Executive Summary — SUSE Rancher Prime

SUSE Rancher Prime is a multi-cluster Kubernetes control plane whose defining characteristic is estate-wide reach: one management plane federating identity, RBAC, policy, and GitOps across on-premises, cloud, and edge clusters — including managed cloud Kubernetes the enterprise already runs — with VMs joining through SUSE Virtualization. Scope: the SUSE vendor boundary — the SUSE Rancher Prime base subscription plus Suite-tier components, the SUSE AI Factory subscription, and SUSE Edge, each named inline where it carries a score; capabilities requiring a different vendor remain Closeable gaps. The gap portfolio is Opinion-dominant in the platform core and Closeable-dominant at the edges. Across orchestration, runtime, and catalog, the primitives are included and the enterprise applies them — configuration, not acquisition. At the data and integration layers the shape inverts: SUSE has no data estate and no integration products, and the SUSE Application Collection's supported artifacts set floors — messaging components, an API gateway — without delivering managed capabilities. FC-2C is absent and Structural, as it is across the on-premises category. Delivery model: self-managed software on customer-owned hardware; hosted offerings cover management planes only, which anchors resource lifecycle automation at the on-premises position. The authority finding is this row's distinctive profile. Delegated dominates the DAPM column because the stack is open source with real exits — RKE2, K3s, KubeVirt, Fleet, K3k, NeuVector — so the operational opinions an enterprise accumulates on this platform are unusually portable. The exceptions: SUSE Observability, whose correlation configurations are proprietary and captive, and the NVIDIA-held GPU management layers. Identity plane continuity is federated through SUSE Rancher Prime itself as the broker: orchestration, execution across both VMs and containers, and catalog consumption are governed by one federated enterprise identity across every managed cluster. Substrate, data, reasoning, and integration layers sit outside the plane — substrate-to-runtime identity enforcement is operator-built configuration, and data governance identity awaits a data estate that does not exist in the portfolio. The agentic layer deserves precise placement. The Liz agent crew and the MCP servers embedded in SUSE Rancher Prime and SUSE Multi-Linux Manager (both GA) constitute a developed operations-tier agentic surface: agents that consume live estate topology and act on infrastructure through governed interfaces with human approval. That is operations assistance, not a reasoning plane — no component derives placement from governance metadata, and the FC-1 metadata a reasoning plane would consume does not exist in the estate. Universal Proxy, in tech preview, is the named path for AI-native integration governance and is not scored. The buyer's trade: a broad, open, low-lock-in control plane with a shipped observability platform in the base subscription — in exchange for owning the data fabric and the integration fabric entirely, and accepting component-grade rather than product-grade depth in AI governance and API lifecycle. The assembly burden sits at the edges, not the core. v1.1 records the SUSE vendor review (workbook returned July 28, 2026). No scores moved. Changes: product naming aligned (SUSE AI Factory, SUSE Application Collection, SUSE Rancher Prime); AI Library support scope documented as two labeled tiers (SUSE-built: installation through code fix; SUSE-supported community: installation and configuration, upstream code fixes); SUSE AI Factory with NVIDIA (generally available July 2026) recorded as the in-boundary NVIDIA AI Enterprise path at accelerator management; SUSE Telco Cloud added alongside SUSE Edge for bare-metal lifecycle; SUSE Storage named as the substrate-tier persistence anchor in the FC-1 note; AMD accelerator support recorded as initial validation, not scored. Two vendor requests were declined under instrument rules: crediting hardware partnerships against the resource-lifecycle delivery model, and crediting a partner ecosystem against the integration fabric — the composition boundary holds.

Identity plane continuity: federated, score 3. SUSE Rancher Prime is itself the federation broker, with Rancher Manager as the broker component. Enterprise identity providers — Active Directory, LDAP, SAML 2.0, OIDC, Okta with SCIM automated provisioning and deprovisioning — federate once into Rancher, and Rancher enforces that identity as RBAC across every managed cluster, including imported EKS, AKS, and GKE clusters. FC-2A: cluster, project, and namespace authority is governed estate-wide by the federated identity, natively. FC-2B: namespace execution is governed by propagated RBAC for both containers and VMs — SUSE Virtualization in Rancher-managed mode uses Rancher authentication, so both workload types sit in one identity plane. FC-3: catalog consumption through Rancher Apps & Marketplace is governed by the same identity; SUSE Application Collection registry access uses SUSE Customer Center accounts and service accounts, a seam at the artifact-consumption edge. The product extensions ride the same broker: SUSE Security (Suite tier) has native Rancher single sign-on with role mapping to its permission model; SUSE Observability and Open WebUI (SUSE AI Factory) join through Rancher acting as an OIDC identity provider — documented configuration of included capability, an Opinion gap. Outside the plane: FC-0 substrate identity does not gate workload execution without operator-built node label, affinity, and admission-policy bridges (Opinion, included primitives); FC-1 data governance identity has no data estate to attach to (Closeable); FC-2C is absent; FC-4 has no integration fabric to propagate identity through — SUSE Application Collection integration artifacts carry their own authentication, and the embedded MCP server governs platform operations, not application integration.

