Preview — Self-hosted CloudThinker is in early access for design partners. Supported topologies, system requirements, and upgrade paths may change before general availability. Contact us to discuss your environment.
Deployment models
| Model | Description |
|---|---|
| SaaS (Multi-Tenant) | Default — managed by CloudThinker. Fastest path to value, no operational burden. |
| Dedicated Cloud | Single-tenant instance hosted by CloudThinker in your preferred region and cloud |
| Self-Hosted | Run CloudThinker inside your own VPC on Kubernetes — your data never leaves your perimeter |
| Air-Gapped | Fully offline install for classified or regulated environments |
System requirements
| Resource | Minimum (POC) | Production |
|---|---|---|
| Kubernetes | 1.34+ | 1.34+ |
| Nodes | 3 × 4 vCPU / 16 GB | 6+ × 8 vCPU / 32 GB |
| PostgreSQL | 14+ | 15+ with HA |
| Object storage | S3 or MinIO | Same |
| LLM access | AWS Bedrock | Same |
Upgrades
| Channel | Cadence |
|---|---|
| Stable | Monthly |
| LTS | Quarterly with 12-month support |
| Patch | As needed for security and critical fixes |
Compliance
Self-hosted deployments inherit the security posture of your cluster — keep CloudThinker inside the same boundary as the workloads it operates on. Self-hosted installs do not need re-certification because your audit boundary already covers the cluster.Related
Security Overview
Authentication, RBAC, and security controls
SSO
SAML and OIDC single sign-on
SCIM
Automated user provisioning