Skip to content

Operations is
not a matter of trust

Who operates which layer, how long an event is retained, what ingestion costs per gigabyte — these are facts, not promises. On this page, they are complete and verifiable.

Metrics and alerts are in preparation and without a committed date — what works in their place today is in the “Metrics” section.

Key facts
Log streams
8 services
Retention in the account
7 to 730 days
Ingestion
€0.0540$0.0626 per GB
Retention classes
3
Cheapest class
€0.0003$0.0003 per GB per month
Export schema
FOCUS 1.1, daily
Net prices plus 19% VAT. The tier prices are derived from the storage products; the calculation is in the log platform section.
Product lines
5
Responsibility shown across 6 layers
Service logs
8
without add-ons, without an agent in the guest system
Ingestion
€0.0540$0.0626/GB
derived from the NVMe storage price
20 GB per day
€65.01$75.41
Ingestion and ten years of retention, per month

What happens when something happens

Operations is a chain of four steps, and it always breaks in the same place: where nobody has defined who acts. Each step below therefore carries two details — what it costs and how long it takes.

  1. 01

    Measure

    There are three types of recording, and they answer three different questions. A measurement — a metric — is a number with a timestamp, such as utilisation or response time. A log is a line about a single event, i.e. who triggered what and when. A trace follows a single request across all involved services.

    What it costs

    €0.0540$0.0626 / GB

    Only for your own streams. Every service writes the 8 service logs on its own, without any add-ons and without agents in the guest system.

    How long it takes

    under 5 seconds

    This is how long it takes from arrival to queryability: under 5 s on average, under 20 s in the 99th percentile. Indexing happens upon arrival, not during the search — which is why this time does not depend on how old the searched period is.

  2. 02

    Alert

    A recording that nobody looks at is not operations. Rules continuously compare against a threshold and report to on-call schedules, to webhooks — calls to an address of your choice — or to an existing system. If you already have your own, you can attach a stream to it as a forwarder.

    What it costs

    included in the ingestion fee

    Queries, saved queries, forwarding and moving between classes cost nothing extra. Only the ingested and retained volume is billed.

    How long it takes

    24-hour backlog

    This is how long a forwarder pauses if the destination is down. After that, it reports a loss instead of hiding it — a silent gap in the log would be the worse state.

  3. 03

    Intervene

    Now only one question counts: who is allowed to act, and who has to. The answer is not in the contract, but in the matrix in the next section — level by level, with exactly three possible values per field.

    What it costs

    €0.00$0.00 to €1,890.00$2,192.40 / month

    The basic level “Basic” is included in the price; “Critical” is the fastest. None of these levels shifts the boundary between us and you — it only shifts the response time.

    How long it takes

    15 min to 8 h

    Initial response to a critical fault, depending on the support level. For the 5 product lines, it is specified across 6 levels who is even allowed to fix the fault.

  4. 04

    Prove

    After the incident comes the question of what exactly happened — from your own audit, from an auditor or from a customer. It can only be answered if the recording survived the incident.

    What it costs

    from €0.0003$0.0003 / GB per month

    This is the last of the 3 retention classes. The first costs €0.0099$0.0115 per GB and month — the difference is the reason why a record moves instead of staying put.

    How long it takes

    7 days to 10 years

    Service logs remain in the account for 7 to 730 days and are then deleted, not greyed out. In the log platform, the cascade reaches up to day 3,650. From the archive, the following applies: Provisioning within 12 h.

A narrow sensor mast on the front wall of a cold aisle containment, three black measuring heads at three heights, the cables routed downwards in a straight bundle.
Sensor mast on the front wall of a cold aisle containment, three measuring heads at three heights. What is created here is step 01: a measurement — a number with a timestamp.

Who operates what — layer by layer

Operations rarely fails because of technology and almost always because of the line nobody read. That is why the breakdown is shown here side by side for all product lines: six layers from the power socket to your data, three possible answers per field.

  • ENTRONYX CLOUD

    We manage this layer and are liable for its outcome.

  • Shared

    Both parties act on the same layer in separate areas.

  • Customer

    You manage this layer; we have no access there.

Responsibility per level, not per contract. “Shared” means: both sides act on the same level in separate places — where the seam runs is stated below the matrix.

