For the complete documentation index, see llms.txt. This page is also available as Markdown.

Overview: Air Gap

Overview and requirements for AirGap for OneSite Patch

AirGap for OneSite Patch is an add-on that allows you to distribute patches to highly secure, air-gapped environments (network isolated) using a secure provisioning process.

Air-gapped server diagram

This process involves syncing paired servers, an air-gapped Patch server in your isolated network and an online Patch server connected to the Internet. The air-gapped server builds a software inventory from devices in an isolated network and requests a patch payload from the online server. This request is physically conveyed to the online server, which downloads the relevant patches and compiles a payload. The payload is then physically conveyed to the air-gapped server for distribution to clients.

Requirements

AirGap is designed to be used in a highly secure environment, and therefore, only works with the Adaptiva on-prem solution. It is not available in our SaaS product. Currently, we only support Windows OS and 3rd party apps for deployment.

An air-gapped Patch environment needs two servers:

  • An online Patch server, capable of downloading patches.

  • An air-gapped server that stays in isolation.

Additionally, you will need some sort of physical media to transport .txt and .zip files between the servers.

Each Patch server must install the OneSite Platform and then license OneSite Patch and the AirGap for OneSite Patch add-on. The OneSite Platform build versions must be the same on both servers.

The configuration of the servers must be done by a Super Admin on each server (you can configure this user during installation).

Zones

Once deployed, the platform can support multiple air-gapped environments as "zones," each managed centrally from the online server. This allows administrators to maintain consistent oversight while tailoring patch distribution to the needs of separate secure environments.

Last updated

Was this helpful?