[{"data":1,"prerenderedAt":-1},["ShallowReactive",2],{"portal-settings:stajic:zh":3,"public-menus:all":38,"post:air-gapped-ai-how-ai-systems-work-without-internet-or-cloud-access:zh":205,"related:post:air-gapped-ai-how-ai-systems-work-without-internet-or-cloud-access:zh:1":3705},{"statusCode":4,"data":5,"message":37},200,{"tenantId":6,"lang":7,"defaultLang":8,"siteUrl":9,"contactEmail":10,"brandName":11,"logoUrl":12,"siteName":11,"siteDescription":13,"ogImage":10,"robotsIndex":14,"socialLinks":10,"reservedSlugs":10,"seoPolicy":15},"stajic","zh","de","https:\u002F\u002Fstajic.de",null,"Stajic Platform","\u002FLogo_Planet.svg","Stajic Portal",true,{"branding":16,"relatedContent":17,"crossDomainLinks":18},{"logoUrl":12},{"enabled":14},[19,22,25,28,31,34],{"url":20,"label":21,"isActive":14,"showInFooter":14,"includeInSameAs":14},"https:\u002F\u002Ffigure.rocks","figure.rocks",{"url":23,"label":24,"isActive":14,"showInFooter":14,"includeInSameAs":14},"https:\u002F\u002Floving.rocks","loving.rocks",{"url":26,"label":27,"isActive":14,"showInFooter":14,"includeInSameAs":14},"https:\u002F\u002Fbazify.com","bazify.com",{"url":29,"label":30,"isActive":14,"showInFooter":14,"includeInSameAs":14},"https:\u002F\u002Fbazify.de","bazify.de",{"url":32,"label":33,"isActive":14,"showInFooter":14,"includeInSameAs":14},"https:\u002F\u002Fbazify.at","bazify.at",{"url":35,"label":36,"isActive":14,"showInFooter":14,"includeInSameAs":14},"https:\u002F\u002Fbazify.ba","bazify.ba","Portal settings resolved",[39,45],{"id":40,"name":41,"location":42,"isActive":14,"isDefault":43,"items":44},1,"main-navigation","header",false,[],{"id":46,"name":47,"location":48,"isActive":14,"isDefault":14,"items":49},4,"main-menu","sidebar",[50,66,79,93,103,118,133],{"id":51,"title":52,"url":60,"target":61,"icon":62,"isActive":14,"type":63,"productId":10,"categoryId":10,"shopCategoryId":10,"articleId":10,"pageId":64,"portfolioId":10,"children":65},"item-18",{"de":53,"en":54,"es":55,"fr":56,"it":54,"ru":57,"sr":58,"zh":59},"Startseite","Home","Inicio","Accueil","Главная","Почетна","首页","\u002Ffull-stack-web-developer-munich-performance-seo-and-maintainable-builds","_self","i-lucide-home","page",111,[],{"id":67,"title":68,"url":75,"target":61,"icon":76,"isActive":14,"type":63,"productId":10,"categoryId":10,"shopCategoryId":10,"articleId":10,"pageId":77,"portfolioId":10,"children":78},"item-22",{"de":69,"en":69,"es":70,"fr":69,"it":71,"ru":72,"sr":73,"zh":74},"Vision","Visión","Visione","Видение","Визија","想象","\u002Fueber-uns-webdesign-muenchen-webaplikation","i-lucide-eye",113,[],{"id":80,"title":81,"url":89,"target":61,"icon":90,"isActive":14,"type":63,"productId":10,"categoryId":10,"shopCategoryId":10,"articleId":10,"pageId":91,"portfolioId":10,"children":92},"item-19",{"de":82,"en":83,"es":84,"fr":83,"it":85,"ru":86,"sr":87,"zh":88},"Leistungen","Services","Servicios","Servizi","Услуги","Услуге","服务","\u002Fservices-dienstleistungen-muenchen","i-lucide-wrench",116,[],{"id":94,"title":95,"url":99,"target":61,"icon":100,"isActive":14,"type":63,"productId":10,"categoryId":10,"shopCategoryId":10,"articleId":10,"pageId":101,"portfolioId":10,"children":102},"item-23",{"de":96,"en":96,"es":96,"fr":96,"it":96,"ru":97,"sr":97,"zh":98},"Blog","Блог","博客","\u002Fblog","i-lucide-book-open",112,[],{"id":104,"title":105,"url":114,"target":61,"icon":115,"isActive":14,"type":63,"productId":10,"categoryId":10,"shopCategoryId":10,"articleId":10,"pageId":116,"portfolioId":10,"children":117},"item-32",{"de":106,"en":107,"es":108,"fr":109,"it":110,"ru":111,"sr":112,"zh":113},"Neue Technologien","New Technologies","Nuevas tecnologías","Nouvelles technologies","Nuove tecnologie","Новые технологии","Нове технологије","新技术！","\u002Fneue-webtechnologien","i-lucide-sparkles",122,[],{"id":119,"title":120,"url":129,"target":61,"icon":130,"isActive":14,"type":63,"productId":10,"categoryId":10,"shopCategoryId":10,"articleId":10,"pageId":131,"portfolioId":10,"children":132},"item-20",{"de":121,"en":122,"es":123,"fr":124,"it":125,"ru":126,"sr":127,"zh":128},"Kontakt","Contact us!","Contacto","Contact","Contatto","Контакт","Контактирајте нас","联系我们！","\u002Fcontact","i-lucide-mail",115,[],{"id":134,"title":135,"url":144,"target":61,"icon":145,"isActive":14,"type":63,"productId":10,"categoryId":10,"shopCategoryId":10,"articleId":10,"pageId":146,"portfolioId":10,"children":147},"item-21",{"de":136,"en":137,"es":138,"fr":139,"it":140,"ru":141,"sr":142,"zh":143},"Unsere Arbeit","Our Work","Nuestro trabajo","Nos réalisations","I nostri lavori","Наши работы","Наши радови","文件夹","\u002Fportfolio","i-lucide-briefcase",114,[148,161,175,181,193],{"id":149,"title":150,"url":144,"target":61,"icon":159,"isActive":14,"type":63,"productId":10,"categoryId":10,"shopCategoryId":10,"articleId":10,"pageId":146,"portfolioId":10,"children":160},"item-24",{"de":151,"en":152,"es":153,"fr":154,"it":155,"ru":156,"sr":157,"zh":158},"Alle Projekte","All Projects","Todos los proyectos","Tous les projets","Tutti i progetti","Все проекты","Сви пројекти","所有项目","i-lucide-grid-3x3",[],{"id":162,"title":163,"url":171,"target":61,"icon":172,"isActive":14,"type":173,"productId":10,"categoryId":10,"shopCategoryId":10,"articleId":10,"pageId":10,"portfolioId":10,"children":174},"item-29",{"de":164,"en":165,"es":166,"fr":167,"it":168,"ru":169,"sr":170,"zh":143},"Local Roots, Global Reach","Local Roots - Global Reach","Empresa local ","Entreprise locale","Azienda locale","Местная компания","Локално предузеће глобално тржиште","\u002Fportfolio\u002Flocal-roots-global-reach-communication-media-systems-for-modern-business","i-lucide-folder","custom",[],{"id":176,"title":177,"url":179,"target":61,"icon":172,"isActive":14,"type":173,"productId":10,"categoryId":10,"shopCategoryId":10,"articleId":10,"pageId":10,"portfolioId":10,"children":180},"item-28",{"de":178,"en":178,"es":178,"fr":178,"it":178,"ru":178,"sr":178,"zh":178},"Solr Suggester","\u002Fportfolio\u002Fsolr-fuzzy-suggester-und-solr-infix-suggester-abfrage-ueber-ajax-und-filterung",[],{"id":182,"title":183,"url":191,"target":61,"icon":172,"isActive":14,"type":173,"productId":10,"categoryId":10,"shopCategoryId":10,"articleId":10,"pageId":10,"portfolioId":10,"children":192},"item-27",{"de":184,"en":185,"es":186,"fr":187,"it":188,"ru":189,"sr":190,"zh":185},"Firmenwebseite SEO","Company Website SEO","Sitio web corporativo SEO","Site web d’entreprise SEO","Sito web aziendale SEO","Корпоративный сайт SEO","Пословна веб-страница SEO","\u002Fportfolio\u002Fseo-sem-branding-mobile-webseite-muenchen",[],{"id":194,"title":195,"url":203,"target":61,"icon":172,"isActive":14,"type":173,"productId":10,"categoryId":10,"shopCategoryId":10,"articleId":10,"pageId":10,"portfolioId":10,"children":204},"item-31",{"de":196,"en":197,"es":198,"fr":199,"it":200,"ru":201,"sr":202,"zh":197},"Digitalisierungsportal","Digitalization Portal","Portal de digitalización","Portail de numérisation","Portale di digitalizzazione","Портал цифровизации","Портал за дигитализацију","\u002Fportfolio\u002Fdigitalisierungsportal-archiv-museum-bibliothek-ead-lido-mets-mods",[],{"statusCode":4,"data":206,"message":3704},{"id":207,"title":208,"slug":209,"content":210,"contentJson":211,"excerpt":1688,"featuredImage":1689,"featuredImageAlt":1690,"featuredImageCaption":10,"featuredImageTitle":10,"featuredImageCopyright":10,"featuredImageAuthor":10,"featuredImageSourceUrl":10,"featuredImageLicense":10,"featuredImageIsAiGenerated":43,"status":1691,"publishedAt":1692,"createdAt":1693,"updatedAt":1694,"seoLocalePaths":1695,"categories":1704,"author":1717,"translations":1722},"494","气隙AI：AI系统如何在没有互联网或云访问的情况下工作","air-gapped-ai-how-ai-systems-work-without-internet-or-cloud-access","\u003Cp>气隙AI是指部署在安全域内的人工智能系统，该安全域与其隔离的外部系统之间没有物理网络连接，任何跨越该边界的传输都通过刻意控制的、非自动化的程序进行。因此，推理所需的AI模型、运行时、数据、检索索引、工具和操作依赖项必须在隔离环境内部可用。气隙AI不仅仅是“本地模型”或“本地服务器”：其定义性属性是围绕整个系统的网络和传输边界。\u003C\u002Fp>\n\u003Caside class=\"editorjs-callout editorjs-callout--info my-6 rounded-xl border p-5 border-blue-300 bg-blue-50 dark:border-blue-900 dark:bg-blue-950\u002F20\" role=\"note\">\u003Cstrong class=\"block mb-2 text-gray-900 dark:text-gray-100\">直接回答\u003C\u002Fstrong>\u003Cdiv class=\"text-gray-700 dark:text-gray-200\">如果所有必需的依赖项在隔离域内可用，气隙AI系统可以在没有互联网或云API的情况下运行LLM推理、RAG、文档分析甚至代理工作流。\u003Cbr>\u003Cbr>一种实用的架构是：\u003Cbr>\u003Cstrong>受控导入 → 内部制品\u002F模型仓库 → 本地AI运行时 → 本地数据\u002FRAG → 本地工具 → 内部用户\u002F服务 → 本地监控\u002F审计\u003C\u002Fstrong>。\u003Cbr>\u003Cbr>困难的部分不是让一个LLM离线回答。而是在不暗中依赖外部服务的情况下运营整个AI生命周期——更新、模型、驱动程序、软件包、数据导入、凭据、日志记录和安全性。\u003C\u002Fdiv>\u003C\u002Faside>\n\u003Caside class=\"editorjs-callout editorjs-callout--warning my-6 rounded-xl border p-5 border-amber-300 bg-amber-50 dark:border-amber-900 dark:bg-amber-950\u002F20\" role=\"note\">\u003Cstrong class=\"block mb-2 text-gray-900 dark:text-gray-100\">气隙的含义比“无互联网”更严格\u003C\u002Fstrong>\u003Cdiv class=\"text-gray-700 dark:text-gray-200\">NIST的网络安全词汇表将气隙定义为两个系统\u003Cstrong>没有物理连接\u003C\u002Fstrong>且任何逻辑传输\u003Cstrong>不是自动化的\u003C\u002Fstrong>的接口；数据仅在人工控制下手动跨越。供应商文档有时更广泛地使用“气隙”或“断开连接”来描述没有外部互联网连接但具有内部网络和受控暂存基础设施的环境。架构文档应说明实际实现的是哪种含义。\u003C\u002Fdiv>\u003C\u002Faside>\n\u003Caside class=\"editorjs-callout editorjs-callout--warning my-6 rounded-xl border p-5 border-amber-300 bg-amber-50 dark:border-amber-900 dark:bg-amber-950\u002F20\" role=\"note\">\u003Cstrong class=\"block mb-2 text-gray-900 dark:text-gray-100\">气隙并不意味着定义上的安全\u003C\u002Fstrong>\u003Cdiv class=\"text-gray-700 dark:text-gray-200\">移除直接网络连接消除了许多远程路径，但并未消除恶意可移动介质、受损的软件\u002F模型导入、内部威胁、脆弱的内部服务、物理入侵、通过导入文档的提示注入或隔离网络内的横向移动。\u003C\u002Fdiv>\u003C\u002Faside>\n\u003Caside class=\"editorjs-callout editorjs-callout--note my-6 rounded-xl border p-5 border-gray-300 bg-gray-50 dark:border-gray-700 dark:bg-gray-900\u002F40\" role=\"note\">\u003Cstrong class=\"block mb-2 text-gray-900 dark:text-gray-100\">当前来源说明——2026年10月8日\u003C\u002Fstrong>\u003Cdiv class=\"text-gray-700 dark:text-gray-200\">当前的NVIDIA NIM和Red Hat AI Inference文档都支持通过预先暂存模型和容器资产来在没有外部互联网访问的情况下提供LLM服务。NVIDIA记录了连接准备阶段，随后是使用本地资产且没有云注册表凭据的隔离执行阶段。Red Hat使用镜像容器\u002F模型仓库用于断开的OpenShift环境。这些是有用的实现示例，但它们并不推翻NIST对气隙更严格的定义。\u003C\u002Fdiv>\u003C\u002Faside>\n\u003Cnav class=\"editorjs-toc\" data-editorjs-toc=\"true\" aria-label=\"目录\">\u003Cstrong class=\"editorjs-toc__title\">目录\u003C\u002Fstrong>\u003Col class=\"editorjs-toc__list editorjs-toc__list--depth-0\">\u003Cli class=\"editorjs-toc__item\">\u003Ca href=\"#section-7\" class=\"editorjs-toc__link\">气隙AI的真正含义\u003C\u002Fa>\u003C\u002Fli>\u003Cli class=\"editorjs-toc__item\">\u003Ca href=\"#section-11\" class=\"editorjs-toc__link\">最简单的例子\u003C\u002Fa>\u003C\u002Fli>\u003Cli class=\"editorjs-toc__item\">\u003Ca href=\"#section-17\" class=\"editorjs-toc__link\">简单示例的局限\u003C\u002Fa>\u003C\u002Fli>\u003Cli class=\"editorjs-toc__item\">\u003Ca href=\"#section-21\" class=\"editorjs-toc__link\">物理隔离 vs 离线 vs 本地 vs 本地部署 vs 私有 vs 主权 AI\u003C\u002Fa>\u003C\u002Fli>\u003Cli class=\"editorjs-toc__item\">\u003Ca href=\"#section-25\" class=\"editorjs-toc__link\">严格物理隔离 vs 实际断连部署\u003C\u002Fa>\u003C\u002Fli>\u003Cli class=\"editorjs-toc__item\">\u003Ca href=\"#section-28\" class=\"editorjs-toc__link\">实用的物理隔离 AI 架构\u003C\u002Fa>\u003C\u002Fli>\u003Cli class=\"editorjs-toc__item\">\u003Ca href=\"#section-32\" class=\"editorjs-toc__link\">模型必须预先准备\u003C\u002Fa>\u003C\u002Fli>\u003Cli class=\"editorjs-toc__item\">\u003Ca href=\"#section-36\" class=\"editorjs-toc__link\">具有远程代码依赖的模型是物理隔离的风险\u003C\u002Fa>\u003C\u002Fli>\u003Cli class=\"editorjs-toc__item\">\u003Ca href=\"#section-40\" class=\"editorjs-toc__link\">容器、软件包和驱动成为本地供应链制品\u003C\u002Fa>\u003C\u002Fli>\u003Cli class=\"editorjs-toc__item\">\u003Ca href=\"#section-44\" class=\"editorjs-toc__link\">了解完整的依赖清单\u003C\u002Fa>\u003C\u002Fli>\u003Cli class=\"editorjs-toc__item\">\u003Ca href=\"#section-46\" class=\"editorjs-toc__link\">内部镜像是基础设施，而非便利措施\u003C\u002Fa>\u003C\u002Fli>\u003Cli class=\"editorjs-toc__item\">\u003Ca href=\"#section-50\" class=\"editorjs-toc__link\">RAG 可以完全在气隙环境中运行\u003C\u002Fa>\u003C\u002Fli>\u003Cli class=\"editorjs-toc__item\">\u003Ca href=\"#section-56\" class=\"editorjs-toc__link\">代理可以气隙运行——但仅限可访问的工具\u003C\u002Fa>\u003C\u002Fli>\u003Cli class=\"editorjs-toc__item\">\u003Ca href=\"#section-60\" class=\"editorjs-toc__link\">MCP不会绕过气隙\u003C\u002Fa>\u003C\u002Fli>\u003Cli class=\"editorjs-toc__item\">\u003Ca href=\"#section-64\" class=\"editorjs-toc__link\">身份和认证也必须离线工作\u003C\u002Fa>\u003C\u002Fli>\u003Cli class=\"editorjs-toc__item\">\u003Ca href=\"#section-68\" class=\"editorjs-toc__link\">时间、证书和信任存储成为本地依赖\u003C\u002Fa>\u003C\u002Fli>\u003Cli class=\"editorjs-toc__item\">\u003Ca href=\"#section-72\" class=\"editorjs-toc__link\">遥测和崩溃报告需要明确的策略\u003C\u002Fa>\u003C\u002Fli>\u003Cli class=\"editorjs-toc__item\">\u003Ca href=\"#section-76\" class=\"editorjs-toc__link\">气隙系统仍然需要补丁\u003C\u002Fa>\u003C\u002Fli>\u003Cli class=\"editorjs-toc__item\">\u003Ca href=\"#section-80\" class=\"editorjs-toc__link\">受控的更新路径\u003C\u002Fa>\u003C\u002Fli>\u003Cli class=\"editorjs-toc__item\">\u003Ca href=\"#section-82\" class=\"editorjs-toc__link\">传输边界是最敏感的运营接口\u003C\u002Fa>\u003C\u002Fli>\u003Cli class=\"editorjs-toc__item\">\u003Ca href=\"#section-86\" class=\"editorjs-toc__link\">可移动介质不是中立的管道\u003C\u002Fa>\u003C\u002Fli>\u003Cli class=\"editorjs-toc__item\">\u003Ca href=\"#section-90\" class=\"editorjs-toc__link\">气隙增加了供应链的重要性\u003C\u002Fa>\u003C\u002Fli>\u003Cli class=\"editorjs-toc__item\">\u003Ca href=\"#section-94\" class=\"editorjs-toc__link\">气隙就绪状态应经过测试，而非假定\u003C\u002Fa>\u003C\u002Fli>\u003Cli class=\"editorjs-toc__item\">\u003Ca href=\"#section-97\" class=\"editorjs-toc__link\">缓存过一次并不等同于气隙就绪\u003C\u002Fa>\u003C\u002Fli>\u003Cli class=\"editorjs-toc__item\">\u003Ca href=\"#section-101\" class=\"editorjs-toc__link\">气隙内部仍存在哪些威胁？