Offline Installation
The offline installer is for air-gapped or restricted RHEL 9 environments with no outbound internet access on the target host. You download the Kamiwaza bundle on a connected machine, transfer it to the target host, and install without pulling anything from the internet during installation.
Supported host: RHEL-compatible 9.x (x86_64).
This is an advanced, operator-driven path. If your host has internet access, use the simpler Online Installation instead.
Prerequisites
-
A Kamiwaza Prod license key, used to download the bundle artifacts from Keygen.
-
A RHEL-compatible 9.x host (x86_64) that meets the System Requirements.
-
Free disk space, on the right filesystems. The offline flow stages large artifacts and provisions cluster storage under
/,/tmp, and/var/lib. Confirm each path has room on the volume that actually backs it — on hosts with LVM or separate partitions (most cloud RHEL images ship this way), a large total disk does not help if/varis a small separate volume. Recommended free space:/var/lib≥ 140 GB — the largest consumer. Holds the Rook/Ceph storage OSD image (80 GB by default, set viaKAMIWAZA_ROOK_OSD_IMAGE_SIZE), the container images under/var/lib/k0sand/var/lib/containers, and the extracted extension bundle staged under/var/lib/kajiya-reports./tmp≥ 25 GB — bundle extraction and install scratch space./≥ 30 GB — installed tooling under/optand/usr/local, plus general headroom.
A small default
/tmpor/varis the most common cause of install failure — the preflight aborts atstorage_host_prepif/var/libcannot fit the storage image. Grow the backing LV or partition (or mount adequate storage at/var/lib) before you begin. -
A machine with internet access to download the bundle, and a way to transfer files to the target host.
Throughout this guide, replace the placeholders:
<license-key>— your Kamiwaza Prod license key.<domain>— the base domain to serve Kamiwaza from (for examplekamiwaza.example.com).<admin-password>— the initial admin password.
Step 1: Download the Bundle Artifacts
The 1.0.1 offline bundle is published to Keygen as a set of split, checksummed artifacts. Download them (on a connected machine or on the host if it has temporary access), verify the checksums, and recombine the split parts.
The extension-bundle filename is release-specific. The value below matches the published 1.0.1 bundle; if release_origination.md lists a different name for your build, use that instead.
export KEYGEN_TOKEN="<license-key>"
export RELEASE="1.0.1"
export EXT_BUNDLE="kamiwaza-extensions-bundle-20260715-151239.tar.gz"
export BASE="https://raw.pkg.keygen.sh/kamiwaza/kamiwaza-prod/@bundles/${RELEASE}"
sudo install -d -m 0755 -o "$USER" -g "$USER" /opt/kamiwaza/prereqs
cd /opt/kamiwaza/prereqs
for file in \
release_origination.md \
kamiwaza-tools-rpm.pub.gpg \
kamiwaza-helm.sha256 \
kamiwaza-helm.asc \
kamiwaza-helm.00.tar.part-000 \
kamiwaza-helm.00.tar.part-000.sha256 \
kamiwaza-helm.00.tar.part-001 \
kamiwaza-helm.00.tar.part-001.sha256 \
kamiwaza-helm.00.tar.part-002 \
kamiwaza-helm.00.tar.part-002.sha256 \
kamiwaza-helm.00.tar.parts.json \
kamiwaza-prod-1.0.1-1.el9.x86_64.rpm \
"${EXT_BUNDLE}.sha256" \
"${EXT_BUNDLE}.part-000" \
"${EXT_BUNDLE}.part-000.sha256" \
"${EXT_BUNDLE}.part-001" \
"${EXT_BUNDLE}.part-001.sha256" \
"${EXT_BUNDLE}.part-002" \
"${EXT_BUNDLE}.part-002.sha256" \
"${EXT_BUNDLE}.part-003" \
"${EXT_BUNDLE}.part-003.sha256" \
"${EXT_BUNDLE}.parts.json"
do
# Always attempt a resume: curl --continue-at - fetches a fresh file or
# resumes a partial one, so rerunning the block after an interruption
# repairs truncated downloads instead of skipping them.
curl -fL --retry 5 --retry-delay 10 --retry-all-errors --continue-at - \
-H "Authorization: License ${KEYGEN_TOKEN}" \
-o "$file" \
"${BASE}/${file}"
done
# Verify part checksums
for checksum in \
kamiwaza-helm.00.tar.part-*.sha256 \
"${EXT_BUNDLE}".part-*.sha256
do
sha256sum -c "${checksum}"
done
# Recombine split parts and verify the full-artifact checksums
cat kamiwaza-helm.00.tar.part-{000..002} > kamiwaza-helm.00.tar
cat "${EXT_BUNDLE}".part-{000..003} > "${EXT_BUNDLE}"
ln -sf kamiwaza-helm.00.tar kamiwaza-helm.tar
sha256sum -c kamiwaza-helm.sha256
sha256sum -c "${EXT_BUNDLE}.sha256"
The release_origination.md artifact records the exact build provenance and image tags for this bundle. Refer to it if any of the version tags below differ from what shipped in your release.
