Sovereign cloud is moving from a niche topic to a practical procurement and delivery question for many European organisations, particularly in regulated sectors and government. Concerns about data residency, regulatory compliance, supply chain risk, the ability to control access and rising geopolitical risk are driving IT leaders to treat sovereignty as a core requirement rather than an optional feature. Recent moves on export controls and cross-border technology restrictions mean organisations increasingly factor the risk of sudden policy changes into their sourcing and resilience plans. That reality raises a set of everyday questions for CIOs and practitioners: what do sovereign-cloud providers actually offer today, which workloads are good candidates for migration, what changes are needed in architecture and operations, and how does total cost compare with mainstream hyperscalers.
To answer those questions we ran a hands-on hackathon with StackIT, a German sovereign-cloud provider and a Deloitte alliance partner (Link). StackIT was founded in 2018 and became commercially available in 2022. It provides a portfolio of managed services and holds key certifications such as ISO27001 (link). The provider has already drawn attention in the Netherlands after the Rijksoverheid has signed a framework deal, which makes StackIT a practical option for other Dutch government bodies. For organisations outside government the appeal is similar: a way to meet strict data-privacy and regulatory requirements while retaining cloud-style agility and reducing exposure to geopolitical shocks.
We organised the hackathon with two concrete aims. First, to respond to genuine customer demand: many Dutch organisations now treat sovereignty as a hard requirement and ask us to assess the operational impact of moving critical workloads and to support migrations that exclude some large US-based clouds for compliance reasons. Second, to broaden practical capability inside our teams: knowledge about how to design, deploy and operate sovereign-cloud solutions often resides with a small set of engineers who gained it through hands-on projects. The event let multidisciplinary teams validate technical feasibility, exercise deployment and migration patterns, test integration with existing CI/CD and security tooling, and surface operational and commercial gaps before we scale support to early adopters.
What we tested: More than 20 participants split into six teams, each tackling a specific challenge:
- Compute: deploy an application on virtual machines (VM’s) and test networking and IaaS features.
- Containers: deploy a containerised app using StackIT’s container options.
- Platform engineering: build configurations and pipelines to enable teams to host apps on a secure, usable platform.
- Data engineering: deploy a data platform implementing a Medallion architecture.
- LLMs and RAG: deploy an LLM based chatbot with retrieval augmented generation.
- Cybersecurity: exercise StackIT’s security and compliance services.
(We also prepared a serverless challenge, but StackIT currently has no serverless functions, so we didn’t run that challenge.)
On the final day each team demonstrated what they had built, assessed the provider’s services and described the obstacles they had encountered. All teams completed their challenges within the time limit, but the relative immaturity and user experience of several managed services created friction and extra operational work.
The negatives
-
Low managed service maturity: Several StackIT services felt early stage. The cybersecurity team found an audit-log API that returned pages of raw JSON with no search capability. The data team discovered managed Airflow and Jupyter offerings still in beta and behind a wait list. The compute team sometimes had to destroy and recreate virtual machines to change basic properties. These limitations slowed development and forced manual workarounds.
-
Fragmented interfaces and authentication: Several services redirected users to third party web consoles with independent authentication and authorization schemes. Multiple logins and inconsistent role definitions caused confusion and extra operational overhead, especially for teams integrating across services.
The positives
-
Open-source ecosystem: StackIT relies heavily on proven open-source tooling rather than proprietary locks. Examples included OpenTofu instead of CloudFormation, Grafana for monitoring, and Kubernetes as the platform for workloads. That approach made it straightforward to fill functional gaps by deploying established open-source projects on Kubernetes. Teams with Kubernetes experience found multiple viable workarounds.
-
Core capabilities present: The foundational governance, security and infrastructure features were sufficient for the hackathon scenarios. Network security and segmentation, Kubernetes controllers integrating seamlessly with StackIT services (e.g. persistence and networking). Despite obstacles, every team was able to implement and deploy a working solution.
To wrap-up
StackIT is a credible alternative to the US hyperscalers for organisations that place sovereignty at the top of their requirements. Migrating applications or platforms away from hyperscalers remains complex and difficult work, such projects will face challenges that we may not have surfaced in this 3-day hackathon. That said, the work we completed gives us reason to be confident that such migrations are technically feasible with the right planning and skills.
The hyperscalers benefit from massive scale, deep capital pools and extensive managed services. Sovereign-cloud providers like StackIT do not yet match that scale or breadth. Their pragmatic response is to lean heavily on open-source tooling and a standards-first approach, and to grow capability through customer adoption. That pathway can narrow the functional gap faster than rebuilding equivalent proprietary stacks from scratch.
If sovereignty, geopolitical exposure or compliance risk are important for your organisation, investing in sovereign-cloud pilots and partnerships is a sensible next step. Providers mature faster when customers provide real workloads, steady revenue and exacting service requirements.
If this resonates, get in touch. We can act as a sparring partner, run a tailored hackathon with your team, or help design and execute a road map to make your stack more (or fully) sovereign.