Air-Gapped & On-Prem
Choosing Between MeghRaj and Your Own Racks
· 10 minute read
MeghRaj is a government cloud programme, not a magic GPU shop. Own racks are control, not virtue. Choose on procurement path, control plane and whether the hall can actually place accelerators.
MeghRaj is not a startup. It is the Government of India's GI Cloud initiative, announced to push departments toward shared, auditable cloud services instead of a server under every desk. NIC's National Cloud has been the public face many officers know. MeitY's empanelment path brought other CSPs into the same policy orbit. If someone in a meeting says 'just put it on MeghRaj' they may mean any of those things. Make them point at a portal and a service description.
Your own racks are also not a moral victory. They are a decision to own placement, isolation and often the ugly parts of power and patching. They can be the only way to keep a true air gap. They can also be a crate in a corridor with a heroic deputy director.
This comparison refuses two lies: that GI Cloud is automatically AI-ready, and that own racks are automatically sovereign. We will compare control, procurement and GPU availability as decision factors. We will not invent a unit price or a GeM GMV.
First, name the offering
| What people say | What you should ask |
|---|---|
| MeghRaj | Which service? NIC National Cloud, a state landing zone, or an empanelled CSP? |
| National Cloud | Which NDC hall, which tenancy, which catalogue item for GPU or dedicated host? |
| Empanelled CSP | Which MeitY-empanelled offering, which Indian region, which STQC scope? |
| Own racks | In whose building? SDC cage, campus HPC, plant DMZ, or a vendor colo calling itself yours? |
Three decision factors that are not price theatre
Control
Who can snapshot the disk? Who holds the hypervisor? Who can push a route? Who sees console logs? GI Cloud offerings vary: some give you a tight tenant, some give you a VM on a busy estate, some give you a managed Kubernetes with an operator you did not choose. Own racks vary too: a cage in an SDC with hall operators is not a rack in a minister's antechamber.
Write a control score: identity, egress, admin path, key custody, backup location. Score the actual offering, not the brand. A well-run National Cloud tenant can beat a sloppy own rack on control. A dedicated departmental cage can beat a shared GPU pool on control. Measure.
Procurement
GI Cloud exists partly so departments can consume infrastructure without a full hardware tender every time. That is a real advantage: time, GFR hygiene, and a vendor who already knows government. Own racks mean a hardware BoQ, delivery, installation, AMC, and often GeM or an open tender. That is slower and more honest about capital.
Do not assume GI Cloud is always faster. A GPU SKU that is not on the catalogue will send you into a special indent anyway. Do not assume own racks are always cleaner. A poorly specified tender will land you an SI who brings their own licence server.
GPU availability
This is the practical breaker. Many GI Cloud catalogues grew around CPU. Accelerators appear, then vanish, then require a conversation. Own racks let you buy the node you need — if the hall will power it and if you can wait for supply. Neither path has magic inventory. Ask for a current, written availability statement. Do not use a tweet or a blog's imagined queue.
A comparison you can score
| Question | GI Cloud / MeghRaj-path | Own racks |
|---|---|---|
| Time to a CPU VM | Usually better | Usually worse |
| Time to a specific GPU | Depends on catalogue — ask | Depends on supply + hall — ask |
| Air-gap possible | Only if the offering isolates and allows deny-all | Yes, if you actually isolate |
| Admin path | Tenant + operator / MSP | You + whoever has the cage keys |
| Capex vs opex | Mostly consume | Mostly buy, then AMC |
| Exit | Export disks and artefacts; watch lock-in to a managed K8s | You own the box; you still need runbooks |
| Political readability | Easy to defend as policy-aligned | Easy to defend as control-aligned |
Objections you will hear — and what to do with them
Policy requires MeghRaj.
Then consume it where it fits, and write a dedicated-host or hall-cage offering as part of that policy if you need isolation. Policy is not a suicide pact with a shared GPU.
Own racks are Atmanirbhar; cloud is not.
GI Cloud is an Indian government programme. Empanelled CSPs have an Indian compliance story you still have to read. Nationalism is not a network diagram.
We will decide on price after informal calls.
Informal GPU prices are how files go wrong. Official quote, same control score, then finance. Anything else is a bazaar.
A three-week choice playbook
- Week 1: write the control score you need (air gap or not, admin path, GPU class as a range).
