dido:02-crusible:99-annexes:annex-c-requirements:03-functional-requirements:03-05-air-gap-operations:fr-ag-001

Differences

This shows you the differences between two versions of the page.

Link to this comparison view

Both sides previous revision Previous revision
Next revision
Previous revision
dido:02-crusible:99-annexes:annex-c-requirements:03-functional-requirements:03-05-air-gap-operations:fr-ag-001 [2026/07/18 09:50] nick_didodido:02-crusible:99-annexes:annex-c-requirements:03-functional-requirements:03-05-air-gap-operations:fr-ag-001 [2026/07/30 05:56] (current) nick_dido
Line 5: Line 5:
 ===== Statement ===== ===== Statement =====
  
-[[dido:99_annexes:annex-b-terms-and-definitions:c:crucible|Crucible]] SHALL execute an identified [[dido:99_annexes:annex-b-terms-and-definitions:d:deployment_operation|Deployment Operation]] within [[dido:99_annexes:annex-b-terms-and-definitions:d:disconnected_environment|Disconnected Environment]] without direct electronic communication with specified external systems, services, repositories, [[dido:99_annexes:annex-b-terms-and-definitions:p:provider|Providers]], or networks.+[[dido:99_annexes:annex-b-terms-and-definitions:c:crucible|Crucible]] SHALL perform [[dido:99_annexes:annex-b-terms-and-definitions:d:deployment_operation|Deployment Operations]] within [[dido:99_annexes:annex-b-terms-and-definitions:d:disconnected_environment|Disconnected Environments]].
  
-===== Source Statement =====+===== Derived From =====
  
-> The [[dido:99_annexes:annex-b-terms-and-definitions:c:crucible|system]] shall support [[dido:99_annexes:annex-b-terms-and-definitions:d:disconnected_environment|disconnected]] [[dido:99_annexes:annex-b-terms-and-definitions:d:deployment_operation|deployment operations]].+This requirement derives from:
  
-===== Source =====+  * Crucible System Requirements Specification, Version 1.1 Draft, Functional Requirements, FR-AG-001
  
-Crucible System Requirements Specification, Version 1.1 Draft, Functional Requirements, FR-AG-001.+The Original Requirement states:
  
-===== Assessment =====+> //The system shall support disconnected deployment operations.//[[dido:02-crusible:99-annexes:annex-b:cr-001|[C1]]]
  
-The source statement identifies the intended operating condition but does not provide a fully testable formulation.+FR-AG-001:
  
-The following Specification Discipline and Authoring findings apply:+  * Replaces **The system** with the defined system name [[dido:99_annexes:annex-b-terms-and-definitions:c:crucible|Crucible]] 
 +  * Changes **shall** to the established uppercase normative form **SHALL** 
 +  * Replaces the weak verb **support** with the observable behavior **perform** 
 +  * Uses the defined [[dido:99_annexes:annex-b-terms-and-definitions:d:deployment_operation|Deployment Operation]] concept 
 +  * Uses the defined [[dido:99_annexes:annex-b-terms-and-definitions:d:disconnected_environment|Disconnected Environment]] concept
  
-  * **The system** does not use the defined system name +No other substantive normalization is required.
-  * **shall** does not follow the established uppercase normative convention +
-  * **Support** is a weak verb that does not identify the required behavior +
-  * **Disconnected deployment operations** does not use the defined [[dido:99_annexes:annex-b-terms-and-definitions:d:deployment_operation|Deployment Operation]] concept +
-  * **Disconnected deployment operations** does not use the defined [[dido:99_annexes:annex-b-terms-and-definitions:d:disconnected_environment|Disconnected Environment]] concept +
-  * The source statement does not identify the communication restrictions that govern execution +
-  * The source statement does not identify the external subjects with which communication is prohibited +
-  * The source statement does not prescribe a deployment tool, transfer mechanism, repository implementation, network technology, [[dido:99_annexes:annex-b-terms-and-definitions:p:provider|Provider]], or target platform+
  
-The normalized Statement:+===== Rationale =====
  
-  * Replaces **The system** with [[dido:99_annexes:annex-b-terms-and-definitions:c:crucible|Crucible]] +[[dido:99_annexes:annex-b-terms-and-definitions:d:disconnected_environment|Disconnected Environment]] operates without direct electronic communication with specified external systems, services, repositories, Providers, or networks.
-  * Replaces **support** with the direct behavior **execute** +
-  * Uses the defined [[dido:99_annexes:annex-b-terms-and-definitions:d:deployment_operation|Deployment Operation]] concept +
-  * Uses the defined [[dido:99_annexes:annex-b-terms-and-definitions:d:disconnected_environment|Disconnected Environment]] concept +
-  * Requires identification of the Deployment Operation +
-  * Identifies the external communication restrictions that govern execution +
-  * Preserves implementation independence +
-  * Retains one primary required behavior+
  
