
Inside Cato’s SASE Architecture: A Blueprint for Modern Security
🕓 January 26, 2025
MJ is the Lead Solutions Architect & Technology Consultant at FSD-Tech. He has 20+ years of experience in IT Infrastructure & Digital Transformation. His Interests are in Next-Gen IT Infra Solutions like SASE, SDN, OCP, Hybrid & Multi-Cloud Solutions.
Share it with friends!
FishOS is Sardina Systems’ all-in-one cloud platform that combines OpenStack, Kubernetes and Ceph into a single, fully automated stack, giving IT teams a shortcut to private- and hybrid-cloud excellence without the usual complexity. Think of it as a “ready-to-swim” shoal of services for orchestration, storage, observability, auto-healing, and AI-driven optimization, all components pre-integrated and remotely managed so you can roll out new workloads—or your own fully organized Data Centre. In short, FishOS gives enterprises a ready-to-run private or hybrid cloud—complete with observability, governance, and day-2 operations—so IT teams spend time on innovation rather than infrastructure wrangling.
OpenStack began in 2010 as a joint project between Rackspace and NASA, releasing a new version every six months and rapidly becoming the de-facto open-source IaaS framework. While OpenStack matured, many enterprises struggled with DIY deployment and painful upgrades. By 2014, many organisations struggled with the complexity of Internal DIY deployments of OpenStack. That’s when Sardina Systems stepped in, launching FishOS, a pre-integrated distribution that automated deployment, scaling, and upgrades. Today FishOS tracks every upstream OpenStack release, adds Kubernetes and Ceph, and layers on zero-downtime upgrade tooling, a predictive optimiser, and and remote platform support at no extra cost.
Year | OpenStack Milestone | FishOS Milestone |
---|---|---|
2014 | Icehouse | FishOS |
2016 | Newton | First Zero-Downtime Upgrader |
2018 | Rocky | Kubernetes integration (v1.11) |
2021 | Xena | ML-based FishOS Health Engine |
2024 | Caracal | CDN component for edge caching |
2025 | Flamingo | Gaudi2 GPU support for AI/ML |
# | Feature | What it means in Simple Terms | How it Helps You |
---|---|---|---|
1 | All-in-One Cloud Stack | FishOS bundles the three big pieces you normally install separately—servers (OpenStack for VMs), containers (Kubernetes for apps), and storage (Ceph for files)—into one unified platform. | You avoid the jigsaw puzzle of mixing different products and vendors. Everything just works together, right out of the box. |
2 | Fully Automated Deployer | A guided wizard (think smartphone setup screen) asks a few inputs and then automatically builds your private cloud in hours. | No need to spend weeks wiring servers manually or memorising command-line spells. |
3 | Zero-Downtime Upgrader | FishOS Upgrader ensures zero-downtime rolling upgrades, allowing your system to remain operational and your team’s productivity to stay uninterrupted. | Your business doesn’t pause for maintenance windows, and you stop dreading upgrade weekends. |
4 | AI Health Engine | Built-in machine-learning watches temperature, memory and traffic. | Fewer slowdowns, fewer “call-outs” at 3 a.m., happier end users. |
5 | Self-Healing | If a node crashes, FishOS automatically restarts the affected apps on healthy servers. | Users’ workloads remain safe and uninterrupted. |
6 | Included 9x5 support at no extra cost, or an advanced 24x7 package | Sardina Systems experts will patch and troubleshoot software around the clock. | You get expert support without hiring a bench of rare OpenStack gurus. |
7 | Pay-As-You-Grow Licensing | Pricing scales with physical CPU cores, so small pilots start cheap and grow smoothly. | Budgets stay predictable; no giant upfront hit. |
