C-DAC
Meghdoot Sovereign Stack
A pitch for C-DAC Chennai · Version 1.0
Eighty-four services across the four EOI domains
An Academia-Led Submission to C-DAC Chennai · 2026

Meghdoot is here. The service layer isn't.

We propose to build it. One hundred and twenty-three named services across the four domains the Expression of Interest specifies — reaching ninety-three percent baseline parity with Amazon, Microsoft and Google while preserving the twenty-three sovereign moats no hyperscaler can structurally replicate. Every service bills in rupees through the Unified Payments Interface, speaks the twenty-two scheduled Indian languages through Bhashini, and signs its compliance evidence under the Controller of Certifying Authorities. The existing BOSS Linux, OpenStack, Ceph, KVM and Kubernetes substrate stays exactly as it is today.

Proposed by Chennai Institute of Technology
For Centre for Development of Advanced Computing — Chennai
Engagement Period
Three plus two years
Co-Development
Academia + C-DAC + Industry
Lead Researchers
Nine senior professors
Domains Covered
All four · No gaps
MSS
Eight layers
Compute · 30 services
Artificial Intelligence · 30 services
Data and Analytics · 29 services
Migration · 19 services
Integration Layer · 9 buses
User Experience · 7 surfaces
Chapter One · The Problem

Where the foreign clouds run out of road

Twenty-four gaps that AWS, Azure, GCP, Snowflake and Databricks leave open in India — spanning technological architecture (cold-start latency, CXL, sovereign silicon, confidential TEE root), AI & data (Indic LLMs, agent tool catalogues, residency-aware lakehouse), regulatory primitives (DPDP, RBI, CERT-In, Z3 proofs), Indian DPI (UPI, ONDC, Aadhaar, GSTN), language, and edge geography. The architecture in the slides that follow closes every one of them.

24
capability gaps · 7 dimensions
Chapter Two · The Scale

From eighty-four to one hundred and twenty-three

We started with four hundred and twenty-eight unique selling propositions across twenty-four research reports, synthesised them to eighty-four canonical services, then ran a baseline-cloud completeness check against AWS, Azure and GCP. Thirty-nine additional services were added to close the managed-PaaS gap (managed Kubernetes, RDB, NoSQL, cache, time-series, graph, search, queue, ETL, CDN, BMaaS, MLOps studio, vector DB, agentic runtime, code assistant, confidential GPU, physical data transport, parallel-run, live DB bridge, TCO calculator and more). The catalogue is now one hundred and twenty-three services at ninety-three percent hyperscaler parity, with all twenty-three sovereign moats preserved.

Chapter Two-and-a-Half · The Framework

Four phases, one discipline

The catalogue does not land all at once. It compounds, the way every hyperscaler grew — IaaS primitives first, managed PaaS second, intelligent automation third, sovereign innovation last. Each phase makes the next one possible; nothing in P3 ships without the P1 substrate underneath. This is what the next twenty slides are organised around.

P1—P4
capability maturity
Chapter Three · The Architecture

Where the new work fits

Four new layers stack on top of the Meghdoot foundation. The BOSS Linux host, the OpenStack control plane, the Ceph storage layer, the KVM hypervisor and the Kubernetes orchestration all stay exactly as they are operating today at C-DAC. Click any layer below to see what it contains.

Chapter Four · The Four Domains

The four domains your EOI calls out

Compute, Artificial Intelligence, Data and Analytics, and Migration. Each domain is led by a named senior researcher with the PhD-plus-three-years background the EOI asks for. Crucially, all four domains share the same nine integration buses for consent, identity, billing, language and the rest. That shared bus layer is what makes this one architecture rather than four products glued together at the edges.

Compute · 30 Services · AWS · Azure · GCP equivalents tagged

Compute, end to end

From foundational primitives to hyperscaler-grade innovation: managed Kubernetes (Megh-K8s, peer to EKS / AKS / GKE), serverless containers (Vaayu-Run, peer to Fargate / Container Apps / Cloud Run), bare-metal as a service (Loha, peer to Outposts / BareMetal Infra / Bare Metal Solution), HPC (Yagna), hybrid DC racks (Setu-Sthapana), sovereign CDN with BharatNet PoPs (Tarang-CDN), service mesh (Jaal), DNS (Naam), WAF (Suraksha), and the original snapshot-FaaS / CXL / harvest / confidential VM differentiators that hyperscalers cannot copy.