- Week 2: ask GI Cloud / NIC / SDC for a written offering that meets the score. Ask your hall about own-rack placement.
- Week 3: compare the two written answers plus lead times. Pick, or pick a hybrid (build on GI Cloud, run on racks). File the letters, not the adjectives.
How this shows up in the file
The choice note should define MeghRaj as GI Cloud, name the actual offering, and say why own racks were accepted or rejected on control, procurement and GPU availability. A later secretary should not have to guess whether you meant National Cloud or a private colo with a tricolour sticker.
A hybrid that is still honest
Many files should not pick a single home. Build and artefact staging can live on a GI Cloud tenant that already has identity and a scanner. The run room can be a dedicated rack in an SDC cage. The bag is the border. That is MeghRaj-and-racks, not MeghRaj-versus-racks.
What is dishonest is a run path that spans both without a bag: a model on a departmental GPU calling an index on a shared tenant with a default route. Then you have two homes and one leak. Draw the border as strictly as if one side were foreign, even when both sides are Indian government. Tenancy is not patriotism.
- Write which side may hold personal data.
- Write which side may pull public images.
- Write how artefacts cross.
- Write what still works if the WAN between hall and rack dies.
Procurement can still be tidy: consume GI Cloud for the build side on a rate card, and buy the run rack as capital, each with its own sanction paragraph. Two paragraphs beat one muddy paragraph that says 'cloud plus some hardware'.
This article is a field guide, not legal, procurement, electrical or engineering advice. Confirm numbers, duties and designs against the current Gazette, CERT-In directions, your SDC / NIC / campus standards, a site survey and your counsel before you file them.
How to prove this on a rack, not on a slide
“Choosing Between MeghRaj and Your Own Racks” only matters if a CISO can fail it. A P1 CIO/CTO should be able to point at a cable, a registry, a licence file, a PDU reading or a SIEM index and say: this is the control. If the only evidence is a brochure that mentions “MeghRaj GI Cloud AI”, you do not have the control.
MeghRaj is a government cloud programme, not a magic GPU shop. Own racks are control, not virtue. Choose on procurement path, control plane and whether the hall can actually place accelerators. Air-gap and on-prem programmes die in the second month, when the first update, the first crash, or the first GPU lead-time slip arrives. Budget the boring path — media, offline licence, local registry, local traces — in the same note as the model name.
On-prem is not air-gapped. An India region is not either. Write the forbidden path (outbound HTTPS, licence phone-home, crash reporter, hidden model API) as a numbered list and test it with the internet off. Whatever still dies was a dependency you did not draw.
- Draw the data path for one user-visible answer under “MeghRaj GI Cloud AI”.
- Disable outbound internet on staging and run the demo script.
- List every remaining hop: update, licence, registry, NTP, DNS, SIEM.
- Give each hop an owner inside the department, not only the SI.
- Minute the restore or the media-transfer once before go-live.
Close this loop before the next CAB
Put “Choosing Between MeghRaj and Your Own Racks” on the next change-advisory or bid-opening agenda as a single line item with an owner. If it cannot earn a line item, it will not earn a control. The owner should be a P1 CIO/CTO, not “the vendor.”
Revisit the item when the model, the GeM term, the region, or the SI changes. “MeghRaj GI Cloud AI” is not a one-time workshop. It is a watch item. Date the last check. Unsigned watch items are souvenirs.
Questions this usually raises
- What is MeghRaj, precisely?
- MeghRaj is the GI Cloud initiative of the Government of India, intended to provide cloud services for government. NIC's National Cloud is a principal delivery path; MeitY also empaneled other CSPs under the wider GI Cloud story. Always ask which offering, which hall and which contract you would actually sit on.
- Does choosing MeghRaj make the AI sovereign?
- It can improve location and procurement hygiene. It does not by itself ban training, kill telemetry, or isolate a tenant. Sovereignty is still a map of hops and admin paths.
- Can you quote current MeghRaj GPU prices?
- No. Catalogues move, and unofficial numbers in a blog become folklore in files. Compare the procurement path and who you pay. Get a current quote through the official channel for the SKU class you need.
- When are own racks the better file?
- When you need an air gap the catalogue cannot offer, a GPU density the hall cannot place this year, or a data class that cannot live under the available tenancy and MSP model. Own racks still need a hall, power and people.