Skip to content

Repository files navigation

Camunda 8 Self-Managed on STACKIT

Sovereign process orchestration, delivered as code.

Run Camunda 8 where European law applies. Consid designs and builds Camunda 8 Self-Managed on STACKIT, the cloud of the Schwarz Group — your process data, backups and logs stay in German data centres, operated under German jurisdiction, GDPR-compliant by design.

The whole platform is Terraform, Helm and GitOps in your Git repository. No hand-built infrastructure, no proprietary tooling, no lock-in: you own the platform and the code from day one.

Reference architecture: a STACKIT Germany perimeter containing the Camunda 8 orchestration cluster (Zeebe, Operate, Tasklist, Identity) above PostgreSQL Flex, OpenSearch and Object Storage, on the STACKIT Kubernetes Engine with Observability, Secrets Manager, Load Balancer and DNS — all provisioned with Terraform, Helm and GitOps from your Git.

What this is: a reference architecture and delivery approach for running Camunda 8 Self-Managed on STACKIT. This repository is documentation — the Terraform and Helm baseline is delivered into your own Git repository as part of an engagement. Jump to the FAQ or get in touch.


Contents


Why Camunda on STACKIT

Sovereign by default. Process data, backups and logs stay in STACKIT data centres in Germany, operated by Schwarz Digits. No third-country transfer to argue about, and the GDPR, DORA and audit questions get answered in the design phase — not after go-live.

Production-grade from day one. Multi-AZ Kubernetes, managed PostgreSQL, snapshots to object storage, and a restore procedure we have actually executed. Not a proof of concept that quietly became production.

Everything as code. The whole platform is reproducible per environment, reviewable in pull requests, and yours to keep. There is no dependency on a Consid tool you cannot see inside.

One partner, whole stack. Camunda process expertise, Kubernetes platform engineering and STACKIT know-how sit in the same team. One roadmap, one escalation path — no finger-pointing between vendors when the engine backs up.

We run it ourselves. Consid operates its own Camunda 8 Self-Managed platform on STACKIT — the same architecture and the same Terraform and Helm baseline we hand to you. The runbooks, the upgrade path and the restore procedure are exercised on our own cluster before they reach yours.


Reference architecture

Every stateful Camunda component has a managed STACKIT counterpart, so your team operates a platform instead of a server estate.

Camunda 8 component STACKIT service Why
Orchestration cluster
Zeebe engine, Operate, Tasklist, Identity
STACKIT Kubernetes Engine (SKE) Managed control plane, multi-AZ node pools, rolling node replacement
Secondary storage
process history & read models
Managed OpenSearch, or Elasticsearch on SKE Backs the Operate, Tasklist and Optimize views without a self-built cluster
Web Modeler & Identity
relational persistence
STACKIT PostgreSQL Flex Managed HA Postgres with automated backups and point-in-time recovery
Backups, exports, documents STACKIT Object Storage (S3-compatible) Zeebe and search snapshots, document store, long-term retention
Ingress & TLS STACKIT Load Balancer + DNS, cert-manager Public or VPN-only endpoints, certificates renewed automatically
Metrics, logs, alerts STACKIT Observability Prometheus, Grafana, Loki and Alertmanager as a service
Credentials STACKIT Secrets Manager No secrets in Git, rotation without redeploying the chart
Authentication & SSO Your identity provider over OIDC Entra ID or Keycloak — existing groups, MFA and joiner/leaver process
Provisioning STACKIT Terraform provider, Helm and ArgoCD One pipeline from empty STACKIT project to a running cluster

Also part of the blueprint:

  • Isolated STACKIT project per environment (dev / stage / prod)
  • Private networking — no public engine endpoint unless you want one
  • Camunda multi-tenancy for several business units on one cluster
  • Connectors and job workers in your language of choice

What we deliver

Same platform blueprint, three ways to work with us. Different amount of us.

Advise — Consulting

For teams with their own Kubernetes capability who want a sound design and someone to call. Available now.

  • Needs and readiness assessment: processes, volumes, integrations, compliance
  • Target architecture and sizing for STACKIT, with a cost model
  • Reference Terraform and Helm baseline, handed into your Git
  • Runbooks for backup, restore, upgrade and incident handling
  • Support subscription: named contacts, agreed response times, upgrade advisories

You run the platform. We make sure the design is right and you are never stuck.

