Roadmap Cloud Platform

Our Roadmap for the Thlassa Cloud Platform.

Below is an snapshot of the Thalassa Cloud roadmap, grouped by timeline with the current development status.

Status Key

StatusDescription
completedDevelopment completed and shipped
in progressActively being worked on
designIn design or PoC phase
plannedPlanned for implementation
gathering inputWe’re gathering feedback and shaping the scope

CategoryFeatureDescriptionStatus
IaaSCore InfrastructureVPCs, NAT Gateways, Load Balancers, VMs, and Block Storagecompleted
IaaSHA NAT gatewaysHighly Available NAT gateway across multi-zones supportcompleted
IaCTerraform ProviderTerraform provider for managing Thalassa Cloud resourcescompleted
CLItcloud CLICommand-line tool for interacting with Thalassa Cloudcompleted
KubernetesManaged KubernetesHigh-quality Kubernetes service built for productioncompleted
FinOpsCost ExplorerResource usage tracking and initial cost breakdowncompleted
NetworkingVPC FirewallSubnet- and VPC-level firewall configurationcompleted
Kuberneteskubernetes v1.33Support Kubernetes v1.33completed
NetworkingInternal DNS resolversNew HA Internal DNS resolvers for upstream resolutioncompleted
SecurityAudit LoggingPlatform-wide audit loggingcompleted
KubernetesRBAC with IAMIntegrated RBAC tied to IAM users and rolescompleted
BillingInvoice GenerationExportable monthly billing statementscompleted
BillingPayment Processor IntegrationsStripe, Mollie and otherscompleted
KubernetesCloud Controller ManagerIntegrated cloud controller manager for Kubernetescompleted
KubernetesCSI ControllerContainer Storage Interface controller for Kubernetescompleted
IAMSystem Service AccountsSupport for system service accountscompleted
KubernetesKubernetes DashboardWeb-based Kubernetes user interfacecompleted
KubernetesKubernetes Cluster RBACRole-Based Access Control for Kubernetes clusterscompleted
IaaSOrganisation Resource QuotasResource quotas at the organization levelcompleted
NetworkingLoadbalancers: UDP SupportSupport for UDP traffic in load balancerscompleted

Near-Term (Q2 2025)

These items are scheduled to be completed within the near future.

CategoryFeatureDescriptionStatus
OperationsPublic CloudEnabling open access to Thalassa Managed Public Cloud, allowing full self-service sign-up.in progress
DatabasesManaged PostgreSQLIntroducing our first managed database service with PostgreSQL.in progress
NetworkingSecurity GroupsImplementing assignable security groups for cloud services (IaaS, Kubernetes, etc).in progress
IaaSObject StorageS3-compatible storage service for unstructured data.in progress
IaaSSnapshots & BackupsProviding volume snapshots and back-up services.in progress
NetworkingIPv6 & Dual StackDual-stack (IPv4/IPv6) and IPv6 only networking support for all services.in progress
KubernetesAuto Scaling CapabilitiesKubernetes with node pool autoscaling and update strategies.design
PlatformQuick Launch TemplatesCreating one-click deployment templates for common workloads.design
SecurityAutomated Ingress BlocklistsDeveloping IP blocklists via threat intelligence feeds to automatically protect against malicious traffic.design
SecurityOIDC Based API CredentialsImplementing OIDC (OpenID Connect) based API credentials as a replacement for Personal Access Tokens.design

Mid-Term (Q3 2025 – Q1 2026)

CategoryFeatureDescriptionStatus
ComplianceISO27001Achieve ISO 27001 certification for ISMplanned
ComplianceSOC2Obtain SOC2planned
KubernetesAutomated Cluster UpgradesAuto-upgrades for Kubernetes clustersplanned
NetworkingVPC PeeringInternal connectivity between VPCsplanned
NetworkingVPC BastionBastion Service to allow SSH access to Virtual Machines within an VPCplanned
NetworkingReserved IP AddressesReserve and assign specific IP addresses to network services such as LBs and NAT Gatewaysplanned
KubernetesContainer RegistryProvide fully integrated Container Registry for storing OCI artifactsplanned
IaaSCustom Machine ImagesCustom image support for organization-level controlplanned
IAMSystem AccountsSupport for service accounts and automation rolesplanned
ProjectsAllow logical seperation within an organisation using projectsResource isolation within organizationsplanned
SecurityWeb Application Firewall (WAF)Layer 7 protection for appsplanned
NetworkingL7 Load BalancingHTTPS, TLS, and gRPC supportplanned
NetworkingSite-to-Site VPN EndpointsManaged IPSec connectivityplanned
ObservabilityManaged PrometheusLong-term metric storageplanned
ObservabilityLogging AccessCentralized access to platform logsplanned
PaaSInitial RolloutGitOps-ready deployment platformplanned
FinOpsCost Explorer 2.0Labels, filters, and report schedulingplanned
ComplianceAudit & Compliance CenterVisual dashboard for audit dataplanned
PaaSManaged SecretsSecure secret store for appsplanned
FinOpsBudget Limits & AlertsOrg-level cost controls and alertsplanned
NetworkingCustom DNS ZonesManage private DNS zonesgathering input
ServicesManaged KafkaPotential managed Kafka based on demandgathering input
ServicesManaged RabbitMQ / NATSMessaging services as managed offeringsgathering input
SecurityCustomer Managed Encryption KeysBYOK encryption for sensitive datagathering input
DatabasesManaged ValkeyManaged Valkey (Redis fork)gathering input
PolicyCentralized Policy Engine (OPA)Org-wide policy enforcementgathering input
PolicyChange Approval WorkflowsRequire approval for sensitive operationsgathering input

Long-Term (2026 and Beyond)

CategoryFeatureDescriptionStatus
PaaSServerless CapabilitiesDeploy apps without managing infragathering input
PaaSMulti-Cluster Service MeshUnified networking across clusters and regionsplanned
EcosystemAdd-On MarketplaceDeploy certified third-party apps and integrationsgathering input