearly all of them inside the country. Lineserve peers at KIXP, the neutral exchange TESPOK runs across four Nairobi facilities, so traffic between your instance and another of its 136 networks is handed over a few kilometres away. A round trip that starts and finishes inside the metro is typically around 2 ms.

That matters because of where Kenya's bandwidth comes ashore. Every international subsea cable lands at Mombasa — SEACOM, EASSy, TEAMS, PEACE, DARE1 and LION2 — and the capacity is hauled roughly 480 km inland before it reaches a Nairobi rack. Anything leaving the country still makes that trip. Domestic traffic takes the other route entirely, exchanged in Nairobi between networks in the same city, and choosing ke-1a decides which of those two journeys your checkout depends on.

Dar es Salaam and Lagos sit on the same account, the same API and the same shilling invoice. Open tz-1a when you start selling into Tanzania and want the data held there under Tanzanian law, or ng-1a when Lagos becomes a market rather than a pin on a map. They are also where a copy goes when you want one outside Kenya — a standby database, a backup bucket — which makes disaster recovery a configuration change instead of a second supplier.

Live

Kenya

Nairobi

~2 ms

typical, within metro · Data stays in Kenya

Live

Tanzania

Dar es Salaam

~6 ms

typical, within metro · Data stays in Tanzania

Live

Nigeria

Lagos

~4 ms

typical, within metro · Data stays in Nigeria

Live

Uganda

Kampala

~3 ms

typical, within metro · Data stays in Uganda

Expansion zonesSouth Africa · za-1aGhana · gh-1a

Use cases

Built for what you're building

Web applications

Spread HTTP and HTTPS traffic across your web servers for high volume with zero downtime.

APIs & microservices

A single entry point routing requests across API instances and containerized services.

Database read scaling

Balance read queries across replicas while writes go straight to the primary.

Gaming & streaming

Low-latency TCP and UDP balancing for player connections and high-bandwidth media.

How it works

In front of your traffic in three steps

1

Create a load balancer

Pick a region and a size tier — live in under 60 seconds from the console or API.

2

Add backends & health checks

Point it at your servers, choose an algorithm, and set the health check that fits.

3

Point your DNS at it

One record change and traffic flows through — failover and monitoring are already on.

Uptime SLA

99.9%

  • DDoS filtering is included, not an upsell
  • Service credits applied automatically when we miss the SLA
  • Measured monthly, per region, on network and power availability

Support

A Nairobi number, and East Africa Time all year

Kenya has its own line: +254 119 039 063. Alongside it are [email protected] and the ticket system, and Lineserve Limited keeps an office on Utalii Lane, View Park Towers, in the Nairobi CBD. A supplier with a street address in your own city is a different kind of counterparty from a web form and a billing address in another hemisphere.

Kenya runs on East Africa Time, UTC+3, and has never observed daylight saving. That reads like trivia until you are the one holding the phone. Business hours here mean the same thing in January and in July; nothing slides by an hour twice a year because another country changed its clocks. When your checkout starts throwing 502s at 09:20 on a Tuesday, it is 09:20 for whoever picks up — an ordinary working morning in the same city, rather than the small hours of somebody's Monday night, eight time zones west.

The other half of local support is vocabulary, not hours. The person you reach knows what a Safaricom callback is, what KIXP has to do with the trace you are staring at, and why your finance team wants a KRA PIN on the invoice. None of that has to be explained before the actual problem can be. Buy from somewhere that has never sold into Kenya and the first twenty minutes of every serious ticket go on describing the country.

Why Lineserve

Managed beats maintaining your own proxy

Running NGINX or HAProxy on a VPS means one more machine to patch, monitor, certify, and fail over — and it's usually the single point of failure in front of everything else.

CapabilityLineserveSelf-run NGINX/HAProxy
No proxy VM to run or patch
Automatic failoverSometimes
Managed SSL with auto-renewal
Upgrade capacity with zero downtime
Billing in KES
Support in your timezone
Data stays in Kenya

Data residency

The balancer is the first thing that touches a Kenyan request

Terminating TLS at the balancer moves a piece of your architecture forward: the certificate lives there, the connection from the user ends there, and the access log with request-level detail is written there. A load balancer in ke-1a therefore holds all of that in Nairobi, in the same city as the backends behind it and the people in front of it.

Kenya's Data Protection Act, No. 24 of 2019 is administered by the Office of the Data Protection Commissioner, and hosting abroad does not put a business outside it — section 4(b) reaches a controller or processor with no Kenyan establishment that processes the personal data of people located in Kenya. Section 48 permits transfers out of the country where appropriate safeguards have been demonstrated to the Data Commissioner or another listed ground applies, and section 49 adds the data subject's consent for sensitive personal data. Keep the entry point and the pool in Nairobi and there is no transfer in the request path to account for.

