| Next revision | Previous revision |
| dido:02-crusible:99-annexes:annex-c-requirements:03-functional-requirements:03-05-air-gap-operations:fr-ag-001 [2026/07/18 09:19] – created nick_dido | dido:02-crusible:99-annexes:annex-c-requirements:03-functional-requirements:03-05-air-gap-operations:fr-ag-001 [2026/07/30 05:56] (current) – nick_dido |
|---|
| ===== Statement ===== | ===== Statement ===== |
| |
| [[dido:99_annexes:annex-b-terms-and-definitions:c:crucible|Crucible]] SHALL perform deployment operations within a [[dido:99_annexes:annex-b-terms-and-definitions:d:disconnected_environment|Disconnected Environment]] without accessing an external network resource. | [[dido:99_annexes:annex-b-terms-and-definitions:c:crucible|Crucible]] SHALL perform [[dido:99_annexes:annex-b-terms-and-definitions:d:deployment_operation|Deployment Operations]] within [[dido:99_annexes:annex-b-terms-and-definitions:d:disconnected_environment|Disconnected Environments]]. |
| |
| ===== Source Statement ===== | ===== Derived From ===== |
| |
| > The system shall support disconnected deployment operations. | This requirement derives from: |
| |
| ===== Source ===== | * Crucible System Requirements Specification, Version 1.1 Draft, Functional Requirements, FR-AG-001 |
| |
| Crucible System Requirements Specification, Version 1.1 Draft, Functional Requirements, FR-AG-001. | The Original Requirement states: |
| |
| ===== Assessment ===== | > //The system shall support disconnected deployment operations.//[[dido:02-crusible:99-annexes:annex-b:cr-001|[C1]]] |
| |
| The source statement identifies the intended operating condition but does not provide a fully testable formulation. | FR-AG-001: |
| |
| The following Specification Discipline and Authoring findings apply: | * Replaces **The system** with the defined system name [[dido:99_annexes:annex-b-terms-and-definitions:c:crucible|Crucible]] |
| | * Changes **shall** to the established uppercase normative form **SHALL** |
| * **The system** does not use the defined system name | * Replaces the weak verb **support** with the observable behavior **perform** |
| * **shall** does not follow the established uppercase normative convention | * Uses the defined [[dido:99_annexes:annex-b-terms-and-definitions:d:deployment_operation|Deployment Operation]] concept |
| * **Support** is a weak verb that does not identify the required behavior | |
| * **Disconnected deployment operations** does not identify the environmental condition that governs execution | |
| * The source statement does not identify whether external network resources may be accessed | |
| * The source statement does not prescribe a deployment tool, transfer mechanism, repository implementation, network technology, or target platform | |
| | |
| The normalized Statement: | |
| | |
| * Replaces **The system** with [[dido:99_annexes:annex-b-terms-and-definitions:c:crucible|Crucible]] | |
| * Replaces **support** with the direct behavior **perform** | |
| * Identifies deployment operations as the required activity | |
| * Uses the defined [[dido:99_annexes:annex-b-terms-and-definitions:d:disconnected_environment|Disconnected Environment]] concept | * Uses the defined [[dido:99_annexes:annex-b-terms-and-definitions:d:disconnected_environment|Disconnected Environment]] concept |
| * Excludes access to external network resources during the deployment operation | |
| * Preserves implementation independence | |
| * Retains one primary required behavior | |
| |
| The normalized Statement does not require every dependency to originate within the Disconnected Environment. Separate requirements govern dependency capture, transfer, import, authorization, integrity verification, and synchronization. | No other substantive normalization is required. |
| |
| ===== Rationale ===== | ===== Rationale ===== |
| |
| A [[dido:99_annexes:annex-b-terms-and-definitions:d:disconnected_environment|Disconnected Environment]] cannot depend on continuous access to external repositories, services, interfaces, or management systems. | A [[dido:99_annexes:annex-b-terms-and-definitions:d:disconnected_environment|Disconnected Environment]] operates without direct electronic communication with specified external systems, services, repositories, Providers, or networks. |
| |
| Before deployment begins, the environment must contain or have authorized access to the artifacts, configurations, dependencies, credentials, metadata, and other resources required by the deployment. | Performing [[dido:99_annexes:annex-b-terms-and-definitions:d:deployment_operation|Deployment Operations]] within such an environment requires the necessary software, [[dido:99_annexes:annex-b-terms-and-definitions:d:dependency|Dependencies]], configuration information, credentials, repositories, and [[dido:99_annexes:annex-b-terms-and-definitions:a:artifact|Artifacts]] to be locally available or otherwise accessible within the permitted operational boundary. |
| |
| Disconnected deployment operations may include: | This requirement establishes disconnected deployment behavior without prescribing: |
