# ZSoftly Cloud Platform > ZSoftly Cloud Platform (ZCP) is a Canadian-operated public and private cloud for compute, storage, networking, Kubernetes, security, and platform engineering services. This index is generated at build time from public ZCP marketing content pages with Markdown exports. It excludes the interactive assistant. The API, CLI, and implementation guides are maintained in the separate [ZCP documentation site](https://docs.zcp.zsoftly.ca). Important notes: - Creating and operating cloud resources requires a ZCP account through the customer portal. - Prices on this site are in Canadian dollars. Confirm current availability and service limits in the linked product pages and technical documentation. - ZCP supports integrations and workflows that use S3-compatible object storage, Kubernetes, Terraform or OpenTofu, the ZCP CLI, and standard cloud networking tools. Refer to the technical documentation for setup instructions. ## Getting Started - [Cloud Platform Engineering and DevOps Services](https://zcp.zsoftly.ca/professional-services.md): Cloud and platform engineering, DevOps, reliability, cloud migration, and security services from ZSoftly Professional Services. - [Why ZCP](https://zcp.zsoftly.ca/why-zcp.md): Learn why ZSoftly Cloud Platform is building a developer-first sovereign cloud with Canadian regions, open infrastructure, predictable CAD pricing, and direct operational accountability. ## Platform - [ZCP Availability](https://zcp.zsoftly.ca/availability.md): See where ZCP services run today, which capabilities are in preview, and what is planned for future deployments. - [ZSoftly CI Runners](https://zcp.zsoftly.ca/ci-runners.md): Early access for managed GitHub Actions and GitLab CI runners on Canadian ZCP infrastructure. - [Contact Sales](https://zcp.zsoftly.ca/contact.md): Talk to the ZSoftly team about migration, private cloud, volume pricing, or enterprise support. We respond within one business day. - [ZCP Architecture Designer](https://zcp.zsoftly.ca/designer.md): Design ZSoftly Cloud Platform infrastructure visually, validate the architecture, and export zcp CLI commands for local deployment. - [FAQ](https://zcp.zsoftly.ca/faq.md): Answers to common questions about billing, infrastructure, migration, compliance, and portal access on ZSoftly Cloud Platform. - [Your Cloud and DevOps Team](https://zcp.zsoftly.ca/index.md): ZSoftly engineers design, build, and operate cloud infrastructure, Kubernetes platforms, and delivery pipelines, on your cloud, your hardware, or ZCP. - [Marketplace](https://zcp.zsoftly.ca/marketplace.md): Run databases, web stacks, dev tools, and more on ZCP. Browse the full, current image catalogue on the docs site, grouped by workload. - [Portal](https://zcp.zsoftly.ca/portal.md): Access the ZSoftly Cloud Platform portal. Eligible new accounts receive CA$100 in promotional credit at signup. Spend CA$200 on eligible compute plans, then request another CA$200 in promotional credit, for up to CA$300 total. No long-term contract. - [Pricing](https://zcp.zsoftly.ca/pricing.md): Simple, transparent cloud pricing. Virtual machines, object storage, block storage, Kubernetes, observability, and support. All prices published. Billed in CAD. - [Site Map](https://zcp.zsoftly.ca/sitemap.md): Every page on the ZSoftly Cloud Platform website in one place: platform services, pricing, solutions, professional services, resources, blog posts, company and legal pages. ## Services - [AI Agents & Chatbots - Custom AI Solutions](https://zcp.zsoftly.ca/professional-services/ai-agents.md): Build intelligent AI agents and chatbots for your business with conversational AI, automation, and integrations. - [Architecture Workshop](https://zcp.zsoftly.ca/professional-services/architecture-workshop.md): Architecture workshop, discovery, and assessment engagements for AWS, DevOps, Kubernetes, security, and cloud modernization. - [AWS Cost Optimization](https://zcp.zsoftly.ca/professional-services/aws/cost-optimization.md): AWS cost optimization, rightsizing, architecture review, and spend reduction services from ZSoftly. - [EKS Auto Mode Services](https://zcp.zsoftly.ca/professional-services/aws/eks-auto-mode.md): EKS migration, cluster design, and Kubernetes delivery services from ZSoftly. - [AWS Cloud Solutions - Development, Migration & Management](https://zcp.zsoftly.ca/professional-services/aws.md): Complete AWS solutions. From development to migration and management. AWS Partner with 100% certified team. - [Managed AWS](https://zcp.zsoftly.ca/professional-services/aws/managed.md): Managed AWS operations, monitoring, security, optimization, and support from ZSoftly. - [Cloud Native & Containerization Services](https://zcp.zsoftly.ca/professional-services/containers.md): Docker, Kubernetes, and containerization experts. Build scalable, cloud-native applications with microservices architecture and DevOps best practices. - [Managed Continuous Deployment](https://zcp.zsoftly.ca/professional-services/continuous-deployment.md): Managed continuous deployment for ArgoCD, Octopus Deploy, AWS CodeDeploy, GitHub Actions, and GitLab. - [Sovereign Application Platforms](https://zcp.zsoftly.ca/professional-services/devops/application-platforms.md): Deploy and operate Dokploy and other application platforms on Canadian ZCP infrastructure, in private cloud, or on dedicated infrastructure with ZSoftly managed operations. - [GitHub Actions CI/CD Solutions](https://zcp.zsoftly.ca/professional-services/devops/github-actions.md): Expert GitHub Actions services including workflow development, enterprise integration, security, and migration. - [GitLab Solutions](https://zcp.zsoftly.ca/professional-services/devops/gitlab.md): Official GitLab Channel Partner offering migration, implementation, managed operations, training, and compliance support. - [DevOps Services - CI/CD & Automation](https://zcp.zsoftly.ca/professional-services/devops.md): DevOps services for CI/CD, automation, GitLab, Kubernetes, Docker, and Terraform. - [Jenkins CI/CD Solutions](https://zcp.zsoftly.ca/professional-services/devops/jenkins.md): Expert Jenkins CI/CD services including pipeline development, enterprise integration, security, build automation, and migration. - [Jenkins Migration Services](https://zcp.zsoftly.ca/professional-services/devops/jenkins-migration.md): Escape legacy Jenkins. Get faster deployments with a structured migration to GitLab or GitHub Actions. - [Managed Observability & Incident Response](https://zcp.zsoftly.ca/professional-services/devops/observability.md): Deploy and operate OneUptime with ZSoftly. Choose open-source self-hosting, a licensed Enterprise Edition deployment, or managed operations on ZCP or in your environment. - [Headscale VPN Implementation - Self-Hosted Zero Trust Networking](https://zcp.zsoftly.ca/professional-services/headscale.md): Replace legacy VPN appliances and per-user ZTNA subscriptions with self-hosted Headscale and WireGuard. Lower cost, full metadata privacy, Canadian data residency. Implemented and managed by ZSoftly. - [Authentik Implementation Services - Self-Hosted SSO & IAM](https://zcp.zsoftly.ca/professional-services/identity/authentik.md): Authentik implementation and migration from Okta, CyberArk Identity, or Active Directory. Self-hosted SSO, MFA, and federation with no per-user licensing. Supports SOC 2 and HIPAA control evidence. - [IAM, SSO & Identity Management Services](https://zcp.zsoftly.ca/professional-services/identity.md): Identity and access management for CISOs and CTOs. Cut per-user licensing, close audit findings, and modernize Okta, CyberArk, or Active Directory with Authentik or JumpCloud. - [JumpCloud Implementation Services - Managed Directory & SSO](https://zcp.zsoftly.ca/professional-services/identity/jumpcloud.md): JumpCloud implementation, Active Directory migration, SSO and MFA rollout, and device management for Windows, Mac, and Linux fleets. Deployed and managed by ZSoftly. - [Cloud Services - Multi-Cloud Solutions](https://zcp.zsoftly.ca/professional-services/multi-cloud.md): Cloud-agnostic solutions across AWS, Azure, and GCP. Expert cloud architecture, migration, and optimization services. - [Managed CI/CD Runners](https://zcp.zsoftly.ca/professional-services/runners.md): Managed CI/CD runners for GitHub Actions, GitLab, and Bitbucket. Deploy in your cloud or ours. - [Security Services - Cloud Security & Compliance](https://zcp.zsoftly.ca/professional-services/security.md): Protect critical assets with full-stack security solutions. Vanta, Prisma Cloud, and JumpCloud partnerships. SOC 2, PCI-DSS, ISO 27001 expertise. - [Auto-scaling](https://zcp.zsoftly.ca/services/auto-scaling.md): Set a minimum and maximum, and ZCP adds or removes capacity as demand moves — across both cloud compute and Kubernetes worker nodes. You pay only for the instances that are running, with no separate auto-scaling charge and no egress fees. - [Automation](https://zcp.zsoftly.ca/services/automation.md): Manage your platform the way modern engineering teams expect — as code, with the Terraform, Ansible, and GitOps tooling they already know. Repeatable environments, fewer manual mistakes, and a clear audit trail. - [Backups and Snapshots](https://zcp.zsoftly.ca/services/backups.md): Protect every instance with scheduled backups and point-in-time snapshots. Take a snapshot before a risky change, keep offsite copies, and move long-term data to a lower-cost archive tier, all billed per GB in CAD. - [Bare Metal](https://zcp.zsoftly.ca/services/bare-metal.md): Dedicated physical servers — including GPU configurations for AI and HPC — provisioned to your specification across 28+ facilities in Canada, the USA, the UK, Europe, and Australia. No shared tenancy, no noisy neighbours, no virtualization overhead. We scope, harden, and operate it with you. - [Block Storage](https://zcp.zsoftly.ca/services/block-storage.md): High-performance NVMe block storage that attaches directly to your machines and expands online as you grow, with snapshots on demand. Capacity scales with the business, not against a maintenance window. - [Cloud Storage: Dedicated Ceph Clusters](https://zcp.zsoftly.ca/services/cloud-storage.md): ZSoftly Cloud Storage (ZCS) is a dedicated, single-tenant Ceph storage cluster with root access. Exabyte-scale object (S3), block (RBD), and file (CephFS) storage, hosted in our regions or on your own hardware. - [Colocation](https://zcp.zsoftly.ca/services/colocation.md): Keep the hardware you own and run it in our data center. Ship your servers to us and our team receives them, racks them, cables them, and connects them to power and network. Choose space for a single server, a half rack, or a full rack, and add remote hands or full management when you need them. - [DNS as a Service](https://zcp.zsoftly.ca/services/dns.md): Authoritative DNS for your domains, managed from the same portal as the rest of your platform and included free on every account. Redundant nameservers in separate Canadian regions keep your domains resolving — without adding another vendor or another invoice. - [File Storage](https://zcp.zsoftly.ca/services/file-storage.md): Shared network file storage that mounts to many machines at once, across Linux and Windows, and grows online without downtime. The simple way to give teams and applications a common, resilient place for files. - [Services](https://zcp.zsoftly.ca/services.md): Virtual machines, file storage, object storage, block storage, Kubernetes, security, observability, networking, and private cloud, all on an open-source sovereign foundation. CAD billing, available worldwide. - [Kubernetes](https://zcp.zsoftly.ca/services/kubernetes.md): A managed Kubernetes control plane on dedicated infrastructure. It is standard, upstream Kubernetes — no forks, no proprietary operators — so what you build here runs anywhere, and your team is never locked to one vendor. - [Load Balancing](https://zcp.zsoftly.ca/services/load-balancer.md): Spread traffic across your VMs for high availability and zero-downtime deploys, with DDoS monitoring built in. Flat per-instance pricing in Canadian dollars — no capacity units, no per-connection math, and no bandwidth bill. - [Marketplace](https://zcp.zsoftly.ca/services/marketplace.md): Launch databases, web stacks, developer tools, monitoring, VPNs, and AI agents in a few clicks. Each app is pre-configured on first boot, runs on an instance you own with root access, and carries no per-app premium: you pay only for the server. - [Networking](https://zcp.zsoftly.ca/services/networking.md): Build the network topology your applications need — from private VM-to-VM links to multi-tier VPCs with routing and firewalls — all self-service from the portal, with transparent CAD pricing and no per-gigabyte transfer surprises. - [Object Storage](https://zcp.zsoftly.ca/services/object-storage.md): Fully S3-compatible object storage that works with