  • Public Cloud3 of 6 with us
    Location and power
    ENTRONYX CLOUD
    Hardware and firmware
    ENTRONYX CLOUD
    Virtualisation
    ENTRONYX CLOUD
    Operating system
    Shared
    Runtime and application
    Customer
    Data and backup
    Shared
  • Private Cloud3 of 6 with us
    Location and power
    ENTRONYX CLOUD
    Hardware and firmware
    ENTRONYX CLOUD
    Virtualisation
    ENTRONYX CLOUD
    Operating system
    Customer
    Runtime and application
    Customer
    Data and backup
    Shared
  • Bare Metal1 of 6 with us
    Location and power
    ENTRONYX CLOUD
    Hardware and firmware
    Shared
    Virtualisation
    Customer
    Operating system
    Customer
    Runtime and application
    Customer
    Data and backup
    Customer
  • VPS3 of 6 with us
    Location and power
    ENTRONYX CLOUD
    Hardware and firmware
    ENTRONYX CLOUD
    Virtualisation
    ENTRONYX CLOUD
    Operating system
    Shared
    Runtime and application
    Customer
    Data and backup
    Shared
  • Web hosting4 of 6 with us
    Location and power
    ENTRONYX CLOUD
    Hardware and firmware
    ENTRONYX CLOUD
    Virtualisation
    ENTRONYX CLOUD
    Operating system
    ENTRONYX CLOUD
    Runtime and application
    Shared
    Data and backup
    Shared

Where the seam runs — one sentence per product line

A mark in the table decides nothing as long as it is not clear where the responsibility changes. Each line has exactly one such place.

Public Cloud

3 of 6 levels with us

We provide the image and keep it up to date; as soon as an instance starts from it, you patch it. Block storage is replicated three times by us — this is not a backup, you plan that.

Public Cloud in detail

Private Cloud

3 of 6 levels with us

The boundary is at the guest system: everything below it — hardware, firmware, hypervisor, datastore — belongs to us, everything in the guest belongs to you. We have no access there, not even on request.

Private Cloud in detail

Bare Metal

1 of 6 levels with us

We replace defective components, you determine the timing of a firmware version. Above the firmware we have no access and no visibility — not even to the state of your data.

Bare Metal in detail

VPS

3 of 6 levels with us

The core of the host system and the emergency console belong to us, the guest system to you. We create weekly snapshots; you decide whether their state is sufficient for your recovery.

VPS in detail

Web hosting

4 of 6 levels with us

We operate the web server, PHP and database and keep them up to date; you choose the major version and are responsible for the application code. The daily backup runs for 14 days — you retrieve anything needed beyond that.

Web hosting in detail
A server chassis from above, the row of fans spins evenly, the air shimmers over the copper heat pipes.

What each service writes by default

No add-on to book, no agents on the guest system and no configuration. The periods below are maximum values in the account: after that, the record is deleted, not greyed out. If you need to keep records for longer, forward them.

Service logs per product: event types, retention in the account and stream identifier
ServiceEvent typesRetentionStream
Public Cloud instancesStart, stop, resize, migration between hosts, console access90 dayscompute.instance
Object StorageS3 requests with method, key, status code, signature error, object lock expiration30 daysstorage.object.access
Load BalancerAccess log per request, health check state change, TLS negotiation errors7 daysnetwork.lb.access
Managed KubernetesAPI server audit log, scheduling decisions, restart of control components30 daysk8s.audit
Managed databasesConnection establishment, slow queries above threshold, failover, recovery points30 daysdb.engine
Dedicated servers (BMC)Power supply and fan status, temperature thresholds, RAID events, boot processes180 daysmetal.bmc
Account and identityLogins, failed logins, role changes, key creation and revocation400 days (13 months)iam.audit
BillingBooking items per resource and day, budget alerts, contract changes730 days (24 months)billing.ledger

Retrieval via the API

Every stream is accessible via the same interface, with the same identifier shown in the table. Three ways, three use cases — the choice depends on the data volume, not the plan.

  • GETPagination via the account APIOne period, one stream, one page cursor. Response as ndjson — one JSON line per record —, maximum 10,000 records per page. Intended for lookups and small evaluations, not for exporting entire days.
  • SIGSigned export of a periodA job generates a compressed file and a temporary address. For periods up to the full retention period of a stream; the file contains one checksum per hour.
  • SUBContinuous forwardingA stream is permanently attached to a destination and stored there as soon as it is created. The backlog is kept for 24 hours; after that, the forwarding reports a loss instead of hiding it.
Retrieval and forwardingbash
# Failed requests of a Load Balancer, last six hours
$ curl -sS \
    -H "Authorization: Bearer $ENTRONYX_TOKEN" \
    "https://api.entronyx.cloud/v1/logs/network.lb.access\
?von=2026-08-29T06:00:00Z&bis=2026-08-29T12:00:00Z\
&filter=status>=500&limit=1000"
 
# Write the same period permanently to a separate bucket
$ entronyx logs weiterleiten network.lb.access \
    --ziel s3://protokolle-prod/lb/ --format parquet
The filter expression is the same as in the logging platform; the command line calls the same interface as curl.