FC-0 — Physical & Virtual Substrate

Hardware lifecycle management · score 2, gap closeable, DAPM Delegated Included: Rancher lifecycles Kubernetes clusters and nodes through Cluster API. SUSE Rancher Suite tier (SUSE Virtualization): cluster upgrades move the SUSE Linux Micro node OS, the hypervisor stack, and storage as one orchestrated operation, with per-node pause-and-resume upgrade control — node OS lifecycle is genuinely integrated with workload management. SUSE Edge and SUSE Telco Cloud (separate SUSE product lines): Metal3 and Cluster API provide bare-metal lifecycle over Redfish BMC protocols — automated inspection, cleaning, provisioning, and deprovisioning — and Elemental provides node onboarding and OS lifecycle for edge estates. The boundary of the capability: no SUSE product manages firmware, BIOS, or BMC lifecycle. SUSE Multi-Linux Manager patches Linux estates but does not push firmware. OEM firmware tooling remains a separate management surface the enterprise operates alongside the platform. Closeable — firmware lifecycle automation requires acquiring and operating OEM or third-party tooling outside the SUSE boundary.

Substrate heterogeneity · score 2, gap structural, DAPM Retained SUSE Rancher Suite tier (SUSE Virtualization): runs on commodity x86_64 and ARM64 servers, with YES certification recommended rather than a strict component-combination compatibility list — enterprises can generally bring existing OEM estate hardware rather than purchasing certified node configurations. The hypervisor layer provides unified virtualization primitives across heterogeneous OEM hardware. Accelerators: NVIDIA vGPU and Multi-Instance GPU (MIG) support with automatic detection and hardware-isolated partitioning (MIG at the Suite tier; NVIDIA vGPU licensing is a separate NVIDIA relationship), and PCI passthrough for other devices. Gap from 3: accelerator management covers a single vendor family (NVIDIA), and OEM hardware management depth — firmware, out-of-band health — remains OEM-tool-specific beneath the unified virtualization layer. Bare-metal RKE2 with GPU operators is also a supported deployment shape for accelerated workloads — heterogeneity management is not bound to the hypervisor path alone. AMD accelerator support is in initial validation: AMD and SUSE began testing AMD inference microservices and enterprise blueprints on AMD Instinct MI350P in 2026. A validation effort is not a shipped product, so the productized accelerator path remains a single vendor family today. Structural — accelerator ecosystem breadth is an architectural scope constraint; this cell re-scores when a multi-vendor accelerator product reaches general availability.

Substrate portability · score 3, gap structural, DAPM Delegated Included: one Rancher management plane manages RKE2 and K3s clusters on-premises (SUSE Virtualization, bare metal), in cloud (RKE2 on cloud instances, plus imported EKS, AKS, and GKE under the same authentication, policy, and GitOps surface), and at edge (K3s, SUSE Edge) — the multi-cluster estate is one management boundary rather than per-substrate silos. The workload cluster stack runs across all substrate types without architectural change. Bounds stated honestly: SUSE Virtualization itself is on-premises only — VM workload portability is bounded to the on-premises estate, and cross-substrate portability lives at the Kubernetes layer. Gap from 4: the 4 anchor is reserved for cloud-native platforms where the hyperscaler is the substrate. Structural.

FC-1 — Distributed Data & Context Fabric

Data location and gravity awareness · score 1, gap closeable, DAPM Retained Included: SUSE Observability (250-node HA entitlement in the SUSE Rancher Prime subscription) provides programmatic, queryable topology and telemetry across the multi-cluster estate — clusters, workloads, and dependencies correlated in one model. SUSE Storage (Suite tier) exposes volume topology. This is infrastructure and storage awareness, not data awareness: no component knows what data a persistent volume contains or what regulatory classification applies to it, and there is no data catalog anywhere in the SUSE portfolio — no vendor data services estate exists to anchor one. A placement query asking where regulated data lives and whether a workload may access it from a given cluster cannot be answered by the platform. Closeable through third-party data catalog acquisition — a new vendor relationship and integration surface the enterprise owns.

Governance and compliance metadata · score 2, gap closeable, DAPM Retained SUSE Rancher Suite tier (SUSE Security): admission control, runtime enforcement, network microsegmentation, and compliance scanning against CIS, PCI DSS, NIST, and HIPAA frameworks at the infrastructure and Kubernetes workload level — and network-layer data loss prevention that inspects payloads in flight, a genuine data-adjacent enforcement capability. Kubewarden (certified Rancher project, add-on subscription) adds policy-as-code admission control. These governance capabilities propagate to workload admission and runtime enforcement. The boundary: none of it classifies or governs enterprise data — database records, files by sensitivity, SaaS system data — and no compliance metadata propagates to placement enforcement. Score 2 reflects genuine workload and infrastructure governance bounded at the data line. Closeable through data governance platform acquisition.

Retrieval and context services · score 3, gap opinion, DAPM Delegated SUSE AI Factory subscription required: purpose-built vector databases — Milvus and Qdrant — ship in the base SUSE AI Factory offering as AI Library applications, with out-of-the-box observability wiring into SUSE Observability, alongside vLLM and Ollama model serving and Open WebUI pipelines for retrieval-augmented patterns. One SUSE vendor relationship, no SI gate. Provenance stated precisely: AI Library registry applications are mirrored upstream projects with SUSE supply-chain attestation, supported at the product level within the SUSE AI Factory subscription — vendor-delivered open source with per-application support labels: SUSE-built applications are supported from installation through configuration to code fix, and SUSE-supported community applications receive installation and configuration support with code fixes flowing through upstream into the next release (vendor-confirmed, July 2026). Pre-validated blueprints — retrieval-augmented generation and inference-endpoint stacks assembled from SUSE Application Collection applications and AI components, in SUSE-curated and NVIDIA AI Enterprise variants — provide vetted starting assemblies. Gap from 4: this is not a managed RAG pipeline service — the enterprise deploys from AI Library and operates the retrieval stack itself. Opinion — applying what the subscription already contains, no new capability acquisition.

