All insights

Air-Gapped & On-Prem

Multi-Site Air-Gapped Deployments Across Districts

· 11 minute read

A state-wide agent is not one cluster with thirty VPNs. It is a versioned appliance, a media bus, and the humility to let a weak district stay smaller.

After the first collectorate box works, someone in the secretariat will say: now do all districts. The map comes out. Thirty or seventy points. The vendor draws a hub-and-spoke with a pretty SD-WAN overlay. That drawing is how you accidentally build a statewide outbound path and call it an air gap.

Districts are not identical. One has a NIC room with two racks and a generator. The next has a single tower PC, a clerk who is also the server admin, and a leased line that dies in the monsoon. A multi-site design that assumes SDC hygiene in every tehsil will fail in the third week, and the failure will be political because the third week is when the chief secretary asks for a dashboard.

This guide is for programme owners who must put the same workflow in many buildings without a standing vendor control plane on the public internet. It is not a WAN design manual. It is the set of decisions that keep each site honest.

Three topologies that are honest

First: a single state SDC deployment that districts reach only as thin clients or browser users over the state WAN, with no local model. This is not multi-site inference. It is central inference plus remote officers. It is often the right answer. It concentrates GPUs, logs, media protocol and people where they exist. It fails when the WAN fails, which you must say in the note.

Second: a central gold image and local inference boxes that never call home. Updates travel as media or as a one-way push over a government WAN that you treat as hostile and pin with allow-lists. Each site is its own perimeter. State HQ does not have a standing shell on the district box.

Third: a hybrid. Heavy workflows stay in the SDC. Light, WAN-intolerant workflows run on a small local CPU box with a tiny corpus. Hybrid is powerful and easy to lie about. Write which workflow lives where. If both can see the same live personal data, you have two stores to erase.

Pick a pattern per workflow. Do not pick a pattern per slide.
PatternWhen it is honestWhat usually goes wrong
Central SDC onlyState WAN is good enough and HQ can staff nightsVendor still opens a cloud fallback when the WAN blips
Local appliance, no call-homeDistricts must survive WAN loss; media desk existsVersion drift; one district on a six-month-old model
Hybrid by workflowYou can name which desk uses which boxQuiet dual processing; two indexes of the same citizen
Hub with vendor SD-WANAlmost never, if you claimed air-gapThe overlay is an outbound fabric with extra branding

The gold image and the media bus

If you chose local appliances, you need a factory. HQ builds one gold image: OS, runtime, model shards, prompts, tool contracts, local identity hook. That image is versioned. Districts do not compose their own stack from a vendor portal.

The media bus is how versions move. A monthly bag or a government-WAN one-way drop to each site, with the same hash protocol you use for a single SDC. Weak districts get fewer versions, not unofficial internet pulls. A district that cannot staff a clean-room bench should not have a local GPU. Give them the central portal instead. Identity stays local or uses the state directory over the government WAN, not the vendor's IdP. Logs stay local for CERT-In's 180 days and, if policy requires, ship a copy to the state SIEM over the government WAN on an allow-list. They do not ship to a vendor cloud so HQ can see a single pane.

Version drift is the real incident

The incident will not look like a hack. It will look like District A refusing a query that District B answers, because A never loaded the March prompt pack. A citizen will compare two collectorates on social media. The secretariat will ask why the same agent disagrees.

Publish a state compatibility matrix: site, image version, model version, prompt pack, last hash, last successful eval. Make it a standing item in the programme meeting. Sites more than one version behind lose the right to new workflows until they catch up. Do not give district enthusiasts root. Local root is how a helpful NIC contractor enables a cloud reranker only for testing. Centralise admin or use break-glass with a state ticket.

  • One gold image, many copies — not many snowflakes.
  • A published version matrix the secretary can understand.
  • WAN used as a courier, not as a vendor control plane.
  • Permission to stay on the central portal if the district cannot staff a bench.
  • No site-level internet just for updates.

Objections you will hear — and what to do with them

These are the lines that stall the file. Answer them in the room, then put the answer in the note. A spoken answer without paper will be forgotten by the next officer.

The chief secretary wants one dashboard of all districts.

Then build a state SIEM or a roll-up that districts push on a schedule, with no prompt text by default. A vendor SaaS dashboard that districts phone is a statewide outbound mesh.

Local politicians will not accept a portal; they want their server.

