Skip to content

Air-gapped operations

Bookend needs no outbound connection to work. Air-gapped mode changes three things.

metering.air_gapped = true (wizard step 9, System → Metering & license, or Settings → Other options) stops the heartbeat. Each quarter an administrator generates the signed usage report from System → Metering & license and delivers it by whatever channel the bank permits (Metering and licensing). The report is signed with the install’s own key, so it can be verified without any connection back to the install.

Releases are always pulled by the bank, never pushed. For an air-gapped host, transfer the release bundle (the images in one tar archive, SHA256SUMS, the release notes, the validation pack and VERIFY.md) on approved media. Check the checksums (sha256sum -c SHA256SUMS) and, when the bundle carries a signature file, verify it as VERIFY.md describes; then docker load the images and follow Upgrade.

System → Releases: the current version and the release list.System → Releases: the current version and the release list.
System → Release notes. The running version and the notes shipped inside the image, so they always match the running build.

The SMTP relay and the core endpoint are inside the bank’s network by definition; nothing changes. If there is no relay at all, disable email-link sign-in (auth.login_otp_enabled = false), keep password sign-in, and add users with a password rather than an emailed invite. Escalations are still recorded on the loan before any mail is attempted.

Everything else: intake, extraction, reconciliation, execution checks, review, boarding through jXchange (inside the network) or file export, wires, evidence packets, diagnostics, audit, the API and the MCP server. The evidence chain is verifiable offline by design. The optional AI model for drafting document templates is off unless you configure one, and a local model inside the network works.