Airgap Operations (DOCS-AIRGAP-57-004)

Audience: operators running Stella Ops in sealed or constrained air-gap modes.

Day-two runbooks for bundle imports, failure recovery, and auditing. For mode definitions and the end-to-end lifecycle, start with the Airgap Overview.

Imports

  1. Verify bundle hash/DSSE (see Mirror Bundles).
  2. stella airgap import --bundle ... --generation N --dry-run (optional).
  3. Apply network policy: ensure sealed/constrained mode set correctly.
  4. Import with stella airgap import ... and watch logs.
  5. Confirm timeline event emitted (bundleId, mirrorGeneration, actor).

Failure recovery

Auditing

Observability

Checklist (per import)