Managed Kubernetes — launching in Dar es Salaam, tz-1a
Coming soonManaged Kubernetes in Tanzania
Somebody has to run etcd. In a team of four, that somebody is also your best engineer.
Kubernetes installs in an afternoon and takes three years to run well — certificate rotations, etcd backups nobody has restored, an upgrade that goes sideways with production on it, and one person who knows how the whole thing was built. That is a full-time role, and Dar es Salaam has few people who have done it and fewer teams who can spare one. Managed Kubernetes runs that layer in tz-1a, with autoscaling worker pools underneath and clusters opening at TZS 55,720 a month plus the resources you use. It is launching soon. Join the waitlist and we will tell you the week it is ready.
- Launching soon — join the waitlist for early access
- Managed control plane: API server, scheduler, etcd
- Clusters in Dar es Salaam, tz-1a
- Autoscaling worker pools, down to zero when idle
- Quoted and billed in TZS
Launching soon · Billed in TZS
Pricing
A cluster fee, plus what your nodes use
Pick a control plane — Basic or Fault Tolerant — then pay only for the vCPU, RAM, storage, and load balancers your worker nodes actually consume. In your currency, no forex.
Basic
Single master node for development, testing, and non-critical workloads.
Hosted in Nairobi, Dar es Salaam, Lagos & Kampala
- 1 master node
- 99.5% control-plane SLA
- Kubernetes 1.28–1.31
- Autoscaling worker pools
- Prometheus & Grafana included
Fault Tolerant
3 master nodes with automatic failover — recommended for production.
Hosted in Nairobi, Dar es Salaam, Lagos & Kampala
- 3 master nodes, automatic failover
- 99.95% control-plane SLA
- Kubernetes 1.28–1.31
- Autoscaling worker pools
- Prometheus & Grafana included
Worker node resources
Billed monthly, per unit consumed, on top of the cluster fee.
| Resource | Unit | Price /mo |
|---|---|---|
| vCPU | per vCPU | TZS 13,320 |
| RAM | per GB | TZS 6,120 |
| Local disk | per GB | TZS 380 |
| Network HDD | per GB | TZS 300 |
| Universal SSD | per GB | TZS 460 |
| Fast SSD | per GB | TZS 680 |
| Public IP | per IP | TZS 3,000 |
| Load balancer — Basic | per LB | TZS 32,760 |
| Load balancer — Basic, redundant | per LB | TZS 65,540 |
| Load balancer — Advanced, redundant | per LB | TZS 131,060 |
Your monthly total is the cluster fee plus the resources your worker nodes consume. Snapshots, file storage, and traffic beyond the included allowance bill at the same per-GB console rates. Prices exclude VAT; local currency figures are indicative and settled at checkout.
Where the cluster stands
Eight hops per request, all of them in one building in Dar es Salaam
The reason to run containers is also the reason distance costs more once you do. A request hits the ingress, reaches a service, which calls two more, which each read from a database and a cache, and something writes an event on the way out. One user action, eight network hops, before a response exists. Inside tz-1a those hops happen inside one facility. Split across an ocean and the same eight hops consume the whole latency budget before your own code has done anything.
TCRA's count for the quarter ending March 2026 places the people at the other end: Vodacom 36.19 million subscriptions, Yas 31.85 million, Airtel Tanzania 23.75 million, Halotel 18.32 million, TTCL 1.80 million — 111.9 million in total, with 58.9 million internet subscriptions at 84.2% penetration and roughly 99% of connections mobile wireless. The largest network reaches under a third of the country, so there is no carrier deal that covers a Tanzanian audience. Being in Tanzania covers all of them at once.
Domestic traffic is exchanged in the city. TIX has run in Dar es Salaam since 2003 as a project of TISPA, the Tanzanian ISP association, and PeeringDB records 32 networks and 798G of connected capacity there, with no port, cross-connect or membership fee — five further TISPA exchanges cover Arusha, Dodoma, Mbeya, Mwanza and Zanzibar. Upcountry, the National ICT Broadband Backbone carries one origin onward: 13,820 km of state fibre laid of a 16,280 km target as of FY2024/25, reaching every region and crossing into six neighbours.