If a download stalls, rerun the block —
curl --continue-at -resumes partial files. If you downloaded on a separate connected machine, transfer the entire/opt/kamiwaza/prereqsdirectory to the same path on the target host before continuing.
Step 2: Install Prerequisites
Install the prerequisites RPM and run the bootstrap script, which installs the container runtime, cluster tooling, and Ansible from the embedded artifacts:
cd /opt/kamiwaza/prereqs
sudo dnf install -y perl
sudo rpm -Uvh --replacepkgs ./kamiwaza-prod-*.x86_64.rpm
sudo /opt/kamiwaza/scripts/bootstrap-prereqs.sh \
--embedded-root /opt/kamiwaza/prereqs \
--os rhel
if [[ -x /usr/local/bin/kubectl ]]; then
sudo ln -sfn /usr/local/bin/kubectl /usr/bin/kubectl
fi
Verify the tools are present:
export HELM_PLUGINS="/usr/local/share/helm/plugins"
checks=(
"ansible::ansible-playbook --version | head -n1"
"podman::podman --version"
"kubectl::kubectl version --client"
"helm::helm version --short"
"helmfile::helmfile --version"
"helm diff::helm dt version"
)
for check in "${checks[@]}"; do
label="${check%%::*}"; command="${check#*::}"
if output="$(bash -o pipefail -c "${command}" 2>&1)"; then
result=GOOD
else
result=BAD
fi
output="$(printf '%s' "${output}" | tr '\n' ' ' | sed -E 's/[[:space:]]+/ /g; s/^ //; s/ $//')"
printf '[%-4s] %s: %s\n' "${result}" "${label}" "${output:-no output}"
done
If verification reports a missing tool, install it from the OS package manager and re-verify:
sudo dnf install -y ansible-core podman kubectl
Step 3: Create the Overrides File
Create the cluster overrides file with your domain. This is also where you add optional deployment customizations.
sudo install -d -m 0755 /opt/kamiwaza/cluster/values
sudo tee /opt/kamiwaza/cluster/values/overrides.yaml > /dev/null <<'EOF'
global:
domain: <domain>
EOF
Advanced deployments (for example, external S3-backed workroom storage or a classification banner) add further keys under
global:andcore:in this file. Those are optional and not required for a standard install.
Step 4: Pre-Extract the Extension Bundle
Stage the extension bundle before installing the platform:
cd /opt/kamiwaza/prereqs
EXT_BUNDLE="$(ls -1 kamiwaza-extensions-bundle-*.tar.gz | head -1)"
rm -rf /tmp/kamiwaza-ext-extract
mkdir -p /tmp/kamiwaza-ext-extract
tar -xzf "$EXT_BUNDLE" -C /tmp/kamiwaza-ext-extract
sudo /tmp/kamiwaza-ext-extract/kamiwaza-extensions-bundle-*/scripts/install-extensions-bundle.sh \
--bundle "/opt/kamiwaza/prereqs/${EXT_BUNDLE}" \
--sha256-file "/opt/kamiwaza/prereqs/${EXT_BUNDLE}.sha256" \
--extract-dir /var/lib/kajiya-reports/extensions-bundle-preinstall \
--skip-images \
--skip-catalog
Step 5: Install Kamiwaza
Set the image tags for the bundle and run the offline installer. The tag and image-override values below match the published 1.0.1 bundle; if release_origination.md lists different values for your build, use those instead.
