Air-Gap Degradation Matrix
Audience: operators and architects planning Stella Ops deployments that move between connected, constrained, and sealed (air-gapped) network postures.
This matrix shows which capabilities work, degrade, or are unavailable across the three connectivity modes, and how to substitute offline equivalents where a feature is unavailable. For the activation flow and supported scope of sealed mode, see the Air-Gap Mode Guide; for the state machine that tracks sealed status, see the AirGap Controller.
Legend: ✓ = available · ✗ = unavailable · qualifier in parentheses = available with conditions.
| Capability | Connected | Constrained | Sealed | Notes |
|---|---|---|---|---|
| Mirror imports | ✓ | ✓ | ✓ | Sealed requires preloaded media + offline validation. |
| Time anchors (external NTP) | ✓ | ✓ (allowlisted) | ✗ | Sealed relies on signed time anchors. |
| Transparency log lookups | ✓ | ✓ (if allowlisted) | ✗ | Sealed skips; rely on bundled checkpoints. |
| Rekor witness | ✓ | optional | ✗ | Disabled in sealed; log locally. |
| SBOM feed refresh | ✓ | ✓ (limited mirrors) | ✓ (offline only) | Use mirror bundles. |
| CLI plugin downloads | ✓ | ✓ (allowlisted) | ✗ | Must ship in the bootstrap pack. |
| Telemetry export | ✓ | optional | optional (log-only) | Sealed may use the console exporter only. |
| Webhook callbacks | ✓ | ✓ (allowlisted, internal only) | ✗ | Use the internal queue instead. |
| OTA updates | ✓ | partial | ✗ | Refresh via mirrorGeneration. |
Remediation guidance
- If a capability is degraded in sealed mode, provide an offline substitute: mirror bundles, time anchors, or a console telemetry exporter.
- When moving from sealed toward constrained or connected, re-enable trust roots and transparency checks gradually, and verify hashes before trusting any newly reachable source.
See also
- Air-Gap Mode Guide — supported scope and activation flow.
- AirGap Controller — sealed/unsealed state, policy hash, and staleness budgets.
- Mirror Bundles — offline image, chart, and feed delivery.
- Staleness and Time — time anchors and staleness budgets.