the AWS-ecosystem tools your teams already use, with no re-architecting. Ingress and egress are free and unmetered, so the costs that surprise you on hyperscalers simply are not there. - [Managed Observability](https://zcp.zsoftly.ca/services/observability.md): A managed observability service built around Prometheus, Grafana, Loki, and Alertmanager. ZSoftly operates the stack, configures dashboards and alerting, and connects it to the incident and communication tools your team already uses. - [Private Cloud: Open-Source Infrastructure, Managed by ZSoftly](https://zcp.zsoftly.ca/services/private-cloud.md): Build a production private cloud on open-source infrastructure with ZSoftly. CloudStack, OpenStack, Ceph, KVM, Kubernetes, networking, backup, disaster recovery, and managed operations. - [Migrate from VMware to ZSoftly Private Cloud](https://zcp.zsoftly.ca/services/private-cloud/migrate.md): A fully managed exit from VMware/Broadcom. Open-source foundation, predictable CAD pricing, sovereign architecture. We scope, convert, cut over, and operate your private cloud. Available worldwide. - [Security](https://zcp.zsoftly.ca/services/security.md): Security that comes with the platform, not as an upsell: firewalls on every workload, DDoS protection on every public address, role-based access, and audit trails — on infrastructure that keeps your data in Canada and under your control. - [Virtual Machines](https://zcp.zsoftly.ca/services/virtual-machines.md): Run your applications on cloud infrastructure ZSoftly owns and operates, with predictable Canadian-dollar pricing and free data transfer. A straightforward path off unpredictable hyperscaler bills and vendor lock-in, with a Canadian team on the call from first deploy through production. ## Solutions - [Canadian Managed Cloud & Modernization for SMBs](https://zcp.zsoftly.ca/cloud-modernization.md): ZSoftly modernizes and manages cloud infrastructure for Canadian SMBs. Cut cloud spend, pass SOC 2 and PCI audits, and ship faster, run by senior engineers on predictable CAD pricing. Book a free cloud assessment. - [Cloud Service Comparison](https://zcp.zsoftly.ca/compare.md): Compare ZSoftly Cloud Platform with AWS, Azure, Google Cloud, Vultr, and DigitalOcean across compute, storage, Kubernetes, networking, databases, security, and billing. - [AI & Machine Learning](https://zcp.zsoftly.ca/solutions/ai.md): AI labs, SaaS platforms, and enterprise teams run AI agents, retrieval pipelines, and vector databases on ZCP today, keeping training data and models in the region they select under a single accountable operator. GPU is available now for private cloud and bare metal; GPU on public cloud is on the roadmap. - [Education](https://zcp.zsoftly.ca/solutions/education.md): School boards, universities, colleges, and EdTech platforms choose ZCP to keep student data in the region they select, hold their budget steady with CAD billing and no FX surprises at renewal, and stay free of vendor lock-in on an open foundation. - [Finance](https://zcp.zsoftly.ca/solutions/finance.md): Credit unions, fintechs, capital-markets firms, and payment platforms move steady-state workloads to ZCP to take FX risk off the table and meet data-residency obligations under their financial regulator. One currency, one jurisdiction per workload, one invoice you can forecast. - [Public Sector & Crown Corporations](https://zcp.zsoftly.ca/solutions/government.md): Public-sector and government-adjacent organizations need a vendor that clears procurement on data residency, ownership, and audit. ZSoftly is an independently held operator, bills in CAD, and runs the platform end to end, with no foreign parent and no reseller layer to explain away. - [Healthcare & Life Sciences](https://zcp.zsoftly.ca/solutions/healthcare.md): Clinical systems, medical imaging, and life-sciences data need a provable answer about where patient information lives and who can reach it. ZCP keeps protected health information in the region you select under one accountable operator, with immutable audit trails ready for your privacy officer under whichever health-privacy framework applies to you. - [Hybrid cloud with AWS, Azure, GCP](https://zcp.zsoftly.ca/solutions/hybrid-cloud.md): Add ZCP to your hyperscaler. Four reference patterns: egress offload, sovereign workloads, DR target, predictable baseline. Keep AWS / Azure / GCP for what they do well. Available worldwide. - [Solutions](https://zcp.zsoftly.ca/solutions.md): ZSoftly Cloud Platform is built for regulated and data-sensitive workloads, education, insurance, finance, AI, healthcare, legal, and government. Data sovereignty infrastructure deployed wherever your requirements dictate. - [Insurance](https://zcp.zsoftly.ca/solutions/insurance.md): P&C carriers, life insurers, and MGAs run their core platforms on ZCP to satisfy data-residency obligations, carry years of regulatory retention without runaway storage bills, and walk into a regulator examination with audit trails already in place, all on a CAD cost they can forecast. - [Legal & Professional Services](https://zcp.zsoftly.ca/solutions/legal.md): Law firms and professional-services firms handling sensitive matters need a verifiable answer about where files live and who has compelled-access exposure. ZCP gives you a single-region, single-operator answer, with no foreign holding-company structure to qualify around, so confidentiality and privilege rest on fact, not assurances. - [MSPs & Channel Partners](https://zcp.zsoftly.ca/solutions/msp.md): Managed service providers resell ZCP and build a private cloud practice under their own brand, backed by a consistent CAD margin, a white-label portal, and a vendor that picks up the phone. A new revenue line without building infrastructure of your own. - [Research & Non-profit Organizations](https://zcp.zsoftly.ca/solutions/research.md): Research institutions and non-profits on publicly funded work need a vendor that satisfies grant-residency and procurement requirements without draining the budget. ZCP supports those constraints, bills in CAD, and charges nothing for data transfer, so more of your funding reaches the work. - [SaaS & Software Companies](https://zcp.zsoftly.ca/solutions/saas.md): SaaS companies serving enterprise customers move to ZCP to take egress billing off the gross margin, clear the data-residency requirements that stall procurement and security reviews, and hold infrastructure cost steady in CAD. - [Canadian