Air-Gapped & On-Prem
Why NIC Data Centres Fail AI Readiness Checks
· 10 minute read
NIC and SDC halls are how India already runs government IT. They fail some AI checklists for boring, fixable reasons. Treat them as a site, not as a villain.
It has become fashionable in some vendor meetings to say NIC cannot do AI. That sentence is lazy and, in many files, false. NIC national data centres and State Data Centres already host the applications citizens actually use. They have physical security, change calendars, identity ties and a political legitimacy a server under a desk will never have.
They do fail a certain kind of AI readiness checklist. The checklist was often written by people who assume a public cloud: instant GPU SKUs, outbound HTTPS to a registry, a vendor-operated control plane, and a power budget that can swallow a 6–10 kW node without a letter. NIC and SDC halls were built for a different density and a different trust model. That is a gap. It is not a smear.
This teardown is for CIOs who need to use those halls honestly. If your SDC can take the workload after a survey, use it. If it cannot, say which control failed — power, GPU, outbound, skill — and pick the next government option. Do not jump to a foreign region because a demo needed a docker pull.
What 'AI ready' actually means in a government hall
Readiness is not a banner on a website. It is four questions a site engineer can answer with measurements. Can the hall deliver the power and cooling for the node you actually ordered? Can it place that node on a network that matches your air-gap or proxy claim? Can it operate the node after the SI leaves? Can it show logs to your SOC for 180 days in India?
| Check | Why halls fail it | Fair response |
|---|---|---|
| GPU availability | Halls were sized for CPU estates; GPUs are still a special order | Forecast and indent; do not assume a catalogue |
| Power / cooling density | Older rows may be 4–8 kW per rack; AI nodes can exceed that | Site survey; maybe a new row, not a new religion |
| Outbound assumptions | Vendor stacks assume Docker Hub, licence, NGC, APM | [Private registry](/blog/container-registries-in-disconnected-networks) + ceremony; reject phone-home |
| Ops skill | Shift staff know VMs and databases, not CUDA and vector restores | Train a cell or buy an SI seat; do not mock the shift |
| Multi-tenancy | Shared management planes and jumpy VLANs | Write isolation; do not hide a GPU on a general VLAN |
| Change windows | Monthly CAB versus weekly model bumps | Agree a calendar; do not bypass CAB |
The four gaps, without the sneer
GPU is a procurement and power problem
Most NIC and SDC catalogues grew around virtual machines, databases and web farms. A GPU node is still often a project, not a menu item. That is frustrating. It is also how public halls avoid surprise electrical load. If you need GPUs, write the indent early, name the SKU class not a fantasy, and accept that lead time is part of the architecture.
Do not treat a missing GPU today as proof the hall is obsolete. Treat it as a capacity plan. Some halls will host your node. Some will point you to a sister NDC, a state HPC, or a MeghRaj offering that has accelerators. Ask. Do not announce.
Power and cooling were specified for a different decade
A departmental CPU rack and a 4–8 GPU training box are not interchangeable tenants. Heat and kilowatts are local facts. We have seen halls that can take one inference node on an existing row and halls that need a dedicated cage. Only a survey knows. Anyone who tells you 'all NIC DCs fail power' has not walked enough floors.
Vendor software assumes the internet
This is the gap vendors blame on NIC and should blame on themselves. Helm charts pull from public registries. Licence daemons call home. Observability exporters aim at a SaaS. A disciplined hall that blocks unknown egress is doing its job. The stack must learn to live there: private registry, offline licence, local SIEM. A hall that opened the firewall to make a demo green would be the one failing India.
Ops skill is scarce everywhere
CUDA driver pins, vector restores and gold-set regressions are new work. SDC shift staff are not stupid for not knowing them. They have been keeping treasuries and land records up. The readiness move is a small shared cell, training, and an SI who leaves runbooks. The unreadiness move is to sneer and then hire a vendor who will not sit a night shift in the same city.
How to run a fair readiness review
- Walk the hall with the operator, not only with the vendor. Ask where a GPU node would sit.
- Measure or obtain the row's spare kilowatts, cooling margin and breaker map. Write ranges if exact telemetry is missing.
- List required outbound destinations of the proposed stack. For each, mark allow, substitute, or refuse.
- Name the operators who will patch and restore. If the names are only in another city, write the travel and the rota.
