Opens in a new tab

Kubernetes for Transit Operators: The Vehicle as a Data Center.

Unwired Edge Compute for Kubernetes puts data center technology on board. Until now, every onboard application had to be procured, updated and fixed separately. Now passenger information, passenger counting and diagnostics run on virtual servers in the vehicle, all managed from the Unwired Edge Cloud.
  • Data Center Grade
  • One Cluster per Vehicle
  • Centrally Managed
  • Extensible
Container rx84a7d21f9 Running
WiFi Portal
Passenger-facing offline portal service
Health Check OK v2.8 Internal Reach
Container rx52n8c77q1 Running
Edge Analytics
Internal event processing and local insights
Health Check OK v1.6 Internal Reach
Add Container
Deploy a service to this network
Client Network Uplinks
WAN Bonding
Primary uplink cluster
5G Uplink
Fallback cellular access
NAT Network
Internal routed segment
PIS
APC
Diagnostics
More
Standardization

One Standard for Every Application, from the Data Center to the Vehicle

Passenger information, passenger counting and diagnostics usually come from different suppliers, and each one brings its own update process, its own monitoring and its own way of handling faults. Unwired Edge Compute for Kubernetes runs them all as standard Kubernetes workloads, so you roll out, monitor and troubleshoot every application the same way, from one place.
  • Standard Kubernetes API and Helm
  • One rollout process for every application
  • One monitoring view across all applications
Read the Technical Details
Central Deployment

Connecting to Edge Cloud

Container update available

Deploying container to vehicles

Container deployed

Management

Update and Configure the Whole Fleet from a Single Console

Managing every application from one place is routine in the data center. Now it is routine in your fleet, too. In the Unwired Edge Cloud Console, you enable Kubernetes for individual vehicles or whole groups, schedule rollouts for specific time windows and check the health of every application. No one has to go out to a vehicle.
  • Over-the-air updates while vehicles are in service
  • Rollout windows per vehicle group
  • One repository for the entire fleet
Contact Us
MASTER BACKUP
MASTER BACKUP
MASTER BACKUP
Service-IP 10.0.0.10
Resilience

Data Center Resilience, Built for Daily Service

Each vehicle runs its own independent Kubernetes cluster. Lose the connection, and your applications keep running locally, with their data on Persistent Volumes in the vehicle. Lose a device, and a second one takes over through a virtual service IP. And if a container crashes, Kubernetes restarts it before anyone in the control center even notices.
  • Keeps running offline, vehicle by vehicle
  • Failover between devices
  • Crashed containers restart automatically
Contact Us
Helm Chart main
app v2.3.1
a3f9c1e chore: bump image tag
Commit pushed Syncing to fleet Deployed · in sync
GitOps
Extensibility

One Standard Requirement Instead of a Custom Build Every Time

Every software supplier knows Kubernetes. So instead of commissioning a custom build for each onboard application, you write a single line into the spec: must run as a standard Kubernetes workload. Any supplier can meet it, any application fits the platform, and when you re-tender, you swap the supplier, not the vehicle.
  • Add new applications as Helm charts
  • Switch suppliers without touching the hardware
  • Applications from Unwired, from partners, or your own
See Application Examples

Built for the Fleet.

Two rail cars facing each other at night, coupler released, a green status light on each car front
One Cluster per Vehicle

One Independent Cluster per Vehicle, on the Router or on Separate Hardware

Every vehicle runs its own single-node cluster. We deliberately don't span a cluster across several cars, because cars get coupled and uncoupled all the time. Where the cluster lives is up to you: on a powerful vehicle router or on separate compute hardware running Unwired Edge Cloud OS. Either way, you manage and operate it exactly the same.
Aerial view of a rail yard at night, dozens of trainsets parked side by side, each with a green status light
From Repository to Vehicle

GitOps Rolls Out Every Release to Hundreds of Vehicles, Under Full Control

You set up your GitOps tool on the vehicles with the Helm deployer that ships with the platform. From then on, each cluster pulls its desired state from your repository and keeps itself in sync. You always know which version is running where. Rollout windows and limited concurrency, set in the Unwired Edge Cloud, stop the whole fleet from updating at once.
A fanned-out bundle of network and fiber optic cables, some fiber tips glowing green
Connected to the Vehicle Hardware

Containers Connect to In-Vehicle VLANs and Physical Interfaces

Advanced networking connects containers directly to the VLANs of the in-vehicle network, while the host firewall stays in charge. Hardware access gives your onboard applications GPIO, GPS, RS485, USB, audio and DisplayPort.
Passenger train with a green light strip in a tunnel, passengers with laptops and smartphones visible through the windows
Always On

Persistent Volumes and Failover Keep Onboard Services Available

Persistent Volumes sit on a separate SSD or NVMe drive, apart from the operating system, and survive reboots and power cuts. Any service that needs a fixed address on the train gets a virtual service IP that moves to another device if the first one fails. Your onboard application gets a say through its health check.
Test lab with several vehicle routers under continuous testing, green status LEDs, test equipment and a monitor showing results in the background
Audit-Ready Out of the Box

Versions and Updates Deliver the Evidence CRA, NIS2 and ISO 27001 Require

Containers run isolated from the host system, and workloads follow Pod Security Standards: non-root, with resource limits. Before every release, the operating system and the Kubernetes service go through automated tests plus an SBOM and CVE check. Logs and metrics stream to the Unwired Edge Cloud in real time, and observability turns them into the version evidence CRA, NIS2 and ISO 27001 call for.
A single glowing glass cube next to a cluster of linked cubes, representing a single container and a Kubernetes cluster
Two Editions, One Platform

One Platform, from Compact Routers to Dedicated Compute Hardware

Unwired Edge Compute Standard runs lightweight OCI containers on every device in the portfolio, and that is all you need to virtualize a single onboard application. Unwired Edge Compute for Kubernetes is for fleets that want to run their onboard applications the way a data center does: standardized, centrally managed and resilient. Read more about edge computing.

