You typed "openstack cloud with ddos protection" into a search box, which tells me a few things about you. You already know what OpenStack is, so you're not someone who needs a cloud explained from scratch. And you've either been hit by a DDoS attack before, or you're smart enough to want a wall up before the first wave arrives. Either way, you're shopping for two things at once — an open-source cloud platform you actually control, and a network that won't fold the moment somebody points a fire hose at your IP.
That's a narrower ask than it sounds. Most "DDoS-protected cloud" results you'll see fall into two camps. The first is the hyperscalers — AWS, Azure, GCP — where DDoS protection is a line item, sometimes a pricey one, and where the cloud itself runs on proprietary software that quietly locks you in. The second is a long tail of hosts that slap a "DDoS protected" badge on the homepage and then null-route your IP the moment real traffic shows up, because their idea of mitigation is to make you invisible to the internet so the attack stops hitting them.
What you probably want sits in between: an OpenStack environment you can script against, move workloads in and out of, and own your images — sitting on a network that was built around attack mitigation rather than bolting it on as a marketing afterthought. That's the specific gap Sharktech has been filling since 2003, and their OpenStack cloud is the most direct answer to this particular search I've found. Let me walk you through what's actually there.
OpenStack itself doesn't ship with a DDoS story. It's a control plane — Nova for compute, Neutron for networking, Cinder and Swift for storage, Keystone for identity. It gives you APIs, multi-tenancy, floating IPs, security groups, snapshots, the works. But the moment an attack lands on your public IP, OpenStack looks at Neutron and Neutron looks back at you, and neither of them has a 600 Gbps scrubbing facility in the trunk.
So the protection has to live a layer below the cloud software — at the network edge, on the provider's backbone, ideally on infrastructure the provider owns and operates themselves rather than rents from a third-party scrubbing service. This is the part that filters out most of the field. A provider can run a perfectly good OpenStack deployment and still have a network that isn't built to absorb a volumetric attack, because building that network is a completely different and much more expensive skill.
The other half of the problem is openness. The whole reason you typed "openstack" instead of just "cloud" is that you don't want to be trapped. You want to upload your own qcow2 images, run your own cloud-init scripts, download your disk when you leave, and not have to learn a vendor's proprietary API just to spawn a VM. A lot of "managed OpenStack" offerings quietly strip that freedom away, and a lot of providers who do keep it open don't have the network. Finding both in one place is the actual job here.
Sharktech is a Las Vegas-based infrastructure provider that's been around since August 2003 — which, in hosting years, makes them older than the iPhone and most of the cloud industry as we know it. They run five data centers: Los Angeles, Las Vegas, Denver, Chicago, and Amsterdam. Their reputation was built on DDoS-protected hosting first, and they added an OpenStack-powered cloud on top of that foundation later, which is the opposite order from most providers and the reason the combo actually works here.
The key detail: their cloud platform runs on the same network that was engineered around attack mitigation from day one. It's not a separate product with a separate (weaker) pipe. The entire infrastructure — cloud, bare metal, VPS — sits behind the same mitigation system, which is included in the base price of every plan rather than being a premium add-on you have to remember to tick.
If you want to skip ahead and look at the actual cloud plans, here's the door:
👉 Explore Sharktech's OpenStack cloud plans
Here's what's verifiable from Sharktech's own materials and corroborated by long-term users. Every plan, at every tier, includes mitigation up to 60 Gbps per IP at no extra charge — it's baked into the base price, not a line item. Their global connectivity sits at roughly 1.1 Tbps, which is the total capacity attacks can be scrubbed across. The system is their own proprietary mitigation rather than a rebranded third-party appliance, and it watches the network in real time and filters attacks as they happen instead of waiting for a threshold and then null-routing you.
The real-world data point that's worth more than any spec sheet: a game-server operator reported absorbing attacks in the 38 Gbps range on a regular basis with services staying online. Gaming traffic is about the harshest test case there is for DDoS protection, because game servers are targeted constantly and players notice latency spikes in milliseconds. If the mitigation holds there, it'll hold for an e-commerce frontend, a fintech API, or a corporate site that suddenly gets noticed by the wrong people.
For OpenStack specifically, this matters in a way that's easy to underestimate. In a public OpenStack cloud, your workloads share physical infrastructure with other tenants, which means an attack aimed at a neighbor can become your problem if the provider's edge isn't robust. A network that's been built to absorb hundreds of Gbps is exactly the kind of moat that keeps a loud neighbor from becoming your outage.