Set Regulation 26 of the Data Protection (General) Regulations, 2021 beside the traffic calendar and the two lists rhyme. Section 50 lets the Cabinet Secretary require processing through a server or data centre located in Kenya, and Regulation 26 names six purposes — among them the conduct of elections, overseeing systems for administering public finances, and early childhood and basic education. Those are three of Kenya's sharpest single-day peaks and three of the six named purposes at once.

An access log is personal data

Request-level logging at the balancer captures client IP addresses, timestamps and paths for every visitor. That is a live dataset about identifiable people, and it accumulates fastest on the days you were built for. Held in ke-1a, it stays in Nairobi with everything else.

In a restricted sector, size is no defence

Registration with the Office of the Data Protection Commissioner runs from KES 4,000 for micro and small entities to KES 40,000 for large ones, and the exemption for small entities is switched off in financial services, telecommunications, health, education, insurance, betting and public bodies. A four-person digital lender registers on the same footing as a bank. That follows from what you process; what a region supplies is the location.

What Lineserve supplies is data residency for Kenya's Data Protection Act — your data held in Nairobi and moved out of Kenya only when you move it. Registration, notices and the rest of the controller's job stay with you.

Who it is for

The Kenyan traffic that needs something in front of it

Two things make a business buy a load balancer: traffic that spikes, and traffic that cannot stop. Kenya supplies unusually clear examples of both.

Newsrooms, results portals and civic platforms

Nairobi's media sector is unusually large for the size of the market and its traffic is event-shaped rather than curve-shaped: an August general election, budget day in June, exam results, a court judgment nobody diaried. Live-blog infrastructure, WordPress behind a cache and a results lookup are all read-heavy and all trivially poolable — which means the peak is answered by adding backends before the date and taking them away after it, behind one balancer whose address never changes.

Digital lenders and mobile-money integrations

The Central Bank has licensed digital credit providers under its 2022 regulations and processed well over 800 applications since. The architecture repeats: callback receivers that must be awake when the operator calls them, credit-scoring jobs, KYC document stores, loan-book databases, USSD gateway backends. Payday and month-end are the peaks, and the callback endpoint is the one component where a single machine is a business risk rather than an engineering preference.

SACCOs and microfinance

Deposit-taking SACCOs sit under SASRA and run genuine core banking: member portals, USSD and mobile channels, mobile-money reconciliation. The load has a monthly rhythm — closes, dividend runs, statement generation — during which the member portal is being hit by the whole membership at once. Balancing the member-facing tier lets the batch work carry on behind it without the portal being the casualty.

Online retail and the checkout path

KENIC counts roughly 123,150 registered .ke domains, and a long tail of retail has moved from social selling onto WooCommerce. Checkout is where a Kenyan shopper feels every extra second, and it is also where a payment callback arrives. Two or three web backends behind one balancer is the difference between a slow Friday and a lost one.

ISPs, WISPs and managed service providers

Behind Safaricom and Faiba, the Authority's fixed-ISP table has a long tail — Ahadi Wireless, Vilcom, Mawingu and dozens of regional operators. RADIUS and AAA, recursive resolvers, provisioning and billing portals: these run over TCP and UDP as often as HTTP, and they are load-bearing for the operator's own customers. Balancing them is about the second reason people buy this rather than the first.

Health, education and NGO platforms

Nairobi holds a very large concentration of NGO and UN regional offices, and their systems are the ones Regulation 26 names: DHIS2 deployments, form servers taking submissions from enumerators on mobile data, school management platforms. The surges are administrative — a reporting deadline, a term start — and the residency question is already on the procurement form.

Cloud servers, VPS, dedicated LineServe Core hardware and object storage are live in ke-1a today and are what a balancer will sit in front of. Load Balancers themselves are launching soon — join the waitlist through [email protected].

Before launch

What you are probably running in front of it now

NGINX or HAProxy on a VPS you keep alive yourself

This is the honest majority case in Nairobi, and it works right up until the morning it does not. The proxy is one machine you patch, monitor, certify and fail over, and it sits in the path of everything behind it — simultaneously the cheapest component and the single point of failure. It also needs a human on results morning, watching the certificate and the connection table at 06:00. A managed balancer takes that off your rota. The preparation that pays now is making your backends interchangeable: configuration out of the box, sessions out of local memory, health endpoints that answer honestly.

A cloud load balancer sitting outside Kenya

The other common shape is a balancer in Europe in front of servers that have already moved to Nairobi, usually because the balancer came with the old account and nobody unpicked it. Every Kenyan request then leaves the country to reach the thing that sends it back into the country, twice per round trip, on the busiest day of your year. The fix is an entry point in the same region as the pool — and the answer that decides how fast that cutover goes is knowing which of your backends are genuinely stateless.