-The normalized Statement does not require every [[dido:99_annexes:annex-b-terms-and-definitions:d:dependency|Dependency]] to originate within the Disconnected Environment.+Performing [[dido:99_annexes:annex-b-terms-and-definitions:d:deployment_operation|Deployment Operations]] within such an environment requires the necessary software, [[dido:99_annexes:annex-b-terms-and-definitions:d:dependency|Dependencies]], configuration information, credentials, repositories, and [[dido:99_annexes:annex-b-terms-and-definitions:a:artifact|Artifacts]] to be locally available or otherwise accessible within the permitted operational boundary.
  
-Separate requirements govern:+This requirement establishes disconnected deployment behavior without prescribing:
  
 +  * The Deployment Operation
 +  * The deployment subjects
 +  * The external systems from which the environment is disconnected
 +  * The transfer mechanism
   * [[dido:99_annexes:annex-b-terms-and-definitions:d:dependency_capture|Dependency Capture]]   * [[dido:99_annexes:annex-b-terms-and-definitions:d:dependency_capture|Dependency Capture]]
-  * Controlled transfer 
   * Artifact export   * Artifact export
   * Artifact import   * Artifact import
Line 52: Line 45:
   * [[dido:99_annexes:annex-b-terms-and-definitions:t:transfer_bundle_integrity|Transfer Bundle Integrity]]   * [[dido:99_annexes:annex-b-terms-and-definitions:t:transfer_bundle_integrity|Transfer Bundle Integrity]]
   * Baseline synchronization   * Baseline synchronization
 +  * Air-gapped operation
  
-===== Rationale ===== +Separate requirementsworkflows, or policies define those subjects and behaviors.
- +
-A [[dido:99_annexes:annex-b-terms-and-definitions:d:disconnected_environment|Disconnected Environment]] operates without direct electronic communication with specified external systemsservices, repositories, [[dido:99_annexes:annex-b-terms-and-definitions:p:provider|Providers]], or networks. +
- +
-The Disconnected Environment therefore relies on locally available: +
- +
-  * Software +
-  * [[dido:99_annexes:annex-b-terms-and-definitions:d:dependency|Dependencies]] +
-  * Repositories +
-  * Services +
-  * Configuration information +
-  * Credentials +
-  * Operational data +
-  * [[dido:99_annexes:annex-b-terms-and-definitions:a:artifact|Artifacts]] +
-  * Validation resources +
- +
-Controlled transfer processes supply new or updated material when the Disconnected Environment cannot communicate directly with the original source. +
- +
-Before [[dido:99_annexes:annex-b-terms-and-definitions:c:crucible|Crucible]] executes a [[dido:99_annexes:annex-b-terms-and-definitions:d:deployment_operation|Deployment Operation]], the Disconnected Environment must contain or have authorized local access to the Artifacts, configurations, Dependencies, credentials, metadata, and other resources required by that Deployment Operation. +
- +
-A Deployment Operation may create, configure, update, replace, or remove: +
- +
-  * [[dido:99_annexes:annex-b-terms-and-definitions:i:infrastructure_resource|Infrastructure Resources]] +
-  * [[dido:99_annexes:annex-b-terms-and-definitions:v:virtual_machine|Virtual Machines]] +
-  * [[dido:99_annexes:annex-b-terms-and-definitions:k:kubernetes_cluster|Kubernetes Clusters]] +
-  * [[dido:99_annexes:annex-b-terms-and-definitions:c:containerized_workload|Containerized Workloads]] +
-  * [[dido:99_annexes:annex-b-terms-and-definitions:p:platform_service|Platform Services]] +
-  * Configuration +
-  * Relationships among deployed subjects +
- +
-A Deployment Operation may use: +
- +
-  * A [[dido:99_annexes:annex-b-terms-and-definitions:c:crucible_description|Crucible Description]] +
-  * An [[dido:99_annexes:annex-b-terms-and-definitions:i:infrastructure_configuration|Infrastructure Configuration]] +
-  * An [[dido:99_annexes:annex-b-terms-and-definitions:i:infrastructure_baseline|Infrastructure Baseline]] +
-  * A [[dido:99_annexes:annex-b-terms-and-definitions:m:machine_image|Machine Image]] +
-  * A [[dido:99_annexes:annex-b-terms-and-definitions:c:container_image|Container Image]] +
-  * [[dido:99_annexes:annex-b-terms-and-definitions:p:platform_independent_information|Platform Independent Information]] +
-  * [[dido:99_annexes:annex-b-terms-and-definitions:p:platform_specific_information|Platform Specific Information]] +
- +
-Related deployment activities may include: +
- +
-  * [[dido:99_annexes:annex-b-terms-and-definitions:d:deployment_validation|Deployment Validation]] +
-  * [[dido:99_annexes:annex-b-terms-and-definitions:d:deployment_rollback|Deployment Rollback]] +
- +
-A Disconnected Environment may retain internal network connectivity among its components. The communication restriction applies to the specified external systems, services, repositories, Providers, or networks identified by the applicable operational boundary. +
- +
-A Disconnected Environment differs from an [[dido:99_annexes:annex-b-terms-and-definitions:a:air-gapped_environment|Air-Gapped Environment]]: +
- +
-  * A Disconnected Environment operates without direct electronic communication with specified external subjects +
-  * An Air-Gapped Environment is separated from external subjects by an intentionally maintained [[dido:99_annexes:annex-b-terms-and-definitions:a:air_gap|Air Gap]] +
- +
-An Air-Gapped Environment is a specialized Disconnected Environment.+
  
