FedRAMP High Deployment Guide

Architecture overview, NIST 800-53 High control mapping, air-gap procedures.

NIST controls:Full NIST 800-53 High baseline
Last updated:2026-03-22
Category:Technical
# FedRAMP High Deployment — Cloud Air-Gap Without USB ## The Misconception "Air-gap" for FedRAMP High doesn't mean physically disconnected. It means: - **No unauthorized egress** — workloads can't phone home to arbitrary internet endpoints - **Controlled ingress** — only authorized traffic from authorized sources - **Data sovereignty** — data stays within the FedRAMP authorization boundary - **Supply chain control** — all software artifacts verified and auditable AWS GovCloud, Azure Government, and GCP Assured Workloads provide this. You never touch a USB drive. ## How It Actually Works (No USB) ``` Arivaran Commercial Hub FedRAMP Authorization Boundary (SOC 2, commercial cloud) (GovCloud / Azure Gov / GCP Assured) ┌──────────────────────┐ ┌──────────────────────────────────┐ │ Harbor Registry │ │ │ │ (images, charts) │─── IPsec ──→│ ECR/ACR/GAR (mirror) │ │ │ VPN or │ All images scanned + signed │ │ Hub API │ PrivateLink│ │ │ (bootstrap, PKI) │────────────→│ Satellite (EKS/AKS/GKE) │ │ │ │ step-ca (local PKI) │ │ │ │ CNPG+Citus (RDS or self-mgd) │ │ │ │ S3/Blob/GCS (local storage) │ │ │ │ KuiperDesk services │ │ │ │ │ │ │←── IPsec ───│ Heartbeat + metrics only │ │ │ (metadata │ (no backup data crosses boundary)│ │ │ only) │ │ └──────────────────────┘ └──────────────────────────────────┘ ``` ## Cloud-Specific Transfer Mechanisms (No USB) ### AWS GovCloud | Mechanism | Use Case | How | |-----------|----------|-----| | **ECR Cross-Account Replication** | Container images | Push to commercial ECR → auto-replicate to GovCloud ECR. No manual transfer. | | **S3 Cross-Region Replication** | Helm charts, agent binaries | S3 in commercial → replicate to GovCloud S3 bucket | | **AWS PrivateLink** | Hub → satellite API calls | Private connectivity, no internet traversal | | **AWS Transit Gateway** | Network peering | Connect commercial VPC to GovCloud VPC | | **AWS Transfer Family** | Bulk data transfer | SFTP/FTPS for large artifact bundles | | **Snowball Edge** | True air-gap (SCIF) | Physical device only for IL5/IL6 | ```yaml # values-fedramp-high-aws.yaml cloud: provider: aws region: us-gov-west-1 # GovCloud region fipsEndpoints: true # Use FIPS 140-2 validated endpoints registry: # ECR in GovCloud (replicated from commercial Harbor) host: "<account-id>.dkr.ecr.us-gov-west-1.amazonaws.com" mirror: source: "registry.arivaran.ai" target: "<govcloud-ecr>" replicationType: cross-account # automatic, no USB pki: provider: step-ca # local CA, not Let's Encrypt # ACM Private CA also available on GovCloud (FedRAMP authorized) # But step-ca gives us full control stepCA: enabled: true fipsMode: true # step-ca compiled with FIPS Go crypto storage: backend: aws-s3 s3: bucket: "kuiperdesk-<tenant>-govcloud" kmsKeyArn: "arn:aws-us-gov:kms:..." # GovCloud KMS encryption: aws:kms # SSE-KMS (FIPS 140-2 Level 3) objectLock: true # WORM for compliance retention database: backend: rds rds: instanceClass: db.r6g.large engine: aurora-postgresql engineVersion: "15.4" encrypted: true kmsKeyArn: "arn:aws-us-gov:kms:..." fipsEndpoint: true multiAz: true # HA within GovCloud region networking: # PrivateLink from commercial hub → GovCloud satellite hubConnection: privatelink privateLink: serviceName: "com.amazonaws.vpce.us-gov-west-1.vpce-svc-xxx" # No network overlay needed — PrivateLink provides private connectivity ``` ### Azure Government | Mechanism | Use Case | How | |-----------|----------|-----| | **ACR Geo-Replication** | Container images | Push to commercial ACR → geo-replicate to Azure Gov ACR | | **Azure Private Link** | Hub → satellite API | Private connectivity across tenants | | **Azure