Forwarding to your own systems

A stream can go to multiple destinations simultaneously, filtered or complete. The destination does not have to be with us — the retention period in the account ends, your copy does not.

Own S3 bucket

Hourly storage as compressed ndjson or Parquet (columnar format for analysis), optionally in a bucket with object lock.

Also to an external S3 destination outside ENTRONYX.

Syslog over TLS

RFC 5424, mutual certificate verification, queue with retry over 24 hours.

Common destination for existing SIEM installations (central security analysis of logs).

OTLP endpoint

OpenTelemetry protocol via gRPC or HTTP to a collector of your choice.

No vendor-locked format.

HTTPS webhook

Only for filtered streams, maximum 50 events per second, signed with HMAC-SHA-256.

For alerting, not for mass export.

An entire wall of identical storage modules from the front: matte black carrier bezels with recessed grips and milled ventilation slots, seamlessly in a grid.

A data record passes through 3 retention tiers at ENTRONYX CLOUD and is deleted after 3,650 days — deleted, not greyed out. The first tier costs €0.0099$0.0115 per GB and month, the last €0.0003$0.0003: factor 33. That is why the data record moves instead of staying put.

Retention · 3 tiers up to day 3,650

Ingest, index, query — and eventually forget

The platform ingests external streams just like our own: application logs, syslog from the data centre, OTLP from a service mesh. You pay twice: once for ingestion, then for the time a record is retained.

Ingestion rate

Ingestion costs €0.0540$0.0626 per ingested gigabyte. It is not storage, but compute work: parsing, normalising timestamps, enriching fields, writing the index. This is priced at 3 times what a gigabyte on our NVMe storage costs for a month — €0.0180$0.0209 × 3.

The reference quantity is the ingested, uncompressed gigabyte. What the platform does with it in the background — compressing, indexing, moving — does not change the amount. Otherwise, every invoice would need to know the compression ratio of your own data.

Throughput per account
50 MB/s sustained, 4.3 TB per day
Events per second
250,000, peaks up to 400,000 over 60 s
Size of an event
1 MiB, longer lines are truncated and marked
Delay until queryable
under 5 s on average, under 20 s in the 99th percentile
Index fields per record type
200
Inputs
HTTPS (ndjson), Syslog over TLS, OTLP, Fluent Bit, Vector, Kafka

Indexing and query language

Indexing happens on arrival, not on search. Time, stream and resource are always ingested from every record; the platform recognises further fields from known formats or you define them yourself. Queries are done in a pipeline: first filter, then transform, then aggregate.

Query
# Error rate per route, last 24 hours, descending
strom = "network.lb.access" und status >= 500
| zerlege pfad als route
| zaehle() nach route, status
| sortiere anzahl absteigend
| grenze 20
Each stage of the pipeline works on the result of the previous one. If you only write the filter, you get the raw lines.
Format
Pipeline: filter, then transformation, then aggregation
Time reference
absolute or relative, time zone per query
Aggregates
count, sum, average, percentile, unique
Join
up to 3 streams via a common field
Saved queries
named, versioned, callable via API
Limits
60 s runtime, 20 concurrent queries per account

Retention classes

The retention period — usually called retention in tools — is not a single number here, but a cascade. A record starts indexed and moves on by itself. The limits are adjustable, the order is not: a class can only forget more than its predecessor, never less.

Indexed

Day 0 to 30

Full-text and field search, aggregation, linking via streams

Retention period
30 days
Response time
Result in under 2 s for a 7-day period
Background storage
Object Storage Performance

Price

€0.0099$0.0115per GB and month

Raw text compressed 5:1 (0.20) plus full index (0.35)

Searchable

Day 30 to 180

Field search for time, power and resource; full text only after pre-filter

Retention period
150 days
Response time
Result in 5 to 30 s depending on period
Background storage
Object Storage Standard

Price

€0.0018$0.0021per GB and month

Raw text compressed 5:1 (0.20) plus coarse index on time and stream (0.05)

Archive

Day 180 to 3,650

No direct access — period is retrieved and re-indexed

Retention period
3,470 days
Response time
Provisioning within 12 h
Background storage
Cold Archive

