ReferencePlatform prerequisites
What needs to exist before install day. These are the same in all four deployment models, and every one of them is standard platform infrastructure rather than something DocxIntel invents.
Orchestration and runtime
- Kubernetes
- v1.28 to v1.32, with containerd 1.7+. Tested on vanilla Kubernetes, OpenShift 4.14+, EKS, AKS and RKE2
- Helm
- v3.14 or later. The chart is delivered in the bundle and installs as a single release
- Single-node alternative
- Docker Engine 24.0+ with Compose v2.24+, for evaluation sandboxes and small production sites
- Host operating system
- RHEL 8.8+ or 9.2+, Rocky Linux 9, Ubuntu 22.04 or 24.04 LTS, SLES 15 SP5. x86_64 only
- Container registry
- Any OCI-compliant internal registry — Harbor, Artifactory, ECR, ACR, Quay — reachable from every node
Compute and GPU
- GPU class
- NVIDIA L40S 48 GB is the reference worker. A100 80 GB, H100 80 GB, L4 24 GB and RTX 6000 Ada are all supported
- Minimum GPU count
- One GPU for a sandbox or small site; two or more for production, so a node can be drained without stopping intake
- Driver and toolkit
- NVIDIA driver 550 or later, CUDA 12.4 runtime, NVIDIA Container Toolkit 1.15+, GPU Operator 24.x on Kubernetes
- CPU and memory per GPU node
- 16 vCPU and 128 GB RAM per GPU as a baseline — page normalisation and PDF rendering are CPU-bound, not GPU-bound
- Control-plane nodes
- Three CPU-only nodes at 8 vCPU and 32 GB each for a highly available cluster; one node is sufficient for evaluation
Storage
- Local scratch
- NVMe SSD, 2 TB per GPU node, for page render cache and model weights. Weights alone occupy roughly 46 GB
- Block storage
- A CSI storage class supporting ReadWriteOnce, 500 GB minimum for PostgreSQL, with snapshot support preferred
- Object storage
- Any S3-compatible endpoint — MinIO, Ceph RGW, NetApp StorageGRID, Dell ECS, AWS S3 or Azure Blob via the S3 gateway
- Capacity planning
- Roughly 30 GB of DocxIntel-owned storage per 100,000 pages at steady state — see sizing and throughput
Network and ingress
- Ingress
- NGINX Ingress 1.10+, HAProxy, F5 or any L7 load balancer you already operate. TLS 1.2 and 1.3, your certificates
- Inbound ports
- TCP 443 to the gateway and console. No other inbound port is required from outside the cluster
- Outbound requirements
- None. The platform never initiates an external connection in any deployment model
- DNS and certificates
- Two internal DNS names — API and console — resolvable inside your zones, with certificates from your own CA
Identity and integration
- Single sign-on
- OIDC (Entra ID, Keycloak, Okta, Ping) or SAML 2.0. Group claims map to DocxIntel roles without manual sync
- Provisioning
- SCIM 2.0 for automated user and group lifecycle, optional. Local accounts are available for break-glass only
- Key management
- KMIP 1.4+, PKCS#11 HSM, AWS KMS, Azure Key Vault or HashiCorp Vault. Keys never leave your custody
- Observability
- Prometheus scrape on 9090, OpenTelemetry OTLP export on 4317, structured JSON logs to your existing collector
- Database
- PostgreSQL 15 or 16 with the pgvector extension. Ships in the bundle, or point at your own managed instance
Exact figures for your environment are confirmed against your document mix and volume during the architecture review, and again on your own hardware during the Proof of Value. Installation reference material is maintained in the product documentation.