\u003C\u002Fa>\u003C\u002Fli>\u003Cli class=\"editorjs-toc__item\">\u003Ca href=\"#section-103\" class=\"editorjs-toc__link\">气隙实际改善了哪些方面\u003C\u002Fa>\u003C\u002Fli>\u003Cli class=\"editorjs-toc__item\">\u003Ca href=\"#section-107\" class=\"editorjs-toc__link\">气隙使哪些事情变得更困难\u003C\u002Fa>\u003C\u002Fli>\u003Cli class=\"editorjs-toc__item\">\u003Ca href=\"#section-109\" class=\"editorjs-toc__link\">气隙AI与私有AI\u003C\u002Fa>\u003C\u002Fli>\u003Cli class=\"editorjs-toc__item\">\u003Ca href=\"#section-113\" class=\"editorjs-toc__link\">气隙AI与主权AI\u003C\u002Fa>\u003C\u002Fli>\u003Cli class=\"editorjs-toc__item\">\u003Ca href=\"#section-117\" class=\"editorjs-toc__link\">原始实现证据：Aaasaasa AI Client证明了什么——以及没有证明什么\u003C\u002Fa>\u003C\u002Fli>\u003Cli class=\"editorjs-toc__item\">\u003Ca href=\"#section-123\" class=\"editorjs-toc__link\">何时气隙AI是合理的？\u003C\u002Fa>\u003C\u002Fli>\u003Cli class=\"editorjs-toc__item\">\u003Ca href=\"#section-127\" class=\"editorjs-toc__link\">实用的气隙AI设计流程\u003C\u002Fa>\u003C\u002Fli>\u003Cli class=\"editorjs-toc__item\">\u003Ca href=\"#section-129\" class=\"editorjs-toc__link\">气隙AI架构检查清单\u003C\u002Fa>\u003C\u002Fli>\u003Cli class=\"editorjs-toc__item\">\u003Ca href=\"#section-131\" class=\"editorjs-toc__link\">常见的气隙AI故障模式\u003C\u002Fa>\u003C\u002Fli>\u003Cli class=\"editorjs-toc__item\">\u003Ca href=\"#section-133\" class=\"editorjs-toc__link\">常见误解\u003C\u002Fa>\u003C\u002Fli>\u003Cli class=\"editorjs-toc__item\">\u003Ca href=\"#section-135\" class=\"editorjs-toc__link\">局限性\u003C\u002Fa>\u003C\u002Fli>\u003Cli class=\"editorjs-toc__item\">\u003Ca href=\"#section-141\" class=\"editorjs-toc__link\">什么会改变这个答案？\u003C\u002Fa>\u003C\u002Fli>\u003Cli class=\"editorjs-toc__item\">\u003Ca href=\"#section-145\" class=\"editorjs-toc__link\">相关规范知识\u003C\u002Fa>\u003C\u002Fli>\u003Cli class=\"editorjs-toc__item\">\u003Ca href=\"#section-150\" class=\"editorjs-toc__link\">常见问题\u003C\u002Fa>\u003C\u002Fli>\u003Cli class=\"editorjs-toc__item\">\u003Ca href=\"#section-152\" class=\"editorjs-toc__link\">术语表\u003C\u002Fa>\u003C\u002Fli>\u003Cli class=\"editorjs-toc__item\">\u003Ca href=\"#section-154\" class=\"editorjs-toc__link\">结论\u003C\u002Fa>\u003C\u002Fli>\u003Cli class=\"editorjs-toc__item\">\u003Ca href=\"#section-158\" class=\"editorjs-toc__link\">主要来源和当前实现参考\u003C\u002Fa>\u003C\u002Fli>\u003C\u002Fol>\u003C\u002Fnav>\n\u003Ch2 id=\"section-7\">气隙AI的真正含义\u003C\u002Fh2>\n\u003Cp>AI这个词并不改变基本的安全概念。气隙是安全域之间的边界。AI只是使隔离侧在操作上要求更高，因为现代AI堆栈通常假设可下载的模型、包注册表、遥测、API、模型中心和频繁的软件更新。\u003C\u002Fp>\n\u003Cp>隔离环境仍然可以包含许多连接的机器。内部集群可能有GPU、应用服务器、存储、数据库、身份服务和监控相互连接。气隙存在于该飞地和外部域之间。\u003C\u002Fp>\n\u003Cp>因此，相关问题不是“这个GPU有Wi-Fi吗？”而是“这个AI环境能否通过自动化的物理或逻辑路径与外部域交换信息？”\u003C\u002Fp>\n\u003Ch2 id=\"section-11\">最简单的例子\u003C\u002Fh2>\n\u003Cp>想象一家公司想要一个用于机密技术文档的内部助手，但不允许该环境将这些文档发送到互联网。\u003C\u002Fp>\n\u003Cp>该公司在连接的暂存环境中下载经批准的LLM、嵌入模型、容器镜像和软件包。验证后，经批准的制品被转移到隔离环境中。\u003C\u002Fp>\n\u003Cp>在飞地内部，模型服务器、文档解析器、向量数据库、应用程序和身份服务在本地运行。用户可以在没有云模型或公共模型注册表的情况下，针对内部文档提问并使用RAG。\u003C\u002Fp>\n\u003Cp>当需要更新时，更新再次通过受控导入过程，而不是由生产AI服务器直接下载。\u003C\u002Fp>\n\u003Csection class=\"editorjs-process my-6\">\u003Ch3 class=\"mb-3 text-lg font-semibold\">基本的气隙AI操作周期\u003C\u002Fh3>\u003Cdiv class=\"grid grid-cols-1 md:grid-cols-2 xl:grid-cols-3 gap-4\">\u003Cdiv class=\"editorjs-process__step min-w-0  rounded-xl border border-gray-200 dark:border-gray-700 p-4\">\u003Cdiv class=\"text-xs font-semibold text-gray-500 dark:text-gray-400\">1\u003C\u002Fdiv>\u003Cdiv class=\"mt-1 font-semibold text-gray-900 dark:text-gray-100\">1. 在飞地外获取\u003C\u002Fdiv>\u003Cdiv class=\"mt-1 text-sm text-gray-600 dark:text-gray-300\">在连接的暂存环境中下载经批准的模型、软件包、容器、驱动程序、签名和文档。\u003C\u002Fdiv>\u003C\u002Fdiv>\u003Cdiv class=\"editorjs-process__step min-w-0  rounded-xl border border-gray-200 dark:border-gray-700 p-4\">\u003Cdiv class=\"text-xs font-semibold text-gray-500 dark:text-gray-400\">2\u003C\u002Fdiv>\u003Cdiv class=\"mt-1 font-semibold text-gray-900 dark:text-gray-100\">2. 传输前验证\u003C\u002Fdiv>\u003Cdiv class=\"mt-1 text-sm text-gray-600 dark:text-gray-300\">根据组织策略检查来源、签名\u002F校验和、恶意软件状态、许可和兼容性。\u003C\u002Fdiv>\u003C\u002Fdiv>\u003Cdiv class=\"editorjs-process__step min-w-0  rounded-xl border border-gray-200 dark:border-gray-700 p-4\">\u003Cdiv class=\"text-xs font-semibold text-gray-500 dark:text-gray-400\">3\u003C\u002Fdiv>\u003Cdiv class=\"mt-1 font-semibold text-gray-900 dark:text-gray-100\">3. 通过受控边界传输\u003C\u002Fdiv>\u003Cdiv class=\"mt-1 text-sm text-gray-600 dark:text-gray-300\">使用授权的手动或中介过程移动经批准的制品。\u003C\u002Fdiv>\u003C\u002Fdiv>\u003Cdiv class=\"editorjs-process__step min-w-0  rounded-xl border border-gray-200 dark:border-gray-700 p-4\">\u003Cdiv class=\"text-xs font-semibold text-gray-500 dark:text-gray-400\">4\u003C\u002Fdiv>\u003Cdiv class=\"mt-1 font-semibold text-gray-900 dark:text-gray-100\">4. 内部发布\u003C\u002Fdiv>\u003Cdiv class=\"mt-1 text-sm text-gray-600 dark:text-gray-300\">将制品放入内部模型、容器、软件包或文件仓库。\u003C\u002Fdiv>\u003C\u002Fdiv>\u003Cdiv class=\"editorjs-process__step min-w-0  rounded-xl border border-gray-200 dark:border-gray-700 p-4\">\u003Cdiv class=\"text-xs font-semibold text-gray-500 dark:text-gray-400\">5\u003C\u002Fdiv>\u003Cdiv class=\"mt-1 font-semibold text-gray-900 dark:text-gray-100\">5. 本地部署\u003C\u002Fdiv>\u003Cdiv class=\"mt-1 text-sm text-gray-600 dark:text-gray-300\">在没有外部依赖的情况下运行推理、RAG、应用程序和工具。\u003C\u002Fdiv>\u003C\u002Fdiv>\u003Cdiv class=\"editorjs-process__step min-w-0  rounded-xl border border-gray-200 dark:border-gray-700 p-4\">\u003Cdiv class=\"text-xs font-semibold text-gray-500 dark:text-gray-400\">6\u003C\u002Fdiv>\u003Cdiv class=\"mt-1 font-semibold text-gray-900 dark:text-gray-100\">6. 在飞地内监控\u003C\u002Fdiv>\u003Cdiv class=\"mt-1 text-sm text-gray-600 dark:text-gray-300\">在本地收集日志、指标、模型\u002F运行时状态和安全事件。\u003C\u002Fdiv>\u003C\u002Fdiv>\u003Cdiv class=\"editorjs-process__step min-w-0  rounded-xl border border-gray-200 dark:border-gray-700 p-4\">\u003Cdiv class=\"text-xs font-semibold text-gray-500 dark:text-gray-400\">7\u003C\u002Fdiv>\u003Cdiv class=\"mt-1 font-semibold text-gray-900 dark:text-gray-100\">7. 仅导出经批准的证据\u003C\u002Fdiv>\u003Cdiv class=\"mt-1 text-sm text-gray-600 dark:text-gray-300\">在策略允许的情况下，通过反向受控过程向外移动选定的报告或制品。\u003C\u002Fdiv>\u003C\u002Fdiv>\u003Cdiv class=\"editorjs-process__step min-w-0  rounded-xl border border-gray-200 dark:border-gray-700 p-4\">\u003Cdiv class=\"text-xs font-semibold text-gray-500 dark:text-gray-400\">8\u003C\u002Fdiv>\u003Cdiv class=\"mt-1 font-semibold text-gray-900 dark:text-gray-100\">8. 为更新重复\u003C\u002Fdiv>\u003Cdiv class=\"mt-1 text-sm text-gray-600 dark:text-gray-300\">将新模型、补丁、语料库和依赖项视为新的供应链导入。\u003C\u002Fdiv>\u003C\u002Fdiv>\u003C\u002Fdiv>\u003C\u002Fsection>\n\u003Ch2 id=\"section-17\">简单示例的局限\u003C\u002Fh2>\n\u003Cp>生产气隙环境可能比一台工作站大得多。它可能包括Kubernetes\u002FOpenShift、内部注册表、对象存储、身份提供商、向量数据库、可观测性、备份基础设施和多个模型服务节点。\u003C\u002Fp>\n\u003Cp>隔离区内的服务越多，组织就越需要复制那些联网环境通常从互联网获取的能力。\u003C\u002Fp>\n\u003Cp>因此，物理隔离转移了复杂性。它减少了直接的外部连接，但增加了隔离域内的制品管理、补丁、依赖、供应链和运维责任。\u003C\u002Fp>\n\u003Ch2 id=\"section-21\">物理隔离 vs 离线 vs 本地 vs 本地部署 vs 私有 vs 主权 AI\u003C\u002Fh2>\n\u003Cdiv class=\"overflow-x-auto\">\u003Ctable class=\"w-full border-collapse\">\u003Cthead>\u003Ctr>\u003Cth class=\"border border-gray-300 px-4 py-2 text-left font-semibold\">术语\u003C\u002Fth>\u003Cth class=\"border border-gray-300 px-4 py-2 text-left font-semibold\">主要描述的内容\u003C\u002Fth>\u003Cth class=\"border border-gray-300 px-4 py-2 text-left font-semibold\">是否需要互联网\u002F外部连接？\u003C\u002Fth>\u003C\u002Ftr>\u003C\u002Fthead>\u003Ctbody>\u003Ctr>\u003Ctd class=\"border border-gray-300 px-4 py-2\">本地 AI\u003C\u002Ftd>\u003Ctd class=\"border border-gray-300 px-4 py-2\">推理\u002F运行时在本地硬件上运行\u003C\u002Ftd>\u003Ctd class=\"border border-gray-300 px-4 py-2\">否；但仍可能调用云服务\u003C\u002Ftd>\u003C\u002Ftr>\u003Ctr>\u003Ctd class=\"border border-gray-300 px-4 py-2\">可离线运行的 AI\u003C\u002Ftd>\u003Ctd class=\"border border-gray-300 px-4 py-2\">无需互联网即可继续运行\u003C\u002Ftd>\u003Ctd class=\"border border-gray-300 px-4 py-2\">离线运行期间不需要；重新连接可能是正常的\u003C\u002Ftd>\u003C\u002Ftr>\u003Ctr>\u003Ctd class=\"border border-gray-300 px-4 py-2\">断连环境\u003C\u002Ftd>\u003Ctd class=\"border border-gray-300 px-4 py-2\">部署环境没有直接的外部互联网路径\u003C\u002Ftd>\u003Ctd class=\"border border-gray-300 px-4 py-2\">通常不需要；可能使用受控的镜像\u002F堡垒机\u003C\u002Ftd>\u003C\u002Ftr>\u003Ctr>\u003Ctd class=\"border border-gray-300 px-4 py-2\">本地部署 AI\u003C\u002Ftd>\u003Ctd class=\"border border-gray-300 px-4 py-2\">基础设施在组织自有\u002F本地环境中运行\u003C\u002Ftd>\u003Ctd class=\"border border-gray-300 px-4 py-2\">仍可能具有完整的互联网连接\u003C\u002Ftd>\u003C\u002Ftr>\u003Ctr>\u003Ctd class=\"border border-gray-300 px-4 py-2\">私有 AI\u003C\u002Ftd>\u003Ctd class=\"border border-gray-300 px-4 py-2\">AI 处理受到控制以满足隐私\u002F保密要求\u003C\u002Ftd>\u003Ctd class=\"border border-gray-300 px-4 py-2\">取决于架构；可以连接或断开\u003C\u002Ftd>\u003C\u002Ftr>\u003Ctr>\u003Ctd class=\"border border-gray-300 px-4 py-2\">物理隔离 AI\u003C\u002Ftd>\u003Ctd class=\"border border-gray-300 px-4 py-2\">安全域物理断开，跨边界传输在严格定义下是非自动化\u002F手动的\u003C\u002Ftd>\u003Ctd class=\"border border-gray-300 px-4 py-2\">无自动化外部路径\u003C\u002Ftd>\u003C\u002Ftr>\u003Ctr>\u003Ctd class=\"border border-gray-300 px-4 py-2\">主权 AI\u003C\u002Ftd>\u003Ctd class=\"border border-gray-300 px-4 py-2\">对模型、数据、基础设施和依赖的控制\u002F管辖权\u003C\u002Ftd>\u003Ctd class=\"border border-gray-300 px-4 py-2\">不一定；主权比网络隔离范围更广\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003C\u002Fdiv>\n\u003Cp>这些术语可能重叠，但并非同义词。连接到互联网的本地 Ollama 服务器是本地 AI，而不是物理隔离 AI。调用云模型的本地部署 RAG 平台是带有云推理的本地部署应用基础设施，而不是物理隔离 AI。\u003C\u002Fp>\n\u003Cp>物理隔离系统在设计上通常是私有的，因为数据保留在隔离区内，但隐私还取决于授权、日志记录、数据处理、物理安全和运维策略。