Skip to main content
Every Private Cloud cluster is delivered with a handover document specific to your deployment. This page describes what we check before handover and what the document contains, so you know what to expect and what to verify on first login.

Before handover

A cluster is not delivered until it has passed:
  1. Acceptance certification. A benchmark run across the delivered nodes — GPU health, NCCL collectives (all-reduce, reduce-scatter, all-gather), per-rail and pairwise fabric bandwidth, and correctness — scored against pass thresholds. The certification run ID and score are recorded in your document.
  2. Hardening validation. The effective SSH daemon configuration is audited (sshd -T) for public-key-only authentication; a password-only login attempt must fail with Permission denied (publickey); default accounts are confirmed locked; the firewall or security-group policy is reviewed against the intended exposure.
  3. Account cleanup. Provisioning, installer, and partner accounts are removed. Your user and public key are installed; the sudo decision (passwordless or not) is recorded.
  4. Data sanitization. Drives that have been used before are block-erased at the hardware level and fresh filesystems created. Nothing from a previous tenant is copied forward.
  5. Runtime checks. Docker and the NVIDIA Container Toolkit are verified on every node with a disposable GPU container that must see all GPUs; the test containers and images are removed afterwards.
  6. Cleanup. Benchmark containers, temporary files, and benchmarking artifacts are removed. No benchmark jobs are left running at handover unless coordinated with you.
  7. Baseline capture. OS, kernel, driver, container runtime, and RDMA port state are recorded per node.
When nodes are added to an existing cluster, the additions get access, runtime, and sanitization checks and a fresh baseline. The original certification is not automatically extended to the combined cluster — ask for a re-certification if you want a benchmark that covers the new topology.

What the handover document contains

First login

Run these on each node and compare with your document:
Then confirm GPU access from a container:
Anything that doesn’t match the document — a missing mount, a port not active, a GPU not enumerated — goes to support with the node’s short name and the command output.