Skip to content

// installation

Operating models

Applies to

Product: Server · Audience: Platform Operator · IT management · Procurement

Who operates the system day to day: the customer (self-managed) or basebox, if installation and/or operation have been commissioned. Access for operation by basebox takes place via PAM/VPN or another agreed path. The operating model is independent of where the server stands and where the hardware comes from.

The two models

Self-managed server. After receiving the software, you are responsible for infrastructure and operation: operating system, drivers, Kubernetes, basebox installation, service models, inference, network, backups, updates, monitoring. basebox provides software, updates, documentation and support.

Installation / operation by basebox. If commissioned separately, basebox installs and/or operates the system via a controlled, agreed access path – typically privileged access management (PAM) and/or VPN, time-limited and approved by the customer. The scope is defined per project.

Buying the software does not include operations

A basebox Server licence is a software licence. Operation by basebox is a separate engagement. Do not assume it is included – and conversely, do not assume basebox has access to your server if you have not commissioned it.

Who does what in which model

Area Self-managed Operated by basebox
Physical hardware, data center Customer / hardware partner / hosting Customer / hardware partner / hosting
Operating system, NVIDIA drivers, Kubernetes Customer basebox, if in scope
basebox installation Customer basebox
Service models, inference Customer Per project scope
Network Customer Shared: customer network with the customer, access path with basebox
Ongoing operations: monitoring, backup, updates Customer basebox, if commissioned
Application administration (users, models, apps, connectors) Customer Customer
Application data (documents, chats, knowledge bases) Customer Customer

"basebox, if in scope" means: can be part of the engagement, is not automatically included. The canonical table: Responsibilities.

What stays with the customer in every model

basebox operating the infrastructure does not make basebox the administrator of your application. Users, groups, roles, model selection, apps, knowledge bases, connector enablement, policies and audit remain with your administrators. Responsibility for the data – in the data protection sense – remains with your organisation.

Access when basebox operates

  • Path: PAM and/or VPN or another contractually agreed path.
  • Time-limited and approved by the customer. Maintenance access is opened for support purposes and disabled afterwards.
  • Logged. What is logged, who approves and how access is revoked: Remote maintenance.
  • No access without an engagement. A self-managed server is not reachable for basebox.

Hybrid forms

The two models are endpoints; in between there are common variants:

Variant Description
Installation by basebox, operation by the customer basebox installs and hands over; afterwards your IT operates. basebox's access ends with the handover.
Operation by the customer with on-demand support access Your IT operates; for individual support cases, access is enabled for a limited time.
Operation by basebox, infrastructure at the customer The server stands at your site, basebox operates the software stack via remote maintenance.
Operation by basebox, hosting at basebox Server and operation at basebox – still a dedicated server, not Cloud.

What exactly is in scope belongs in the contract – the table above is built for that.

What you need for self-operation

  • A person or team with Kubernetes and Linux experience; NVIDIA drivers and the GPU Operator are part of daily work.
  • An operations plan: monitoring, backup and restore, updates with a backup beforehand, capacity – see Customer-managed operations.
  • Registry access or an offline transfer procedure for updates.
  • The willingness to read release notes: security and feature updates are announced; installation is up to you.

What you need for operation by basebox

  • An approved access path (PAM/VPN) with an approval process on your side.
  • A contact person who approves maintenance windows and signs off changes.
  • Still administrators for the application.
  • Clarity about which items of the table are in scope – see Operation by basebox.

Decision aid

Situation Model
Own IT with Kubernetes experience, control over everything wanted Self-managed
No Kubernetes experience, but a dedicated server needed Operated by basebox
Compliance requires that no external party has access Self-managed, possibly installation by basebox with handover
Little operational capacity, server should stand at basebox Hosting and operation by basebox

Next step: Installation paths