Cloud Provider Selection
Last updated on
Why the provider decision is strategic
Section titled “Why the provider decision is strategic”The choice of cloud provider is not an IT decision — it is a strategic decision with 5–10 years of relevance. Wrong provider decisions create lock-in, compliance risks and migration costs running into eight figures.
The most common decision pitfall: provider selection is made based on product feature lists and price negotiations, without weighting the strategic dimensions (sovereignty, portability, regulatory compliance).
Multi-cloud vs. single-cloud: the strategic decision
Section titled “Multi-cloud vs. single-cloud: the strategic decision”Many organisations arrive with a multi-cloud question: “Should we use STACKIT and another provider?”
When multi-cloud makes sense:
Workloads with different sovereignty profiles (Tier 1 on STACKIT, global CDN infrastructure on other providers); specific capabilities that STACKIT does not yet offer at the same maturity; existing investments with another provider that cannot be migrated immediately.
When single-cloud (STACKIT) is the better choice:
A clear sovereignty obligation for all or most workloads; simpler governance, unified toolchain, no cross-cloud complexity; a DACH-focused organisation without global deployment requirements.
The pitfall warning: Multi-cloud as a strategy sounds attractive but is expensive in practice — double tooling, double training, double governance complexity. Many organisations that start with multi-cloud consolidate after 2–3 years.
Vendor lock-in: architectural protection with STACKIT
Section titled “Vendor lock-in: architectural protection with STACKIT”STACKIT’s open-standards approach provides structural protection against lock-in:
| Technology | STACKIT implementation | Exit path |
|---|---|---|
| Container orchestration | SKE (STACKIT Kubernetes Engine) | Any CNCF-conformant K8s provider |
| Infrastructure as Code | STACKIT Terraform Provider | Terraform knowledge is portable |
| Object storage | S3-compatible API | Any S3-compatible provider |
| Managed databases | PostgreSQL, MySQL, Redis (standard APIs) | Self-operable |
This means: a STACKIT exit is possible without rewriting the entire IaC library.
Decision process: structured, not political
Section titled “Decision process: structured, not political”A poor provider decision process looks like this: IT presents a recommendation, the board asks why not the well-known US provider, the decision is made based on brand recognition.
A good process:
- Adopt the evaluation matrix with weightings in the Steering Committee before evaluating providers — not after
- Proof of concept with the top 2 providers for a defined test workload
- Security/compliance assessment by CISO and DPO
- TCO analysis over 3 years (not just list prices)
- Decision documentation: why this provider, why not the others — for later review
Practical steps
Section titled “Practical steps”- Adapt the evaluation matrix to your North Star and sovereignty profile
- Run a STACKIT PoC for a Tier 1 workload
- CISO assessment of Cloud Act risks for current providers in the portfolio
- TCO comparison including hidden costs (egress, support, compliance tooling)
- Formalise the decision in the Cloud Strategy Board