The cloud itself is OpenStack-powered and runs on Virtuozzo Virtual Hybrid Infrastructure under the hood. The pitch that's relevant to your search is the no-lock-in part, and it's real rather than rhetorical.
You get a resource pool instead of fixed VM presets. So if you've bought, say, 8 vCPUs, 8 GB of RAM, and 300 GB of SSD, you can carve that into one big VM, four small ones, or any combination in between — and redistribute it later when your needs change. That's a fundamentally different mental model from "pick a t3.medium and live with it."
On the openness front:
You can upload your own disk images (qcow2) and custom ISOs through the web portal or the API, so migrating an existing workload in is straightforward.
You can download your server disk images whenever you want — for offsite backup, disaster recovery, or just because you've decided to leave. Your data stays yours.
The full RESTful API surface is exposed: Nova for compute, Cinder and Swift for storage, Neutron for networking, Keystone for identity. If you've already got Terraform or Ansible modules written against OpenStack, they'll work here.
Linux images are pulled from official upstream cloud images and refreshed weekly, and you can layer your own bash or cloud-init scripts on top at launch.
The networking stack is the part that rounds out the "real OpenStack" feel: private networks for isolating backend traffic, security groups for granular firewall rules, virtual routers with NAT, floating IPs, load balancing, IPv4 and IPv6, and native VPN support for bridging the cloud to on-prem hardware — free, not upsold.
Storage comes in three tiers, and the performance numbers are published rather than vague:
NVMe at roughly 1.2 GB/s and up to 18,000 IOPS — the tier for databases and anything latency-sensitive.
SSD at roughly 350 MB/s and up to 6,000 IOPS — the general-purpose workhorse.
HDD at roughly 120 MB/s and up to 3,000 IOPS — for archives and backups where cost matters more than speed.
All of this sits on a 40G/100G internal cloud network with full redundancy, so a single hardware failure doesn't take your VMs down — they're spread across multiple servers and storage nodes.
Sharktech splits their cloud into two billing models. Public Cloud is pay-as-you-go: each plan includes a fixed resource commit, and if you go over, you pay hourly for the extra. Dedicated Cloud is the prepaid version — you get exactly what you ordered, billed flat each month, no surprises. Both run on the same OpenStack infrastructure; the only difference is how the bill behaves.
Here are the public cloud tiers with the details I can confirm. Prices below are the monthly included-commit rates; overage is billed hourly beyond that.
Public Cloud Tiny
Price: $7.95/month
What's included: an entry-level resource allocation meant for getting a small workload live on the OpenStack platform without committing to a larger pool.
Who it's for: someone who wants to test the platform, run a single small service, or just kick the tires on the API and the control panel before scaling up.
The catch: it's the floor of the lineup, so once you outgrow it you'll want to move up rather than push it past its commit.
Public Cloud Small
Price: $39/month
What's included: 4 vCPU, 8 GB RAM, 300 GB SSD storage, 1 public IPv4 address, and the standard included outbound bandwidth.
Who it's for: a small production app, a staging environment that mirrors production, or a dev team that wants real OpenStack without hyperscaler pricing.
The key difference from Tiny: enough RAM and storage to run a real workload instead of a proof of concept.
Public Cloud Medium
Price: $79/month
What's included: 8 vCPU, 16 GB RAM, 800 GB SSD storage, 1 public IPv4 address, and included outbound bandwidth.
Who it's for: a mid-tier web app, a database server with room to breathe, or a cluster of smaller VMs carved out of the resource pool.
The key difference from Small: double the cores, double the RAM, and a serious bump in storage — the point where you can split the pool across multiple VMs for real.
Public Cloud Large
Price: approximately $249/month
What's included: a substantial resource pool in the 32 vCPU / 64 GB RAM range with over 1 TB of SSD storage and 15 TB of included outbound bandwidth.
Who it's for: production workloads with real traffic, multi-tenant SaaS deployments, or teams consolidating several services onto one OpenStack tenant.
The key difference from Medium: this is where the resource-pool model starts paying for itself, because you can run a small fleet of VMs instead of one big one.
Public Cloud Enterprise
Price: starting at $499/month
What's included: 64 vCPU, 128 GB RAM, 5 TB SSD storage, 20 TB outbound bandwidth, 1 public IPv4.
Who it's for: heavier workloads, larger teams, and anyone who's been comparing this exact configuration against an AWS EC2 equivalent and doing the math.
The key difference: this is the tier where Sharktech's "at least 40% cheaper than hyperscalers" claim starts translating into noticeable monthly savings, and where the included DDoS protection stops being a nice-to-have and starts being a line item you'd be paying extra for elsewhere.