Price

€0.0003$0.0003per GB and month

Raw text compressed 8:1 (0.125), no index

Derivation of class prices: storage factor times monthly price of the underlying storage product
ClassBackground storagePrice of storageper GB and monthStorage factorResultper GB and month
IndexedObject Storage Performance€0.0180$0.02090.550€0.0099$0.0115
SearchableObject Storage Standard€0.0070$0.00810.250€0.0018$0.0021
ArchiveCold Archive€0.0024$0.00280.125€0.0003$0.0003

What this amounts to per month

With a constant influx, each class holds exactly the daily volume times the retention time — the retained volume is therefore a multiplication and not a forecast. A stream of 20 GB per day costs €32.85$38.11 for ingestion. Add to that €5.94$6.89 for 600 GB in class Indexed, €5.40$6.26 for 3,000 GB in class Searchable as well as €20.82$24.15 for 69,400 GB in class Archive. Together, this is €65.01$75.41 per month.

Monthly costs of the log platform with constant influx
InfluxIngestionIndexed30 daysSearchable150 daysArchive3,470 daysTotalper month
5 GB per day€8.21$9.52€1.49$1.73€1.35$1.57€5.20$6.03€16.25$18.85
20 GB per day€32.85$38.11€5.94$6.89€5.40$6.26€20.82$24.15€65.01$75.41
100 GB per day€164.25$190.53€29.70$34.45€27.00$31.32€104.10$120.76€325.05$377.06
500 GB per day€821.25$952.65€148.50$172.26€135.00$156.60€520.50$603.78€1,625.25$1,885.29

Metrics and alerts — in preparation

This service does not exist yet. It is in progress, but we are not giving a date because we cannot commit to one. What is possible today in its place is listed below — and it is more than the missing entry suggests.

In preparation · no date committed

What is possible here today

Platform status: status page

Availability per service and location over 90 days, ongoing incidents with root cause and announced maintenance windows. The same measurement that determines SLA service credits — you can subscribe to it.

To the status page

Status of your services: logs

Health check changes, failovers, RAID events and slow queries appear as events in the service logs. If you need alerts from them, attach a forwarding to an existing system.

View service logs

Custom measurement: Prometheus on instances

Prometheus (collects metrics), Grafana (displays them) and the usual exporters run on instances and dedicated servers without restriction. Traffic within a vRack — your private network — is not charged, the time series remain in your project.

vRack as a measurement network

What the service should be able to do

4 points we are working on. They are listed here as an intention, not a commitment — and without pre-orders, because a waiting list for a service without a date is just a more polite form of waiting.

  • Time series from instances, databases and Load Balancers without their own agent
  • Ingestion via the Prometheus write protocol, query via PromQL, the Prometheus query language
  • Alert rules alongside log queries, common notification channels
  • Common timeline of metric and log line in one view

An invoice that can be traced back to the day

FinOps means continuously allocating cloud costs to the departments that cause them. This doesn't start with the analysis, but with the tag on the resource — a freely definable key-value pair. Where the tag is missing, any breakdown remains an estimate. That is why the four building blocks are listed here in the order they are introduced.

01

Cost centres and tags on resources

Each resource carries freely selectable tags as key-value pairs. One of them can be designated as a cost centre; it then appears as a separate column on the invoice and in every export.

Tags per resource
50
Key / value length
64 / 256 characters
Mandatory tags
enforceable via IAM policy
Subsequent change
takes effect from the current billing day
02

Budgets with threshold alerts

A budget applies to a project, a cost centre or a tag combination. An alert is triggered when a threshold is reached and additionally as soon as the projection for the current month is set to exceed a threshold.

Thresholds per budget
up to 5, freely set
Default
50%, 80%, 100%
Projection
moving average of the last 7 days
Reporting channels
Email, webhook, event stream
03

Monthly breakdown by project

Billing is available per project, resource and day — not just as a monthly total. This allows a jump in an invoice to be traced back to the day and resource where it originated.

Finest resolution
Resource and day
Comparison
Previous month and previous year's month
Available from
the following day, not just at the end of the month
Retention
24 months in the account
04

Raw data export

The billing items are written daily to a bucket of your choice — the same rows from which the invoice is generated. Not a processed extract, but the dataset itself.

