Skip to main content

RGS Carbide Enclave

End-to-end airgapped deployment of the RGS Carbide suite running in an enclave network with an NVIDIA DGX Spark for AI workload serving.

What this is

A fully airgapped Kubernetes environment built on:

ComponentRole
HarvesterBare-metal hypervisor / HCI platform
RKE2Kubernetes management cluster
Rancher ManagerCluster lifecycle + RBAC
HarborOCI container registry
KeycloakOIDC identity provider
cert-manager + step-caInternal PKI / TLS everywhere
HaulerAirgap artifact transport
NVIDIA DGX Sparkarm64 AI inference node

Hardware

HostRoleModelRAM
nuc-00Bastion / adminNUC13ANHi332 GB
nuc-01Harvester node 1NUC10i7FNHTBD
nuc-02Harvester node 2NUC10i7FNHTBD
nuc-03Harvester node 3NUC10i7FNHTBD
sparkNVIDIA DGX Spark (arm64)GB10128 GB
nasNAS / NFSASUS X9994 GB

Network

ItemValue
Domaincarbide-enclave.kubernerdes.com
Subnet10.0.0.0/22
Bastion (nuc-00)10.0.0.10
Harvester VIP10.0.0.100
Rancher VIP10.0.0.30
Harbor VIP10.0.0.99
Keycloak VIP10.0.0.98
DGX Spark10.0.0.251

Bootstrap order

1. Bastion setup (nuc-00) ✅ complete
├── DNS, DHCP, NTP, web, TFTP
└── step-ca (internal root CA) ✅ complete
2. Hauler collect ✅ complete
3. Harvester bare-metal install
4. RKE2 management cluster
5. cert-manager + StepIssuer
6. Harbor
7. Keycloak
8. Rancher Manager
9. DGX Spark + GPU Operator
10. AI serving (vLLM / Ollama)

Repositories