Data pipeline and lineage · score 2, gap closeable, DAPM Delegated SUSE AI Factory subscription required: MLflow and Kubeflow ship as AI Library applications — ML pipeline orchestration and experiment/artifact lineage for AI workloads, vendor-delivered and product-supported. For traditional data: SUSE Application Collection carries Apache Kafka as an attested, validated artifact — deployable within the SUSE boundary with artifact-level support — but an artifact is not a managed pipeline service, and this function requires managed pipeline capability: no SUSE product provides ETL, change data capture, streaming pipeline management, or enterprise data lineage. The profile is exactly the gradient's middle: ML pipelines present through the SUSE AI Factory subscription, traditional pipeline capability absent. Closeable — estate-scale pipeline and lineage capability requires platform acquisition outside the boundary.

FC-2A — Infrastructure Orchestration

Workload universality · score 3, gap structural, DAPM Delegated Included: containers orchestrated natively across the estate — RKE2 and K3s clusters plus imported EKS, AKS, and GKE under one Rancher plane with shared authentication, RBAC, and projects. SUSE Rancher Suite tier (SUSE Virtualization): VMs join through unified VM-and-container management in a single Rancher pane. Batch runs as Kubernetes Jobs; AI workloads run as Kubernetes workloads (SUSE AI Factory on RKE2). The architecture is federated — VMs execute on HCI clusters, containers on workload clusters, often provisioned as guest clusters sharing the same HCI capacity pool — with management unified above. No managed database service exists in the portfolio; databases run as workloads the enterprise operates. Gap from 4: shared pools and quota do not span workload types as a single scheduler, and GPU scheduling intelligence is partly held by the accelerator vendor. Structural — single-scheduler workload universality is not productized on-premises.

Resource lifecycle automation · score 2, gap structural, DAPM Retained Included: automated lifecycle within fixed capacity — Cluster API node provisioning, Rancher auto-provisioning RKE2 nodes as SUSE Virtualization VMs (genuinely elastic within the HCI pool), cluster autoscaler on cloud substrate, SUSE Storage replica management. VM Auto Balancing (utilization-based VM redistribution) is early access and not scored. Delivery model, which is part of this score: SUSE sells self-managed software on customer-owned hardware. SUSE Rancher Prime Hosted and SUSE Observability Hosted Prime host management planes only — there is no managed hardware consumption offering with pre-staged capacity. On-premises capacity is bounded by owned physical nodes; the physical supply chain remains outside the platform's control. Structural — the on-premises operating model constraint.

Policy and quota enforcement · score 3, gap opinion, DAPM Retained Included: estate-wide RBAC — one authentication and role surface enforced across every managed cluster, including imported EKS, AKS, and GKE clusters, so policy authority extends across control planes the enterprise does not host. Projects apply resource quotas across namespaces; Fleet distributes policy and configuration declaratively at fleet scale with drift detection. Kubewarden (certified Rancher project, add-on subscription): policy-as-code admission control with a policy library. SUSE Rancher Suite tier (SUSE Security): admission and runtime security enforcement. Gap from 4: enforcement layers — admission, network, runtime — are configured per layer from included primitives rather than propagating from a single policy engine. Opinion — the enterprise configures consistent enforcement using what the subscription contains.

Substrate lifecycle integration · score 2, gap closeable, DAPM Delegated SUSE Rancher Suite tier (SUSE Virtualization): maintenance mode live-migrates VMs before node maintenance; integrated upgrades move node OS, hypervisor, and storage as one orchestrated operation with per-node pause-and-resume control; Kubernetes node health drives workload rescheduling; SUSE Storage rebuilds replicas on node failure. Gap from 3: no hardware-event layer — out-of-band hardware health telemetry (IPMI, Redfish) does not feed scheduling or update decisions during operations. SUSE Edge's Metal3 inspection is provisioning-time, not operational. Firmware lifecycle sits entirely outside the platform (see FC-0 F1). Planned maintenance evacuates workloads correctly; what is missing is the substrate health signal informing the control plane's decisions. Closeable — hardware-event integration requires acquiring and integrating OEM management tooling.

Accelerator and GPU management · score 3, gap opinion, DAPM Delegated SUSE Rancher Suite tier: NVIDIA vGPU and Multi-Instance GPU (MIG) support on SUSE Virtualization with automatic detection and hardware-isolated partitioning (NVIDIA vGPU capability is also delivered in-boundary through SUSE AI Factory with NVIDIA, which embeds NVIDIA AI Enterprise into the SUSE offering, generally available July 2026, with NVIDIA AI Enterprise certification extending to SUSE Linux Enterprise Server; standalone NVIDIA vGPU licensing otherwise remains a separate NVIDIA relationship). Included in SUSE Rancher Prime: NVIDIA GPU Operator validated on RKE2, backed by RKE2's CNCF Kubernetes AI Conformance certification — independently validated GPU device plugin integration, gang scheduling, and high-performance networking — and Virtual Cluster GPU multi-tenancy via K3k (GA): isolated Kubernetes control planes on shared GPU infrastructure in shared GPU mode, with per-virtual-cluster GPU usage restriction as the documented quota mechanism. The platform provides hardware-enforced partitioning plus a shipped multi-tenancy and quota layer. Gap from 4: scheduling intelligence — topology-aware placement, fair-share queueing — remains with NVIDIA components or enterprise-applied upstream tooling rather than native platform scheduling. Opinion — advanced patterns are configured from validated primitives already in the boundary.