30
compute services
18 services
Compute · Phased Rollout

Compute, phase by phase

P1 lays the IaaS substrate the rest of the platform stands on. P2 turns it into a managed-PaaS surface tenants can self-serve. P3 makes it intelligent — autoscaling that learns, hybrid clusters that federate. P4 is where the sovereign frontier opens — confidential GPU, edge security at every PoP, the things no foreign cloud will ship from Indian soil.

30
services across 4 phases
Artificial Intelligence · 30 Services · with hyperscaler peers

Sovereign AI, from notebooks to agents

Vidya-Studio (peer to SageMaker / AML Studio / Vertex AI), BharatVector-DB (peer to OpenSearch / Cosmos / Vertex Vector), Karya agentic runtime (peer to Bedrock AgentCore / AI Foundry / Gemini A2A), Param-Sahaay code assistant on BharatGen-Code, Rakshak-GPU confidential H100/B200, Yantra-Serve non-LLM serving, Bhandara-Features feature store, Anketh 22-language labelling. Plus the original Vidyut LLM gateway, Vaani speech across all 22 scheduled languages, Chakshu AIS-140 traffic vision, Krishi crop diagnosis, Federated-Mitra hospital learning.

30
AI services
22 services
Artificial Intelligence · Phased Rollout

AI, phase by phase

P1 stands up the sovereign LLM gateway and the responsible-AI fabric so models can be served, watermarked and audited under Indian law. P2 brings the MLOps surface (notebooks, training, serving) that every team needs. P3 is when agents come online with full DPI tool catalogues and the vector store that backs them. P4 is the frontier: confidential GPU TEEs, a code assistant on BharatGen-Code, the sovereign equivalents that hyperscalers are still rolling out themselves.

30
services across 4 phases
Data & Analytics · 29 Services · the gap-closer domain

Every database the cloud demands

The single most damaging hole in the previous catalog: no managed RDBs. The addendum closes it completely. Setu-DB (Postgres/MySQL/MariaDB, peer to RDS / Azure Database / Cloud SQL), Saraswati-DB (distributed SQL, peer to Aurora DSQL / Cosmos / Spanner), Kosh (NoSQL, peer to DynamoDB / Cosmos / Firestore), Triveni (cache, peer to ElastiCache / Azure Cache / Memorystore), Kaal (time-series, peer to Timestream / ADX / Bigtable), Jaal-Graph (peer to Neptune / Spanner Graph), Khoj (search with 22-language Indic analysers), Sandesh (queues + pub-sub), Sandhi-ETL (Airbyte + dbt + Dagster), Pravaha-Spark serverless, Darpan zero-ETL CDC, Krama orchestration. Plus the original Bhandara lakehouse, BharatTier cold storage, Sutra lineage and confidential clean rooms.

29
data services
17 services
Data & Analytics · Phased Rollout

Data, phase by phase

This is the domain the addendum reshaped the most. P1 closes the single most damaging gap in the original catalogue — a managed Postgres / MySQL / MariaDB (Setu-DB) and an in-memory cache (Triveni). P2 adds the rest of the OLTP surface (Kosh NoSQL, Kaal time-series, Khoj search, Sandesh queues). P3 brings analytics-grade horsepower (Saraswati distributed SQL, Pravaha-Spark, Sandhi-ETL, Darpan CDC, Krama orchestration). P4 hardens the sovereign clean room and seven-year archive for SEBI.

29
services across 4 phases
Migration & Modernisation · 19 Services · de-risked cutover

Move it without breaking it

A six-hour cutover orchestrator (Setu-Yatra) that satisfies RBI MD-ITOS 2023; a Z3-verified COBOL-to-Java transpiler (Vivartan); SAP ECC → S/4HANA, Oracle Forms → React/Quarkus, Bhulekh land-records, Tally/Busy/Marg accounting modernisers, and VMware exodus paths. Augmented now by Avishkar (discovery + strategy, peer to AWS Migration Hub / Azure Migrate / GCP Migration Center), Yaan (physical-transport appliances, peer to Snow family / Data Box / Transfer Appliance), Yamuna-Transfer (FASP-style WAN saturation), Yugma (parallel-run, peer to GCP Dual Run — the only productised peer), Setu-Pravaha (live DB bridge, peer to Azure Arc-enabled SQL MI link), and Lekha-TCO (INR-native cost calculator).