Protect Your Investment: One Platform for Everything You Put on Board.

A Platform, Not Another Project
The platform grows with your fleet. Every new onboard application builds on the same foundation, with no hardware or integration project of its own.
Predictable Rollouts
Staggered updates while vehicles are in service.
Auditable
Every version and rollout fully documented.
Works Offline
Every cluster keeps running without a connection.
Base Services
Tested and maintained by Unwired.
Open Standards, No Lock-In
Your suppliers deliver standard Kubernetes, not a custom build for the vehicle. When you re-tender, you change the supplier, not the platform.

Supported Devices.

We already support a wide range of devices, and we add more all the time. See the full list here.
Learn More

FAQ

Kubernetes is the standard data centers use to run, update and monitor applications built from many containers. Kubernetes in the vehicle takes that operating model and applies it to the fleet: onboard applications such as passenger information, passenger counting and diagnostics run as Kubernetes workloads, deployed centrally from the Unwired Edge Cloud and monitored the same way across the board. It is aimed at transit operators with larger fleets and several onboard applications from different suppliers, in other words, anywhere updates, faults and re-tendering are still handled application by application. Large rail operators in Europe already run this model.

For a single onboard application, Kubernetes rarely tips the decision; Unwired Edge Compute Standard with OCI containers is often all it takes. The real question is what you will add over the next few years. A virtualization platform in the vehicle does more than get one application on board: every application you add after it shares the same rollout, the same monitoring and the same resilience, with no new hardware project. Start with Kubernetes and you build the platform once, then specify every future application as a standard Kubernetes workload, whoever supplies it. The payoff comes over the life of the contract, not with the first project.

Both are editions of the Unwired Edge Cloud edge computing platform. Unwired Edge Compute Standard runs individual OCI containers on every device in the portfolio, smaller vehicle routers included, and is the right fit for virtualizing a single onboard application. Unwired Edge Compute for Kubernetes orchestrates applications made up of several services, using the standard Kubernetes API, Helm charts and GitOps. It adds Persistent Volumes, failover between devices and observability down to the pod. For that, you need a powerful vehicle router or separate compute hardware running Unwired Edge Cloud OS. Both editions are enabled and rolled out through the same device management.

A multi-node Kubernetes cluster has to hold a quorum at all times, meaning it must be able to reach a majority of its nodes. On a train, you can’t count on that: cars are coupled and uncoupled, links between vehicles drop, individual devices fail. A cluster spanning the whole train would break down at exactly those moments. That is why Unwired Edge Compute for Kubernetes runs an independent single-node cluster in every vehicle. Each vehicle keeps running on its own, with or without a connection to other cars or to the cloud. Resilience comes from the onboard application itself and from failover between devices using a virtual service IP.

They keep running. The cluster in the vehicle doesn’t need a cloud connection to work; it only uses one to fetch new versions from the repository and to ship logs and metrics. When the connection drops, passenger information, passenger counting and diagnostics carry on locally, with their data on Persistent Volumes in the vehicle. Once the connection is back, the vehicle syncs to its desired state and the Unwired Edge Cloud shows its status in real time again. This behavior is designed for service with patchy coverage, and you can reproduce it in the lab.

NIS2, the Cyber Resilience Act and ISO 27001 all call for traceable versions across the entire lifecycle, prompt security updates and clean separation between systems. Kubernetes in the vehicle lays the groundwork: containers run isolated from the host system, and workloads follow Pod Security Standards as non-root with resource limits. The operating system and the Kubernetes service go through an SBOM and CVE check before every release. Every version you roll out is uniquely identified and logged, and the observability of the Unwired Edge Cloud supplies the version evidence auditors ask for. You meet these requirements with the same platform you already use to manage devices and network.

There are three approaches on the market. Some vehicle router vendors offer a container runtime on their own devices, usually for individual OCI containers managed device by device. System integrators add additional hardware for each onboard application, each with its own management software. The third approach is a platform that brings network, device management and application operations together in one place. The Unwired Edge Cloud is one of these: Unwired Edge Cloud OS runs vendor-agnostic on routers and compute hardware, supports OCI containers as well as full Kubernetes, and comes with observability and long-term updates built in. What to look for: standard APIs, central rollout, audit evidence.

Ready for a Modern Fleet Network?

Bring passenger Wi-Fi, captive portal updates, uplink reliability, and device management together on one platform — controlled centrally and simple to manage.
Guifre vidal von Unwired Networks
Sabine Holzgruber Unwired Networks

Get Whitepaper

Whitepaper ROUTER
Please use your company email address.
Whitepaper TRAIN NETWORK
Please use your company email address.

Subscribe to our newsletter

Newsletter Signup