Give them a labelled local box only if they can staff the bench and accept the version matrix. A dead local server is worse politics than a portal with an SLA.

SWAN is already government, so any traffic on it is fine.

SWAN is better than the internet. It is still a shared network. Allow-list, encrypt, and do not put vendor control traffic on it just because the circuit is paid from the IT budget.

A state rollout in one quarter without a fantasy WAN

  1. Weeks 1–2: classify each site as portal-only, local-light, or local-heavy. Publish the list. Expect arguments. Keep the list honest.
  2. Weeks 3–5: build the gold image and the media bus. Dry-run two sites of different classes.
  3. Weeks 6–8: train the three people each local site actually has, including the seal protocol.
  4. Weeks 9–12: roll in waves. Freeze versions during a wave. Update the matrix every Friday. Refuse unofficial internet bridges.

How this shows up in the file

The rollout note should attach the site classification, the topology per workflow, the version matrix template, and a sentence that HQ will not operate a vendor overlay. A later collector should see why their building got a portal instead of a GPU.

If a site later grows a rack, they change class by a written request, not by a contractor with a carton.

Who owns a site when HQ is a time zone away

Every local-heavy site needs three names posted on the rack: the administrative owner, the technical hands, and the state ticket queue that answers when both are on leave. A WhatsApp group is not a queue. A queue has a clock and a log. HQ must resist the urge to keep a standing admin account just in case. Break-glass should mint a short-lived credential after a state ticket, and should expire.

Eval is how you notice drift before social media does

Once a month, HQ ships a ten-item eval pack — redacted, versioned — with the media bus. Each site runs it or the portal runs it on their behalf. Results come back as numbers, not as prompt text. A site that drops on citation or refusal is marked amber on the matrix. Amber sites do not get new workflows. They get a bag.

The politics of the portal district

Collectors who did not get a box will complain. Give them a written class, a WAN SLA, and a path to change class when they can staff a bench. Invite them to the Friday matrix so they see that GPU districts also get marked amber. Silence reads as favouritism. A matrix reads as a programme. Never let a local MLA's visit force a weekend GPU install without the protocol. A visit can force a portal demo in the collectorate hall. That is enough optics.

What the next noting must contain

“Multi-Site Air-Gapped Deployments Across Districts” belongs in a file, not only in a search result. A P4 Programme/Implementation should be able to point at one artefact that proves “multi site AI deployment”: a packet capture, a processing schedule, a scored evaluation row, a dated notice, or a refusal rule. If the only evidence is a slide, you have a heading.

A state-wide agent is not one cluster with thirty VPNs. It is a versioned appliance, a media bus, and the humility to let a weak district stay smaller. DPDP 2023 does not define sovereign AI and does not write a blanket localisation rule for every model hop. CERT-In’s 28 April 2022 directions still set specified incident clocks and 180-day log retention in India for in-scope events. The November 2025 AI governance text is guidance, not a statute. A Proprietary Article Certificate, when it is lawful, lives in GFR Rule 166 — not Rule 161.

Write three dated sentences under C2 Air-Gapped & On-Prem: what was decided, which designation owns it after the next posting order, and when it will be re-checked. Unsigned sentences are souvenirs. Dated sentences are controls.

  • Name the designation that owns “multi site AI deployment”, plus a deputy.
  • Attach one artefact a stranger can open next year.
  • Name the instrument you are actually using — Act, direction, GFR clause, GeM term, or guideline paragraph.
  • Leave unsourced percentages, GMV slides and house forecasts out of the noting.
  • Revisit when the model, the SI, the notice, the region or the posting changes.

This article is informational field guidance for Indian public institutions, not legal, procurement, security-accreditation or engineering advice. Confirm against the current Gazette, CERT-In direction, GFR, GeM term, SDC policy and your counsel before you file it.

Questions this usually raises

Should every district get the same GPU?
No. Match hardware to site class. Identical hardware in unequal buildings produces equal invoices and unequal uptime.
Can districts share one model store over SWAN?
They can share a central inference service. They should not mount each other's disks. Shared stores create shared incidents and shared erasure problems.
How do we patch thirty air-gapped boxes?
With a gold image and a media or one-way bus, on a published cadence. Not with thirty separate vendor tunnels.
What if one district insists on a local ChatGPT account as well?
Treat it as unofficial processing. Either bring the workflow onto the official path or issue a written prohibition. A second unofficial path makes the official air gap decorative.

Sources