Keos
KeosAutonomous edge runtime

A complete Kubernetes cluster
on every site, autonomously.

Keos is the on-site runtime of the Pocteo Platform. An immutable, self-healing Kubernetes node that boots from bare metal, survives weeks without WAN, and keeps your workloads running where the data is produced.

Keos runtime
Why KEOS?

The big idea, in three slides.

A plain-English walkthrough for non-technical visitors — analogy, business value, and the promise.

Why KEOS · 01 / 03

Let's Keep It Simple

How Pocteo & KEOS work together, explained in plain English.

On the device

KEOS: The Smartphone OS

Think of KEOS as an unbreakable, highly secure operating system (like iOS or Android) built specifically for industrial machines, EV chargers, or smart devices. It's built to stay up and running even if it loses internet connection.

In the cloud

Pocteo: The Control Tower

Pocteo Platform is the central control tower. It's a single dashboard that lets you monitor, update, and repair your entire fleet of machines globally with just one click — without ever sending a technician on-site.

Edge runtime

Engineered for headless sites and unreliable links.

Keos is what runs at the factory, the vessel, the wind farm, the store. It is designed to never need a human on site.

Immutable, network-bootable OS

Edge nodes PXE/iPXE-boot a signed, immutable image. No SSH, no drift, no hand-edits. A/B partitions deliver atomic upgrades with automatic rollback.

Disconnected by design

Operates for days or weeks without WAN. Local Git mirror, local container registry, local control loops. When the link returns, state reconciles in the background.

P2P mesh between sites

Neighboring edge clusters sync over an encrypted WireGuard mesh with Cilium Cluster Mesh — workloads keep moving even when the cloud is unreachable.

Ruggedized, low-footprint

Runs on 2-core gateways, industrial PCs, vessels and vehicles. Tolerates power cuts, brown-outs and reboots with deterministic recovery.

Air-gap ready

Signed artifacts, sealed secrets, local Vault-backed identity. Edge API servers are never internet-exposed; control flows over egress-only mTLS tunnels.

GitOps to the node

Embedded FluxCD reconciles OS, Kubernetes, CNI, storage and workloads from one declarative manifest. Same blueprint on every site.

Cloud × Edge

Governed from Pocteo Platform. Run by Keos.

One declarative manifest in Pocteo Platform becomes the live state of every Keos cluster — online, intermittent or fully air-gapped.

Cloud

Declare

Define fleet, modes, OS, CNI, workloads in one manifest.

Sync

Distribute

Signed artifacts replicate to every site over mTLS or local Git mirror.

Edge

Reconcile

Each Keos cluster drives its own state — autonomously, forever.

Specifications

What runs on a Keos node.

CapabilityDetails
Form factorsBare metal · Industrial PC · Vehicle gateway · VM (Proxmox / vSphere / KVM)
Minimum footprint2 vCPU · 4 GB RAM · 32 GB storage
Operating systemImmutable, signed, A/B partitioned (Talos-inspired)
KubernetesUpstream Kubernetes 1.31, single-node or HA
NetworkingCilium eBPF · L2/BGP load balancing · WireGuard mesh
StorageLocal-path · Longhorn · OpenEBS
SecuritymTLS · Vault · Cert-Manager · Kyverno · Falco · Tetragon
ConnectivityOnline · Intermittent · Air-gapped
Cilium eBPFWireGuard meshFluxCD embeddedLocal Git mirror

Bring a unified, autonomous operating plane to every edge site.