Cloud platform for telecom operators — sovereign, edge-ready, AI-aware

Open-source Cozystack (a CNCF project we create and maintain) Ænix Platform, the supported commercial distribution Aenix builds, operates and migrates it.

Aenix builds sovereign, edge-ready cloud platforms for telecom operators across the EU, DACH, and Central Asia, using Cozystack — the open-source (Apache 2.0) CNCF platform Aenix maintains. The same platform runs at core data centres, regional sites, and customer-edge locations under one operations model, replacing aging NFV environments with a Kubernetes-native foundation that runs VMs and containers on one API via KubeVirt. It supports 5G MEC and VNFs at the edge, multi-tenant customer-facing sovereign cloud products via the Tenant CRD, sovereign AI for telco-data analytics and customer-care workloads, and NIS2 essential-entity compliance with air-gapped deployments and customer-controlled encryption. Aenix delivers this as a Platform Readiness Assessment followed by a 6-24 month multi-site implementation, with no per-CPU licensing.

Quick facts

  • What it is A sovereign, edge-to-core cloud platform for telecom operators, built on Cozystack and delivered with Aenix implementation services.
  • License Apache 2.0 (no per-CPU / per-core licensing)
  • Status Cozystack is a CNCF project (Sandbox since 2025-02-28; Incubating expected late summer 2026)
  • Who it's for Telecom operators in the EU, DACH, and Central Asia running NFV-to-Kubernetes transitions, edge cloud, sovereign-cloud product launches, or telco AI infrastructure.
  • Key capability One platform across core DC, regional, and customer-edge sites: KubeVirt for VMs and containers, Cilium (eBPF) networking, LINSTOR/DRBD storage, and Tenant CRD multi-tenancy for customer-facing offers.
  • Regulation NIS2 essential-entity compliance for telecom: air-gapped deployments, customer-controlled encryption, audit-readiness.
  • Engagement Platform Readiness Assessment first; Phase 2 multi-site implementation typically spans 6-24 months.

Telecom operators in 2026 face an architectural inflection point: legacy NFV environments aging out, edge-compute demands growing, sovereign-cloud branded products launching across the sector, AI workloads on customer data, and NIS2 essential-entity compliance. The architectural answer is a coherent platform that runs at core data centres, regional sites, and customer edge — under one operations model.

Ænix builds platforms for telecom operators across the EU, DACH, and Central Asia. Same platform, Cozystack, running at core and edge.

Pairs with: Ænix Public Cloud Platform for telcos launching customer-facing sovereign cloud products at multi-region scale; Private Cloud Platform for NIS2-aligned internal cloud and edge platforms.


What telecom operators come to us for

  • Sovereign cloud product launches — operators offering customer-facing sovereign cloud (regional telco sovereign cloud products, member-state-specific sovereign products). See Data sovereignty.
  • NFV → Kubernetes platform transitions — legacy NFV environments replaced with Kubernetes-native equivalents.
  • Edge cloud at scale — central core + regional + customer-edge sites under unified operations.
  • Sovereign AI infrastructure — telco-data analytics, customer-care AI, network-ops AI.
  • NIS2 compliance — telecom is an essential entity under NIS2.
  • Hyperscaler exit — sustained workloads where economics no longer fit.

Why telco architecture is different

Core data centre
extends to
Regional sites
extends to
Customer edge
5G MECVNFs
runs on
Cozystack
KubeVirt VMs + containersCilium (eBPF)LINSTOR/DRBDTenant CRD
  • Multi-site operations — core DC + regional sites + edge sites + customer-premises equipment, under one platform abstraction.
  • 5G + AI convergence — network slicing, MEC, and AI inference at edge.
  • Regulatory complexity — NIS2 essential-entity, sectoral telco regulators, sovereignty mandates per jurisdiction.
  • Customer-facing offers — many telcos resell platform capability to enterprise customers; multi-tenant customer-facing model is structural.
  • Long depreciation cycles — hardware refresh cycles longer than typical enterprise; platform must work on multiple hardware generations.

The dataplane question

Everything above is true of any distributed estate. What makes telco different is that a share of the workload does not tolerate a generic Kubernetes dataplane, and a platform that cannot say how it handles that is not a telco platform.