 ===== Applies To ===== ===== Applies To =====
Line 114: Line 56:
   * [[dido:99_annexes:annex-b-terms-and-definitions:d:deployment_operation|Deployment Operations]]   * [[dido:99_annexes:annex-b-terms-and-definitions:d:deployment_operation|Deployment Operations]]
   * [[dido:99_annexes:annex-b-terms-and-definitions:d:disconnected_environment|Disconnected Environments]]   * [[dido:99_annexes:annex-b-terms-and-definitions:d:disconnected_environment|Disconnected Environments]]
-  * Deployment subjects +  * Disconnected deployment workflows
-  * [[dido:99_annexes:annex-b-terms-and-definitions:a:artifact|Artifacts]] +
-  * [[dido:99_annexes:annex-b-terms-and-definitions:d:dependency|Dependencies]] +
-  * Local repositories +
-  * Local configuration sources +
-  * Local credentials +
-  * Local validation resources +
-  * [[dido:99_annexes:annex-b-terms-and-definitions:i:infrastructure_resource|Infrastructure Resources]] +
-  * [[dido:99_annexes:annex-b-terms-and-definitions:v:virtual_machine|Virtual Machines]] +
-  * [[dido:99_annexes:annex-b-terms-and-definitions:k:kubernetes_cluster|Kubernetes Clusters]] +
-  * [[dido:99_annexes:annex-b-terms-and-definitions:c:containerized_workload|Containerized Workloads]] +
-  * [[dido:99_annexes:annex-b-terms-and-definitions:p:platform_service|Platform Services]] +
-  * [[dido:99_annexes:annex-b-terms-and-definitions:c:ci_cd_pipeline|CI/CD Pipelines]]+
  
 ===== Verification ===== ===== Verification =====
  
-  - Verification SHALL confirm that the tested environment satisfies the definition of a [[dido:99_annexes:annex-b-terms-and-definitions:d:disconnected_environment|Disconnected Environment]] +Verification confirms that:
-  - Verification SHALL identify the [[dido:99_annexes:annex-b-terms-and-definitions:d:deployment_operation|Deployment Operation]] selected for testing +
-  - Verification SHALL identify the external systems, services, repositories, [[dido:99_annexes:annex-b-terms-and-definitions:p:provider|Providers]], or networks with which direct electronic communication is prohibited +
-  - Verification SHALL confirm that [[dido:99_annexes:annex-b-terms-and-definitions:c:crucible|Crucible]] executes the identified Deployment Operation within the Disconnected Environment +
-  - Verification SHALL confirm that Crucible does not establish direct electronic communication with the specified external systems, services, repositories, Providers, or networks during the Deployment Operation +
-  - Verification SHALL confirm that the Deployment Operation produces the expected deployment result+
  
