AravaliStack is an enterprise-grade, on-premise Platform as a Service (PaaS) โ a complete cloud platform that runs on hardware you own. It delivers the same capabilities as AWS, Azure, or GCP (Kubernetes orchestration, managed databases, ML infrastructure, developer tooling, observability, security) but on your own servers, in your own data centre, with no external dependencies.
AravaliStack is developed and commercialised by TechRajendraยฎ (Rajendra Management Pvt. Ltd.), a technology company registered in New Delhi, India. All engineering, support, and product teams are India-based. Support is available in Hindi and English during IST business hours, with enterprise SLA options.
AravaliStack is built entirely on open-source components โ Kubernetes, Linux, and CNCF-graduated projects form the core of every platform layer. The AravaliStack platform layer โ the integration, configuration, automation, and governance that turns these components into a production-ready enterprise platform โ is proprietary software licensed to enterprise customers. You own your data and your infrastructure. You are never locked into AravaliStack-specific APIs.
Installing Kubernetes is the beginning, not the end. A production enterprise platform requires: a service mesh with mTLS, secrets management with dynamic credentials, identity and access management, object storage, data streaming, ML infrastructure, developer self-service tooling, GitOps-based deployment, cost attribution, integrated observability, and compliance controls. Assembling, integrating, securing, and operating all of this is a multi-year engineering effort. AravaliStack delivers it as a maintained, tested, production-ready platform from day one.
AravaliStack is licensed annually per node cluster. Pricing is based on cluster size (number of nodes) and the modules you need. Most enterprise deployments start at โน40โ80L per year for a 10โ20 node cluster. A custom quote based on your specific requirements is available โ contact us or view our pricing page.
AravaliStack runs on standard x86-64 servers โ Dell PowerEdge, HPE ProLiant, Lenovo ThinkSystem, Cisco UCS, or equivalent. We also support AMD EPYC and Intel Xeon processor families, NVIDIA GPU nodes (A100, H100, RTX series) for ML workloads, and NVMe all-flash storage for high-performance databases. There is no proprietary hardware requirement โ if it runs Linux, it runs AravaliStack.
A production AravaliStack deployment requires a minimum of 3 control plane nodes (for high availability) and 3 worker nodes โ a 6-node minimum. For lab and evaluation purposes, a 3-node all-in-one cluster is supported. For large enterprises, we have deployed clusters of 200+ nodes.
Both. AravaliStack runs natively on bare metal (Linux installed directly on servers) for maximum performance โ ideal for ML workloads, high-throughput databases, and latency-sensitive applications. It also runs on virtual machines (VMware, KVM, Proxmox, Hyper-V) for environments that require VM-based isolation. Bare metal is recommended for production ML and database workloads.
Yes โ and this is one of AravaliStack's core design requirements. All components are available as an offline deployment bundle deliverable via encrypted physical media. There are no phone-home licence checks, no external telemetry calls, no dependency on public DNS or certificate authorities. Once deployed, AravaliStack operates indefinitely with zero internet connectivity. This is required for defence, government, and NCIIPC-designated critical infrastructure deployments.
AravaliStack runs on Ubuntu 22.04 LTS and RHEL 8/9 (and compatible distributions including Rocky Linux and AlmaLinux). Both are supported with full automated installation, hardening (CIS Level 2 benchmark), and patch management. Windows is not required anywhere in the stack.
Yes. AravaliStack includes full NVIDIA GPU support โ CUDA runtime, NVIDIA device plugin for Kubernetes, GPU time-slicing and MIG (Multi-Instance GPU) for A100/H100 cards, and GPU monitoring (DCGM metrics integrated into the observability stack). ML training jobs, inference servers, and GPU-accelerated databases all run natively.
A standard AravaliStack deployment โ hardware provisioned, cluster running, all platform services operational โ takes 3โ5 days for a 10โ20 node cluster when hardware is pre-racked and networked. Complex environments (multi-site, air-gapped, custom HSM integration) take 2โ4 weeks. We provide a dedicated deployment engineer for every installation.
Day 1: Hardware assessment and network design review. Days 2โ3: Automated OS provisioning and cluster formation. Day 4: Platform service installation (all 8 domains). Day 5: Validation testing, security hardening review, and handover. Post-deployment: 30-day hypercare period with daily check-ins. Full documentation and runbooks delivered at handover.
You need at least one engineer with Linux systems administration experience and a willingness to learn Kubernetes fundamentals. AravaliStack is designed to minimise the operational expertise required โ GitOps-based changes, self-healing workloads, automated certificate rotation, and integrated monitoring mean that day-to-day operations require far less Kubernetes expertise than a self-managed cluster. We provide training as part of every deployment.