Build — Implementation (recommended)

For teams who want the platform built properly — and the knowledge to stay in-house. Available now. Everything in Advise, plus:

  • Consultants embedded in your team through build and go-live
  • Landing zone, SKE clusters and data services provisioned with you
  • Camunda install, SSO, connectors, multi-tenancy and CI/CD implemented
  • First processes built together; patterns and standards established
  • Load and failover testing, then a structured handover with enablement

You own it at the end. We make sure you can.

Run — Platform Team as a Service

For organisations who want Camunda as an internal product, without hiring the team for it. Not available yet — in build-out. Everything in Build, plus:

  • A dedicated Consid platform team running Camunda on STACKIT for you
  • On-call cover, SLA-backed incident response, agreed RPO and RTO
  • Patching, version upgrades, capacity and performance management
  • Security operations, access reviews and compliance evidence for auditors
  • Process automation Centre of Excellence: standards, reviews, enablement

We are building this service out now. Tell us what you need and we will bring you in as soon as it opens.


How we deliver it

The platform rolls out from a proven Terraform and Helm baseline via GitOps, so infrastructure takes days — the calendar time goes where it should: your decisions, your integrations, your go-live.

# Step What happens
1 Assess Workshops on process landscape, volumes, integrations, compliance and existing platform capability. Output: requirements, cluster sizing, target architecture and cost model.
2 Landing zone STACKIT organisation and projects per environment, networking, IAM roles and least-privilege service accounts, Terraform state backend, Git repository and CI/CD pipelines.
3 Platform build SKE clusters, PostgreSQL, search, object storage, ingress, observability and secrets — all as code. Backup and restore configured and rehearsed.
4 Camunda rollout Helm-based install per environment, SSO wiring, connector setup, tenants, resource limits and partition layout, then a load test against your expected throughput.
5 Go live First processes to production: cutover, runbooks, alert routing, on-call handover and a documentation walk-through with the people who will carry the pager.
6 Support & evolve Your team runs the platform, with us on call for it: upgrade advisories inside Camunda's support window, architecture and cost reviews, new processes onboarded, enablement for your developers.

A first production cluster typically stands a few weeks after kick-off — we scope the timeline with you during the assessment.


Sovereignty and compliance

  • STACKIT data centres in Germany
  • GDPR-compliant processing, operated by Schwarz Digits (Schwarz Group)
  • Your code, your Git, your STACKIT account
  • Exit path documented from the start

Frequently asked questions

Can I run Camunda 8 in German data centres?

Yes. Camunda 8 Self-Managed runs on STACKIT, the cloud of the Schwarz Group, whose data centres are located in Germany and operated by Schwarz Digits. Process data, backups, logs and search indices all stay within that footprint — there is no third-country transfer in the default architecture.

Is Camunda 8 on STACKIT GDPR-compliant?

The infrastructure is built for it: data residency in Germany, a German processor, private networking, encrypted storage, least-privilege IAM and audit trails. GDPR compliance also depends on how you model and retain process data, so we cover retention, deletion and data minimisation for your processes during the assessment. Your own legal and data-protection team should sign off on the finished design.

Is this affected by the US CLOUD Act?

STACKIT is operated by Schwarz Digits, a German company within the Schwarz Group, rather than by a US-headquartered provider — which is the reason many regulated organisations in Germany choose it. Whether that fully satisfies your specific regulatory position is a legal question for your counsel, not an architectural one, and we are happy to supply the technical detail they need to assess it.

Which STACKIT services does Camunda 8 Self-Managed need?

STACKIT Kubernetes Engine (SKE) for the orchestration cluster, PostgreSQL Flex for relational state, a search cluster for process history, S3-compatible Object Storage for backups and documents, Load Balancer and DNS for ingress, Observability for metrics, logs and alerts, and Secrets Manager for credentials. The full mapping is in Reference architecture.

Can Camunda 8 run on STACKIT Kubernetes Engine (SKE)?

