Enterprise AI on Kubernetes and in a closed contour

Performer: Павел Стасиньский

Рейтинг 0 · Число отзывов 0 · Годы опыта 10 · Регион Москва

Годы опыта 10 · Регион Москва

Yandex reviews

We move LLM, RAG and AI agents from prototype to production infrastructure: containerization, GPU, roles and access, logging, monitoring and integration with corporate systems.

Telegram

A laptop prototype is not production. We move LLM, RAG and agents onto Kubernetes with access control, logs and security readiness.

A familiar situation

  • The prototype works, but security won't sign off on it
  • Data can't leave the perimeter to external APIs
  • No access control over the knowledge base
  • The AI agent has excessive permissions
  • No logging of actions or data access
  • Unclear how to scale the model across GPUs

Services

  • AI Kubernetes Readiness AuditInfrastructure readiness audit before an LLM/RAG rollout.
  • LLM ProductionizationMoving a working prototype into production.
  • Secure RAG DeploymentKnowledge base with roles, document filtering and query audit.
  • AI Agent RuntimeIsolated environment for agents and control over available tools.
  • Container Security IntegrationPreparing the AI application for DevSecOps and Kaspersky Container Security.

How an engagement runs

01

Contour audit

Contour audit: infrastructure, data, model, agents — what exists and what is missing

02

Architecture

Architecture design: Kubernetes/OpenShift/DeckHouse, GPU nodes, namespaces, network

03

Containerization

Containerize LLM/RAG/agents, RBAC, secrets, logging, monitoring

04

Handover

Optional — prepare for Kaspersky Container Security integration and handover to the team

Typical architecture

  • Kubernetes / OpenShift / DeckHouse + GPU nodes
  • Namespaces, network, RBAC and secrets for LLM/RAG
  • Inference, agent orchestration, logging
  • Model-load monitoring and GPU cost control
  • Optional: prep for Kaspersky Container Security

How this connects to Kaspersky

We follow secure containerization practices and can account for integration requirements with Kaspersky Container Security — image scanning, policies and cluster runtime control. We design and deploy the AI layer; container security tooling is supplied and configured as a separate product via authorized distribution.

Impact

5 services

from K8s audit to Agent Runtime

on-prem

closed contour without external APIs

from 28 days

Secure Private AI Cloud pack

Price and conditions

Commercial terms for this service
Pricefrom €8,000
Timeline28 days
FormatFixed estimate · remote delivery
ScopeContour: AI layer (private LLM, RAG, knowledge base, Bitrix24/1C), infrastructure (RU cloud, VPN, IAM, backup, logs) and Kaspersky (VM, Linux/Windows, containers, Security Center). Deploy, monitoring, monthly report, incident response. Kaspersky licenses via authorized distribution.

Reviews from Yandex

Public feedback from Yandex Services — same performer profile as the feed.

Невероятный специалист. Откликнулся сразу, на протяжении всего процесса был на связи, работа выполнена качественно в минимальные сроки.

Евгения М.

Yandex

25.07.2025

Павел — ас своего дела! Всё на высшем уровне, всегда на связи, оперативно отвечал на вопросы. Чувствовалось, что ему важен результат.

Ольга

Yandex

20.10.2025

FAQ

Can LLM and RAG run in a closed contour with no internet access?
Yes. The model, RAG and agents deploy on-prem or in an isolated Kubernetes segment — no outbound calls to external APIs.
How is this different from a generic DevOps integrator?
We design and deploy the AI layer itself — LLM, RAG, agents — so it runs correctly on Kubernetes and is ready for security tooling integration. Kubernetes is infrastructure for a specific AI product here, not a standalone service.
Which GPUs and orchestrators do you support?
Kubernetes, OpenShift, DeckHouse; CPU and GPU inference, GPU sharing across workloads, autoscaling for peak model load.
What's included in the AI Kubernetes Readiness Audit?
A check of the cluster, network, access and data for production-readiness of LLM/RAG: bottlenecks, security risks, a scope estimate and a roadmap.
Can Kaspersky Container Security be added to an already running cluster?
Yes, via the separate Container Security Integration product — we prepare the cluster and the AI application for integration, and the security tool itself is supplied and configured via Kaspersky's authorized distribution.

Or leave a request

We move LLM, RAG and AI agents from prototype to production infrastructure: containerization, GPU, roles and access, logging, monitoring and integration with corporate systems.

Name and contact are enough for the first step. A task description is optional.