Europa-only Alternative zu Fly.io.

Fly.io ("Fly") is a US-headquartered edge compute platform that runs Firecracker microVMs in 30+ regions including Amsterdam, Frankfurt, Paris, Madrid and Stockholm. Fly Inc. is a Delaware corporation, the EU regions are EU-located but US-controlled, and the CLOUD Act applies. Fly's technical approach (microVMs at the edge, near-instant cold start, simple `fly deploy`) is genuinely innovative; replacing it with a sovereign EU stack means trading that specific multi-region edge model for either a region-fixed deployment or a self-managed equivalent on EU infrastructure.

United States Ersatz-Stack, ausschließlich EU 10 Dienste zugeordnet
Anbieter
Fly.io
Hauptsitz
Chicago, IL
Rechtsmacht
United States
Rechtsregime
CLOUD Act, FISA 702

"EU-Region" ist keine Souveränität. Vier Fragen entscheiden.

Data-Residency sagt, wo die Bits liegen. Souveränität sagt, welches Rechtssystem Zugriff erzwingen kann. Die Antwort muss auf allen vier Punkten halten, sonst ist der Stack nicht souverän.

Residenz

Wo sind die Daten physisch gespeichert?

Nicht "in der Cloud": welches Rechenzentrum, in welchem Land, unter welcher Jurisdiktion.

Subprozessoren

Wer ist sonst noch in Ihrem Datenpfad?

Jeder Anbieter, der die Daten berührt: das CDN, das E-Mail-Relay, der Error-Tracker, die Analytics-Pipeline.

Rechtsmacht

Wessen Gesetze können die Offenlegung erzwingen?

Ein Anbieter mit US-Hauptsitz untersteht FISA 702 und dem CLOUD Act, auch wenn die Bits in Frankfurt liegen.

Schlüsselverwahrung

Wer hält tatsächlich die Verschlüsselungsschlüssel?

Wenn der Cloud-Anbieter sowohl die Daten als auch die Schlüssel hält, sind die Daten für ihn lesbar, unabhängig von jedem AVV.

Erfüllt nicht AWS · Azure · GCP · EU-Region

Scheitert an Rechtsmacht und Schlüsselverwahrung.

EU-Daten, US-Mutterkonzern, US-Subprozessoren im Standardpfad, vom Anbieter verwaltete Schlüssel.

Erfüllt Binadit Managed Stack

Besteht in allen vier Punkten.

EU-gehostet auf Infrastruktur mit EU-Hauptsitz. Null US-Subprozessoren im Standardpfad. Kunden- oder EU-KMS-Schlüssel. Namentlich in Ihrer Artikel-28-AVV aufgeführt.

Warum Teams aussteigen Fly.io

Fly.io exits we have scoped come from regulated workloads (healthcare SaaS, fintech) where the multi-region edge pattern was nice-to-have but the US-jurisdictional processor was a blocker. The honest answer for these workloads: most don't actually need 30 regions, they need 2-3 EU regions with low latency. That requirement is met by two of our EU regions, with a CDN like Bunny.net for static assets - which collectively serves EU users with sub-50ms latency and full EU jurisdiction.

Fly.io Dienste und ihre EU-only Äquivalente

Eine Migration ist nicht "eine Box gegen eine andere tauschen". Die Zuordnung unten ist das, was wir für Kunden ausführen, die Folgendes verlassen: Fly.io auf Grundlage von Schrems II: vollständige EU-Jurisdiktion, kein US-Mutterkonzern im Datenpfad.

Fly Machines (microVMs)

Was wir stattdessen betreiben
Binadit Managed Cloud Platform. KVM-VMs auf Debian oder Ubuntu, provisioniert mit Terraform und konfiguriert mit Ansible.
Engineering-Hinweis
Für die meisten Workloads decken reguläre VMs mit Multi-Region-Deployment via DNS-GeoIP den Anwendungsfall ab. Für echte MicroVM-pro-Request-Szenarien ist selbst gehostetes Firecracker auf EU-Compute die souveräne Lösung.

Fly Apps (PaaS layer)

Was wir stattdessen betreiben
Binadit Managed Cloud Platform. Docker-Images, gebaut in GitLab CI und deployed auf Kubernetes, mit Review-Umgebungen pro Branch.
Engineering-Hinweis
Die Multi-Server-Funktion von Coolify deckt Multi-Region-Deployment-Muster ab.

Fly Postgres (clustered)

Was wir stattdessen betreiben
Binadit Managed Cloud Platform. PostgreSQL oder MySQL mit Patroni für Failover und pgBackRest für Point-in-Time Recovery.
Engineering-Hinweis
Patroni auf EU-Compute ist das Open-Source-Muster, das auch Flys eigenes Postgres-Angebot antreibt.

Fly Redis (Upstash)

Was wir stattdessen betreiben
Binadit Managed Cloud Platform. Redis oder Valkey, mit Sentinel für Failover.
Engineering-Hinweis
Hinweis: Upstash selbst hat seinen Hauptsitz in den USA, daher ist Fly Redis US-auf-US.

