Air-gapped operation¶
In a classified or otherwise isolated enclave, "the tool must not phone home" is not a preference — it is the condition of being allowed to run at all. Air-gap mode makes that property explicit and enforced, rather than something an operator has to infer from the absence of observed traffic.
Enterprise
Air-gapped operation is an Enterprise-edition capability, and it is off by default.
What it does¶
With air-gap mode on, the verifier makes no out-of-enclave connection. The core attestation loop is unaffected — it only ever talked to your own agents over mutual TLS inside your own network, and that remains true. What is refused is everything that would reach outside: catalog fetches over the network, and any other egress path that is not an agent it is enrolled with.
The run banner states the enforcement and its honest limits when the verifier starts, so an auditor can see the posture in the logs rather than take it on trust.
Turning it on¶
Truthy values are 1, true, yes (case-insensitive, surrounding whitespace
trimmed). The value is read once at startup and cached — the process runs under
a fixed systemd environment, so it cannot change mid-run.
Two posture adjustments¶
| Variable | Effect | Default |
|---|---|---|
ETMINAN_AIRGAP_ALLOW_REMOTE_SYSLOG |
Still send SIEM syslog to a remote collector while in air-gap mode — for a collector that lives inside the enclave | off |
ETMINAN_AIRGAP_DISABLE_PLUGINS |
The strictest posture: skip all change-source and notification plugin execution, so no opaque subprocess egress is possible at all | off |
Both are consulted only when air-gap mode is on.
A plugin is a subprocess, and a subprocess can do anything
Air-gap mode governs what the verifier does. A notification or
change-source plugin is a separate program the verifier executes; the
allowlist and hash-pinning constrain which program, not what that program
then does with a socket. In an enclave where that distinction matters, set
ETMINAN_AIRGAP_DISABLE_PLUGINS and accept the loss of those channels.
Installing plugins without a network¶
The plugin catalog normally resolves over the network. In air-gap mode that fetch is refused — so plugins are installed from a local signed bundle instead:
The directory must contain manifest.json, manifest.json.sig and the plugin
file(s); <name> must appear in that bundle's manifest, and the command refuses
a plugin that is already installed. The signature is verified before anything is
written — the offline path is not a relaxed path.
This command must run as root, and the verify-then-exec gate in the plugin executor still applies at execution time.
Bring the bundle in the way everything else comes in
A signed bundle on removable media is a supply-chain event like any other. Verify its signature against the Etminan Team key on the outside before it crosses the boundary, not only on the inside.
What air-gap mode does not do¶
State it out loud, because an assessor will ask:
- It does not make the verifier's own host secure. It constrains one process's egress; it is not a network control, and it is not a substitute for one.
- It does not change the trust model. The verifier remains the single point of trust — see the residual risks in the design record.
- It does not cover the agents. They never had outbound connections to begin with; they only answer the verifier.
Next steps¶
- Verifier configuration — where these variables are set in the unit environment.
- Plugin API — the allowlist and hash-pinning model these postures interact with.