International capacity comes ashore in the same city — SEACOM, EASSy and SEAS land at Dar es Salaam, a named landing point on 2Africa too — so there is no inland haul between the cable and the rack. What Tanzania does not have is any hyperscale cloud region or content-delivery edge of its own: Amazon's African region is Cape Town, Microsoft's is in South Africa, and the large content networks sit in Nairobi, Lagos and Mombasa. A cluster in tz-1a is compute in Tanzania rather than near it.
111.9M
Telecom subscriptions in Tanzania (TCRA, Q1 2026)
798G
Capacity connected at TIX, Dar es Salaam (PeeringDB)
1.28–1.31
Kubernetes versions at launch
99.95%
Control-plane SLA on Fault Tolerant clusters
What comes wired in
A CSI driver that provisions HDD, Universal SSD or Fast SSD volumes straight from your PVCs. Services of type LoadBalancer that provision a cloud load balancer. An NGINX ingress controller and Helm from any repository. Prometheus and Grafana with alerting on every cluster. Private clusters — control plane and workers with no public IPs, reached over VPN or a bastion — from the first release rather than a later tier.
The role you would otherwise have to fill
Tanzania's pool of engineers who have genuinely operated a control plane in production is small, and 2025 was a thin year for local startup funding, which makes a dedicated platform hire hard to justify twice over. That is the honest reason this product exists: the software is easy to install and expensive to keep healthy, and most Tanzanian teams need that skill far less than one full-time person's worth.
The platform
Everything a production cluster needs
Networking, storage, monitoring, and access control come wired in — so day two looks like day one.
Managed control plane
API server, scheduler, controller manager, and etcd — run, upgraded, and backed up by us.
Autoscaling worker pools
The cluster autoscaler adds and removes nodes with demand, down to zero when idle.
Auto-healing nodes
Unhealthy nodes are detected and replaced automatically, with no manual intervention.
Persistent volumes
A CSI driver provisions HDD, Universal SSD, or Fast SSD volumes straight from your PVCs.
Private clusters
Run control plane and workers with no public IPs, reached over VPN or a bastion host.
Load balancer integration
Services of type LoadBalancer provision cloud load balancers automatically.
Prometheus & Grafana
Built-in monitoring and dashboards on every cluster, with alerting included.
Helm & NGINX ingress
Deploy from any Helm repository, with a built-in NGINX ingress controller for traffic.
Multiple K8s versions
Choose Kubernetes 1.28–1.31 and upgrade through the console with zero downtime.
Regions
tz-1a is home. Nairobi and Lagos are on the same account.
Deploy in Dar es Salaam and your data stays in Tanzania, in the same city as most of the people using it. ke-1a in Nairobi and ng-1a in Lagos are one API call away on the same console and the same shilling bill, so a standby or an offsite copy is a line in a config file rather than a supplier to onboard. Typical in-metro round trips are around 6 ms in Dar es Salaam, ~2 ms in Nairobi and ~4 ms in Lagos.
Traffic between Tanzanian networks is exchanged in Dar es Salaam. The Tanzania Internet eXchange has run there since 2003 as a project of TISPA, the Tanzanian ISP association; PeeringDB records 32 networks and 798G of connected capacity there, with Akamai, Meta, Cloudflare and TTCL among them, and no fee to join. The point of a local exchange is a plain one: a packet from one Tanzanian network to another changes hands in the city, instead of being hauled to Europe and back to travel four kilometres.
International capacity comes ashore in the same city: SEACOM, EASSy and SEAS land at Dar es Salaam, a named landing point on 2Africa as well. Inland, the National ICT Broadband Backbone carries it onward — government fibre managed by TTCL, 13,820 km laid of a 16,280 km target as of FY2024/25, reaching every region and crossing into Zambia, Malawi, Kenya, Uganda, Rwanda and Burundi. One origin in Dar es Salaam therefore has a real answer for a user in Mwanza, a site office outside Geita and a clearing agent at Tunduma.
TCRA's count for the quarter ending March 2026 tells you who is at the other end: Vodacom 36.19 million subscriptions, Yas 31.85 million, Airtel Tanzania 23.75 million, Halotel 18.32 million, against 58.9 million internet subscriptions nationally, roughly 99% of them mobile wireless. The largest reaches under a third of the country: no carrier arrangement covers a Tanzanian audience, and being inside Tanzania covers all of them at once.
