Incident Mode Runbook
Audience: operators and incident commanders responding to a security or availability incident in a Stella Ops deployment.
This page is a pointer. The authoritative incident index — including regulatory-reporting timelines, emergency access, and key/crypto compromise procedures — is the Incident Response Runbook. Start there to find the right runbook, then follow that runbook end to end.
Where to go
| If you need to… | Go to |
|---|---|
| Find the right incident runbook (the index) | Incident Response Runbook |
| File a regulatory report (CRA 24h / 72h / 14d) and enable Evidence Locker incident mode | CRA Article 14 operator reporting |
| Gain emergency access | Break-glass account runbook |
| Preserve and verify evidence during an incident | Evidence Locker operations |
| Respond to an air-gapped / offline deployment incident | Air-gap operations runbook |
| Triage a policy-engine incident | Policy incident runbook |
Determinism checklist
Apply these to any captures, fixtures, or evidence you attach to an incident so the record is reproducible and offline-verifiable:
- [ ] Hash any inbound assets/payloads and place the sums alongside the artifacts (e.g. a
SHA256SUMSfile in the same folder). - [ ] Keep examples offline-friendly and deterministic (fixed seeds, pinned versions, stable ordering).
- [ ] Record the source and approver for any provided captures or schemas.