8 | Open Standards & APIs | FishOS uses industry-standard interfaces; you can plug in any compatible tool or move workloads elsewhere later. | No vendor lock-in—your data stays portable and future-proof. |
9 | Built-In Security & Compliance | Encryption, role-based access and detailed audit logs are switched on from day one. | Meets everyday audit checks (GDPR, PCI-DSS) without bolt-on products. |
10 | GPU & AI/ML Ready | FishOS by Sardina Systems is designed to be hardware-agnostic. Whether you are working with NVIDIA, AMD, or other vendors, this cloud solution can effectively manage GPU workloads. | Data-science teams get super-fast training without separate infrastructure. |
11 | Edge & Multi-Site Friendly | The same platform can run in a core data centre or a small edge cabinet; a central dashboard manages every site. | Ideal for retail chains, telcos or smart-factory setups that need local processing. |
12 | Real-Time Monitoring Dashboard | A web console shows informative and colourful charts—CPU, storage, network, alerts—in one place. | No need in integration of separate monitoring tool |
13 | Cost Optimisation | FishOS analyses unused resources and suggests where to downsize or power-cap idle servers. | Slash electricity bills and squeeze more life out of existing hardware. |
14 | Multi-Tenant Isolation | Each team or customer gets its own “private slice” with walls in between. | Perfect for service providers or large enterprises that need departmental separation. |
15 | Developer-Friendly Tooling | Support for CI/CD pipelines, Helm charts and Terraform modules. | Your devs can deploy apps quickly without waiting on the ops team. |
Bottom line is that FishOS turns a pile of industry-standard servers into a self-driving, secure, always-on cloud—no PhD in Linux and OpenStack required.
Faster Time-to-Value – Deploy a production-grade private cloud in days, not quarters, and start launching revenue-generating services immediately. Generally Green-field clouds go live in under a week; brown-field VMware estates migrate in as little as from few days up to 10 weeks using built-in convert-and-import tooling
Lower TCO – Optimization slashes over-provisioning, typically freeing 20-40 % of stranded capacity. Hardware lasts longer; power bills shrink. Choosing FishOS slashes licensing and renewal costs associated with proprietary commercial stacks.
Future-Proof Stack & Architecture – With upstream alignment every six months, you automatically gain the newest OpenStack release. As such, customers inherit features such as advanced live-migration, hardware offload, and patches automatically.
Operational Simplicity – Running your large-scale VM infrastructure or private cloud becomes another simple affair with FishOS Health Engine + FishOS Upgrader + the Platform Support = less firefighting, more innovation
Skills Gap Closed – Remote operations let small in-house teams leverage both FSD-Tech’s & Sardina’s experts instead of hiring hard-to-find & Expensive OpenStack gurus
Regulatory Confidence – FishOS inherits the open-source community’s transparent, audited codebase—critical for finance, healthcare and government compliance.
Compliance & Governance - Fine-grained RBAC, encrypted volumes, and full audit logging help meet GDPR, PCI-DSS, and local regulations across UAE, KSA, and India.
Workload Freedom – Run VMs, containers, AI pipelines and petabyte-scale storage in one pane of glass, eliminating silos and costly data moves.
Now that we’ve covered what FishOS is, along with its key features and benefits, let’s explore the FishOS deployment lifecycle through the lens of Day-0, Day-1, and Day-2 operations.
So, in simple terms:
Day-0 is all the thinking and planning before you switch anything on.
Day-1 is the initial setup that turns the plan into a working system.
Day-2 is the ongoing care and improvement that keeps the system reliable and up to date for years to come.
