One platform,from metal to tokens

PaletteAI is how enterprises, neo cloud and sovereign cloud providers, and regulated industries teams design, deploy, and manage  VMs, Kubernetes, and AI workloads at scale — across clouds, data centers, and the edge.

PaletteAI logo

Your whole estate, centrally managed

Platform and infrastructure teams are now faced with the complexity of managing Kubernetes across clouds and in a data center, continuing to run VMs, and maintaining GPU nodes that cost more than the rest of the estate combined.

PaletteAI puts all of it under one central management plane. Describe what an environment should look like — OS, Kubernetes, networking, storage, applications, AI stack — as a declarative profile. PaletteAI builds it, keeps it that way, and repeats it identically, whether you run ten clusters or thousands.

One control point for clusters, infrastructure, and the workloads on top - wherever they run.

The full lifecycle, from design to operations

Four stages, one loop — and all of it native to the platform.

Declarative blueprint stacks

Cluster Profiles are versioned blueprints for everything in a cluster: OS, Kubernetes distribution, networking, storage, add-ons, applications. Profile Bundles package complete AI stacks the same way — infrastructure plus applications like Run:ai and ClearML, ready to deploy repeatably. Start from the curated catalog in PaletteAI Studio, tune it, or bring your own.

Versioned, reusable profiles for infrastructure and applications
A curated catalog, plus bring-your-own packs for anything we haven't met yet
Variables and per-environment overrides, so one profile serves many sites

Define once, deploy anywhere

Point a profile at a target and go: public cloud, managed Kubernetes, VMware, bare metal, or edge devices in the field. Create new clusters or bring existing ones under management. PaletteAI discovers hardware — including GPUs — provisions the full stack, and gives your teams self-service within the guardrails you set.

New clusters, or existing ones brought under management
Full-stack provisioning, from OS to application
GPU discovery, pooling, and allocation for AI workloads

Make day 2 boring

The real work starts after deployment. Edit a profile and every cluster running it flags the change; approve it, and the rollout happens in parallel with zero-downtime upgrades. Backup and restore, OS patching, health alerts pushed to Slack or ServiceNow, and self-healing are built in. GE HealthCare patched 100 clusters this way.

Zero-downtime rolling upgrades, executed in parallel across fleets
Scheduled backups, OS patching, and certificate rotation
Health and usage monitoring across every cluster

Freedom for teams, control for you

Multitenancy is native. Tenants and projects isolate teams; quotas cap what each can consume, including GPUs; granular RBAC controls who touches what, down to individual profiles. Scheduled scans validate clusters against CIS benchmarks, run penetration and conformance tests, and generate SBOMs your auditors can use.

Tenant and project isolation with granular RBAC
Resource and GPU quotas, with cost insights for chargeback
CIS benchmark, penetration, conformance, and SBOM scans on a schedule

Runs where your infrastructure lives

Public cloud, native or managed Kubernetes. Data centers on VMware or bare metal. Edge sites on hardware as small as a single node, in places with no reliable network and nobody on site holding a kubeconfig. PaletteAI treats heterogeneity as normal: mixed distributions, mixed operating systems, mixed hardware generations, NVIDIA GPUs and DPUs — one console for the lot.

Environments

awsEKS
AWS and EKS
AzureAKS
Azure and AKS
Gogole Cloud
Google Cloud
CloudStack
CloudStack
VMware
VMware
vSphere
Nutanix
Nutanix
Bare MetalCanonical
Bare metal and
Canonical MAAS
Edge
Edge devices
OpenshiftRancherTanzu
Existing clusters —
OpenShift, Rancher, Tanzu and more

Stack choices

PXK
PXK
RKE2
RKE2
K3s
K3s
Ubuntu
Ubuntu
openSUSE
openSUSE
PXK
PXK
RKE2
RKE2
Rocky Linux
Rocky Linux
K3s
K3s
Ubuntu
Ubuntu
openSUSE
openSUSE
RHEL
RHEL
Hadron
Hadron
... and more
PXK
PXK
RKE2
RKE2
K3s
K3s
Ubuntu
Ubuntu
openSUSE
openSUSE
Explore integrations and environments

From one cluster to thousands, with no slowdown

Most platforms funnel every decision through a central brain. Fine at 20 clusters; painful at 200; a liability at 2,000. PaletteAI's architecture is decentralized: management intelligence runs inside each cluster, so policy is enforced locally and upgrades roll out in parallel, over the air.

Lose the link and clusters carry on — enforcing policy, healing failures, running workloads — then resync when the connection returns. It's what makes air-gapped estates and thousand-site edge fleets manageable by a team that also has other jobs to do.

Local policy enforcement in every cluster
Parallel over-the-air upgrades
Full autonomy when disconnected or air-gapped
From one cluster to thousands
How the decentralized architecture works

Hub and spoke

Every decision waits on the hub

PaletteAI: decentralized

Each cluster carries its own agents and policy

Open source at the core, your choices on top

PaletteAI is built on projects your engineers already know — Cluster API, Kairos, KubeVirt, Velero, Prometheus — and stays close to upstream Kubernetes. The catalog is curated, and it's optional: bring your own packs, pin your own versions, drive everything through the API, Terraform, or GitOps. And if you ever walk away, your clusters are still conformant Kubernetes. We'd rather keep you by being good.

A management plan that fits how you operate

Some teams want the management plane run for them. Others need it inside their own four walls, under their own controls — sometimes with no route to the public internet at all. PaletteAI offers a range of deployment and management options to suit, from distributed enterprise fleets to sovereign, air-gapped platforms. Where your control plane lives should be your call.

Compare deployment options
Enterprise fleets
Sovereign and regulated platforms
Disconnected and air-gapped sites

Security from silicon to token factory

Every layer carries its own protection: immutable OS options and secure boot at the edge, zero-trust identity and access through the platform, SBOM scans that keep your software supply chain auditable — from a company operating under ISO 27001:2022 and SOC 2 Type 2. And when compliance is the mission, PaletteAI VerteX adds FIPS 140-3 validated cryptography at every layer: the same platform, hardened for government, defense, and regulated industries.

Enterprise software that behaves like it

A NOC-style console that shows every cluster by location and health. An API that covers everything the UI can do. SLAs, 24x7 support, and services people who've done the migration you're dreading. None of it is glamorous. All of it decides whether year two feels like year one.

Services and support
“Spectro Cloud's innovation focus has paid off, with major customer account wins over incumbents like Red Hat and SUSE.”
The Forrester Wave™: Multicloud
Container Platforms, 2025

See it on your infrastructure

The quickest way to judge PaletteAI is to watch it build your stack in your environment. Book a 1:1 demo with one of our experts.