Sovereign Cloud & AI](https://zcp.zsoftly.ca/sovereign-cloud.md): 85% of Canada's cloud is controlled by US hyperscalers, and the US CLOUD Act can reach data even when it sits in Canada. ZSoftly is the Canadian-owned, Canadian-controlled sovereignty layer for cloud, AI, and backup. Book a free sovereignty assessment. ## Examples - [ArgoCD CLI Login Fails on EKS Auto Mode? Here Is the Fix](https://zcp.zsoftly.ca/blog/argocd-eks-auto-mode-cli-login-fix.md): Standard ArgoCD login commands fail on EKS Auto Mode because AWS manages ArgoCD differently. This guide shows you the correct authentication method using tokens and environment variables. - [AWS Cost Guardrails for Bedrock and Cloud Teams](https://zcp.zsoftly.ca/blog/aws-cost-guardrails-bedrock-budgets-scp.md): Learn how organizations should use AWS Budgets, Cost Anomaly Detection, Bedrock-specific alerts, and emergency SCP controls to reduce surprise cloud bills. - [AWS Secrets Management Simplified: Choosing Between Secrets Manager, Parameter Store, and AppConfig](https://zcp.zsoftly.ca/blog/aws-secrets-management-secrets-manager-parameter-store-appconfig.md): AWS offers three services for secrets and configuration management. Learn when to use Secrets Manager for secrets, Parameter Store for simple key-value pairs, and AppConfig for feature flags. Includes cost comparison, migration strategies, and CloudFormation templates. - [Building the ZCP Terraform / OpenTofu Provider](https://zcp.zsoftly.ca/blog/building-the-zcp-terraform-opentofu-provider.md): ZCP infrastructure is now code. How we built our provider on the CLI SDK, what live testing taught us about state, networks, and public IPs, and why we ship to both registries with signed releases. - [Cloud Security Compliance Automation Costs in Canada](https://zcp.zsoftly.ca/blog/cloud-security-compliance-automation-costs-canada.md): Learn how Canadian businesses can use cloud security compliance automation for SOC 2, HIPAA, and ISO to cut risk, reduce audit pain, and control long-term costs. - [Deploy Dokploy on ZCP: Launch a VM and Self-Host Your Apps](https://zcp.zsoftly.ca/blog/deploy-your-first-vm.md): A step-by-step guide to launching a virtual machine and installing Dokploy on ZSoftly Cloud Platform, entirely from the portal. Self-host your apps and databases with Git deploys and automatic TLS. - [Managed DNS on ZCP: setup, architecture, and how to use it](https://zcp.zsoftly.ca/blog/dns-on-zcp.md): How ZCP managed DNS works, how to delegate a domain to ns1/ns2.zsoftly.ca, and how to manage records from the customer portal. - [How We Eliminated 23 Bastion Hosts with JumpCloud and AWS SSM](https://zcp.zsoftly.ca/blog/how-we-eliminated-bastion-hosts-jumpcloud-ssm.md): How we replaced legacy bastion host architecture with Zero Trust access. We cut infrastructure costs, eliminated SSH key sprawl, and passed SOC 2 with significantly fewer findings. - [Beyond GitHub Actions Quota Limits: Building Production-Grade CI/CD Artifact Storage](https://zcp.zsoftly.ca/blog/how-we-eliminated-cicd-downtime-cloudflare-r2.md): When GitHub Actions quota limits halted a startup's entire deployment pipeline for 24 hours, we helped them build a strategic solution. Learn the decision framework for evaluating artifact storage, why most teams make the wrong architectural choices, and how to build CI/CD infrastructure that scales with your business. - [Why Hybrid Cloud is the Future: A Complete Guide After the 2025 Outage Crisis](https://zcp.zsoftly.ca/blog/hybrid-cloud-strategy-2025-outage-crisis.md): After four major cloud outages in a 30-day period (AWS, Azure, GitHub, Cloudflare), 80% of enterprises are moving to hybrid cloud. This comprehensive guide covers the concentration problem, SaaS dependency risks, the business case for hybrid cloud, and a practical 8-step implementation playbook. - [Introducing zxtra: Our AI Assistant Built on Cloudflare Workers AI](https://zcp.zsoftly.ca/blog/introducing-zxtra-ai-assistant-cloudflare-workers-ai.md): We built zxtra, an AI assistant that answers questions about ZSoftly directly on our website. Learn how we used Cloudflare Workers AI to create a fast, secure chatbot with zero infrastructure overhead. - [Kubernetes 1.37 on ZCP: Features, Versions, and Upgrades](https://zcp.zsoftly.ca/blog/kubernetes-1-37-now-available.md): Kubernetes 1.37 is available on ZCP. Review supported versions, a scale-to-zero queue-worker example, upstream support dates, and how to plan your upgrade. - [Migrating a VPN Server From AWS to Private Cloud: What Nobody Tells You](https://zcp.zsoftly.ca/blog/migrating-a-vpn-server-from-aws-to-private-cloud.md): Lessons from moving a VPN control plane from AWS to private cloud infrastructure, including the routing assumption that breaks published container ports. - [Moving Our DNS from a Third Party to Our Own Nameservers](https://zcp.zsoftly.ca/blog/migrating-our-dns-to-our-own-platform.md): A .ca registry requirement, a delegation change we did not ask for, and the migration of zsoftly.ca onto ZSoftly nameservers, told as it happened. - [Multi-Cloud CSPM Implementation: Managing AWS, Azure, and GCP Security from a Single Pane of Glass](https://zcp.zsoftly.ca/blog/multi-cloud-cspm-aws-azure-gcp-unified-security.md): AWS has 15,000+ IAM actions, Azure nearly 19,000, and GCP over 10,000. Learn practical approaches for unified security monitoring, compliance automation for GDPR, HIPAA, and SOC 2 without enterprise-grade tools. - [Open-Sourcing Our Apache CloudStack Terraform Modules](https://zcp.zsoftly.ca/blog/open-source-terraform-modules-apache-cloudstack.md): We packaged the Terraform we write for Apache CloudStack into reusable modules, scrubbed the internal specifics, and released them under MIT. Eight modules cover networking, compute, storage, Kubernetes, and more. Validate them with no credentials. - [Two Lessons From Running OPNsense in Production](https://zcp.zsoftly.ca/blog/opnsense-bare-metal-lessons.md): We ran OPNsense as a VM on network-defined storage and watched a single switch fault cascade into a cluster-wide outage. Two lessons we will not relearn: put your firewall on bare metal, and if you must virtualize it, keep the disk local. - [Running Your VPN Gateway Inside the Thing It Protects Is a Bad Idea](https://zcp.zsoftly.ca/blog/ops-02-subnet-router-migration.md): We ran our Tailscale subnet router as an LXC container on the same Proxmox host it was providing remote access to. It worked. Until Proxmox