Format
CSV and Parquet
Schema
FOCUS 1.1
Frequency
daily, previous day's backlog until 06:00
Target
own S3 bucket, even outside ENTRONYX

The raw data, not the extract

The same rows that make up the invoice are exported — one row per resource, day and booking type, with the resource tags in their own columns. The schema follows FOCUS 1.1, the open exchange format for cloud cost data, so that the file can sit alongside extracts from other providers without translation.

The base prices from which these rows are generated are listed in full on the pricing page — including term discounts and billing cycle. What is in the export must be found there; if not, it is an error and not a tariff.

An optical patch panel from the front: hundreds of fibre optic cables in orderly vertical arcs, above them a bare head rail with the wordmark.
Patch panel in the data centre. Every resource connected here appears in the export as a separate row per day and booking type.
Daily exportbash
# Fetch booking items of the previous day (FOCUS 1.1, Parquet)
$ entronyx abrechnung ausfuhr \
    --tag 2026-08-28 \
    --format parquet \
    --ziel s3://finops-prod/rohdaten/
 
# Columns of the file
# ChargePeriodStart, ResourceId, ServiceName, RegionId,
# Tags.kostenstelle, Tags.umgebung, PricingQuantity, BilledCost
The export runs even without being called: the previous day is in the target bucket by 06:00.

An account that is tidy from day one

A Landing Zone is the prepared basic structure of a new account: separation, permissions, network and logging, before the first application runs in it. Most legacy issues arise in the first week — one project for everything, one role for everyone, a flat network, no logging. Here, the structure is provided as Terraform modules, not a click-through wizard. Terraform is the tool that creates infrastructure from text files.

Project structure

Four separate projects instead of a shared one. The separation is based on who is allowed to see production data — not on teams.

  • Projects prod, stage, dev and tools
  • Separate billing view per project
  • Mandatory tags kostenstelle, umgebung, eigentuemer
  • Deletion lock for prod

entronyx/landing-zone/projects

Basic IAM roles

Five identity and access management (IAM) roles that together cover standard requirements. No role may expand its own permissions; elevated permissions are granted temporarily and logged.

  • Roles: viewer, operator, network administration, security, billing
  • Temporary elevation, maximum 8 hours
  • Two-factor requirement for all write roles
  • Service accounts without password, only with key pair

entronyx/landing-zone/iam

Network segmentation

One vRack per environment, containing separate subnets for ingress, application and data. Databases receive no public address and no outbound route to the internet.

  • vRack per environment, no connection between prod and dev
  • Subnets eingang, anwendung, daten
  • NAT gateway only for the application subnet
  • Security groups with basic rule “deny all”

entronyx/landing-zone/network

Logging

A logging account that receives the streams of all projects and in which no one can delete — not even the security role. Without this component, an audit log is merely a suggestion.

  • Audit bucket with object lock, immutable for 400 days
  • Forwarding of iam.audit and billing.ledger
  • Ingestion into the logging platform, class indexed
  • Alert if a stream is missing for more than 30 minutes

entronyx/landing-zone/logging

Terraform modules

The four components are themselves Terraform modules with defined outputs. They can be adopted individually; an existing environment is imported instead of newly created.

  • State file in a separate bucket with lock
  • Versioned modules, semantic version numbers
  • Example pipeline for plan and apply
  • Import of existing resources without recreation

entronyx/landing-zone

Integration into your own code

The Landing Zone is not a wizard that runs once and is no longer traceable afterwards. It consists of versioned Terraform modules with defined outputs; what it creates is in your directory and not in our interface.

Provider, command line, state storage and the example pipeline for plan and apply can be found in the tools for developers. If you already operate an account, you import it — the modules do not create anything twice.

Landing Zone in Terraformhcl
# Basic structure of a new account
module "landing_zone" {
  source  = "entronyx/landing-zone/entronyx"
  version = "1.4.0"
 
  umgebungen      = ["prod", "stage", "dev"]
  region          = "fra1"
  pflichtmarken   = ["kostenstelle", "umgebung", "eigentuemer"]
  audit_bucket    = "protokolle-audit"
  audit_sperrtage = 400
}
 
# Read existing project instead of creating a new one
$ terraform import module.landing_zone.entronyx_project.prod pn-8f21c4
The retention period of the audit bucket is the only setting that can only be extended and never shortened retrospectively.

First clarify the boundary, then choose the tools

The responsibility matrix answers which layers you operate yourself. This determines which logs you need, which retention tier is sufficient and whether a landing zone is worth the effort. If you want to discuss the split for a specific environment, you can reach us via the contact.

Product lines
5
Log streams
8
Ingestion per GB
€0.0540$0.0626
Retention up to
10 years