Some checks failed
AOC Guard CI / aoc-guard (push) Has been cancelled
AOC Guard CI / aoc-verify (push) Has been cancelled
Docs CI / lint-and-preview (push) Has been cancelled
Mirror Thin Bundle Sign & Verify / mirror-sign (push) Has been cancelled
api-governance / spectral-lint (push) Has been cancelled
1.6 KiB
1.6 KiB
CLI Airgap Guide (DOCS-AIRGAP-57-003)
Offline/air-gapped usage patterns for the Stella CLI.
Prerequisites
- CLI installed from offline bundle;
local-nugets/and cached plugins available. - Mirror/Bootstrap bundles staged locally; no external network required.
- Set
STELLA_OFFLINE=trueto prevent outbound fetches.
Common commands
- Validate mirror bundle
stella airgap verify-bundle /mnt/media/mirror.tar \ --manifest /mnt/media/manifest.json \ --trust-root /opt/stella/trust/mirror-root.pem - Import bundle into local registry
stella airgap import --bundle /mnt/media/mirror.tar --generation 12 - Check sealed mode status
stella airgap status - List bundles and staleness
stella airgap list --format table
Determinism & offline rules
- Commands must succeed without egress; any outbound attempt is a bug—report with logs.
- Hashes and signatures are verified locally using bundled trust roots; no OCSP/CRL.
- Outputs are stable JSON/NDJSON; timestamps use UTC.
Exit codes
0success2validation failed (hash/signature mismatch)3sealed-mode violation (unexpected egress attempted)4input/argument error>4unexpected error (inspect logs)
Logs
- Default stderr structured JSON: includes
tenant,bundleId,mirrorGeneration,sealedflag. - For audits, use
--log-file /var/log/stella/airgap.log --log-format json.
Tips
- Keep bundles on read-only media to avoid hash drift.
- Use
--dry-runto validate without writing to registries. - Pair with
docs/airgap/overview.mdanddocs/airgap/sealing-and-egress.mdfor policy context.