Your app online, on your cloud, in a few lines.
Describe your app or site in a single config file: Cubo2 deploys it to a shared, hybrid or private cluster — GCP, AWS or your own servers. From then on, you're in control from the console — deployments, performance, updates — with an AI assistant that automates, diagnoses and writes your reports. And our experts are one click away: infra, identity, design, custom development.
One file.
All the infra.
Describe your app or site in a few lines. Cubo2 provisions the infrastructure at the isolation level you choose — shared, hybrid or private, in your cloud account or on your own servers: cluster, managed database, secrets, domain, certificates, monitoring. No DevOps team, no weeks of set-up.
- 01ConfigureA
cubo2.yamlfile in your repo: runtime, database, secrets, domain, target and isolation level. - 02ProvisionThe platform generates and applies the infra as code — Kubernetes, managed database, secrets vault, DNS & TLS.
- 03DeployEvery push triggers a build, tests and a preview environment. Going to production is just a merge.
# cubo2.yaml — everything you need to go live app: atelier-web runtime: node20 build: npm run build cloud: provider: gcp # gcp | aws | onprem region: europe-west1 isolation: shared # shared → hybrid → private services: database: engine: postgres # → Cloud SQL · RDS · on-prem backups: daily secrets: backend: vault # → Vault · Secrets Manager keys: [STRIPE_KEY, SMTP_PASS] storage: bucket domain: atelier.be scale: { min: 1, max: 6 }
- ComputeGKE · Cloud Run
- DatabaseCloud SQL
- SecretsSecret Manager · Vault
- StorageCloud Storage
- ComputeEKS · ECS
- DatabaseRDS · Aurora
- SecretsSecrets Manager · Vault
- StorageS3
- ComputeKubernetes
- DatabasePostgreSQL · MySQL
- SecretsHashiCorp Vault
- StorageS3-compatible
Shared, hybrid
or private.
Every project picks its isolation level — and its price with it. Start on shared resources, move to dedicated when load or data sensitivity calls for it. Same config, same console.
Shared
Compute is pooled across projects. Your app runs on a shared cluster and your data in a common database, isolated row by row with Row-Level Security.
- ClusterPooled, per-project quotas
- DatabaseShared, RLS per tenant
- Ideal forMVPs, websites, moderate traffic
isolation: sharedHybrid
Your pods are dedicated to your app and your database is separate — on the same RDS or Cloud SQL instance. No more noisy neighbours, without the cost of a full infrastructure.
- ClusterPooled, dedicated pods per app
- DatabaseSeparate, same instance
- Ideal forScaling up, performance needs
isolation: hybridPrivate
A fully separate cluster, your own database instance, your own network and encryption keys — in your GCP or AWS account, or on your own servers.
- ClusterDedicated, isolated network
- DatabaseDedicated instance
- Ideal forSensitive data, compliance
isolation: privateNever back down.
Project growing? Change one line of config or click in the console: the platform provisions the new environment and moves your data across via logical replication, with zero downtime. The path runs one way only — data that once needed isolating never goes back to a more open environment.
Your projects.
Your hands.
Once you're live, everything runs from the Cubo2 console: deploy, manage your environments, track performance and apply updates — yourself, with no tickets and no middlemen. A built-in AI assistant helps you day to day — and when you want a human eye, a Cubo2 engineer is one click away.
Launch a new project, spin up preview environments, manage domains, variables and secrets, roll back in one click.
- Projects & environments
- Shared → private isolation
- Secrets & team access
Latency, errors, uptime, usage and cloud costs in real time — with alerts that reach you before your users do.
- Metrics & logs
- Email · Slack alerts
- Cost tracking
The console flags new runtime, database and dependency versions. Security patches ship automatically; everything else is tested in preview before production.
- Scheduled patches
- 1-click security check
- Backups before every update
Self-sufficient day to day, never on your own. Our engineers and designers step in on demand — for a question, a migration or a whole project.
- On-demand expert session
- Architecture review
- Monthly support
Always up to date.
Checked in one click.
We maintain the services your projects run on: versions tracked, security patches applied, compatibility tested before every upgrade. And whenever you want, a full security check runs in one click from the console.
- Kubernetes & runtimesSupported versions, upgrades tested first, then rolled out.Maintained
- Managed databasesMinor patches applied automatically, majors scheduled with a backup.Maintained
- Vault & secrets managementUpdates, secret rotation, access policies reviewed.Maintained
- Base images & certificatesImages rebuilt on every patch, TLS certificates renewed.Automatic
- TLS certificatesValid · 74 d
- Secrets exposed in codeNone
- Vulnerable dependencies2 to fixFix
- Container images scanned0 critical
- Network & exposed portsCompliant
- Access & rolesReviewed
- Backups & restoreTested yesterday
PDF report ↓
Just ask.
The platform does it.
An AI chat is built into the console. It knows your projects, your metrics and your configuration — and draws on a knowledge base built by our experts: ask it a question, request a report, describe an automation in plain English. It suggests the action, you approve it.
- “Apply patches on Sundays at 3 a.m.”
- “Scale out if latency tops 300 ms”
- “One preview per pull request”
- “Rotate secrets every 90 days”
- “Slack alert if cost goes over €100”
- “Why is my app slow?”
- “Explain this 502 error”
- “How do I add a domain?”
- “Should I go hybrid?”
- “This month's perf report, as a PDF”
Its intelligence
is our expertise.
