“I know that AWS is based in the United States. However, we now have a European sovereign cloud.”
Tina Morris, technical business developer within Amazon’s cloud division, made the remark at the latest RIPE Meeting. She was reacting to the RIPE NCC’s intention to reduce its dependence on American hyperscalers.
The regional IP address registry, which serves Europe and part of Asia, fears a potential presidential decree that could cut it off from technologies. Its executive director would like to believe the scenario is “unthinkable,” but he concedes that it cannot be ruled out.
A Geopolitical Wake-Up Call
In this context, the RIPE NCC is “re-evaluating” its architecture. It is not a question of restoring it to how it looked before the launch of its cloud-first strategy in 2019. Expectations around security, stability, and resilience are, in fact, no longer the same, especially at the regulatory level. Yet geopolitical uncertainty pushes toward a more independent and self-hosted approach. The rising costs of cloud usage are another factor.
This reversal had already been largely decided last year. With, among other things, a pause on PaaS deployments. Things are now clearer, we are told. The RIPE NCC does not spell out its plans, but it does speak of a greenfield migration. It estimates a €5 million cost for 2026–2028. Its operating expenses would return to the level seen in the 2010s. Moreover, it will need to replace obsolete equipment that was not replaced when investments were focused on the cloud.
A S3 Migration Decided in 2021 Within an Economic Logic
At AWS, the RIPE NCC uses S3, notably to store the historical data of its RIPE Atlas platform (which measures Internet connectivity).
That platform weighed in at nearly 1 petabyte in the autumn of 2021, when the registry formalized its Cloud Strategy Framework. It complemented this with a methodology for evaluating the criticality of its services, including levels of requirements (uptime, avoiding lock-in with managed services, reducing dependencies on a single provider, etc.).
The cloud migration, at its core, rested on an economic rationale. The RIPE NCC admitted that it had initially believed the savings from reduced storage costs would, in the long term, offset the growth in data volume. It designed the underlying architecture (Hadoop + HBase) accordingly, with the intention of acquiring off-the-shelf hardware progressively.
Following this model, by early 2024 the RIPE NCC had reached roughly fifty racks across two data centers. Its annual hosting and power costs—excluding equipment and engineering—were around one million euros. With the prospect of halving its footprint by the end of the year and then limiting it to ten racks by the end of 2025, it had decided to move part of RIPE Atlas to the cloud—as well as its RIS (Routing Information Service) base. All while keeping on-site the “jewels of the crown,” such as the registry, member data, and the RPKI infrastructure.
“Hot” RIPE Atlas data (less than a month old) was hosted in a Hadoop cluster on bare metal at Hetzner. The older data remained on S3, exploiting storage classes down to Glacier. The back-end ran on EKS, with BigQuery enabling researchers to access open measurement data.
A Cloud Framework Relaxed Over Time
Over time, the RIPE NCC had loosened its cloud framework along several dimensions. It had, for instance, allowed, except for its most critical services, the use of industry standards in addition to open standards. The framework for evaluating service criticality also evolved, placing greater emphasis on data integrity and confidentiality.
The on-site portion also underwent changes. In particular, the vendors involved. The two companies with which the RIPE NCC had contracted had, through mergers and acquisitions, ended up under the same corporate umbrella. One of the two data centers now sits outside Amsterdam… and above sea level, we are told.
The architecture renewal will span 2027–2031. It will include a virtualization component, with the RIPE NCC aiming to minimize the lock-in in this area… It is worth noting that it uses AWS for online meetings, Google Workspace for productivity, and Akamai for the CDN.