Skip to content

Swiss cloud glossary: the words this site uses

One name per thing, kept the same across the site. Technical terms are introduced where they first appear, then used as they are: VM, flavor, tenant, compute, workload, subnet, egress, cutover, rollback.

ISO 27001
3 DC
SLA 99.99%
RPO and RTO
Two distinct objectives in a recovery plan. RPO (Recovery Point Objective) is how much data you accept losing, measured in time: an RPO of one hour means the last recoverable point may be an hour old. RTO (Recovery Time Objective) is how long before the service is back. They are set separately, and an availability percentage promises neither. On Hikube the RPO depends on your volumes’ replication mode, and the RTO is not covered by the SLA: scope on the security and compliance evidence.
Backup and replication
Two protections against two different accidents, and conflating them is expensive. Replication keeps several live copies of a volume: if a disk or a site fails, the other copies answer. It does not protect against a deletion, which replicates too, nor against ransomware encryption. A backup is a dated copy you can restore as it was yesterday: that is what answers human error. You need both. On Hikube, three-site replication sits in the volume price; backup is a separate service, managed backup.
Synchronous and asynchronous replication
The choice that fixes your RPO. Synchronous: a write is only acknowledged to the application once it exists on the copies, nothing is lost if a site fails, but every write pays the latency between sites. Asynchronous: the write is acknowledged immediately and copied after, more throughput, and a loss window equal to the copy lag. There is no universally right choice; measure the latency on your real write profile before deciding. Modes available on volumes: block storage.
WORM
Write Once Read Many: once written, an object cannot be modified or deleted before its expiry, not even by an administrator. That is what makes an archive hold up, an audit log, a regulatory record, and what protects it from ransomware that has the rights. Watch the purchasing confusion: a WORM bucket is not a backup, it does not restore a VM. The two modes of Hikube object storage, governance and compliance, are on S3 object storage.
Control plane and workers
The two halves of a Kubernetes cluster. The control plane decides: it takes your manifests, chooses where pods go and keeps cluster state in etcd. The workers execute: they are the machines where your containers actually run. The split matters at purchase, because it says who repairs what at three in the morning. On Hikube, Hidora SA operates the control plane, workers live in your environment and are sized as node groups: managed Kubernetes.
Training and inference
The two phases of a model, with opposite needs. Training builds it: hours or days of saturated compute, on a lot of GPU memory, in batches, a job that can wait for the night. Inference uses it: short, latency-sensitive requests to be served continuously. A card that is excellent for one can be oversized for the other, and that is the first question to settle before choosing a GPU: the GPU catalog.
VRAM
The memory on the GPU card itself, distinct from the machine’s RAM. It decides whether a model fits: if it does not fit in the available VRAM, it does not run, or it runs degraded, split across cards. So it is the first criterion when choosing a GPU, ahead of raw compute, and the reason a faster but narrower card can be the wrong purchase. Capacity per card: the GPU catalog.
VM (virtual machine)
A complete computer, in software: its own operating system, disks and network address, on hardware shared with others. It is the basic unit of an IaaS, and the object you carry over as-is when leaving VMware. This site writes VM.
Flavor (instance size)
A fixed combination of vCPU and memory, named with a short label such as s1.small. Choosing a flavor means choosing a VM’s power; disk and public IP are billed separately. Sizes and prices: the pricing page.
Tenant (customer environment)
Your isolated space on the platform: your VMs, volumes and networks, separated from other customers’. When a page says a backup “stays in the tenant”, it means the copy leaves neither your environment nor the country.
Compute
The billed processing capacity: the vCPU and memory your VMs and Kubernetes nodes consume. It is set against storage and network, billed separately. In a cost comparison, “compute” means that line.
Workload
What you run: an application, a database, a training job. The word is deliberately broad, because the platform does not distinguish, it sees VMs and pods.
Subnet
A slice of addresses inside your private network, used to separate what should not talk: production, DMZ, backup, administration. This is where a VMware estate’s VLANs are re-expressed. Detail: the VPC private network.
Egress (outbound traffic)
Data leaving the provider’s network: to the internet, your offices or another cloud. Most providers bill it per gigabyte; on Hikube, inbound and outbound traffic are free. The line item and its effect: what egress fees cost.
Cutover
The moment a service changes platform for good: users land on the new one, the old one stops. It happens in an announced window, with success criteria set in advance. The procedure: the VMware exit checklist.
Rollback
Going back to the original platform when a cutover misses its criteria. It exists only if prepared: the source left bootable, a decision deadline set before the window opens, one named person who calls it.
IaaS
Infrastructure as a Service: VMs, network and storage billed on usage. Hikube is Swiss IaaS (Hidora SA), not shared web hosting.
Sovereign cloud
Infrastructure whose operator, jurisdiction and data location align with one state: here, exclusive Switzerland.
CLOUD Act
US law (Clarifying Lawful Overseas Use of Data Act) allowing authorities to compel a provider subject to US law to produce data, including data stored abroad. A US group’s “Switzerland” region does not change that lever. Hikube is operated by Hidora SA, with no US parent.
GDPR
EU General Data Protection Regulation. It can apply to EU personal data even if the processor is in Switzerland. EU-Switzerland adequacy frames that transfer. Hikube (Hidora SA) provides a DPA; the controller’s compliance stays theirs.
nFADP
The Swiss data protection act, revised and in force since September 2023. It governs how a Swiss organisation processes personal data: informing individuals, keeping a processing register, notifying breaches, framing subprocessors. It binds your organisation, not your host: a provider can supply you the evidence, it cannot be compliant on your behalf. What Hikube supplies: the security and compliance evidence.
Talos Linux
Immutable operating system built only for Kubernetes (Sidero Labs). No SSH or admin shell on the node. Hikube uses it for customer clusters.
KCSP
Kubernetes Certified Service Provider: a CNCF certification held by Hidora SA. Two distinct programmes: Hidora SA is the KCSP, and the clusters Hikube provides are CNCF-certified Kubernetes (Certified Kubernetes Hosted) on Talos Linux.
VPC
Virtual Private Cloud: a tenant’s private network, split into subnets (prod, DMZ, backup…).
Kubernetes hosting
Providing a Kubernetes cluster (control plane and workers) in a datacenter. At Hikube: managed Kubernetes hosting in Switzerland, Talos, CNCF, three DCs.
GPU cloud
NVIDIA GPUs attached to a VM or Kubernetes, billed on usage. Hikube GPU cloud stays in Switzerland (L4 to H200).
Multi-AZ
On hyperscalers, a high-availability option often billed separately. Hikube has no Multi-AZ SKU: block storage is always geo-redundant (Geneva, Gland, Lucerne), sync or async.
Swiss hosting
Hosting whose servers are in Switzerland. Hikube is Swiss hosting IaaS (cloud), not a shared Swiss web host.
Hidora
Hidora SA, a Swiss company in Lancy (Geneva), UID CHE-286.910.173. It is the legal operator of the Hikube cloud.

Ready to run on 100% Swiss infrastructure?

14-day trial, no credit card. GPUs included.