Files
git.stella-ops.org/docs/modules/cli/guides/airgap.md
StellaOps Bot 150b3730ef
Some checks failed
AOC Guard CI / aoc-guard (push) Has been cancelled
AOC Guard CI / aoc-verify (push) Has been cancelled
Docs CI / lint-and-preview (push) Has been cancelled
Mirror Thin Bundle Sign & Verify / mirror-sign (push) Has been cancelled
api-governance / spectral-lint (push) Has been cancelled
up
2025-11-24 07:52:25 +02:00

1.6 KiB

CLI Airgap Guide (DOCS-AIRGAP-57-003)

Offline/air-gapped usage patterns for the Stella CLI.

Prerequisites

  • CLI installed from offline bundle; local-nugets/ and cached plugins available.
  • Mirror/Bootstrap bundles staged locally; no external network required.
  • Set STELLA_OFFLINE=true to prevent outbound fetches.

Common commands

  • Validate mirror bundle
    stella airgap verify-bundle /mnt/media/mirror.tar \
      --manifest /mnt/media/manifest.json \
      --trust-root /opt/stella/trust/mirror-root.pem
    
  • Import bundle into local registry
    stella airgap import --bundle /mnt/media/mirror.tar --generation 12
    
  • Check sealed mode status
    stella airgap status
    
  • List bundles and staleness
    stella airgap list --format table
    

Determinism & offline rules

  • Commands must succeed without egress; any outbound attempt is a bug—report with logs.
  • Hashes and signatures are verified locally using bundled trust roots; no OCSP/CRL.
  • Outputs are stable JSON/NDJSON; timestamps use UTC.

Exit codes

  • 0 success
  • 2 validation failed (hash/signature mismatch)
  • 3 sealed-mode violation (unexpected egress attempted)
  • 4 input/argument error
  • >4 unexpected error (inspect logs)

Logs

  • Default stderr structured JSON: includes tenant, bundleId, mirrorGeneration, sealed flag.
  • For audits, use --log-file /var/log/stella/airgap.log --log-format json.

Tips

  • Keep bundles on read-only media to avoid hash drift.
  • Use --dry-run to validate without writing to registries.
  • Pair with docs/airgap/overview.md and docs/airgap/sealing-and-egress.md for policy context.