S1 — Turnkey Managed
Openbox team provisions everything (VPC, EKS, RDS, S3, IAM, TLS, DNS, Helm install) in your AWS account and owns day-2 operations. You focus on using the platform.
When to pick S1
- No DevOps team in-house, or DevOps team already at capacity
- Want a hard SLA on uptime and response times
- Compliance program requires clear ownership of infra ops (Openbox holds the pager)
- Willing to grant Openbox a scoped cross-account IAM role
When NOT to pick S1
- Strong preference for infra sovereignty → see S2 Fresh AWS
- Already run mature Kubernetes clusters you want to reuse → see S3 BYOC
- Air-gapped requirement — S1 cannot service disconnected networks
Handoff model
What Openbox owns
- Infrastructure provisioning + upgrades (K8s, RDS, ES, etc.)
- Helm chart upgrades (aligned with Openbox release cadence)
- Certificate rotation, secret rotation
- Backup + DR drills
- Incident response per SLA tier
- Vulnerability patching
What you own
- AWS account bill (you pay AWS directly, Openbox has no billing relationship with AWS on your behalf)
- Application-level configuration (Keycloak realms, OPA policies, guardrail thresholds)
- Data classification + retention policy
- User management (via Keycloak)
Read next
- Prerequisites: cross-account IAM role → — the IAM trust policy Openbox needs
- Handoff & SLA → — deliverables, response tiers, escalation