Deployment

Installed on your infrastructure. In a few commands.

graal installs from a Helm chart on your Kubernetes or OpenShift, with no cluster administration rights and no custom resources. You choose where the platform runs, and you stay in control of every upgrade.

Three options

Where your data already lives

The same platform, the same chart, three ways to host it.

On-premises

Your datacenter, your Kubernetes or OpenShift, behind your firewalls. Workloads and data stay inside your network.

Private cloud

Your cloud, your account, your network rules. graal installs on your managed cluster like any other application.

Qualified hosting provider

Deployable with a SecNumCloud-qualified or HDS-certified hosting provider. The provider holds the label for its offer; graal installs on its Kubernetes.

Architecture

What gets installed in your cluster

A control plane, an execution layer for workloads, and your existing resources. Your teams come in through your SSO, your AI agents through MCP: everything stays with you.

Your teams · SSO

◆ Your AI agents · MCP

graal · control plane

  • Console
  • REST API and MCP
  • Identity · Keycloak
  • Metadata · PostgreSQL

graal · execution

  • Jobs and workflows
  • Notebooks
  • Distributed Spark
  • Model serving

Your resources

  • S3 storage
  • LDAP / AD directory
  • Image registry
  • Observability

Your Kubernetes cluster · on-premises, private cloud or qualified hosting

Prerequisites

What graal needs

Standard components your platform team already knows.

  • A maintained Kubernetes or OpenShift cluster
  • A PostgreSQL database, yours or the one shipped with the chart
  • S3-compatible object storage
  • An OIDC or SAML identity provider, or an LDAP directory (Keycloak is included)
  • An image registry, your own for an offline installation
  • A domain name and a TLS certificate

Operations

Operated like your other applications

High availability

Components replicated and spread across nodes: an upgrade or a lost node interrupts neither workloads nor scheduling.

Backup and restore

Metadata, configuration and encrypted secrets backed up continuously; restoration is documented and rehearsed.

Observability

Prometheus metrics and OpenTelemetry traces, sent to your own monitoring tools.

GitOps

Pinned versions, values in your repository, upgrades applied by your GitOps tool.

Offline

Installed without Internet access

The chart, the images and their signatures are mirrored into your registry. Installation and upgrades never leave your network.

offline installation
# chart and images mirrored into your registry, digests and signatures included$ helm install graal oci://registry.internal/graal/graal \  --values values.yaml --set global.imageRegistry=registry.internal✓ graal installed — console: https://graal.internal

Your environment

OpenShift, multiple entities, your brand

OpenShift

Images run under the arbitrary user ID that OpenShift assigns, with no security constraint to relax.

Multiple entities

Subsidiaries, departments or sites on a single installation, each with its own directory, projects and permissions.

White label

Login screen, colors and domain name in your brand, entity by entity.

Reversibility

Leaving remains possible

What you build in graal stays readable without graal.

The code is yours

Every pipeline exports to Pandas or PySpark code that runs outside the platform.

Open formats

Apache Iceberg tables and Parquet files on your S3 storage, readable by any compatible engine.

Documented interfaces

A REST API described in OpenAPI, the MLflow API and an MCP server: your tools keep talking to your data.

See the technical specification

FAQ

Before you install

Do we need a Kubernetes cluster?

Yes. graal installs on your Kubernetes or OpenShift, on-premises or with a hosting provider. If the cluster still has to be built, graal Services help you.

How long does an installation take?

In the pilot, installation takes weeks 2 and 3, including the SSO connection and the first data sources.

Who applies upgrades?

You do, at the pace you choose: every release ships with its notes and is applied with Helm or your GitOps tool.

What rights does graal need on the cluster?

No administration rights. The exact list of objects created and rights granted is in the technical specification.

Plan a pilot installation

Two weeks to install graal on your infrastructure, with your platform team: the first step of the 8-week pilot.