export DOMAIN="<domain>"
export ADMIN_PASSWORD="<admin-password>"
export APP_TAG="release-1.0.1"
export FRONTEND_TAG="${APP_TAG}"
export CONTAINERS_TAG="release-1.0.1"
export EXTENSION_OPERATOR_TAG="release-1.0.1"
export KAMIWAZA_VERSION="${APP_TAG}"
export KAMIWAZA_IMAGE_TAG="${APP_TAG}"
export KAMIWAZA_K8S_RUNTIME="k0s-podman"
export KAMIWAZA_ROOK_OSD_IMAGE_SIZE=80G
export KAMIWAZA_RESOURCE_PROFILE=small
export HELMFILE_EXTRA_SET="--set global.security.allowInsecureImages=true"
export KAMIWAZA_OFFLINE_APP_IMAGE_TAG="${APP_TAG}"
export KAMIWAZA_OFFLINE_CORE_TAG="${APP_TAG}"
export KAMIWAZA_OFFLINE_FRONTEND_TAG="${FRONTEND_TAG}"
export KAMIWAZA_OFFLINE_INIT_KEYCLOAK_USERS_TAG="${APP_TAG}"
export KAMIWAZA_OFFLINE_CONTAINERS_IMAGE_TAG="${CONTAINERS_TAG}"
export KAMIWAZA_OFFLINE_CHAINGUARD_BASE_TAG="${CONTAINERS_TAG}"
export KAMIWAZA_IMAGE_OVERRIDES="keycloak=${CONTAINERS_TAG},postgres=v18.4,etcd=v3.6.10,kubectl=v1.35.5-dev,traefik=v3.6.20-kz.1,chainguard-base=${CONTAINERS_TAG},kafka-iamguarded=v4.3.0,neo4j=v5.26.25-kz.1,datahub-gms=${CONTAINERS_TAG},datahub-frontend=${CONTAINERS_TAG},datahub-upgrade=${CONTAINERS_TAG},datahub-postgres-setup=${CONTAINERS_TAG},vram-plugin=${APP_TAG},opensearch=v2.19.5,extension-operator=${EXTENSION_OPERATOR_TAG}"
sudo -E /opt/kamiwaza/scripts/install-prod.sh \
--offline \
--domain "${DOMAIN}" \
--admin-password "${ADMIN_PASSWORD}" \
--wrap-bundle '/opt/kamiwaza/prereqs/kamiwaza-helm.*.tar' \
--wrap-sha256 /opt/kamiwaza/prereqs/kamiwaza-helm.sha256 \
--wrap-signature /opt/kamiwaza/prereqs/kamiwaza-helm.asc \
--wrap-pubkey /opt/kamiwaza/prereqs/kamiwaza-tools-rpm.pub.gpg \
-e helm_timeout=12m \
-y
Step 6: Finish Extension Installation
Make sure ${DOMAIN} resolves from the install host, then install the extensions from the pre-staged bundle:
export DOMAIN="<domain>"
export ADMIN_PASSWORD="<admin-password>"
# Add a hosts-file entry if the domain does not already resolve locally
if ! curl -ksS "https://${DOMAIN}/api/health" >/dev/null; then
NODE_IP="$(sudo kubectl get nodes -o wide --no-headers | awk 'NR==1 {print $6}')"
echo "${NODE_IP:-127.0.0.1} ${DOMAIN}" | sudo tee -a /etc/hosts
fi
BUNDLE_ROOT="$(sudo find /var/lib/kajiya-reports/extensions-bundle-preinstall \
-maxdepth 1 -type d -name 'kamiwaza-extensions-bundle-*' | head -1)"
test -n "${BUNDLE_ROOT}" || { echo "No pre-extracted extension bundle found"; exit 1; }
printf '%s\n' "${ADMIN_PASSWORD}" | sudo "${BUNDLE_ROOT}/scripts/install-extensions-bundle.sh" \
--bundle-root "${BUNDLE_ROOT}" \
--container-cli podman \
--sudo-mode always \
--api-url "https://${DOMAIN}/api" \
--username admin \
--password-stdin
Step 7: Verify the Installation
sudo kubectl get pods -A
sudo kubectl get kamiwazaextensions -A
All pods should be Running, Ready, or Completed. On a fresh install kubectl get kamiwazaextensions -A reports No resources found — the extension templates are cataloged but none is deployed until you launch one, so this is expected. Then log in at https://<domain>/login with admin and the password you set. The installer serves the site with a self-signed certificate by default, so your browser will show a security warning on first access — continue past it to reach the login page.
Troubleshooting
- Output appears stalled during
bootstrap-prereqs.shorinstall-prod.sh. Thednf/rpmoutput can appear to hang while these scripts run. This is not a prompt waiting for input; if output appears stalled, press Enter several times until it resumes. - Disk pressure or staging failures. Confirm
/,/tmp, and/var/libeach have enough free space before installing (see Prerequisites).
Next Steps
- Quickstart — confirm the service is running and take your first steps.
- Uninstalling Kamiwaza.