Data Locality
Gallium holds no copy of the data inside your virtual machines. It holds the metadata that describes your infrastructure, the audit logs of what was done to it, and any templates you store. For how the Gallium Console and the Gallium Hypervisor relate, see the Architecture Overview.
What the Gallium Cloud Holds
The cloud holds the records that describe and govern your infrastructure, not its contents.
| Data | Includes |
|---|---|
| Infrastructure metadata | Names, descriptions, and specifications for virtual machines, hypervisors, clusters, and deployments, plus status, hardware inventory, capacity, OS version, network addresses, and network and storage configuration |
| Identity and access | Organizations, users, roles, authentication and MFA, single sign-on configuration, and SSH public keys |
| Audit and activity logs | The record of actions taken against your infrastructure, including support access activity |
| Telemetry | Health data for the hypervisor and its local control plane, used to keep the deployment running |
| Metrics (Edge only) | Virtual machine, system, and network performance numbers, stored as time series |
| Alerting | Alert profiles, alert rules, and incident history |
| Templates | Virtual machine and tool templates, the one kind of content Gallium stores for you, held in the region you choose |
| Backup schedules and status | When a backup runs and whether it succeeded, never its contents |
What Stays on Your Hypervisor
Everything your workloads produce and consume stays on hardware you control.
| Data | Notes |
|---|---|
| Virtual disk contents | Everything written inside your virtual machines, never copied to the cloud |
| Memory and running state | Present only on the hypervisor |
| Guest operating systems and applications | Including anything installed in the guest |
| Cloud-init and Windows configuration drive data | Encrypted in transit and stored only on the hypervisor |
| Storage Pool data | On your local disks |
| Metrics (Cluster and Standalone) | Virtual machine, system, and network performance numbers, stored on the deployment |
| Backup data | Written to a backup target you control |
| Files moved with the File Transfer Manager | Transferred peer-to-peer between your browser and the hypervisor |
What Passes Through the Cloud but Is Not Stored
When you open a virtual machine’s console, the screen output and your keystrokes are relayed through Gallium in real time, using single-use, short-lived tokens. The session passes through so you can interact with the machine. It is not recorded.