Kubernetes & Container Registry Service Terms
PART I - PURPOSE AND SCOPE
Article 1. Purpose and scope of application
1.1. These Terms (the "Terms") apply to the HiTechCloud Kubernetes Service (HKS) and HiTechCloud Container Registry (HCR), container-native services provided by HiTechCloud for deploying, operating, and centrally storing the Customer's containerized applications and Container Images.
1.2. The two services are governed by the same Terms because they are tightly integrated: HKS uses HCR as its default registry for pulling deployment images.
Article 2. Definitions
- “HKS” - HiTechCloud Kubernetes Service: a Managed Kubernetes platform conformant with the upstream Cloud Native Computing Foundation (CNCF) standard.
- “HCR” – HiTechCloud Container Registry: a service for storing, managing and distributing container images (Docker/OCI compatible), Helm charts and Software Bill of Materials (SBOM).
- “Cluster”: a group of nodes working together to form the Customer's Kubernetes environment.
- “Node”: a virtual machine or physical server acting as a worker or control plane node in the cluster.
- “Pod / Deployment / Service / Namespace / Secret / ConfigMap”: Kubernetes resources as defined upstream.
▸ Legal basis:
Civil Code 2015; Commercial Law 2005;
Law on Information Technology 2006; Law on Network Information Security 2015; Law on Cybersecurity 2018;
Decree 13/2023/ND-CP (PDPD); Decree 53/2022/ND-CP;
Decree 147/2024/ND-CP on the management of internet services.
PART II - SERVICE DESCRIPTION AND CONFIGURATION
Article 3. Service and product description
3.1. HKS provides a control plane fully managed by HiTechCloud, comprising kube-apiserver, kube-controller-manager, kube-scheduler and etcd with scheduled backups. Worker nodes are created to the configuration the Customer selects (vCPU, RAM, disk).
3.2. HKS provides built-in support for:
- CNI: Calico, Cilium (eBPF), Flannel;
- CSI: HiTechCloud Block Storage, Cloud Storage (Object/File);
- Ingress: NGINX Ingress, Traefik, HAProxy; LoadBalancer integrated with NLB;
- Optional service mesh: Istio, Linkerd;
- Optional GitOps: integration with HiTechCloud ArgoCD;
- Observability: Prometheus, Grafana, Loki, Tempo, OpenTelemetry Collector.
3.3. HCR provides the following features:
- Push/pull images over the standard OCI v1.1 protocol (compatible with Docker CLI, podman, skopeo, BuildKit);
- Automatic vulnerability scanning on every push (Trivy, Grype), with deploy blocked by CVSS policy;
- Image signing (cosign), policy enforcement (Kyverno/OPA Gatekeeper);
- Multi-region replication; immutable tag policy; garbage collection;
- Supports Helm chart repositories and SBOM in SPDX/CycloneDX format.
Article 4. Configurations, plans, and service levels
4.1. Supported Kubernetes versions: the three most recent upstream releases (rolling support). HKS commits to shipping security patches within 14 days of the upstream release.
4.2. Cluster type:
- Standard Cluster: Control Plane shared, ≤ 100 Node;
- Dedicated Cluster: dedicated control plane, supports 500+ nodes, with multi-zone HA;
- Bare-metal cluster: worker nodes are Dedicated Servers, suited to compute-intensive and GPU workloads.
4.3. Worker node configurations range from 2 vCPU/4 GB RAM to 96 vCPU/768 GB RAM; NVIDIA L4/L40S/A100/H100 GPUs can be attached for AI workloads.
4.4. Container Registry storage classes: Standard (NVMe), Archive (Cold).
PART III - COMMITMENTS AND SUPPORT
Article 5. Service level agreement (SLA) and support
5.1. HKS Control Plane uptime ≥ 99.95%/month (Dedicated); ≥ 99.9% (Standard); HCR ≥ 99.9%/month.
5.2. P1 response ≤ 15 minutes; control plane recovery RTO ≤ 1 hour. See the SLA commitment.
5.3. Vulnerability scanning on an image completes within 10 minutes of push.
PART IV - RIGHTS AND OBLIGATIONS
Article 6. HiTechCloud's rights and obligations
- (a) Operate and maintain the control plane, with hourly etcd backups (retained 7 days);
- (b) Apply critical Kubernetes patches within 14 days of the upstream release;
- (c) 24/7 technical support for PREMIUM/ENTERPRISE plans;
- (d) Provide audit logs for the API server, kubelet and RBAC events through an internal SIEM and, optionally, export them to the Customer's system;
- (e) Image scanning security and signing keys for HCR.
Article 7. Customer's rights and obligations
- (a) Manage applications deployed on the cluster: Deployment, StatefulSet, CronJob, Helm release;
- (b) Manage the application's secrets, ConfigMaps and network policies;
- (c) Comply with Pod Security Standards (Restricted/Baseline); do not run privileged containers on a Standard Cluster;
- (d) Scanning and patching image vulnerabilities before production deployment;
- (e) Backing up application data yourself (databases in Pods, PVCs) – HiTechCloud does not back up PVCs by default unless the Backup add-on is purchased;
- (f) Complying with the AUP and resource/quota limits.
PART V - FEES AND PAYMENT
Article 8. Service fees and payment
8.1. HKS Standard: charged by number of Worker Nodes × hours × configuration; shared control plane at no charge. HKS Dedicated: adds a charge for a dedicated control plane.
8.2. HCR: charged by storage capacity (VND/GB/month) plus egress fees when pulling images outside HiTechCloud.
8.3. Surcharges for GPU nodes, Spot/preemptible instances (where applicable), and accounts using Add-on services (Backup PVC, managed Service Mesh).
8.4. Paid in advance monthly, quarterly or annually; overdue payments are handled under Article 2.6 of the main contract.
PART VI - SECURITY AND COMPLIANCE
Article 9. Security, data, and legal compliance
9.1. Encryption:
- etcd at rest with AES-256-GCM and KMS-managed keys;
- Secrets are encrypted at rest through a KMS provider (envelope encryption);
- HCR image at-rest: AES-256; in-transit: TLS 1.3.
9.2. Access control:
- RBAC is mandatory; OIDC integration with the Customer's identity provider (Azure AD, Google, Okta);
- Audit log of every API call, retained for 12 months.
9.3. Compliance:
- Compliance with CIS Kubernetes Benchmark v1.9+;
- When processing Personal Data, the PDPD applies and a DPA is signed.
PART VII - SUSPENSION, TERMINATION, AND EFFECT
Article 10. Suspension and termination
10.1. HiTechCloud has the right to suspend a Cluster/Repository when the Customer breaches the AUP or endangers shared infrastructure (for example, cryptocurrency-mining containers on a shared plan, images containing malware, or resource abuse).
10.2. On termination, the Customer has 30 days to export cluster state and manifests and to pull images. Data is then permanently erased in accordance with NIST SP 800-88.
Article 11. Effect and review
11.1. These terms take effect from 19/05/2026 and are reviewed in full at least once every 12 months, or whenever there is a material change in the law.
11.2. Any amendment or supplement must be approved by the Director of HiTechCloud and published on the hitechcloud.vn service portal at least 15 days before it takes effect, except in information security emergencies.
11.3. These terms form an integral part of the Terms of Service and supplement the applicable policies. In the event of a conflict, the customer's specific appendices or order forms take precedence on scope and configuration; these terms take precedence on the SLA and on service-specific technical obligations.