GDC Air-Gapped: How It Works, Use Cases, and Deployment

Introduction to GDC Air-Gapped

Google Distributed Cloud (GDC) air-gapped is a fully managed solution designed for organizations that require complete isolation to meet strict sovereignty and regulatory requirements. The solution we offer through Clarence is a unique initiative in Luxembourg and Europe. Initially based on Google Cloud technologies, it enables customers to confidently deploy sensitive applications containing critical data while providing next-generation digital sovereignty controls.

Unlike traditional hybrid cloud models that maintain a connection to a parent region, GDC air-gapped is a disconnected cloud that ensures customer separation and private access. Installed and managed locally, the solution provides all the necessary safeguards for data protection and represents the best compromise on the market between “strong sovereignty” and “access to the best of the cloud.” As a pioneer in the European market, the platform can deliver a public-cloud-like experience within an environment that is completely isolated from third parties, including Google. Such a configuration provides complete control over data location and access rights.

Architecture Overview and National Collaboration:

Hardware and Software Infrastructure: Google provides a hardware and software platform incorporating a range of features developed for its public cloud, but operating independently.

  • High-Security Hosting: LuxConnect provides a wide range of services, including its highly secure Tier IV data centers. These services ensure data residency in Luxembourg, as well as the resilience and redundancy of the platform.
  • Trusted Management: Proximus Luxembourg plays a crucial role in operational sovereignty. This means installing, maintaining, and controlling the environment, performing updates, providing customer support, and delivering a range of value-added services.

Public-sector use case: The Luxembourg Government IT Centre (CTIE) already uses this infrastructure to secure the nation’s most sensitive data while modernizing public administration.

See the official documentation for more technical details: https://cloud.google.com/distributed-cloud-air-gapped

 

What Is GDC Air-Gapped?

GDC air-gapped is a sovereign extension of Google Cloud that brings technological innovation into a physically isolated environment. Google Distributed Cloud enables public-sector organizations and regulated businesses to meet strict data residency and security requirements while delivering innovative solutions to their users.

Technically, it is based on the Kubernetes Resource Model (KRM), providing developers with a consistent experience and a broad range of managed services. In the public sector, this makes it possible to process national registries or national security data streams with extensive AI and analytics capabilities, without ever relying on a satellite or Internet connection.

 

What Is a GDC Appliance?

The GDC appliance is an integrated, portable, and rugged computing unit weighing approximately 45.3 kg (100 lbs). This “Cloud-in-a-Box” device is ideal for field environments and tactical operations centers (Edge AI). These solutions combine hardware and software to enable real-time data processing for use cases such as object detection, medical imaging analysis, or predictive maintenance of critical infrastructure.

Certified to MIL-STD-810H, the appliance is designed to withstand shocks, vibrations, and extreme temperatures (including tents and industrial sites). It incorporates three high-performance server blades, a Mellanox Top-of-Rack (ToR) switch, and its own local control plane, bringing Google’s cloud and AI capabilities to tactical edge environments where no connectivity is available.

 

Use Cases and Industries

A sovereign cloud is intended for customers whose data is highly critical and who want access to hyperscaler services while benefiting from the advantages of sovereignty. GDC air-gapped offers an attractive value proposition for businesses by aligning with the European drive toward digital independence and autonomy, while enabling them to retain control over data access and integrity.

  • Public Sector & Government: Strategic autonomy for e-government services and hosting of essential public services.
  • Healthcare: Local processing of genomic data and AI-assisted medical imaging analysis performed locally.
  • Defense: Tactical translation in the field and real-time offline video analysis.
  • Finance: Modernization of transaction infrastructures in full compliance with CSSF Circular 22/806.

 

Why Isolate a Cloud (Air-Gapping)?

Air-gapping means operating in a completely disconnected environment while still integrating Google’s AI capabilities for your sensitive data and workloads. The solution does not require any connection to Google Cloud or the public Internet to manage the infrastructure, services, APIs, or tools, and is designed to remain permanently disconnected.