-Verification may include: +  [[dido:99_annexes:annex-b-terms-and-definitions:d:disconnected_environment|Disconnected Environment]] is selected for testing 
- +  - [[dido:99_annexes:annex-b-terms-and-definitions:d:deployment_operation|Deployment Operation]] is selected for testing 
-  * Disconnected deployment testing +  - [[dido:99_annexes:annex-b-terms-and-definitions:c:crucible|Crucible]] performs the tested Deployment Operation within the Disconnected Environment 
-  * Network boundary inspection +  - The Deployment Operation completes without relying on direct electronic communication prohibited by the defined disconnected boundary 
-  * External communication monitoring +  - The result of the tested Deployment Operation can be determined
-  * Local repository inspection +
-  * [[dido:99_annexes:annex-b-terms-and-definitions:d:dependency|Dependency]] availability inspection +
-  * Deployment output inspection +
-  * Deployment log inspection +
-  * [[dido:99_annexes:annex-b-terms-and-definitions:d:deployment_validation|Deployment Validation]] +
- +
-The verification record SHALL identify: +
- +
-  - The [[dido:99_annexes:annex-b-terms-and-definitions:d:disconnected_environment|Disconnected Environment]] +
-  - The tested [[dido:99_annexes:annex-b-terms-and-definitions:d:deployment_operation|Deployment Operation]] +
-  - The deployment subjects +
-  - The locally available [[dido:99_annexes:annex-b-terms-and-definitions:a:artifact|Artifacts]] +
-  - The locally available [[dido:99_annexes:annex-b-terms-and-definitions:d:dependency|Dependencies]] +
-  - The specified external systems, services, repositories, [[dido:99_annexes:annex-b-terms-and-definitions:p:provider|Providers]], or networks +
-  - The observed electronic communication +
-  - The deployment result +
-  - The generated [[dido:99_annexes:annex-b-terms-and-definitions:e:evidence|Evidence]] +
- +
-===== Outgoing Traceability ===== +
- +
-This requirement realizes: +
- +
-  * [[dido:02-crusible:99-annexes:annex-c-requirements:01-mission-objectives:mo-004|MO-004]] +
-  * [[dido:02-crusible:99-annexes:annex-c-requirements:01-mission-objectives:mo-006|MO-006]] +
- +
-This requirement relates to: +
- +
-  * [[dido:02-crusible:99-annexes:annex-c-requirements:03-functional-requirements:03-03-deployment-orchestration:start|C.3.3 Deployment Orchestration]] +
-  * [[dido:02-crusible:99-annexes:annex-c-requirements:03-functional-requirements:03-05-air-gap-operations:fr-ag-002|FR-AG-002 — Artifact Export Packages]] +
-  * [[dido:02-crusible:99-annexes:annex-c-requirements:03-functional-requirements:03-05-air-gap-operations:fr-ag-003|FR-AG-003 — Artifact Import Packages]] +
-  * [[dido:02-crusible:99-annexes:annex-c-requirements:03-functional-requirements:03-05-air-gap-operations:fr-ag-004|FR-AG-004 — Baseline Synchronization]] +
-  * [[dido:02-crusible:99-annexes:annex-c-requirements:03-functional-requirements:03-05-air-gap-operations:fr-ag-005|FR-AG-005 — Deployment Traceability Across Disconnected Environments]] +
-  * [[dido:02-crusible:99-annexes:annex-c-requirements:03-functional-requirements:03-10-dependency-capture-and-offline-transfer:start|C.3.10 Dependency Capture and Offline Transfer]] +
-  * [[dido:02-crusible:08-dependencies-and-air-gap-operations:start|8. Dependencies and Air Gap Operations]]+
  
 ===== Referenced By ===== ===== Referenced By =====
  
-The wiki Backlinks function provides the current list of pages that reference ''FR-AG-001''.+The following pages reference this requirement:
  
-Incoming [[dido:99_annexes:annex-b-terms-and-definitions:t:traceability|Traceability]] should be derived dynamically from backlinks rather than maintained as a duplicate manual list.+{{backlinks>.#dido:02-crusible}}
  
-Backlinks identify incoming references but do not define the semantics of each relationship. Referencing pages should identify whether the relationship represents realization, refinement, verification, dependency, or another defined traceability relationship.+===== Implementation Status =====
  
