| Getting Started | Account activation, Dashboard access, first project and first Shoot cluster | Activate your account |
| Access & User Management | User and group management in Keycloak, project membership, OIDC federation and kubeconfig access | Identity & Access Management |
| Managed Kubernetes | Cluster configuration, worker pools, scaling, Kubernetes version upgrades, hibernation and advanced options such as GPU nodes, volume encryption and service mesh | Shoot spec overview |
| Networking | Load balancer configuration, DNS record management and DNS zone setup | Load balancers |
| Observability | Cluster health dashboards, capacity monitoring and SGX memory metrics | Shoot monitoring |
| Private Deployment | Private stack deployment option on OSC | Private Deployment Architecture |
| Extensions | Optional platform services: cert-manager, S3 buckets, audit logs, bastion hosts, DEX clients, node feature discovery and Shoot peering | cert-manager |
| Confidential Computing | Running workloads in hardware-attested, isolated enclaves using SCONE and SGX-enabled worker pools | Confidential Computing overview |