Stage | Think of it as… | What Actually Happens |
Day-0 | Planning the house – drawing blueprints, understanding functionality, choosing materials and making sure the design is safe. | You decide what the cloud will look like: pick servers, network cables, storage size, security rules, and make a checklist so nothing is forgotten later. |
Day-1 | Building the house – pouring the foundation, raising walls, fitting windows. | You install the cloud software, connect the servers, create the first user accounts, and launch a few test apps to prove it works. |
Day-2 | Living in and looking after the house – cleaning, fixing leaks, adding new rooms, repainting. | You run the cloud every day: apply updates, monitor health, add more capacity when needed, back up data, and keep everything secure and fast. |
Phase | What it means in cloud projects | How FishOS handles it |
Day-0 — Design & Planning | Selecting hardware, defining network topology, choosing hypervisor/storage, and setting security baselines before a single node is powered on. | FishOS ships pre-validated reference and customizable architectures (single-rack PoC through multi-site spine-leaf) and a sizing calculator delivered by Sardina Systems' team. This front-loads capacity planning and compliance mapping, so the deployment script you run on Day-1 is already tuned for HA and Ceph replica counts. |
Day-1 — Deployment & Initial Configuration | Installing the software, bringing the cluster to an operational state, seeding images, and onboarding the first users. | The FishOS Deployer is an Ansible-based wizard that spins up controllers, computes, storage, and monitoring in hours. It auto-generates certificates, registers nodes with Ironic, so tenants can launch their first VM or pod “from day one, with zero-downtime reconfiguration. |
Day-2 — Operate, Optimise & Evolve | Everything that happens after go-live: patching, upgrades, scaling, performance tuning, backup, and cost optimisation. | FishOS was engineered for zero-downtime cloud operations, with a full suite of Day-2 operations and upgrade tools. FishOS Workload Manager continuously re-packs workloads, FishOS Health Engine continuously watches over the system and predicts faults before they occur, the Upgrader performs rolling OpenStack releases, and it includes features such as 9x7 Remote Software Support, capacity forecasting, and security hotfixes, all run without service interruption. |
In short: FishOS compresses Day-0 planning through proven reference designs, automates Day-1 deployment with a unique deployment tool, and turns traditionally painful Day-2 chores into background, zero-downtime tasks monitored by AI tooling, with included software support.
If you’re juggling legacy VM blocks and If your roadmap calls for cloud agility without hyperscale lock-in—or you’re staring down rising VMware licensing fees— FishOS offers an open, optimised, cost-effective and remotely-operated alternative:
Challenge | FishOS Answer with FSD-Tech |
---|---|
Multi-stack complexity | Unified OpenStack + K8s + Ceph |
Downtime during upgrades | Zero-Downtime Upgrader |
Skill gap | Remote Support NOC |
CapEx pressure | Commodity hardware, pay-as-you-grow licensing |
FishOS provides an off-the-shelf foundation that evolves as fast as your strategy.
As an Enterprise Customer of FSD-Tech & FishOS, you get:
Enterprise Hardening – Security baselines, HA reference design, and Ceph triple-replication out of the box.
Operational Simplicity – Single-click scaling, HA nodes, and automated orchestration.
Vendor Agility – Commodity hardware compatibility and open APIs keep exit costs near zero.
Business Alignment – Pay-as-you-grow licensing matches opex to demand, leaving capital free for innovation.
Ready to see FishOS in action? Book a 30-minute readiness assessment and receive a free TCO snapshot tailored to your data-centre footprint. Click Here
The core (OpenStack, Kubernetes, Ceph) is 100 % open-source; Sardina Systems adds tested packaging, AI tools, and support under a commercial license.
A minimal PoC runs on 24 CPU cores, 128 GB RAM on 3 nodes, and 1 GbE networking; production clouds typically start at three control nodes, three compute nodes, and three Ceph storage nodes with 10/25 GbE.
A 50-VM proof-of-concept can go live in about one week; full estates scale linearly (e.g., 500 VMs ≈ 6–8 weeks) thanks to the FishOS Move It Appliance.
Yes. Upload a Windows ISO, attach VirtIO drivers, and launch via Horizon or the API; licensing remains your responsibility.
The Zero-Downtime Upgrader rolls through hosts and services one at a time, keeping VMs and pods running; no weekend outage windows required.
Absolutely—FishOS introduces NVIDIA and Intel Gaudi cards to the system, then schedules GPU-tagged pods or VMs to those hosts.
Encryption at rest (Ceph), TLS in flight, role-based access control, and full audit logs ship by default; Sardina Systems offers hardening guides for GDPR, PCI-DSS, NCA (KSA), and UAE ISR.
No. All APIs are upstream OpenStack and Kubernetes, so workloads and data remain portable—excluding system-specific features and support.
Licensing is per physical CPU core, including all add-ons (AI optimiser, CDN, dashboards). Start small, expand later—ideal for budget staging. Start small, expand later—ideal for budget staging.
Sardina Systems provides 9x5 software support at no cost and advanced 24×7 support. The team of experts can step in remotely.