\u003C\u002Fp>\n\u003Ch2 id=\"section-25\">严格物理隔离 vs 实际断连部署\u003C\u002Fh2>\n\u003Csection class=\"editorjs-comparison my-6\">\u003Ch3 class=\"mb-3 text-lg font-semibold\">常被称为“物理隔离”的两种含义\u003C\u002Fh3>\u003Cdiv class=\"overflow-x-auto\">\u003Ctable class=\"w-full border-collapse\">\u003Cthead>\u003Ctr>\u003Cth class=\"border border-gray-300 bg-gray-50 px-4 py-3 text-left dark:border-gray-700 dark:bg-gray-900\">\u003C\u002Fth>\u003Cth class=\"border border-gray-300 bg-gray-50 px-4 py-3 text-left font-semibold dark:border-gray-700 dark:bg-gray-900\">严格物理隔离\u003C\u002Fth>\u003Cth class=\"border border-gray-300 bg-gray-50 px-4 py-3 text-left font-semibold dark:border-gray-700 dark:bg-gray-900\">断连\u002F无互联网部署\u003C\u002Fth>\u003C\u002Ftr>\u003C\u002Fthead>\u003Ctbody>\u003Ctr>\u003Cth class=\"border border-gray-300 px-4 py-3 text-left font-semibold dark:border-gray-700\">外部物理连接\u003C\u002Fth>\u003Ctd class=\"border border-gray-300 px-4 py-3 dark:border-gray-700\">\u003C\u002Ftd>\u003Ctd class=\"border border-gray-300 px-4 py-3 dark:border-gray-700\">\u003C\u002Ftd>\u003C\u002Ftr>\u003Ctr>\u003Cth class=\"border border-gray-300 px-4 py-3 text-left font-semibold dark:border-gray-700\">跨边界传输\u003C\u002Fth>\u003Ctd class=\"border border-gray-300 px-4 py-3 dark:border-gray-700\">\u003C\u002Ftd>\u003Ctd class=\"border border-gray-300 px-4 py-3 dark:border-gray-700\">\u003C\u002Ftd>\u003C\u002Ftr>\u003Ctr>\u003Cth class=\"border border-gray-300 px-4 py-3 text-left font-semibold dark:border-gray-700\">AI 工作负载的互联网访问\u003C\u002Fth>\u003Ctd class=\"border border-gray-300 px-4 py-3 dark:border-gray-700\">\u003C\u002Ftd>\u003Ctd class=\"border border-gray-300 px-4 py-3 dark:border-gray-700\">\u003C\u002Ftd>\u003C\u002Ftr>\u003Ctr>\u003Cth class=\"border border-gray-300 px-4 py-3 text-left font-semibold dark:border-gray-700\">内部网络\u003C\u002Fth>\u003Ctd class=\"border border-gray-300 px-4 py-3 dark:border-gray-700\">\u003C\u002Ftd>\u003Ctd class=\"border border-gray-300 px-4 py-3 dark:border-gray-700\">\u003C\u002Ftd>\u003C\u002Ftr>\u003Ctr>\u003Cth class=\"border border-gray-300 px-4 py-3 text-left font-semibold dark:border-gray-700\">使用该术语的场景\u003C\u002Fth>\u003Ctd class=\"border border-gray-300 px-4 py-3 dark:border-gray-700\">\u003C\u002Ftd>\u003Ctd class=\"border border-gray-300 px-4 py-3 dark:border-gray-700\">\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003C\u002Fdiv>\u003C\u002Fsection>\n\u003Caside class=\"editorjs-callout editorjs-callout--success my-6 rounded-xl border p-5 border-emerald-300 bg-emerald-50 dark:border-emerald-900 dark:bg-emerald-950\u002F20\" role=\"note\">\u003Cstrong class=\"block mb-2 text-gray-900 dark:text-gray-100\">记录边界，而不是依赖标签\u003C\u002Fstrong>\u003Cdiv class=\"text-gray-700 dark:text-gray-200\">对于架构和安全审查，请写出实际规则：\u003Cstrong>无出站互联网\u003C\u002Fstrong>、\u003Cstrong>无物理外部网络路径\u003C\u002Fstrong>、\u003Cstrong>仅手动传输\u003C\u002Fstrong>，或\u003Cstrong>带经批准堡垒机\u002F镜像的断连集群\u003C\u002Fstrong>。这比只说“物理隔离”更精确。\u003C\u002Fdiv>\u003C\u002Faside>\n\u003Ch2 id=\"section-28\">实用的物理隔离 AI 架构\u003C\u002Fh2>\n\u003Cdiv class=\"overflow-x-auto\">\u003Ctable class=\"w-full border-collapse\">\u003Cthead>\u003Ctr>\u003Cth class=\"border border-gray-300 px-4 py-2 text-left font-semibold\">层\u003C\u002Fth>\u003Cth class=\"border border-gray-300 px-4 py-2 text-left font-semibold\">隔离环境内必须存在的内容\u003C\u002Fth>\u003C\u002Ftr>\u003C\u002Fthead>\u003Ctbody>\u003Ctr>\u003Ctd class=\"border border-gray-300 px-4 py-2\">用户\u002F应用层\u003C\u002Ftd>\u003Ctd class=\"border border-gray-300 px-4 py-2\">聊天 UI、API、业务应用或内部代理接口\u003C\u002Ftd>\u003C\u002Ftr>\u003Ctr>\u003Ctd class=\"border border-gray-300 px-4 py-2\">身份与授权\u003C\u002Ftd>\u003Ctd class=\"border border-gray-300 px-4 py-2\">本地\u002F内部认证、RBAC、租户\u002F资源权限\u003C\u002Ftd>\u003C\u002Ftr>\u003Ctr>\u003Ctd class=\"border border-gray-300 px-4 py-2\">AI 网关\u002F运行时\u003C\u002Ftd>\u003Ctd class=\"border border-gray-300 px-4 py-2\">模型路由、请求策略、上下文组装和运行时控制\u003C\u002Ftd>\u003C\u002Ftr>\u003Ctr>\u003Ctd class=\"border border-gray-300 px-4 py-2\">模型服务\u003C\u002Ftd>\u003Ctd class=\"border border-gray-300 px-4 py-2\">本地模型服务器、权重、分词器\u002F配置和加速器运行时\u003C\u002Ftd>\u003C\u002Ftr>\u003Ctr>\u003Ctd class=\"border border-gray-300 px-4 py-2\">RAG \u002F 知识\u003C\u002Ftd>\u003Ctd class=\"border border-gray-300 px-4 py-2\">文档存储、解析器、嵌入、向量\u002F词法索引、元数据和来源\u003C\u002Ftd>\u003C\u002Ftr>\u003Ctr>\u003Ctd class=\"border border-gray-300 px-4 py-2\">工具\u002F服务\u003C\u002Ftd>\u003Ctd class=\"border border-gray-300 px-4 py-2\">仅限隔离区可访问的内部\u002F本地 API 和经批准的系统\u003C\u002Ftd>\u003C\u002Ftr>\u003Ctr>\u003Ctd class=\"border border-gray-300 px-4 py-2\">制品仓库\u003C\u002Ftd>\u003Ctd class=\"border border-gray-300 px-4 py-2\">本地容器注册表、包镜像、模型存储，以及可选的 OS\u002F更新仓库\u003C\u002Ftd>\u003C\u002Ftr>\u003Ctr>\u003Ctd class=\"border border-gray-300 px-4 py-2\">可观测性\u003C\u002Ftd>\u003Ctd class=\"border border-gray-300 px-4 py-2\">内部日志、指标、追踪和审计记录\u003C\u002Ftd>\u003C\u002Ftr>\u003Ctr>\u003Ctd class=\"border border-gray-300 px-4 py-2\">备份\u002F恢复\u003C\u002Ftd>\u003Ctd class=\"border border-gray-300 px-4 py-2\">适合该安全域的本地或单独控制的备份流程\u003C\u002Ftd>\u003C\u002Ftr>\u003Ctr>\u003Ctd class=\"border border-gray-300 px-4 py-2\">传输边界\u003C\u002Ftd>\u003Ctd class=\"border border-gray-300 px-4 py-2\">带检查和批准的受控导入\u002F导出流程\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003C\u002Fdiv>\n\u003Cp>完整的架构应能够在没有 DNS 查询、许可证检查、包下载或对公共服务 API 调用的情况下启动和运行，除非这些依赖已有经批准的内部替代方案。\u003C\u002Fp>\n\u003Cp>一个有用的设计测试是断开部署与所有外部服务的连接，并冷启动整个技术栈。隐藏依赖往往会在启动、模型加载、认证、包解析或遥测初始化期间出现。\u003C\u002Fp>\n\u003Ch2 id=\"section-32\">模型必须预先准备\u003C\u002Fh2>\n\u003Cp>如果隔离工作负载没有通往云模型 API 的路径，那么按定义这些 API 不可用。因此，隔离区需要可在本地运行的模型制品或内部托管的推理服务。\u003C\u002Fp>\n\u003Cp>NVIDIA 当前的 NIM 物理隔离文档明确使用两阶段模式：在联网机器上下载并准备模型资产，传输它们，然后从本地存储运行隔离的 NIM，无需出站注册表访问或云 API 密钥。\u003C\u002Fp>\n\u003Cp>模型权重只是依赖集的一部分。分词器、配置文件、适配器、量化元数据以及任何所需的运行时代码也必须存在。\u003C\u002Fp>\n\u003Ch2 id=\"section-36\">具有远程代码依赖的模型是物理隔离的风险\u003C\u002Fh2>\n\u003Cp>一些模型仓库包含自定义 Python 代码或运行时钩子，这些代码或钩子通常会获取额外的代码或资源。\u003C\u002Fp>\n\u003Cp>当前 Red Hat AI Inference 文档明确警告，一些需要远程代码的 Hugging Face 模型无法在断连环境中正常运行，因为即使配置了离线模式，该库仍会尝试访问网络。\u003C\u002Fp>\n\u003Cp>实际经验是，在批准模型用于隔离部署之前，先离线测试其整个加载路径。“我下载了权重”并不能证明该模型是自包含的。\u003C\u002Fp>\n\u003Ch2 id=\"section-40\">容器、软件包和驱动成为本地供应链制品\u003C\u002Fh2>\n\u003Cp>联网环境通常会从公共注册表拉取容器镜像、Python 软件包、操作系统更新和 GPU 组件。气隙环境不能假定这些服务中的任何一个可用。\u003C\u002Fp>\n\u003Cp>Red Hat 的断连 AI 部署模型使用内部镜像注册表来存放容器镜像和 Operator 目录。模型可以作为 OCI 制品进行镜像，或传输到持久化存储。\u003C\u002Fp>\n\u003Cp>对于更广泛的技术栈，同样的模式通常也适用于语言包、Linux 仓库、JavaScript 包和内部二进制文件：经批准的制品通过传输流程一次性进入，然后由受信任的内部仓库提供服务。\u003C\u002Fp>\n\u003Ch2 id=\"section-44\">了解完整的依赖清单\u003C\u002Fh2>\n\u003Cdiv class=\"overflow-x-auto\">\u003Ctable class=\"w-full border-collapse\">\u003Cthead>\u003Ctr>\u003Cth class=\"border border-gray-300 px-4 py-2 text-left font-semibold\">依赖类别\u003C\u002Fth>\u003Cth class=\"border border-gray-300 px-4 py-2 text-left font-semibold\">示例\u003C\u002Fth>\u003C\u002Ftr>\u003C\u002Fthead>\u003Ctbody>\u003Ctr>\u003Ctd class=\"border border-gray-300 px-4 py-2\">模型制品\u003C\u002Ftd>\u003Ctd class=\"border border-gray-300 px-4 py-2\">权重、分词器、配置、适配器、量化元数据\u003C\u002Ftd>\u003C\u002Ftr>\u003Ctr>\u003Ctd class=\"border border-gray-300 px-4 py-2\">推理运行时\u003C\u002Ftd>\u003Ctd class=\"border border-gray-300 px-4 py-2\">vLLM、llama.cpp、Ollama、NIM 或其他服务运行时\u003C\u002Ftd>\u003C\u002Ftr>\u003Ctr>\u003Ctd class=\"border border-gray-300 px-4 py-2\">GPU\u002F运行时栈\u003C\u002Ftd>\u003Ctd class=\"border border-gray-300 px-4 py-2\">驱动、CUDA\u002FROCm 库、容器运行时\u003C\u002Ftd>\u003C\u002Ftr>\u003Ctr>\u003Ctd class=\"border border-gray-300 px-4 py-2\">应用软件包\u003C\u002Ftd>\u003Ctd class=\"border border-gray-300 px-4 py-2\">Python wheels、npm 包、系统库\u003C\u002Ftd>\u003C\u002Ftr>\u003Ctr>\u003Ctd class=\"border border-gray-300 px-4 py-2\">容器\u003C\u002Ftd>\u003Ctd class=\"border border-gray-300 px-4 py-2\">应用、推理、数据库、向量数据库、监控镜像\u003C\u002Ftd>\u003C\u002Ftr>\u003Ctr>\u003Ctd class=\"border border-gray-300 px-4 py-2\">RAG 模型\u003C\u002Ftd>\u003Ctd class=\"border border-gray-300 px-4 py-2\">嵌入模型、重排序器、OCR\u002F视觉模型\u003C\u002Ftd>\u003C\u002Ftr>\u003Ctr>\u003Ctd class=\"border border-gray-300 px-4 py-2\">数据\u003C\u002Ftd>\u003Ctd class=\"border border-gray-300 px-4 py-2\">知识语料库、元数据、模式、评估数据集\u003C\u002Ftd>\u003C\u002Ftr>\u003Ctr>\u003Ctd class=\"border border-gray-300 px-4 py-2\">安全材料\u003C\u002Ftd>\u003Ctd class=\"border border-gray-300 px-4 py-2\">证书、CA 捆绑包、策略\u002F配置、适用时的恶意软件签名\u003C\u002Ftd>\u003C\u002Ftr>\u003Ctr>\u003Ctd class=\"border border-gray-300 px-4 py-2\">运维制品\u003C\u002Ftd>\u003Ctd class=\"border border-gray-300 px-4 py-2\">仪表板、告警规则、备份工具、运行手册\u003C\u002Ftd>\u003C\u002Ftr>\u003Ctr>\u003Ctd class=\"border border-gray-300 px-4 py-2\">许可\u003C\u002Ftd>\u003Ctd class=\"border border-gray-300 px-4 py-2\">需要时使用离线兼容的许可证\u002F授权\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003C\u002Fdiv>\n\u003Ch2 id=\"section-46\">内部镜像是基础设施，而非便利措施\u003C\u002Fh2>\n\u003Cp>当隔离域对经批准的制品拥有已知的内部来源时，断连部署才变得可维护。\u003C\u002Fp>\n\u003Cp>Red Hat 文档化的方法使用断连集群可访问的镜像注册表，因此工作负载不需要公共注册表。\u003C\u002Fp>\n\u003Cp>同样的架构思路可以应用于模型存储和软件包仓库。目标是让制品来源、版本和批准状态变得明确，而不是手动将随机文件复制到每台服务器。\u003C\u002Fp>\n\u003Ch2 id=\"section-50\">RAG 可以完全在气隙环境中运行\u003C\u002Fh2>\n\u003Cp>RAG 不需要公共互联网。它需要一个可检索的语料库、一个摄取\u002F索引管道，以及一个能够使用检索上下文的模型。\u003C\u002Fp>\n\u003Cp>在气隙环境中，文档存储、解析器\u002FOCR、嵌入模型、向量或词法索引、重排序器和生成模型都可以在本地运行。\u003C\u002Fp>\n\u003Cp>变化的是来源获取方式。除非通过受控边界导入等效数据，否则实时网络搜索和云文档连接器不可用。\u003C\u002Fp>\n\u003Cp>因此，语料库成为一种受治理的制品。每次导入都应保留来源标识、日期\u002F版本和出处，以便用户知道隔离系统实际包含哪些知识。\u003C\u002Fp>\n\u003Caside class=\"editorjs-referral my-6\">\u003Ca href=\"https:\u002F\u002Fstajic.de\u002Fzh\u002Fblog\u002Fwhat-is-rag-the-simplest-explanation-of-how-it-works\" class=\"flex flex-col sm:flex-row gap-4 rounded-xl border border-gray-200 dark:border-gray-700 p-4 transition hover:border-primary-500\">\u003Cdiv class=\"min-w-0 flex-1\">\u003Cstrong class=\"block text-lg text-gray-900 dark:text-gray-100\">什么是RAG？其工作原理的最简单解释\u003C\u002Fstrong>\u003Cp class=\"mt-2 text-sm text-gray-600 dark:text-gray-300\">RAG本身独立于云托管。在气隙架构中，检索和生成只需由本地\u002F内部组件提供。\u003C\u002Fp>\u003Cspan class=\"mt-3 inline-flex text-sm font-medium text-primary-600 dark:text-primary-400\">阅读RAG基础 →\u003C\u002Fspan>\u003C\u002Fdiv>\u003C\u002Fa>\u003C\u002Faside>\n\u003Ch2 id=\"section-56\">代理可以气隙运行——但仅限可访问的工具\u003C\u002Fh2>\n\u003Cp>如果模型\u002F运行时和所需工具是本地或在内部网络上可访问的，代理循环可以完全在隔离飞地内运行。\u003C\u002Fp>\n\u003Cp>依赖GitHub、公共网络搜索、云电子邮件或外部SaaS API的工具将失败，除非架构提供经批准的内部等效项或受控的异步交换过程。\u003C\u002Fp>\n\u003Cp>这就是为什么气隙代理设计应从能力清单开始：每个工具端点必须分类为内部、导入、不可用或故意排除。\u003C\u002Fp>\n\u003Ch2 id=\"section-60\">MCP不会绕过气隙\u003C\u002Fh2>\n\u003Cp>MCP可以在隔离的AI环境中暴露本地工具和资源，但协议不会通过安全边界创建连接。\u003C\u002Fp>\n\u003Cp>读取内部文档的本地MCP服务器可以完全离线工作。公共互联网上的远程MCP服务器无法从严格的气隙飞地访问。\u003C\u002Fp>\n\u003Cp>同样的原则适用于任何连接器协议：互操作性与网络权限是分开的。\u003C\u002Fp>\n\u003Ch2 id=\"section-64\">身份和认证也必须离线工作\u003C\u002Fh2>\n\u003Cp>AI应用程序可以本地托管，同时仍依赖云身份提供商。这种隐藏的依赖破坏了真正的断开操作。\u003C\u002Fp>\n\u003Cp>因此，气隙设计需要一种在飞地内运行的身份架构：本地目录、内部身份提供商、内部PKI、本地服务凭证或其他经批准的机制。\u003C\u002Fp>\n\u003Cp>即使没有互联网，授权仍然是必要的。气隙不会取代RBAC、租户隔离或最小权限。\u003C\u002Fp>\n\u003Ch2 id=\"section-68\">时间、证书和信任存储成为本地依赖\u003C\u002Fh2>\n\u003Cp>许多身份验证和日志系统依赖于可靠的时间。证书会过期。信任存储会变化。签名工件需要验证。\u003C\u002Fp>\n\u003Cp>因此，断开连接的飞地应具有内部时间同步和证书\u002F信任生命周期，在正常操作期间不依赖于访问公共服务。\u003C\u002Fp>\n\u003Cp>这些是普通的基础设施问题，只有在没有互联网访问的情况下测试架构时才会显现。\u003C\u002Fp>\n\u003Ch2 id=\"section-72\">遥测和崩溃报告需要明确的策略\u003C\u002Fh2>\n\u003Cp>许多现代库默认尝试进行分析、更新检查或错误报告。\u003C\u002Fp>\n\u003Cp>在隔离环境中，这些调用应被禁用或重定向到内部可观测性系统。反复失败的遥测尝试可能导致延迟、日志噪音和意外的启动行为。\u003C\u002Fp>\n\u003Cp>气隙部署应了解哪些组件尝试外联，即使防火墙会阻止它们。\u003C\u002Fp>\n\u003Ch2 id=\"section-76\">气隙系统仍然需要补丁\u003C\u002Fh2>\n\u003Cp>网络隔离并不能阻止软件产生漏洞。它只改变了补丁到达系统的方式。\u003C\u002Fp>\n\u003Cp>NIST将补丁管理视为预防性维护：组织仍然需要识别、获取、优先排序、安装和验证补丁与更新。\u003C\u002Fp>\n\u003Cp>因此，气隙操作需要为操作系统软件包、容器镜像、驱动程序、AI运行时和安全更新建立可重复的导入节奏。权衡在于隔离稳定性与陈旧软件带来的漏洞暴露之间。\u003C\u002Fp>\n\u003Ch2 id=\"section-80\">受控的更新路径\u003C\u002Fh2>\n\u003Csection class=\"editorjs-process my-6\">\u003Ch3 class=\"mb-3 text-lg font-semibold\">隔离AI环境的示例更新生命周期\u003C\u002Fh3>\u003Cdiv class=\"grid grid-cols-1 md:grid-cols-2 xl:grid-cols-3 gap-4\">\u003Cdiv class=\"editorjs-process__step min-w-0  rounded-xl border border-gray-200 dark:border-gray-700 p-4\">\u003Cdiv class=\"text-xs font-semibold text-gray-500 dark:text-gray-400\">1\u003C\u002Fdiv>\u003Cdiv class=\"mt-1 font-semibold text-gray-900 dark:text-gray-100\">1. 识别所需更新\u003C\u002Fdiv>\u003Cdiv class=\"mt-1 text-sm text-gray-600 dark:text-gray-300\">安全公告、模型\u002F运行时改进或运营需求触发变更。\u003C\u002Fdiv>\u003C\u002Fdiv>\u003Cdiv class=\"editorjs-process__step min-w-0  rounded-xl border border-gray-200 dark:border-gray-700 p-4\">\u003Cdiv class=\"text-xs font-semibold text-gray-500 dark:text-gray-400\">2\u003C\u002Fdiv>\u003Cdiv class=\"mt-1 font-semibold text-gray-900 dark:text-gray-100\">2. 在联网暂存区获取\u003C\u002Fdiv>\u003Cdiv class=\"mt-1 text-sm text-gray-600 dark:text-gray-300\">下载确切版本以及签名\u002F校验和和元数据。