Dream Code Factory logo

Software with a home.

We build and run your EU-sovereign cloud platform.

For European companies that want their software — and their customers' data — out of foreign legal reach. We design, build, and operate your platform on EU soil, and hand you the keys: everything declared in git, in repositories you own.

The problem

An EU region is not sovereignty.

Jurisdiction follows the vendor

A US-parented cloud is legally reachable wherever the servers stand. An “EU region” changes the latency, not the law.

Convenience is the lock-in

The managed services that make deploys magical are the ones you can't take with you. Every proprietary primitive is an exit fee you haven't priced yet.

DIY costs your roadmap

Building a real platform yourself — networking, TLS, secrets, backups, upgrades — costs months of engineering you meant to spend on product.

“The moat is jurisdictional sovereignty, not merely ‘servers in the EU’.”

The offer

We build it. We run it. You own it.

One engagement, one outcome: a production platform under your jurisdiction and your git history — with us operating it, and nothing standing between you and taking it over.

An EU cluster, built

Kubernetes on immutable Talos Linux at Hetzner in Germany — provisioned end to end with OpenTofu, fronted by Traefik, secured with Let's Encrypt.

Code you own

Every layer declared in git, in repositories you control — infrastructure, configuration, workloads. Nothing clicked, nothing undocumented.

GitOps delivery

Argo CD reconciles the cluster to the repository. Deploys are merges, rollbacks are reverts — no kubectl from a laptop, ever.

Secrets, self-hosted

An OpenBao vault wired in with External Secrets. Credentials live on your platform, not in someone else's cloud.

Postgres with tested restores

CloudNativePG with backups to EU object storage — and restore drills that actually ran, not backups taken on faith.

Backups for the platform itself

Velero protects the cluster's state and volumes, to EU object storage.

Single sign-on

Keycloak with the realm declared as code — one login for the tools your team runs.

Run, watched, upgraded

We operate it day to day: upgrades, patches, and observability with Prometheus, Loki, and OpenTelemetry.

Time

Start from a platform that already runs — not from a hiring plan for a platform team.

Effort

You ship product. We run the substrate — upgrades, certificates, backups included.

Likelihood

Nothing here is speculative: the pattern we sell is the one serving this very page.

The proof

A platform, not a promise.

Everything we sell, we already run. This site is served by a Kubernetes cluster in Falkenstein, Germany — immutable Talos Linux nodes, provisioned by OpenTofu, delivered by Argo CD, fronted by Traefik, secured with Let's Encrypt. If it isn't in the repository, it isn't running.

The pipeline has no hands in it: a change lands as a reviewed commit, CI builds one multi-arch image, and Argo CD reconciles the cluster to match git. No kubectl from a laptop, ever.

  • Talos Linux

    Immutable, API-driven OS

  • Kubernetes

    The substrate

  • OpenTofu

    Infrastructure as code

  • Argo CD

    GitOps delivery

  • Traefik v3

    Gateway API edge

  • cert-manager

    Let's Encrypt TLS

  • Hetzner FSN1

    EU data centre

  • .eu

    EU-jurisdiction domain

The guarantee

The exit is part of the deal.

The honest guarantee isn't a badge — it's architecture. Your platform is declared in git, in repositories you own, on open standards: Kubernetes, the Gateway API, OCI images, ACME certificates, plain Postgres. If we ever stop being the right partner, leaving is a git clone, not a negotiation.

A deliberate seam separates the platform from its workloads: the substrate can be swapped — another EU provider, another Kubernetes — with no workload rewrite. We published the whole contract: what keeps a platform portable.

European by design

Aligned with Europe's cloud ambition.

With IPCEI-CIS, the EU has articulated where European cloud should go: an open, interoperable, sovereign cloud-edge continuum. Every platform we build points the same direction — EU throughout, minimal data collection, open standards over proprietary convenience.

Cloud-edge continuum

One declarative model from data centre to edge. The whole platform is text in git — it can be reproduced anywhere Kubernetes runs.

Jurisdictional sovereignty

EU data centre, EU DNS, .eu registry. Not a compliance checkbox — a design constraint applied to every dependency we take.

Interoperability

Open standards end to end: Kubernetes, the Gateway API, OCI images, ACME certificates. No proprietary primitives, no lock-in.

Openness

Built in the open, documented as it happens. Decisions are recorded, trade-offs are named, and the blog shows the work.

Dream Code Factory is an independent company. Alignment with IPCEI-CIS objectives is a design choice, not an affiliation, participation, or funding claim.

From the blog

The work, shown.

We build in public. Every post documents work that shipped — every command actually ran.

Read the blog

Start here

Tell us what you run.

One email: what you're running today, and where you want it to live. A person reads it, a person replies. No forms, no tracking, no follow-up sequence — this site doesn't even collect data, and neither should your platform.