ExpressRoute** | Dedicated connection | Private peering between commercial and gov | | **Azure Blob Replication** | Charts, binaries | Object replication across regions | ```yaml # values-fedramp-high-azure.yaml cloud: provider: azure region: usgovvirginia # Azure Government region registry: host: "<registry>.azurecr.us" # Azure Gov ACR database: backend: azure-postgresql azurePostgres: sku: GP_Standard_D2s_v3 encrypted: true geoRedundantBackup: true storage: backend: azure-blob azureBlob: accountName: "kuiperdesk<tenant>gov" encryption: microsoft-managed # or customer-managed HSM keys immutableStorage: true # legal hold / time-based retention ``` ### GCP Assured Workloads | Mechanism | Use Case | How | |-----------|----------|-----| | **Artifact Registry Replication** | Container images | Push to commercial → replicate to Assured project | | **VPC Service Controls** | Data boundary | Prevents data exfiltration at API level | | **Private Service Connect** | Hub → satellite | Private connectivity | | **Cloud KMS (FIPS 140-2 L3)** | Encryption keys | HSM-backed keys | ## True Air-Gap (USB Required — IL5/IL6/SCIF Only) USB sneakernet is ONLY needed for: - **IL5/IL6** (Impact Level 5/6) — classified environments - **SCIF** (Sensitive Compartmented Information Facility) — no network at all - **Submarine/ship** — literally disconnected - **Field deployment** — military forward operating base For these, the USB/ISO bundle from our air-gap policy applies. But this is <1% of FedRAMP deployments. ## How This Eases FedRAMP High Certification ### What Auditors Check (and How We Pass) | NIST 800-53 Control | What Auditors Want | What We Provide | |---------------------|-------------------|-----------------| | **AC-2** Account management | Centralized identity | Keycloak on satellite (own realm, own user store) | | **AC-17** Remote access | Controlled, encrypted | PrivateLink / IPsec only — no public internet | | **AU-2/AU-3** Audit events | Complete audit trail | Every API call logged, immutable audit table in Citus | | **CA-3** System interconnections | Documented, authorized | Hub ↔ satellite ISA documented, only metadata crosses | | **CM-2** Baseline config | Reproducible, versioned | Helm chart = deterministic, values-fedramp.yaml = config baseline | | **CM-7** Least functionality | Minimal services | Only KuiperDesk services, no extras, network policies enforce | | **IA-2** Identification | MFA, unique accounts | Keycloak with FIDO2/TOTP, required of every account in a FedRAMP deployment (`values-fedramp.yaml`); a fresh second factor before privileged dashboard actions; per-agent TPM identity | | **IA-5** Authenticator mgmt | Rotation, strength | step-ca auto-rotates, TPM non-exportable keys | | **IR-4** Incident handling | Revocation capability | Satellite CA revocable in < 60s (see PKI trust policy) | | **MP-4** Media protection | Encrypt removable media | Only for IL5+, USB bundle is encrypted + checksummed | | **PE-17** Alternate work site | Remote backup access | Satellite on customer premises, dashboard accessible locally | | **PL-4** Rules of behavior | Acceptable use | Tenant TOS + technical enforcement (network policies) | | **RA-5** Vulnerability scanning | Continuous scanning | Trivy on Harbor (pre-deployment), runtime: Tetragon | | **SA-12** Supply chain | Provenance, integrity | All images from Harbor, cosign signed, SBOM available | | **SC-7** Boundary protection | Network boundary | GovCloud VPC + PrivateLink + Cilium network policies | | **SC-8** Transmission confidentiality | Encrypt all transit | TLS 1.3 everywhere, FIPS 140-2 validated crypto | | **SC-12** Crypto key management | FIPS validated | CloudHSM root (Level 3), step-ca FIPS mode, KMS for data | | **SC-13** Cryptographic protection | FIPS algorithms | All crypto modules FIPS 140-2 validated | | **SC-28** Protection