What actually happens when you install DataTorch on a network with no internet egress. A runbook from a recent customer install.
DataTorch · November 8, 2025
We get asked some version of "does air-gapped really work?" on most discovery calls. The honest answer is yes, but the more useful answer is to describe what an air-gapped install actually looks like, because the experience differs from cloud installs in ways IT teams care about.
This post is a sanitized walkthrough of a recent fully-disconnected install. Customer details omitted.
The lab network had no outbound internet access. No traffic could leave the perimeter, including to package mirrors, license servers, or telemetry endpoints. The install needed to complete from a single offline bundle, and the running system needed to operate without any outbound traffic.
We've shipped DataTorch installs across a range of these constraints. This one was on the strict end.
A single offline bundle (datatorch-v0.4.x.tar.gz) containing the application, dependency images, a Postgres bundle, a Redis bundle, and a small CLI to drive the install. Total size around 1.2 GB. The bundle was transferred onto the customer's network via their normal procedure (in this case a vetted USB drop from a clean staging machine), not over the network.
The customer's infrastructure team ran the install on their Kubernetes cluster (RHEL 8 nodes, Kubernetes 1.27). The CLI took a few minutes to:
We verified one more thing before signing off: no outbound traffic. We watched the network monitor with the customer's security engineer. Nothing left the perimeter: no telemetry, no license phone-home, no support-channel callout. That was the point.
A few things we tell customers upfront.
Updates ship as bundles, not as apt-get upgrade. When we release a new version, we ship you an updated offline bundle, and you run the same install flow. Cadence is yours, not ours.
Support is via the channel you control. We can't tail logs on your cluster. If something needs investigating, we work from logs and screen-shares your team initiates. Slower than SSH-in, by design.
Some integrations are out. If you wanted a Slack notification on pipeline completion, that's an outbound call. We won't make it. We'll send a webhook your internal notification system can route.
The customers who choose this configuration are doing it for one of two reasons: a regulatory requirement that data and inference paths stay local, or an IP-driven decision (proprietary models or proprietary assays they don't want a vendor anywhere near). Sometimes both.
If your lab is in that bucket, the install pattern above is what we'd run with you. If you have constraints that make even this approach too open, we'd want to talk through them before recommending anything.
Tools and community for image annotation: label, review, and share datasets, from everyday photos to the imagery only specialists can read.
© 2026 DataTorch. All rights reserved.