\u003C\u002Fdiv>\u003C\u002Fdiv>\u003Cdiv class=\"editorjs-process__step min-w-0  rounded-xl border border-gray-200 dark:border-gray-700 p-4\">\u003Cdiv class=\"text-xs font-semibold text-gray-500 dark:text-gray-400\">3\u003C\u002Fdiv>\u003Cdiv class=\"mt-1 font-semibold text-gray-900 dark:text-gray-100\">3. 验证供应链证据\u003C\u002Fdiv>\u003Cdiv class=\"mt-1 text-sm text-gray-600 dark:text-gray-300\">验证来源、完整性、兼容性和策略要求。\u003C\u002Fdiv>\u003C\u002Fdiv>\u003Cdiv class=\"editorjs-process__step min-w-0  rounded-xl border border-gray-200 dark:border-gray-700 p-4\">\u003Cdiv class=\"text-xs font-semibold text-gray-500 dark:text-gray-400\">4\u003C\u002Fdiv>\u003Cdiv class=\"mt-1 font-semibold text-gray-900 dark:text-gray-100\">4. 在代表性离线暂存区测试\u003C\u002Fdiv>\u003Cdiv class=\"mt-1 text-sm text-gray-600 dark:text-gray-300\">确认更新在没有意外网络依赖的情况下正常工作。\u003C\u002Fdiv>\u003C\u002Fdiv>\u003Cdiv class=\"editorjs-process__step min-w-0  rounded-xl border border-gray-200 dark:border-gray-700 p-4\">\u003Cdiv class=\"text-xs font-semibold text-gray-500 dark:text-gray-400\">5\u003C\u002Fdiv>\u003Cdiv class=\"mt-1 font-semibold text-gray-900 dark:text-gray-100\">5. 批准传输\u003C\u002Fdiv>\u003Cdiv class=\"mt-1 text-sm text-gray-600 dark:text-gray-300\">应用组织的变更和安全流程。\u003C\u002Fdiv>\u003C\u002Fdiv>\u003Cdiv class=\"editorjs-process__step min-w-0  rounded-xl border border-gray-200 dark:border-gray-700 p-4\">\u003Cdiv class=\"text-xs font-semibold text-gray-500 dark:text-gray-400\">6\u003C\u002Fdiv>\u003Cdiv class=\"mt-1 font-semibold text-gray-900 dark:text-gray-100\">6. 导入到隔离区仓库\u003C\u002Fdiv>\u003Cdiv class=\"mt-1 text-sm text-gray-600 dark:text-gray-300\">将制品发布到内部可信源。\u003C\u002Fdiv>\u003C\u002Fdiv>\u003Cdiv class=\"editorjs-process__step min-w-0  rounded-xl border border-gray-200 dark:border-gray-700 p-4\">\u003Cdiv class=\"text-xs font-semibold text-gray-500 dark:text-gray-400\">7\u003C\u002Fdiv>\u003Cdiv class=\"mt-1 font-semibold text-gray-900 dark:text-gray-100\">7. 逐步部署\u003C\u002Fdiv>\u003Cdiv class=\"mt-1 text-sm text-gray-600 dark:text-gray-300\">在架构允许的情况下，先应用于测试\u002F金丝雀节点，再广泛推广。\u003C\u002Fdiv>\u003C\u002Fdiv>\u003Cdiv class=\"editorjs-process__step min-w-0  rounded-xl border border-gray-200 dark:border-gray-700 p-4\">\u003Cdiv class=\"text-xs font-semibold text-gray-500 dark:text-gray-400\">8\u003C\u002Fdiv>\u003Cdiv class=\"mt-1 font-semibold text-gray-900 dark:text-gray-100\">8. 验证并记录\u003C\u002Fdiv>\u003Cdiv class=\"mt-1 text-sm text-gray-600 dark:text-gray-300\">确认版本、健康状况、行为和回滚状态。\u003C\u002Fdiv>\u003C\u002Fdiv>\u003C\u002Fdiv>\u003C\u002Fsection>\n\u003Ch2 id=\"section-82\">传输边界是最敏感的运营接口\u003C\u002Fh2>\n\u003Cp>如果外部信息必须进入气隙系统，导入通道就成为主要的安全控制点。\u003C\u002Fp>\n\u003Cp>NSA网络安全技术网络威胁框架明确将可移动介质复制视为对手可用于进入断开连接或气隙网络的路径。\u003C\u002Fp>\n\u003Cp>这就是为什么受控的介质处理、检查、来源追溯、必要时的加密、恶意软件扫描和角色分离可能与AI堆栈本身同样重要。\u003C\u002Fp>\n\u003Ch2 id=\"section-86\">可移动介质不是中立的管道\u003C\u002Fh2>\n\u003Cp>USB驱动和其他便携式介质可以携带合法的模型\u002F数据制品以及恶意内容。\u003C\u002Fp>\n\u003Cp>NIST的介质清理指南将存储介质视为机密性生命周期对象，根据敏感性和重用需求可能需要清除、净化或销毁。\u003C\u002Fp>\n\u003Cp>确切的传输程序因组织而异，但架构原则是稳定的：跨边界介质应作为安全资产进行管理，而不是被视为非正式的便利工具。\u003C\u002Fp>\n\u003Ch2 id=\"section-90\">气隙增加了供应链的重要性\u003C\u002Fh2>\n\u003Cp>隔离系统接收的实时外部输入较少，但每一个导入的二进制文件、模型、容器和软件包都变得更加重要，因为飞地可能会长期信任它们。\u003C\u002Fp>\n\u003Cp>NIST 软件供应链指南强调来源、供应商风险、漏洞管理、软件验证和面向 SBOM 的实践。这些关注点与离线 AI 制品导入直接相关。\u003C\u002Fp>\n\u003Cp>模型供应链值得与应用供应链同等重视：在导入之前，应了解模型来源、许可证、哈希、格式、所需代码、分词器、适配器和评估状态。\u003C\u002Fp>\n\u003Ch2 id=\"section-94\">气隙就绪状态应经过测试，而非假定\u003C\u002Fh2>\n\u003Caside class=\"editorjs-callout editorjs-callout--note my-6 rounded-xl border p-5 border-gray-300 bg-gray-50 dark:border-gray-700 dark:bg-gray-900\u002F40\" role=\"note\">\u003Cstrong class=\"block mb-2 text-gray-900 dark:text-gray-100\">建议的验证模式\u003C\u002Fstrong>\u003Cdiv class=\"text-gray-700 dark:text-gray-200\">以下气隙就绪测试是一种工程综合方法，并非 NIST 或供应商认证方法。它旨在部署前暴露隐藏的外部依赖。\u003C\u002Fdiv>\u003C\u002Faside>\n\u003Cdiv class=\"overflow-x-auto\">\u003Ctable class=\"w-full border-collapse\">\u003Cthead>\u003Ctr>\u003Cth class=\"border border-gray-300 px-4 py-2 text-left font-semibold\">测试\u003C\u002Fth>\u003Cth class=\"border border-gray-300 px-4 py-2 text-left font-semibold\">它证明了什么\u003C\u002Fth>\u003C\u002Ftr>\u003C\u002Fthead>\u003Ctbody>\u003Ctr>\u003Ctd class=\"border border-gray-300 px-4 py-2\">在阻止所有出站网络的情况下冷启动\u003C\u002Ftd>\u003Ctd class=\"border border-gray-300 px-4 py-2\">运行时在启动期间不需要公共服务\u003C\u002Ftd>\u003C\u002Ftr>\u003Ctr>\u003Ctd class=\"border border-gray-300 px-4 py-2\">从本地存储加载每个已批准的模型\u003C\u002Ftd>\u003Ctd class=\"border border-gray-300 px-4 py-2\">权重\u002F分词器\u002F配置完整\u003C\u002Ftd>\u003C\u002Ftr>\u003Ctr>\u003Ctd class=\"border border-gray-300 px-4 py-2\">仅从内部注册表重建\u002F重新部署\u003C\u002Ftd>\u003Ctd class=\"border border-gray-300 px-4 py-2\">容器\u002F软件包镜像源足够\u003C\u002Ftd>\u003C\u002Ftr>\u003Ctr>\u003Ctd class=\"border border-gray-300 px-4 py-2\">在外部 IdP 不可达时对用户进行身份验证\u003C\u002Ftd>\u003Ctd class=\"border border-gray-300 px-4 py-2\">身份系统在飞地内部可正常工作\u003C\u002Ftd>\u003C\u002Ftr>\u003Ctr>\u003Ctd class=\"border border-gray-300 px-4 py-2\">离线运行 RAG 摄取和查询\u003C\u002Ftd>\u003Ctd class=\"border border-gray-300 px-4 py-2\">嵌入\u002F索引\u002F检索栈是本地化的\u003C\u002Ftd>\u003C\u002Ftr>\u003Ctr>\u003Ctd class=\"border border-gray-300 px-4 py-2\">运行具有代表性的代理工具\u003C\u002Ftd>\u003Ctd class=\"border border-gray-300 px-4 py-2\">工具不依赖外部 API\u003C\u002Ftd>\u003C\u002Ftr>\u003Ctr>\u003Ctd class=\"border border-gray-300 px-4 py-2\">删除缓存后重启\u003C\u002Ftd>\u003Ctd class=\"border border-gray-300 px-4 py-2\">离线运行不会意外依赖先前缓存的下载内容\u003C\u002Ftd>\u003C\u002Ftr>\u003Ctr>\u003Ctd class=\"border border-gray-300 px-4 py-2\">推进模拟的证书\u002F更新生命周期\u003C\u002Ftd>\u003Ctd class=\"border border-gray-300 px-4 py-2\">信任和维护依赖关系已被理解\u003C\u002Ftd>\u003C\u002Ftr>\u003Ctr>\u003Ctd class=\"border border-gray-300 px-4 py-2\">通过暂存路径导入新模型\u003C\u002Ftd>\u003Ctd class=\"border border-gray-300 px-4 py-2\">传输\u002F变更流程可操作\u003C\u002Ftd>\u003C\u002Ftr>\u003Ctr>\u003Ctd class=\"border border-gray-300 px-4 py-2\">从备份恢复\u003C\u002Ftd>\u003Ctd class=\"border border-gray-300 px-4 py-2\">恢复过程不需要不可用的云存储\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003C\u002Fdiv>\n\u003Ch2 id=\"section-97\">缓存过一次并不等同于气隙就绪\u003C\u002Fh2>\n\u003Cp>系统可能看起来处于离线状态，因为模型和软件包已从先前的互联网访问中缓存。\u003C\u002Fp>\n\u003Cp>删除缓存或部署到干净节点可能会暴露缺失的分词器文件、Python 软件包、模型清单或远程代码依赖。\u003C\u002Fp>\n\u003Cp>因此，气隙就绪状态应从干净的内部制品进行验证，而不仅仅是从先前连接过的开发者工作站进行验证。\u003C\u002Fp>\n\u003Ch2 id=\"section-101\">气隙内部仍存在哪些威胁？\u003C\u002Fh2>\n\u003Cdiv class=\"overflow-x-auto\">\u003Ctable class=\"w-full border-collapse\">\u003Cthead>\u003Ctr>\u003Cth class=\"border border-gray-300 px-4 py-2 text-left font-semibold\">威胁\u003C\u002Fth>\u003Cth class=\"border border-gray-300 px-4 py-2 text-left font-semibold\">为什么气隙无法消除它\u003C\u002Fth>\u003C\u002Ftr>\u003C\u002Fthead>\u003Ctbody>\u003Ctr>\u003Ctd class=\"border border-gray-300 px-4 py-2\">被入侵的导入制品\u003C\u002Ftd>\u003Ctd class=\"border border-gray-300 px-4 py-2\">恶意软件\u002F模型\u002F软件包可通过授权传输路径进入\u003C\u002Ftd>\u003C\u002Ftr>\u003Ctr>\u003Ctd class=\"border border-gray-300 px-4 py-2\">恶意可移动介质\u003C\u002Ftd>\u003Ctd class=\"border border-gray-300 px-4 py-2\">物理传输可携带可执行载荷\u003C\u002Ftd>\u003C\u002Ftr>\u003Ctr>\u003Ctd class=\"border border-gray-300 px-4 py-2\">内部人员滥用\u003C\u002Ftd>\u003Ctd class=\"border border-gray-300 px-4 py-2\">授权用户已经存在于飞地内部\u003C\u002Ftd>\u003C\u002Ftr>\u003Ctr>\u003Ctd class=\"border border-gray-300 px-4 py-2\">导入文档中的提示注入\u003C\u002Ftd>\u003Ctd class=\"border border-gray-300 px-4 py-2\">不可信内容可在无互联网的情况下影响 RAG\u002F代理\u003C\u002Ftd>\u003C\u002Ftr>\u003Ctr>\u003Ctd class=\"border border-gray-300 px-4 py-2\">权限过高的代理工具\u003C\u002Ftd>\u003Ctd class=\"border border-gray-300 px-4 py-2\">本地工具仍可破坏本地系统\u003C\u002Ftd>\u003C\u002Ftr>\u003Ctr>\u003Ctd class=\"border border-gray-300 px-4 py-2\">跨租户数据泄露\u003C\u002Ftd>\u003Ctd class=\"border border-gray-300 px-4 py-2\">内部授权缺陷仍可能存在\u003C\u002Ftd>\u003C\u002Ftr>\u003Ctr>\u003Ctd class=\"border border-gray-300 px-4 py-2\">存在漏洞的内部软件\u003C\u002Ftd>\u003Ctd class=\"border border-gray-300 px-4 py-2\">缺乏外部连接并不能消除可利用的缺陷\u003C\u002Ftd>\u003C\u002Ftr>\u003Ctr>\u003Ctd class=\"border border-gray-300 px-4 py-2\">横向移动\u003C\u002Ftd>\u003Ctd class=\"border border-gray-300 px-4 py-2\">被入侵的节点可以攻击其他内部连接的节点\u003C\u002Ftd>\u003C\u002Ftr>\u003Ctr>\u003Ctd class=\"border border-gray-300 px-4 py-2\">过时的依赖项\u003C\u002Ftd>\u003Ctd class=\"border border-gray-300 px-4 py-2\">更新节奏缓慢可能导致已知漏洞未修补\u003C\u002Ftd>\u003C\u002Ftr>\u003Ctr>\u003Ctd class=\"border border-gray-300 px-4 py-2\">物理盗窃\u002F篡改\u003C\u002Ftd>\u003Ctd class=\"border border-gray-300 px-4 py-2\">硬件和介质安全仍然至关重要\u003C\u002Ftd>\u003C\u002Ftr>\u003Ctr>\u003Ctd class=\"border border-gray-300 px-4 py-2\">不良模型行为\u003C\u002Ftd>\u003Ctd class=\"border border-gray-300 px-4 py-2\">幻觉、偏见和任务失败与网络无关\u003C\u002Ftd>\u003C\u002Ftr>\u003Ctr>\u003Ctd class=\"border border-gray-300 px-4 py-2\">供应链投毒\u003C\u002Ftd>\u003Ctd class=\"border border-gray-300 px-4 py-2\">受信任的导入源仍可能被入侵\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003C\u002Fdiv>\n\u003Ch2 id=\"section-103\">气隙实际改善了哪些方面\u003C\u002Fh2>\n\u003Cp>真正的气隙可以实质性减少依赖直接远程连接的攻击路径：外部命令与控制、云凭据滥用、面向互联网的服务利用，以及通过普通出站 API 造成的意外数据外泄。\u003C\u002Fp>\n\u003Cp>它还在一个狭义层面上简化了数据驻留：如果不存在路径，推理数据就无法发送到外部云服务。\u003C\u002Fp>\n\u003Cp>当传输边界和内部访问控制同样严格时，这些好处最为显著。管理不善的 USB 流程可能会破坏预期的隔离。\u003C\u002Fp>\n\u003Ch2 id=\"section-107\">气隙使哪些事情变得更困难\u003C\u002Fh2>\n\u003Cdiv class=\"overflow-x-auto\">\u003Ctable class=\"w-full border-collapse\">\u003Cthead>\u003Ctr>\u003Cth class=\"border border-gray-300 px-4 py-2 text-left font-semibold\">领域\u003C\u002Fth>\u003Cth class=\"border border-gray-300 px-4 py-2 text-left font-semibold\">运营后果\u003C\u002Fth>\u003C\u002Ftr>\u003C\u002Fthead>\u003Ctbody>\u003Ctr>\u003Ctd class=\"border border-gray-300 px-4 py-2\">模型更新\u003C\u002Ftd>\u003Ctd class=\"border border-gray-300 px-4 py-2\">手动\u002F分阶段传输，而非直接从模型中心拉取\u003C\u002Ftd>\u003C\u002Ftr>\u003Ctr>\u003Ctd class=\"border border-gray-300 px-4 py-2\">安全补丁\u003C\u002Ftd>\u003Ctd class=\"border border-gray-300 px-4 py-2\">延迟且受治理的导入工作流\u003C\u002Ftd>\u003C\u002Ftr>\u003Ctr>\u003Ctd class=\"border border-gray-300 px-4 py-2\">软件包安装\u003C\u002Ftd>\u003Ctd class=\"border border-gray-300 px-4 py-2\">需要内部镜像源或预构建制品\u003C\u002Ftd>\u003C\u002Ftr>\u003Ctr>\u003Ctd class=\"border border-gray-300 px-4 py-2\">云 AI API\u003C\u002Ftd>\u003Ctd class=\"border border-gray-300 px-4 py-2\">不可用\u003C\u002Ftd>\u003C\u002Ftr>\u003Ctr>\u003Ctd class=\"border border-gray-300 px-4 py-2\">网络搜索\u002F连接器\u003C\u002Ftd>\u003Ctd class=\"border border-gray-300 px-4 py-2\">不可用，除非数据单独导入\u003C\u002Ftd>\u003C\u002Ftr>\u003Ctr>\u003Ctd class=\"border border-gray-300 px-4 py-2\">身份验证\u003C\u002Ftd>\u003Ctd class=\"border border-gray-300 px-4 py-2\">需要内部\u002F可离线运行的身份服务\u003C\u002Ftd>\u003C\u002Ftr>\u003Ctr>\u003Ctd class=\"border border-gray-300 px-4 py-2\">监控\u003C\u002Ftd>\u003Ctd class=\"border border-gray-300 px-4 py-2\">需要内部可观测性和受控导出\u003C\u002Ftd>\u003C\u002Ftr>\u003Ctr>\u003Ctd class=\"border border-gray-300 px-4 py-2\">许可\u003C\u002Ftd>\u003Ctd class=\"border border-gray-300 px-4 py-2\">需要在线激活的产品可能不适用\u003C\u002Ftd>\u003C\u002Ftr>\u003Ctr>\u003Ctd class=\"border border-gray-300 px-4 py-2\">故障排除\u003C\u002Ftd>\u003Ctd class=\"border border-gray-300 px-4 py-2\">无法从生产飞地轻松实时访问供应商资源\u003C\u002Ftd>\u003C\u002Ftr>\u003Ctr>\u003Ctd class=\"border border-gray-300 px-4 py-2\">容量\u003C\u002Ftd>\u003Ctd class=\"border border-gray-300 px-4 py-2\">所有推理计算必须存在于本地\u003C\u002Ftd>\u003C\u002Ftr>\u003Ctr>\u003Ctd class=\"border border-gray-300 px-4 py-2\">灾难恢复\u003C\u002Ftd>\u003Ctd class=\"border border-gray-300 px-4 py-2\">云备份可能不可用或受策略限制\u003C\u002Ftd>\u003C\u002Ftr>\u003Ctr>\u003Ctd class=\"border border-gray-300 px-4 py-2\">知识新鲜度\u003C\u002Ftd>\u003Ctd class=\"border border-gray-300 px-4 py-2\">外部信息仅以导入流程的速度到达\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003C\u002Fdiv>\n\u003Ch2 id=\"section-109\">气隙AI与私有AI\u003C\u002Fh2>\n\u003Cp>私有AI主要关注控制敏感数据和AI处理过程。私有AI平台可以部署在本地，同时仍可访问经批准的云模型或外部服务。\u003C\u002Fp>\n\u003Cp>气隙AI在连接性方面要求更为严格。一个系统可以是私有的，但不一定是气隙的；而一个气隙系统如果每个内部用户都有不受限制的访问权限，其隐私保护仍可能很差。