Air-Gap Degradation Matrix

Audience: operators and architects planning Stella Ops deployments that move between connected, constrained, and sealed (air-gapped) network postures.

This matrix shows which capabilities work, degrade, or are unavailable across the three connectivity modes, and how to substitute offline equivalents where a feature is unavailable. For the activation flow and supported scope of sealed mode, see the Air-Gap Mode Guide; for the state machine that tracks sealed status, see the AirGap Controller.

Legend: ✓ = available · ✗ = unavailable · qualifier in parentheses = available with conditions.

CapabilityConnectedConstrainedSealedNotes
Mirror imports✓✓✓Sealed requires preloaded media + offline validation.
Time anchors (external NTP)✓✓ (allowlisted)✗Sealed relies on signed time anchors.
Transparency log lookups✓✓ (if allowlisted)✗Sealed skips; rely on bundled checkpoints.
Rekor witness✓optional✗Disabled in sealed; log locally.
SBOM feed refresh✓✓ (limited mirrors)✓ (offline only)Use mirror bundles.
CLI plugin downloads✓✓ (allowlisted)✗Must ship in the bootstrap pack.
Telemetry export✓optionaloptional (log-only)Sealed may use the console exporter only.
Webhook callbacks✓✓ (allowlisted, internal only)✗Use the internal queue instead.
OTA updates✓partial✗Refresh via mirrorGeneration.

Remediation guidance

See also