needed attention. Here is how we fixed it. - [How We Consolidated 4 PostgreSQL Clusters into 1 with CloudNativePG](https://zcp.zsoftly.ca/blog/postgresql-consolidation-cloudnativepg-kubernetes.md): We ran 4 separate PostgreSQL clusters for 91MB of data. Each cluster had its own PodDisruptionBudget blocking node drains. This guide shows how we consolidated them into a single HA cluster with PgBouncer connection pooling using CloudNativePG and ArgoCD. - [VMware to Apache CloudStack Migration: Step-by-Step Guide](https://zcp.zsoftly.ca/blog/vmware-to-cloudstack-migration-guide.md): Step-by-step guide to migrating VMware vSphere VMs to Apache CloudStack + KVM. Covers virt-v2v, domains, accounts, networks, and the CloudStack 4.19 migration tool. - [ZCP September 2026 Update: Kubernetes, CLI, and Terraform](https://zcp.zsoftly.ca/blog/zcp-september-2026-update.md): Review Kubernetes 1.37 availability, the safer ZCP CLI v0.0.28 and v0.0.29 workflows, and Terraform provider v0.2.0. ## Insights and Updates - [Blog](https://zcp.zsoftly.ca/blog/10.md): Updates, engineering stories, and tutorials from the ZSoftly Cloud Platform team. - [Blog](https://zcp.zsoftly.ca/blog/11.md): Updates, engineering stories, and tutorials from the ZSoftly Cloud Platform team. - [Blog](https://zcp.zsoftly.ca/blog/2.md): Updates, engineering stories, and tutorials from the ZSoftly Cloud Platform team. - [Blog](https://zcp.zsoftly.ca/blog/3.md): Updates, engineering stories, and tutorials from the ZSoftly Cloud Platform team. - [Blog](https://zcp.zsoftly.ca/blog/4.md): Updates, engineering stories, and tutorials from the ZSoftly Cloud Platform team. - [Blog](https://zcp.zsoftly.ca/blog/5.md): Updates, engineering stories, and tutorials from the ZSoftly Cloud Platform team. - [Blog](https://zcp.zsoftly.ca/blog/6.md): Updates, engineering stories, and tutorials from the ZSoftly Cloud Platform team. - [Blog](https://zcp.zsoftly.ca/blog/7.md): Updates, engineering stories, and tutorials from the ZSoftly Cloud Platform team. - [Blog](https://zcp.zsoftly.ca/blog/8.md): Updates, engineering stories, and tutorials from the ZSoftly Cloud Platform team. - [Blog](https://zcp.zsoftly.ca/blog/9.md): Updates, engineering stories, and tutorials from the ZSoftly Cloud Platform team. - [A New Mark for the ZCP Developer Cloud](https://zcp.zsoftly.ca/blog/a-new-mark-for-the-zcp-developer-cloud.md): The story behind the new ZCP visual mark and how it represents a layered developer cloud with sovereignty at its core. - [Bypassing VPN Failure with AWS SSM Port Forwarding](https://zcp.zsoftly.ca/blog/bypassing-vpn-failure-aws-ssm-port-forwarding.md): A real-world scenario demonstrating how to maintain secure access to critical servers when VPN fails. Learn how AWS SSM Port Forwarding provides out-of-band emergency access for Windows and Linux servers through secure tunneling. - [Canadian Cloud Sovereignty Requires More Than an Address](https://zcp.zsoftly.ca/blog/canadian-cloud-sovereignty-requires-more-than-a-canadian-address.md): Data residency is essential, but sovereign cloud also depends on ownership, legal jurisdiction, operations, and control of the compute stack. - [Announcements](https://zcp.zsoftly.ca/blog/category/announcements/2.md): Product launches, new features, and platform updates. - [Announcements](https://zcp.zsoftly.ca/blog/category/announcements.md): Product launches, new features, and platform updates. - [Company](https://zcp.zsoftly.ca/blog/category/company/2.md): Team updates, partnerships, and the Canadian cloud industry. - [Company](https://zcp.zsoftly.ca/blog/category/company.md): Team updates, partnerships, and the Canadian cloud industry. - [Engineering](https://zcp.zsoftly.ca/blog/category/engineering/2.md): Architecture decisions, performance, and how we build ZCP. - [Engineering](https://zcp.zsoftly.ca/blog/category/engineering/3.md): Architecture decisions, performance, and how we build ZCP. - [Engineering](https://zcp.zsoftly.ca/blog/category/engineering/4.md): Architecture decisions, performance, and how we build ZCP. - [Engineering](https://zcp.zsoftly.ca/blog/category/engineering/5.md): Architecture decisions, performance, and how we build ZCP. - [Engineering](https://zcp.zsoftly.ca/blog/category/engineering.md): Architecture decisions, performance, and how we build ZCP. - [Tutorials](https://zcp.zsoftly.ca/blog/category/tutorials/2.md): Step-by-step guides for building on ZSoftly Cloud Platform. - [Tutorials](https://zcp.zsoftly.ca/blog/category/tutorials/3.md): Step-by-step guides for building on ZSoftly Cloud Platform. - [Tutorials](https://zcp.zsoftly.ca/blog/category/tutorials.md): Step-by-step guides for building on ZSoftly Cloud Platform. - [MaaS, IaaS, PaaS, SaaS Explained: The Cloud Service Model Stack](https://zcp.zsoftly.ca/blog/cloud-service-models-explained.md): Understand the four cloud service models (MaaS, IaaS, PaaS, SaaS) in plain terms, with NIST definitions and ZCP services mapped to each layer. - [Cloud Security Posture Management (CSPM) for SMBs: How to Achieve Enterprise-Grade Security on a Mid-Market Budget](https://zcp.zsoftly.ca/blog/cspm-for-smbs-enterprise-security-mid-market-budget.md): Learn how mid-market companies ($10M-$100M revenue) can achieve enterprise-grade cloud security at 20% of the cost using AWS native tools. Includes practical implementation roadmap, cost breakdowns, and proven strategies for CSPM implementation without dedicated security teams. - [Debian 12 and 13 on ZCP: Regions, Sizing, and Best Practices](https://zcp.zsoftly.ca/blog/debian-images-on-zcp-availability-boundary.md): Debian 12 and 13 are available in YOW-1 and YUL-1. Review ZCP sizing guidance, operational practices, and official Debian cloud references. - [AWS EKS Auto Mode: What It Is, How It Works, and When to Use It](https://zcp.zsoftly.ca/blog/eks-auto-mode-eliminate-platform-team-overhead.md): AWS EKS Auto Mode automates the entire Kubernetes data plane. This guide covers AWS managed services pricing, the cost model ($0.10/hr), and a decision framework for evaluating whether Auto Mode fits your AWS DevOps workloads. - [How We Cut EKS Costs 62% by Rethinking Node Architecture](https://zcp.zsoftly.ca/blog/eks-node-consolidation-platform-nodepool-karpenter.md): Our sandbox cluster ran 8 EC2 instances 24/7 costing $260/month. Most were idle overnight. By separating platform services from time-based workloads and recognizing CI/CD managers as 24/7 services, we consolidated