# FedRAMP High Deployment — Cloud Air-Gap Without USB
## The Misconception
"Air-gap" for FedRAMP High doesn't mean physically disconnected. It means:
- **No unauthorized egress** — workloads can't phone home to arbitrary internet endpoints
- **Controlled ingress** — only authorized traffic from authorized sources
- **Data sovereignty** — data stays within the FedRAMP authorization boundary
- **Supply chain control** — all software artifacts verified and auditable
AWS GovCloud, Azure Government, and GCP Assured Workloads provide this. You never touch a USB drive.
## How It Actually Works (No USB)
```
Arivaran Commercial Hub FedRAMP Authorization Boundary
(SOC 2, commercial cloud) (GovCloud / Azure Gov / GCP Assured)
┌──────────────────────┐ ┌──────────────────────────────────┐
│ Harbor Registry │ │ │
│ (images, charts) │─── IPsec ──→│ ECR/ACR/GAR (mirror) │
│ │ VPN or │ All images scanned + signed │
│ Hub API │ PrivateLink│ │
│ (bootstrap, PKI) │────────────→│ Satellite (EKS/AKS/GKE) │
│ │ │ step-ca (local PKI) │
│ │ │ CNPG+Citus (RDS or self-mgd) │
│ │ │ S3/Blob/GCS (local storage) │
│ │ │ KuiperDesk services │
│ │ │ │
│ │←── IPsec ───│ Heartbeat + metrics only │
│ │ (metadata │ (no backup data crosses boundary)│
│ │ only) │ │
└──────────────────────┘ └──────────────────────────────────┘
```
## Cloud-Specific Transfer Mechanisms (No USB)
### AWS GovCloud
| Mechanism | Use Case | How |
|-----------|----------|-----|
| **ECR Cross-Account Replication** | Container images | Push to commercial ECR → auto-replicate to GovCloud ECR. No manual transfer. |
| **S3 Cross-Region Replication** | Helm charts, agent binaries | S3 in commercial → replicate to GovCloud S3 bucket |
| **AWS PrivateLink** | Hub → satellite API calls | Private connectivity, no internet traversal |
| **AWS Transit Gateway** | Network peering | Connect commercial VPC to GovCloud VPC |
| **AWS Transfer Family** | Bulk data transfer | SFTP/FTPS for large artifact bundles |
| **Snowball Edge** | True air-gap (SCIF) | Physical device only for IL5/IL6 |
```yaml
# values-fedramp-high-aws.yaml
cloud:
provider: aws
region: us-gov-west-1 # GovCloud region
fipsEndpoints: true # Use FIPS 140-2 validated endpoints
registry:
# ECR in GovCloud (replicated from commercial Harbor)
host: "<account-id>.dkr.ecr.us-gov-west-1.amazonaws.com"
mirror:
source: "registry.arivaran.ai"
target: "<govcloud-ecr>"
replicationType: cross-account # automatic, no USB
pki:
provider: step-ca # local CA, not Let's Encrypt
# ACM Private CA also available on GovCloud (FedRAMP authorized)
# But step-ca gives us full control
stepCA:
enabled: true
fipsMode: true # step-ca compiled with FIPS Go crypto
storage:
backend: aws-s3
s3:
bucket: "kuiperdesk-<tenant>-govcloud"
kmsKeyArn: "arn:aws-us-gov:kms:..." # GovCloud KMS
encryption: aws:kms # SSE-KMS (FIPS 140-2 Level 3)
objectLock: true # WORM for compliance retention
database:
backend: rds
rds:
instanceClass: db.r6g.large
engine: aurora-postgresql
engineVersion: "15.4"
encrypted: true
kmsKeyArn: "arn:aws-us-gov:kms:..."
