Air-gapped sites
Install 3AM where servers have no internet access, from one signed bundle.
The bundle 3am-<version>.tar contains everything an install needs:
| Path in the bundle | What |
|---|---|
install.sh | The installer |
images/3am-core.tar, images/model-runtime.tar | The container images |
models/cpu.tar (and gpu.tar in GPU bundles) | Pinned model weights |
config/packs/ | Your sealed check packs (they open only with your licence) |
helm/3am-<version>.tgz, compose/ | The Helm chart and Compose files |
manifest.env, manifest.json | Versions and image digests |
SHA256SUMS, SHA256SUMS.sig, 3am-release.pub | Checksums of every file, signed by 3AM |
An install from the bundle never reaches the network. If the bundle lacks something (for example the GPU build of the model runtime), the installer falls back (to the CPU profile) and says so. It never downloads anything.
1. Verify the bundle before it enters your network
Compare the bundle's SHA-256 with the value 3AM sends you separately (e-mail or your secure transfer system):
sha256sum 3am-0.1.0.tar2. Verify the files inside it
The installer does this automatically. To check by hand after unpacking:
tar -xf 3am-0.1.0.tar && cd 3am-0.1.0
sha256sum -c SHA256SUMS
openssl pkeyutl -verify -pubin -inkey 3am-release.pub -rawin -in SHA256SUMS -sigfile SHA256SUMS.sig
openssl pkey -pubin -in 3am-release.pub -outform DER | openssl dgst -sha256 # compare with 3AM's published keySignature Verified Successfully means every checksum is exactly as 3AM published it.
3. Install
Single server: Linux (or Windows Server). Kubernetes: push the images to
your registry, then follow Kubernetes. For the model on an air-gapped cluster, set
model.pullOnStart=false and load models/cpu.tar into the model volume:
POD=$(kubectl -n bank-ops get pod -l app.kubernetes.io/component=model -o jsonpath='{.items[0].metadata.name}')
kubectl -n bank-ops cp 3am-0.1.0/models/cpu.tar "$POD":/tmp/cpu.tar
kubectl -n bank-ops exec "$POD" -- tar -xf /tmp/cpu.tar -C /models
kubectl -n bank-ops exec "$POD" -- rm /tmp/cpu.tar
kubectl -n bank-ops rollout restart deploy/threeam-modelUpdates
Each new version is a new bundle. Verify it the same way, then run its installer (or helm upgrade). The data,
tokens and settings are kept.