This complete autonomy provides innovative capabilities that were previously available only in a public cloud. It ensures the confidentiality and security of information while providing full operational autonomy. For Luxembourg banks, this physical isolation is the ultimate technical response to the requirement for independence from foreign jurisdictions, thereby securing critical functions in line with CSSF audit requirements.

Digital Sovereignty and Data Localization

Clarence is THE European benchmark for sovereign cloud, operating entirely under European jurisdictions for the control, security, and comprehensive management of our data-related risks. This disconnected sovereign cloud solution leverages the cutting-edge expertise of third-country technologies while keeping them confined within the national territory.

Sovereignty at Clarence is built around three key pillars:

  1. Data Sovereignty: Physical data localization in LuxConnect’s Tier IV data centers in Luxembourg, ensuring that data never leaves the country.
  2. Technological Sovereignty: Use of an open ecosystem based on the Kubernetes API and leading open-source components, facilitating rapid adoption by developers without dependence on proprietary systems.
  3. Operational Sovereignty: Operations managed by Proximus Luxembourg, with the ability to customize certain elements, such as the nationality or security clearances of authorized operators permitted to intervene on site.

 

GDC Air-Gapped Technical Architecture

Google Distributed Cloud is a fully managed solution combining software and hardware infrastructure, designed for data centers and edge environments to meet regulatory requirements and address the need for local data processing, resilience, and low latency.

 

Rôle de Kubernetes dans GDC air-gapped

GDC air-gapped is part of Google Cloud’s open cloud strategy and relies entirely on the Kubernetes API. Kubernetes (via GKE on GDC) orchestrates containers, manages application self-healing, and ensures the fair distribution of local resources. The use of open technologies enables organizations to leverage their existing DevOps skills and tools, facilitating application portability to and from other cloud environments. For stateful services such as SQL or NoSQL databases (PostgreSQL, AlloyDB Omni), Kubernetes automates storage provisioning and high availability without any external connection.

 

Components of a GDC Appliance

The solution offers a high degree of flexibility in terms of hardware infrastructure, including both general-purpose computing resources and GPUs.  

  • Flexible Hardware Options: Customers can start with a minimal configuration (an appliance or a few racks) and scale up to hundreds of racks according to their needs.
  • Hardware Appliance: A compact chassis containing three compute blades (x86-64 v3 CPUs), a redundant Mellanox network switch, and high-speed ports (10/25 GbE).
  • Cutting-Edge AI Capabilities: Gemini is now available on GDC. Gemini’s advanced reasoning and state-of-the-art generative capabilities on GDC unlock key generative AI use cases, including automation, content generation, research, and summarization in on-premises environments.

 

Deployment and Prerequisites

The deployment of GDC air-gapped with Clarence follows a rigorous engineering process designed to ensure optimal performance and security from day one.

Hardware, Storage, and Network Configuration

A minimum production configuration generally requires four racks (three for compute/storage and one for operational tools).

  • Hybrid Storage: Use of all-flash (SSD) solutions for high-performance block storage and S3-compatible object storage for large-scale volumes and archives.
  • Network Segmentation: Clarence configures isolated VLANs for management (iLO/Mgmt on VLAN 501) and data (VLAN 100). Strict access control lists (ACLs) prevent any traffic leakage between tenants.
  • Configurable Operations: While the underlying technology is identical across each deployment, the operational model can be tailored to the specific needs of each customer.
 

Step-by-Step Installation Procedure

  1. Site Survey (15 days): Validation of the data center space, HVAC cooling systems, and electrical power capacity.

    1. Design Generation: Google and Clarence create a customized solution design based on your compute and AI requirements.
    2. Delivery and Racking: Physical installation of certified hardware within secure facilities.
    3. Software Initialization: Deployment of the hardened Rocky Linux operating system (FIPS 140-2 certified) and configuration of the zonal control plane via the gdcloud CLI.

Project Configuration: Creation of namespaces and allocation of resource quotas.

