
A complete Kubernetes cluster
on every site, autonomously.
Keos is the on-site runtime of the Pocteo Platform. An immutable, self-healing Kubernetes node that boots from bare metal, survives weeks without WAN, and keeps your workloads running where the data is produced.

The big idea, in three slides.
A plain-English walkthrough for non-technical visitors — analogy, business value, and the promise.
Let's Keep It Simple
How Pocteo & KEOS work together, explained in plain English.
KEOS: The Smartphone OS
Think of KEOS as an unbreakable, highly secure operating system (like iOS or Android) built specifically for industrial machines, EV chargers, or smart devices. It's built to stay up and running even if it loses internet connection.
Pocteo: The Control Tower
Pocteo Platform is the central control tower. It's a single dashboard that lets you monitor, update, and repair your entire fleet of machines globally with just one click — without ever sending a technician on-site.
Engineered for headless sites and unreliable links.
Keos is what runs at the factory, the vessel, the wind farm, the store. It is designed to never need a human on site.
Immutable, network-bootable OS
Edge nodes PXE/iPXE-boot a signed, immutable image. No SSH, no drift, no hand-edits. A/B partitions deliver atomic upgrades with automatic rollback.
Disconnected by design
Operates for days or weeks without WAN. Local Git mirror, local container registry, local control loops. When the link returns, state reconciles in the background.
P2P mesh between sites
Neighboring edge clusters sync over an encrypted WireGuard mesh with Cilium Cluster Mesh — workloads keep moving even when the cloud is unreachable.
Ruggedized, low-footprint
Runs on 2-core gateways, industrial PCs, vessels and vehicles. Tolerates power cuts, brown-outs and reboots with deterministic recovery.
Air-gap ready
Signed artifacts, sealed secrets, local Vault-backed identity. Edge API servers are never internet-exposed; control flows over egress-only mTLS tunnels.
GitOps to the node
Embedded FluxCD reconciles OS, Kubernetes, CNI, storage and workloads from one declarative manifest. Same blueprint on every site.
Governed from Pocteo Platform. Run by Keos.
One declarative manifest in Pocteo Platform becomes the live state of every Keos cluster — online, intermittent or fully air-gapped.
Declare
Define fleet, modes, OS, CNI, workloads in one manifest.
Distribute
Signed artifacts replicate to every site over mTLS or local Git mirror.
Reconcile
Each Keos cluster drives its own state — autonomously, forever.
What runs on a Keos node.
| Capability | Details |
|---|---|
| Form factors | Bare metal · Industrial PC · Vehicle gateway · VM (Proxmox / vSphere / KVM) |
| Minimum footprint | 2 vCPU · 4 GB RAM · 32 GB storage |
| Operating system | Immutable, signed, A/B partitioned (Talos-inspired) |
| Kubernetes | Upstream Kubernetes 1.31, single-node or HA |
| Networking | Cilium eBPF · L2/BGP load balancing · WireGuard mesh |
| Storage | Local-path · Longhorn · OpenEBS |
| Security | mTLS · Vault · Cert-Manager · Kyverno · Falco · Tetragon |
| Connectivity | Online · Intermittent · Air-gapped |
