Skip to content

docs(edge-sync): document air-gap bundle export - #21

Closed
xe-nvdk wants to merge 3 commits into
mainfrom
docs/edge-sync-airgap
Closed

xe-nvdk wants to merge 3 commits into
mainfrom
docs/edge-sync-airgap

Conversation

@xe-nvdk

@xe-nvdk xe-nvdk commented Aug 7, 2026

Copy link
Copy Markdown
Member

Summary

Documents the spoke half of the air-gap transport (Basekick-Labs/arc#581): the [edge_sync.spoke.bundle] block, writing and inspecting a bundle, the destination allow-list, the exported-vs-synced distinction, and reverting a drive that never arrived.

Explains the two format decisions rather than just stating them — a directory over an archive because resume is free and the contents are auditable with ls and sha256sum, which is what matters when someone has to inspect what crosses an air gap.

States what is NOT in the release

  • The hub-side import — a bundle can be written, verified, and inspected today; importing it lands next.
  • The acknowledgment, so exported files do not reach synced and are not pruned. On a long-running air-gap spoke the ledger grows until that ships.
  • Bundles are signed, not encrypted. The manifest gives integrity and authenticity; the Parquet files are readable by anyone holding the drive.

Ships alongside Basekick-Labs/arc#581; every documented endpoint, config key, and status code was verified against the shipped code rather than the design doc.

🤖 Generated with Claude Code

Covers the spoke half of the air-gap transport (Basekick-Labs/arc PR 9b):
the [edge_sync.spoke.bundle] block, writing and inspecting a bundle, the
destination allow-list, the exported-vs-synced distinction, and reverting
a drive that never arrived.

Explains the two format decisions rather than just stating them: a
directory over an archive because resume is free and the contents are
auditable with ls and sha256sum, which matters when someone has to
inspect what crosses an air gap.

States what is NOT in the release: the hub-side import, the
acknowledgment that advances exported to synced (so ledgers do not prune
yet), and that bundles are signed but not encrypted.

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
Covers the import half (Basekick-Labs/arc PR 9c): the [edge_sync.import]
block, importing a drive, the three refusals an operator will actually
meet, and the import history endpoint.

Explains why a duplicate drive is refused by a dedup ledger rather than a
timestamp window — the online freshness check works because a request is
in flight, and a bundle is not. Notes the (spoke_id, bundle_id) key, so a
compromised spoke cannot block another's future drives.

Documents cluster-mode Raft batching, since a 2,500-file bundle costing 3
proposals instead of 2,500 is the kind of thing an operator sizing a
cluster needs to know.

Removes the "hub-side import is not in this release" limitation. The
acknowledgment limitation stays.

Co-Authored-By: Claude Opus 5 (1M context) <noreply@anthropic.com>
docs(edge-sync): document hub-side air-gap import
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant