LATEST / UPBOUND
28 SEP 2026 Project Champagne: running inference in-house19 AUG 2026 Upbound v3 brings a shared API to the fleet2025 Crossplane reaches CNCF graduation
Company / The infrastructure issue

Upbound wants your cloud to stop waiting for permission

The company behind Crossplane turns cloud infrastructure into a service developers can request themselves. Its next test is giving AI agents the same freedom, with rules that survive contact with reality.

At Millennium bcp, the machines were not the only things that needed speeding up. The Portuguese bank had spent more than five years developing its infrastructure automation. Yet developers still joined a queue. Resources could be delivered efficiently; getting permission to receive them remained another matter. That small distinction explains much of Upbound’s business. A company can automate its machinery and leave its bureaucracy perfectly intact.

The useful bits
  • Build approved infrastructure services developers request through an API.
  • Keep checking those resources after the initial deployment.
  • Pay for enterprise operation, support, and governance around open source Crossplane.

The queue is the product

Upbound makes software for platform teams: the engineers who build the internal systems other developers depend on. Its foundation is Crossplane, an open source framework it created in 2018. Crossplane extends Kubernetes’ declarative approach beyond containers to infrastructure and services. A team describes the state it wants. Controllers compare that intention with reality and work to close the gap.

Imagine an approved database service. The platform team decides which settings, permissions, and supporting resources belong together, then exposes that bundle as a custom API. An application developer requests the service instead of assembling every component. The difficult decisions happen when the platform is designed; each subsequent request can reuse them.

This is the distinction worth understanding. Provisioning is an event. Reconciliation is a continuing responsibility. Terraform and Pulumi are alternatives for infrastructure automation, while running community Crossplane yourself is an alternative to buying Upbound. The choice involves how your team wants to express infrastructure and who will operate the machinery after launch.

A bank keeps the old machinery

Millennium bcp did not want to discard years of working Terraform modules. It wanted to preserve that investment while improving self-service and addressing drift and compliance. Upbound’s case study describes a phased approach using its Terraform provider. The reported service-level agreement fell from eight days to eight minutes.

“Now we can spin up an application anywhere quickly and securely”Nuno Guedes · Cloud Compute Lead, Millennium bcp

The lesson is more useful than the stopwatch. Migration can begin at the interface between a platform team and its customers, while familiar tools remain underneath. Developers get an approved path; infrastructure specialists retain responsibility for how it works.

At Brazilian cosmetics group Grupo Boticário, a small infrastructure team served a hundred product teams. Different tools and repeated requests produced a backlog. Its platform combined Crossplane and Upbound with GitHub Actions, ArgoCD, and Backstage. Upbound reports deployments in minutes rather than more than seven days. These are particular customer outcomes, dependent on their starting points, rather than a timetable every buyer inherits.

The business above the open source

Founder and CEO Bassam Tabbara had already co-founded Symform and served as CTO at Quantum. Upbound, founded in 2017, carries that infrastructure background into a commercial platform. Crossplane’s separate community achieved CNCF graduation in 2025, following work on security audits and vendor-neutral governance. Open source provides a foundation beyond one company’s subscription.

Upbound founder and CEO Bassam Tabbara
A man with a standing appointment with infrastructure. Bassam Tabbara, Upbound’s founder and CEO, previously co-founded Symform.

Upbound sells the surrounding operational work. Its offerings include a supported Crossplane distribution, managed control planes, self-hosting options, official integration packages, developer tooling, and professional services. Platform v3 adds a shared fleet API, web console, and identity model. Buyers are paying to make an internal platform dependable and governable, with assistance when the abstractions become awkward.

Published Standard starting minimum$1,000/ month

Consumption-based. Enterprise and Business Critical are custom-priced.

Resources are metered per resource-hour, with plan consumption minimums. The subscription also sits beside cloud bills and the engineering effort required to design services. Upbound announced a $60 million Series B in November 2021, bringing announced funding to $69 million. Altimeter led that round alongside GV, Intel Capital, and Telstra Ventures.

Developer tooling is part of the offer too. Upbound’s testing workflow can render composition output offline, allowing engineers to check the resources their logic produces before contacting a cloud. That catches a different class of mistake from a live integration test. The latter still matters: a correctly rendered configuration cannot prove that a provider will accept it.

One set of rules, even for the robots

As infrastructure spreads across teams, knowing what exists becomes its own job. Upbound v3, launched in August 2026, gives humans, pipelines, and agents access paths to a shared estate. Hub supplies the fleet API; Console supplies the browser interface. Scoped identities and access controls put permissions into the system that handles the operation.

Upbound Insights dashboard showing control plane, resource, and definition inventory alongside an activity chart
The fleet, finally in one frame. Upbound’s published Insights dashboard. Select the image for a closer look; these are product illustration values.

Its own development fleet supplied a revealing test. Insights flagged 230 unsynced resources across 24 control planes. Engineers connected Claude to Hub and grouped the failures. Eleven missing secrets accounted for 181 of them. Restoring one credential reduced the count by 61. A formidable backlog had become a smaller set of causes. This was an internal example with deliberately scrubbed development resources, rather than a customer benchmark.

The $15,000 experiment

The newer Modelplane project applies control planes to AI inference. Still in early development, it orchestrates clusters, model placement, serving engines, and routing across infrastructure. In September 2026, Upbound described Project Champagne: running its own workloads on the technology it wanted others to use.

The starting budget was $15,000 a month, intended to grow with experience. GPU capacity became an early obstacle: AWS quota did not guarantee available machines. The team also reconsidered chasing newer models when its existing ones were running below their supported context lengths. Better use of the current setup offered an improvement without immediately buying more hardware.

Those details keep the proposition honest. Owning inference means owning operational questions about memory, streaming, identity, and hardware availability. A control plane helps organize that work. The work still exists.

Behind the software is a remote-first company. Its February 2026 account of a Cancún gathering describes engineers and commercial teams meeting to discuss customer feedback and strategy. Distributed work still occasionally calls for everyone to occupy the same room.

Start with the waiting

My reading of these examples is to begin with one repeated request, one approved service, and a measured queue. Preserve working modules where practical. Test the platform’s logic before deploying it, then verify it against real infrastructure. Expand when developers actually use the path.

The purchasing question follows from that experiment: which operations will the vendor handle, and which decisions will your engineers continue to own? An internal platform needs a product owner as well as a runtime.

The fit is strongest when infrastructure requests repeat and a team can maintain shared APIs and policies. A small, occasional deployment may not justify that commitment. Upbound’s appeal grows with the number of people waiting for someone else to make the cloud available.