Project Tellus: Software-Defined Networks for Gaia-X
At the end of January 2025, the Gaia-X project Tellus completed its implementation phase. For three years, ten companies and research institutions, led by internet exchange operator DE-CIX, worked on a question that we deal with at KAEMI every day: how can network connections with guaranteed quality be ordered and provisioned as easily as a cloud resource? KAEMI was part of the consortium and co-developed, above all, the software-defined networking part. Time to take a look at the result.
What Tellus was about
Modern applications rarely run in a single location. A digital twin pulls data from the factory, computes in a cloud, and feeds results back to machines and people. For scenarios like these, best-effort internet is not enough: they need connections with assured bandwidth, low latency, and demonstrable security, across the systems of multiple providers.
That is exactly where Tellus came in. Until now, anyone who wanted to run a business-critical application across distributed infrastructures bought circuits, cloud resources, and services individually and combined them by hand, without end-to-end guarantees. Tellus automates this process: a Gaia-X-compliant infrastructure finds, combines, and provisions network and cloud services based on the requirements of the application in question.
The project was funded through the Gaia-X funding competition of the German Federal Ministry for Economic Affairs and Climate Action with around 8.75 million euros, over a 36-month term starting in November 2021. Alongside DE-CIX and KAEMI, the consortium included Cloud&Heat, Mimetik, plusserver, the CISPA Helmholtz Center for Information Security, SpaceNet, WOBCOM, TRUMPF, and IONOS.
A software layer on top of the internet
Technically, Tellus is a cross-domain SDN: a software-defined networking layer that sits on top of the existing internet infrastructure and extends it with automation and performance guarantees. Instead of laying new lines, software describes what an application needs and assembles the right connection from existing building blocks.
The architecture follows a hierarchical design. Each participant runs its own Tellus Node, while a logically central Super Node handles brokering. Providers register their services in a Service Registry, along with the performance levels they guarantee and the security requirements they meet. When an application requests a connection, the controller matches the requirement profile against the registry, uses a graph database with weighted path search to determine the right chain of services, and provisions it via APIs. Sign-in relies on Self-Sovereign Identity: users prove their identity without giving up control over it.
Our part: the software-defined network
Within the project, KAEMI mainly co-developed the network layer, the layer that turns an order into a working connection. Our experience from managing SD-WAN and site networking fed in where concept and day-to-day practice meet: how connections between sites, data centers, and clouds can be described, provisioned automatically, and monitored in live operation, and what a performance guarantee is worth if nobody measures it.
For us, the change of perspective was the exciting part. In our day-to-day business, we build networks for individual companies. Tellus asks: what happens when many providers place their network and cloud building blocks in a shared catalog and software composes end-to-end connections from them?
What the prototype shows
The project concluded with a working proof of concept: through a user interface, virtual networks and services can be assembled to meet the requirements of specific industrial applications. Three use cases guided the project from the start: a data glove from Mimetik that transmits hand movements to a robot in real time, a digital twin from IONOS that simulates production steps and monitors them live, and fully automated laser cutting systems from TRUMPF, whose pay-per-part model depends on reliable, dynamic networks.
Why the result matters
Tellus is designed as open-source software and covers the entire supply chain of interconnection services. The project shows that connectivity with guarantees can be cataloged and booked like a product, Gaia-X-compliant and across provider boundaries. For a data economy in which companies want to share and jointly process sensitive data, that is a foundational building block. Digital sovereignty is not only about where data is stored, but also about the path it takes.
The result confirms a development we also see in our day-to-day business: rigid circuits are giving way to software-defined connections that can be provisioned in minutes and adapted to demand, up to and including private cloud connectivity . Details on the project's completion are available in the DE-CIX press release .