Air-gapped configuration
Run self-hosted SBOM Observer in a network with no internet access.
An air-gapped installation is a self-hosted installation without outbound internet access. Everything else is the same, except that SBOM Observer can't download vulnerability data itself; you bring it in. See Deployment models to compare the options.
Differences from self-hosted
| Self-hosted | Air-gapped | |
|---|---|---|
| Internet access | Yes | No |
| Vulnerability data | Downloaded by SBOM Observer | Transferred in by you, on a schedule |
Prerequisites
All self-hosted installation requirements apply, except internet access. In addition:
- A transfer method your security policy approves for moving vulnerability data into the isolated network, such as a controlled gateway, a data diode, or encrypted media.
- A procedure for receiving, checking, and importing each data transfer.
- Confirmation that the SBOM Observer hosts have no outbound internet access.
Contact support when planning the data transfer; it is the part that needs designing per site.
Complete setup instructions, including Docker Compose files and environment configuration, are in the Customer License Portal.
Vulnerability data management
In an air-gapped installation, vulnerability data only changes when you import it. Each update has three parts:
- A gateway server you control, with internet access, downloads the latest datasets.
- The datasets move into the isolated network through your approved transfer method.
- The import procedure from the License Portal loads them into SBOM Observer.
How often to run it is your decision. Vulnerabilities published after the last import don't show up until the next one.
Version updates
Contact support for the upgrade procedure in an air-gapped installation.
Related
- Reference: Self-hosted installation for internet-connected deployments.
- Concept: Deployment models