A Kubernetes factory, or a platform for your applications
Kubermatic Kubernetes Platform (KKP) is well engineered for one job, which is producing and hosting Kubernetes clusters for many tenants. Its seed architecture runs each user cluster’s control plane as pods, which keeps the cost per cluster low. Projects, quotas, metering and white-labelling make it a product for service providers, telcos and central IT teams.
Ankra serves the team that consumes the cluster. It builds or imports Kubernetes, then turns repositories into running services, keeps the platform add-ons current, ranks vulnerabilities, estimates cost, backs up data and operates it all with AI.
If your product is Kubernetes itself, Kubermatic fits that shape. If your product is software that runs on Kubernetes, Ankra covers more of the work.
Building and running the clusters
KKP supports a long list of providers, with real depth in private clouds such as OpenStack, VMware Cloud Director, Nutanix and KubeVirt. It also creates EKS, AKS and GKE clusters. You run the master and seed clusters yourself, unless you buy the managed subscription.
Ankra builds kubeadm or k3s clusters on Hetzner, OVHcloud, UpCloud, DigitalOcean, AWS EC2 and Proxmox VE, creates six provider-run services, and imports any conformant cluster, including clusters KKP made. On clusters it builds, Ankra handles upgrades, node groups and power schedules, with node autoscaling on the five public clouds. Its control plane is a hosted service in the EU, so there is no management cluster for your team to run.
What happens after the cluster exists
Creating a cluster is the first hour of its life. The years after are add-on upgrades, releases, incidents and security fixes.
KKP’s Enterprise application catalogue installs tools such as Argo CD, Flux, Trivy and Falco. The Kubermatic Developer Platform adds self-service APIs for internal services. Delivery, CI and incident handling then run in whichever tools you deploy and connect.
Ankra builds that work into the platform.
- Applications turn a repository into a running service and deploy every successful build
- Ankra Pipelines run tests, rootless builds and Semgrep, Checkov and Trivy scans in your cluster, and publish only the image that passed the gate
- stacks order Helm charts and manifests by dependency, and stack profiles version them across environments
- the Security Center ranks running-workload CVEs by CISA KEV and EPSS
- Cloud Cost estimates spend and reprices clusters on other providers
- backups write to a bucket you own and restore in place
Applications and previews work with GitHub repositories, and some documented pipeline stage kinds do not run yet.
AI on each side
Kubermatic gives your own AI tools access rather than shipping an AI operator. K8sGPT and the Kubernetes MCP server are catalogue apps, and KDP 1.2 adds an MCP endpoint. Kubermatic AI is a separate product for pooling GPUs and serving models.
Ankra’s AI is part of the platform. It drafts stacks from a description, analyses firing alerts with AI Insights, and reviews pull requests and opens fix pull requests through the AI Gateway. Every write waits for a person by default, under autonomy controls you set. Ankra also has an MCP server for your own tools.
Two kinds of openness
Kubermatic is open core. The Community Edition is Apache 2.0, while enterprise features such as multiple seeds, the application catalogue, cluster backups, quotas and policy are source-visible under a licence that requires a paid subscription.
Ankra’s platform is commercial, and its CLI and Terraform provider are open source. What Ankra manages stays standard Helm charts and manifests, and with a Git repository connected they live in your repository. Leaving means keeping working configuration, not exporting it.
When to choose Ankra, and when to choose Kubermatic
Choose Ankra when your team ships software on Kubernetes and wants clusters, delivery, security, cost and AI operations without running a management plane.
Choose Kubermatic when
- you offer Kubernetes as a service to many tenants or business units
- control-plane density and per-tenant metering drive your costs
- you run OpenStack, VMware Cloud Director or Nutanix private clouds
- a self-hosted, air-gapped management plane with an open source core is required
Compare the work that remains
- Create the foundation. Record who runs the management plane and the work outside the product.
- Ship a release. Include build, tests, scans, a preview and a rollback.
- Upgrade an add-on. Note who checks dependencies and how a failed upgrade is undone.
- Investigate a vulnerability. Find every affected workload and release the fix.
- Compare total cost. Include licences, infrastructure and the people who operate the platform.
Ankra’s pricing follows managed worker vCPU, with the first 30 vCPU free. Kubermatic Enterprise is priced on request.
Reviewed 9 October 2026 against KKP 2.31, KDP 1.2 and the linked documentation. Product scope and plans can change.