Cloudspaces

Fully isolated virtual environments where you deploy and manage virtual machines, vGPUs, networking, load balancers, reverse proxies, backups, DNS, SSL certificates, vTPM, secure boot and storage

Flexible virtual machines and networking

Cloudspaces

In short: A cloudspace is a fully isolated virtual environment where you deploy and manage virtual machines, networking, storage, and security. Each cloudspace is a customer-owned layer 2 network with a virtual firewall, supporting VMs, vGPUs, load balancers, backups, and both software-defined and direct NVMe storage.

Cloudspaces are fully isolated virtual environments that provide complete control over your virtual infrastructure. Each cloudspace is a customer-owned layer 2 network with a virtual firewall, where you can deploy and manage virtual machines, vGPUs, networking, load balancers, reverse proxies, backups, DNS, SSL certificates, vTPM, secure boot, and storage. Designed for flexibility, cloudspaces support anti-affinity policies and let you attach both software-defined and direct NVMe storage — giving you the performance and control you need, out of the box.

Cloudspace detail page with external IP, subnet and gateway, tabs for VMs, ingress, DNS, WireGuard VPNs and external networks, and one running VM
A cloudspace in Kampala with its network details and a running virtual machine.Shown: portal.dynagrid.tech, the white-label portal of Dynagrid, a VCO running on whitesky.

Key Features

  • Bound to a cloud location for optimal performance and compliance
  • Isolated layer 2 network ensuring complete security separation
  • Flexible firewall options to meet your specific networking needs

Firewall Options

Built-in Firewall Features

  • DHCP server for automatic IP assignment
  • Cloud init for automated VM configuration
  • DNAT port forwards to a single VM for external access
  • Advanced routing capabilities
  • VPN access to cloudspace for secure remote connectivity
  • Automated VPNs between cloudspaces (Connected Cloudspaces)

Custom Firewall Support

Any virtualized firewall deployed in a virtual machine can act as the firewall for a cloudspace, giving you complete flexibility in your security architecture.

Network Connectivity

  • Support for 0 or more external networks (internet, customer network, etc.)
  • Granular control over network access and routing
A cloudspace: isolated network behind its own firewallA cloudspace in a cloud location is an isolated layer 2 network with virtual machines behind a virtual firewall that provides DHCP, port forwards, routing and VPN access. The VMs are not reachable from outside by default. The firewall connects to zero or more external networks, such as the internet or a customer network, and an automated VPN connects it to another cloudspace. Any virtual firewall running in a VM can take the firewall role.Cloud locationCloudspace Aisolated layer 2 networkVMVMVMnot reachable from outside by defaultVirtualfirewallDHCPport forwardsroutingVPN accessExternal networks0 or moreInternetCustomer networkautomated VPNCloudspace Bconnected cloudspaceOr use any virtual firewall running in a VM
A cloudspace: isolated network behind its own firewallA cloudspace in a cloud location is an isolated layer 2 network with virtual machines behind a virtual firewall that provides DHCP, port forwards, routing and VPN access. The VMs are not reachable from outside by default. The firewall connects to zero or more external networks, such as the internet or a customer network, and an automated VPN connects it to another cloudspace. Any virtual firewall running in a VM can take the firewall role.External networks, 0 or moreInternetCustomer networkVirtual firewallDHCP, port forwards, routing, VPNCloudspace Aisolated layer 2 networkVMVMVMnot reachable from outside by defaultautomated VPNCloudspace Bconnected cloudspaceOr use any virtual firewallrunning in a VM
A cloudspace is an isolated layer 2 network behind its own virtual firewall; VMs are not reachable from outside unless you open a path.

Ingress and Load Balancing

Server Pools

Organize your services with intelligent server pool management.

Advanced Load Balancing

The virtual firewall of every cloudspace includes a built-in Traefik that distributes traffic over a server pool:

  • Layer 7 Load Balancing (HTTP/HTTPS):
    • Reverse proxies with SSL offloading
    • Let’s Encrypt support for automatic SSL certificate management
  • Layer 4 Load Balancing (TCP/UDP):
    • TCP load balancers with SSL offloading or pass-through
    • UDP load balancers for specialized applications

For direct access to a single machine, a DNAT port forward sends a TCP or UDP port straight to one specific virtual machine.