| |
| * Deployment of [[dido:99_annexes:annex-b-terms-and-definitions:i:infrastructure_resource|Infrastructure Resources]] | * The Deployment Operation |
| * Deployment of [[dido:99_annexes:annex-b-terms-and-definitions:v:virtual_machine|Virtual Machines]] | * The deployment subjects |
| * Deployment of [[dido:99_annexes:annex-b-terms-and-definitions:k:kubernetes_cluster|Kubernetes Clusters]] | * The external systems from which the environment is disconnected |
| * Deployment of [[dido:99_annexes:annex-b-terms-and-definitions:c:containerized_workload|Containerized Workloads]] | * The transfer mechanism |
| * Deployment of [[dido:99_annexes:annex-b-terms-and-definitions:p:platform_service|Platform Services]] | * [[dido:99_annexes:annex-b-terms-and-definitions:d:dependency_capture|Dependency Capture]] |
| * [[dido:99_annexes:annex-b-terms-and-definitions:d:deployment_validation|Deployment Validation]] | * Artifact export |
| * [[dido:99_annexes:annex-b-terms-and-definitions:d:deployment_rollback|Deployment Rollback]] | * Artifact import |
| | * [[dido:99_annexes:annex-b-terms-and-definitions:t:transfer_authorization|Transfer Authorization]] |
| | * [[dido:99_annexes:annex-b-terms-and-definitions:t:transfer_bundle_integrity|Transfer Bundle Integrity]] |
| | * Baseline synchronization |
| | * Air-gapped operation |
| |
| A Disconnected Environment differs from an [[dido:99_annexes:annex-b-terms-and-definitions:a:air-gapped_environment|Air-Gapped Environment]] because a Disconnected Environment may lack current connectivity without necessarily implementing the controlled physical or logical isolation associated with an Air-Gapped Environment. | Separate requirements, workflows, or policies define those subjects and behaviors. |
| |
| ===== Applies To ===== | ===== Applies To ===== |
| |
| * [[dido:99_annexes:annex-b-terms-and-definitions:c:crucible|Crucible]] | * [[dido:99_annexes:annex-b-terms-and-definitions:c:crucible|Crucible]] |
| | * [[dido:99_annexes:annex-b-terms-and-definitions:d:deployment_operation|Deployment Operations]] |
| * [[dido:99_annexes:annex-b-terms-and-definitions:d:disconnected_environment|Disconnected Environments]] | * [[dido:99_annexes:annex-b-terms-and-definitions:d:disconnected_environment|Disconnected Environments]] |
| * Deployment operations | * Disconnected deployment workflows |
| * Deployment subjects | |
| * Imported artifacts | |
| * Imported dependencies | |
| * Local repositories | |
| * Local configuration sources | |
| * Local credentials | |
| * Local validation resources | |
| * [[dido:99_annexes:annex-b-terms-and-definitions:c:ci_cd_pipeline|CI/CD Pipelines]] | |
| |
| ===== Verification ===== | ===== Verification ===== |
| |
| - Verification SHALL confirm that the tested deployment occurs within a [[dido:99_annexes:annex-b-terms-and-definitions:d:disconnected_environment|Disconnected Environment]] | Verification confirms that: |
| - Verification SHALL confirm that [[dido:99_annexes:annex-b-terms-and-definitions:c:crucible|Crucible]] performs the identified deployment operation | |
| - Verification SHALL confirm that Crucible does not access an external network resource during the deployment operation | |
| - Verification SHALL confirm that the deployment produces the expected deployment result | |
| |
| Verification may include: | - A [[dido:99_annexes:annex-b-terms-and-definitions:d:disconnected_environment|Disconnected Environment]] is selected for testing |
| | - A [[dido:99_annexes:annex-b-terms-and-definitions:d:deployment_operation|Deployment Operation]] is selected for testing |
| * Network isolation testing | - [[dido:99_annexes:annex-b-terms-and-definitions:c:crucible|Crucible]] performs the tested Deployment Operation within the Disconnected Environment |
| * External resource access monitoring | - The Deployment Operation completes without relying on direct electronic communication prohibited by the defined disconnected boundary |
| * Disconnected deployment testing | - The result of the tested Deployment Operation can be determined |
| * Local repository inspection | |
| * Dependency availability inspection | |
| * Deployment output inspection | |
| * Deployment log inspection | |
| | |
| The verification record SHALL identify: | |
| | |
| - The Disconnected Environment | |
| - The deployment operation | |
| - The deployment subjects | |
| - The locally available artifacts and dependencies | |
| - The prohibited external network resources | |
| - The observed network activity | |
| - The deployment result | |
| - The generated [[dido:99_annexes:annex-b-terms-and-definitions:e:evidence|Evidence]] | |
| | |
| ===== Outgoing Traceability ===== | |
| | |
| This requirement realizes: | |
| | |
| * [[dido:02-crusible:99-annexes:annex-c-requirements:01-mission-objectives:mo-004|MO-004]] | |
| * [[dido:02-crusible:99-annexes:annex-c-requirements:01-mission-objectives:mo-006|MO-006]] | |
| | |
| This requirement relates to: | |
| | |
| * [[dido:02-crusible:99-annexes:annex-c-requirements:03-functional-requirements:03-03-deployment-orchestration:start|C.3.3 Deployment Orchestration]] | |
