Identity platform
Deploy and update Nubus components on Kubernetes in a controlled way.
WZ-IT connects users, groups, SSO and applications through Nubus and operates the platform on a suitable Kubernetes architecture.
The following are trademarks of their respective owners: Nubus (Univention GmbH). WZ-IT is an independent service provider and has no business, partnership, or contractual relationship with these companies. We offer independent migration, installation, hosting, and operations services.
Nubus combines identity store, directory management, identity provider, portal, provisioning and connectors in a central identity platform.
We design Kubernetes, databases, directories, OIDC and SAML trust, certificates, provisioning flows and administrative roles together.
Errors in attributes, groups or provisioning affect every connected application. Changes therefore require staging, rollback and documented responsibilities.
Vendor support, existing directory services and the target application landscape are assessed before the proposal.
Identities, directories, provisioning, SSO and self-service form a security-critical platform connecting applications and organisational processes.
Deploy and update Nubus components on Kubernetes in a controlled way.
Design users, groups, attributes and lifecycle as leading identity data.
Connect OIDC, SAML, APIs and target applications in a controlled way.
Operate monitoring, backups, keys, auditing and emergency access.
WZ-IT operates the technical platform; business identity data and approval rules remain with the customer organisation.
| Area | Responsibility | Scope and boundaries |
|---|---|---|
| Nubus and Kubernetes | WZ-IT | Platform components, deployment, monitoring, backups and controlled updates. |
| Keys and emergency access | WZ-IT | Technical secrets, certificates and documented break-glass procedures. |
| Directory model | Shared | We implement attributes and groups technically; the customer provides the business model. |
| Application integration | Shared | WZ-IT connects protocols; application owners validate roles and approval. |
| Joiner, mover and leaver | Customer | The customer owns sources, approval and organisational identity processes. |
| Custom provisioning | Optional WZ-IT service | Custom connectors and workflows are developed and tested separately. |
Manage accounts, groups, attributes and lifecycles centrally and provision them in a controlled way.
Connect applications to a central identity provider through OpenID Connect or SAML.
Connect existing LDAP, Active Directory or other identity sources through suitable connectors.
Send identity changes to target applications through defined events and interfaces.
Bundle application access and provide selected user actions through self-service processes.
Manage Helm releases, dependent services, secrets, certificates and upgrades reproducibly.
Assess existing data and configuration, migrate them in a test run and move to managed operations through a controlled cutover.
Secure SSO, roles, administrative paths and external access for the application and existing infrastructure.
Back up all stateful components consistently and document the recovery path for the agreed scope.
Monitor and update the application and its technical dependencies and operate them under the agreed service level.
A clearly defined operating scope instead of an opaque hosting flat fee.
We set up a test instance for you, usually on the next business day. No payment details required. After seven days it is deleted unless you continue.
We combine the right compute size with ongoing operations, backups, monitoring and a service level appropriate for the criticality of Nubus. High availability and recovery targets are designed separately where needed.
We also design custom hosting architectures, integrations and migrations around Nubus. Contact us for a technical assessment.
One managed standard Nubus application is included in the Starter workload. Business and higher levels add a flexible operations allowance for planned work during regular service hours. Select compute, additional applications, storage and the appropriate service level.
A workload is one compute instance with the applications agreed for it.
One standard app per workload is already included. Additional dedicated servers count as separate workloads.
€79.90 per started TB and month, including daily encrypted offsite backup with 7-day retention.
Enquiry
Briefly describe the current state and objective for Nubus. We assess infrastructure, integration, and ongoing operations.
User count alone is insufficient. Groups, attributes, provisioning, login peaks, connected applications and availability objectives determine the platform.
| Usage scenario | Technical starting point | Key factors |
|---|---|---|
| Central login for initial applications | Identity assessment | Directory, protocols and pilot applications are defined. |
| Many applications and provisioning | Platform architecture | Connectors, synchronisation and failure paths are designed. |
| Multiple organisational units | Data-model assessment | Tenants, groups, delegation and administrative boundaries are agreed. |
| Critical central identity | HA and recovery concept | Redundancy, emergency access, keys and RTO/RPO are designed explicitly. |
Nubus is a platform and is quoted individually based on identity model, applications, availability and operating boundaries.
Nubus runs as a Kubernetes platform in a controlled environment aligned with the existing identity landscape.
Dedicated Kubernetes environment with agreed security and service level.
Operate in your account and existing network segments.
Platform in your data centre close to directories and applications.
Central identity with controlled connections to cloud and on-premises applications.
Nubus combines directory, identity provider, provisioning and portal without replacing business responsibilities.
Central login, self-service and delegated administration.
TLS, segmentation, MFA and protected administrative paths.
Directory, login, groups, policies and provisioning.
SSO and account provisioning for approved business applications.
Attributes, groups, sources and traceable changes.
Synchronisation and controlled lifecycle processes.
Login events, errors, capacity and security signals.
A central identity platform increases dependency. Emergency access, recovery and changes therefore require particularly strict controls.
Answers about Kubernetes, SSO, directories and responsibility.
No. Nubus is a Kubernetes-based identity platform with multiple components and is designed for the existing environment.
Typical targets use OIDC and SAML for SSO plus directory and provisioning paths. Compatibility is assessed per application.
Yes. We design Kubernetes, network segments, storage, backups and connections to internal applications and directories.
WZ-IT operates the technology. Business data sources, approvals, group logic and joiner-mover-leaver processes remain with the customer.
We design backups, restore, emergency access and, depending on criticality, redundancy with explicit RTO/RPO objectives.
As an alternative to managed hosting in the data centre, WZ-IT provides the hardware, configures Nubus, and handles hardening, monitoring, updates, backup and technical support. Access can be limited to the internal network or enabled through VPN and existing identities.
from EUR 349 excl. VAT / month · plus one-time provisioning and initial setup

These solutions are often used together with Nubus
These solutions offer similar functionalities and can be evaluated together
These solutions are direct alternatives with similar use cases
No risk: worst case, you leave with a clearer understanding of your project than before.


“WZ-IT's advice on our Azure migration was technically sound and completely non-binding right from the intro call - we took away a great deal.”
Whether a specific IT challenge or just an idea - we look forward to the exchange. In a brief conversation, we'll evaluate together if and how your project fits with WZ-IT.