Skip to main content

Private cloud deployment

Run Cequence AI Gateway in your own Kubernetes cluster. You create a pool in the portal, then deploy the Operator to your cluster with the CLI. The Operator connects to the Cequence control plane and deploys everything else.

How deployment works​

  1. Create a pool in the portal.
  2. Install the CLI.
  3. Check your cluster permissions.
  4. Deploy the Operator.

Then manage the pool from the portal — see Pool operations. If your cluster has no general internet access, see Air-gapped clusters.

Deployment Model​

AI Gateway in your cluster is operator-managed and manifest-driven from the Cequence control plane — not a Helm chart you fork and maintain.

  • What runs in your cluster: a small Operator that holds a one-way heartbeat connection to the control plane, plus the Armor data plane gateway and supporting components (Redis, ingress, SIEM exporter).
  • Who decides what's deployed: the control plane. Pool configuration (resources, ingress, images, Redis mode, annotations) is set through the Private Pools page in the portal. The Operator reconciles the cluster to match.
  • Upgrades: continuous. New component versions are rolled out by the Operator based on the pool's rollout policy. You don't carry chart drift across versions or maintain a vendored fork.
  • Inspection: every manifest the Operator would apply can be printed with aigateway deploy install --dry-run --show-manifests. This is for security review and pre-flight inspection — it is not a supported fork-and-maintain path. Manifests change between Operator versions; pinning a snapshot will break upgrades.

The trade-off is intentional: less control over the manifest surface, in exchange for guaranteed-consistent upgrades and a much smaller artifact for your security team to review.

Mapping to your enterprise controls​

Customer constraintHow AI Gateway fits
Images must come from our internal artifact registryMirror our images and point the pool at your registry
No general internet access from the cluster (restricted egress / air-gapped)Allowlist two outbound HTTPS hosts and mirror the images into your registry — see Air-gapped clusters
Production-grade caching with backup/restore and your standard cache opsBring your own enterprise Redis (ElastiCache, Memorystore, Redis Enterprise, etc.) in Manual mode — recommended for all production deployments
CI/CD only; no interactive installersNon-interactive deployment via environment variables and OAuth client credentials
Security review of cluster permissions before installRBAC is namespace-scoped, split into bootstrap and steady-state; a single Role manifest is generated for pre-review