  • SR-IOV and device passthrough. Packet-processing functions want a VF bound directly to the workload, not a veth pair. Cozystack supports SR-IOV virtual functions and PCI passthrough into both KubeVirt VMs and containers, so a VNF that was certified on a VF keeps its VF. Where a function needs a whole NIC or an accelerator, it gets one.
  • DPDK and userspace networking. Functions built on DPDK bypass the kernel network stack entirely; they need hugepages, CPU pinning, isolated cores and a NUMA-aware placement, not a best-effort scheduler slot. Those are node-level and pod-level settings on the platform, applied per workload class rather than cluster-wide, so a DPDK function and an ordinary microservice share a cluster without either compromising.
  • CNFs and the VNFs that are not ready to become CNFs. Vendor network functions arrive as VMs with a support matrix, and the transition to containers happens on the vendor’s schedule, not yours. Both run side by side on one platform: KubeVirt for the VM-packaged functions, containers for the cloud-native ones, one API, one lifecycle, one observability stack.
  • Cilium and eBPF for everything else. Management, OSS/BSS, customer-facing services and MEC applications run on the eBPF dataplane, with network policy and observability that do not require a sidecar per pod.

The honest boundary: this is a platform for the estate around the network — MEC, edge applications, OSS/BSS, customer-facing cloud, AI inference, and the VNFs that live in a data centre. It is not a claim to replace a purpose-built packet core.


How Ænix engages with telecom operators

Standard Platform Readiness Assessment with telecom-specific workstreams: multi-site architecture, edge readiness, sovereign-cloud product packaging (where applicable), NIS2 controls, AI infrastructure for telco use cases.

Phase 2 implementation typically spans 6-24 months for a multi-site telecom platform.


What runs on Cozystack in telecom

Telco engagements sit in the same NDA cohort as the bank work; naming is permitted from mid-2027. The closest written-up case is a telecom operator that built a corporate AI platform on Cozystack and shipped the same distribution into a state-owned end customer.


Why Ænix specifically for telecom

  • Edge-to-core platform. Cozystack runs at scale at core data centres, regional sites, and edge — under unified operations.
  • Multi-tenant customer-facing model — Tenant CRD designed for service-provider model, suitable for telco customer-facing cloud products.
  • Open-source foundation — Apache 2.0 platform; no per-CPU pricing, no vendor lock-in across hardware refresh cycles.
  • Sovereignty-aligned — air-gapped deployments supported, customer-controlled encryption, audit-readiness for NIS2.
  • EU + Central Asia teams.

Ready to scope your build? Book a call →

How to start


Ænix is the team behind Cozystack (CNCF Project), and we offer Ænix Platform — our commercial productized offering based on Cozystack, Kubernetes Certified Distribution.

Frequently asked questions

Can the same platform run at both core data centres and edge sites?

Yes. Cozystack runs at core data centres, regional sites, and customer-edge locations under one unified operations model, supporting 5G MEC and VNFs at the edge while sharing the same platform abstraction with the core.

How does Aenix help telcos replace legacy NFV environments?

Aenix transitions legacy NFV environments to Kubernetes-native equivalents on Cozystack, which runs both VMs and containers on a single Kubernetes API through KubeVirt — so VNFs and cloud-native workloads coexist on one platform.

Is this suitable for launching customer-facing sovereign cloud products?

Yes. Cozystack’s Tenant CRD is designed for the service-provider, multi-tenant model, making it suitable for telcos that resell platform capability or launch customer-facing sovereign cloud products at multi-region scale.

Does it support NIS2 compliance for telecom operators?

Telecom is an essential entity under NIS2. The platform supports air-gapped deployments, customer-controlled encryption, and audit-readiness aligned to NIS2 controls, with telecom-specific NIS2 workstreams in the Platform Readiness Assessment.

Is there per-CPU or per-core licensing?

No. Cozystack is Apache 2.0 with no per-CPU or per-core licensing, which avoids vendor lock-in across the long hardware refresh cycles typical in telecom. Aenix sells the productized Ænix Platform and services on top.

How long does a telecom platform engagement take?

Aenix starts with a Platform Readiness Assessment covering multi-site architecture, edge readiness, sovereign-cloud packaging, NIS2 controls, and telco AI use cases. Phase 2 implementation typically spans 6-24 months for a multi-site telecom platform.

Ready to talk?

Book a 30-minute discovery call — no commitment. We confirm fit, the right platform, and the next steps.