Enterprise AI on Kubernetes and in a closed contour

Performer: Павел Стасиньский

Рейтинг 0 · Число отзывов 0 · Годы опыта 10 · Регион Москва

Годы опыта 10 · Регион Москва

Yandex reviews

We move LLM, RAG and AI agents from prototype to production infrastructure: containerization, GPU, roles and access, logging, monitoring and integration with corporate systems.

Telegram

A laptop prototype is not production. We move LLM, RAG and agents onto Kubernetes with access control, logs and security readiness.

A familiar situation

  • The prototype works, but security won't sign off on it
  • Data can't leave the perimeter to external APIs
  • No access control over the knowledge base
  • The AI agent has excessive permissions
  • No logging of actions or data access
  • Unclear how to scale the model across GPUs

Services

  • AI Kubernetes Readiness Audit Infrastructure readiness audit before an LLM/RAG rollout.
  • LLM Productionization Moving a working prototype into production.
  • Secure RAG Deployment Knowledge base with roles, document filtering and query audit.
  • AI Agent Runtime Isolated environment for agents and control over available tools.
  • Container Security Integration Preparing the AI application for DevSecOps and Kaspersky Container Security.

How an engagement runs

01

Contour audit

Contour audit: infrastructure, data, model, agents — what exists and what is missing

02

Architecture

Architecture design: Kubernetes/OpenShift/DeckHouse, GPU nodes, namespaces, network

03

Containerization

Containerize LLM/RAG/agents, RBAC, secrets, logging, monitoring

04

Handover

Optional — prepare for Kaspersky Container Security integration and handover to the team

Typical architecture

  • Kubernetes / OpenShift / DeckHouse + GPU nodes
  • Namespaces, network, RBAC and secrets for LLM/RAG
  • Inference, agent orchestration, logging
  • Model-load monitoring and GPU cost control
  • Optional: prep for Kaspersky Container Security

How this connects to Kaspersky

We follow secure containerization practices and can account for integration requirements with Kaspersky Container Security — image scanning, policies and cluster runtime control. We design and deploy the AI layer; container security tooling is supplied and configured as a separate product via authorized distribution.

Impact

5 services

from K8s audit to Agent Runtime

on-prem

closed contour without external APIs

from 28 days

Secure Private AI Cloud pack

Price and conditions

Commercial terms for this service
Price 80 000 000 soʻmdan
Muddat 28 kun
Format Fixed estimate · remote delivery
Scope Secure AI: bulut yoki on-prem, NDA, rollar va monitoring.

Reviews from Yandex

Public feedback from Yandex Services — same performer profile as the feed.

“Невероятный специалист. Откликнулся сразу, на протяжении всего процесса был на связи, работа выполнена качественно в минимальные сроки.”

Евгения М.

Yandex · 25.07.2025

“Павел — ас своего дела! Всё на высшем уровне, всегда на связи, оперативно отвечал на вопросы. Чувствовалось, что ему важен результат.”

Ольга

Yandex · 20.10.2025

“Объёмно проконсультировал по кластеризации данных. Вопросов не осталось.”

Алексей Карманников

Yandex · 24.03.2024

“Отличный исполнитель, всё в срок, чётко и правильно. Всегда на связи, рекомендую!”

Терентьев Николай

Yandex · 05.12.2023

FAQ

Can LLM and RAG run in a closed contour with no internet access?
Yes. The model, RAG and agents deploy on-prem or in an isolated Kubernetes segment — no outbound calls to external APIs.
How is this different from a generic DevOps integrator?
We design and deploy the AI layer itself — LLM, RAG, agents — so it runs correctly on Kubernetes and is ready for security tooling integration. Kubernetes is infrastructure for a specific AI product here, not a standalone service.
Which GPUs and orchestrators do you support?
Kubernetes, OpenShift, DeckHouse; CPU and GPU inference, GPU sharing across workloads, autoscaling for peak model load.
What's included in the AI Kubernetes Readiness Audit?
A check of the cluster, network, access and data for production-readiness of LLM/RAG: bottlenecks, security risks, a scope estimate and a roadmap.
Can Kaspersky Container Security be added to an already running cluster?
Yes, via the separate Container Security Integration product — we prepare the cluster and the AI application for integration, and the security tool itself is supplied and configured via Kaspersky's authorized distribution.

Yoki ariza qoldiring

We move LLM, RAG and AI agents from prototype to production infrastructure: containerization, GPU, roles and access, logging, monitoring and integration with corporate systems.

Ism va aloqa — birinchi qadam uchun yetarli. Vazifa tavsifi ixtiyoriy.