Tanzania
Dar es Salaam
~6 ms
typical, within metro · Data stays in Tanzania
Kenya
Nairobi
~2 ms
typical, within metro · Data stays in Kenya
Nigeria
Lagos
~4 ms
typical, within metro · Data stays in Nigeria
Uganda
Kampala
~3 ms
typical, within metro · Data stays in Uganda
Use cases
Built for what you're building
Microservices
Run service meshes with built-in discovery, load balancing, and rolling deploys.
CI/CD pipelines
Host Jenkins, GitLab runners, or Argo CD close to your team, scaling with each build.
Batch & ML workloads
Queue batch jobs and training runs on autoscaling pools that shrink when idle.
Dev environments
Give every team an isolated namespace — one cluster, clean boundaries, less sprawl.
How it works
From zero to cluster in four steps
Pick region, version & cluster type
Choose your region, a Kubernetes version, and Basic or Fault Tolerant control plane.
Add worker pools
Size pools in vCPU, RAM, and storage, and set autoscaler bounds per pool.
Deploy with your tools
Download the kubeconfig, then kubectl apply or helm install like any cluster.
Let it run
The autoscaler tracks demand and auto-healing replaces bad nodes — day and night.
Uptime SLA
99.9%
- When hardware fails
- When the region is the risk
- Service credits applied automatically when we miss the SLA
Support
A Tanzanian line, and a clock that already matches yours
Call +255 761 847 121. Tanzania is on East Africa Time all year with no daylight saving, so there is no drift to track and no arithmetic before you dial — business hours mean the same thing in March as in November. A ticket opened at the start of a Dar es Salaam morning lands inside a working day, rather than at the bottom of a queue that wakes up as yours is ending.
That match is worth the most at the moment you can least afford it. Month-end, last Friday, 16:40: the reconciliation job has stalled, the settlement file has not written, and the deadline is Monday. What you want then is an engineer who is awake and at work with your instance ID in front of them — a resize that needs a reboot window, a snapshot restored into a new instance, a routing question, a port that has stopped answering. Not a form, and not a five-hour wait for somebody's morning.
[email protected] takes the commercial half, and it is worth using before you order: your TIN and registered name as the TRA holds them, a purchase-order or grant code the invoice must carry, an annual invoice that fits the budget year. Migration planning and assistance come at no extra charge, from a rack in Frankfurt or from across town. Customer references are available under NDA.
Tanzania
+255 761 847 121Sales
[email protected]Why Lineserve
Managed here beats self-managed anywhere
Running your own control plane on VMs means patching, etcd backups, and 2 a.m. failovers. Running on a distant hyperscaler means forex bills and latency. This is the third option.
What it will cost
A cluster fee in shillings, then the resources your pods asked for
Two numbers make a Kubernetes bill, and keeping them apart is what makes the second predictable. The cluster management fee comes first: Basic, a single master node for development, testing and non-critical workloads, opens at TZS 55,720 a month behind a 99.5% control-plane SLA. Fault Tolerant, three master nodes with automatic failover, opens at TZS 232,680 behind a 99.95% SLA. Production belongs on Fault Tolerant. Everything else is a judgement about what a broken control plane costs you on a Thursday afternoon.
Worker resources are the second number, billed per unit consumed: TZS 13,320 per vCPU and TZS 6,120 per GB of RAM a month, node-local disk at TZS 380 per GB, and persistent volumes at TZS 300 per GB for Network HDD, TZS 460 for Universal SSD and TZS 680 for Fast SSD. A public IP is TZS 3,000. Load balancers run TZS 32,760 for a Basic, TZS 65,540 for a Basic with automatic failover and TZS 131,060 for an Advanced redundant one. Nothing is bundled into a node size somebody else chose, which is what makes a pool you scale down actually get cheaper.
That is why the autoscaler is worth turning on rather than admiring. Pools grow with demand and shrink to zero when idle, so a nightly aggregation pool is billed for the hours it ran. Model three lines — the cluster fee, the steady-state pool, and what the peak costs for the hours the peak lasts — and a harvest season or a survey round becomes an hours number rather than a months number.