Platform updates are delivered as signed Helm chart bundles, versioned and tested before release. Updates are applied through the GitOps pipeline โ a pull request is opened in your configuration repository, reviewed by your team, and merged to apply. For air-gapped environments, updates are delivered as encrypted offline bundles. There are no forced updates and no update windows imposed by us.
Enterprise customers receive 24ร7 on-call support with defined response SLAs (P1: 30 minutes, P2: 2 hours, P3: next business day). Support is staffed in India (IST) by engineers who built the platform. We also provide runbooks for every common failure scenario so your team can resolve most issues independently.
Yes. Multi-site AravaliStack deployments support active-active and active-passive configurations. The platform includes cross-site service mesh federation (encrypted mTLS between sites), object storage replication, database replication, and GitOps-based configuration sync. Typical use cases include primary DC + DR site, or primary DC + two regional edge deployments.
AravaliStack is designed to satisfy RBI's data localisation requirements, IT governance framework for banks and NBFCs, and guidelines on outsourcing of IT services. Specifically: data stays physically within your infrastructure (satisfying data localisation), all changes go through GitOps with approval workflows (satisfying change management requirements), and the platform generates the audit trails and access logs required for RBI IT examinations. We have worked with RBI-regulated banks and NBFCs to validate this compliance posture.
Data sovereignty is a first-principle design constraint, not an add-on feature. AravaliStack makes zero outbound network calls โ no telemetry, no licence checks, no external API dependencies. All data processed by your workloads stays within your infrastructure. The platform includes encryption at rest (AES-256, with your own key management), encryption in transit (TLS 1.3 enforced by service mesh), and zero-trust access controls that prevent unauthorised data access even within the cluster.
AravaliStack's security architecture is aligned with ISO 27001, SOC 2 Type II, CIS Kubernetes Benchmark (Level 2), and NIST SP 800-207 (Zero Trust Architecture). Our enterprise customers have successfully used AravaliStack deployments in RBI IT examinations, SEBI compliance audits, and CERT-In assessments. Full security documentation is available under NDA from our Security Trust Centre.
Zero trust in AravaliStack is not a marketing claim โ it is a specific set of technical controls: (1) SPIFFE/SPIRE-issued machine identities for every workload โ short-lived X.509 certificates, rotated every 1โ4 hours; (2) Istio service mesh enforcing mutual TLS on all service-to-service communication; (3) OPA-based policy engine controlling every API call to the Kubernetes control plane; (4) Vault-issued dynamic secrets โ database credentials with configurable TTLs, no static passwords. Default-deny network policies block all traffic not explicitly permitted.
Yes. AravaliStack's key management layer supports integration with hardware security modules (HSMs) โ including Thales Luna, nCipher, and PKCS#11-compatible HSMs โ for organisations that require hardware-backed key storage. Encryption keys for object storage, Kubernetes secrets, and certificate authorities can all be protected by an HSM.
No. AravaliStack collects zero telemetry, usage data, or operational metrics. There are no analytics calls, no error reporting to external servers, no licence validation endpoints. This is verifiable โ the platform is air-gapped capable by design, which means it functions identically with or without internet access, confirming that no external calls are required for any function.
AravaliStack is licensed on an annual subscription basis, per cluster, with pricing based on the number of nodes. The licence includes the platform software, all platform modules (compute, security, networking, data, ML, developer tools, cost intelligence, marketplace), software updates, and enterprise support. There are no per-CPU, per-core, or per-workload charges beyond the node-based licence.
Yes. We offer a structured 30-day Proof of Concept (PoC) programme for enterprise customers. The PoC includes: a lab deployment on 3โ6 nodes (which can be virtual machines on your existing infrastructure), deployment of your target workload, performance and compliance validation, and a full technical report. The PoC is priced at cost and the fee is credited toward the full licence if you proceed.
The minimum licence term is 12 months. Multi-year agreements (3 or 5 years) are available with favourable pricing and guaranteed licence rate locks. Enterprise customers are encouraged to consider 3-year agreements to align with hardware depreciation cycles.
You do. Completely. AravaliStack licences software to you โ the hardware, the data, the configurations, and the workloads are entirely yours. If you choose not to renew the licence, the platform continues to function (you own it), but you lose access to updates and support. There is no kill switch, no feature degradation, and no data held hostage.
Yes. A Partner Programme for Managed Service Providers (MSPs), System Integrators (GSIs), and resellers is available. MSP partners can deploy AravaliStack for multiple enterprise customers on a shared or dedicated basis, with per-tenant cost attribution and invoicing. Contact us at partners@aravalistack.com to discuss partnership tiers.
Our team answers pre-sales questions within one business day.