| * [[dido:02-crusible:99-annexes:annex-c-requirements:03-functional-requirements:03-05-air-gap-operations:fr-ag-002|FR-AG-002 — Artifact Export Packages]] | |
| * [[dido:02-crusible:99-annexes:annex-c-requirements:03-functional-requirements:03-05-air-gap-operations:fr-ag-003|FR-AG-003 — Artifact Import Packages]] | |
| * [[dido:02-crusible:99-annexes:annex-c-requirements:03-functional-requirements:03-05-air-gap-operations:fr-ag-004|FR-AG-004 — Baseline Synchronization]] | |
| * [[dido:02-crusible:99-annexes:annex-c-requirements:03-functional-requirements:03-05-air-gap-operations:fr-ag-005|FR-AG-005 — Deployment Traceability Across Disconnected Environments]] | |
| * [[dido:02-crusible:08-dependencies-and-air-gap-operations:start|8. Dependencies and Air Gap Operations]] | |
| |
| ===== Referenced By ===== | ===== Referenced By ===== |
| |
| The wiki Backlinks function provides the current list of pages that reference ''FR-AG-001''. | The following pages reference this requirement: |
| |
| Incoming [[dido:99_annexes:annex-b-terms-and-definitions:t:traceability|Traceability]] should be derived dynamically from backlinks rather than maintained as a duplicate manual list. | {{backlinks>.#dido:02-crusible}} |
| |
| ===== ConOps Relationship ===== | ===== Implementation Status ===== |
| |
| The Crucible Concept of Operations describes a connected-to-disconnected supply chain in which dependencies and artifacts are captured in a Connected Environment, transferred through an authorized boundary, and consumed within a Disconnected Environment. | Implemented and Verified |
| |
| FR-AG-001 establishes the required deployment behavior after the required resources enter the Disconnected Environment. | ===== Requirement Status ===== |
| |
| ===== Delivery Phase ===== | <todo>Review and approve FR-AG-001 as a leaf requirement.</todo> |
| |
| Phase 1 | ---- |
| | ===== Issues ===== |
| |
| ===== Implementation Status ===== | <todo>Determine whether separate requirements identify the resources that must be locally available for disconnected Deployment Operations.</todo> |
| | |
| Not Assessed | |
| | |
| Implementation status requires verification that Crucible performs deployment operations in a Disconnected Environment without accessing any external network resources. | |
| | |
| ===== Requirement Status ===== | |
| |
| Draft | <todo>Determine whether separate requirements define the external communication boundaries used for each Disconnected Environment.</todo> |
| |
| ---- | ---- |
| ===== Notes for Editors ===== | ===== Notes for Editors ===== |
| |
| This requirements page should retain the stable requirement identifier 'FR-AG-001'. | This requirement page retains the stable requirement identifier ''FR-AG-001''. |
| |
| Changes to the Statement SHALL preserve the approved intent of the source requirement. | This page is a leaf requirement page and omits a trailing '':start'' from its namespace. |
| |
| The Source Statement should preserve the original wording from the controlling System Requirements Specification. | The Statement preserves the approved source intent by requiring Crucible to perform Deployment Operations within Disconnected Environments. |
| |
| The Statement should remain limited to the performance of deployment operations within a Disconnected Environment without access to external network resources. | Do not add Artifact export, Artifact import, Dependency Capture, synchronization, Transfer Authorization, Transfer Bundle Integrity, specific deployment subjects, or Air-Gapped Environment obligations unless the controlling requirement changes through an approved requirements process. |
| |
| Requirements for artifact export, artifact import, dependency capture, synchronization, and transfer authorization should remain in their applicable requirement pages. | A [[dido:99_annexes:annex-b-terms-and-definitions:d:disconnected_environment|Disconnected Environment]] can retain internal connectivity. This requirement does not equate disconnected operation with operation in an [[dido:99_annexes:annex-b-terms-and-definitions:a:air-gapped_environment|Air-Gapped Environment]]. |
| | |
| Verification criteria should test only the behavior stated in the normalized Statement and should not introduce additional normative obligations. | |
| | |
| Incoming Traceability should use the wiki Backlinks function rather than a manually maintained list. | |
| |
| To reference this requirement Statement from another wiki page, insert: | To reference this requirement Statement from another wiki page, insert: |
| {{section>dido:02-crusible:99-annexes:annex-c-requirements:03-functional-requirements:03-05-air-gap-operations:fr-ag-001#Statement&noheader&nofooter&noeditbtn}} | {{section>dido:02-crusible:99-annexes:annex-c-requirements:03-functional-requirements:03-05-air-gap-operations:fr-ag-001#Statement&noheader&nofooter&noeditbtn}} |
| </code> | </code> |
| |
| Do not rename this page after an external citation unless a redirect or move plan is in place. | |
| |
| ---- | ---- |