Enterprise · Data Centers

Your own data centre, governed like your cloud accounts

Many infrastructure tools assume every workload runs in a public cloud. Realm9 supports Proxmox and VMware vCenter as connection targets, so on-prem changes follow the same review, approval and audit path as cloud changes.

Hypervisors as first-class connections

Add a Proxmox or VMware vCenter connection alongside your AWS and Azure accounts. Terraform projects can target any of them, and teams work through the same projects, workspaces and runs.

  • Proxmox and VMware vCenter connections next to AWS and Azure
  • Plans, applies and destroys for VMs through the standard Terraform run
  • Credentials held in your chosen secrets vault rather than in code
  • Workspaces attached to environments, so bookings and provisioning stay linked
Connections
NameTypeStatus
aws-productionAWS🟢 Connected
azure-sharedAzure🟢 Connected
dc1-proxmoxProxmox🟢 Connected
dc1-vcenterVMware vCenter🟢 Connected

Hybrid connectivity and hardened baselines

Site-to-site VPN, private connectivity and CIS benchmark scanning are part of the platform rather than a separate programme of work.

  • Site-to-site VPN and private links between sites and cloud regions
  • CIS benchmark scanning with exportable evidence per host
  • Zabbix and Prometheus integration so bookings and health share one view
  • Offline update channel for air-gapped sites
CIS compliance · cis-l2 profile
HostProfilePassFailDrift
pve-ldn-01rhel9-level221840
pve-ldn-02rhel9-level222020
esxi-ldn-11vmware-l116402
esxi-ldn-12vmware-l116400
Evidence bundlecis-2026-09-13.zip · signed
Next scheduled scan2026-09-20 02:00 UTC

The same policy and approval rules on-prem

Policy profiles and approval gates apply to a project regardless of where it deploys. A VM change in your data centre is scanned and approved the same way as a change in a cloud account.

  • Checkov, Trivy and TruffleHog findings on on-prem Terraform code
  • Advisory, soft-mandatory or hard-mandatory enforcement per profile
  • Named approvers and minimum approval counts per project
  • Run history, logs and approvals recorded in the audit trail
Run · dc1-build-runners (plan)
proxmox_vm_qemu.build_runner[3]
resource to add
Policy
no blocking findings
Approval
pending · platform leads
Apply
held until approved

Deployment that respects your boundaries

Organisations with on-prem estates often have strict rules about where management tools run. Realm9 can be deployed as a dedicated single-tenant cloud environment or self-hosted in your own infrastructure.

  • Self-hosted deployment mode for running Realm9 in your environment
  • Dedicated single-tenant cloud environment as an alternative
  • Single sign-on through your identity provider, with SCIM provisioning
  • Audit history exportable to your SIEM
Deployment status
ModeSelf-hosted (dc1-vcenter)
IdentitySSO via Okta · SCIM enabled
TenancySingle-tenant, dedicated
SIEM exportsplunk-hec · connected

Bring your data centre into the same workflow as your cloud

Proxmox, VMware vCenter, AWS and Azure — one set of projects, policies and approvals.