at rest | Encrypt all storage | RDS encryption (KMS), S3 SSE-KMS, EBS encryption | | **SI-7** Software integrity | Verified, signed | cosign signatures on all images, Helm chart provenance | ### What We Already Have vs What's Needed | Capability | Status | Notes | |-----------|--------|-------| | FIPS 140-2 crypto (agent) | **Ready** | AlmaLinux FIPS mode, OpenSSL FIPS provider | | FIPS 140-2 crypto (services) | **Ready** | C++ services use FIPS-validated TLS | | FIPS 140-2 crypto (CA) | **Ready** | CloudHSM Level 3 root, step-ca FIPS mode | | Encryption at rest | **Ready** | LUKS (bare metal), KMS (cloud), Citus pgcrypto | | Encryption in transit | **Ready** | TLS 1.3 everywhere, gRPC-over-TLS | | Network boundary | **Ready** | Cilium policies + GovCloud VPC + PrivateLink | | Audit logging | **Ready** | Immutable audit table, OTel export | | Vulnerability scanning | **Ready** | Trivy + Harbor pre-deployment scan | | Image signing | **Ready** | cosign via Harbor | | Identity management | **Ready** | Keycloak + TPM attestation | | CA revocation | **Ready** | CRL + OCSP + hub blocklist | | Satellite isolation | **Ready** | Per-satellite intermediate CA, data sovereignty | | IaC reproducibility | **Ready** | Helm chart + values file = deterministic baseline | | SBOM generation | **Needed** | Generate per-image SBOM (Syft/Trivy) | | POA&M tracking | **Needed** | Plan of Action & Milestones document | | SSP (System Security Plan) | **Needed** | The actual FedRAMP documentation package | | 3PAO assessment | **Needed** | Third-party assessment by accredited org | | Continuous monitoring | **Partial** | Have metrics/alerts, need ConMon reporting format | ### FedRAMP Certification Path 1. **Select sponsor** — federal agency willing to use KuiperDesk (ATO sponsor) 2. **Engage 3PAO** — accredited assessor (e.g., Coalfire, Schellman, A-LIGN) 3. **Prepare SSP** — System Security Plan documenting all 325+ controls 4. **Readiness assessment** — 3PAO reviews SSP + architecture 5. **Full assessment** — 3PAO tests all controls (penetration test, config review) 6. **Remediate** — Fix any findings 7. **Authorization** — Agency ATO + FedRAMP PMO listing 8. **Continuous monitoring** — Monthly vulnerability scans, annual assessment **Estimated timeline**: 6-12 months from engagement to P-ATO **Estimated cost**: $300K-$500K (3PAO fees + remediation effort) ### Our Architectural Advantages for FedRAMP 1. **Satellite model = clean authorization boundary** — customer data never leaves their GovCloud VPC. The hub (commercial) is a separate system with its own SOC 2. 2. **Helm chart = deterministic baseline** — CM-2 compliance is trivial: `helm template` outputs the exact expected state. 3. **step-ca = FIPS crypto we control** — no dependency on external CA (Let's Encrypt is NOT FedRAMP authorized). 4. **Per-satellite intermediate CA** — SC-12 key management is clean: each satellite has isolated PKI, revocable from hub. 5. **Citus tenant isolation** — even within a satellite, data is distributed by tenant_id. Multi-tenant Tier B/C satellites get row-level isolation. 6. **Agent TPM identity** — IA-2/IA-5 authenticator management: non-exportable hardware-bound keys, auto-rotating certificates. ## Revision History | Date | Change | Author | |------|--------|--------| | 2026-03-22 | Initial — GovCloud deployment, cloud transfer mechanisms, FedRAMP control mapping, certification path | Navid Ahmadi (Compliance), Claire Dubois (Security), Tariq Hassan (Platform) | | 2026-09-30 | IA-2: a second factor is required of every account in a FedRAMP deployment (`values-fedramp.yaml`, `compliance.fedramp`), #20984 | Engineering |

This document is part of the Arivaran Twin compliance program. For questions or the latest version, contact compliance@arivaran.ai.

Release-ready. Saved on this browser.