Cloud & On-Prem Deployments
Run Vucos the way your regulator, procurement, and network team need it — fully managed SaaS, dedicated single-tenant cloud, hybrid with on-prem components, or entirely inside your own data center — from the same versioned code base.
One platform, four deployment models
Vucos is delivered as Kubernetes-native workloads with Helm and Terraform, wrapped by managed operators that understand the OTT stack specifically. The same build is certified against AWS, Google Cloud, Microsoft Azure, OVHcloud, and on-prem Kubernetes distributions. You choose multi-tenant SaaS for speed, dedicated cloud for control, hybrid for data-residency or network interconnect reasons, or fully on-prem where a regulator requires it — without forking the product.
Why this matters
Deployment shape is usually the first architectural decision that locks an OTT operator into years of compromise. Teams pick SaaS for time-to-market and later need a private tenant for a regulator; or they pick on-prem for control and find they cannot ship features at the cadence their market demands. Most platforms force you to choose once, and to re-platform when the choice stops fitting.
Vucos is designed so deployment is a property of a region or a tenant, not of the product. The same analytics, entitlement, and ad decisioning code runs whether the workload lives in a public cloud region, a colocation rack, or a hybrid split — and operators can move workloads between shapes as regulation, cost, or operations require.
Deployment capabilities
Managed SaaS multi-tenant
Fastest time-to-launch. Shared control plane with per-tenant isolation, multi-region failover, and a managed SRE team keeping it green 24/7.
Dedicated single-tenant cloud
Your own VPC in AWS, GCP, Azure, or OVH. Dedicated databases, DRM licenses, and network perimeter with the same features and upgrade cadence as SaaS.
Hybrid deployment
Run the control plane in managed cloud while keeping origins, transcoding, or subscriber data on-prem — connected over private peering or direct connect.
Full on-prem
Ship to your data center on certified Kubernetes distributions (OpenShift, Rancher, vanilla). Air-gapped installs and offline updates supported.
CI/CD & release pipelines
Blue/green and canary releases on a per-tenant basis. GitOps-driven promotion, automated regression and load tests, signed container images, and SBOM generation.
Disaster recovery
Cross-region active/active or active/passive with documented RTO and RPO per service. Regular DR drills, automated backups, and point-in-time recovery.
How operators deploy
Data-residency hybrid
Run the operational control plane in the Vucos EU region while pinning subscriber data and identity to an on-prem cluster in the home country. Auditors get a documented boundary; engineering still ships weekly.
Fully on-prem with DR
Deliver the full Vucos stack to two regional data centers on OpenShift, with active/passive DR and quarterly failover drills. Updates are pulled from a regulated registry; all traffic stays inside the carrier network.
SaaS multi-tenant with burst
Launch on managed SaaS in under 30 days, with automatic scale-out for match-day bursts. Later, migrate to a dedicated cloud tenant once volume justifies it, with no code rewrite.
Technical details
- AWS
- Google Cloud
- Microsoft Azure
- OVHcloud
- Alibaba Cloud
- Tencent Cloud
- Red Hat OpenShift 4.x
- SUSE Rancher
- VMware Tanzu
- Vanilla Kubernetes 1.27+
- Air-gapped registry support
- Terraform modules per cloud
- Helm charts per service
- Kustomize overlays per tenant
- Ansible for bare-metal prep
- GitOps with Argo CD / Flux
- Blue/green and canary deploys
- Signed images (Cosign) and SBOM
- Automated regression and soak tests
- Documented RTO/RPO per service
- Active/active across regions (SaaS)
- Active/passive DR (dedicated/on-prem)
- Quarterly DR drills
- SOC 2 Type II
- ISO 27001
- GDPR-aligned data residency
- Customer-managed encryption keys (BYOK)
- Private networking (PrivateLink, Interconnect, ExpressRoute)
Key Takeaways
- Same code base for SaaS, dedicated cloud, hybrid, and on-prem
- Kubernetes-native with Terraform modules and Helm charts
- Blue/green and canary releases per tenant, with automated regression tests
- Cross-region DR with documented RTO/RPO per service
- Certified on AWS, GCP, Azure, OVH, Alibaba, and Tencent
- SOC 2 Type II, ISO 27001, GDPR-aligned, customer-managed encryption keys
Frequently Asked Questions
Can we start on SaaS and move to dedicated cloud later?
Do on-prem deployments lag behind SaaS on features?
What about data residency in the EU or Middle East?
How are upgrades delivered without downtime?
What are the security controls?
Who operates the platform?
Related
Modular OTT Architecture
Buy the whole platform and it works on day one. Replace any piece with your own — billing, DRM, recommendations, analytics — and it keeps working. Modular by contract, composable in production.
Read moreObservability & Monitoring
Traces, metrics, and logs — correlated, queryable, and owned by you. The observability spine that turns a 3 AM incident into a 9-minute mean time to diagnose instead of a war-room hunt through five vendor consoles.
Read moreIntegrations
Vucos is built to plug into the systems you already run — billing, CAS/DRM, CDN, ad servers, BSS/OSS, identity, and payment — through a consistent API-first, webhook-driven surface that turns vendor swaps from quarters of work into days.
Read moreReady to learn more?
Talk to an architect about how this fits your deployment.