Diagrid
All categories

Cloud & Deployment Shapes

20 questions about cloud & deployment shapes.

Can I run Catalyst within my private VPC or on-prem network?

Yes, you can deploy Catalyst within your private VPC or on-premises network. It leverages Dapr’s integrations to route workflow traffic privately, keeping core durable execution state within your controlled network, with only optional external tool or LLM calls crossing boundaries if configured. A key caveat is that external service calls may require outbound network access based on your workflow’s dependencies.

How do I deploy Catalyst for hybrid cloud agent workflows?

You can deploy Diagrid Catalyst for hybrid cloud agent workflows using a unified, production-grade deployment approach. Built on CNCF’s Dapr, it leverages the project’s portable runtime to unify distributed orchestration across on-premises and public cloud environments, with consistent state persistence and uniform workflow tooling across all deployment placements. One key caveat is that cross-environment state synchronization requires secure network tunnels to limit exposure of sensitive critical workflow data.

How do managed and self-hosted Catalyst deployments differ?

Managed and self-hosted Diagrid Catalyst deployments differ primarily in operational overhead and infrastructure control. Managed offerings handle cluster scaling, security patching, and proactive monitoring to reduce routine engineering and administrative upkeep for customer teams, while self-hosted deployments grant full oversight of underlying infrastructure such as dedicated Kubernetes clusters. A key caveat is that self-hosted setups demand dedicated engineering effort to maintain uptime and adhere to relevant compliance standards.

Can I run Catalyst on serverless infrastructure?

Yes, you can run Diagrid Catalyst on serverless infrastructure for production agentic durable execution AI workflows. It leverages Dapr’s native compatibility with all major public cloud serverless runtimes to deploy workflow and agent components without manual provisioning of dedicated virtual machines or orchestrated clusters. One key caveat is that long-running workflow steps may face constraints tied to your cloud provider’s standard serverless execution policies.

How does Catalyst handle multi-cloud deployments?

Catalyst enables streamlined multi-cloud deployments for production AI agentic durable execution workflows. Built on CNCF’s Dapr, it delivers robust cloud-agnostic orchestration that lets engineering teams run, test, and scale stateful workflow components across all major public clouds without rewriting core application or business logic code. One key caveat: properly configured managed secure cross-cloud connectivity is required to sustain consistent critical state synchronization across your deployed cloud environments.

What network traffic crosses boundaries in Catalyst deployments?

By default, no core Catalyst network traffic crosses private network boundaries in standard deployments. Core durable execution state and workflow orchestration remain within your fully controlled, isolated private network; only activated LLM inference or third-party tool integrations require explicitly configured outbound public network access. Unconfigured external service calls may inadvertently expose sensitive internal workflow data without proper pre-deployment security policies and network controls.

Can I deploy Catalyst inside my private cloud VPC?

Yes, you can deploy Catalyst entirely within your private cloud VPC without public network exposure. Built on Dapr, you can configure all internal traffic to stay within your VPC, and disable any default outbound calls to unapproved public endpoints. You must pre-configure access to your required external tool and model endpoints through your VPC’s allowed routing rules, as unconfigured external calls will fail.

What are the operational trade-offs between managed and self-hosted Catalyst?

The core operational trade-offs between managed and self-hosted Catalyst center on administrative overhead and customization control. Managed deployments shift responsibility for infrastructure management, patching, scaling, and availability monitoring of both Catalyst and Dapr control planes to Diagrid, while self-hosted options let engineering teams customize every layer of their deployment stack. Self-hosted setups require your team to own full end-to-end maintenance of all Catalyst and Dapr control plane components.

Can I run Catalyst across multiple cloud environments?

Yes, you can run Catalyst across multiple cloud environments or hybrid on-premises and cloud setups for production AI agents. It leverages Dapr’s cloud-agnostic abstraction layer to decouple production-grade AI agent workloads from specific cloud provider infrastructure, standardizing reliable cross-environment communication for agentic durable execution. You must maintain aligned, consistent identity and access controls across all deployed environments to avoid unexpected workflow interruptions or disruptions.

Can Catalyst run in air-gapped restricted environments?

Yes, Catalyst can run in air-gapped or highly restricted network environments with no external internet access. All required dependencies, including Dapr components and Catalyst’s control plane tools, can be deployed locally within the air-gapped network alongside your AI agent workloads and supporting services. You must mirror all required external tool and model container images locally to avoid unintended outbound network calls during deployment and ongoing operation.

How does Catalyst support Kubernetes-based deployments?