FC-2B — Execution & Runtime

Runtime universality · score 3, gap structural, DAPM Delegated Included: containers execute across the RKE2/K3s estate; batch runs as Kubernetes Jobs. SUSE Rancher Suite tier (SUSE Virtualization): VMs execute as KubeVirt custom resources — kubectl-manageable, Kubernetes-native API surface. SUSE AI Factory subscription: AI inference runs as Kubernetes workloads with OpenAI-compatible endpoints. Every workload type speaks the Kubernetes API — the developer toolchain is consistent in kind across the portfolio. The structural shape: workload types execute in separate cluster domains — HCI clusters for VMs, workload clusters for containers, often as guest clusters on the same HCI capacity — unified at the Rancher management layer rather than sharing one cluster boundary. Gap from 4: a single execution surface spanning all workload types in one namespace and scheduler is not productized on-premises. Structural.

Persona abstraction at execution · score 3, gap opinion, DAPM Retained Platform-gap versus opinion-gap, stated explicitly: the primitives exist and are complete; the shipped opinion covers some workload types. Included primitives: Rancher projects and RBAC separate developer and operator personas across the estate; K3k virtual clusters give developers an entire isolated Kubernetes control plane while operators retain the substrate — control-plane-grain persona separation, a stronger isolation unit than namespace scoping; Fleet separates application-team GitOps from infrastructure configuration. SUSE Rancher Suite tier: SUSE Virtualization VM templates and instance types abstract substrate details when operators pre-configure them; SUSE Security provides the security-audit persona surface at runtime, and SUSE Observability (included) provides estate-wide operator visibility. The opinion gap: turnkey separation is shipped for container workloads through the Rancher UI and project model; VM workloads expose more network and storage substrate to developers unless operators pre-configure templates. Opinion — configuration of existing primitives, no acquisition.

Execution lifecycle and observability · score 3, gap opinion, DAPM Ceded Two components scored together, per the function definition. Telemetry exposure: standard formats across the estate — Prometheus, OpenTelemetry, OTLP — including out-of-the-box OpenTelemetry instrumentation for SUSE AI Factory components (Ollama, Open WebUI, Milvus). Correlation layer: shipped in the base subscription — SUSE Observability (250-node HA entitlement with SUSE Rancher Prime) is a dedicated topology-correlation platform, correlating topology, telemetry, and traces across the multi-cluster estate in one model, with an AI agent surface over it. Buyer situation, per the function's discipline: for buyers without an observability platform, the correlation layer is included rather than a separate acquisition; for buyers with one, standard-format telemetry integrates as configuration. Gap from 4: correlation across VM guest interiors and AI surfaces requires configuration and agents, and the enterprise operates the observability platform itself — it is software in the subscription, not a managed service. Opinion.

AI inference and agent execution · score 3, gap opinion, DAPM Delegated SUSE AI Factory subscription required: model serving is platform-native in the base offering — vLLM and Ollama from AI Library, Open WebUI as the serving front end, LiteLLM as the model-API proxy layer (API keys, multi-provider routing, cost tracking), mcpo for MCP-to-OpenAPI bridging, MLflow for model lifecycle, and out-of-the-box AI observability into SUSE Observability. Universal Proxy — centralized MCP endpoint governance — is tech preview and not scored. Gap from 4, and the within-band character stated plainly: governance depth (token quotas, showback, gateway policy) comes from applying LiteLLM, a mirrored-upstream component inside the supported stack, rather than from a shipped governance product; inference auto-scaling is Kubernetes-native (HPA/KEDA) rather than serverless. Opinion — the components are in the subscription; the enterprise configures the governance depth it needs.

FC-2C — The Reasoning Plane

Autonomous placement reasoning · score 0, gap structural, DAPM Retained What exists: Kubernetes scheduler primitives (affinity, taints and tolerations), Fleet's cluster-label targeting for GitOps placement at fleet scale, Kubewarden admission policies, SUSE Virtualization VM scheduling (VM Auto Balancing, early access, is utilization rebalancing, not policy reasoning). The Liz agent crew (GA) correlates live estate signals and executes operations through governed MCP interfaces with human approval. Applying the derivation test to a concrete scenario — a new GDPR residency requirement arrives: the constraint enters through a human, because no data-classification plane exists to receive it programmatically (see FC-1); the operator translates it into Fleet cluster selectors, Kubewarden admission policies, and network segmentation rules; the platform dispatches those rules exactly as written. Liz can assist — draft the policy, audit drift, correlate violations — but with human approval, as operator tooling. The constraint-to-rule translation remains the operator's job. This is rule dispatch executed well, not derivation. The agentic layer is genuine scaffolding at the operations tier — agents consuming live topology and acting on infrastructure through governed interfaces — but operations assistance is not placement reasoning, and the gap is doubly structural: the reasoning plane is absent, and the FC-1 governance metadata it would consume is also absent. Structural — no product with a confirmed timeline addresses placement derivation from governance metadata.

