kimo
EngineeringSeries: Kimo Bridge

Air-gapped by design: shipping Kimo on-premise

Shipping modern software into a network with no internet connection forces every assumption into the open. Here is how we package, verify, update and support Kimo on-premise — with zero outbound calls and no second-class feature set.

Rhea Patel
Staff engineer10 min read

Most “on-prem” SaaS is the cloud product with the telemetry turned off and half the features missing. We decided early that Kimo Defense Intelligence would treat air-gapped as the primary deployment target, and that the cloud would be the special case. That decision shaped the build system, the update channel, and even the AI features.

§01Start from the threat model

Customers running air-gapped enclaves worry about three things, in this order:

  1. Exfiltration — no byte of data, metadata or usage should leave the enclave, ever.
  2. Supply-chain integrity — what they install is exactly what we built, and they can prove it.
  3. Operability — their team can install, upgrade and troubleshoot without us in the room.

Everything below maps to one of those three.

§02Zero phone-home, enforced

Removing telemetry calls is easy. Proving they are gone is harder. Our on-prem build compiles with a sovereign flag that strips every outbound client at build time — analytics, crash reporting, update checks, font CDNs, map tiles. CI then boots the bundle in a network namespace with no route and fails the build if any process attempts a DNS lookup.

ci/egress-check.sh
bash
# Boot the full stack with no network route and record any egress attempt
unshare --net --map-root-user ./kimo-stack up --profile sovereign &
sleep 60
./kimo-stack smoke-test --all-features

# Fail if anything tried to resolve a hostname
if grep -q "resolve" /var/log/kimo/egress-audit.log; then
  echo "egress attempt detected" && exit 1
fi

Map tiles, fonts, icons and the language model weights all ship inside the bundle. The basemap uses vector tiles generated from OpenStreetMap extracts for the customer’s area of operation.

§03Signed bundles and reproducible builds

Each release is a single archive containing container images, migrations, model weights and a software bill of materials (SBOM). The archive and every image inside it are signed. Customers verify on a transfer station before media crosses into the enclave:

Verify a release on the transfer station
bash
# 1. Check the bundle signature against our published key
cosign verify-blob \
  --key kimo-release.pub \
  --signature kimo-4.8.2.tar.sig \
  kimo-4.8.2.tar

# 2. Check every image digest listed in the SBOM
kimo-verify sbom kimo-4.8.2.spdx.json --images ./images/

# 3. Optional: rebuild from source and compare digests
make reproducible VERSION=4.8.2 && sha256sum -c digests.txt

§04Offline updates without drama

Upgrades are the moment on-prem deployments go wrong. We made them boring with three rules: migrations are always forward-compatible for one version, every upgrade runs a pre-flight check that reports what will change before touching anything, and rollback is a single command that restores both images and schema.

Median upgrade window by deployment size
  • v4.6 (manual steps)
  • v4.8 (pre-flight + rollback)
Figure. Simulated customer fleet, last 6 releases. Window measured from pre-flight start to all health checks green.

§05No second-class features

The hardest part was Ask Kimo. In the cloud it calls a hosted language model. On-premise, it runs a quantised open-weights model on the customer’s own GPUs — or CPU-only for small deployments, with longer response times. Because Ask Kimo grounds every answer in the semantic layer rather than free generation, a smaller model loses surprisingly little accuracy.

CapabilityCloudOn-premAir-gapped
Connectors (incl. Kafka, SIEM, AIS)YesYesYes
Ask KimoHosted modelLocal modelLocal model
Maps & geospatialYesYesBundled tiles
SSO / SCIMYesYesLocal IdP
UpdatesContinuousSigned bundlesSigned media
SupportIn-appRemote sessionDiagnostic export
Feature matrix for Kimo Defense Intelligence 4.8.

§06Supporting what we cannot see

With no remote access, support relies on a diagnostic export: a redacted archive of logs, health checks and configuration that the customer reviews before carrying it out. It contains no data rows and no query text by default. Our support engineers can replay most issues from it on a mirrored lab environment.

>The best compliment we got from an accreditation reviewer was that the install guide was boring.
— Rhea Patel, Staff engineer

If you are evaluating an air-gapped deployment, the on-premise install guide covers hardware sizing and the transfer workflow, and the security page lists certifications and our disclosure policy.

  • #On-premise
  • #Supply chain
  • #Security
Found this useful? Pass it on.
Written by
Rhea Patel
Staff engineer at Kimo · 1 article

Writes about On-premise, Supply chain, Security.

People, companies and figures in this article are illustrative; charts use simulated data. All aircraft data shown in Kimo is simulated.

Put it to work

Go deeper

Whitepaper

Your Data, Your Rules

The hybrid analytics architecture behind Kimo Bridge: live query pushdown, optional cloud sync, and zero-trust by default.

22 pages
Template

Airspace watch

Live air picture with emergency squawks, loitering and geofence alerts.

4 min setup
Live demo

Open Airspace

Tracks, emergency squawks and a GNSS-interference map on a simulated feed.

Simulated data · no sign-up

All resources
ArticleEngineering
Defense

Airspace awareness from open ADS-B data

How ADS-B works, what open receiver networks can and cannot tell you, and how to fuse it into one air picture.

Hugo Lefèvre
12 min read

Airspace awareness from open data.

Fuse ADS-B, AIS and OSINT feeds on your own infrastructure. The demo runs entirely on simulated data.