These are Tanzanian figures from a Tanzanian price list, and that matters more here than almost anywhere: the Finance Act 2024 and GN 198 of 2025 make it an offence to quote or accept foreign currency for domestic transactions, so a shilling price list is the right way round rather than a convenience bolted onto a dollar one. VAT sits on top at 18% on the mainland, administered by the Tanzania Revenue Authority and shown separately at checkout. Send [email protected] your TIN and registered name as the TRA holds it when you join the waitlist, with any grant or purchase-order code the invoice has to carry.
Reserve pricing while you still have a budget year
Tell [email protected] the cluster tier and the rough pool shape and the team will put launch pricing in writing against your account. Grant-funded procurement in particular needs a number long before an engineering team needs a cluster, and annual billing at ten months for twelve lines up with a budget year rather than cutting across it.
Where a cluster stops being the cheap answer
Worth being blunt: one application with steady traffic runs better and cheaper on a cloud server or a VPS, and both are live in tz-1a today from TZS 27,780 and TZS 43,900. Kubernetes earns its cluster fee when you have many services, many clients, or a load whose shape changes by the hour. If that is not you yet, wait for the second product rather than the launch of this one.
Prices exclude VAT; 18% is added at checkout. Figures are indicative launch pricing rather than an amount payable today, worker resources bill per unit consumed, and annual billing is ten months for twelve on eligible plans.
Data residency
The manifests are portable. The volumes need a permit to leave.
It is easy to file a cluster under stateless and move on. Then you list the PersistentVolumeClaims: the Postgres a team installed with a Helm chart, the uploads directory holding scanned consent forms, the queue with message bodies in it, the logs carrying phone numbers and national ID references, the registry cache. All of it is data, on disks, in one building, in whichever country the cluster was created in.
Tanzania's Personal Data Protection Act, 2022 has been in force since 1 May 2023, with the Personal Data Protection Commission fully operational since 3 April 2024. Controllers and processors register with the Commission before processing, five years at a time. And personal data leaves Tanzania on a permit — applied for in advance under Regulation 20, setting out the recipient, the data subjects, the categories, the purpose, the duration, the destination country and entity, and the security arrangements there. The Commission may approve, ask for more, or refuse, and it monitors the conditions afterwards.
Prior authorisation is a different animal from a self-assessment: it finishes when a regulator says so rather than when you do. For a cluster that means the placement decision is worth making once, deliberately, at creation — because a volume that ends up in the wrong country is not fixed by a manifest change. Administrative penalties under the Act run to TZS 100,000,000, and criminal fines reach TZS 5,000,000,000 for corporations.
Create the cluster in tz-1a and the worker nodes, their volumes and their backups are in Dar es Salaam, under Tanzanian law, and do not leave without your instruction. That is data residency for Tanzania's Personal Data Protection Act. Your obligations as controller stay yours, registration included, and they are lighter when nothing crossed a border.
Point the backup target at the same country
Velero snapshots, database dumps and object storage mirrors are the classic route by which data quietly leaves a country, because that is where the credentials already pointed. Lineserve object storage runs a per-region endpoint in Dar es Salaam, so a backup target inside Tanzania is a configuration line rather than a project — and a restore that crosses the metro rather than an ocean.
Non-personal state can go anywhere
Container images, build artefacts, Helm charts and telemetry stripped of identifiers raise none of these questions and can sit wherever your pipeline is happiest. Drawing that line explicitly in your own architecture is an afternoon well spent — treating every byte as sensitive produces a system your team cannot operate.
Who runs here
The Tanzanian teams a managed control plane is actually for
Not every workload needs Kubernetes. These are the ones where it is already the right answer, and the control plane is the part nobody in the building has time for.
ISPs, telcos and their resellers
Four mobile networks, a state backbone operator and a set of enterprise ISPs, all clustered around the same exchange. The workloads are many small services rather than one big one: RADIUS and AAA, DNS resolvers and authoritative zones, mail relays, provisioning and billing portals, NetFlow collectors, looking-glass and speed-test endpoints, IPAM. That is a container platform's natural shape — and these buyers will read a traceroute before they read a page like this one, which is the correct order.
