Video software vendor

Air-gapped Kubernetes embedded in trucks, all over the world

A video software vendor wanted to run its platform in trucks deployed to every corner of the world, with no internet connection at all. Its team had no Kubernetes experience. Six months later, the platform was running on its own, and the client still builds on it today.

Where they started

Hand-configured servers around a rough Docker Swarm cluster. It met none of the client’s expectations, and the team had to build much of what a modern orchestrator provides out of the box: service restarts, scaling, configuration management.

We came in as a subcontractor to the client’s software partner.

The challenge

Running Kubernetes without internet access, for installation and day-to-day operation alike, at a time when neither the tooling nor the documentation covered this case:

  • installing without access to public repositories;
  • hosting a local image registry, down to the system images everyone forgets, such as the pause image behind every pod;
  • updating with no connection;
  • all for a team that was new to container orchestration.

The critical moment

Kubespray had next to no support for air-gapped installs, and errors surfaced late, sometimes deep into testing. Every fix uncovered a new problem, to the point where delivering on time looked out of reach.

We changed our method: a fully automated platform build, failing fast on the developer’s machine, and a very thorough test suite that blocked regressions and drastically shortened the feedback loop.

What we delivered

  • A tailor-made, 100% offline Kubernetes cluster: Kubespray, containerd, local-path-provisioner for storage, an embedded Docker registry.
  • A fully declarative platform: every deployment is an Ansible playbook, versioned in Git and applied automatically. The client can rebuild and evolve it on its own.
  • Scaling: without touching the client’s proprietary software, its application now handles a much heavier load.

Outcome

A self-contained platform, deployed in trucks all over the world. The client took ownership of it and keeps iterating on it, years later. They would have liked us to stay.

“We would never have made it without you.”

If we did it again in 2026

The ecosystem has matured. Today we would choose Talos Linux, an immutable OS built for Kubernetes, Cilium for networking and security, and CloudNativePG for databases. The approach would stay the same: everything declarative, everything tested, nothing by hand.

Other case studies

  • Financial institution

    Secure AWS landing zone

    Context
    Teams moving to the cloud in a scattered way: accounts created one by one, with no central organisation and no least privilege.
    What we did
    An AWS landing zone (Organizations, Control Tower, Terraform), SSO integrated with the corporate identity system, and guardrails that enforce internal rules automatically.
    Outcome
    A transformed security posture, and the cloud foundation of the whole organisation, which keeps welcoming new services.
    Read the full case study — Secure AWS landing zone
  • Healthcare start-up

    On-premise sovereign AI

    Context
    Customer feedback volumes that had become unmanageable, and medical data that must never leave the company.
    What we did
    Open-weight LLMs on custom-orchestrated on-premise hardware, RAG over internal knowledge, and MCP servers built to query business software.
    Outcome
    In production, several hours saved per case, and an MVP delivered at two thirds of the estimated budget.
    Read the full case study — On-premise sovereign AI
  • IT service provider

    Open-source observability for 1,500 services

    Context
    A proprietary monitoring stack at the end of its rope: no way to group signals or model dependencies, slowness, and around fifteen incidents a day.
    What we did
    A highly available observability platform (OpenTelemetry, Mimir, VictoriaMetrics, Loki, Tempo), service discovery, and custom Prometheus-compatible probes.
    Outcome
    From fifteen incidents a day to one or two a month, and on-call engineers who are hardly ever woken at night.
    Read the full case study — Open-source observability for 1,500 services

Contact

A similar project?

Tell us about your context. We reply within two working days with a first, concrete opinion.

Prefer a direct line?

contact@okko.be