Custom Cloud
If none of those fit — because you need more compute, a specific storage mix, or a particular network configuration — Sharktech will quote a custom plan. This is the route for unusual workloads rather than a pricing trick.
A few specifics worth knowing before you commit, because the OpenStack public cloud model has a couple of quirks that aren't obvious from the plan names.
Public Cloud plans (except Enterprise and Custom) come with a maximum resource cap. That's a deliberate ceiling to stop a runaway script or a misconfigured autoscaler from quietly racking up an unbounded bill — a genuinely thoughtful detail if you've ever watched a hyperscaler charge spiral at 3 AM. You can exceed your included commit and pay hourly for the overage, but only up to that cap; beyond it, you'd move to a larger plan or a Custom quote.
The hourly overage rates are published and flat across the platform:
CPU: $0.0025 per core per hour
RAM: $0.0035 per GB per hour
NVMe storage: $0.00009 per GB per hour
SSD storage: $0.00006 per GB per hour
HDD storage: $0.00002 per GB per hour
On bandwidth: inbound traffic is free, full stop. Outbound traffic includes 5,000 GB (5 TB) per month in the base plan, and anything beyond that is billed at $0.002 per GB. That egress rate is dramatically lower than what the big three charge for outbound data transfer, and the "ingress is free" piece matters more than people realize — it's the difference between a migration costing nothing and a migration costing four figures.
Each cloud instance includes one public IPv4 address at no charge. Additional IPv4 addresses are $1.50 per month each. IPv6 is supported throughout.
Sharktech runs promotional pricing fairly often, and longer billing cycles come with automatic discounts — annual billing in particular is where the per-month number drops noticeably compared to paying month-to-month. Rather than quote a specific coupon code that might be expired by the time you read this, the honest move is to check the current offers on the plans page when you're ready to pull the trigger:
👉 See current Sharktech cloud pricing and promos
If you're placing a larger or custom order, it's also worth opening a sales conversation directly — Sharktech's sales team has a track record of working with clients on custom BGP and Anycast configurations at no extra cost for longer-term accounts, which isn't the kind of flexibility you get from a self-service hyperscaler dashboard.
The control panel is the part that surprised me. A lot of OpenStack deployments have a management UI that feels like it was designed by the people who wrote the API, for the people who wrote the API. Sharktech's is actually navigable — you can see your overall stats, your VM list with console access, your routers, your floating IPs, your firewalls, your load balancers, and your storage allocations in views that don't require an OpenStack certification to parse.
You can deploy a VM in seconds from the portal, attach it to a private network, assign it a floating IP, put it behind a load balancer, and snapshot it — all without writing a line of YAML. And when you do want to write the YAML, the same operations are available through the API, so there's no "portal-only" feature trap.
The image library is worth a mention too: official Linux cloud images from the major distributions, refreshed weekly, with full support for SSH keys, user data, and custom cloud-init at launch. If you've got a hardened image you've built elsewhere, you can upload it as a qcow2 and boot from it directly.
Having gone through all of it, here's the honest read on fit.
It's a strong match if you're a game-server operator, a fintech or e-commerce team that gets targeted, an IT shop migrating off an overpriced hyperscaler, or a developer who wants OpenStack's freedom without running the control plane yourself. It's also a good call if you need China-facing infrastructure — Sharktech peers with China Telecom and China Mobile, which is unusual for a US-based provider and matters a lot for that specific traffic profile.
It's probably not the right fit if you want a one-click managed WordPress host, if you need a 30-day money-back guarantee (Sharktech's payments are non-refundable, which is standard for this class of infrastructure but worth knowing up front), or if you're looking for hand-holding on server administration. The support is staffed by real engineers rather than tier-1 script readers, but the expectation is that you know what you're doing with a Linux box.
"OpenStack cloud with DDoS protection" is a search that's asking for two genuinely hard things in one product, and most of the market gives you one or the other. Sharktech is one of the few places where both halves are real — the OpenStack side gives you the API surface, the image portability, the resource-pool model, and the no-lock-in freedom you came looking for, and the DDoS side gives you 60 Gbps of included mitigation per IP on a network with 1.1 Tbps of scrubbing headroom, built by people who've been doing this for over twenty years.
If you want to go hands-on with the platform, the entry point is small enough to be a learning exercise and the ceiling is high enough to run real production. Here's where to start:
👉 Open an OpenStack cloud with built-in DDoS protection at Sharktech