Skip to main content

Air-Gapped Deployment

This guide covers deploying Simba Intelligence, as part of the Self-Service Analytics (formerly Logi Composer) Helm chart, in environments without direct internet access — air-gapped networks, restricted corporate environments, or private clouds that require all container images to come from an internal registry.

Overview

A standard deployment pulls most images from Docker Hub (a few dependency images come from other registries, such as ghcr.io) and the chart from the Self-Service Analytics Helm repository. In a restricted environment you mirror both: push every required image to your internal registry, transfer the chart, then override the image locations in your values file.

What You’ll Need

  • A machine with internet connectivity, for pulling images and the chart
  • An internal container registry (Azure Container Registry, AWS ECR, Harbor, Artifactory, or any OCI-compliant registry)
  • docker CLI or equivalent container tooling
  • helm CLI
  • A Kubernetes cluster with access to the internal registry

Step 1: Determine the Image List

Image names and tags change between chart releases, so derive the list from the exact chart version you are deploying rather than from a static table. On the internet-connected machine:
Windows PowerShell:
💡 Render with your real values file. Optional services and subcharts — simbaIntelligence.mcp, screenshotService, reportService, dataGatewayService, Prometheus, the OpenTelemetry Collector — only contribute images when they are enabled. Rendering with the values you will actually deploy gives you exactly the set you need and nothing more.
The list will include the Simba Intelligence application image (used by the REST API service, Celery worker, Celery beat, MCP server, and the database-migration Job), the Self-Service Analytics service images, and infrastructure images such as PostgreSQL, Redis, and Consul. Default registries and tags are visible in helm show values composer/composer --version <VERSION> under the root image key and the per-service image blocks.

Step 2: Pull, Tag, and Push

Using the images.txt produced in Step 1:
Adjust the destination naming to match your registry’s conventions — some registries require a fixed project or namespace prefix.

Step 3: Transfer the Helm Chart

Transfer the resulting composer-<VERSION>.tgz to the air-gapped environment and install from the local file.

Step 4: Override Image Locations

Add image overrides to your values file. Most services follow one of two patterns, discoverable via helm show values — but a few utility and dependency images are not in values.yaml at all and are easy to miss. Render the chart with your overrides (as in Step 1) and confirm every image in the output points at your registry before relying on this list.
📝 Note: internalPostgresql.image.override.enabled / .name replaces the entire image reference, which is useful when your registry layout does not map cleanly onto registry/repository/tag.
⚠️ Verify with helm template: After building your overrides, confirm nothing was missed:
Every line should reference your internal registry. Any Docker Hub reference still present means an image (a dependency subchart, a utility image, or a newly added service in a later chart version) needs its own override — the two patterns above don’t cover every image in the chart.

Step 5: Create an Image Pull Secret

If your internal registry requires authentication:
Reference it via the root imagePullSecrets value as shown above.

Step 6: Deploy


External Redis Module Requirements

The chart’s in-cluster Redis image includes the required modules. If you use an external Redis instance (simbaIntelligence.redis.external.*), ensure these are installed: Also set maxmemory-policy to volatile-ttl.

AI Provider Connectivity

Even in air-gapped environments, Simba Intelligence requires outbound connectivity to at least one AI provider (Gemini Enterprise Agent Platform, Azure OpenAI, AWS Bedrock, or Microsoft Foundry) for natural language query processing. If your network blocks all outbound traffic, configure firewall rules to allow the provider endpoints:
⚠️ Important: Simba Intelligence cannot function without access to an AI provider. Mirroring images and charts solves image pulls only — provider connectivity is a separate network requirement.

Verification

Confirm every pod is running from your internal registry:
Include init containers in the check — they pull images too: