Skip to main content

S1 — Turnkey Managed

Openbox team provisions everything (VPC, EKS, RDS, S3, IAM, TLS, DNS, Helm install) in your AWS account and owns day-2 operations. You focus on using the platform.

When to pick S1

  • No DevOps team in-house, or DevOps team already at capacity
  • Want a hard SLA on uptime and response times
  • Compliance program requires clear ownership of infra ops (Openbox holds the pager)
  • Willing to grant Openbox a scoped cross-account IAM role

When NOT to pick S1

  • Strong preference for infra sovereignty → see S2 Fresh AWS
  • Already run mature Kubernetes clusters you want to reuse → see S3 BYOC
  • Air-gapped requirement — S1 cannot service disconnected networks

Handoff model

What Openbox owns

  • Infrastructure provisioning + upgrades (K8s, RDS, ES, etc.)
  • Helm chart upgrades (aligned with Openbox release cadence)
  • Certificate rotation, secret rotation
  • Backup + DR drills
  • Incident response per SLA tier
  • Vulnerability patching

What you own

  • AWS account bill (you pay AWS directly, Openbox has no billing relationship with AWS on your behalf)
  • Application-level configuration (Keycloak realms, OPA policies, guardrail thresholds)
  • Data classification + retention policy
  • User management (via Keycloak)
  1. Prerequisites: cross-account IAM role → — the IAM trust policy Openbox needs
  2. Handoff & SLA → — deliverables, response tiers, escalation