FC-3 — Application Distribution and Governance

Application catalog and distribution · score 3, gap opinion, DAPM Delegated Included: a supply-chain-first catalog. SUSE Application Collection (Prime tier, approximately 141 applications) delivers curated applications as coherent units — base image, runtime, application, Helm chart — with signatures, SBOM/VEX, SLSA Level 3 provenance attestation, and subscription- and service-account-gated consumption. Rancher Apps & Marketplace provides Helm-based deployment with repository control. SUSE Rancher Suite tier (SUSE Private Registry, Harbor-based): the enterprise's own governed publication surface — RBAC, scanning, signing, retention. Kubewarden (certified Rancher project, add-on subscription) closes the consumption loop by enforcing signature verification at admission. VM images are governed at the SUSE Virtualization image and template level; AI components distribute through AI Library (SUSE AI Factory subscription). Gap from 4: this is a chart-and-image catalog — strong publication governance with thinner day-2 operational intelligence, Helm upgrades rather than operators encoding application-specific operational knowledge; traditional applications inside VMs are governed at the image level, not the application payload. Opinion — extending governance uses registry and admission primitives already in the boundary.

Application lifecycle governance · score 3, gap opinion, DAPM Delegated Included: Fleet GitOps, first-party and fleet-scale — declarative application lifecycle with every change Git-tracked, drift detected, and reconciliation logged: audit trail as architecture. One engine spans the entire estate — the same GitOps lifecycle governance applies to every managed cluster and workload type rather than separate per-product lifecycle domains, which is what earns the score. SUSE Application Collection provides version streams with chart comparison for upgrade evaluation. SUSE Rancher Suite tier: Harbor-based retention and immutability policies in Private Registry; SUSE Security provides runtime compliance drift detection. Rancher audit logging records management-plane actions. Gap from 4: no channel-based deprecation and retirement semantics for catalog content, and unified audit across all application types in one correlated surface requires SIEM integration — configuration against standard audit telemetry. Opinion.

Developer experience and self-service · score 3, gap opinion, DAPM Delegated Included: self-service deployment from the Rancher catalog within project RBAC and quota guardrails — approval is platform policy, not a ticket queue. K3k virtual clusters as self-service units: a developer receives an entire isolated Kubernetes control plane on shared infrastructure, a coarser and cleaner self-service grain than namespace vending. SUSE Rancher Suite tier: VM self-service through the unified Rancher pane. Rancher Developer Access (separately purchased subscription): SUSE Application Collection integrated into Rancher Desktop with zero-CVE images — workstation-to-production artifact continuity. SUSE AI Factory subscription: AI self-service through Open WebUI and AI Library. Gap from 4: no internal developer portal product — golden-path platform engineering (a Backstage-class portal) is enterprise assembly — and the self-service grain varies across workload types. Opinion — consistent entry points are configured from included primitives.

AI application and agent distribution · score 2, gap closeable, DAPM Delegated SUSE AI Factory subscription: AI components distribute through AI Library and Helm with supply-chain attestation — governed distribution through general-purpose mechanisms. Model versioning exists as an applied component: the MLflow model registry within the SUSE AI Factory subscription, and Ollama model management. What is absent is a productized AI-specific governance surface: no model catalog shipped as a product with RBAC and token quotas, no agent tool authorization, no prompt-injection controls, no AI output audit trails. Universal Proxy (tech preview, not scored) targets MCP connection governance — an integration-layer capability, not distribution governance. Score 2: distribution via general-purpose mechanisms without AI-specific audit. Closeable — partial hardening is available by applying MLflow and admission primitives, but AI-specific governance at the next band requires capability no SUSE subscription currently contains.

FC-4 — Integration Fabric

Event fabric and messaging · score 1, gap closeable, DAPM Delegated No event fabric product exists in the SUSE portfolio. What the boundary provides: Apache Kafka and NATS ship as SUSE Application Collection artifacts — attested images and charts validated on RKE2, with artifact-level support inside the one-vendor boundary. Deploying them yields messaging the enterprise operates; it does not yield a managed event fabric — schema governance, filtering, fan-out, dead-letter handling, replay, and delivery guarantees as operated capability remain enterprise-built on top of the deployed components. The artifact tier sets the floor at 1 (messaging components available within the vendor boundary); the managed-fabric capability is Closeable — reaching it requires either acquiring a managed streaming platform from a different vendor or building and operating the fabric layer as an enterprise capability.

API management and gateway · score 2, gap opinion, DAPM Delegated No API management product exists in the SUSE portfolio. What the boundary provides: Apache APISIX — an API gateway with authentication, rate limiting, and transformation capability — ships as an SUSE Application Collection artifact, and Traefik Gateway API is the supported ingress path on RKE2 with long-term support. This is a gateway component, enterprise-operated: the gateway function is real and in-boundary, with artifact-level support. Gap from 3: no productized API lifecycle — publication workflow, developer portal, versioning governance, and API analytics as vendor-operated capability; the enterprise assembles these from APISIX's own feature set and operates the result. Opinion — the component is already in the subscription and the enterprise applies it; support is artifact-level, and the operational lifecycle of the gateway is the enterprise's own.

Workflow and process orchestration · score 0, gap closeable, DAPM Retained No workflow or process orchestration capability exists anywhere in the boundary. Fleet is GitOps continuous delivery, not process orchestration. No workflow engine ships in any SUSE product or in the SUSE Application Collection. The Liz agent crew executes operational tasks with human approval and is not a business-process engine. BPMN-compliant business process orchestration — long-running transactions, saga patterns, compensation logic, human task management — and AI agent chain orchestration require acquisition entirely outside the SUSE boundary and enterprise operation of the result. Closeable.