NGO and donor platforms
DHIS2 and other health and monitoring systems, KoBoToolbox and ODK form servers taking submissions from field teams, beneficiary registries, reporting dashboards, ERPNext or Odoo for grant accounting. Programme offices often run five or six of these at once for different funders, with different lifecycles and different end dates — which is exactly when namespaces and quotas beat six separate servers. TANGO alone counts over 485 member organisations, and the personal data on those volumes sits under the Commission's regime.
Ports, transit and freight systems
Dar es Salaam is the transit gateway for six land-linked countries. Transport management, customs integration middleware, container tracking portals, EDI, and a constant telematics stream from truck fleets on Tanzanian roads. The ingest service, the tracking API and the client portal each scale differently and each fail differently, which is the argument for separating them — and for auto-healing nodes rather than a person watching a dashboard at 03:00.
Mining and its contractors
Gold is the largest export earner and the hosting buyer is very often the service contractor rather than the mine. Site-to-cloud aggregation from remote operations on thin links, geological and survey data stores, HSE and contractor compliance systems, procurement portals. Several small services with wildly different uptime requirements, on one cluster, with the ingest path staying inside Tanzania from the site onward.
Agriculture and agri-export
Coffee, tea, cashew, cloves, tobacco — traffic that tracks the harvest calendar rather than the working week. Cooperative membership and payout systems, traceability, warehouse receipt systems, buyer portals. A worker pool with an autoscaler floor of zero costs nothing in the off-season and takes the buying season when it arrives, which suits a business whose revenue does the same thing.
Financial services and fintech
Agent-banking backends, USSD gateways, KYC services, reconciliation and settlement jobs, reporting into the Bank of Tanzania. Month-end is a hard, predictable peak on top of a steady baseline, and the services behind it want to scale independently. A Fault Tolerant control plane is the part you do not want failing during a settlement run.
Agencies, ISVs and resellers
Dar es Salaam holds 66.5% of Tanzanian startups, clustered on the Ali Hassan Mwinyi Road corridor. A namespace per client, quotas at the boundary, and pools sized on the aggregate rather than the worst case — a long tail of small client services that would be uneconomic as individual VMs. The model only works at agency margins if the control plane is somebody else's job.
Customer references are available under NDA — ask [email protected] or call +255 761 847 121 and the team will arrange one against the workload you are buying for.
Migrating
What moving a cluster here will look like at launch
From a control plane you run yourself
kubeadm on three VMs works, right up until the afternoon it does not — a certificate expires, etcd needs a restore rather than a restart, an upgrade goes sideways with production on it. At launch that layer is run, upgraded and backed up for you: API server, scheduler, controller manager and etcd, with unhealthy nodes detected and replaced automatically and version upgrades between 1.28 and 1.31 run through the console. Your manifests do not change. What changes is that the one person who knows how the cluster was built stops being a single point of failure for the whole organisation.
From a cluster hosted outside Tanzania
The mechanics are the standard ones — kubectl, Helm and Velero. Export the namespaces, swap provider-specific annotations and storage classes for the CSI classes here, re-issue the ingress, run both until the new cluster is healthy, then move DNS. What changes afterwards is two things at once: eight hops per request stop crossing an ocean, and the personal data on your volumes stops being a transfer that needs a permit from the Commission. Migration planning is included at no extra charge and is better done before the service opens than after.
One question settles where a cluster really is, and it is worth asking of every provider you shortlist, this one included: which building are the worker nodes in, and in which country is that building? For tz-1a the answer is Dar es Salaam.
FAQ
Questions, answered
A service where we run the Kubernetes control plane for you — API server, scheduler, controller manager, and etcd — and handle upgrades, backups, and availability. You deploy and manage your applications; we keep the cluster healthy.
Basic clusters run a single master node and suit development, testing, and non-critical workloads, with a 99.5% control-plane SLA. Fault Tolerant clusters run 3 master nodes with automatic failover on a 99.95% SLA — recommended for production.
You pay the monthly cluster management fee (Basic or Fault Tolerant) plus the worker-node resources you actually consume — vCPU, RAM, storage, and load balancers. Scale worker pools up or down anytime; you only pay for what you use.
