Self-Service AI in an Air-Gapped Network for a Government Health Ministry
- Case Study
- Jul 12
- 2 min read
A government health ministry needed multiple research teams to use modern AI tools inside fully air-gapped networks, each fully isolated. Dayo-Tech built self-service environments on Kubernetes and DGX A100, solving the air gap with offline package mirrors.
The Decision
The Customer, a government health ministry, needed multiple research teams to work with modern AI tools inside fully air-gapped networks, with each team's environment kept completely separate from the others. The defining constraint was isolation, not capacity.
That combination creates a contradiction most organizations never face: how to deliver flexible, self-service AI research in an environment that, by design, cannot reach the internet. A restrictive, manually managed setup would have left researchers repeatedly blocked by missing dependencies, unable to work at the pace their research demanded. The decision was to build an environment that honored the air gap completely while still feeling self-service to the people using it.
The Architecture
Dayo-Tech designed the platform around Kubernetes orchestration running on NVIDIA DGX A100 hardware, with full isolation between research teams as a foundational principle rather than an added control.
The insight that made the platform genuinely usable was the offline artifact repositories. By establishing internal PyPI and APT mirrors, Dayo-Tech removed the single biggest source of friction in air-gapped AI work, the inability to install software dependencies. With those mirrors in place, researchers could pull the packages they needed from inside the air gap, with no external connection. Self-service tooling, Jupyter, MLflow, PyTorch, and RStudio, was made available on top of that foundation.
The Platform
The platform gives researchers self-service access to their tools while running entirely within an air-gapped boundary. Kubernetes orchestrates resources across NVIDIA DGX A100 systems; teams provision environments with Jupyter, MLflow, PyTorch, and RStudio; and the offline PyPI and APT mirrors supply the packages those environments depend on, all without external connectivity. Each team's environment stays fully isolated from the others.
The experience is what matters. A researcher can spin up an environment, install what they need from the internal mirrors, and work without hitting the dependency walls that normally define air-gapped systems, while the Ministry retains the complete isolation its security posture requires.
Technology Stack
Compute / GPU: NVIDIA DGX A100
Virtualization / Containers: Kubernetes
Automation / DevOps: Offline PyPI mirror; offline APT mirror
Research Tooling: Jupyter; MLflow; PyTorch; RStudio
The Impact
Research teams now self-serve isolated AI environments on Kubernetes and NVIDIA DGX A100 hardware inside fully air-gapped networks, with offline PyPI and APT mirrors removing the external-dependency blockers that would otherwise make such work impractical. Full isolation between teams is maintained throughout. Described qualitatively, no usage figures were part of this engagement, friction that would normally cripple air-gapped AI research was removed, so researchers get modern, self-service tooling without any compromise to the network's isolation.
Closing
This engagement highlights Dayo-Tech's ability to solve problems that have no off-the-shelf answer. Delivering modern, self-service AI infrastructure inside one of the most restrictive environments an organization can operate in took creative, security-first architecture, not just hardware deployment. It's a strong example of Dayo-Tech engineering through a hard constraint rather than around it.




Comments