The layers im Detail.
Eight layers, one principle: on the outside you keep control, on the inside we take over everything. Every layer contains all outer layers — always dedicated, in Germany as the standard, on request (multiple regions) also at other locations worldwide. Available for every layer: redundant off-site backups at a second location.
Full Proxmox Cluster — or shared
The outermost layer: your own Proxmox cluster. Proxmox VE is the open-source virtualization platform your virtual machines run on — cluster-capable, with live migration and high availability. You get it on your own dedicated hardware or as a partitioned part of a shared cluster, with CephFS (shared, synchronous across all nodes) or isolated storage per node, in NVMe, SSD or HDD.
Managed VMs in the cluster
You don't need a whole cluster — just reliable virtual machines. On this layer we operate your VMs as part of our Proxmox cluster: dedicated CPU cores and dedicated RAM per VM, no overcommit, no noisy neighbors. The infrastructure below (layer 01) is included and our concern.
Managed OPNsense firewall cluster
On this layer HOST SMITH takes over your network perimeter: a managed OPNsense firewall cluster in front of your VMs and clusters. OPNsense is the open-source firewall for rules, NAT, VPN and intrusion detection — with us always redundant: two instances in a cluster, connected via CARP IPs. If one firewall fails, the second takes over in a split second, without connections dropping.
Managed Edge — HAProxy & Caddy
The edge of your network, professionally operated: HAProxy distributes traffic to your applications as a load balancer in multiple instances, a Caddy cluster terminates TLS and obtains certificates fully automatically. The ACME certificate store lives in a Redis backing — distributed, so every Caddy instance knows all certificates at all times and renewals never collide.
Docker Swarm / Kubernetes
Your applications run in containers? On this layer we operate the orchestration cluster for them: Docker Swarm for pragmatic setups, Kubernetes for complex platforms. The cluster distributes your services automatically across multiple nodes, restarts them on failures and scales them as needed — on managed VMs with dedicated resources (layers 01–04 included).
Orchestration — e.g. Portainer
The container cluster is running (layer 05) — now your team needs an interface to work with it. We install and manage your orchestration software, for example Portainer — or an alternative like Rancher, Coolify or CapRover: the web interface developers use to deploy, scale, read logs and manage environments without a command line. We'll find out together which interface fits your team.
Managed Portainer
The layer for teams that want to focus exclusively on their application: you work only in Portainer. No access to VMs, none to Swarm or Kubernetes nodes — the entire infrastructure below (layers 01–06) is fully our responsibility. What you see is your deploy interface; what you don't see simply works.
Managed Services
The innermost layer: you only use the finished service. PostgreSQL, MariaDB, Redis, RabbitMQ, Elasticsearch, ClickHouse — plus active-active clusters with YugabyteDB (PostgreSQL-compatible) and Galera (MariaDB-compatible), Varnish as HTTP cache, managed prerender with backing storage and S3-compatible object storage. Every service fully managed, every one on dedicated resources.