\u003C\u002Fp>\n\u003Cp>安全目标应决定架构：机密性、主权性、韧性和隔离性是相关但不同的需求。\u003C\u002Fp>\n\u003Ch2 id=\"section-113\">气隙AI与主权AI\u003C\u002Fh2>\n\u003Cp>主权AI涉及对更广泛依赖链的控制：数据、模型、基础设施、操作人员、司法管辖区和战略依赖。\u003C\u002Fp>\n\u003Cp>气隙可以通过减少外部运行时依赖来支持主权，但它并不能保证主权控制。隔离区仍可能依赖外国硬件、专有模型许可证或外部更新供应商。\u003C\u002Fp>\n\u003Cp>下一篇规范文章明确区分了这些控制维度。\u003C\u002Fp>\n\u003Ch2 id=\"section-117\">原始实现证据：Aaasaasa AI Client证明了什么——以及没有证明什么\u003C\u002Fh2>\n\u003Caside class=\"editorjs-callout editorjs-callout--note my-6 rounded-xl border p-5 border-gray-300 bg-gray-50 dark:border-gray-700 dark:bg-gray-900\u002F40\" role=\"note\">\u003Cstrong class=\"block mb-2 text-gray-900 dark:text-gray-100\">实现边界\u003C\u002Fstrong>\u003Cdiv class=\"text-gray-700 dark:text-gray-200\">Aaasaasa AI Client是\u003Cstrong>本地推理架构\u003C\u002Fstrong>、提供商抽象以及运行时\u002F模型位置分离的有用证据。它\u003Cstrong>不是已部署气隙环境的证据\u003C\u002Fstrong>。该仓库还支持云和远程路径，且没有经过验证的项目证据能够确立一个物理隔离的安全域。\u003C\u002Fdiv>\u003C\u002Faside>\n\u003Cp>AI Hub将代理\u002F客户端、提供商、模型和连接位置分开。它支持本地Ollama推理和本地提供商Codex操作作为不同选择，而不是假设每个AI请求都发送到云模型。\u003C\u002Fp>\n\u003Cp>该仓库明确指出，本地运行时仍可使用云模型，而Direct Ollama聊天则是本地推理。这一区别与气隙架构直接相关：本地执行并不能证明模型或周围依赖是断开的。\u003C\u002Fp>\n\u003Cp>因此，提供商抽象、本地模型发现和本地推理是具备气隙能力的产品架构的构建模块，但网络边界、离线依赖镜像、受控传输流程以及离线身份\u002F运营仍必须单独设计。\u003C\u002Fp>\n\u003Cdiv class=\"overflow-x-auto\">\u003Ctable class=\"w-full border-collapse\">\u003Cthead>\u003Ctr>\u003Cth class=\"border border-gray-300 px-4 py-2 text-left font-semibold\">已验证的项目能力\u003C\u002Fth>\u003Cth class=\"border border-gray-300 px-4 py-2 text-left font-semibold\">气隙相关性\u003C\u002Fth>\u003C\u002Ftr>\u003C\u002Fthead>\u003Ctbody>\u003Ctr>\u003Ctd class=\"border border-gray-300 px-4 py-2\">本地Ollama推理\u003C\u002Ftd>\u003Ctd class=\"border border-gray-300 px-4 py-2\">支持本地模型执行\u003C\u002Ftd>\u003C\u002Ftr>\u003Ctr>\u003Ctd class=\"border border-gray-300 px-4 py-2\">本地提供商\u002F运行时路径\u003C\u002Ftd>\u003Ctd class=\"border border-gray-300 px-4 py-2\">减少对云推理的依赖\u003C\u002Ftd>\u003C\u002Ftr>\u003Ctr>\u003Ctd class=\"border border-gray-300 px-4 py-2\">提供商\u002F模型\u002F运行时分离\u003C\u002Ftd>\u003Ctd class=\"border border-gray-300 px-4 py-2\">使云依赖显式化而非隐藏\u003C\u002Ftd>\u003C\u002Ftr>\u003Ctr>\u003Ctd class=\"border border-gray-300 px-4 py-2\">集中权限\u003C\u002Ftd>\u003Ctd class=\"border border-gray-300 px-4 py-2\">支持本地工具\u002F数据访问控制\u003C\u002Ftd>\u003C\u002Ftr>\u003Ctr>\u003Ctd class=\"border border-gray-300 px-4 py-2\">同时存在云\u002F远程提供商支持\u003C\u002Ftd>\u003Ctd class=\"border border-gray-300 px-4 py-2\">证明产品本身具备混合能力，而非天生气隙\u003C\u002Ftd>\u003C\u002Ftr>\u003Ctr>\u003Ctd class=\"border border-gray-300 px-4 py-2\">没有经过验证的隔离部署边界\u003C\u002Ftd>\u003Ctd class=\"border border-gray-300 px-4 py-2\">防止夸大气隙成熟度\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003C\u002Fdiv>\n\u003Ch2 id=\"section-123\">何时气隙AI是合理的？\u003C\u002Fh2>\n\u003Cdiv class=\"overflow-x-auto\">\u003Ctable class=\"w-full border-collapse\">\u003Cthead>\u003Ctr>\u003Cth class=\"border border-gray-300 px-4 py-2 text-left font-semibold\">气隙可能合理的情况\u003C\u002Fth>\u003Cth class=\"border border-gray-300 px-4 py-2 text-left font-semibold\">连接式私有架构可能更好的情况\u003C\u002Fth>\u003C\u002Ftr>\u003C\u002Fthead>\u003Ctbody>\u003Ctr>\u003Ctd class=\"border border-gray-300 px-4 py-2\">安全策略明确要求物理隔离域\u003C\u002Ftd>\u003Ctd class=\"border border-gray-300 px-4 py-2\">主要需求仅是提示\u002F数据不被公共消费服务使用\u003C\u002Ftd>\u003C\u002Ftr>\u003Ctr>\u003Ctd class=\"border border-gray-300 px-4 py-2\">机密或极其敏感的数据不能跨越外部网络\u003C\u002Ftd>\u003Ctd class=\"border border-gray-300 px-4 py-2\">经批准的企业云\u002F私有端点满足数据控制要求\u003C\u002Ftd>\u003C\u002Ftr>\u003Ctr>\u003Ctd class=\"border border-gray-300 px-4 py-2\">运营环境没有可靠的外部连接\u003C\u002Ftd>\u003Ctd class=\"border border-gray-300 px-4 py-2\">互联网可用且运营敏捷性很重要\u003C\u002Ftd>\u003C\u002Ftr>\u003Ctr>\u003Ctd class=\"border border-gray-300 px-4 py-2\">任务连续性不得依赖云\u002F提供商可用性\u003C\u002Ftd>\u003Ctd class=\"border border-gray-300 px-4 py-2\">托管模型质量和快速升级更有价值\u003C\u002Ftd>\u003C\u002Ftr>\u003Ctr>\u003Ctd class=\"border border-gray-300 px-4 py-2\">受监管\u002F关键环境要求受控传输\u003C\u002Ftd>\u003Ctd class=\"border border-gray-300 px-4 py-2\">标准安全控制能够满足实际威胁模型\u003C\u002Ftd>\u003C\u002Ftr>\u003Ctr>\u003Ctd class=\"border border-gray-300 px-4 py-2\">禁止外部SaaS\u002FAPI访问\u003C\u002Ftd>\u003Ctd class=\"border border-gray-300 px-4 py-2\">业务工作流严重依赖外部连接器\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003C\u002Fdiv>\n\u003Cp>气隙应是从威胁模型或策略中推导出的需求，而不是一种声望功能。当被消除的连接路径本身不可接受时，它具有真正的安全价值。\u003C\u002Fp>\n\u003Cp>对于许多企业用例，具有出口限制、本地推理和经批准更新渠道的严格控制私有网络，可能比严格的物理气隙在安全性和可维护性之间提供更好的平衡。\u003C\u002Fp>\n\u003Ch2 id=\"section-127\">实用的气隙AI设计流程\u003C\u002Fh2>\n\u003Csection class=\"editorjs-process my-6\">\u003Ch3 class=\"mb-3 text-lg font-semibold\">从边界向内设计\u003C\u002Fh3>\u003Cdiv class=\"grid grid-cols-1 md:grid-cols-2 xl:grid-cols-3 gap-4\">\u003Cdiv class=\"editorjs-process__step min-w-0  rounded-xl border border-gray-200 dark:border-gray-700 p-4\">\u003Cdiv class=\"text-xs font-semibold text-gray-500 dark:text-gray-400\">1\u003C\u002Fdiv>\u003Cdiv class=\"mt-1 font-semibold text-gray-900 dark:text-gray-100\">1. 定义气隙隔离的内容\u003C\u002Fdiv>\u003Cdiv class=\"mt-1 text-sm text-gray-600 dark:text-gray-300\">明确安全域，以及需求是严格的物理隔离还是仅仅无互联网连接。\u003C\u002Fdiv>\u003C\u002Fdiv>\u003Cdiv class=\"editorjs-process__step min-w-0  rounded-xl border border-gray-200 dark:border-gray-700 p-4\">\u003Cdiv class=\"text-xs font-semibold text-gray-500 dark:text-gray-400\">2\u003C\u002Fdiv>\u003Cdiv class=\"mt-1 font-semibold text-gray-900 dark:text-gray-100\">2. 清点所有外部依赖\u003C\u002Fdiv>\u003Cdiv class=\"mt-1 text-sm text-gray-600 dark:text-gray-300\">模型、软件包、注册表、身份、遥测、许可、存储、API、DNS\u002F时间和支持服务。\u003C\u002Fdiv>\u003C\u002Fdiv>\u003Cdiv class=\"editorjs-process__step min-w-0  rounded-xl border border-gray-200 dark:border-gray-700 p-4\">\u003Cdiv class=\"text-xs font-semibold text-gray-500 dark:text-gray-400\">3\u003C\u002Fdiv>\u003Cdiv class=\"mt-1 font-semibold text-gray-900 dark:text-gray-100\">3. 选择支持离线的模型和运行时\u003C\u002Fdiv>\u003Cdiv class=\"mt-1 text-sm text-gray-600 dark:text-gray-300\">验证模型资产和运行时代码无需远程调用即可加载。\u003C\u002Fdiv>\u003C\u002Fdiv>\u003Cdiv class=\"editorjs-process__step min-w-0  rounded-xl border border-gray-200 dark:border-gray-700 p-4\">\u003Cdiv class=\"text-xs font-semibold text-gray-500 dark:text-gray-400\">4\u003C\u002Fdiv>\u003Cdiv class=\"mt-1 font-semibold text-gray-900 dark:text-gray-100\">4. 构建内部制品仓库\u003C\u002Fdiv>\u003Cdiv class=\"mt-1 text-sm text-gray-600 dark:text-gray-300\">为容器、软件包、模型和更新创建可信来源。\u003C\u002Fdiv>\u003C\u002Fdiv>\u003Cdiv class=\"editorjs-process__step min-w-0  rounded-xl border border-gray-200 dark:border-gray-700 p-4\">\u003Cdiv class=\"text-xs font-semibold text-gray-500 dark:text-gray-400\">5\u003C\u002Fdiv>\u003Cdiv class=\"mt-1 font-semibold text-gray-900 dark:text-gray-100\">5. 设计受控传输\u003C\u002Fdiv>\u003Cdiv class=\"mt-1 text-sm text-gray-600 dark:text-gray-300\">定义暂存、验证、介质\u002F网关处理、审批和来源追溯。\u003C\u002Fdiv>\u003C\u002Fdiv>\u003Cdiv class=\"editorjs-process__step min-w-0  rounded-xl border border-gray-200 dark:border-gray-700 p-4\">\u003Cdiv class=\"text-xs font-semibold text-gray-500 dark:text-gray-400\">6\u003C\u002Fdiv>\u003Cdiv class=\"mt-1 font-semibold text-gray-900 dark:text-gray-100\">6. 构建内部身份和授权\u003C\u002Fdiv>\u003Cdiv class=\"mt-1 text-sm text-gray-600 dark:text-gray-300\">确保用户、服务和工具无需云依赖即可认证。\u003C\u002Fdiv>\u003C\u002Fdiv>\u003Cdiv class=\"editorjs-process__step min-w-0  rounded-xl border border-gray-200 dark:border-gray-700 p-4\">\u003Cdiv class=\"text-xs font-semibold text-gray-500 dark:text-gray-400\">7\u003C\u002Fdiv>\u003Cdiv class=\"mt-1 font-semibold text-gray-900 dark:text-gray-100\">7. 保持RAG和工具本地化\u003C\u002Fdiv>\u003Cdiv class=\"mt-1 text-sm text-gray-600 dark:text-gray-300\">在隔离区内部署知识、嵌入、索引和所需的服务API。\u003C\u002Fdiv>\u003C\u002Fdiv>\u003Cdiv class=\"editorjs-process__step min-w-0  rounded-xl border border-gray-200 dark:border-gray-700 p-4\">\u003Cdiv class=\"text-xs font-semibold text-gray-500 dark:text-gray-400\">8\u003C\u002Fdiv>\u003Cdiv class=\"mt-1 font-semibold text-gray-900 dark:text-gray-100\">8. 构建内部可观测性\u003C\u002Fdiv>\u003Cdiv class=\"mt-1 text-sm text-gray-600 dark:text-gray-300\">在本地运行日志、指标、追踪和安全监控。\u003C\u002Fdiv>\u003C\u002Fdiv>\u003Cdiv class=\"editorjs-process__step min-w-0  rounded-xl border border-gray-200 dark:border-gray-700 p-4\">\u003Cdiv class=\"text-xs font-semibold text-gray-500 dark:text-gray-400\">9\u003C\u002Fdiv>\u003Cdiv class=\"mt-1 font-semibold text-gray-900 dark:text-gray-100\">9. 定义补丁\u002F模型更新节奏\u003C\u002Fdiv>\u003Cdiv class=\"mt-1 text-sm text-gray-600 dark:text-gray-300\">在漏洞响应与受控导入流程之间取得平衡。\u003C\u002Fdiv>\u003C\u002Fdiv>\u003Cdiv class=\"editorjs-process__step min-w-0  rounded-xl border border-gray-200 dark:border-gray-700 p-4\">\u003Cdiv class=\"text-xs font-semibold text-gray-500 dark:text-gray-400\">10\u003C\u002Fdiv>\u003Cdiv class=\"mt-1 font-semibold text-gray-900 dark:text-gray-100\">10. 从干净的断开状态进行测试\u003C\u002Fdiv>\u003Cdiv class=\"mt-1 text-sm text-gray-600 dark:text-gray-300\">在无继承缓存或隐藏互联网访问的情况下冷启动并运行。\u003C\u002Fdiv>\u003C\u002Fdiv>\u003Cdiv class=\"editorjs-process__step min-w-0  rounded-xl border border-gray-200 dark:border-gray-700 p-4\">\u003Cdiv class=\"text-xs font-semibold text-gray-500 dark:text-gray-400\">11\u003C\u002Fdiv>\u003Cdiv class=\"mt-1 font-semibold text-gray-900 dark:text-gray-100\">11. 测试入侵路径\u003C\u002Fdiv>\u003Cdiv class=\"mt-1 text-sm text-gray-600 dark:text-gray-300\">演练可移动介质、供应链、提示注入、内部人员和横向移动场景。\u003C\u002Fdiv>\u003C\u002Fdiv>\u003Cdiv class=\"editorjs-process__step min-w-0  rounded-xl border border-gray-200 dark:border-gray-700 p-4\">\u003Cdiv class=\"text-xs font-semibold text-gray-500 dark:text-gray-400\">12\u003C\u002Fdiv>\u003Cdiv class=\"mt-1 font-semibold text-gray-900 dark:text-gray-100\">12. 记录例外和导出\u003C\u002Fdiv>\u003Cdiv class=\"mt-1 text-sm text-gray-600 dark:text-gray-300\">每条允许的跨边界路径都应有明确的用途、负责人和控制集。\u003C\u002Fdiv>\u003C\u002Fdiv>\u003C\u002Fdiv>\u003C\u002Fsection>\n\u003Ch2 id=\"section-129\">气隙AI架构检查清单\u003C\u002Fh2>\n\u003Cdiv class=\"overflow-x-auto\">\u003Ctable class=\"w-full border-collapse\">\u003Cthead>\u003Ctr>\u003Cth class=\"border border-gray-300 px-4 py-2 text-left font-semibold\">问题\u003C\u002Fth>\u003Cth class=\"border border-gray-300 px-4 py-2 text-left font-semibold\">预期证据\u003C\u002Fth>\u003C\u002Ftr>\u003C\u002Fthead>\u003Ctbody>\u003Ctr>\u003Ctd class=\"border border-gray-300 px-4 py-2\">究竟什么与什么隔离？\u003C\u002Ftd>\u003Ctd class=\"border border-gray-300 px-4 py-2\">记录的安全域边界\u003C\u002Ftd>\u003C\u002Ftr>\u003Ctr>\u003Ctd class=\"border border-gray-300 px-4 py-2\">边界是否物理断开？\u003C\u002Ftd>\u003Ctd class=\"border border-gray-300 px-4 py-2\">若声称严格气隙，需提供网络\u002F物理架构证据\u003C\u002Ftd>\u003C\u002Ftr>\u003Ctr>\u003Ctd class=\"border border-gray-300 px-4 py-2\">数据如何跨越边界？\u003C\u002Ftd>\u003Ctd class=\"border border-gray-300 px-4 py-2\">授权的非自动化\u002F手动或明确记录的断开工作流\u003C\u002Ftd>\u003C\u002Ftr>\u003Ctr>\u003Ctd class=\"border border-gray-300 px-4 py-2\">每个模型能否离线冷启动？\u003C\u002Ftd>\u003Ctd class=\"border border-gray-300 px-4 py-2\">离线加载测试\u003C\u002Ftd>\u003C\u002Ftr>\u003Ctr>\u003Ctd class=\"border border-gray-300 px-4 py-2\">分词器\u002F配置\u002F运行时资产是否完整？\u003C\u002Ftd>\u003Ctd class=\"border border-gray-300 px-4 py-2\">已验证的内部模型包\u003C\u002Ftd>\u003C\u002Ftr>\u003Ctr>\u003Ctd class=\"border border-gray-300 px-4 py-2\">容器\u002F软件包来自哪里？\u003C\u002Ftd>\u003Ctd class=\"border border-gray-300 px-4 py-2\">内部可信镜像\u002F仓库\u003C\u002Ftd>\u003C\u002Ftr>\u003Ctr>\u003Ctd class=\"border border-gray-300 px-4 py-2\">身份能否在无云服务下工作？\u003C\u002Ftd>\u003Ctd class=\"border border-gray-300 px-4 py-2\">内部IdP\u002FPKI\u002F服务凭据路径\u003C\u002Ftd>\u003C\u002Ftr>\u003Ctr>\u003Ctd class=\"border border-gray-300 px-4 py-2\">RAG能否离线摄取\u002F查询？\u003C\u002Ftd>\u003Ctd class=\"border border-gray-300 px-4 py-2\">本地摄取、嵌入、索引和检索\u003C\u002Ftd>\u003C\u002Ftr>\u003Ctr>\u003Ctd class=\"border border-gray-300 px-4 py-2\">哪些代理工具仍然可用？\u003C\u002Ftd>\u003Ctd class=\"border border-gray-300 px-4 py-2\">内部能力清单\u003C\u002Ftd>\u003C\u002Ftr>\u003Ctr>\u003Ctd class=\"border border-gray-300 px-4 py-2\">补丁如何导入？