SaaS and enterprise system integration · score 0, gap closeable, DAPM Retained No connector library exists in the SUSE portfolio — no maintained connectors to ERP, CRM, HCM, mainframe, or SaaS systems of record, and no integration framework product. Every system-of-record integration is enterprise-built and enterprise-maintained, with the enterprise absorbing upstream API changes itself. This is the most operationally expensive absence in the row: each cross-system governance gap carries its own multi-year build-and-maintain burden. Closeable through third-party integration platform acquisition — the same path available on any substrate, credited to none.

AI-native integration · score 2, gap vendor-roadmap, DAPM Delegated SUSE AI Factory subscription, GA today as applied components: LiteLLM provides model API federation — multi-provider routing, API keys, quotas — and mcpo bridges MCP servers to OpenAPI endpoints; both are mirrored-upstream components inside the supported stack that the enterprise configures. Adjacent but not credited here: the GA MCP server embedded in SUSE Rancher Prime and SUSE Multi-Linux Manager exposes platform operations to AI agents — an operations-management surface, not an application integration fabric. The named roadmap product: Universal Proxy — centralized MCP endpoint management, automated server discovery and registration, smart traffic routing, cost control, and shadow-AI discovery — is in tech preview. Score 2 reflects the GA component layer: AI-native integration patterns available through in-boundary components without managed connection infrastructure. Vendor roadmap — a specific product in confirmed development addresses the managed-infrastructure gap; GA would move this function toward 3, re-scored on evidence at that time.

Fourth Cloud · Control Plane Assessment

SUSE Rancher Prime

Complete

Fourth Cloud Control Plane Assessment — SUSE Vendor Boundary

How to read these scores

The Fourth Cloud instrument scores functions within layers, not layers as aggregates. Each function gets a 0–4 score, a gap ownership classification, and a DAPM authority classification. The layer is a grouping; the function score is the finding.

Score gradient (0–4)

  • 4 — Hyperscaler. AWS/hyperscaler equivalent — fully managed, fully automated.
  • 3 — Strong. Meaningful automation and integration. Narrow, well-understood gaps.
  • 2 — Moderate. Partial coverage within constraints the vendor does not control.
  • 1 — Weak. Addressed for some workload types but not others; manual-assisted.
  • 0 — Absent. Vendor provides nothing. Enterprise owns the function entirely.

Gap ownership (every score < 4)

  • Closeable. Enterprise must acquire new capability — new software, vendor, or contract.
  • Opinion. Primitives exist; enterprise applies configuration without new acquisition.
  • Vendor roadmap. Vendor has announced product intent with a timeline.
  • Structural. Consequence of the on-prem operating model — no near-term close.

DAPM authority

  • Retained. Enterprise can swap providers without rebuilding. Default when vendor provides nothing.
  • Delegated. Substitutable partner provides this capability — alternatives exist.
  • Ceded. Vendor's opinions are proprietary with no open exit; lift-to-leave requires rebuild.
  • Absent. No capability exists at this layer.

Summary Finding

Version · v1.1Date · July 28, 2026Evolution · continuous

SUSE Rancher Prime is a multi-cluster Kubernetes control plane whose defining characteristic is estate-wide reach: one management plane federating identity, RBAC, policy, and GitOps across on-premises, cloud, and edge clusters — including managed cloud Kubernetes the enterprise already runs — with VMs joining through SUSE Virtualization. Scope: the SUSE vendor boundary — the SUSE Rancher Prime base subscription plus Suite-tier components, the SUSE AI Factory subscription, and SUSE Edge, each named inline where it carries a score; capabilities requiring a different vendor remain Closeable gaps.

The gap portfolio is Opinion-dominant in the platform core and Closeable-dominant at the edges. Across orchestration, runtime, and catalog, the primitives are included and the enterprise applies them — configuration, not acquisition. At the data and integration layers the shape inverts: SUSE has no data estate and no integration products, and the SUSE Application Collection's supported artifacts set floors — messaging components, an API gateway — without delivering managed capabilities. FC-2C is absent and Structural, as it is across the on-premises category. Delivery model: self-managed software on customer-owned hardware; hosted offerings cover management planes only, which anchors resource lifecycle automation at the on-premises position.

The authority finding is this row's distinctive profile. Delegated dominates the DAPM column because the stack is open source with real exits — RKE2, K3s, KubeVirt, Fleet, K3k, NeuVector — so the operational opinions an enterprise accumulates on this platform are unusually portable. The exceptions: SUSE Observability, whose correlation configurations are proprietary and captive, and the NVIDIA-held GPU management layers.

Identity plane continuity is federated through SUSE Rancher Prime itself as the broker: orchestration, execution across both VMs and containers, and catalog consumption are governed by one federated enterprise identity across every managed cluster. Substrate, data, reasoning, and integration layers sit outside the plane — substrate-to-runtime identity enforcement is operator-built configuration, and data governance identity awaits a data estate that does not exist in the portfolio.

The agentic layer deserves precise placement. The Liz agent crew and the MCP servers embedded in SUSE Rancher Prime and SUSE Multi-Linux Manager (both GA) constitute a developed operations-tier agentic surface: agents that consume live estate topology and act on infrastructure through governed interfaces with human approval. That is operations assistance, not a reasoning plane — no component derives placement from governance metadata, and the FC-1 metadata a reasoning plane would consume does not exist in the estate. Universal Proxy, in tech preview, is the named path for AI-native integration governance and is not scored.

