Layer3 Logo

New Zealand private cloud

Private cloud hosting

Your servers, in Auckland, on hardware we own.

Layer3 runs private-cloud infrastructure in Auckland, with failover options in Wellington over a 10 Gbit link. Pricing and data-transfer inclusions are scoped in your proposal, with support from the New Zealand team that operates the platform.

Auckland

Primary site at Vocus, Albany

Wellington

Failover site available

100 Gbit

Internal core network

ISO/IEC 27001:2022

Certified operations

01

The case for change

Cloud was supposed to make costs predictable.

For a steady set of virtual machines it does the opposite. You get an invoice that moves when the workload has not, a line item for moving your own data, and a latency penalty on every file open - for systems that have not changed shape in five years.

Cost

Cloud spend that is difficult to forecast

Egress, API calls and premium storage are metered separately, so the total moves month to month even when nothing about the workload has. Finance cannot budget it and nobody in the building can fully explain it.

Distance

Workload location changes performance

Interactive workloads are sensitive to the distance between users, applications and data. Compare private cloud and Azure using the actual application architecture and the New Zealand regions and services available for that workload.

Residency

A region name is not an answer

A region setting is a configuration, not a guarantee, and it says nothing about where the people supporting it sit or where the backups land. Buyers in government, health and finance have started asking for more than that.

Where it runs

Two datacentres, both in New Zealand.

Layer3 owns the hardware. It is colocated in two facilities, so the building, the power and the cooling are run by people who do nothing else, and the platform on top of it is run by us.

Auckland – primary

Facility

Vocus, Albany

Role

Production. Every workload runs here by default.

Certified

The facility holds ISO 27001 and SOC 2 Type II.

Power

Dual utility feeds with N+1 diesel generation.

Network

100 Gbit internal core.

Wellington – failover

Facility

DTS, Wellington

Role

Failover, and the replication target for Auckland.

Link

10 Gbit to the Auckland site.

Recovery

Restore point for backups, and the live target where a customer takes warm replication.

Both sites are operated within Layer3's ISO/IEC 27001-certified ISMS.

The network

The part most hosting pages leave out.

A private cloud is only as good as the path to it. Ours is built for systems that talk constantly to people and equipment on your own sites, rather than for workloads that only ever see the internet.

100 Gbit

Internal core

The fabric between compute and storage inside the Auckland site. This is what database and virtual desktop workloads actually feel.

10 Gbit

Between datacentres

Auckland to Wellington, carrying backup and replication traffic without competing with anything customer-facing.

10 Gbit

To the outside world

Wide area links out of the platform, sized so that a busy day at one customer is not a slow day at another.

Direct

Back to your sites

Private layer 2 or layer 3 links, or encrypted tunnels, from any New Zealand site into your own segment of the platform.

What runs on it

If it runs on a virtual machine, it runs here.

The platform is a Hyper-V cluster, not a bespoke stack, so what you already run is what you keep running.

Hyper-V cluster

A multi-tenant Windows virtualisation fabric, with your workloads in their own segment of it. Layer3 moved to Hyper-V deliberately, and wrote publicly about why.

Windows Server

Domain controllers, application servers, print and file services, remote desktop hosts.

Linux

Web, application and database servers alongside the Windows estate, on the same fabric and the same support arrangement.

SQL Server

Dedicated tenancy, which is frequently where the licensing arithmetic turns in favour of running it here rather than in a hyperscale cloud.

Virtual desktops

Session hosts can be placed close to the data they use on Layer3's New Zealand network, reducing avoidable latency for supported workload designs.

Line-of-business systems

The applications that will not re-platform and do not need to. Practice management, ERP, engineering and finance systems.

Backup and recovery

Three copies, two sites, one of them not in the country.

Backup runs on Veeam. A local copy stays on the Auckland platform for fast restores, everything replicates to Wellington across the 10 Gbit link, and a long-term archive lands in AWS Glacier. Recovery targets are agreed per customer and written into the proposal rather than advertised here, because a number that fits one estate misleads the next.

Diagram of Layer3's backup and disaster recovery architecture: Auckland production with local Veeam backup, replicating to Wellington for failover over a 10 Gbit link, with long-term archive in AWS Glacier.

Production and failover both sit in New Zealand. The long-term archive is encrypted and held in AWS Glacier in Sydney, which is the one place customer data leaves the country - stated here rather than buried, because it is the question a regulated buyer will ask.

On site

Local Veeam backup

A copy on the Auckland platform, which is what almost every real restore comes from. Recovering a deleted file or a broken database does not need to touch another site.

Between sites

Replication to Wellington

Backups replicate to DTS across the 10 Gbit link, so a total loss of the Auckland site is a recovery, not an extinction event. Warm replication of live machines is available as an option on top.

Off shore

Long-term archive

A third copy in AWS Glacier for retention that outlives the systems it came from. Encrypted, and held in Sydney.

Disaster recovery is tested to a schedule agreed with you, not assumed to work. Recovery point and recovery time targets are set against your actual systems during scoping.

Private cloud or Azure

We run both, so we will tell you which one you want.

Eleven questions help compare the operating models. Your answers will usually favour one column; a split result can indicate a hybrid design.