to 3 nodes saving $160/month while improving reliability. - [Email Security Needs an Owner](https://zcp.zsoftly.ca/blog/email-security-needs-an-owner.md): A practical email security operating model for solo founders, startups, and security teams: ownership, sender authentication, access control, validation, and review. - [Even On-Prem, Servers Should Be Cattle, Not Pets](https://zcp.zsoftly.ca/blog/even-on-prem-servers-should-be-cattle-not-pets.md): How ZSoftly redesigned on-premises authoritative DNS with an independently serving PowerDNS secondary, TSIG-authenticated zone transfers, DNSSEC validation, and alert tuning to cut pager noise, so no single server is a point of failure. - [Full AWS Observability With Open Source Tools](https://zcp.zsoftly.ca/blog/full-aws-observability-open-source.md): CloudWatch gives you metrics. It does not give you actionable dashboards, historical trends, or alerts. We built a four-container open source stack that turns raw AWS data into full observability — no agents on app servers, no licensing costs, auto-discovery via AWS tags. - [GitOps + Kubernetes Cost Optimization: Reducing Cloud Spend by 80% Without Sacrificing Performance](https://zcp.zsoftly.ca/blog/gitops-kubernetes-cost-optimization-reduce-cloud-spend.md): Spot instances can cut compute costs by up to 90%. Learn actionable strategies for SMBs running Kubernetes, including GitOps-driven resource right-sizing, cost visibility in CI/CD pipelines, and real-world examples of dramatic cost reductions. - [Blog](https://zcp.zsoftly.ca/blog.md): Updates, engineering stories, and tutorials from the ZSoftly Cloud Platform team. - [Intel Xeon Compute Now Available in Montréal (YUL-1)](https://zcp.zsoftly.ca/blog/intel-cpu-compute-yul.md): Deploy Intel Xeon Gold workloads in ZCP YUL-1: general-purpose ci2 and memory-optimized cim2 plans, custom sizing, and Kubernetes node capacity at the same list prices as equivalent AMD sizes. - [Introducing ZSoftly Cloud Platform](https://zcp.zsoftly.ca/blog/introducing-zsoftly-cloud-platform.md): ZCP is an independent sovereign cloud running on bare metal we own, with two live regions (YUL-1, YOW-1) and five more planned across North America and Europe. - [Kubernetes FinOps for Growing Companies: From Chaos to Cost Control](https://zcp.zsoftly.ca/blog/kubernetes-finops-cost-control-growing-companies.md): Establish standardized labeling conventions for cost attribution, implement cost budgets at team level, and automate resource cleanup. Includes practical templates for TTL policies and integration with existing DevOps workflows. - [Local vs Replicated Block Storage in YUL-1](https://zcp.zsoftly.ca/blog/local-vs-distributed-yul-root-storage-results.md): Compare local NVMe, local SATA SSD, and shared replicated block storage in YUL-1. Review measured I/O, pricing, recovery boundaries, and workload fit. - [Making Cloud Management Simpler on ZCP](https://zcp.zsoftly.ca/blog/making-cloud-management-simpler-on-zcp.md): How the ZCP portal organizes cloud work by project, what you manage from one account, and the design rules behind the ZCP console. - [The Mid-Market DevSecOps Playbook: Integrating Security into Your CI/CD Pipeline Without Breaking the Bank](https://zcp.zsoftly.ca/blog/mid-market-devsecops-playbook-security-cicd-pipeline.md): Integrate SAST, DAST, and secret scanning into your CI/CD pipeline using open-source alternatives to expensive security tools. Step-by-step implementation guide with GitLab CI/CD, AWS CodePipeline, and ROI calculations for security automation. - [Object vs block vs file storage: which one to use and when](https://zcp.zsoftly.ca/blog/object-block-file-storage-compared.md): Object, block, and file storage solve different problems. A short technical primer with real cost-per-GB numbers from ZCP and clear selection rules. - [One foundation, two products: ZCP private and public cloud architecture](https://zcp.zsoftly.ca/blog/one-foundation-two-products.md): How ZCP delivers both a private cloud and a public cloud from the same underlying open-source stack. The CMP layer separates the two delivery models. - [Open Letter: Teach Canadians to Build Cloud Infrastructure](https://zcp.zsoftly.ca/blog/open-letter-canadian-colleges-universities-teach-cloud-building.md): A call for Canadian colleges, universities, and tech boot camps to teach open cloud infrastructure alongside AWS, Azure, and VMware. - [How We Built ZCP: Proxmox, Ceph, and CloudStack](https://zcp.zsoftly.ca/blog/our-infrastructure-stack.md): A look inside ZCP's infrastructure stack. Why we chose open-source components, how they fit together, and what it means for reliability and performance. - [ZCP Blocks Outbound SMTP Port 25 by Default](https://zcp.zsoftly.ca/blog/outbound-smtp-port-25-blocked-by-default.md): ZCP blocks outbound SMTP port 25 by default. Learn which mail ports remain open, how to send email through a relay, and how to request an exception. - [ZCP Billing Modes Explained: Prepaid vs Postpaid vs Manual](https://zcp.zsoftly.ca/blog/payment-modes-on-zcp-prepaid-postpaid-manual.md): A clear explanation of ZCP payment modes. What Prepaid, Postpaid, and Manual billing mean, how each one works, and how the choice at signup affects your account. - [Building Private Cloud Infrastructure with Apache CloudStack - Architecture and Design Decisions](https://zcp.zsoftly.ca/blog/private-cloud-architecture-cloudstack.md): Why private cloud matters for Canadian businesses, how CloudStack provides enterprise IaaS capabilities, and the key architectural decisions for deploying production-ready private cloud infrastructure. - [Public vs private vs hybrid cloud: when each fits which workload](https://zcp.zsoftly.ca/blog/public-private-hybrid-cloud.md): A short, practical guide to public, private, and hybrid cloud deployment. When each fits, what to watch for, and how to combine them. - [How AWS Route53 Profiles Solved DNS Challenges in SMB, Corporate, and Startup Environments](https://zcp.zsoftly.ca/blog/route53-profiles-multi-account-dns-management.md): Real-world case studies showing how Route53 Profiles transformed DNS management for organizations of all sizes. Learn how to centralize DNS configurations across multiple AWS accounts and VPCs, eliminating complexity and ensuring consistent, secure access to critical resources. - [Sample Montreal cloud rack: hardware, cost, and 5-10 year payback](https://zcp.zsoftly.ca/blog/sample-cloud-rack-montreal.md): A