Air-Gap Mode Guide

Audience: operators deploying Stella Ops into a sealed (air-gapped) environment with no outbound network access.

This guide defines the supported deployment scope for air-gap mode and the canonical activation flow. For the state machine that tracks sealed status, see the AirGap Controller; for priming a fresh sealed site, see the Bootstrap Pack.

Supported Scope

Air-gap mode uses Offline Kit assets, Docker Compose or host/service-manager deployment, signed release manifests, local registries, local object storage, and sealed evidence packs.

Kubernetes and Helm air-gap deployment instructions are retired.

Activation Flow

  1. Verify Offline Kit checksums and signatures.
  2. Import images and external data bundles into approved local stores.
  3. Configure services through Compose environment files or host secret stores.
  4. Start the supported Offline Kit profile.
  5. Run sealed-mode health checks and egress verification.
  6. Store manifest hashes, config hashes, and verification output in evidence.

Unsupported Legacy Paths

Do not run Helm installs, apply Kubernetes manifests, or use kubectl in Stella Ops air-gap deployment procedures. These paths are retired and are not maintained for sealed deployments.