Air-Gap Mode Guide
Audience: operators deploying Stella Ops into a sealed (air-gapped) environment with no outbound network access.
This guide defines the supported deployment scope for air-gap mode and the canonical activation flow. For the state machine that tracks sealed status, see the AirGap Controller; for priming a fresh sealed site, see the Bootstrap Pack.
Supported Scope
Air-gap mode uses Offline Kit assets, Docker Compose or host/service-manager deployment, signed release manifests, local registries, local object storage, and sealed evidence packs.
Kubernetes and Helm air-gap deployment instructions are retired.
Activation Flow
- Verify Offline Kit checksums and signatures.
- Import images and external data bundles into approved local stores.
- Configure services through Compose environment files or host secret stores.
- Start the supported Offline Kit profile.
- Run sealed-mode health checks and egress verification.
- Store manifest hashes, config hashes, and verification output in evidence.
Unsupported Legacy Paths
Do not run Helm installs, apply Kubernetes manifests, or use kubectl in Stella Ops air-gap deployment procedures. These paths are retired and are not maintained for sealed deployments.
Related
- AirGap Controller — sealed/unsealed state, policy hash, and staleness budgets.
- Bootstrap Pack — build and install the pack that primes a sealed environment.
- Sealing and Egress — egress enforcement applied during install.