four-server rack at a Montreal colo delivering IaaS, PaaS, and storage as a private or public cloud, with 5 to 10 year cost math against AWS. - [Building a Secure Cloud Infrastructure: The Essential AWS Security Stack for Mid-Market Companies](https://zcp.zsoftly.ca/blog/secure-cloud-infrastructure-aws-security-stack-mid-market.md): Multi-layered security approach including CloudWatch monitoring, CloudTrail auditing, and AWS Config compliance. Phased implementation roadmap with budget considerations, automation scripts, and IaC templates to achieve compliance without dedicated security teams. - [Why We Moved From SigNoz to the Grafana Stack](https://zcp.zsoftly.ca/blog/signoz-to-grafana-stack.md): We picked SigNoz for its OpenTelemetry-native approach. A few months in, we moved to Prometheus, Loki, Alertmanager, and Grafana, with Grafana Alloy as the single collection agent. Here is the honest breakdown. - [To the ZSoftly Engineering Team](https://zcp.zsoftly.ca/blog/thank-you-zsoftly-engineering.md): A thank you to the team waking up to breaking changes, making hard decisions under pressure, and pushing the limits of what we build. - [The ZCP Console Gets Its Own Brand](https://zcp.zsoftly.ca/blog/the-console-now-wears-its-own-mark.md): Why the ZCP console now carries ZCP branding rather than ZSoftly, and what changed: wordmarks, provider tiles, region and zone icons, and project icons. - [What is cloud computing? NIST definition, five characteristics, four models](https://zcp.zsoftly.ca/blog/what-is-cloud-computing.md): NIST defines cloud computing with five essential characteristics and four deployment models. A short, technical primer for decision-makers. - [What is IaaS? Infrastructure-as-a-Service Explained (with ZCP examples)](https://zcp.zsoftly.ca/blog/what-is-iaas-infrastructure-as-a-service.md): IaaS gives you raw compute, storage, and networking under your control. NIST definition, the three pillars, and what real IaaS looks like on ZCP. - [What is Metal-as-a-Service (MaaS)? Bare-Metal Provisioning Explained](https://zcp.zsoftly.ca/blog/what-is-maas-metal-as-a-service.md): Metal-as-a-Service explained: how Canonical MAAS and OpenStack Ironic provision bare-metal servers via API, and when to choose MaaS over virtual machines. - [What is PaaS? Platform-as-a-Service Explained (with ZCP examples)](https://zcp.zsoftly.ca/blog/what-is-paas-platform-as-a-service.md): PaaS abstracts the runtime so teams ship faster. NIST definition, the control trade-offs, and how ZCP delivers managed Kubernetes and Observability today. - [What is SaaS (Software-as-a-Service)? A Technical Definition](https://zcp.zsoftly.ca/blog/what-is-saas-software-as-a-service.md): SaaS defined per NIST SP 800-145, the CAPEX-to-OPEX shift, and why SaaS providers run their apps on IaaS underneath. Plain-language guide for buyers. - [What is software-defined networking? ONF definition, OpenFlow, and cloud VPCs](https://zcp.zsoftly.ca/blog/what-is-software-defined-networking.md): SDN decouples the network control plane from the forwarding plane. A primer covering the ONF definition, OpenFlow, and how cloud VPCs depend on it. - [What is Sovereign Cloud? Data, Operations, and Jurisdiction](https://zcp.zsoftly.ca/blog/what-is-sovereign-cloud.md): Sovereign cloud is a category, not a feature. The three layers, data residency, operational, and corporate sovereignty, and why procurement asks in 2026. - [Private AI on ZCP YUL-1: Compute, Cost, and Control](https://zcp.zsoftly.ca/blog/what-we-learned-running-ollama-on-zcp-intel-yul.md): A business-focused report on running Ollama and Open WebUI on a 64 GB Intel VM in ZCP YUL-1, including cost, performance, security, and deployment choices. - [Why We Are Building a Canadian-Owned Cloud Platform](https://zcp.zsoftly.ca/blog/why-canadian-cloud.md): Data residency, pricing transparency, and accountability. The case for Canadian cloud infrastructure owned and operated in Canada. - [ZCP Marketplace Apps: 64 Preconfigured Images for Self-Hosted Software](https://zcp.zsoftly.ca/blog/zcp-marketplace-app-images.md): Explore the 64 ZCP marketplace app images available today, how first-boot setup works, and which image to choose for databases, DevOps, monitoring, VPN, CMS, AI, and business apps. - [ZCP Pricing V2: Compute and Storage Sold Separately](https://zcp.zsoftly.ca/blog/zcp-pricing-v2-compute-and-storage-sold-separately.md): ZCP plans now cover CPU and memory only. Size the root disk in GB, pay per GB by tier, and keep existing servers on their current plan and price. - [ZCP Q3 2026 Update: Shipped Features and Work in Progress](https://zcp.zsoftly.ca/blog/zcp-q3-2026-update.md): What shipped on ZCP in Q3 2026, plus an October update on backup billing, Kubernetes billing, the Store, Marketplace emails, and account security. - [Zero-Trust Access with AWS SSM: Eliminating SSH Keys and Bastion Hosts Forever](https://zcp.zsoftly.ca/blog/zero-trust-access-aws-ssm-eliminate-ssh-keys-bastion-hosts.md): Learn how AWS Systems Manager Session Manager enables secure access without SSH keys, open ports, or bastion hosts. Includes practical IAM policy templates, cost savings analysis, and complete migration strategy from traditional SSH to SSM-based access. ## Optional - [Careers - Join Our Growing Team](https://zcp.zsoftly.ca/about/careers.md): Join the cloud engineers building an independent Canadian sovereign cloud. We're building a real alternative to the hyperscalers. Explore career opportunities at ZSoftly. - [About ZSoftly](https://zcp.zsoftly.ca/about.md): ZSoftly is a cloud and DevOps engineering company. We design, build and run infrastructure, Kubernetes and delivery pipelines for clients in Canada, the US and the UK. We work on your cloud, your hardware or the ZSoftly Cloud Platform. - [Our Story - How ZSoftly Built a Sovereign Cloud](https://zcp.zsoftly.ca/about/our-story.md): How ZSoftly grew from a team of cloud engineers into an independent, Canadian-owned sovereign cloud platform, built to end hyperscaler lock-in, egress bills, and foreign data jurisdiction. - [Partners](https://zcp.zsoftly.ca/about/partners.md): ZSoftly partners with leading data center operators to deliver private cloud, bare metal, and colocation services across Canada, the USA, the United Kingdom, Europe, and Australia. - [Built on Proven Open Source](https://zcp.zsoftly.ca/about/tech-stack.md): ZSoftly Cloud Platform runs on mature open-source cloud infrastructure: