Deploy MigryX with a single command — Docker, Kubernetes, OpenShift, or a Windows VM. Air-gapped capable. No outbound connections. Your source code and data never leave your environment.
Security Posture
MigryX is built for regulated environments. Every component runs inside your perimeter with no external dependencies.
Fully disconnected deployment supported. No internet access required during analysis, conversion, execution, or validation.
Zero external API calls. Zero telemetry. Zero phoning home. Every byte stays on your infrastructure.
All processing — parsing, conversion, validation, and AI augmentation — executes inside a single container on your host.
TLS encryption for VS Code, Jupyter, the nginx proxy, and the backend API. Use your own certificates.
Project metadata and audit logs stored in a local PostgreSQL instance. No external database connections. All data on local disk.
Docker Deployment
Deploy MigryX on any Linux host, on-premises or in your private cloud. Docker, Podman, or OpenShift — all OCI-compatible runtimes supported.
| Service | Port |
|---|---|
| VS Code Server | 1443 |
| nginx Proxy (HTTPS UI) | 3174 |
| Backend API | 3177 |
| PostgreSQL | 5432 |
| Jupyter Notebook | 8080 |
| Merlin Conversion Engine | 8000 |
Map to host ports as needed. Keep access restricted to your internal network.
Workspace, SSL certificates, and PostgreSQL data can be persisted with Docker volume mounts.
Prefer Windows? Install MigryX on a Windows VM with the same hardware profile. All services — backend, Jupyter, VS Code, PostgreSQL — run locally as Windows processes. No Docker required.
Cloud Deployment
Deploy MigryX on any major cloud provider inside your own VPC. Same container, same air-gapped posture, same zero-egress guarantee.
VPC • PrivateLink • S3 • ECR • KMS • CloudWatch • IAM • Security Groups
VNet • Private Endpoints • ADLS • ACR • Key Vault • Log Analytics • AAD • NSGs
VPC • Private Service Connect • GCS • Artifact Registry • Cloud KMS • Cloud Logging • IAM
Architecture Overview
Three pillars that make MigryX deployment-ready for any environment — from a single Docker host to a multi-region Kubernetes cluster.
Single-container architecture with all services bundled. Docker, Podman, Kubernetes, OpenShift, or bare Windows VM. One-command install, air-gapped capable, with no external runtime dependencies.
Ingest from any legacy platform — SAS, Talend, Alteryx, DataStage, Informatica, ODI, SSIS, COBOL, Teradata, Oracle PL/SQL, and SQL dialects. Output to Databricks, Snowflake, BigQuery, PySpark, Polars, Fabric, dbt, and Python.
Local PostgreSQL for project metadata, lineage graphs, and audit logs. Workspace files on the container filesystem with optional volume mounts for persistence. No external database dependencies.
Security & Compliance
MigryX meets the security and compliance requirements of financial services, healthcare, government, and defense organizations.
All source code, converted output, lineage data, and metadata remain in your chosen environment — on-premises data center or private cloud region. No cross-border data movement.
SSO integration with LDAP, Okta, and SAML. Role-based access control for project-level permissions. Multi-factor authentication supported.
Complete audit trail for every conversion — who ran what, when, with which parameters, and what the output was. Logs stored locally in PostgreSQL and on disk.
Column-level lineage, STTM mappings, data classification tags, and validation reports provide audit-ready evidence for SOX, GDPR, BCBS 239, and HIPAA.
PostgreSQL and workspace data can be backed up with standard tooling — pg_dump, volume snapshots, or your existing enterprise backup solution.
Each MigryX instance is fully isolated. No shared tenancy, no shared databases, no shared storage. Container-level network policies prevent lateral movement.
See MigryX running in your environment. Book a 30-minute demo or reach out to discuss your deployment requirements.