19
migration services
13 services
Migration & Modernisation · Phased Rollout

Migration, phase by phase

P1 is the discovery + physical-transport pair (Avishkar + Yaan): you cannot migrate what you cannot see, and you cannot ingest petabytes over a leased line. P2 enables continuous ingest (Yamuna-Transfer, Setu-Pravaha live DB bridge). P3 is where the de-risked cutover engines come in: Yugma parallel-run, Vivartan Z3-verified COBOL transpiler, the SAP and Oracle Forms paths. P4 brings the procurement-grade INR TCO calculator (Lekha-TCO) and portfolio-level wave planning.

19
services across 4 phases
Integration Layer · The Glue

The nine integration buses

Every service in the catalogue speaks to every other service through these nine buses, never directly. The bus list, in plain English: consent receipts under the Data Protection Act, certificates signed at the Controller of Certifying Authorities, per-second rupee billing through the National Payments Corporation, twenty-two-language translation via Bhashini, the Open Network for Digital Commerce protocol, Aadhaar and DigiLocker identity, Goods-and-Services Tax filings, the federated edge mesh across BharatNet and RailTel, and telemetry flowing into the C-DAC security operations centre.

9
integration buses
Event Mesh
Named Tarang
The nine buses
Each bus is an independent service. Click a row for detail.
User Experience Layer · The Face

The five user-facing surfaces

A tenant dashboard derived from OpenStack Skyline and internationalised into all twenty-two scheduled languages. A developer marketplace built on Backstage with a gallery of Heat templates and software development kits. A finance console with sub-paisa rupee precision and full Goods-and-Services Tax invoice generation. An attestation visualiser that surfaces the confidential-hardware chain in a form a Reserve Bank inspector can verify. A read-only regulator portal scoped per agency. Below these five, every request requires a Keystone identity token. There is no other way in.

5
user experience surfaces
5 surfaces
Chapter Five · Cross-Domain Synergies

Twenty-one cross-domain connections

Each row below is a directed flow of data or events between two named services, carried by a specific Meghdoot mechanism, with a measurable outcome that proves the connection is real rather than aspirational. Hover any row and the matching edge will light up in the diagram on the left.

21
directed flows
Chapter Six · India's Public Digital Rails

The Indian Digital Public Infrastructure we wire into

Ten sovereign rails that the platform integrates with directly: the Unified Payments Interface for billing, the Open Network for Digital Commerce for retail events, Bhashini for languages, the Goods-and-Services Tax Network for filings, the Account Aggregator framework for financial-data consent, DigiLocker for documents, Aadhaar for identity, the Ayushman Bharat Digital Mission for health records, BharatNet and RailTel for edge presence, and the Controller of Certifying Authorities for digital certificates. None of these is a commercial API a foreign cloud can simply purchase. Most require sovereign accreditation that takes years.

10
sovereign rails
Chapter Seven · Side by Side

Side-by-side with the global hyperscalers

A like-for-like comparison on the capabilities Indian regulators actually demand of cloud providers. A Native mark means the capability is scheduled, billed, signed and audited at the substrate level. A Partial mark means it is commercially available but as an add-on the customer is expected to integrate themselves.

14
capabilities benchmarked
Capability
Amazon
Microsoft
Google
Our Proposal
Chapter Seven-and-a-Half · The Equivalence Map

A service-by-service map to AWS, Azure and GCP

Every one of the one hundred and twenty-three services is mapped to its closest AWS / Azure / GCP peer and to the open-source projects we use to implement it. Cells marked "No native peer" are sovereign moats — capabilities that depend on Indian DPI, regulators, languages, silicon or geography.

