Deployment
Installed on your infrastructure. In a few commands.
graal installs from a Helm chart on your Kubernetes or OpenShift, with no cluster administration rights and no custom resources. You choose where the platform runs, and you stay in control of every upgrade.
Three options
Where your data already lives
The same platform, the same chart, three ways to host it.
On-premises
Your datacenter, your Kubernetes or OpenShift, behind your firewalls. Workloads and data stay inside your network.
Private cloud
Your cloud, your account, your network rules. graal installs on your managed cluster like any other application.
Qualified hosting provider
Deployable with a SecNumCloud-qualified or HDS-certified hosting provider. The provider holds the label for its offer; graal installs on its Kubernetes.
Architecture
What gets installed in your cluster
A control plane, an execution layer for workloads, and your existing resources. Your teams come in through your SSO, your AI agents through MCP: everything stays with you.
Your teams · SSO
◆ Your AI agents · MCP
graal · control plane
- Console
- REST API and MCP
- Identity · Keycloak
- Metadata · PostgreSQL
graal · execution
- Jobs and workflows
- Notebooks
- Distributed Spark
- Model serving
Your resources
- S3 storage
- LDAP / AD directory
- Image registry
- Observability
Your Kubernetes cluster · on-premises, private cloud or qualified hosting
Prerequisites
What graal needs
Standard components your platform team already knows.
- A maintained Kubernetes or OpenShift cluster
- A PostgreSQL database, yours or the one shipped with the chart
- S3-compatible object storage
- An OIDC or SAML identity provider, or an LDAP directory (Keycloak is included)
- An image registry, your own for an offline installation
- A domain name and a TLS certificate
Operations
Operated like your other applications
High availability
Components replicated and spread across nodes: an upgrade or a lost node interrupts neither workloads nor scheduling.
Backup and restore
Metadata, configuration and encrypted secrets backed up continuously; restoration is documented and rehearsed.
Observability
Prometheus metrics and OpenTelemetry traces, sent to your own monitoring tools.
GitOps
Pinned versions, values in your repository, upgrades applied by your GitOps tool.
Offline
Installed without Internet access
The chart, the images and their signatures are mirrored into your registry. Installation and upgrades never leave your network.
# chart and images mirrored into your registry, digests and signatures included$ helm install graal oci://registry.internal/graal/graal \ --values values.yaml --set global.imageRegistry=registry.internal✓ graal installed — console: https://graal.internalYour environment
OpenShift, multiple entities, your brand
OpenShift
Images run under the arbitrary user ID that OpenShift assigns, with no security constraint to relax.
Multiple entities
Subsidiaries, departments or sites on a single installation, each with its own directory, projects and permissions.
White label
Login screen, colors and domain name in your brand, entity by entity.
Reversibility
Leaving remains possible
What you build in graal stays readable without graal.
The code is yours
Every pipeline exports to Pandas or PySpark code that runs outside the platform.
Open formats
Apache Iceberg tables and Parquet files on your S3 storage, readable by any compatible engine.
Documented interfaces
A REST API described in OpenAPI, the MLflow API and an MCP server: your tools keep talking to your data.
See the technical specificationFAQ
Before you install
Do we need a Kubernetes cluster?
Yes. graal installs on your Kubernetes or OpenShift, on-premises or with a hosting provider. If the cluster still has to be built, graal Services help you.
How long does an installation take?
In the pilot, installation takes weeks 2 and 3, including the SSO connection and the first data sources.
Who applies upgrades?
You do, at the pace you choose: every release ships with its notes and is applied with Helm or your GitOps tool.
What rights does graal need on the cluster?
No administration rights. The exact list of objects created and rights granted is in the technical specification.
Plan a pilot installation
Two weeks to install graal on your infrastructure, with your platform team: the first step of the 8-week pilot.