Gatana logoGatana Docs

On-Premise & Self-Hosting

Instead of using Gatana Cloud, you can run the entire Gatana stack yourself

Self-hosting is available as part of the Enterprise plan. Please reach out to your account manager or send us an email at [email protected]

Helm Chart

Helm Chart soruce is available at https://github.com/gatana-ai/gatana-helm

helm install gatana oci://ghcr.io/gatana-ai/charts/gatana \
  --namespace gatana \
  -f values.yaml

Why Self-Host?

Self-hosting Gatana gives you complete control over the Gatana infrastructure. Gatana (the company) will never see any of your configuration or data. This is ideal for organizations with strict compliance requirements, data residency obligations, or those who prefer to keep all AI tool interactions within their own network.

Benefits

  • Data sovereignty — All data stays within your infrastructure, never leaving your network
  • Compliance — Meet regulatory and compliance requirements by controlling where data is processed and stored
  • Network isolation — Run MCP servers that access internal systems without exposing them to the internet

Trade-offs

  • No automatic updates — New features and security patches require manual upgrades
  • Infrastructure costs — You provision and pay for the compute, database, and networking resources

Configuration

The chart's values.yaml documents every setting. The choices that shape an install:

  • Object storage. Gatana needs two buckets, for uploaded files and for Runnable Code packages. storage.provider selects gcs (Google Cloud Storage, the default) or s3, which covers AWS S3 and S3-compatible stores such as MinIO or Ceph. For S3, set storage.s3.region, point storage.s3.endpoint at a compatible store (empty means AWS), and either name a credentials secret or rely on ambient credentials (IRSA, node role).
  • Encryption of stored secrets. kms.provider chooses what wraps the organization data keys: Google Cloud KMS, AWS KMS, or nothing. The default is none, which stores sensitive values protected only by disk encryption, so review this before production use. See Confidentiality for the table of values.
  • Persistent storage for servers. Persistent storage is offered only when workloads.storageClassName names a Kubernetes storage class fit for untrusted workloads. workloads.storageSize sets the size every volume gets. Left empty, the option stays hidden in the app.
  • Tailscale. Tailscale egress is offered only when workloads.tailscaleImage names the sidecar image, on a cluster whose admission policy lets a container hold NET_ADMIN. Left empty, the option stays hidden in the app.
  • Glama registry search. The Add Server registry search also shows remote servers listed on Glama when glama.apiKey (or glama.apiKeySecret) provides a Glama API key. Left empty, only the official MCP registry is searched.

Interested?

We would be happy to work with you, you can reach us at [email protected].

On this page