\u003C\u002Ftd>\u003Ctd class=\"border border-gray-300 px-4 py-2\">受控维护流程\u003C\u002Ftd>\u003C\u002Ftr>\u003Ctr>\u003Ctd class=\"border border-gray-300 px-4 py-2\">制品如何验证？\u003C\u002Ftd>\u003Ctd class=\"border border-gray-300 px-4 py-2\">完整性\u002F来源\u002F恶意软件\u002F供应链控制\u003C\u002Ftd>\u003C\u002Ftr>\u003Ctr>\u003Ctd class=\"border border-gray-300 px-4 py-2\">可移动介质如何管理？\u003C\u002Ftd>\u003Ctd class=\"border border-gray-300 px-4 py-2\">介质处理和消毒策略\u003C\u002Ftd>\u003C\u002Ftr>\u003Ctr>\u003Ctd class=\"border border-gray-300 px-4 py-2\">清除缓存后系统能否运行？\u003C\u002Ftd>\u003Ctd class=\"border border-gray-300 px-4 py-2\">干净环境离线测试\u003C\u002Ftd>\u003C\u002Ftr>\u003Ctr>\u003Ctd class=\"border border-gray-300 px-4 py-2\">日志和追踪存储在哪里？\u003C\u002Ftd>\u003Ctd class=\"border border-gray-300 px-4 py-2\">内部可观测性平台\u003C\u002Ftd>\u003C\u002Ftr>\u003Ctr>\u003Ctd class=\"border border-gray-300 px-4 py-2\">导出如何审批？\u003C\u002Ftd>\u003Ctd class=\"border border-gray-300 px-4 py-2\">受控出口流程\u003C\u002Ftd>\u003C\u002Ftr>\u003Ctr>\u003Ctd class=\"border border-gray-300 px-4 py-2\">什么证明这是气隙而非仅仅本地？\u003C\u002Ftd>\u003Ctd class=\"border border-gray-300 px-4 py-2\">边界和传输证据，而非模型位置\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003C\u002Fdiv>\n\u003Ch2 id=\"section-131\">常见的气隙AI故障模式\u003C\u002Fh2>\n\u003Cdiv class=\"overflow-x-auto\">\u003Ctable class=\"w-full border-collapse\">\u003Cthead>\u003Ctr>\u003Cth class=\"border border-gray-300 px-4 py-2 text-left font-semibold\">故障模式\u003C\u002Fth>\u003Cth class=\"border border-gray-300 px-4 py-2 text-left font-semibold\">实际失败原因\u003C\u002Fth>\u003C\u002Ftr>\u003C\u002Fthead>\u003Ctbody>\u003Ctr>\u003Ctd class=\"border border-gray-300 px-4 py-2\">本地模型在启动时仍下载分词器\u002F配置\u003C\u002Ftd>\u003Ctd class=\"border border-gray-300 px-4 py-2\">模型包不完整\u003C\u002Ftd>\u003C\u002Ftr>\u003Ctr>\u003Ctd class=\"border border-gray-300 px-4 py-2\">容器引用公共注册表\u003C\u002Ftd>\u003Ctd class=\"border border-gray-300 px-4 py-2\">部署非自包含\u003C\u002Ftd>\u003C\u002Ftr>\u003Ctr>\u003Ctd class=\"border border-gray-300 px-4 py-2\">登录需要云身份\u003C\u002Ftd>\u003Ctd class=\"border border-gray-300 px-4 py-2\">应用是本地但身份不是\u003C\u002Ftd>\u003C\u002Ftr>\u003Ctr>\u003Ctd class=\"border border-gray-300 px-4 py-2\">需要外部许可证服务器\u003C\u002Ftd>\u003Ctd class=\"border border-gray-300 px-4 py-2\">供应商依赖与离线运行矛盾\u003C\u002Ftd>\u003C\u002Ftr>\u003Ctr>\u003Ctd class=\"border border-gray-300 px-4 py-2\">缺少嵌入模型\u003C\u002Ftd>\u003Ctd class=\"border border-gray-300 px-4 py-2\">聊天可用但RAG摄取失败\u003C\u002Ftd>\u003C\u002Ftr>\u003Ctr>\u003Ctd class=\"border border-gray-300 px-4 py-2\">代理工具调用公共SaaS\u003C\u002Ftd>\u003Ctd class=\"border border-gray-300 px-4 py-2\">代理架构不兼容气隙\u003C\u002Ftd>\u003C\u002Ftr>\u003Ctr>\u003Ctd class=\"border border-gray-300 px-4 py-2\">仅GPU节点隔离\u003C\u002Ftd>\u003Ctd class=\"border border-gray-300 px-4 py-2\">数据库、UI或监控仍依赖外部服务\u003C\u002Ftd>\u003C\u002Ftr>\u003Ctr>\u003Ctd class=\"border border-gray-300 px-4 py-2\">USB导入不规范\u003C\u002Ftd>\u003Ctd class=\"border border-gray-300 px-4 py-2\">传输边界成为不受控攻击路径\u003C\u002Ftd>\u003C\u002Ftr>\u003Ctr>\u003Ctd class=\"border border-gray-300 px-4 py-2\">无补丁流程\u003C\u002Ftd>\u003Ctd class=\"border border-gray-300 px-4 py-2\">隔离导致漏洞债务累积\u003C\u002Ftd>\u003C\u002Ftr>\u003Ctr>\u003Ctd class=\"border border-gray-300 px-4 py-2\">使用有缓存的开发机作为证明\u003C\u002Ftd>\u003Ctd class=\"border border-gray-300 px-4 py-2\">全新部署在无互联网时失败\u003C\u002Ftd>\u003C\u002Ftr>\u003Ctr>\u003Ctd class=\"border border-gray-300 px-4 py-2\">气隙替代了授权思考\u003C\u002Ftd>\u003Ctd class=\"border border-gray-300 px-4 py-2\">内部用户\u002F服务权限过高\u003C\u002Ftd>\u003C\u002Ftr>\u003Ctr>\u003Ctd class=\"border border-gray-300 px-4 py-2\">气隙标签用于仅防火墙出口阻断\u003C\u002Ftd>\u003Ctd class=\"border border-gray-300 px-4 py-2\">安全文档夸大了实际边界\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003C\u002Fdiv>\n\u003Ch2 id=\"section-133\">常见误解\u003C\u002Fh2>\n\u003Cdiv class=\"overflow-x-auto\">\u003Ctable class=\"w-full border-collapse\">\u003Cthead>\u003Ctr>\u003Cth class=\"border border-gray-300 px-4 py-2 text-left font-semibold\">误解\u003C\u002Fth>\u003Cth class=\"border border-gray-300 px-4 py-2 text-left font-semibold\">更正\u003C\u002Fth>\u003C\u002Ftr>\u003C\u002Fthead>\u003Ctbody>\u003Ctr>\u003Ctd class=\"border border-gray-300 px-4 py-2\">“本地AI就是气隙AI。”\u003C\u002Ftd>\u003Ctd class=\"border border-gray-300 px-4 py-2\">本地描述推理运行位置；气隙描述安全\u002F网络边界。\u003C\u002Ftd>\u003C\u002Ftr>\u003Ctr>\u003Ctd class=\"border border-gray-300 px-4 py-2\">“气隙意味着一台独立PC。”\u003C\u002Ftd>\u003Ctd class=\"border border-gray-300 px-4 py-2\">隔离区可以包含整个内部网络或集群。\u003C\u002Ftd>\u003C\u002Ftr>\u003Ctr>\u003Ctd class=\"border border-gray-300 px-4 py-2\">“无互联网等于严格气隙。”\u003C\u002Ftd>\u003Ctd class=\"border border-gray-300 px-4 py-2\">根据NIST定义，分离系统还缺乏物理连接，且跨边界传输是非自动化的。\u003C\u002Ftd>\u003C\u002Ftr>\u003Ctr>\u003Ctd class=\"border border-gray-300 px-4 py-2\">“气隙消除网络风险。”\u003C\u002Ftd>\u003Ctd class=\"border border-gray-300 px-4 py-2\">供应链、可移动介质、内部人员、内部网络和应用风险仍然存在。\u003C\u002Ftd>\u003C\u002Ftr>\u003Ctr>\u003Ctd class=\"border border-gray-300 px-4 py-2\">“RAG需要云。”\u003C\u002Ftd>\u003Ctd class=\"border border-gray-300 px-4 py-2\">RAG可以完全使用本地模型、索引和数据运行。\u003C\u002Ftd>\u003C\u002Ftr>\u003Ctr>\u003Ctd class=\"border border-gray-300 px-4 py-2\">“代理无法离线工作。”\u003C\u002Ftd>\u003Ctd class=\"border border-gray-300 px-4 py-2\">代理可以使用内部\u002F本地工具；它们只是无法访问不可用的外部服务。\u003C\u002Ftd>\u003C\u002Ftr>\u003Ctr>\u003Ctd class=\"border border-gray-300 px-4 py-2\">“安装后系统无需更新。”\u003C\u002Ftd>\u003Ctd class=\"border border-gray-300 px-4 py-2\">补丁、驱动、模型和依赖仍需生命周期管理。\u003C\u002Ftd>\u003C\u002Ftr>\u003Ctr>\u003Ctd class=\"border border-gray-300 px-4 py-2\">“下载的模型是自包含的。”\u003C\u002Ftd>\u003Ctd class=\"border border-gray-300 px-4 py-2\">分词器、远程代码、库或模型资产仍可能触发网络依赖。\u003C\u002Ftd>\u003C\u002Ftr>\u003Ctr>\u003Ctd class=\"border border-gray-300 px-4 py-2\">“私有AI和气隙AI相同。”\u003C\u002Ftd>\u003Ctd class=\"border border-gray-300 px-4 py-2\">私有AI是数据\u002F控制属性；气隙是连接属性。\u003C\u002Ftd>\u003C\u002Ftr>\u003Ctr>\u003Ctd class=\"border border-gray-300 px-4 py-2\">“气隙保证主权。”\u003C\u002Ftd>\u003Ctd class=\"border border-gray-300 px-4 py-2\">外部硬件、许可、模型和供应链仍可能是依赖。\u003C\u002Ftd>\u003C\u002Ftr>\u003C\u002Ftbody>\u003C\u002Ftable>\u003C\u002Fdiv>\n\u003Ch2 id=\"section-135\">局限性\u003C\u002Fh2>\n\u003Cp>严格气隙使外部知识更新更慢，因为每个新来源都必须经过传输流程。\u003C\u002Fp>\n\u003Cp>当许可、远程代码要求、硬件需求或仅提供商API无法离线满足时，它们可能限制模型选择。\u003C\u002Fp>\n\u003Cp>它们增加运营成本，因为通常作为云服务消费的基础设施必须在内部拥有和维护。\u003C\u002Fp>\n\u003Cp>它们还可能造成补丁延迟：更强的变更控制可能保持系统稳定，同时延迟紧急漏洞修复。\u003C\u002Fp>\n\u003Cp>因此，气隙AI应作为多种安全架构之一进行评估，而非假定其普遍优越。\u003C\u002Fp>\n\u003Ch2 id=\"section-141\">什么会改变这个答案？\u003C\u002Fh2>\n\u003Cp>供应商对断开操作的支持变化很快。新的模型格式、签名的OCI制品、离线许可机制和集成模型注册表可以减少操作摩擦。\u003C\u002Fp>\n\u003Cp>即使供应商继续宽松地使用这些术语，严格气隙与断开部署之间的区别仍将重要。\u003C\u002Fp>\n\u003Cp>稳定的原则是，真正的气隙声明取决于系统边界和传输机制，而非LLM是否恰好本地运行。\u003C\u002Fp>\n\u003Ch2 id=\"section-145\">相关规范知识\u003C\u002Fh2>\n\u003Cp>气隙AI是一个部署\u002F安全架构节点。私有AI、主权AI和提供商抽象回答了关于机密性、控制和依赖性的不同问题。\u003C\u002Fp>\n\u003Cp>在断开连接的环境中，MLOps\u002FLLMOps 的要求更高，因为模型、软件包和更新的生命周期必须通过内部仓库和受控传输来运作。\u003C\u002Fp>\n\u003Cp>只要数据和工具在内部可用，RAG 和代理式 AI 在隔离区内仍然是有效的模式。\u003C\u002Fp>\n\u003Caside class=\"editorjs-referral my-6\">\u003Ca href=\"https:\u002F\u002Fstajic.de\u002Fzh\u002Fblog\u002Fai-agent-memory-is-not-rag-how-to-separate-memory-retrieval-state-and-context\" class=\"flex flex-col sm:flex-row gap-4 rounded-xl border border-gray-200 dark:border-gray-700 p-4 transition hover:border-primary-500\">\u003Cdiv class=\"min-w-0 flex-1\">\u003Cstrong class=\"block text-lg text-gray-900 dark:text-gray-100\">AI 代理记忆不是 RAG：如何区分记忆、检索、状态和上下文\u003C\u002Fstrong>\u003Cp class=\"mt-2 text-sm text-gray-600 dark:text-gray-300\">气隙 AI 仍然需要在持久记忆、权威状态、检索和模型上下文之间建立正确的内部边界。\u003C\u002Fp>\u003Cspan class=\"mt-3 inline-flex text-sm font-medium text-primary-600 dark:text-primary-400\">阅读记忆架构文章 →\u003C\u002Fspan>\u003C\u002Fdiv>\u003C\u002Fa>\u003C\u002Faside>\n\u003Ch2 id=\"section-150\">常见问题\u003C\u002Fh2>\n\u003Csection class=\"editorjs-faq my-6 rounded-xl border border-gray-200 p-5 dark:border-gray-700\">\u003Ch3 class=\"mb-3 text-lg font-semibold\">气隙 AI 常见问题\u003C\u002Fh3>\u003Cdiv id=\"faq1\" class=\"border-t border-gray-200 py-4 first:border-t-0 dark:border-gray-700\">\u003Ch4 class=\"font-semibold text-gray-900 dark:text-gray-100\">什么是气隙 AI？\u003C\u002Fh4>\u003Cdiv class=\"mt-2 text-gray-600 dark:text-gray-300\">气隙 AI 是部署在与外部系统物理断开的安全域内的 AI，根据严格的 NIST 定义，跨边界传输通过受控的非自动化程序进行。\u003C\u002Fdiv>\u003C\u002Fdiv>\u003Cdiv id=\"faq2\" class=\"border-t border-gray-200 py-4 first:border-t-0 dark:border-gray-700\">\u003Ch4 class=\"font-semibold text-gray-900 dark:text-gray-100\">气隙 AI 需要互联网访问吗？\u003C\u002Fh4>\u003Cdiv class=\"mt-2 text-gray-600 dark:text-gray-300\">正常推理和运行不需要。所需的模型、软件包、数据和服务必须在隔离环境内可用。\u003C\u002Fdiv>\u003C\u002Fdiv>\u003Cdiv id=\"faq3\" class=\"border-t border-gray-200 py-4 first:border-t-0 dark:border-gray-700\">\u003Ch4 class=\"font-semibold text-gray-900 dark:text-gray-100\">本地 LLM 是否自动就是气隙的？\u003C\u002Fh4>\u003Cdiv class=\"mt-2 text-gray-600 dark:text-gray-300\">不是。本地模型可以运行在仍然具有互联网访问或使用云身份、工具或存储的机器上。气隙描述的是完整的系统边界。\u003C\u002Fdiv>\u003C\u002Fdiv>\u003Cdiv id=\"faq4\" class=\"border-t border-gray-200 py-4 first:border-t-0 dark:border-gray-700\">\u003Ch4 class=\"font-semibold text-gray-900 dark:text-gray-100\">RAG 能在气隙网络中工作吗？\u003C\u002Fh4>\u003Cdiv class=\"mt-2 text-gray-600 dark:text-gray-300\">可以。文档、嵌入模型、向量或词法索引、重排序器和生成模型都可以在本地运行。外部知识必须通过受控边界导入。\u003C\u002Fdiv>\u003C\u002Fdiv>\u003Cdiv id=\"faq5\" class=\"border-t border-gray-200 py-4 first:border-t-0 dark:border-gray-700\">\u003Ch4 class=\"font-semibold text-gray-900 dark:text-gray-100\">AI 代理能在气隙环境中工作吗？\u003C\u002Fh4>\u003Cdiv class=\"mt-2 text-gray-600 dark:text-gray-300\">可以，如果它们的工具和所需系统在隔离网络内可用。未经允许的跨边界机制，公共 SaaS 和云 API 不可用。\u003C\u002Fdiv>\u003C\u002Fdiv>\u003Cdiv id=\"faq6\" class=\"border-t border-gray-200 py-4 first:border-t-0 dark:border-gray-700\">\u003Ch4 class=\"font-semibold text-gray-900 dark:text-gray-100\">在气隙环境中如何更新模型？\u003C\u002Fh4>\u003Cdiv class=\"mt-2 text-gray-600 dark:text-gray-300\">模型通常在连接的暂存环境中获取和验证，通过批准的流程传输，并发布到内部模型\u002F工件仓库。\u003C\u002Fdiv>\u003C\u002Fdiv>\u003Cdiv id=\"faq7\" class=\"border-t border-gray-200 py-4 first:border-t-0 dark:border-gray-700\">\u003Ch4 class=\"font-semibold text-gray-900 dark:text-gray-100\">本地部署 AI 与气隙 AI 相同吗？\u003C\u002Fh4>\u003Cdiv class=\"mt-2 text-gray-600 dark:text-gray-300\">不同。本地部署描述的是基础设施位置。本地系统可以保持互联网连接。\u003C\u002Fdiv>\u003C\u002Fdiv>\u003Cdiv id=\"faq8\" class=\"border-t border-gray-200 py-4 first:border-t-0 dark:border-gray-700\">\u003Ch4 class=\"font-semibold text-gray-900 dark:text-gray-100\">私有 AI 与气隙 AI 相同吗？\u003C\u002Fh4>\u003Cdiv class=\"mt-2 text-gray-600 dark:text-gray-300\">不同。私有 AI 关乎数据\u002F控制要求，仍然可以使用连接的基础设施。气隙特指网络\u002F域隔离。\u003C\u002Fdiv>\u003C\u002Fdiv>\u003Cdiv id=\"faq9\" class=\"border-t border-gray-200 py-4 first:border-t-0 dark:border-gray-700\">\u003Ch4 class=\"font-semibold text-gray-900 dark:text-gray-100\">气隙能使 AI 安全吗？\u003C\u002Fh4>\u003Cdiv class=\"mt-2 text-gray-600 dark:text-gray-300\">它消除或减少了一些远程连接风险，但并未消除供应链、可移动介质、内部人员、内部授权、物理或模型行为风险。\u003C\u002Fdiv>\u003C\u002Fdiv>\u003Cdiv id=\"faq10\" class=\"border-t border-gray-200 py-4 first:border-t-0 dark:border-gray-700\">\u003Ch4 class=\"font-semibold text-gray-900 dark:text-gray-100\">气隙就绪的最佳测试是什么？\u003C\u002Fh4>\u003Cdiv class=\"mt-2 text-gray-600 dark:text-gray-300\">在干净环境中部署或冷启动整个堆栈，所有外部连接不可用，并验证模型、身份、RAG、工具、监控、更新和恢复仅依赖经批准的内部工件和服务。\u003C\u002Fdiv>\u003C\u002Fdiv>\u003C\u002Fsection>\n\u003Ch2 id=\"section-152\">术语表\u003C\u002Fh2>\n\u003Csection class=\"editorjs-glossary my-6 rounded-xl border border-gray-200 dark:border-gray-700 p-5\">\u003Ch3 class=\"mb-3 text-lg font-semibold\">关键气隙 AI 术语\u003C\u002Fh3>\u003Cdl>\u003Cdiv id=\"air-gap\" class=\"border-t border-gray-200 dark:border-gray-700 py-3 first:border-t-0\">\u003Cdt class=\"font-semibold text-gray-900 dark:text-gray-100\">气隙\u003C\u002Fdt>\u003Cdd class=\"mt-1 text-gray-600 dark:text-gray-300\">安全域接口，系统之间没有物理连接，根据 NIST 术语表定义，任何跨边界的逻辑传输都是非自动化\u002F手动的。