-===== ConOps Relationship =====+Implemented and Verified
  
-The Crucible Concept of Operations describes a connected-to-disconnected supply chain in which [[dido:99_annexes:annex-b-terms-and-definitions:d:dependency|Dependencies]] and [[dido:99_annexes:annex-b-terms-and-definitions:a:artifact|Artifacts]] are captured in a [[dido:99_annexes:annex-b-terms-and-definitions:c:connected_environment|Connected Environment]], transferred across an authorized [[dido:99_annexes:annex-b-terms-and-definitions:t:transfer_boundary|Transfer Boundary]], and consumed within a [[dido:99_annexes:annex-b-terms-and-definitions:d:disconnected_environment|Disconnected Environment]].+===== Requirement Status =====
  
-FR-AG-001 establishes the required behavior for executing [[dido:99_annexes:annex-b-terms-and-definitions:d:deployment_operation|Deployment Operation]] after the required Artifacts and Dependencies enter the Disconnected Environment.+<todo>Review and approve FR-AG-001 as leaf requirement.</todo>
  
-===== Delivery Phase =====+---- 
 +===== Issues =====
  
-Phase 1+<todo>Determine whether separate requirements identify the resources that must be locally available for disconnected Deployment Operations.</todo>
  
-===== Implementation Status ===== +<todo>Determine whether separate requirements define the external communication boundaries used for each Disconnected Environment.</todo>
- +
-Not Assessed +
- +
-Implementation status requires verification that [[dido:99_annexes:annex-b-terms-and-definitions:c:crucible|Crucible]] executes an identified [[dido:99_annexes:annex-b-terms-and-definitions:d:deployment_operation|Deployment Operation]] within a [[dido:99_annexes:annex-b-terms-and-definitions:d:disconnected_environment|Disconnected Environment]] without direct electronic communication with specified external systems, services, repositories, [[dido:99_annexes:annex-b-terms-and-definitions:p:provider|Providers]], or networks. +
- +
-===== Requirement Status ===== +
- +
-Draft +
- +
-The source System Requirements Specification identifies Version 1.1 as a draft.+
  
 ---- ----
 ===== Notes for Editors ===== ===== Notes for Editors =====
  
-This requirement page should retain the stable requirement identifier ''FR-AG-001''.+This requirement page retains the stable requirement identifier ''FR-AG-001''.
  
-Changes to the Statement SHALL preserve the approved intent of the source requirement.+This page is a leaf requirement page and omits a trailing '':start'' from its namespace.
  
-The Source Statement should preserve the original visible wording from the controlling System Requirements Specification while linking applicable words and phrases to the controlling Terms and Definitions entries.+The Statement preserves the approved source intent by requiring Crucible to perform Deployment Operations within Disconnected Environments.
  
-The Statement should remain limited to execution of an identified Deployment Operation within a Disconnected Environment without direct electronic communication with specified external systemsservicesrepositoriesProviders, or networks.+Do not add Artifact exportArtifact importDependency Capturesynchronization, Transfer Authorization, Transfer Bundle Integrity, specific deployment subjects, or Air-Gapped Environment obligations unless the controlling requirement changes through an approved requirements process.
  
-Requirements for Artifact export, Artifact import, Dependency Capture, synchronization, Transfer Authorization, and Transfer Bundle Integrity should remain in their applicable requirement pages. +A [[dido:99_annexes:annex-b-terms-and-definitions:d:disconnected_environment|Disconnected Environment]] can retain internal connectivity. This requirement does not equate disconnected operation with operation in an [[dido:99_annexes:annex-b-terms-and-definitions:a:air-gapped_environment|Air-Gapped Environment]].
- +
-Verification criteria should test only the behavior stated in the normalized Statement and should not introduce additional normative obligations. +
- +
-Incoming Traceability should use the wiki Backlinks function rather than manually maintained list.+
  
 To reference this requirement Statement from another wiki page, insert: To reference this requirement Statement from another wiki page, insert:
Line 229: Line 107:
 {{section>dido:02-crusible:99-annexes:annex-c-requirements:03-functional-requirements:03-05-air-gap-operations:fr-ag-001#Statement&noheader&nofooter&noeditbtn}} {{section>dido:02-crusible:99-annexes:annex-c-requirements:03-functional-requirements:03-05-air-gap-operations:fr-ag-001#Statement&noheader&nofooter&noeditbtn}}
 </code> </code>
- 
-Do not rename this page after an external citation unless a redirect or move plan is in place. 
  
 ---- ----
  • dido/02-crusible/99-annexes/annex-c-requirements/03-functional-requirements/03-05-air-gap-operations/fr-ag-001.1784393423.txt.gz
  • Last modified: 2026/07/18 09:50
  • by nick_dido