International Telecommunication Union (ITU) is United Nations specialized agency for digital technologies. Together with dNation and Vanilla Core they built Sovereign Cloud hosting GovStack application (public sector digitalization software) for multiple tenants.
Architecture

Requirements
ITU was looking for a solution matching following requirements:
- No Vendor Lock-in
- Infrastructure as a Service (IaaS) and Kubernetes as a Service (KaaS)
- Strong isolation of environments (tenants)
- GovStack Application
- Ability to run AI workloads
Addressing Requirements: No Vendor Lock-in, IaaS, Strong Isolation
To address no vendor lock-in, IaaS and strong isolation requirements, OpenStack by OpenInfra has been chosen as the cornerstone of whole solution.
OpenStack provides:
- True sovereignty without any vendor lock-in, all sourced code is available under Apache 2.0 license
- IaaS
- Ability to transparently handle hardware and network failures
- Isolation between workloads, including network traffic
Yaook distribution of OpenStack has been used for seamless installation and operations. Yaook has been developed by ALASCA (Association for Operational, Open Cloud Infrastructures e.V.) non-profit consortium.
Sovereign Cloud Stack (SCS) non-profit is a European initiative that creates an open, transparent and vendor-neutral cloud ecosystem. Part of its activities covered by Forum SCS-Standards are to define, document and develop standards and certifications to ensure expected level of quality of sovereign clusters. Yaook is the SCS certified solution.
Yaook runs OpenStack containerized within Kubernetes running on bare metal nodes:

Yaook’s architecture allows:
- Automatically transfer a set of bare metal machines to an operational OpenStack cluster
- Release management – all OpenStack components are tested together and then atomically released as a single package using standard Kubernetes deploy mechanisms
ALASCA Arko is a standardized platform for efficient monitoring of hybrid cloud infrastructures. We are using it for constant cluster monitoring, alerting and supporting Day 2 operations.
Arko follows these design principles:
- Intuitive: Green, orange and red colors signaling whether your action is needed
- Relevant information only: Provides only metrics relevant for area of interest
- Hierarchical (drill-down): Details needed? Just click on it.

Addressing Requirements: KaaS
VanillaStack has been used to meet KaaS requirement. It follows these basic principles:

Addressing Requirements: GovStack
GovStack is a toolkit for the digitalization of public sector infrastructure so everyone can access government services using trusted digital technologies that fit their lives and needs.
Deployed Sovereign Cluster hosts multiple tenants, each of them running their own instance of GovStack, utilizing OpenStack’s built-in separation capabilities.

Addressing Requirements: AI workloads
Deployed Sovereign Cluster contains nodes with GPUs as well. To run AI workload with full performance, VMs have direct access to GPU (via PCI Passthrough).
If you have any questions
Do not hesitate to contact us:
- For Infrastructure related questions: Martin Pilka <[email protected]>
- For GovStack related questions: Karsten Samaschke <[email protected]>
- ALASCA/SCS Sovereign Cloud for International Telecommunication Union (ITU) - August 12, 2026
- The KInIT Case Study: Sovereign AI Cloud - April 16, 2026