Yes. The Camunda 8 orchestration cluster — Zeebe, Operate, Tasklist and Identity — is deployed to SKE with the official Helm charts, across multi-AZ node pools with a managed control plane and rolling node replacement.

Does Camunda 8 need Elasticsearch, or can it use OpenSearch?

Camunda 8 supports both Elasticsearch and OpenSearch as secondary storage for process history and the read models behind Operate, Tasklist and Optimize. On STACKIT this is either a managed OpenSearch instance or a search cluster running on SKE, depending on your retention, throughput and operating preferences.

How long does it take to get Camunda 8 running on STACKIT?

The assessment takes roughly a week. Because the platform comes from a proven Terraform and Helm baseline rolled out via GitOps, standing up the landing zone, clusters, data services and Camunda itself is a matter of days rather than months — the calendar time goes into your decisions, integrations and go-live. A first production cluster typically stands a few weeks after kick-off; we scope it with you during the assessment.

Who owns the Terraform and Helm code?

You do. The entire platform is delivered as code into your Git repository, reproducible per environment and reviewable in pull requests. There is no proprietary Consid tooling in the runtime path and no lock-in — the exit path is documented from the start.

Can we connect Camunda 8 on STACKIT to our identity provider?

Yes. Authentication runs through your existing identity provider over OIDC — Microsoft Entra ID and Keycloak are both common — so existing groups, MFA and your joiner/leaver process apply to Camunda without a parallel user directory.

How are backups and disaster recovery handled?

Coordinated Zeebe and search snapshots go to S3-compatible Object Storage, with point-in-time recovery for PostgreSQL. Restores are rehearsed on a schedule rather than assumed, and RPO and RTO targets are agreed with you and backed by multi-AZ node pools and Zeebe partition replication.

Does Camunda 8 on STACKIT support multi-tenancy?

Yes. Camunda 8 multi-tenancy lets several business units or products share one cluster with separated process data and authorisation, and each environment (dev, stage, prod) gets its own isolated STACKIT project.

Can we migrate from Camunda 7 or Camunda Cloud (SaaS)?

Migration paths from both are supported, but they are a separate piece of work driven by your process estate rather than by the platform. The blueprint here is about getting a production-grade Camunda 8 cluster running on STACKIT; we scope any migration on top of it.

Do you run Camunda 8 on STACKIT yourselves?

Yes. Consid operates its own Camunda 8 Self-Managed platform on STACKIT, built from the same Terraform and Helm baseline described here. That is where upgrades, backup and restore procedures and runbooks get exercised first, so what reaches your environment has already been run somewhere real.

Do we need a Camunda licence, and does Consid sell it?

Camunda 8 Self-Managed requires a commercial licence from Camunda for production use. You negotiate and contract that directly with Camunda — Consid is not a reseller and takes no margin on licensing. We help you size the licence against your expected volumes and will join the conversation if that is useful, but the agreement is between you and Camunda. Budget for it separately from our fees and from STACKIT infrastructure cost.

What does Consid do, and what do we do ourselves?

That is yours to choose. We can stop after the assessment and architecture, handing you a reference Terraform and Helm baseline plus runbooks to run yourself, or our engineers can build the platform embedded in your team through to go-live and a structured handover. Either way you own the platform and the code at the end. See What we deliver.


About Consid

Consid is a Nordic digital transformation consultancy, founded in 2000 in Jönköping, Sweden. We have grown to more than 1,800 colleagues across 45+ offices in Sweden, Norway, Denmark, Finland, Germany and Poland, working with over 700 active customers in both the private and the public sector.

We combine technology, strategy and creativity: strategy and design, custom development, cloud and platform engineering, data and AI, and long-term managed services. A large share of our client relationships have run for well over a decade.

For Camunda on STACKIT that matters in one specific way: the people who model your processes and the people who run your Kubernetes clusters work for the same company. You are not integrating two vendors and hoping they agree.

Founded 2000, Jönköping (SE)
People 1,800+
Offices 45+ in 6 countries
Customers 700+ active
Focus here Process automation & platform engineering

Contact

Tell us where you are and we will come back with a concrete next step — usually a 90-minute assessment workshop.

