Private cloud deployment
Run Cequence AI Gateway in your own Kubernetes cluster. You create a pool in the portal, then deploy the Operator to your cluster with the CLI. The Operator connects to the Cequence control plane and deploys everything else.
How deployment works
- Create a pool in the portal.
- Install the CLI.
- Check your cluster permissions.
- Deploy the Operator.
Then manage the pool from the portal — see Pool operations. If your cluster has no general internet access, see Air-gapped clusters.
Deployment Model
AI Gateway in your cluster is operator-managed and manifest-driven from the Cequence control plane — not a Helm chart you fork and maintain.
- What runs in your cluster: a small Operator that holds a one-way heartbeat connection to the control plane, plus the Armor data plane gateway and supporting components (Redis, ingress, SIEM exporter).
- Who decides what's deployed: the control plane. Pool configuration (resources, ingress, images, Redis mode, annotations) is set through the Private Pools page in the portal. The Operator reconciles the cluster to match.
- Upgrades: continuous. New component versions are rolled out by the Operator based on the pool's rollout policy. You don't carry chart drift across versions or maintain a vendored fork.
- Inspection: every manifest the Operator would apply can be printed with
aigateway deploy install --dry-run --show-manifests. This is for security review and pre-flight inspection — it is not a supported fork-and-maintain path. Manifests change between Operator versions; pinning a snapshot will break upgrades.
The trade-off is intentional: less control over the manifest surface, in exchange for guaranteed-consistent upgrades and a much smaller artifact for your security team to review.
Mapping to your enterprise controls
| Customer constraint | How AI Gateway fits |
|---|---|
| Images must come from our internal artifact registry | Mirror our images and point the pool at your registry |
| No general internet access from the cluster (restricted egress / air-gapped) | Allowlist two outbound HTTPS hosts and mirror the images into your registry — see Air-gapped clusters |
| Production-grade caching with backup/restore and your standard cache ops | Bring your own enterprise Redis (ElastiCache, Memorystore, Redis Enterprise, etc.) in Manual mode — recommended for all production deployments |
| CI/CD only; no interactive installers | Non-interactive deployment via environment variables and OAuth client credentials |
| Security review of cluster permissions before install | RBAC is namespace-scoped, split into bootstrap and steady-state; a single Role manifest is generated for pre-review |
Copyright © 2026 Cequence Security
Cequence AI Gateway
Cequence AI Gateway