Air-Gap Degradation Matrix

Audience: operators and architects planning Stella Ops deployments that move between connected, constrained, and sealed (air-gapped) network postures.

This matrix shows which capabilities work, degrade, or are unavailable across the three connectivity modes, and how to substitute offline equivalents where a feature is unavailable. For the activation flow and supported scope of sealed mode, see the Air-Gap Mode Guide; for the state machine that tracks sealed status, see the AirGap Controller.

Legend: ✓ = available · ✗ = unavailable · qualifier in parentheses = available with conditions.

CapabilityConnectedConstrainedSealedNotes
Mirror importsSealed requires preloaded media + offline validation.
Time anchors (external NTP)✓ (allowlisted)Sealed relies on signed time anchors.
Transparency log lookups✓ (if allowlisted)Sealed skips; rely on bundled checkpoints.
Rekor witnessoptionalDisabled in sealed; log locally.
SBOM feed refresh✓ (limited mirrors)✓ (offline only)Use mirror bundles.
CLI plugin downloads✓ (allowlisted)Must ship in the bootstrap pack.
Telemetry exportoptionaloptional (log-only)Sealed may use the console exporter only.
Webhook callbacks✓ (allowlisted, internal only)Use the internal queue instead.
OTA updatespartialRefresh via mirrorGeneration.

Remediation guidance

See also