Jordes Havekost — Camunda on STACKIT, Consid Germany
📧 anfrage@consid.com
🌐 www.consid.com

What happens next

  1. We reply within two working days.
  2. A 30-minute call to understand the shape of the problem.
  3. A 90-minute assessment workshop — no charge, no obligation.
  4. A written recommendation: architecture, effort and a cost model.

Useful things to mention when you get in touch: the processes you want to orchestrate, expected volumes, your timeline, and any compliance constraints. Whether you are starting greenfield, already running Camunda 8 elsewhere, or already on STACKIT and looking for help operating it.


Machine-readable

The same facts, structured, for anyone consuming this repository with a tool rather than reading it. GitHub strips <script> from rendered Markdown, so structured data cannot live in this README — it lives in these files instead. All three are plain files at the repository root and are also served from the landing page host.

File What it is
schema.jsonld The schema.org graph from the English landing page: Organization, Service with an OfferCatalog of all three offerings, and a WebPage/FAQPage carrying the 14 FAQ entries. Identical to the JSON-LD embedded in the page.
offering.json The same offering as plain JSON: the three tiers with availability, the Camunda-to-STACKIT service mapping, the delivery steps, timelines, sovereignty and the licensing position.
llms.txt Curated entry point following the llmstxt.org convention: summary, key facts and where to go next.

The canonical version of this offering is the landing page at ai.consid.cloud/camunda-on-stackit-offering (German). This README is the same content as a document; the page carries the structured data inline.


Legal — Impressum & Datenschutz

Provider identification under German law (§ 5 DDG, § 18 Abs. 2 MStV), reproduced in German as required.

Impressum

Anbieter Consid GmbH, St. Annenufer 5, 20457 Hamburg, Deutschland
Geschäftsführung Lars Ulrich Napret
Registergericht Amtsgericht Hamburg, HRB 178879
Umsatzsteuer-ID DE359609304
E-Mail anfrage@consid.com
Inhaltlich verantwortlich (§ 18 Abs. 2 MStV) Lars Ulrich Napret, Adresse wie oben

Datenschutz

Stand: August 2026.

Verantwortlicher. Consid GmbH, St. Annenufer 5, 20457 Hamburg, anfrage@consid.com.

Dieses Repository. Dieses Repository wird von GitHub, Inc. gehostet. Beim Aufruf verarbeitet GitHub Verbindungsdaten in eigener Verantwortung; es gelten das GitHub Privacy Statement und die GitHub Terms of Service. Wir selbst setzen hier keine Cookies, betreiben kein Tracking und erstellen keine Nutzungsprofile.

Kontaktaufnahme. Schreiben Sie uns per E-Mail oder über ein Issue, verarbeiten wir Ihre Angaben ausschließlich zur Bearbeitung und Beantwortung der Anfrage (Art. 6 Abs. 1 lit. b bzw. lit. f DSGVO) und löschen sie, sobald sie nicht mehr benötigt werden und keine Aufbewahrungspflichten entgegenstehen. Inhalte, die Sie in einem öffentlichen Issue oder Pull Request veröffentlichen, sind öffentlich sichtbar.

Ihre Rechte. Sie haben das Recht auf Auskunft, Berichtigung, Löschung, Einschränkung der Verarbeitung, Datenübertragbarkeit und Widerspruch (Art. 15–21 DSGVO) sowie ein Beschwerderecht bei einer Aufsichtsbehörde (Art. 77 DSGVO). Für uns zuständig ist der Hamburgische Beauftragte für Datenschutz und Informationsfreiheit, Ludwig-Erhard-Straße 22, 20459 Hamburg.

Die vollständige Datenschutzerklärung für die von uns selbst betriebene Website — inklusive Hosting, Logdaten und Aufrufanalyse — finden Sie unter Datenschutz.


Camunda is a trademark of Camunda Services GmbH. STACKIT is a brand of the Schwarz Group. Consid is an independent service provider — this document describes our own offering.

About

Consid's offering for running Camunda 8 Self-Managed on STACKIT — GDPR-compliant process orchestration in German data centres, provisioned as code.

Topics

Resources

Stars

0 stars

Watchers

0 watching

Forks

Contributors

Languages