Question

Points to

Layer3 private cloud

Points to

Azure

Is this a set of virtual machines you already run, or something you would rebuild?

Servers as they are, Windows and Linux

We want to re-platform onto managed services

Do those machines carry Microsoft server licensing - Windows Server, SQL Server?

Yes, and the licensing cost matters

Little or no Microsoft server licensing

Is the load steady, or does it spike?

Steady - it runs much the same all year

Spiky, seasonal, or growing in bursts

Would an agreed monthly service charge be easier to govern than consumption billing?

Yes - finance wants one number

We can manage a variable bill

Do these systems talk constantly to people or equipment on your own sites?

Yes - file, SQL, virtual desktops, plant systems

Mostly reached over the internet

Is New Zealand data residency a hard requirement you have to evidence?

Yes, and we get asked to prove it

Preferred, not mandatory

Do you want platform services rather than servers - managed databases, app hosting, functions?

Servers are what we run

Yes, that is the direction

Are you already building on Entra ID, Intune and the wider Microsoft cloud?

Some of it

Yes, it is where we are heading

Do you need capacity or disaster recovery outside New Zealand?

No

Yes

Is this development and test that gets created and destroyed?

No, it is production

Yes, frequently

Do you need to scale to nothing outside business hours?

No

Yes

Most organisations land split, and that is a real answer rather than a fudge - the steady core in Auckland, elastic and platform workloads in Azure. We run both, so the recommendation is not decided by what we happen to sell. What we do in Azure

How you buy it

As much or as little of it as you want to run yourself.

The platform is the same in all three cases. What changes is who holds the console.

Self-service

You drive

Portal access to build, resize and manage your own machines. Layer3 runs the platform underneath and stays out of the way above it.

Co-managed

We share it

Your team keeps the applications, we take the operating systems, patching, backup and capacity. The boundary is written down rather than assumed.

Fully managed

We run it

Everything from the hardware to the application layer, inside a managed plan, with the same service desk that covers the rest of your estate.

Pricing is scoped per machine or reserved block of resource, with included capacity, data transfer, support and any variable charges documented in your proposal. Compare Layer3 private cloud and Azure using a dated, like-for-like model covering compute, storage, data transfer, resilience, licensing, support and operations.

Moving in

Five steps, and you keep running throughout.

Migration is Veeam replication rather than a weekend of downtime. Machines are copied while they run, kept in sync, and cut over when you are ready.

01

Assess

Inventory of what you run, how it is sized, what talks to what, and which licences follow you.

02

Design

Your segment of the platform, the link back to your sites, and the backup and recovery arrangement, agreed in writing.

03

Seed

Machines replicate into Auckland while they keep running where they are. No outage, and no commitment yet.

04

Test

An isolated cutover rehearsal against the real replicas, so the plan is proven rather than believed.

05

Cut over

A final sync and a switch, in a window you choose, with the old environment left intact until you are satisfied.

Proof

Who we already look after.

Customer outcome

50+ to under 10

ECL Group moved from an internal IT function to a fully managed Layer3 service, and its server estate went from more than fifty on-premises machines to fewer than ten in the Layer3 cloud.

Read the ECL Group case study

Questions

Questions about private cloud hosting

If yours is not here, ask us directly — you will get an engineer, not a form response.

Book a discovery call

Dedicated infrastructure that Layer3 owns and runs on your behalf, in New Zealand datacentres, with your workloads in their own segment of it. You get the flexibility of virtual machines without owning, housing or replacing the hardware.

Production runs at Vocus in Albany, Auckland. Failover and replication sit at DTS in Wellington, connected by a 10 Gbit link. The Albany facility holds ISO 27001 and SOC 2 Type II certification.

Production and failover are both in New Zealand. The long-term backup archive is encrypted and held in AWS Glacier in Sydney, so that one copy is in Australia. We would rather tell you that up front than have you find it in a due-diligence questionnaire.

Backup runs on Veeam: a local copy in Auckland for fast restores, replication to Wellington across the 10 Gbit link, and a long-term archive in AWS Glacier. Warm replication of live machines between the two sites is available as an option. Recovery point and recovery time targets are agreed against your systems and written into the proposal.

It suits a different shape of workload. Steady virtual machines carrying Microsoft licensing, talking to systems on your own sites, usually run better and cost less here. Elastic demand, platform services and anything you plan to re-platform usually belong in Azure. We run both and there is a question-by-question comparison on this page.

Windows Server and Linux on a Hyper-V cluster, covering domain controllers, SQL Server, file and print, virtual desktops and line-of-business applications. If it runs on a virtual machine, it runs here.

Private layer 2 or layer 3 links from any New Zealand site, or encrypted tunnels, into your own segment of the platform. Remote users reach it the same way they reach anything else you run.

Yes, and without a weekend of downtime. Machines replicate while they keep running where they are, the cutover is rehearsed against the real replicas, and the old environment stays intact until you are satisfied.

Next step

Tell us what you run, and we will tell you where it belongs.

Including when the answer is Azure, or a mix of the two.

Layer3

Book a discovery call - 30 minutes, no obligation