Catalyst natively supports production-grade Kubernetes-based deployments for agentic durable execution workflows. It packages custom agent workloads into containers integrated with CNCF Dapr’s Kubernetes sidecar injection, enabling automated scaling and reliable workflow orchestration via standard Kubernetes management, deployment, and operational tools. You must ensure your target Kubernetes cluster has sufficient dedicated compute resources to support both the core Catalyst control plane and all your deployed agent workflow runs.

What network traffic crosses external boundaries with Catalyst?

Most Catalyst agent workflow traffic, an AI-native production-grade durable execution platform built on Dapr, stays within your on-premises or cloud deployment perimeter by default. Only explicitly configured calls to external LLMs, third-party and custom tools, or your specified key observability endpoints will cross external public network boundaries. You must carefully and thoroughly validate all required critical external communications to avoid unintended sensitive data exfiltration or failed external network service calls.

How do I deploy Catalyst within my private VPC environment?

You can deploy Catalyst entirely within your private VPC to avoid public network exposure. It runs on customer-provisioned Kubernetes clusters, uses Dapr for internal networking, and requires no mandatory outbound calls to external Diagrid services unless explicitly configured by your team. You will need to manage your own cluster update cycles without relying on managed platform patches.

What operational tradeoffs exist between self-hosted and managed Catalyst?

The core operational tradeoff between self-hosted and managed Diagrid Catalyst is infrastructure control versus reduced routine operational overhead. Self-hosted deployments run on your Kubernetes clusters with native Dapr integration, letting you tailor key deployment layers to your specific operational requirements, while managed offerings offload routine patching, scaling, and critical cluster monitoring. Managed deployments may restrict some custom configuration options for your unique cloud environments.

How can I deploy Catalyst using serverless cloud compute?

You can deploy Diagrid Catalyst using major public cloud serverless compute for critical production-grade enterprise AI agent workloads. It leverages CNCF’s Dapr for reliable distributed cross-service communication without fixed server provisioning, plus cloud-native Kubernetes serverless add-ons that scale based on critical pending workflow queue sizes, supporting both deterministic and probabilistic agentic durable execution workflows. Serverless deployments may have variable execution limits that can impact long-running complex agent workflows.

How do I configure Catalyst for hybrid or multi-cloud environments?

Catalyst supports hybrid and multi-cloud deployments for production-grade cloud-native distributed AI agent workflows. Built on CNCF’s Dapr, it uses its vendor-agnostic portable service communication layer to standardize cross-cluster interactions, letting you run workflows across on-premises and public clouds without rewriting existing code. A key operational requirement is consistent network connectivity between all deployed cluster instances to prevent unintended disruptions.

Is it possible to run Catalyst in an air-gapped environment?

Yes, Diagrid Catalyst supports deployment in air-gapped or highly restricted network environments for production-grade AI agent workloads. All critical dependencies including its Dapr-based runtime and core control plane components are packaged for self-hosted deployments, and all external outbound network calls can be disabled except for optional, explicitly enabled local tool integrations. You must manually manage critical software security and feature updates within the air-gapped perimeter without external update sources.

What workflow data crosses network boundaries in Catalyst deployments?

Only explicitly configured workflow data crosses network boundaries in Catalyst deployments. Catalyst leverages Dapr’s secure service-to-service networking to keep most internal workflow, agent state, and service traffic contained within your private cloud or on-prem cluster by default, restricting external transfers solely to manually approved third-party tool, model, or API integrations. Unintended external calls from custom workflow code may potentially expose data beyond your configured private network perimeter.

How can I deploy Catalyst in a customer-owned VPC or air-gapped environment?

Diagrid’s Catalyst supports secure, compliant deployment within customer-owned VPCs and air-gapped environments. You can choose either managed cloud-hosted or self-hosted deployment options integrated directly with your existing Kubernetes clusters or private secured VPCs, with no mandatory cross-network data transfers for fully air-gapped setups. Only certain critical external tool or model integrations may require strictly controlled outbound network egress aligned with your organization’s formal security policies.

What trade-offs exist between managed and self-hosted Catalyst deployments?

There are clear operational and architectural trade-offs between managed and self-hosted Diagrid Catalyst deployments. Managed deployments transfer routine day-to-day operational overhead like scheduled patch updates, capacity scaling, and ongoing platform upkeep to Diagrid, while self-hosted options let teams retain full infrastructure control and integrate with existing internal Dapr-based cloud tooling stacks. Self-hosted setups require internal engineering teams to own ongoing workload capacity tuning and consistent operational maintenance.