\u003C\u002Fdd>\u003C\u002Fdiv>\u003Cdiv id=\"air-gapped-ai\" class=\"border-t border-gray-200 dark:border-gray-700 py-3 first:border-t-0\">\u003Cdt class=\"font-semibold text-gray-900 dark:text-gray-100\">气隙 AI\u003C\u002Fdt>\u003Cdd class=\"mt-1 text-gray-600 dark:text-gray-300\">部署在气隙安全域内的 AI 系统，其推理和操作依赖项在本地可用。\u003C\u002Fdd>\u003C\u002Fdiv>\u003Cdiv id=\"disconnected-environment\" class=\"border-t border-gray-200 dark:border-gray-700 py-3 first:border-t-0\">\u003Cdt class=\"font-semibold text-gray-900 dark:text-gray-100\">断开连接的环境\u003C\u002Fdt>\u003Cdd class=\"mt-1 text-gray-600 dark:text-gray-300\">没有直接外部互联网访问的部署环境；实现可能使用受控镜像或堡垒工作流。\u003C\u002Fdd>\u003C\u002Fdiv>\u003Cdiv id=\"offline-capable-ai\" class=\"border-t border-gray-200 dark:border-gray-700 py-3 first:border-t-0\">\u003Cdt class=\"font-semibold text-gray-900 dark:text-gray-100\">离线能力 AI\u003C\u002Fdt>\u003Cdd class=\"mt-1 text-gray-600 dark:text-gray-300\">能够在没有互联网连接的情况下运行部分或全部功能的 AI 应用，但不一定永久隔离。\u003C\u002Fdd>\u003C\u002Fdiv>\u003Cdiv id=\"local-ai\" class=\"border-t border-gray-200 dark:border-gray-700 py-3 first:border-t-0\">\u003Cdt class=\"font-semibold text-gray-900 dark:text-gray-100\">本地 AI\u003C\u002Fdt>\u003Cdd class=\"mt-1 text-gray-600 dark:text-gray-300\">在本地硬件上执行 AI 推理或运行时，而不是远程模型端点；不意味着网络隔离。\u003C\u002Fdd>\u003C\u002Fdiv>\u003Cdiv id=\"mirror-registry\" class=\"border-t border-gray-200 dark:border-gray-700 py-3 first:border-t-0\">\u003Cdt class=\"font-semibold text-gray-900 dark:text-gray-100\">镜像仓库\u003C\u002Fdt>\u003Cdd class=\"mt-1 text-gray-600 dark:text-gray-300\">包含断开连接部署所需的容器镜像或其他工件的经批准副本的内部仓库。\u003C\u002Fdd>\u003C\u002Fdiv>\u003Cdiv id=\"staging-environment\" class=\"border-t border-gray-200 dark:border-gray-700 py-3 first:border-t-0\">\u003Cdt class=\"font-semibold text-gray-900 dark:text-gray-100\">暂存环境\u003C\u002Fdt>\u003Cdd class=\"mt-1 text-gray-600 dark:text-gray-300\">在传输到隔离域之前，获取、验证和准备工件的连接或受控区域。\u003C\u002Fdd>\u003C\u002Fdiv>\u003Cdiv id=\"controlled-transfer\" class=\"border-t border-gray-200 dark:border-gray-700 py-3 first:border-t-0\">\u003Cdt class=\"font-semibold text-gray-900 dark:text-gray-100\">受控传输\u003C\u002Fdt>\u003Cdd class=\"mt-1 text-gray-600 dark:text-gray-300\">使用经批准的介质\u002F流程和验证，在隔离边界上对数据或软件进行受治理的移动。\u003C\u002Fdd>\u003C\u002Fdiv>\u003Cdiv id=\"artifact-provenance\" class=\"border-t border-gray-200 dark:border-gray-700 py-3 first:border-t-0\">\u003Cdt class=\"font-semibold text-gray-900 dark:text-gray-100\">工件来源\u003C\u002Fdt>\u003Cdd class=\"mt-1 text-gray-600 dark:text-gray-300\">显示模型、软件包、容器或其他导入工件来源以及如何生产或验证的信息。\u003C\u002Fdd>\u003C\u002Fdiv>\u003Cdiv id=\"removable-media\" class=\"border-t border-gray-200 dark:border-gray-700 py-3 first:border-t-0\">\u003Cdt class=\"font-semibold text-gray-900 dark:text-gray-100\">可移动介质\u003C\u002Fdt>\u003Cdd class=\"mt-1 text-gray-600 dark:text-gray-300\">用于在系统之间传输数据的便携式存储；跨断开域的潜在安全路径。\u003C\u002Fdd>\u003C\u002Fdiv>\u003Cdiv id=\"internal-model-store\" class=\"border-t border-gray-200 dark:border-gray-700 py-3 first:border-t-0\">\u003Cdt class=\"font-semibold text-gray-900 dark:text-gray-100\">内部模型存储\u003C\u002Fdt>\u003Cdd class=\"mt-1 text-gray-600 dark:text-gray-300\">隔离环境内的仓库，经批准的模型工件从中提供或部署。\u003C\u002Fdd>\u003C\u002Fdiv>\u003Cdiv id=\"air-gap-readiness\" class=\"border-t border-gray-200 dark:border-gray-700 py-3 first:border-t-0\">\u003Cdt class=\"font-semibold text-gray-900 dark:text-gray-100\">气隙就绪\u003C\u002Fdt>\u003Cdd class=\"mt-1 text-gray-600 dark:text-gray-300\">完整 AI 堆栈在没有未经批准的外部连接的情况下安装、启动、运行、更新和恢复的已证明能力。\u003C\u002Fdd>\u003C\u002Fdiv>\u003C\u002Fdl>\u003C\u002Fsection>\n\u003Ch2 id=\"section-154\">结论\u003C\u002Fh2>\n\u003Cp>气隙 AI 不是一种特殊的模型。它是一种在故意隔离的安全域内运行的 AI 架构。\u003C\u002Fp>\n\u003Cp>模型可能是简单的部分。生产就绪取决于每个周边依赖项——模型资产、软件包、注册表、身份、RAG、工具、监控、更新和恢复——是否能在没有自动化外部路径的情况下运行。\u003C\u002Fp>\n\u003Cp>最短的可靠规则是：本地推理证明模型在哪里运行；气隙证据证明整个系统如何隔离，以及每次允许的传输如何跨越该边界。\u003C\u002Fp>\n\u003Ch2 id=\"section-158\">主要来源和当前实现参考\u003C\u002Fh2>\n\u003Cp>以下来源确立了安全定义、当前断开连接的 AI 部署模式和生命周期风险。供应商对“气隙”的使用有意与更严格的 NIST 定义区分开来。\u003C\u002Fp>\n\u003Ca href=\"https:\u002F\u002Fcsrc.nist.gov\u002Fglossary\u002Fterm\u002Fair_gap\" target=\"_blank\" rel=\"noopener noreferrer\" class=\"editorjs-link-tool block border border-gray-200 dark:border-gray-700 rounded-lg p-4 transition text-gray-900 dark:text-gray-100 hover:border-primary-500 hover:bg-primary-50 dark:hover:bg-gray-900 hover:text-gray-900 dark:hover:text-gray-100\">\u003Cstrong class=\"block font-semibold\">NIST CSRC — 气隙\u003C\u002Fstrong>\u003Cp class=\"text-sm text-gray-600 dark:text-gray-400\">NIST 术语表定义：物理断开的系统，跨边界的非自动化、手动控制的逻辑传输。\u003C\u002Fp>\u003C\u002Fa>\n\u003Ca href=\"https:\u002F\u002Fdocs.nvidia.com\u002Fnim\u002Flarge-language-models\u002Flatest\u002Fdeploy-air-gap.html\" target=\"_blank\" rel=\"noopener noreferrer\" class=\"editorjs-link-tool block border border-gray-200 dark:border-gray-700 rounded-lg p-4 transition text-gray-900 dark:text-gray-100 hover:border-primary-500 hover:bg-primary-50 dark:hover:bg-gray-900 hover:text-gray-900 dark:hover:text-gray-100\">\u003Cstrong class=\"block font-semibold\">NVIDIA NIM — 气隙部署\u003C\u002Fstrong>\u003Cp class=\"text-sm text-gray-600 dark:text-gray-400\">当前操作指南，用于在连接的系统上暂存模型资产，并在没有互联网、公共注册表或云 API 密钥的情况下从本地存储运行 NIM。\u003C\u002Fp>\u003C\u002Fa>\n\u003Ca href=\"https:\u002F\u002Fdocs.redhat.com\u002Fen\u002Fdocumentation\u002Fred_hat_ai_inference\u002F3.5\u002Fhtml\u002Fdeploy_the_standalone_red_hat_ai_inference_container_in_a_disconnected_environment\u002Findex\" target=\"_blank\" rel=\"noopener noreferrer\" class=\"editorjs-link-tool block border border-gray-200 dark:border-gray-700 rounded-lg p-4 transition text-gray-900 dark:text-gray-100 hover:border-primary-500 hover:bg-primary-50 dark:hover:bg-gray-900 hover:text-gray-900 dark:hover:text-gray-100\">\u003Cstrong class=\"block font-semibold\">Red Hat AI 推理 — 断开连接的部署\u003C\u002Fstrong>\u003Cp class=\"text-sm text-gray-600 dark:text-gray-400\">当前 Red Hat 指南，用于在断开连接的环境中使用镜像工件和内部基础设施提供 LLM 服务。\u003C\u002Fp>\u003C\u002Fa>\n\u003Ca href=\"https:\u002F\u002Fdocs.redhat.com\u002Fen\u002Fdocumentation\u002Fred_hat_ai_inference\u002F3.5\u002Fhtml\u002Fdeploy_the_standalone_red_hat_ai_inference_container_in_a_disconnected_environment\u002Fstoring-models-in-disconnected-environments_disconnected-deploy\" target=\"_blank\" rel=\"noopener noreferrer\" class=\"editorjs-link-tool block border border-gray-200 dark:border-gray-700 rounded-lg p-4 transition text-gray-900 dark:text-gray-100 hover:border-primary-500 hover:bg-primary-50 dark:hover:bg-gray-900 hover:text-gray-900 dark:hover:text-gray-100\">\u003Cstrong class=\"block font-semibold\">红帽 AI 推理 — 在隔离环境中存储模型\u003C\u002Fstrong>\u003Cp class=\"text-sm text-gray-600 dark:text-gray-400\">涵盖 OCI 模型镜像、持久化模型存储以及需要远程代码的模型局限性的当前指南。\u003C\u002Fp>\u003C\u002Fa>\n\u003Ca href=\"https:\u002F\u002Fwww.nsa.gov\u002Fportals\u002F75\u002Fdocuments\u002Fwhat-we-do\u002Fcybersecurity\u002Fprofessional-resources\u002Fctr-nsa-css-technical-cyber-threat-framework.pdf\" target=\"_blank\" rel=\"noopener noreferrer\" class=\"editorjs-link-tool block border border-gray-200 dark:border-gray-700 rounded-lg p-4 transition text-gray-900 dark:text-gray-100 hover:border-primary-500 hover:bg-primary-50 dark:hover:bg-gray-900 hover:text-gray-900 dark:hover:text-gray-100\">\u003Cstrong class=\"block font-semibold\">NSA — 技术网络威胁框架\u003C\u002Fstrong>\u003Cp class=\"text-sm text-gray-600 dark:text-gray-400\">该威胁框架明确将可移动介质复制识别为进入隔离或气隙网络的路径。\u003C\u002Fp>\u003C\u002Fa>\n\u003Ca href=\"https:\u002F\u002Fwww.nist.gov\u002Fpublications\u002Fguidelines-media-sanitization\" target=\"_blank\" rel=\"noopener noreferrer\" class=\"editorjs-link-tool block border border-gray-200 dark:border-gray-700 rounded-lg p-4 transition text-gray-900 dark:text-gray-100 hover:border-primary-500 hover:bg-primary-50 dark:hover:bg-gray-900 hover:text-gray-900 dark:hover:text-gray-100\">\u003Cstrong class=\"block font-semibold\">NIST SP 800-88 Rev. 1 — 介质净化指南\u003C\u002Fstrong>\u003Cp class=\"text-sm text-gray-600 dark:text-gray-400\">根据信息保密要求管理和净化存储介质的指南。\u003C\u002Fp>\u003C\u002Fa>\n\u003Ca href=\"https:\u002F\u002Fcsrc.nist.gov\u002Fpubs\u002Fsp\u002F800\u002F40\u002Fr4\u002Ffinal\" target=\"_blank\" rel=\"noopener noreferrer\" class=\"editorjs-link-tool block border border-gray-200 dark:border-gray-700 rounded-lg p-4 transition text-gray-900 dark:text-gray-100 hover:border-primary-500 hover:bg-primary-50 dark:hover:bg-gray-900 hover:text-gray-900 dark:hover:text-gray-100\">\u003Cstrong class=\"block font-semibold\">NIST SP 800-40 Rev. 4 — 企业补丁管理规划\u003C\u002Fstrong>\u003Cp class=\"text-sm text-gray-600 dark:text-gray-400\">将补丁和更新视为企业系统预防性维护的指导框架。\u003C\u002Fp>\u003C\u002Fa>\n\u003Ca href=\"https:\u002F\u002Fwww.nist.gov\u002Fitl\u002Fexecutive-order-14028-improving-nations-cybersecurity\u002Fsoftware-security-supply-chains\" target=\"_blank\" rel=\"noopener noreferrer\" class=\"editorjs-link-tool block border border-gray-200 dark:border-gray-700 rounded-lg p-4 transition text-gray-900 dark:text-gray-100 hover:border-primary-500 hover:bg-primary-50 dark:hover:bg-gray-900 hover:text-gray-900 dark:hover:text-gray-100\">\u003Cstrong class=\"block font-semibold\">NIST — 供应链中的软件安全\u003C\u002Fstrong>\u003Cp class=\"text-sm text-gray-600 dark:text-gray-400\">NIST 指南，涵盖软件供应链风险、来源、验证、SBOM 相关实践和漏洞管理。\u003C\u002Fp>\u003C\u002Fa>",{"time":212,"blocks":213,"version":1687},1791488480002,[214,220,228,235,241,248,256,261,266,271,276,281,286,291,296,301,333,338,343,348,353,358,396,401,406,411,446,453,458,496,501,506,511,516,521,526,531,536,541,546,551,556,561,566,571,609,614,619,624,629,634,639,644,649,654,663,668,673,678,683,688,693,698,703,708,713,718,723,728,733,738,743,748,753,758,763,768,773,778,783,788,818,823,828,833,838,843,848,853,858,863,868,873,878,883,889,927,932,937,942,947,952,996,1001,1006,1011,1016,1021,1064,1069,1074,1079,1084,1089,1094,1099,1104,1109,1115,1120,1125,1130,1156,1161,1187,1192,1197,1202,1244,1249,1305,1310,1354,1359,1397,1402,1407,1412,1417,1422,1427,1432,1437,1442,1447,1452,1457,1462,1467,1475,1480,1526,1531,1584,1589,1594,1599,1604,1609,1614,1624,1633,1642,1651,1660,1669,1678],{"id":215,"data":216,"type":218,"tunes":219},"intro",{"text":217},"气隙AI是指部署在安全域内的人工智能系统，该安全域与其隔离的外部系统之间没有物理网络连接，任何跨越该边界的传输都通过刻意控制的、非自动化的程序进行。因此，推理所需的AI模型、运行时、数据、检索索引、工具和操作依赖项必须在隔离环境内部可用。气隙AI不仅仅是“本地模型”或“本地服务器”：其定义性属性是围绕整个系统的网络和传输边界。","paragraph",{},{"id":221,"data":222,"type":226,"tunes":227},"direct",{"body":223,"title":224,"variant":225},"如果所有必需的依赖项在隔离域内可用，气隙AI系统可以在没有互联网或云API的情况下运行LLM推理、RAG、文档分析甚至代理工作流。\u003Cbr>\u003Cbr>一种实用的架构是：\u003Cbr>\u003Cstrong>受控导入 → 内部制品\u002F模型仓库 → 本地AI运行时 → 本地数据\u002FRAG → 本地工具 → 内部用户\u002F服务 → 本地监控\u002F审计\u003C\u002Fstrong>。\u003Cbr>\u003Cbr>困难的部分不是让一个LLM离线回答。而是在不暗中依赖外部服务的情况下运营整个AI生命周期——更新、模型、驱动程序、软件包、数据导入、凭据、日志记录和安全性。","直接回答","info","callout",{},{"id":229,"data":230,"type":226,"tunes":234},"nist-boundary",{"body":231,"title":232,"variant":233},"NIST的网络安全词汇表将气隙定义为两个系统\u003Cstrong>没有物理连接\u003C\u002Fstrong>且任何逻辑传输\u003Cstrong>不是自动化的\u003C\u002Fstrong>的接口；数据仅在人工控制下手动跨越。供应商文档有时更广泛地使用“气隙”或“断开连接”来描述没有外部互联网连接但具有内部网络和受控暂存基础设施的环境。架构文档应说明实际实现的是哪种含义。","气隙的含义比“无互联网”更严格","warning",{},{"id":236,"data":237,"type":226,"tunes":240},"not-security",{"body":238,"title":239,"variant":233},"移除直接网络连接消除了许多远程路径，但并未消除恶意可移动介质、受损的软件\u002F模型导入、内部威胁、脆弱的内部服务、物理入侵、通过导入文档的提示注入或隔离网络内的横向移动。","气隙并不意味着定义上的安全",{},{"id":242,"data":243,"type":226,"tunes":247},"current",{"body":244,"title":245,"variant":246},"当前的NVIDIA NIM和Red Hat AI Inference文档都支持通过预先暂存模型和容器资产来在没有外部互联网访问的情况下提供LLM服务。NVIDIA记录了连接准备阶段，随后是使用本地资产且没有云注册表凭据的隔离执行阶段。Red Hat使用镜像容器\u002F模型仓库用于断开的OpenShift环境。这些是有用的实现示例，但它们并不推翻NIST对气隙更严格的定义。","当前来源说明——2026年10月8日","note",{},{"id":249,"data":250,"type":254,"tunes":255},"toc",{"title":251,"maxLevel":252,"minLevel":253},"目录",3,2,"tableOfContents",{},{"id":257,"data":258,"type":42,"tunes":260},"h-meaning",{"text":259,"level":253},"气隙AI的真正含义",{},{"id":262,"data":263,"type":218,"tunes":265},"p-meaning-1",{"text":264},"AI这个词并不改变基本的安全概念。气隙是安全域之间的边界。AI只是使隔离侧在操作上要求更高，因为现代AI堆栈通常假设可下载的模型、包注册表、遥测、API、模型中心和频繁的软件更新。",{},{"id":267,"data":268,"type":218,"tunes":270},"p-meaning-2",{"text":269},"隔离环境仍然可以包含许多连接的机器。内部集群可能有GPU、应用服务器、存储、数据库、身份服务和监控相互连接。