Ingress: load balancing and port forwardingClient traffic reaches a cloudspace through its virtual firewall. The built-in Traefik handles layer 7 reverse proxying with SSL offloading and Let's Encrypt certificates, and layer 4 TCP and UDP forwarding, where TCP supports SSL offloading or pass-through; both distribute traffic over a server pool of virtual machines. A DNAT port forward instead sends a TCP or UDP port to one specific virtual machine.ClientsVirtual firewallBuilt-in TraefikLayer 7: reverse proxySSL offloadingLet's Encrypt certificatesLayer 4: TCP and UDPTCP: SSL offloadingor pass-throughDNAT port forwardTCP or UDP portto one specific VMServer poolone VMVMVMVM
Ingress: load balancing and port forwardingClient traffic reaches a cloudspace through its virtual firewall. The built-in Traefik handles layer 7 reverse proxying with SSL offloading and Let's Encrypt certificates, and layer 4 TCP and UDP forwarding, where TCP supports SSL offloading or pass-through; both distribute traffic over a server pool of virtual machines. A DNAT port forward instead sends a TCP or UDP port to one specific virtual machine.ClientsBuilt-in Traefikin the virtual firewallLayer 7: reverse proxySSL offloadingLet's Encrypt certificatesLayer 4: TCP and UDPTCP: SSL offloadingor pass-throughServer poolDNAT port forwardin the virtual firewallTCP or UDP port to one specific VMone VMVMVMVM
Two ways in through the virtual firewall: the built-in Traefik balances layer 7 (HTTP/HTTPS) and layer 4 (TCP/UDP) traffic over a server pool, while a DNAT port forward sends a TCP or UDP port to one specific VM.

Virtual Machines

Deployment Options

Virtual machines are bound to a cloudspace and can be created through multiple methods:

Creation Methods

  • Predefined images for quick deployment
  • Install from ISO image for custom installations
  • Clone from a snapshot for rapid scaling

Import Options

  • VMware, Veeam and Acronis recovery media and backup imports
  • whitesky backup system integration

Storage Solutions

Software Defined Storage

  • vDisks based on integrated whitesky software defined storage (not Ceph!)
  • Optional NVMe local cache for enhanced performance
  • Automated vDisk snapshots every hour with configurable retention
  • Direct attached NVMe for high-demanding IO workloads
  • CD-ROM images for installation and maintenance
  • Integrated backup to S3 storage for data protection

Advanced Features

GPU Support

  • vGPU support with both virtualized and dedicated GPU options, where the cloud location offers GPUs (configured by the Cloud Enabler in Meneja)
  • Perfect for AI/ML workloads and graphics-intensive applications

Performance Optimization

  • CPU pinning for consistent performance
  • Custom CPU topologies for specialized workloads
  • Anti-affinity groups to ensure high availability

Networking Capabilities

  • Default cloudspace network interface (VMs never reachable from outside by default)
  • Extra interfaces to other cloudspaces for multi-tier architectures
  • Extra interfaces to external networks for hybrid connectivity

Management and Monitoring

  • Comprehensive audits for compliance and security
  • Dynamic sizing for memory, CPU and vDisks
  • Performance stats and spending history for optimization
  • Microsoft software licensing overview for compliance management

Automation and Integration

  • Cloud init for virtual machine initialization
  • Cloud init templates for initializing additional software
  • QEMU agent automation for file management and program execution
  • VM Template creation for standardized deployments

Migration and Backup

  • Import/export via S3 bucket for data portability
  • VM copy (whitesky to whitesky) via CLI for easy replication
  • Nearly online migration from most platforms using third-party replication (Mobiti, RackWare)
  • Backup/restore via whitesky Backup for comprehensive data protection

Why Choose Our IaaS?

Our Infrastructure as a Service solution provides enterprise-grade virtualization with the flexibility and control you need to build robust, scalable applications while maintaining complete sovereignty over your data and infrastructure.

Whether you’re migrating from legacy systems or building new cloud-native applications, our IaaS platform provides the foundation you need to succeed.