fipsEndpoint: true
multiAz: true # HA within GovCloud region
networking:
# PrivateLink from commercial hub → GovCloud satellite
hubConnection: privatelink
privateLink:
serviceName: "com.amazonaws.vpce.us-gov-west-1.vpce-svc-xxx"
# No network overlay needed — PrivateLink provides private connectivity
```
### Azure Government
| Mechanism | Use Case | How |
|-----------|----------|-----|
| **ACR Geo-Replication** | Container images | Push to commercial ACR → geo-replicate to Azure Gov ACR |
| **Azure Private Link** | Hub → satellite API | Private connectivity across tenants |
| **Azure ExpressRoute** | Dedicated connection | Private peering between commercial and gov |
| **Azure Blob Replication** | Charts, binaries | Object replication across regions |
```yaml
# values-fedramp-high-azure.yaml
cloud:
provider: azure
region: usgovvirginia # Azure Government region
registry:
host: "<registry>.azurecr.us" # Azure Gov ACR
database:
backend: azure-postgresql
azurePostgres:
sku: GP_Standard_D2s_v3
encrypted: true
geoRedundantBackup: true
storage:
backend: azure-blob
azureBlob:
accountName: "kuiperdesk<tenant>gov"
encryption: microsoft-managed # or customer-managed HSM keys
immutableStorage: true # legal hold / time-based retention
```
### GCP Assured Workloads
| Mechanism | Use Case | How |
|-----------|----------|-----|
| **Artifact Registry Replication** | Container images | Push to commercial → replicate to Assured project |
| **VPC Service Controls** | Data boundary | Prevents data exfiltration at API level |
| **Private Service Connect** | Hub → satellite | Private connectivity |
| **Cloud KMS (FIPS 140-2 L3)** | Encryption keys | HSM-backed keys |
## True Air-Gap (USB Required — IL5/IL6/SCIF Only)
USB sneakernet is ONLY needed for:
- **IL5/IL6** (Impact Level 5/6) — classified environments
- **SCIF** (Sensitive Compartmented Information Facility) — no network at all
- **Submarine/ship** — literally disconnected
- **Field deployment** — military forward operating base
For these, the USB/ISO bundle from our air-gap policy applies. But this is <1% of FedRAMP deployments.
## How This Eases FedRAMP High Certification
### What Auditors Check (and How We Pass)
| NIST 800-53 Control | What Auditors Want | What We Provide |
|---------------------|-------------------|-----------------|
| **AC-2** Account management | Centralized identity | Keycloak on satellite (own realm, own user store) |
| **AC-17** Remote access | Controlled, encrypted | PrivateLink / IPsec only — no public internet |
| **AU-2/AU-3** Audit events | Complete audit trail | Every API call logged, immutable audit table in Citus |
| **CA-3** System interconnections | Documented, authorized | Hub ↔ satellite ISA documented, only metadata crosses |
| **CM-2** Baseline config | Reproducible, versioned | Helm chart = deterministic, values-fedramp.yaml = config baseline |
| **CM-7** Least functionality | Minimal services | Only KuiperDesk services, no extras, network policies enforce |
| **IA-2** Identification | MFA, unique accounts | Keycloak with FIDO2/TOTP, required of every account in a FedRAMP deployment (`values-fedramp.yaml`); a fresh second factor before privileged dashboard actions; per-agent TPM identity |
| **IA-5** Authenticator mgmt | Rotation, strength | step-ca auto-rotates, TPM non-exportable keys |
| **IR-4** Incident handling | Revocation capability | Satellite CA revocable in < 60s (see PKI trust policy) |
| **MP-4** Media protection | Encrypt removable media | Only for IL5+, USB bundle is encrypted + checksummed |
| **PE-17** Alternate work site | Remote backup access | Satellite on customer premises, dashboard accessible locally |
| **PL-4** Rules of behavior | Acceptable use | Tenant TOS + technical enforcement (network policies) |
| **RA-5** Vulnerability scanning | Continuous scanning | Trivy on Harbor (pre-deployment), runtime: Tetragon |
| **SA-12** Supply chain | Provenance, integrity | All images from Harbor, cosign signed, SBOM available |
| **SC-7** Boundary protection | Network boundary | GovCloud VPC + PrivateLink + Cilium network policies |