CloudStack, KVM, Ceph, Kubernetes, Prometheus, Grafana, Alertmanager, and standard APIs. Owned and operated end to end by ZSoftly engineers. - [Vision & Values - What Drives ZSoftly](https://zcp.zsoftly.ca/about/vision-values.md): ZSoftly's mission to give businesses a sovereign alternative to the hyperscalers, our vision for an independent Canadian cloud, and the core values that guide everything we do. - [Why a Canadian Sovereign Cloud](https://zcp.zsoftly.ca/about/why-canadian-team.md): Why organizations worldwide choose a Canadian sovereign cloud: data outside US jurisdiction, $0 egress, predictable CAD pricing, certified facilities, and no hyperscaler lock-in. Serving the USA, Europe, LATAM, and Asia. - [Why Choose Us - What Sets ZSoftly Apart](https://zcp.zsoftly.ca/about/why-choose-us.md): What makes ZSoftly different: an independent Canadian sovereign cloud with $0 egress, predictable CAD pricing, an open-source foundation, certified facilities, and no hyperscaler lock-in. - [ZCP Brand Assets](https://zcp.zsoftly.ca/brand-assets.md): Download official ZCP logo assets in SVG and PNG formats for product, documentation, and customer materials. - [Careers - Join Our Growing Team](https://zcp.zsoftly.ca/careers.md): Join the cloud engineers building an independent Canadian sovereign cloud. We're building a real alternative to the hyperscalers. Explore career opportunities at ZSoftly. - [Join the ZCP Community](https://zcp.zsoftly.ca/community.md): Join developers, operators, and teams building on an independent sovereign cloud platform operated from Canada. - [Terms of Service & Privacy Policy](https://zcp.zsoftly.ca/legal/accept.md): Review the ZSoftly Cloud Platform Terms of Service and Privacy Policy before creating your account. - [Privacy Policy](https://zcp.zsoftly.ca/legal/privacy.md): How ZSoftly Technologies Inc. collects, uses, and protects your personal information. Compliant with PIPEDA, Quebec Law 25, and applicable Canadian privacy legislation. - [Terms of Service](https://zcp.zsoftly.ca/legal/terms.md): Terms and conditions governing use of ZSoftly Cloud Platform. Governed by the laws of Ontario, Canada. - [Architecture Designer Preview Limitations](https://zcp.zsoftly.ca/resources/architecture-designer-preview.md): Preview limitations for the ZCP Architecture Designer and generated starter CLI scripts. - [Case Studies - Client Success Stories](https://zcp.zsoftly.ca/resources/case-studies.md): Real results from real clients. AWS cloud optimization, DevOps transformation, and security compliance case studies. - [Guides - Cloud, DevOps & Security Resources](https://zcp.zsoftly.ca/resources/guides.md): Free technical guides on AWS, cloud migration, DevOps, security, and compliance. - [Resources](https://zcp.zsoftly.ca/resources.md): Guides, whitepapers, case studies and engineering articles from the cloud and DevOps projects ZSoftly delivers and the platform it runs. - [Configuration Management at Platform Scale with Ansible](https://zcp.zsoftly.ca/resources/whitepapers/ansible-configuration-management.md): How to run one Ansible repository across many services and sites. It covers numbered playbooks, site-scoped inventories and group_vars, and idempotent roles with precheck and opt-in modes. It also covers prune gates with ownership predicates, gated CI runs, Vault, drift detection and six anonymised production lessons. - [CI/CD Pipelines for Infrastructure as Code](https://zcp.zsoftly.ca/resources/whitepapers/cicd-iac-guide.md): A reference architecture for Terraform, Ansible and CloudFormation pipelines on AWS: OIDC role chaining, OU-based accounts with StackSets, locked and versioned state, and patterns for GitHub Actions, GitLab CI and Jenkins. - [Building and Operating a Private Cloud on Apache CloudStack and Ceph](https://zcp.zsoftly.ca/resources/whitepapers/cloudstack-ceph-private-cloud.md): A practitioner guide to how ZSoftly builds and runs the ZSoftly Cloud Platform. It covers reference architecture, Ceph pool and placement design, VXLAN networking, and numbered Ansible playbooks. It also covers CloudStack and Ceph upgrades, host patching, per-region monitoring and a readiness checklist. - [Compute and Storage, Priced Separately](https://zcp.zsoftly.ca/resources/whitepapers/compute-storage-priced-separately.md): ZCP Pricing V2 explained: compute-only plans, a root disk you size in GB, six storage tiers, a worked price example, how to size a disk, and what stays the same for existing servers. - [Enterprise EKS Auto Mode Migration Roadmap](https://zcp.zsoftly.ca/resources/whitepapers/eks-migration-guide.md): A 20-week, ten-phase plan for moving Kubernetes workloads to Amazon EKS Auto Mode, with SigNoz, Falco, Trivy and Argo CD, one-app-at-a-time cutovers, cold-standby disaster recovery and a worked cost example at AWS list prices. - [Whitepapers](https://zcp.zsoftly.ca/resources/whitepapers.md): Free, 10-page whitepapers from ZSoftly engineers on object storage, private cloud, DNS, Ansible, EKS migration and CI/CD. Download the PDF, no form. - [Object Storage by Industry](https://zcp.zsoftly.ca/resources/whitepapers/object-storage-by-industry.md): How six industries use S3-compatible object storage, what ZCP Object Storage supports today, how to choose between ZCP Object Storage and dedicated ZSoftly Cloud Storage, and a migration checklist. - [Running Authoritative DNS with PowerDNS and dnsdist](https://zcp.zsoftly.ca/resources/whitepapers/powerdns-authoritative-dns.md): A reference design for authoritative DNS on PowerDNS with dnsdist in front. It covers API-driven zone management, signed zone transfers to a secondary with its own local data, cache and delegation practice, and one-site-at-a-time patching. It also lists the eight alerts we keep and six anonymised production lessons. - [ZCP Roadmap](https://zcp.zsoftly.ca/roadmap.md): See what is available, in preview, being built, and being explored for the ZSoftly Cloud Platform. - [Our Team - The Engineers Behind the Platform](https://zcp.zsoftly.ca/team.md): Meet the cloud engineers who build and operate the ZSoftly sovereign cloud platform, and who stay on the line to support it. Deep expertise in cloud computing, orchestration, and deployment across a diverse portfolio: OpenStack, Apache CloudStack, AWS, Azure, VMware vSphere, Kubernetes, and more. - [Product Updates](https://zcp.zsoftly.ca/updates.md): Follow shipped platform features, CLI releases, Marketplace updates, and documentation changes for ZCP.