Versions 1.28 through 1.31, with new versions added shortly after upstream release. You upgrade your cluster through the console with zero downtime.
Yes. Enable the cluster autoscaler, set minimum and maximum node counts, and it adds or removes worker nodes automatically as your workload demands.
Yes. Create a cluster where the control plane and worker nodes have no public IP addresses, and reach it through a VPN or bastion host for maximum security.
Our CSI driver provisions volumes automatically when you create PersistentVolumeClaims. Choose HDD, Universal SSD, or Fast SSD storage classes to match your performance needs.
Yes. Every cluster ships with built-in Prometheus monitoring and Grafana dashboards. Container logs can flow to our logging service or your own backend.
Yes. Standard tools like kubectl, Helm, and Velero work directly, and our team assists with migration planning at no extra charge.
It is in build and not open for orders. Rather than publish a date that moves, we tell the waitlist directly — email [email protected] or call +255 761 847 121 with the workload you have in mind and you will hear when the first release is ready.
Not yet. What you can do now is size the cluster and the pools with us, get launch pricing in writing against your account, and be in the first group given access. Cloud servers and VPS in tz-1a are live today if you need capacity in Dar es Salaam before then.
In tz-1a, our Dar es Salaam region. Control plane, worker nodes and their persistent volumes all sit there, in the same region already running cloud servers, VPS, dedicated hardware and object storage.
Basic runs a single master node and suits development, testing and non-critical workloads, on a 99.5% control-plane SLA at TZS 55,720 a month. Fault Tolerant runs three master nodes with automatic failover on a 99.95% SLA at TZS 232,680. Production belongs on Fault Tolerant.
The monthly cluster management fee plus the worker resources you consume — TZS 13,320 per vCPU, TZS 6,120 per GB of RAM, TZS 380 per GB of node-local disk, persistent volumes from TZS 300 per GB, public IPs at TZS 3,000 and load balancers from TZS 32,760. Scale pools up or down and the resource line follows.
No. Those figures are indicative launch pricing and nothing bills until the service opens. If your budget year needs a number sooner, ask [email protected] for a written quotation against your account.
TZS, on the same account as everything else you run here. Tanzanian customers pay by M-Pesa, bank transfer or card, in shillings, with no conversion and no foreign transaction on the statement.
No. Displayed prices exclude VAT. Mainland VAT on digital and electronic services is 18%, administered by the Tanzania Revenue Authority, and it is calculated and shown separately at checkout.
1.28 through 1.31 at launch, upgraded through the console, with new versions added shortly after upstream release.
Yes. Set minimum and maximum node counts per pool and the cluster autoscaler adds and removes nodes with demand, down to zero on pools that are idle — which is what makes a seasonal or nightly pool cost what those hours cost.
Yes — control plane and worker nodes with no public IP addresses, reached over VPN or a bastion host, from the first release.
A CSI driver provisions them from your PersistentVolumeClaims, with HDD, Universal SSD and Fast SSD storage classes. Those volumes are created in tz-1a and stay in Dar es Salaam.
Yes. Worker nodes and their volumes sit in tz-1a and are not moved out of the country without your instruction, which gives you data residency for Tanzania's Personal Data Protection Act. Point your backup target at the Dar es Salaam object storage endpoint and the whole path stays in-country.
ke-1a and ng-1a are on the same account and API, so it is a configuration rather than a project. Treat personal data deliberately when you do: a copy outside Tanzania is a transfer under the PDPA and engages the Commission's permit regime. Images, build artefacts and de-identified telemetry raise no such question.
Often, no. One application with steady traffic runs better and cheaper on a cloud server from TZS 27,780 or a VPS from TZS 43,900, both live in tz-1a today. Kubernetes earns its cluster fee when you have many services, many clients, or a load whose shape changes by the hour.
Email [email protected], call +255 761 847 121, or use the contact form, with the cluster tier and pool shape you would use. No card, no commitment — it puts you in the first group given access and gets launch pricing written against your account.
Ship on Kubernetes, skip the control plane
Managed Kubernetes is launching soon. Talk to us to reserve early access and pricing in your local currency, with no card to start.
Launching soon · 99.95% control-plane SLA on Fault Tolerant · Billed in TZS