Deployment Architecture
GuideDeploy RADAR self-hosted beside your existing agent stack. Evidence stays in your infrastructure — VPC, on-prem, or air-gapped.
System Model#
Sidecar
RADAR runs beside your LLM gateway and tool infrastructure. It observes without intercepting the execution path.
Your Infrastructure
All evidence — traces, findings, exports — stays inside your VPC, on-prem environment, or air-gapped network.
No Execution Ownership
RADAR does not run your agents, orchestrate workflows, or replace your existing stack. It monitors and records.
Docker Compose#
Recommended for evaluation and mid-scale production deployments. RADAR runs as a single service with local volume storage.
Volumes
- •
radar-data: evidence storage - •
/data: trace, finding, export persistence
Environment
- •
RADAR_LICENSE_KEY: your evaluation license - •
RADAR_RETENTION_DAYS: evidence retention period
Kubernetes#
For enterprise deployments requiring auto-scaling, rolling updates, and service mesh integration.
Kubernetes considerations
Use persistent volumes for evidence retention. For air-gapped environments, ensure the image is available in your private registry. RADAR does not require external network access after deployment.
Air-Gapped Deployment#
RADAR is designed for zero-trust and air-gapped environments. No external API calls, no telemetry, no cloud dependencies.
No Egress Required
RADAR does not phone home. All evidence processing, retention, and export is local.
Offline License Validation
License keys are validated at startup with optional offline activation for air-gapped networks.
Local Storage Only
All traces, findings, and exports reside on local or networked storage inside your security perimeter.
Evidence Retention#
Configure how long RADAR retains traces, findings, and export history. Retention is enforced at the storage layer and can be customized per environment.