Skip to main content
Version: Next 🚧

Airgap Workflow

What are Disconnected and Airgapped Environments?​

Disconnected and airgapped environments are isolated from external networks, usually including the internet, to protect sensitive systems and data from unauthorized access or transfer. Artifacts cannot be pulled directly from where they are published, so every image, chart, and file has to be brought in deliberately. Most disconnected and airgapped environments fall into one of three categories.

CategoryDefinitionIndustriesHow Hauler Helps
Fully IsolatedNo network path to the outsideClassified government and military networks, critical infrastructure, and secure research facilitiesBundles everything into a single haul that is easy to review, approve, and carry in
Restricted ConnectivityInternal network, but no internet accessRegulated industries, finance, healthcare, sovereign clouds, and enterprise networksSeeds your existing registries, or serves its own registry and fileserver to bootstrap them
Intermittent and Limited ConnectivityOccasional, slow, denied, or unreliable connections, known as DDILShips and aircraft, remote and field locations, edge sites, and tactical deploymentsSplits hauls into chunks for each connection window and serves them locally between connections

Challenges and How Hauler Helps​

ChallengeHow Hauler Helps
Data Transfers - moving artifacts in requires physical media, trusted intermediaries, and approvalsHauler packages everything into a single haul, which can be split into chunks to fit your transfer media
Trust and Integrity - confirming that what arrived is exactly what was intendedSignatures, attestations, and SBOMs travel with each artifact, and the store can be validated after it arrives
Maintenance Complexity - updates and dependencies require careful planning every releaseDeclarative manifests rebuild the same store reliably for every release
Custom Tooling - delivery often depends on custom scripts and ad hoc processesOne binary with a built-in registry and fileserver handles the entire workflow

Workflow​

hauler-workflow-diagram

The Hauler workflow follows your artifacts through each step, from the connected side, into disconnected and airgapped environments, and out to where they are needed.

Connected Side​

Fetch​

Artifacts are added to the store from registries, helm repositories, and urls, either one at a time with hauler store add or declaratively with manifests and hauler store sync.

Validate​

Image signatures are verified with cosign as artifacts are added, when a public key or keyless identity is provided, before anything is saved to the store, and hauler store info --check confirms every artifact in the store is complete.

Save​

hauler store save packages the store into a haul, a single compressed archive ready to be transferred.

Airgap​

The haul is transferred into disconnected and airgapped environments by whatever means your environment allows, such as physical media or a one-way transfer.

Disconnected and Airgapped Side​

Load​

hauler store load unpacks one or more hauls back into a store.

Validate​

hauler store info --check confirms that every artifact arrived complete, and because signatures and attestations travel with each image, they can be verified again with cosign.

Distribute​

The content is served with hauler store serve registry and hauler store serve fileserver, or copied into an existing registry or directory with hauler store copy.

Next Steps​