7.4 Import the Transfer Bundle
Go to 7. Disconnected and Air-Gapped Operations
After an authorized transfer reaches the destination environment, Crucible imports the identified Transfer Bundle into the applicable Disconnected Environment or Air-Gapped Environment.
Import makes approved bundle content available for subsequent repository population, construction, assessment, deployment, or validation. Import does not independently authorize use of every item contained in the bundle.
Receive the Transfer Bundle
Crucible receives the Transfer Bundle through the approved destination-side transfer process.
The received bundle remains associated with:
-
The Transfer Bundle identifier
-
The source environment
-
The destination environment
-
The source Security Domain
-
The destination Security Domain
-
The authorized transfer activity
-
The intended destination lifecycle activity
-
The available integrity information
Crucible does not treat unidentified content or an unassociated collection of files as the approved Transfer Bundle.
Apply Destination Controls
The destination Security Domain applies its access restrictions, information-handling rules, and import controls to the received bundle.
Destination controls can determine:
-
Whether the bundle can enter the destination environment
-
Whether the receiving actor can perform the import
-
Which bundle content the destination can accept
-
Which content requires additional review
-
Which information must remain restricted
-
Whether the bundle requires inspection or verification
-
Whether the destination can use the imported content
A successful transfer across the boundary does not require the destination environment to accept or use the bundle.
Verify Bundle Identity and Integrity
Crucible verifies that the received bundle corresponds to the Transfer Bundle selected for import.
Verification can include:
-
Confirmation of the Transfer Bundle identifier
-
Comparison of the received content with the recorded integrity value
-
Verification of an associated Digital Signature
-
Confirmation of the expected bundle representation
-
Confirmation of required bundle metadata
-
Confirmation of the intended destination environment
An integrity mismatch, missing identifier, invalid signature, or unexpected bundle representation prevents Crucible from treating the received content as the verified Transfer Bundle.
A successful integrity verification establishes that the evaluated bundle corresponds to the expected representation. It does not independently establish that every included item is compliant, approved, or suitable for use.
Inspect the Bundle Contents
Crucible identifies the content and relationships represented within the verified Transfer Bundle.
The bundle can include:
-
Captured direct Dependencies
-
Captured transitive Dependencies
-
Dependency metadata
-
Content intended for Offline Repositories
-
Compliance Findings
-
Associations between Compliance Findings and the artifacts they describe
-
Integrity information
-
Other content required by the approved destination activity
The import activity preserves the identity of each included item and does not merge unrelated content into a single unidentified artifact.
Preserve Included Associations
Crucible preserves the relationships represented by the Transfer Bundle during import.
These relationships can associate:
-
A Dependency with its version or revision
-
A Dependency with its original source
-
A direct Dependency with its transitive Dependencies
-
An artifact with its associated Compliance Findings
-
A Compliance Finding with the subject assessed
-
Included content with the destination activity that requires it
-
An imported item with the Transfer Bundle that carried it
Import does not change the recorded meaning or status of a Compliance Finding.
Handle Import Exceptions
Crucible records conditions that prevent successful import.
Import exceptions can include:
-
An unidentified Transfer Bundle
-
An integrity mismatch
-
An invalid Digital Signature
-
Missing bundle metadata
-
Missing required content
-
Content prohibited by destination information-handling rules
-
Content unsupported by the destination environment
-
An unauthorized import request
-
An incomplete or unreadable bundle
Crucible does not silently replace, omit, repair, or substitute bundle content when doing so would change the approved Transfer Bundle.
The applicable policy or authorized actor determines whether an exception requires rejection, quarantine, additional review, retransmission, or creation of a replacement bundle.
Complete the Import
After successful verification and application of destination controls, Crucible makes the accepted bundle content available within the destination environment.
Successful import can make the content available for:
-
Population of Offline Repositories
-
Image construction
-
Compliance Assessment
-
Infrastructure deployment
-
Deployment Validation
-
Another approved disconnected or air-gapped lifecycle activity
Import does not itself perform those subsequent activities.
Import Result
The import result identifies:
-
The Transfer Bundle received
-
The destination environment
-
The receiving Security Domain
-
The import operation
-
The identity-verification result
-
The integrity-verification result
-
The destination-control result
-
The content accepted for import
-
The content rejected or held for review
-
The associations preserved during import
-
The overall import status
-
Any exception or unresolved condition
The successfully imported content becomes a controlled input to 7.5 Populate Offline Repositories or another approved destination lifecycle activity.
Requirements Addressed
| Requirement | Statement |
|---|---|
| OR-003d — Security Domain Information Enforcement |
Crucible SHALL prevent an operation from processing information not authorized within the operation's governing Security Domain. |
| OR-003e — Information Handling Rule Enforcement |
Crucible SHALL prevent an operation from handling information in a manner prohibited by the Information Handling Rules governing that information. |
| OR-003f — Cross-Domain Transfer Control |
Crucible SHALL transfer information between Security Domains only through an authorized Cross-Domain Transfer. |
| FR-AG-002 — Artifact Export Packages |
Crucible SHALL create Transfer Bundles for export. |
| FR-AG-003 — Artifact Import Packages |
Crucible SHALL import Transfer Bundles. |
| FR-AG-005 — Deployment Traceability Across Disconnected Environments |
Crucible SHALL maintain Deployment Traceability across Disconnected Environments. |
The linked leaf requirement pages remain the canonical sources.
© 2026 Dido Solutions, Inc. and Jackrabbit Consulting, Inc.