123
services mapped
All 123 services
Compute (29)
AI & ML (30)
Data (29)
Migration (19)
Integration Buses (9)
Tenant Plane (7)
Sovereign moats
MSS Service
AWS
Azure
GCP
Open-Source Implementation
Chapter Seven-and-Three-Quarters · The Open-Source Spine

Built on one hundred and fifty plus open-source projects

Every layer is anchored on permissively-licensed open-source — Apache 2.0, BSD, MIT. Vendor lock-in shrinks to the integration glue; the substrate is the global commons. The academic consortium commits to upstream contribution pathways for every major project we touch.

150+
OSS projects, India-stewarded
Chapter Eight · Regulatory Compliance

Sixty-two compliance clauses across fifteen regulators

Every clause maps to the service that satisfies it and the mechanism that enforces it. The evidence artefact for each clause is signed under the same sovereign certificate chain that secures the rest of the platform, so an inspector can verify it without having to trust the vendor.

62
clauses mapped
Chapter Nine · The Coverage Audit

Where each of the four hundred and twenty-eight ideas ended up

Every one of the raw ideas was assigned to exactly one of four outcomes. Only 1.4 percent were retired, well below the 5 percent ceiling we set ourselves at the start of the synthesis. The Sankey diagram below traces the full flow and the table on the right gives the counts.

428
ideas audited
Flow visualisation

428 ideas, traced to 84 services

Chapter Ten · The Roadmap

Sixty months of delivery

The horizon matches the three-plus-two-year empanelment window the EOI specifies. Phase one ships thirty-one services covering the whole of Compute, the Integration Layer and the User Experience Layer. The Artificial Intelligence catalogue follows in Phase two, Data and Analytics in Phase three, Migration in Phase four. Phase five is the national rollout with edge expansion, MeitY empanelment and STQC certification. The month boundaries shown are indicative; they become firm at the Letter of Engagement stage, once team capacity and C-DAC priorities are agreed in writing.

M0—M60
delivery milestones
Chapter Twelve · What We Need

People, hardware and the budget envelope

An indicative five-year envelope, subject to detailed sizing in the Statement of Work. The one hundred and eighty-six headcount is split across the academic consortium, the C-DAC counterpart team and the named industry partners. Hardware grows from a three-rack proof-of-concept laboratory at month three to a national-scale fleet by month sixty.

₹375—560 Cr
indicative budget
People mix · cumulative over five years
Compute, storage and edge growth
Chapter Thirteen · The Moat

Why foreign clouds cannot copy us in eighteen months

The advantages below stack on top of each other. A Payment Aggregator licence from the Reserve Bank takes well over a year. Becoming a Goods-and-Services Tax application service provider takes months. The Aadhaar e-KYC sub-licence from UIDAI is a multi-year process. Add the Bhashini National Language Translation Mission memorandum, the federated-learning accreditation under the Ayushman Bharat Digital Mission, the integration with C-DAC's own Made-in-India BOSS Linux, and the access to anonymised public-sector-bank COBOL corpora that foreign vendors legally cannot hold. No single advantage rests on the slogan "we are Indian" alone.

18—24
month minimum barrier
Top-tier research papers
SOSP, OSDI, NeurIPS, ACL, VLDB and more.
30+
Defensive joint patents
Co-owned with C-DAC.
10
Indian standards contributions
Bureau of Standards, Quality Certification, Cyber Authority, Ministry of Electronics, Payments, Tax, Commerce.
10
Open-source projects upstreamed
Firecracker, vLLM, Iceberg, Flink, Karmada, Konveyor and more.
11
Chapter Fourteen · What Happens Next

Invite us to the technical presentation

This pitch and the accompanying written proposal lay out eighty-four services, twenty-one cross-domain connections, sixty-two compliance clauses and a five-year delivery plan. The next step the EOI specifies is a technical presentation in person. We are ready to come to C-DAC Chennai, walk the evaluation panel through the architecture in detail, field questions on any service in the catalogue, and discuss which workstreams the consortium and the C-DAC counterpart team should prioritise for the Letter of Engagement.

Submitting entity
Academic Consortium
Workstream leaders
Nine senior professors
Deployment location
C-DAC Chennai · Staging data centre
Empanelment horizon
Three plus two years
01 of 21