Four questions are worth putting to any provider, this one included. Which building is the machine in, and in which city? Is domestic traffic exchanged inside Kenya? What does the uptime SLA pay when it is missed, and who claims it? And does the invoice work for your VAT return? Ask them of the balancer as well as the backends.

FAQ

Questions, answered

It sits in front of your servers on a single IP and distributes incoming traffic across them. If a backend fails, traffic reroutes to healthy servers automatically — better availability, better performance, no single point of failure.

A flat monthly rate per size tier — Small, Medium, Large, or Enterprise. Data transfer between the load balancer and backends in the same region is unlimited and included. No per-request charges, no hidden fees.

Yes. Backends can be Lineserve Cloud Servers, VPS, dedicated servers, Kubernetes nodes — or servers hosted anywhere else, as long as the load balancer can reach them over the network.

Upload certificates to the load balancer and it terminates SSL/TLS for you, offloading encryption from your backends. TLS 1.2 and 1.3 are supported, with SNI for serving multiple certificates from one load balancer and automatic renewal.

The load balancer probes each backend over HTTP, HTTPS, TCP, or ICMP on an interval you set. Servers that fail their threshold are removed from the pool automatically and re-added once they recover.

Sticky sessions route a returning client to the same backend — essential for apps that keep session state locally. Choose cookie-based or source-IP persistence per load balancer.

Round Robin for evenly matched servers, Least Connections for long-lived connections, Source IP Hash to pin clients to a server, and Weighted Round Robin to send more traffic to bigger machines.

Yes. Upgrade or downgrade anytime with zero downtime — your configuration, certificates, and backend pools carry over unchanged.

They are in build and there is no public date yet. Nairobi (ke-1a) is one of the regions in the first release. Put your details on the waitlist through [email protected] and you will hear from us when there is something to point at.

Indicative launch pricing runs from KES 2,000 a month for Small, KES 4,000 for Medium, KES 6,500 for Large and KES 13,000 for Enterprise — flat monthly figures per balancer, with no per-request charges. Those numbers are indicative until launch, and they exclude VAT.

Early access is being allocated by workload rather than by queue position. Tell [email protected] what you would put behind a balancer, how many backends, which protocols, and the date in your calendar you are worried about, and that conversation is how a place is reserved.

Not yet — Load Balancers are launching soon and the page shows what it will look like when they land. Cloud servers, VPS, dedicated servers and object storage in ke-1a are live now and are what a balancer will sit in front of.

In the region you create it in. For a Kenyan deployment that is ke-1a, Nairobi — the same city as your backends, so the hop between the balancer and the pool stays inside the metro and is included in the flat price.

HTTP, HTTPS, TCP and UDP, dual-stack on IPv4 and IPv6 at every tier, across Round Robin, Least Connections, Source IP Hash and Weighted Round Robin. Session persistence is available as cookie-based or source-IP sticky sessions where a client has to stay pinned to one backend.

Yes. TLS 1.2 and 1.3 with SNI for multiple certificates, automatic renewal, and the encryption work taken off your backends.

Health checks probe your backends over HTTP, HTTPS, TCP or ICMP with intervals, timeouts and recovery thresholds you set. A backend that stops passing drops out of the pool and traffic reroutes to the healthy ones, with no manual intervention — and it is added back when it starts passing again.

A load balancer serves a pool of backends in its own region, which is what the included unlimited same-region transfer covers. Teams wanting a presence in more than one of Nairobi, Dar es Salaam and Lagos run a balancer in each region and steer between them at the DNS layer, which stays under their control.

In Kenya Shillings, using M-Pesa and other mobile money, bank transfer, or card — the same methods as everything else on a Kenyan account. Tiers move up or down without downtime. Displayed prices exclude VAT, and Kenya's 16% is shown separately at checkout.

Make the peak survivable by addition rather than by luck. Get the read path stateless so a second and third backend are interchangeable copies, move sessions out of local memory, put a real health endpoint on each machine, and know how long a cold backend takes to become useful. Do that before launch and adding a balancer in front is a DNS change on the day.

It is the classic candidate. Callbacks arrive when the operator decides, they cluster with your own busiest traffic, and a single receiver makes one machine the edge of your business. A pool behind one address, with health checks deciding who is answering, is why this gets specified alongside the integration rather than after it.

For Kenyan users reaching a Nairobi balancer in front of Nairobi backends, the request path stays inside the country, and the certificate, connection and access logs are held in ke-1a. That is data residency for Kenya's Data Protection Act; your own controller obligations are unchanged.

Yes — balancers are created and managed from a REST API and a Terraform provider as well as the console, so they belong in the same CI/CD pipeline as the rest of your infrastructure.

Put a load balancer in front of it — soon

Load Balancers are launching soon. Talk to us to reserve early access and pricing in your local currency, with no card to start.

Launching soon · 99.99% uptime SLA · Billed in KES