kimo
Docs

On-premise install

Run Kimo in your own infrastructure: Kubernetes and Docker requirements, the Helm chart, air-gapped installation with the offline bundle, upgrades and backups.

Updated Oct 8, 20268 min readEdit on GitHub

Kimo can run entirely inside your network. The on-premise build is the same software as the cloud, packaged as container images and a Helm chart. It is the default deployment for Kimo Defense Intelligence and is available on Enterprise plans for the other products.

Requirements

ComponentMinimumRecommended
Kubernetes1.28+1.30+, 3 nodes
CPU8 vCPU16 vCPU
Memory32 GB64 GB
Storage200 GB SSD1 TB NVMe for the cache
PostgreSQL (metadata)14+Managed or HA cluster
Object storageS3-compatibleMinIO or Ceph

Install with Helm

  1. 1
    Add the chart repository

    Your license key unlocks the private registry.

    bash
    helm registry login registry.getkimo.com -u $KIMO_LICENSE_IDhelm pull oci://registry.getkimo.com/charts/kimo --version 4.8.2
  2. 2
    Write your values file

    Point Kimo at your metadata database, object storage and identity provider.

  3. 3
    Install

    The install takes 5–10 minutes. All pods should be Ready before you log in.

    bash
    helm install kimo oci://registry.getkimo.com/charts/kimo \  --version 4.8.2 -n kimo --create-namespace -f values.yamlkubectl -n kimo get pods
values.yaml
license:  key: kl_ent_…global:  host: kimo.internal.examplemetadata:  url: postgres://kimo@pg.internal:5432/kimostorage:  s3:    endpoint: https://minio.internal:9000    bucket: kimo-cacheauth:  oidc:    issuer: https://keycloak.internal/realms/opsask:  provider: self-hosted  endpoint: http://llm.internal:8080telemetry:  enabled: false

Air-gapped installation

For networks with no internet access, download the offline bundle (images, chart, connector packs and a signed manifest) on a connected machine, verify it, and carry it across on approved media. The bundle is about 9 GB.

Verify & load
cosign verify-blob --key kimo-release.pub \  --signature kimo-4.8.2-offline.tar.sig kimo-4.8.2-offline.tartar -xf kimo-4.8.2-offline.tar./kimo-offline load --registry registry.internal:5000./kimo-offline install -f values.yaml

Upgrades

Releases follow semantic versioning. Minor versions ship monthly and are safe to apply in place; database migrations run automatically in a pre-upgrade job. Major versions are announced 90 days ahead in the changelog with a migration guide.

Backups and disaster recovery

  • Back up the metadata PostgreSQL database daily; it holds models, dashboards, users and alerts.
  • The object-storage cache can be rebuilt from sources, but backing it up shortens recovery.
  • Export models to Git for an independent copy of your semantic layer.
  • Test restores quarterly: kimo admin restore --dry-run validates a backup without applying it.

Monitoring

The chart exposes Prometheus metrics on every service and ships ready-made Grafana dashboards. Logs are structured JSON on stdout, so they flow into whatever collector you already run. The four signals worth alerting on are listed below; together they catch nearly every incident we have seen in customer installs.

MetricAlert when
kimo_sync_failures_totalMore than 5 in 15 min for one source
kimo_query_p95_secondsAbove 5 s for 10 min
kimo_cache_disk_free_ratioBelow 15%
kimo_license_days_remainingBelow 30 days