| **SC-8** Transmission confidentiality | Encrypt all transit | TLS 1.3 everywhere, FIPS 140-2 validated crypto |
| **SC-12** Crypto key management | FIPS validated | CloudHSM root (Level 3), step-ca FIPS mode, KMS for data |
| **SC-13** Cryptographic protection | FIPS algorithms | All crypto modules FIPS 140-2 validated |
| **SC-28** Protection at rest | Encrypt all storage | RDS encryption (KMS), S3 SSE-KMS, EBS encryption |
| **SI-7** Software integrity | Verified, signed | cosign signatures on all images, Helm chart provenance |
### What We Already Have vs What's Needed
| Capability | Status | Notes |
|-----------|--------|-------|
| FIPS 140-2 crypto (agent) | **Ready** | AlmaLinux FIPS mode, OpenSSL FIPS provider |
| FIPS 140-2 crypto (services) | **Ready** | C++ services use FIPS-validated TLS |
| FIPS 140-2 crypto (CA) | **Ready** | CloudHSM Level 3 root, step-ca FIPS mode |
| Encryption at rest | **Ready** | LUKS (bare metal), KMS (cloud), Citus pgcrypto |
| Encryption in transit | **Ready** | TLS 1.3 everywhere, gRPC-over-TLS |
| Network boundary | **Ready** | Cilium policies + GovCloud VPC + PrivateLink |
| Audit logging | **Ready** | Immutable audit table, OTel export |
| Vulnerability scanning | **Ready** | Trivy + Harbor pre-deployment scan |
| Image signing | **Ready** | cosign via Harbor |
| Identity management | **Ready** | Keycloak + TPM attestation |
| CA revocation | **Ready** | CRL + OCSP + hub blocklist |
| Satellite isolation | **Ready** | Per-satellite intermediate CA, data sovereignty |
| IaC reproducibility | **Ready** | Helm chart + values file = deterministic baseline |
| SBOM generation | **Needed** | Generate per-image SBOM (Syft/Trivy) |
| POA&M tracking | **Needed** | Plan of Action & Milestones document |
| SSP (System Security Plan) | **Needed** | The actual FedRAMP documentation package |
| 3PAO assessment | **Needed** | Third-party assessment by accredited org |
| Continuous monitoring | **Partial** | Have metrics/alerts, need ConMon reporting format |
### FedRAMP Certification Path
1. **Select sponsor** — federal agency willing to use KuiperDesk (ATO sponsor)
2. **Engage 3PAO** — accredited assessor (e.g., Coalfire, Schellman, A-LIGN)
3. **Prepare SSP** — System Security Plan documenting all 325+ controls
4. **Readiness assessment** — 3PAO reviews SSP + architecture
5. **Full assessment** — 3PAO tests all controls (penetration test, config review)
6. **Remediate** — Fix any findings
7. **Authorization** — Agency ATO + FedRAMP PMO listing
8. **Continuous monitoring** — Monthly vulnerability scans, annual assessment
**Estimated timeline**: 6-12 months from engagement to P-ATO
**Estimated cost**: $300K-$500K (3PAO fees + remediation effort)
### Our Architectural Advantages for FedRAMP
1. **Satellite model = clean authorization boundary** — customer data never leaves their GovCloud VPC. The hub (commercial) is a separate system with its own SOC 2.
2. **Helm chart = deterministic baseline** — CM-2 compliance is trivial: `helm template` outputs the exact expected state.
3. **step-ca = FIPS crypto we control** — no dependency on external CA (Let's Encrypt is NOT FedRAMP authorized).
4. **Per-satellite intermediate CA** — SC-12 key management is clean: each satellite has isolated PKI, revocable from hub.
5. **Citus tenant isolation** — even within a satellite, data is distributed by tenant_id. Multi-tenant Tier B/C satellites get row-level isolation.
6. **Agent TPM identity** — IA-2/IA-5 authenticator management: non-exportable hardware-bound keys, auto-rotating certificates.
## Revision History
| Date | Change | Author |
|------|--------|--------|
| 2026-03-22 | Initial — GovCloud deployment, cloud transfer mechanisms, FedRAMP control mapping, certification path | Navid Ahmadi (Compliance), Claire Dubois (Security), Tariq Hassan (Platform) |
| 2026-09-30 | IA-2: a second factor is required of every account in a FedRAMP deployment (`values-fedramp.yaml`, `compliance.fedramp`), #20984 | Engineering |