On-premise install
Run Kimo in your own infrastructure: Kubernetes and Docker requirements, the Helm chart, air-gapped installation with the offline bundle, upgrades and backups.
Kimo can run entirely inside your network. The on-premise build is the same software as the cloud, packaged as container images and a Helm chart. It is the default deployment for Kimo Defense Intelligence and is available on Enterprise plans for the other products.
Requirements
| Component | Minimum | Recommended |
|---|---|---|
| Kubernetes | 1.28+ | 1.30+, 3 nodes |
| CPU | 8 vCPU | 16 vCPU |
| Memory | 32 GB | 64 GB |
| Storage | 200 GB SSD | 1 TB NVMe for the cache |
| PostgreSQL (metadata) | 14+ | Managed or HA cluster |
| Object storage | S3-compatible | MinIO or Ceph |
Install with Helm
- 1Add the chart repository
Your license key unlocks the private registry.
bashhelm registry login registry.getkimo.com -u $KIMO_LICENSE_IDhelm pull oci://registry.getkimo.com/charts/kimo --version 4.8.2 - 2Write your values file
Point Kimo at your metadata database, object storage and identity provider.
- 3Install
The install takes 5–10 minutes. All pods should be Ready before you log in.
bashhelm install kimo oci://registry.getkimo.com/charts/kimo \ --version 4.8.2 -n kimo --create-namespace -f values.yamlkubectl -n kimo get pods
license: key: kl_ent_…global: host: kimo.internal.examplemetadata: url: postgres://[email protected]:5432/kimostorage: s3: endpoint: https://minio.internal:9000 bucket: kimo-cacheauth: oidc: issuer: https://keycloak.internal/realms/opsask: provider: self-hosted endpoint: http://llm.internal:8080telemetry: enabled: falseAir-gapped installation
For networks with no internet access, download the offline bundle (images, chart, connector packs and a signed manifest) on a connected machine, verify it, and carry it across on approved media. The bundle is about 9 GB.
cosign verify-blob --key kimo-release.pub \ --signature kimo-4.8.2-offline.tar.sig kimo-4.8.2-offline.tartar -xf kimo-4.8.2-offline.tar./kimo-offline load --registry registry.internal:5000./kimo-offline install -f values.yamlUpgrades
Releases follow semantic versioning. Minor versions ship monthly and are safe to apply in place; database migrations run automatically in a pre-upgrade job. Major versions are announced 90 days ahead in the changelog with a migration guide.
Backups and disaster recovery
- Back up the metadata PostgreSQL database daily; it holds models, dashboards, users and alerts.
- The object-storage cache can be rebuilt from sources, but backing it up shortens recovery.
- Export models to Git for an independent copy of your semantic layer.
- Test restores quarterly:
kimo admin restore --dry-runvalidates a backup without applying it.
Monitoring
The chart exposes Prometheus metrics on every service and ships ready-made Grafana dashboards. Logs are structured JSON on stdout, so they flow into whatever collector you already run. The four signals worth alerting on are listed below; together they catch nearly every incident we have seen in customer installs.
| Metric | Alert when |
|---|---|
kimo_sync_failures_total | More than 5 in 15 min for one source |
kimo_query_p95_seconds | Above 5 s for 10 min |
kimo_cache_disk_free_ratio | Below 15% |
kimo_license_days_remaining | Below 30 days |
