Skip to main content
Chart defaults ship as a sensible starting point for evaluation and typical production traffic. They are not a hard ceiling. Right-size and fine-tune CPU, memory, replicas, and node pools to match your traffic, latency goals, and budget. The shapes below reflect the maintained neuraltrust-platform chart defaults (in-cluster PostgreSQL and Redis; Firewall CPU workers when TrustGuard is on). They do not include the node OS, kube-system, or your ingress controller — leave headroom for those. Hybrid with fewer products (for example TrustGate only, without Firewall) needs substantially less memory — Firewall CPU workers are the largest consumers. External adds the product console, ClickHouse, ClickStack collector, DataCore, and AlertEngine on top of the data path. See External (self-hosted).

What drives capacity

GPU Firewall workers need a separate GPU pool — see Firewall → GPU workers.

Tuning for your needs

Defaults are intentionally conservative and portable. Common adjustments:
  • Scale out busy gateways and TrustGuard replicas as traffic grows, or turn on horizontal autoscaling when your cluster has metrics.
  • Right-size Firewall workers if you run a subset of detectors, or move heavy workers to GPU.
  • Use managed PostgreSQL and Redis so datastore capacity is independent of the Kubernetes node pool.
  • Pin workloads to a dedicated pool when you want isolation from other cluster tenants.
There is no single “correct” size — start from the defaults, measure under your workload, then tune.