The buyer's trade: a broad, open, low-lock-in control plane with a shipped observability platform in the base subscription — in exchange for owning the data fabric and the integration fabric entirely, and accepting component-grade rather than product-grade depth in AI governance and API lifecycle. The assembly burden sits at the edges, not the core.

v1.1 records the SUSE vendor review (workbook returned July 28, 2026). No scores moved. Changes: product naming aligned (SUSE AI Factory, SUSE Application Collection, SUSE Rancher Prime); AI Library support scope documented as two labeled tiers (SUSE-built: installation through code fix; SUSE-supported community: installation and configuration, upstream code fixes); SUSE AI Factory with NVIDIA (generally available July 2026) recorded as the in-boundary NVIDIA AI Enterprise path at accelerator management; SUSE Telco Cloud added alongside SUSE Edge for bare-metal lifecycle; SUSE Storage named as the substrate-tier persistence anchor in the FC-1 note; AMD accelerator support recorded as initial validation, not scored. Two vendor requests were declined under instrument rules: crediting hardware partnerships against the resource-lifecycle delivery model, and crediting a partner ecosystem against the integration fabric — the composition boundary holds.

Source:SUSE Rancher Prime v2.14 product documentation and support terms, SUSE Rancher Suite packaging, KubeCon + CloudNativeCon Europe 2026 announcements (Liz agent crew GA, embedded MCP server GA, Virtual Cluster GPU multi-tenancy GA via K3k, NVIDIA MIG vGPU GA, VM Auto Balancing early access, Longhorn v2 tech preview), SUSECON 2026 coverage, SUSE Virtualization (Harvester) v1.7 release notes and hardware requirements, SUSE Edge 3.3 documentation (Metal3/Cluster API/Elemental), SUSE AI 1.0 documentation (AI Library, deployment, observability), SUSE Observability documentation (Rancher Prime entitlement), SUSE Application Collection documentation (subscriptions, reference guides), K3k product documentation v1.1.0, NeuVector/SUSE Security Rancher SSO documentation, Rancher OIDC provider documentation, Fourth Cloud methodology v2.4, SUSE vendor feedback via review workbook (July 28, 2026 — naming and narrative corrections, support-scope and guest-VM observability clarifications; no scores moved), SUSE AI Factory with NVIDIA GA announcement (July 9, 2026), AMD/SUSE initial validation blog (2026)

Scoping note

This assessment scores SUSE Rancher Prime v2.14 using the SUSE vendor support boundary as the scope line. The base SUSE Rancher Prime subscription (Rancher Manager, RKE2/K3s with up to five-year lifecycle support, Fleet GitOps, Cluster API, SUSE Application Collection Prime tier, Prime OCI registry, SUSE Observability entitlement, the Liz agent crew and embedded MCP server) is scored as included. SUSE-licensed add-ons are in scope and named inline where they carry a score: the SUSE Rancher Suite tier (SUSE Security, SUSE Private Registry, SUSE Virtualization with SUSE Storage, FIPS content, NVIDIA MIG sharing), the SUSE AI Factory subscription (AI Library: vLLM, Ollama, Open WebUI, Milvus, Qdrant, LiteLLM, mcpo, PyTorch, MLflow, Kubeflow), SUSE Edge (Metal3/Cluster API bare-metal lifecycle, Elemental onboarding), Kubewarden (certified Rancher project, add-on subscription), and Rancher Developer Access (separately purchased). Capabilities requiring a different vendor remain Closeable gaps. Two support-boundary facts inform scoring throughout. First, delivery model: SUSE sells self-managed software on customer-owned hardware; SUSE Rancher Prime Hosted and SUSE Observability Hosted Prime host management planes only — there is no managed hardware consumption offering, which anchors FC-2A F2. Second, support tiers within the boundary: SUSE Application Collection applications carry artifact-level guarantees (signatures, SBOM/VEX, SLSA Level 3 provenance, validation against RKE2) rather than documented production-runtime support, and the SUSE AI Factory AI Library carries two labeled support tiers (vendor-confirmed, July 2026 review): SUSE-built applications are supported by SUSE from installation through configuration to code fix, while SUSE-supported community applications receive installation and configuration support with code fixes flowing through the upstream community into the next release. Registry applications are mirrored upstream projects with SUSE supply-chain attestation. Functions scored on these paths carry those distinctions in their narratives. Universal Proxy (centralized MCP endpoint governance) is tech preview and not scored, per the New Capability Rule.

Identity Plane Continuity — top-level

Federated identity plane

Score · 3
Gap · Mixed
Layers in plane
FC-2A · OrchestrationFC-2B · RuntimeFC-3 · Catalog
Layers siloed
FC-0 · SubstrateFC-1 · ContextFC-2C · ReasoningFC-4 · Integration

