Licensed to be used in conjunction with basebox, only.
// installation
Operating models
Applies to
Product: Server · Audience: Platform Operator · IT management · Procurement
Who operates the system day to day: the customer (self-managed) or basebox, if installation and/or operation have been commissioned. Access for operation by basebox takes place via PAM/VPN or another agreed path. The operating model is independent of where the server stands and where the hardware comes from.
The two models
Self-managed server. After receiving the software, you are responsible for infrastructure and operation: operating system, drivers, Kubernetes, basebox installation, service models, inference, network, backups, updates, monitoring. basebox provides software, updates, documentation and support.
Installation / operation by basebox. If commissioned separately, basebox installs and/or operates the system via a controlled, agreed access path – typically privileged access management (PAM) and/or VPN, time-limited and approved by the customer. The scope is defined per project.
Buying the software does not include operations
A basebox Server licence is a software licence. Operation by basebox is a separate engagement. Do not assume it is included – and conversely, do not assume basebox has access to your server if you have not commissioned it.
Who does what in which model
| Area | Self-managed | Operated by basebox |
|---|---|---|
| Physical hardware, data center | Customer / hardware partner / hosting | Customer / hardware partner / hosting |
| Operating system, NVIDIA drivers, Kubernetes | Customer | basebox, if in scope |
| basebox installation | Customer | basebox |
| Service models, inference | Customer | Per project scope |
| Network | Customer | Shared: customer network with the customer, access path with basebox |
| Ongoing operations: monitoring, backup, updates | Customer | basebox, if commissioned |
| Application administration (users, models, apps, connectors) | Customer | Customer |
| Application data (documents, chats, knowledge bases) | Customer | Customer |
"basebox, if in scope" means: can be part of the engagement, is not automatically included. The canonical table: Responsibilities.
What stays with the customer in every model
basebox operating the infrastructure does not make basebox the administrator of your application. Users, groups, roles, model selection, apps, knowledge bases, connector enablement, policies and audit remain with your administrators. Responsibility for the data – in the data protection sense – remains with your organisation.
Access when basebox operates
- Path: PAM and/or VPN or another contractually agreed path.
- Time-limited and approved by the customer. Maintenance access is opened for support purposes and disabled afterwards.
- Logged. What is logged, who approves and how access is revoked: Remote maintenance.
- No access without an engagement. A self-managed server is not reachable for basebox.
Hybrid forms
The two models are endpoints; in between there are common variants:
| Variant | Description |
|---|---|
| Installation by basebox, operation by the customer | basebox installs and hands over; afterwards your IT operates. basebox's access ends with the handover. |
| Operation by the customer with on-demand support access | Your IT operates; for individual support cases, access is enabled for a limited time. |
| Operation by basebox, infrastructure at the customer | The server stands at your site, basebox operates the software stack via remote maintenance. |
| Operation by basebox, hosting at basebox | Server and operation at basebox – still a dedicated server, not Cloud. |
What exactly is in scope belongs in the contract – the table above is built for that.
What you need for self-operation
- A person or team with Kubernetes and Linux experience; NVIDIA drivers and the GPU Operator are part of daily work.
- An operations plan: monitoring, backup and restore, updates with a backup beforehand, capacity – see Customer-managed operations.
- Registry access or an offline transfer procedure for updates.
- The willingness to read release notes: security and feature updates are announced; installation is up to you.
What you need for operation by basebox
- An approved access path (PAM/VPN) with an approval process on your side.
- A contact person who approves maintenance windows and signs off changes.
- Still administrators for the application.
- Clarity about which items of the table are in scope – see Operation by basebox.
Decision aid
| Situation | Model |
|---|---|
| Own IT with Kubernetes experience, control over everything wanted | Self-managed |
| No Kubernetes experience, but a dedicated server needed | Operated by basebox |
| Compliance requires that no external party has access | Self-managed, possibly installation by basebox with handover |
| Little operational capacity, server should stand at basebox | Hosting and operation by basebox |
Next step: Installation paths