Northflank
PaaS for deploying and scaling modern applications
How do you run software in production without a team to babysit the servers?
Most modern software ships in Packages that hold an application and everything it needs to run, isolated from other software on the same machine.. A container bundles an application with its configuration files, libraries and dependencies and runs it as an isolated process, while all the containers on a machine share one operating system The core of an operating system, which controls the hardware and referees every program's access to it.. Think of shipping containers: the crane doesn't care what's inside.
In production, something has to keep those containers alive. If one goes down, another needs to start. The usual answer is Open-source software that runs containers across a cluster of machines and keeps them healthy., an open-source system that gathers machines into a cluster, restarts containers that fail, spreads traffic across them and rolls out new versions at a controlled rate.
A platform as a service sits a level higher. You look after your application and its data; the provider handles the runtime, operating system, servers, storage and networking. Most platforms also run Continuous integration and delivery: merging code often and building, testing and shipping it automatically.: merging small changes often, then building, testing and deploying them automatically.
Further reading Containerization (computing) (Wikipedia)Overview (Kubernetes Documentation)Kubernetes (Wikipedia)Platform as a service (Wikipedia)CI/CD (Wikipedia)
- i.
Parts, not a platform
Kubernetes is not an all-inclusive platform. It doesn't build your application or deploy source code, and it leaves logging, monitoring and databases to you. It gives you the building blocks for a developer platform, and a common criticism is that it is too complex, which Google itself has admitted. Assembling the rest is the job of an infrastructure team.
- ii.
A shared kernel
Because containers share an operating system, a security problem in one can reach the whole system. That was tolerable when you wrote all the code yourself. It is less so when AI agents write code that has to run somewhere, or customers upload scripts. Stronger isolation means wrapping each workload in a lightweight virtual machine, with hardware virtualization as a second line of defence, or in a user-space kernel like gVisor, which costs extra cycles and memory.
- iii.
GPUs are fussy
Getting a GPU into a Kubernetes cluster means an administrator installing the vendor's drivers on each machine and running the vendor's A Kubernetes add-on from a hardware vendor that lets containers request special hardware such as GPUs.. Only then can a container ask for a GPU the way it asks for CPU or memory. Multiply that by several clouds, each with its own managed flavour of Kubernetes.
- iv.
Data that must stay home
Many companies can't hand everything to someone else's cloud. Data sovereignty means data generated inside a country is governed by that country's laws, which can dictate where it is stored and who may touch it. Early platforms lived only in the public cloud, and private and hybrid versions came later for exactly this reason.
Further reading Overview (Kubernetes Documentation)Kubernetes (Wikipedia)Containerization (computing) (Wikipedia)Secure sandboxes for multi-tenant workloads (Northflank)Kata Containers (Open Infrastructure Foundation)Performance Guide (gVisor)What is gVisor? (gVisor)Schedule GPUs (Kubernetes Documentation)The runtime platform for AI-native companies (Northflank)Data sovereignty (Wikipedia)Platform as a service (Wikipedia)
Northflank wants to give teams one governed path from code, including AI-generated code, to production, across any cloud, a company's own A virtual private cloud: a walled-off network a company rents inside a public cloud. or its own data centre. The idea is that a small team gets the benefits of Kubernetes without having to become Kubernetes experts.
That covers the usual services, databases and scheduled jobs, and the newer workloads too: model inference, training, and agents that run code nobody on the team wrote.
Further reading The runtime platform for AI-native companies (Northflank)AI/ML workloads (Northflank)
- Step 1: Kubernetes as the engine
Northflank runs on Kubernetes and treats it as an operating system. You can deploy to Northflank's own cloud or connect your GKE, EKS, AKS or bare-metal cluster. Connect a Git repository and pushes trigger builds and deploys, and pull requests can spin up throwaway preview environments.
- Step 2: Your cloud, their controls
With bring your own cloud, workloads run in the customer's AWS, GCP or Azure account, on premises or on bare metal, keeping the runtime and data inside the customer's boundary. It builds on standards like Kubernetes APIs and Dockerfiles, so workloads can move between clusters and providers.
- Step 3: GPUs as ordinary resources
Northflank handles GPU attachment, CUDA driver setup and cluster provisioning, and GPU jobs use the same interface, command line and API as CPU ones. Teams can spread GPU work across clouds and switch providers based on availability, price or latency.
- Step 4: A microVM per stranger
For untrusted code, each workload runs in its own A stripped-down virtual machine that starts almost as fast as a container but gets its own kernel. using Kata Containers or gVisor. A microVM boots in under a second, so an agent or a user script can get its own sandbox on demand.
Further reading The runtime platform for AI-native companies (Northflank)Bring your own cloud (Northflank)AI/ML workloads (Northflank)Secure sandboxes for multi-tenant workloads (Northflank)
What happens if your platform disappears?
The first public platform as a service shut down, and in doing so gave the first example of the perils of depending on a single provider. Building on open standards is the usual defence, since it keeps the exit door open.
How much does strong isolation cost?
A user-space kernel imposes costs in extra cycles and memory, which may show up as latency, lower throughput, or not at all. How much depends on the workload, and on how busy the system calls are.
Further reading Platform as a service (Wikipedia)Performance Guide (gVisor)
Northflank is a self-service application platform that allows teams to deploy, run, and scale modern applications without managing underlying cloud infrastructure. The platform abstracts away Kubernetes and cloud primitives, enabling developers to move from code to production quickly while retaining flexibility as systems grow more complex.
Northflank supports containerized services, background jobs, databases, and CPU- and GPU-based workloads, including AI inference, across major cloud providers. As applications become more distributed — and as AI increases the number of services, jobs, and environments teams need to operate — Northflank aims to provide a simpler, more reliable way to run production systems without building large internal infrastructure teams.
Northflank is designed for teams that want to move fast without hiring an infrastructure team — and for systems that need to stay reliable as they scale.
- containers
- Packages that hold an application and everything it needs to run, isolated from other software on the same machine.
- kernel
- The core of an operating system, which controls the hardware and referees every program's access to it.
- Kubernetes
- Open-source software that runs containers across a cluster of machines and keeps them healthy.
- CI/CD
- Continuous integration and delivery: merging code often and building, testing and shipping it automatically.
- VPC
- A virtual private cloud: a walled-off network a company rents inside a public cloud.
- device plugin
- A Kubernetes add-on from a hardware vendor that lets containers request special hardware such as GPUs.
- microVM
- A stripped-down virtual machine that starts almost as fast as a container but gets its own kernel.
- 1Containerization (computing) · Wikipedia
- 2Overview · Kubernetes Documentation
- 3Kubernetes · Wikipedia
- 4Platform as a service · Wikipedia
- 5CI/CD · Wikipedia
- 6Kata Containers · Open Infrastructure Foundation
- 7Performance Guide · gVisor
- 8Schedule GPUs · Kubernetes Documentation
- 9Data sovereignty · Wikipedia
- 10The runtime platform for AI-native companies · Northflank
- 11Bring your own cloud · Northflank
- 12AI/ML workloads · Northflank
- 13Secure sandboxes for multi-tenant workloads · Northflank
- 14What is gVisor? · gVisor