One signed Offline Kit bundle plus an operator runbook delivers feeds, images, and provenance so Stella Ops runs 100% offline behind the strictest perimeter.
The Offline Update Kit includes an installable bundle and runbook so air-gapped deployments keep parity with connected environments.
→Full vulnerability scanning with up-to-date advisories from 33+ sources
→Reachability analysis and VEX-aware risk filtering without internet access
→Policy-gated promotions with signed Decision Capsules for every release
→Deterministic replay and audit verification — no network required
1 · What's inside
Curated advisories
Global feeds plus regional sources (CNNVD, JVN, ENISA, BDU) preserved as individual signed snapshots so policy can trust or ignore each one independently.
Preloaded runtime
Scanner, Zastava, and supporting images for x86‑64 and arm64 ready to mirror into your registry.
Provenance & SBOM
Cosign signatures, DSSE attestations, and SPDX SBOMs that prove what you imported.
Delta updates
Compact daily patches keep the kit fresh without hauling gigabytes across the perimeter.
Three steps to update
1
Download and verify
Fetch the latest kit and signature on a connected mirror. Verify with your Cosign public key before transfer.
2
Transfer to air-gapped site
Use your approved channel: USB, courier, or controlled rsync drop box. Unsigned bundles never cross the boundary.
3
Import
Run stella offline-kit import or use the Console UI. Feeds swap in under three seconds with zero downtime.