NexusClaw
NexusClawEnterprise Applications & Digital Employee Platform
← All capabilities

Deployment / Data & Model Boundary

Deployment is not a configuration list.It is a choice of data, model, and ownership boundaries.

NexusClaw supports managed SaaS, hybrid, and private deployment. All three run the same governance chain, but business data location, model inference, and infrastructure ownership differ.

Choose the boundary before sizing. Every resource figure on this page belongs only to its named topology—build memory, model VRAM, and another deployment shape are not interchangeable.

System architecture · NexusClaw blueprintNexusClaw System Evidence
NexusClaw system architecture and three deployment shapes
The same core runtime supports managed SaaS, hybrid, and single-host full stack; topology changes data, model, and operations ownership.

01 / Topology Choice

Three shapes solve different boundaries, not three pricing tiers

Governance, audit, and Agent runtime remain consistent. Infrastructure ownership, data residency, and inference location change.

01

Managed SaaS

Platform-managed application with cloud models

Available

For teams that want rapid launch, managed database and cache, and cloud model APIs. The application node needs no GPU.

Users
NexusClaw
Cloud
RDS · Redis · OSS
Cloud Model API
  • Unified HTTPS entry
  • Managed RDS / Redis / OSS
  • Local model explicitly disabled
02

Hybrid

Cloud business system + customer AI PC

Available

Enterprise applications and governance stay in the cloud while local inference runs on a customer AI PC through a customer-initiated tunnel.

Cloud
Control Plane
outbound
Customer AI PC
Local Model · GPU
  • Model weights remain on AI PC
  • Cloud does not load the local model
  • Inference path accepted separately
03

Private / single-host

Application, data, and optional local model in customer environment

Available

For customer-owned network and infrastructure boundaries. Sizing depends on data, concurrency, and the selected local model.

Customer environment

Web · API
Postgres · Redis
Object Storage
Optional Local Model
  • Runs inside customer environment
  • Connect customer database and storage
  • Model determines added resources

02 / Data & Model Boundary

Hybrid keeps the business control plane in cloud and model weight on the customer side

The cloud node runs Web, API, mobile, data services, and tunnel service. The AI PC carries the local model and GPU. The customer side initiates the tunnel, so the AI PC need not be publicly exposed.

Cloud business & governance plane

Web · Mobile
Backend API
PostgreSQL
Redis · Files
Audit · Trace
FRP Server

LOCAL_MOE_ENABLED = false

⇄controlled tunnel

Customer AI PC model plane

Local Model Endpoint
Model Weights · GPU
Health · Timeout · Logs

Customer-initiated · no public AI PC exposure

Business data

Resides in cloud data services or the customer environment by project contract; model context remains permissioned and audited.

Model weights

Local model files and GPU remain on the customer AI PC and are not copied to the cloud application node.

Inference failure

Health and timeouts must be monitored. Any provider failover follows explicit routing policy—not a silent promise.

03 / Release & Operations

“Containers are running” is not a complete go-live

Production release starts with an exact commit and immutable image, then database migration, same-version service cutover, strict health checks, and permission smoke tests. Failures roll back at behavior, code, or data level.

01

Pin the version

Record commit SHA, image digest, and configuration version.

02

Run migration

Bind migration to the application version and preserve results.

03

Cut over together

Backend, Web, and Mobile use the same version.

04

Verify health

Strict health, permission, and critical-record smoke checks pass.

05

Keep rollback ready

Feature flags, prior images, and database recovery paths stay explicit.

Product UI · Deployment ManagementNexusClaw System Evidence
NexusClaw Deployment Management product interface
The product deployment surface promotes metadata and configuration between environments; infrastructure release still follows version, migration, health, and rollback controls.
release-evidence.log
commita1b2c3d · exact source
imagesbackend · web · mobile / same version
migrationcompleted · evidence retained
healthstrict / passed
permissionssmoke / passed
rollbackflag · image · PITR / ready

04 / Sizing & Responsibility

Every capacity figure must name its topology

These are starting points for controlled trials and verified shapes, not topology-free promises. Formal projects validate capacity after the shape is selected.

Managed SaaS · controlled trial

4 vCPU / 8 GiB app ECS

Managed database, cache, and object storage; cloud inference; starting point for ≤20 invited users and 3–5 concurrent AI tasks.

Managed SaaS · recommended

8 vCPU / 16 GiB app ECS

More headroom for pre-production operation, still using managed data services and cloud models.

Hybrid · cloud node

About 3–4 GiB total

Backend about 1.5–2 GiB; no local model in cloud. The AI PC carries model memory and GPU.

Private / single-host

Size by model and concurrency

Application, database, and local model may share a host; hybrid cloud-node figures do not apply.

Write these into the project boundary table

01Domain, certificate, and entry
02Database, cache, and backup
03Object storage and secrets
04Model provider and cost
05Tunnel and network path
06Monitoring, upgrade, and rollback owner

Acceptance goes beyond opening the page

Boundary test

Confirm the actual location of business data, logs, model weights, and secrets.

Failure test

Disconnect model endpoint or cache and verify health, alerts, and recovery.

Upgrade test

Migrate, cut over, smoke test, and return to a prior version.

Audit test

Return from one Agent outcome to execution, tools, approval, and owner evidence.

Current capability boundary

A deployment shape is not a compliance certification and does not define your data-residency policy. Hardware, cloud resources, model licenses, network conditions, and backup ownership belong in project scope; private sizing is accepted against the chosen model, data volume, and concurrency.

Bring your data boundary, model choice, and target concurrency

We will lock the topology first, map data and model boundaries, then provide topology-specific sizing, go-live evidence, and rollback acceptance.