  1. Typical Timeline: The process from initial assessment to go-live generally takes 30 to 60 days.
  2. Design Generation: Google and Clarence create a customized solution design based on your compute and AI requirements.
  3. Delivery and Racking: Physical installation of certified hardware within secure facilities.
  4. Software Initialization: Deployment of the hardened Rocky Linux operating system (FIPS 140-2 certified) and configuration of the zonal control plane via the gdcloud CLI.

    Project Configuration: Creation of namespaces and allocation of resource quotas.

  5. Typical Timeline: The process from initial assessment to go-live generally takes 30 to 60 days.

 

Security, Compliance, and Operations

Compliance with the Most Stringent Standards: GDC air-gapped provides robust support for meeting strict security and regulatory requirements. It meets the technical requirements of standards such as ISO 27001/27017, SOC 2, ISMAP, NIST, NATO D48, and many others.

Intrusion Detection and Update Management

Security is based on a Zero Trust model in which every access request is continuously verified. The system natively integrates IDS/IPS solutions that use machine learning to block unauthorized access attempts.

Updates are managed without an Internet connection through a signed package workflow:

  • Software bundles are downloaded to a secure external staging workstation.
  • Each package is validated using a cryptographic signature and SHA-256 checksum.
  • The transfer is carried out via a secure physical medium (hardened USB drive), ensuring that no malicious code enters the environment.

Backup, Disaster Recovery, and Audits

The Backup4GDC service protects entire clusters, virtual machines, and databases through incremental backups stored either on-site or at a second remote site (LuxConnect) for disaster recovery. This isolation simplifies audits, as the entire hardware and software chain can be physically verified in Luxembourg, eliminating the uncertainties associated with traditional cloud outsourcing.

 

Costs, Providers, and Alternatives

The air-gapped offering is built on a highly available, fully redundant architecture designed for mission-critical systems, making it a robust alternative to traditional infrastructures.

GDC Air-Gapped vs. Other Solutions (Bare Metal / DIY) Comparison

Criteria

GDC Air-Gapped (Clarence)

Traditional Bare Metal (On-premise)

Cloud Services

Native Gemini, Vertex AI, and GKE

Must be installed and maintained manually

Sovereignty

Certifiée Air-Gapped et Air-gapped certified and locally managed

Varies depending on internal governance

Operations

Managed by experts (Clarence/Proximus)

Full responsibility rests with the internal IT team

Innovation Speed

Regular updates via the marketplace

Very slow (heavy maintenance burden)

By choosing Clarence, customers benefit from a consistent developer experience and a broad range of managed services, without the hidden costs and operational complexity of a “DIY” deployment on bare-metal servers.

Indicative Pricing and Licensing Models

The cost structure is based on a committed capacity model (servers, racks, and storage) with long-term contracts (36 or 60 months), ensuring full budget predictability.

  • Integrated Marketplace: GDC enables the integration of a catalog of applications from independent software vendors (ISVs) through a certified marketplace.
  • BYOL Model: For third-party software (MongoDB, Elastic, GitLab), the platform supports the Bring Your Own License model, allowing you to reuse your existing software investments within the isolated environment.

Training, Certifications, and Documentation

Google and Clarence offer the GDC Air-Gapped Practitioner Fundamentals training program. This certification course (available through edX or via partners) prepares administrators and DevOps engineers to master the architecture, service configuration, and advanced operations of disconnected AI environments in approximately 12 hours.

FAQ: Frequently Asked Questions About GDC Air-Gapped

What Is GDC Air-Gapped?

It is a sovereign instance of Google Cloud, completely isolated from the Internet, installed and managed in Luxembourg by Clarence.

 

A hardened, portable server (MIL-STD-810H) that brings AI and computing capabilities anywhere, even into the field.

Offline visual and audio translation, AI-assisted video analysis, and generative search (Gemma 7B) on local data.

Through the secure transfer of digitally signed packages via a secure staging workstation and physical media.