- Ask how identity, backup and visitor access already work. Reuse them. Do not invent a parallel cage without a reason.
- Score gaps as fund, redesign, or move-to-another-government-hall. 'Abandon government halls' is a last resort.
When another hall is the right answer
Sometimes the local SDC should not take the box: seismic or flood constraints, no path to the needed power this financial year, a tenancy model that cannot isolate the data class, or a timeline that a sister NDC can meet. Moving to another Indian government or empanelled hall is not a betrayal of NIC. It is using the federation that already exists.
What is a betrayal of the file is using a readiness miss to justify a foreign control plane. Power is not sovereignty. If the only thing the local hall lacked was a 32-amp feed, the answer is a feed, not a region.
Objections you will hear — and what to do with them
The vendor says only their region is AI ready.
Ask them to list the four checks. If their region wins on GPU SKUs and loses on your air-gap and log-retention duties, it is not ready for this workflow. It is ready for their demo.
SDC tickets are slow, so we should colocate ourselves.
Your own cage will have tickets too, and no night shift. Price the people. A slow but staffed hall often beats a fast empty room.
If we publish gaps we will embarrass NIC.
Precise gaps help NIC and SDC operators budget. Vague scorn helps only the vendor who wants you off the hall. Share the survey with the operator before you share it with a steering committee.
A fifteen-day fairness playbook
- Days 1–3: read the existing SDC / NIC hosting note for this department. Reuse identity and backup if you can.
- Days 4–8: joint survey with hall engineer and electrical. Record spare kW, cooling, and a candidate row.
- Days 9–12: outbound and ops interview. List every phone-home. List every named operator.
- Days 13–15: write a three-column note — keep-and-fund, keep-and-redesign, move-to-named-other-hall. Circulate to the operator for factual correction before it goes up.
How this shows up in the file
The readiness note should thank the hall for what it already does, then list measured gaps and who will fund them. That tone is not courtesy. It is accuracy. India will run a lot of agents in halls that already exist. The institutions that treat those halls as partners will ship. The ones that treat them as punchlines will still be choosing a region when the circular is due.
How to partner with the hall
Bring the operator a one-page forecast: how many nodes, what power class as a range, whether training will ever run, who will hold the bag, and whether you need deny-all. Operators can plan rows for people who forecast. They cannot plan rows for people who arrive with a crate and a slogan about AI readiness.
Offer to fund the row if the hall funds the process. Many SDC directors will create a small AI landing zone if a department pays for PDUs and training rather than for a press note. That landing zone will serve the next department. That is how public infrastructure is supposed to compound.
- Share the outbound manifesto of your stack so they can write proxy rules before install day.
- Invite a shift engineer to the dummy bag import. Respect their change calendar.
- Do not name the hall in a blame sentence in a vendor meeting. Name the control.
- If you move to another government hall, tell the original operator why, with the survey attached. They can use it in their own budget.
NIC and SDC staff have kept national services running through elections, monsoons and ransomware scares. An agent that cannot live in that culture is not too advanced for India. It is too poorly engineered for India.
This article is a field guide, not legal, procurement, electrical or engineering advice. Confirm numbers, duties and designs against the current Gazette, CERT-In directions, your SDC / NIC / campus standards, a site survey and your counsel before you file them.
Questions this usually raises
- Should a department avoid NIC or SDC for AI?
- No. They are often the correct administrative home: existing identity, existing backup, existing visitors' protocol, existing audit trail. Avoiding them to put a GPU under a deputy secretary's desk usually makes sovereignty worse. Fix the gaps or choose a hall that already did.
- Is MeghRaj the same as a NIC national data centre?
- MeghRaj is the GI Cloud initiative. NIC's National Cloud is a major way departments consume it. Empanelled CSPs also sit under the wider GI Cloud / AMBUD story. Do not treat the brand names as one SKU. Ask which hall, which tenancy, which GPU, which outbound path.
- Who decides if an SDC can take a GPU rack?
- The SDC operator, on power, cooling, floor loading, fire and network — not the application owner alone. A departmental sanction that ignores the hall is how you get a crate in a corridor. Commission a site survey.
- Do NIC facilities automatically satisfy DPDP or air-gap claims?
- No. Location in an Indian government hall is not a complete residency or control story. You still map logs, admin paths, model updates and any managed-service hop. A good hall makes that map easier. It does not write the map.