SUSE Rancher Prime is itself the federation broker, with Rancher Manager as the broker component. Enterprise identity providers — Active Directory, LDAP, SAML 2.0, OIDC, Okta with SCIM automated provisioning and deprovisioning — federate once into Rancher, and Rancher enforces that identity as RBAC across every managed cluster, including imported EKS, AKS, and GKE clusters. FC-2A: cluster, project, and namespace authority is governed estate-wide by the federated identity, natively. FC-2B: namespace execution is governed by propagated RBAC for both containers and VMs — SUSE Virtualization in Rancher-managed mode uses Rancher authentication, so both workload types sit in one identity plane. FC-3: catalog consumption through Rancher Apps & Marketplace is governed by the same identity; SUSE Application Collection registry access uses SUSE Customer Center accounts and service accounts, a seam at the artifact-consumption edge. The product extensions ride the same broker: SUSE Security (Suite tier) has native Rancher single sign-on with role mapping to its permission model; SUSE Observability and Open WebUI (SUSE AI Factory) join through Rancher acting as an OIDC identity provider — documented configuration of included capability, an Opinion gap. Outside the plane: FC-0 substrate identity does not gate workload execution without operator-built node label, affinity, and admission-policy bridges (Opinion, included primitives); FC-1 data governance identity has no data estate to attach to (Closeable); FC-2C is absent; FC-4 has no integration fabric to propagate identity through — SUSE Application Collection integration artifacts carry their own authentication, and the embedded MCP server governs platform operations, not application integration.

Buyer implicationCan FC-0 identity control FC-2B runtime execution? Not natively — substrate identity influences what runs where only through operator-configured node labels, affinity rules, and admission policies, built from included primitives. What the enterprise does get: one federated identity governs what a person can orchestrate (FC-2A), what executes in their namespaces across both VMs and containers (FC-2B), and what they consume from the catalog (FC-3) — uniformly across on-premises, hosted-cloud, and edge clusters, including managed cloud Kubernetes the enterprise already runs — without building identity bridges between the layers the plane covers. The cost of the siloed layers: substrate-to-runtime enforcement is operator-maintained configuration, and data governance identity requires acquiring a data governance platform first.
Layer-by-layer scoring
2Moderate
Hardware lifecycle management
UniversalGap · CloseableDAPM · Delegated
Included: Rancher lifecycles Kubernetes clusters and nodes through Cluster API. SUSE Rancher Suite tier (SUSE Virtualization): cluster upgrades move the SUSE Linux Micro node OS, the hypervisor stack, and storage as one orchestrated operation, with per-node pause-and-resume upgrade control — node OS lifecycle is genuinely integrated with workload management. SUSE Edge and SUSE Telco Cloud (separate SUSE product lines): Metal3 and Cluster API provide bare-metal lifecycle over Redfish BMC protocols — automated inspection, cleaning, provisioning, and deprovisioning — and Elemental provides node onboarding and OS lifecycle for edge estates. The boundary of the capability: no SUSE product manages firmware, BIOS, or BMC lifecycle. SUSE Multi-Linux Manager patches Linux estates but does not push firmware. OEM firmware tooling remains a separate management surface the enterprise operates alongside the platform. Closeable — firmware lifecycle automation requires acquiring and operating OEM or third-party tooling outside the SUSE boundary.
2Moderate
Substrate heterogeneity
UniversalGap · StructuralDAPM · Retained
SUSE Rancher Suite tier (SUSE Virtualization): runs on commodity x86_64 and ARM64 servers, with YES certification recommended rather than a strict component-combination compatibility list — enterprises can generally bring existing OEM estate hardware rather than purchasing certified node configurations. The hypervisor layer provides unified virtualization primitives across heterogeneous OEM hardware. Accelerators: NVIDIA vGPU and Multi-Instance GPU (MIG) support with automatic detection and hardware-isolated partitioning (MIG at the Suite tier; NVIDIA vGPU licensing is a separate NVIDIA relationship), and PCI passthrough for other devices. Gap from 3: accelerator management covers a single vendor family (NVIDIA), and OEM hardware management depth — firmware, out-of-band health — remains OEM-tool-specific beneath the unified virtualization layer. Bare-metal RKE2 with GPU operators is also a supported deployment shape for accelerated workloads — heterogeneity management is not bound to the hypervisor path alone. AMD accelerator support is in initial validation: AMD and SUSE began testing AMD inference microservices and enterprise blueprints on AMD Instinct MI350P in 2026. A validation effort is not a shipped product, so the productized accelerator path remains a single vendor family today. Structural — accelerator ecosystem breadth is an architectural scope constraint; this cell re-scores when a multi-vendor accelerator product reaches general availability.
3Strong
Substrate portability
UniversalGap · StructuralDAPM · Delegated
Included: one Rancher management plane manages RKE2 and K3s clusters on-premises (SUSE Virtualization, bare metal), in cloud (RKE2 on cloud instances, plus imported EKS, AKS, and GKE under the same authentication, policy, and GitOps surface), and at edge (K3s, SUSE Edge) — the multi-cluster estate is one management boundary rather than per-substrate silos. The workload cluster stack runs across all substrate types without architectural change. Bounds stated honestly: SUSE Virtualization itself is on-premises only — VM workload portability is bounded to the on-premises estate, and cross-substrate portability lives at the Kubernetes layer. Gap from 4: the 4 anchor is reserved for cloud-native platforms where the hyperscaler is the substrate. Structural.
NotesFC-0 F1=2: node OS lifecycle is integrated (SUSE Virtualization one-operation upgrades, SUSE Edge Metal3/Elemental bare-metal lifecycle) but no SUSE product touches firmware — and unlike vendors with in-boundary firmware automation paths, there is none to name inline. F2=2: broad commodity hardware entry through hypervisor abstraction, single accelerator family. F3=3 is the layer's strength: one management plane across on-premises, cloud, and edge, including foreign managed-Kubernetes clusters.

Methodology v2.3 · Grounded in Townsend (2025), Fourth Cloud Readiness Assessment and Evaluation Framework v0.9. See how to read these scores.