Fly Volumes

Was wir stattdessen betreiben
Binadit Managed Cloud Platform. Ceph RBD oder Longhorn für Kubernetes-native Volumes.
Engineering-Hinweis
Standard-NVMe-basierte Volumes; größengleich.

Fly Proxy (Anycast)

Was wir stattdessen betreiben
Binadit Managed Cloud Platform. HAProxy oder Nginx, mit keepalived für Failover.
Engineering-Hinweis
Health Checks, Connection Draining und Sticky Sessions bleiben allesamt erhalten. TLS terminiert hier, wobei Zertifikate automatisch erneuert werden.

Fly Postgres failover (multi-region)

Was wir stattdessen betreiben
Binadit Managed Cloud Platform. Von Patroni verwaltetes PostgreSQL-Failover über Nodes hinweg, mit automatischer Promotion.
Engineering-Hinweis
Für reine EU-Multi-Region-Szenarien (z. B. NL + DE aktiv-aktiv mit regionalem Failover) übernimmt Patroni die Aufgabe.

Fly Secrets

Was wir stattdessen betreiben
Binadit Managed Cloud Platform. HashiCorp Vault oder Infisical, self-hosted, mit automatischer Lease-Rotation.
Engineering-Hinweis
Vault ist die produktionsreife Antwort für jeden nicht-trivialen Secrets-Workload.

flyctl / fly deploy DX

Was wir stattdessen betreiben
Binadit DevOps & Support. kubectl, Terraform und GitLab CI, mit projektspezifischen Wrappern, wo sie hilfreich sind.
Engineering-Hinweis
Die DX-Lücke ist real, aber schließbar. Coolifys `coolify deploy` ist das nächstliegende Äquivalent.

Fly LiteFS (replicated SQLite)

Was wir stattdessen betreiben
Binadit Managed Cloud Platform. PostgreSQL mit Read-Replicas, oder Litestream, wo das SQLite-Modell wirklich passt.
Engineering-Hinweis
Repliziertes SQLite ist elegant für leselastige Single-Writer-Anwendungen. Bei umkämpftem Schreibpfad ist PostgreSQL die sicherere Wahl.

Wie wir migrieren von Fly.io

Eine typische Mittelstand-Migration läuft in drei Phasen. Die Zahlen unten gehen von einem 6-10-köpfigen Engineering-Team und einem mäßig komplexen Anwendungs-Stack aus.

  1. Days 1-3

    Region strategy decision

    Audit which Fly regions you actually use and which ones serve real traffic. For most EU-customer-facing apps, 2-3 EU regions cover it; for global apps, decide on the multi-region pattern (DNS GeoIP, Anycast, regional failover).

  2. Days 4-10

    Database + storage migration

    Fly Postgres replicated to EU managed PostgreSQL or Patroni cluster. Volumes mirrored. Secrets moved to Vault.

  3. Weeks 2-4

    App cutover

    Apps redeployed on Kubernetes on Binadit. DNS migrated to GeoIP routing if multi-region needed. Fly account decommissioned after verification window.

5-year TCO on Fly exits varies more than other US-cloud exits because Fly's pricing model is unusual (per-second microVM billing). For steady-state workloads, EU infrastructure is dramatically cheaper. For very spiky workloads with long idle periods, Fly's scale-to-zero is hard to match cost-effectively in the EU sovereign space without a scale-to-zero container platform.

Fly's "no surveillance" marketing - does it actually mean sovereignty?
Fly.io has been transparent about not being on the US hyperscaler critical-infrastructure surveillance lists. That's an operational claim, not a jurisdictional one. As a US Delaware corporation, Fly is subject to the CLOUD Act regardless of how they market themselves. The legal exposure is the same as any other US-jurisdictional provider.
How do we replace the "microVM cold start" feature?
For most workloads, microVM cold start is a nice-to-have rather than a hard requirement. If you genuinely need it, self-hosted Firecracker on EU compute (the same technology Fly uses) is the path. We deploy this for clients with specific microVM needs.
What about LiteFS for SQLite at the edge?
LiteFS is open-source. Self-host on EU compute with multi-region replication. The migration is mostly mechanical because LiteFS uses standard SQLite under the hood.
How long does a Fly.io exit take?
For a typical workload (a few apps, a Postgres cluster, some volumes): 2-4 weeks elapsed. For multi-region setups with Anycast and LiteFS: 4-8 weeks. The biggest schedule risk is replicating the multi-region pattern, not the technical work itself.
Are there any genuinely Fly-like EU options?
Not yet a 1:1 match in the EU sovereign space. The closest combination is Coolify multi-server + DNS GeoIP for routing + EU managed Postgres. It's not as polished as Fly's integrated experience, but it's sovereign and operationally simpler at the cost of some DX.
What about Fly's GPU offering?
Fly's GPU instances (A10, L40S) compete in inference workloads. Dedicated EU GPU hardware is the sovereign alternative for current-generation GPU compute. For older generations, EU dedicated GPU hardware is competitively priced.

Plane deinen Exit von Fly.io.

30-minütiges Scoping-Gespräch. Wir bilden Ihren Stack auf EU-only Alternativen ab, schätzen den Migrationsaufwand und sagen Ihnen, ob es die richtige Entscheidung ist.