Docs
Install

Air-gapped sites

Install 3AM where servers have no internet access, from one signed bundle.

The bundle 3am-<version>.tar contains everything an install needs:

Path in the bundleWhat
install.shThe installer
images/3am-core.tar, images/model-runtime.tarThe container images
models/cpu.tar (and gpu.tar in GPU bundles)Pinned model weights
config/packs/Your sealed check packs (they open only with your licence)
helm/3am-<version>.tgz, compose/The Helm chart and Compose files
manifest.env, manifest.jsonVersions and image digests
SHA256SUMS, SHA256SUMS.sig, 3am-release.pubChecksums of every file, signed by 3AM

An install from the bundle never reaches the network. If the bundle lacks something (for example the GPU build of the model runtime), the installer falls back (to the CPU profile) and says so. It never downloads anything.

1. Verify the bundle before it enters your network

Compare the bundle's SHA-256 with the value 3AM sends you separately (e-mail or your secure transfer system):

sha256sum 3am-0.1.0.tar

2. Verify the files inside it

The installer does this automatically. To check by hand after unpacking:

tar -xf 3am-0.1.0.tar && cd 3am-0.1.0
sha256sum -c SHA256SUMS
openssl pkeyutl -verify -pubin -inkey 3am-release.pub -rawin -in SHA256SUMS -sigfile SHA256SUMS.sig
openssl pkey -pubin -in 3am-release.pub -outform DER | openssl dgst -sha256      # compare with 3AM's published key

Signature Verified Successfully means every checksum is exactly as 3AM published it.

3. Install

Single server: Linux (or Windows Server). Kubernetes: push the images to your registry, then follow Kubernetes. For the model on an air-gapped cluster, set model.pullOnStart=false and load models/cpu.tar into the model volume:

POD=$(kubectl -n bank-ops get pod -l app.kubernetes.io/component=model -o jsonpath='{.items[0].metadata.name}')
kubectl -n bank-ops cp 3am-0.1.0/models/cpu.tar "$POD":/tmp/cpu.tar
kubectl -n bank-ops exec "$POD" -- tar -xf /tmp/cpu.tar -C /models
kubectl -n bank-ops exec "$POD" -- rm /tmp/cpu.tar
kubectl -n bank-ops rollout restart deploy/threeam-model

Updates

Each new version is a new bundle. Verify it the same way, then run its installer (or helm upgrade). The data, tokens and settings are kept.

On this page