An AI assistant is only as good as what it's given to read. We build the context and knowledge base behind the Cubo2 assistant: platform documentation, our incident procedures, our best practices for each technology.
Our engineers keep enriching it with the problems they actually run into and solve. The result: precise answers grounded in your infrastructure, not generic advice.
For those who'd rather
ship than wire.
You have an app, a site or a product to launch — and no desire to spend weeks on Terraform, IAM and certificates. You stay in control of your cloud and your data; we take care of the plumbing.
Infra
& studio
Three infrastructure building blocks from the platform, two crafts from the studio. Take what you need — everything is designed to work together.
- GCP · AWS · on-premise
- Shared · hybrid · private cluster
- CI/CD & previews
- One-click rollback
- Managed DBs RDS · Cloud SQL
- Vault & Secrets Manager
- Object storage S3 · GCS
- Encrypted backups
- Automatic TLS & DNS
- 1-click security check
- Logs · metrics · AI reports
- Auditable infra as code
- Branding & guidelines
- Art direction
- UX/UI design
- Design system
- Websites & e-commerce
- Apps & SaaS
- APIs & integrations
- Applied AI
Cube,
squared.
Cubo² is two blocks that lock together. The first is the platform: ready-to-use infrastructure to put any app online. The second is the studio: the identity, design and development that make that app worth putting online.
Infrastructure on one side, craft on the other.
One point of contact.
- Vendor lock-in and infrastructure you can't take back
- Plain-text secrets sitting in a .env file
- Weeks of set-up before the first release
- Opaque cloud bills
- Needlessly complicated technical solutions
- Visual effects that serve no purpose
- Your data, your level of isolation
- Infrastructure as code, versioned and auditable
- Security by default, not as an add-on
- Design as a strategic tool
- Every decision explained and justified
- Trust earned through transparency and results
to choose Cubo2
Take the infra.
Add the studio.
Three ways to work with Cubo2: the platform alone, the platform with the studio, or custom infrastructure on your premises.
Platform
Your repo, one config file, a shared or hybrid cluster — or a private one in your GCP or AWS account. You deploy, manage, monitor and update your projects from the console, AI assistant included; we maintain the platform. Expert sessions on demand.
Deploy my project→Platform + studio
Identity, UX/UI and custom development — delivered straight onto the platform. One point of contact, from logo to TLS certificate.
Talk to a founder→On-premise & custom
A private cluster in your cloud, or the platform installed on your own Kubernetes, wired to your Vault and your directory. Migration, compliance, SSO, and a dedicated team.
Talk to a founder→An app in production is never finished.
Security updates, scaling, cloud costs, new features, brand evolution: we stay by your side for the long run — on the infra side and the product side.
From config
to production.
Four steps, always the same — whether you deploy alone or with the studio.
Configure
You describe your app in a few lines: runtime, database, secrets, domain, cloud target. We help you write the first file.
Provision
The platform builds the infra at the isolation level you chose: namespace or dedicated cluster, managed database, secrets vault, DNS and certificates.
Deploy
Every push triggers build, tests and preview. Going to production is a merge — and a rollback, one click.
Operate
You track performance, alerts and updates from the console; the AI assistant automates the rest. Our experts stay on hand — and the studio takes over when you need to go further.
Before you
get in touch.
Google Cloud, AWS, and on-premise on your own Kubernetes. The same configuration runs on all three: switching targets means changing one line.
Start on shared: it's the most affordable, and your data is isolated with Row-Level Security. Move to hybrid when your app needs more performance (dedicated pods, a separate database). Go private from day one if you handle sensitive data or have compliance requirements. Switching happens with zero downtime, always towards more isolation — never the other way round.
It depends on the model. On shared and hybrid, on infrastructure managed by Cubo2, in the region of your choice. On private, on a dedicated cluster — in your own GCP or AWS account, or on your own servers.
Two things. Automate: describe a rule in plain English (“apply patches on Sundays”, “alert me if costs go over €100”) and it builds it. Understand: it answers your questions about the platform, analyses incidents from your metrics and logs, and generates performance reports ready to share. Its relevance comes from its context: a knowledge base built and continuously enriched by our engineers (documentation, incident runbooks, best practices), cross-referenced with your project's data. It always proposes before it acts: nothing goes to production without your sign-off.
Secrets live in HashiCorp Vault, AWS Secrets Manager or GCP Secret Manager and are injected at runtime — never in plain text in the code. Databases are managed services (RDS, Cloud SQL) or your own on-premise PostgreSQL, with encrypted backups.
Your data and configuration can be exported at any time. On private, the infrastructure is described as versioned code (Terraform, Kubernetes manifests) and runs in your own accounts: nothing to migrate, no lock-in.
No. You deploy, track performance and apply updates yourself from the console. For the trickier cases — migration, private networking, compliance, traffic spikes — a Cubo2 expert steps in on demand.
You do, with the platform backing you up. Security patches are applied automatically in a window you choose; version upgrades (runtime, database, dependencies) are flagged in the console and tested in preview before production, with a backup taken first. On the platform side, we keep the services up to date (Kubernetes, managed databases, Vault, images, certificates). And a full security check runs in one click from the console. If you'd rather hand off the rest, our experts will take care of it.
The platform runs on a subscription, priced by isolation model: shared is the most economical because resources are pooled. On private, your cloud resources are billed directly by your provider, with no hidden margin. For the studio, we give you a clear price range from the very first conversation: no mystery quotes.
Another question? Write to us
Let's get acquainted.
To get things started, let's begin with you.