气隙存在于该飞地和外部域之间。",{},{"id":272,"data":273,"type":218,"tunes":275},"p-meaning-3",{"text":274},"因此，相关问题不是“这个GPU有Wi-Fi吗？”而是“这个AI环境能否通过自动化的物理或逻辑路径与外部域交换信息？”",{},{"id":277,"data":278,"type":42,"tunes":280},"h-simple",{"text":279,"level":253},"最简单的例子",{},{"id":282,"data":283,"type":218,"tunes":285},"p-simple-1",{"text":284},"想象一家公司想要一个用于机密技术文档的内部助手，但不允许该环境将这些文档发送到互联网。",{},{"id":287,"data":288,"type":218,"tunes":290},"p-simple-2",{"text":289},"该公司在连接的暂存环境中下载经批准的LLM、嵌入模型、容器镜像和软件包。验证后，经批准的制品被转移到隔离环境中。",{},{"id":292,"data":293,"type":218,"tunes":295},"p-simple-3",{"text":294},"在飞地内部，模型服务器、文档解析器、向量数据库、应用程序和身份服务在本地运行。用户可以在没有云模型或公共模型注册表的情况下，针对内部文档提问并使用RAG。",{},{"id":297,"data":298,"type":218,"tunes":300},"p-simple-4",{"text":299},"当需要更新时，更新再次通过受控导入过程，而不是由生产AI服务器直接下载。",{},{"id":302,"data":303,"type":331,"tunes":332},"simple-flow",{"steps":304,"title":329,"orientation":330},[305,308,311,314,317,320,323,326],{"label":306,"description":307},"1. 在飞地外获取","在连接的暂存环境中下载经批准的模型、软件包、容器、驱动程序、签名和文档。",{"label":309,"description":310},"2. 传输前验证","根据组织策略检查来源、签名\u002F校验和、恶意软件状态、许可和兼容性。",{"label":312,"description":313},"3. 通过受控边界传输","使用授权的手动或中介过程移动经批准的制品。",{"label":315,"description":316},"4. 内部发布","将制品放入内部模型、容器、软件包或文件仓库。",{"label":318,"description":319},"5. 本地部署","在没有外部依赖的情况下运行推理、RAG、应用程序和工具。",{"label":321,"description":322},"6. 在飞地内监控","在本地收集日志、指标、模型\u002F运行时状态和安全事件。",{"label":324,"description":325},"7. 仅导出经批准的证据","在策略允许的情况下，通过反向受控过程向外移动选定的报告或制品。",{"label":327,"description":328},"8. 为更新重复","将新模型、补丁、语料库和依赖项视为新的供应链导入。","基本的气隙AI操作周期","auto","processFlow",{},{"id":334,"data":335,"type":42,"tunes":337},"h-stops",{"text":336,"level":253},"简单示例的局限",{},{"id":339,"data":340,"type":218,"tunes":342},"p-stops-1",{"text":341},"生产气隙环境可能比一台工作站大得多。它可能包括Kubernetes\u002FOpenShift、内部注册表、对象存储、身份提供商、向量数据库、可观测性、备份基础设施和多个模型服务节点。",{},{"id":344,"data":345,"type":218,"tunes":347},"p-stops-2",{"text":346},"隔离区内的服务越多，组织就越需要复制那些联网环境通常从互联网获取的能力。",{},{"id":349,"data":350,"type":218,"tunes":352},"p-stops-3",{"text":351},"因此，物理隔离转移了复杂性。它减少了直接的外部连接，但增加了隔离域内的制品管理、补丁、依赖、供应链和运维责任。",{},{"id":354,"data":355,"type":42,"tunes":357},"h-terms",{"text":356,"level":253},"物理隔离 vs 离线 vs 本地 vs 本地部署 vs 私有 vs 主权 AI",{},{"id":359,"data":360,"type":394,"tunes":395},"terms-table",{"content":361,"stretched":43,"withHeadings":14},[362,366,370,374,378,382,386,390],[363,364,365],"术语","主要描述的内容","是否需要互联网\u002F外部连接？",[367,368,369],"本地 AI","推理\u002F运行时在本地硬件上运行","否；但仍可能调用云服务",[371,372,373],"可离线运行的 AI","无需互联网即可继续运行","离线运行期间不需要；重新连接可能是正常的",[375,376,377],"断连环境","部署环境没有直接的外部互联网路径","通常不需要；可能使用受控的镜像\u002F堡垒机",[379,380,381],"本地部署 AI","基础设施在组织自有\u002F本地环境中运行","仍可能具有完整的互联网连接",[383,384,385],"私有 AI","AI 处理受到控制以满足隐私\u002F保密要求","取决于架构；可以连接或断开",[387,388,389],"物理隔离 AI","安全域物理断开，跨边界传输在严格定义下是非自动化\u002F手动的","无自动化外部路径",[391,392,393],"主权 AI","对模型、数据、基础设施和依赖的控制\u002F管辖权","不一定；主权比网络隔离范围更广","table",{},{"id":397,"data":398,"type":218,"tunes":400},"p-terms-1",{"text":399},"这些术语可能重叠，但并非同义词。连接到互联网的本地 Ollama 服务器是本地 AI，而不是物理隔离 AI。调用云模型的本地部署 RAG 平台是带有云推理的本地部署应用基础设施，而不是物理隔离 AI。",{},{"id":402,"data":403,"type":218,"tunes":405},"p-terms-2",{"text":404},"物理隔离系统在设计上通常是私有的，因为数据保留在隔离区内，但隐私还取决于授权、日志记录、数据处理、物理安全和运维策略。",{},{"id":407,"data":408,"type":42,"tunes":410},"h-strict",{"text":409,"level":253},"严格物理隔离 vs 实际断连部署",{},{"id":412,"data":413,"type":444,"tunes":445},"strict-comparison",{"rows":414,"title":436,"layout":394,"columns":437},[415,420,424,428,432],{"id":416,"label":417,"values":418},"physical","外部物理连接",[419,419],"",{"id":421,"label":422,"values":423},"transfer","跨边界传输",[419,419],{"id":425,"label":426,"values":427},"internet","AI 工作负载的互联网访问",[419,419],{"id":429,"label":430,"values":431},"internalnet","内部网络",[419,419],{"id":433,"label":434,"values":435},"best","使用该术语的场景",[419,419],"常被称为“物理隔离”的两种含义",[438,441],{"id":439,"label":440},"strict","严格物理隔离",{"id":442,"label":443},"disconnected","断连\u002F无互联网部署","comparison",{},{"id":447,"data":448,"type":226,"tunes":452},"naming-rule",{"body":449,"title":450,"variant":451},"对于架构和安全审查，请写出实际规则：\u003Cstrong>无出站互联网\u003C\u002Fstrong>、\u003Cstrong>无物理外部网络路径\u003C\u002Fstrong>、\u003Cstrong>仅手动传输\u003C\u002Fstrong>，或\u003Cstrong>带经批准堡垒机\u002F镜像的断连集群\u003C\u002Fstrong>。这比只说“物理隔离”更精确。","记录边界，而不是依赖标签","success",{},{"id":454,"data":455,"type":42,"tunes":457},"h-architecture",{"text":456,"level":253},"实用的物理隔离 AI 架构",{},{"id":459,"data":460,"type":394,"tunes":495},"architecture-table",{"content":461,"stretched":43,"withHeadings":14},[462,465,468,471,474,477,480,483,486,489,492],[463,464],"层","隔离环境内必须存在的内容",[466,467],"用户\u002F应用层","聊天 UI、API、业务应用或内部代理接口",[469,470],"身份与授权","本地\u002F内部认证、RBAC、租户\u002F资源权限",[472,473],"AI 网关\u002F运行时","模型路由、请求策略、上下文组装和运行时控制",[475,476],"模型服务","本地模型服务器、权重、分词器\u002F配置和加速器运行时",[478,479],"RAG \u002F 知识","文档存储、解析器、嵌入、向量\u002F词法索引、元数据和来源",[481,482],"工具\u002F服务","仅限隔离区可访问的内部\u002F本地 API 和经批准的系统",[484,485],"制品仓库","本地容器注册表、包镜像、模型存储，以及可选的 OS\u002F更新仓库",[487,488],"可观测性","内部日志、指标、追踪和审计记录",[490,491],"备份\u002F恢复","适合该安全域的本地或单独控制的备份流程",[493,494],"传输边界","带检查和批准的受控导入\u002F导出流程",{},{"id":497,"data":498,"type":218,"tunes":500},"p-architecture-1",{"text":499},"完整的架构应能够在没有 DNS 查询、许可证检查、包下载或对公共服务 API 调用的情况下启动和运行，除非这些依赖已有经批准的内部替代方案。",{},{"id":502,"data":503,"type":218,"tunes":505},"p-architecture-2",{"text":504},"一个有用的设计测试是断开部署与所有外部服务的连接，并冷启动整个技术栈。隐藏依赖往往会在启动、模型加载、认证、包解析或遥测初始化期间出现。",{},{"id":507,"data":508,"type":42,"tunes":510},"h-models",{"text":509,"level":253},"模型必须预先准备",{},{"id":512,"data":513,"type":218,"tunes":515},"p-models-1",{"text":514},"如果隔离工作负载没有通往云模型 API 的路径，那么按定义这些 API 不可用。因此，隔离区需要可在本地运行的模型制品或内部托管的推理服务。",{},{"id":517,"data":518,"type":218,"tunes":520},"p-models-2",{"text":519},"NVIDIA 当前的 NIM 物理隔离文档明确使用两阶段模式：在联网机器上下载并准备模型资产，传输它们，然后从本地存储运行隔离的 NIM，无需出站注册表访问或云 API 密钥。",{},{"id":522,"data":523,"type":218,"tunes":525},"p-models-3",{"text":524},"模型权重只是依赖集的一部分。分词器、配置文件、适配器、量化元数据以及任何所需的运行时代码也必须存在。",{},{"id":527,"data":528,"type":42,"tunes":530},"h-remote-code",{"text":529,"level":253},"具有远程代码依赖的模型是物理隔离的风险",{},{"id":532,"data":533,"type":218,"tunes":535},"p-remote-1",{"text":534},"一些模型仓库包含自定义 Python 代码或运行时钩子，这些代码或钩子通常会获取额外的代码或资源。",{},{"id":537,"data":538,"type":218,"tunes":540},"p-remote-2",{"text":539},"当前 Red Hat AI Inference 文档明确警告，一些需要远程代码的 Hugging Face 模型无法在断连环境中正常运行，因为即使配置了离线模式，该库仍会尝试访问网络。",{},{"id":542,"data":543,"type":218,"tunes":545},"p-remote-3",{"text":544},"实际经验是，在批准模型用于隔离部署之前，先离线测试其整个加载路径。“我下载了权重”并不能证明该模型是自包含的。",{},{"id":547,"data":548,"type":42,"tunes":550},"h-artifacts",{"text":549,"level":253},"容器、软件包和驱动成为本地供应链制品",{},{"id":552,"data":553,"type":218,"tunes":555},"p-artifacts-1",{"text":554},"联网环境通常会从公共注册表拉取容器镜像、Python 软件包、操作系统更新和 GPU 组件。气隙环境不能假定这些服务中的任何一个可用。",{},{"id":557,"data":558,"type":218,"tunes":560},"p-artifacts-2",{"text":559},"Red Hat 的断连 AI 部署模型使用内部镜像注册表来存放容器镜像和 Operator 目录。模型可以作为 OCI 制品进行镜像，或传输到持久化存储。",{},{"id":562,"data":563,"type":218,"tunes":565},"p-artifacts-3",{"text":564},"对于更广泛的技术栈，同样的模式通常也适用于语言包、Linux 仓库、JavaScript 包和内部二进制文件：经批准的制品通过传输流程一次性进入，然后由受信任的内部仓库提供服务。",{},{"id":567,"data":568,"type":42,"tunes":570},"h-bom",{"text":569,"level":253},"了解完整的依赖清单",{},{"id":572,"data":573,"type":394,"tunes":608},"dependency-table",{"content":574,"stretched":43,"withHeadings":14},[575,578,581,584,587,590,593,596,599,602,605],[576,577],"依赖类别","示例",[579,580],"模型制品","权重、分词器、配置、适配器、量化元数据",[582,583],"推理运行时","vLLM、llama.cpp、Ollama、NIM 或其他服务运行时",[585,586],"GPU\u002F运行时栈","驱动、CUDA\u002FROCm 库、容器运行时",[588,589],"应用软件包","Python wheels、npm 包、系统库",[591,592],"容器","应用、推理、数据库、向量数据库、监控镜像",[594,595],"RAG 模型","嵌入模型、重排序器、OCR\u002F视觉模型",[597,598],"数据","知识语料库、元数据、模式、评估数据集",[600,601],"安全材料","证书、CA 捆绑包、策略\u002F配置、适用时的恶意软件签名",[603,604],"运维制品","仪表板、告警规则、备份工具、运行手册",[606,607],"许可","需要时使用离线兼容的许可证\u002F授权",{},{"id":610,"data":611,"type":42,"tunes":613},"h-mirror",{"text":612,"level":253},"内部镜像是基础设施，而非便利措施",{},{"id":615,"data":616,"type":218,"tunes":618},"p-mirror-1",{"text":617},"当隔离域对经批准的制品拥有已知的内部来源时，断连部署才变得可维护。",{},{"id":620,"data":621,"type":218,"tunes":623},"p-mirror-2",{"text":622},"Red Hat 文档化的方法使用断连集群可访问的镜像注册表，因此工作负载不需要公共注册表。",{},{"id":625,"data":626,"type":218,"tunes":628},"p-mirror-3",{"text":627},"同样的架构思路可以应用于模型存储和软件包仓库。目标是让制品来源、版本和批准状态变得明确，而不是手动将随机文件复制到每台服务器。",{},{"id":630,"data":631,"type":42,"tunes":633},"h-rag",{"text":632,"level":253},"RAG 可以完全在气隙环境中运行",{},{"id":635,"data":636,"type":218,"tunes":638},"p-rag-1",{"text":637},"RAG 不需要公共互联网。它需要一个可检索的语料库、一个摄取\u002F索引管道，以及一个能够使用检索上下文的模型。",{},{"id":640,"data":641,"type":218,"tunes":643},"p-rag-2",{"text":642},"在气隙环境中，文档存储、解析器\u002FOCR、嵌入模型、向量或词法索引、重排序器和生成模型都可以在本地运行。",{},{"id":645,"data":646,"type":218,"tunes":648},"p-rag-3",{"text":647},"变化的是来源获取方式。除非通过受控边界导入等效数据，否则实时网络搜索和云文档连接器不可用。",{},{"id":650,"data":651,"type":218,"tunes":653},"p-rag-4",{"text":652},"因此，语料库成为一种受治理的制品。每次导入都应保留来源标识、日期\u002F版本和出处，以便用户知道隔离系统实际包含哪些知识。",{},{"id":655,"data":656,"type":661,"tunes":662},"ref-rag",{"url":657,"title":658,"excerpt":659,"ctaLabel":660},"https:\u002F\u002Fstajic.de\u002Fzh\u002Fblog\u002Fwhat-is-rag-the-simplest-explanation-of-how-it-works","什么是RAG？其工作原理的最简单解释","RAG本身独立于云托管。在气隙架构中，检索和生成只需由本地\u002F内部组件提供。","阅读RAG基础","referralArticle",{},{"id":664,"data":665,"type":42,"tunes":667},"h-agents",{"text":666,"level":253},"代理可以气隙运行——但仅限可访问的工具",{},{"id":669,"data":670,"type":218,"tunes":672},"p-agents-1",{"text":671},"如果模型\u002F运行时和所需工具是本地或在内部网络上可访问的，代理循环可以完全在隔离飞地内运行。",{},{"id":674,"data":675,"type":218,"tunes":677},"p-agents-2",{"text":676},"依赖GitHub、公共网络搜索、云电子邮件或外部SaaS API的工具将失败，除非架构提供经批准的内部等效项或受控的异步交换过程。",{},{"id":679,"data":680,"type":218,"tunes":682},"p-agents-3",{"text":681},"这就是为什么气隙代理设计应从能力清单开始：每个工具端点必须分类为内部、导入、不可用或故意排除。",{},{"id":684,"data":685,"type":42,"tunes":687},"h-mcp",{"text":686,"level":253},"MCP不会绕过气隙",{},{"id":689,"data":690,"type":218,"tunes":692},"p-mcp-1",{"text":691},"MCP可以在隔离的AI环境中暴露本地工具和资源，但协议不会通过安全边界创建连接。",{},{"id":694,"data":695,"type":218,"tunes":697},"p-mcp-2",{"text":696},"读取内部文档的本地MCP服务器可以完全离线工作。公共互联网上的远程MCP服务器无法从严格的气隙飞地访问。",{},{"id":699,"data":700,"type":218,"tunes":702},"p-mcp-3",{"text":701},"同样的原则适用于任何连接器协议：互操作性与网络权限是分开的。",{},{"id":704,"data":705,"type":42,"tunes":707},"h-identity",{"text":706,"level":253},"身份和认证也必须离线工作",{},{"id":709,"data":710,"type":218,"tunes":712},"p-id-1",{"text":711},"AI应用程序可以本地托管，同时仍依赖云身份提供商。这种隐藏的依赖破坏了真正的断开操作。",{},{"id":714,"data":715,"type":218,"tunes":717},"p-id-2",{"text":716},"因此，气隙设计需要一种在飞地内运行的身份架构：本地目录、内部身份提供商、内部PKI、本地服务凭证或其他经批准的机制。",{},{"id":719,"data":720,"type":218,"tunes":722},"p-id-3",{"text":721},"即使没有互联网，授权仍然是必要的。气隙不会取代RBAC、租户隔离或最小权限。",{},{"id":724,"data":725,"type":42,"tunes":727},"h-time",{"text":726,"level":253},"时间、证书和信任存储成为本地依赖",{},{"id":729,"data":730,"type":218,"tunes":732},"p-time-1",{"text":731},"许多身份验证和日志系统依赖于可靠的时间。证书会过期。信任存储会变化。签名工件需要验证。",{},{"id":734,"data":735,"type":218,"tunes":737},"p-time-2",{"text":736},"因此，断开连接的飞地应具有内部时间同步和证书\u002F信任生命周期，在正常操作期间不依赖于访问公共服务。",{},{"id":739,"data":740,"type":218,"tunes":742},"p-time-3",{"text":741},"这些是普通的基础设施问题，只有在没有互联网访问的情况下测试架构时才会显现。",{},{"id":744,"data":745,"type":42,"tunes":747},"h-telemetry",{"text":746,"level":253},"遥测和崩溃报告需要明确的策略",{},{"id":749,"data":750,"type":218,"tunes":752},"p-tel-1",{"text":751},"许多现代库默认尝试进行分析、更新检查或错误报告。",{},{"id":754,"data":755,"type":218,"tunes":757},"p-tel-2",{"text":756},"在隔离环境中，这些调用应被禁用或重定向到内部可观测性系统。反复失败的遥测尝试可能导致延迟、日志噪音和意外的启动行为。",{},{"id":759,"data":760,"type":218,"tunes":762},"p-tel-3",{"text":761},"气隙部署应了解哪些组件尝试外联，即使防火墙会阻止它们。",{},{"id":764,"data":765,"type":42,"tunes":767},"h-updates",{"text":766,"level":253},"气隙系统仍然需要补丁",{},{"id":769,"data":770,"type":218,"tunes":772},"p-update-1",{"text":771},"网络隔离并不能阻止软件产生漏洞。它只改变了补丁到达系统的方式。",{},{"id":774,"data":775,"type":218,"tunes":777},"p-update-2",{"text":776},"NIST将补丁管理视为预防性维护：组织仍然需要识别、获取、优先排序、安装和验证补丁与更新。",{},{"id":779,"data":780,"type":218,"tunes":782},"p-update-3",{"text":781},"因此，气隙操作需要为操作系统软件包、容器镜像、驱动程序、AI运行时和安全更新建立可重复的导入节奏。权衡在于隔离稳定性与陈旧软件带来的漏洞暴露之间。",{},{"id":784,"data":785,"type":42,"tunes":787},"h-patch-flow",{"text":786,"level":253},"受控的更新路径",{},{"id":789,"data":790,"type":331,"tunes":817},"patch-flow",{"steps":791,"title":816,"orientation":330},[792,795,798,801,804,807,810,813],{"label":793,"description":794},"1. 识别所需更新","安全公告、模型\u002F运行时改进或运营需求触发变更。",{"label":796,"description":797},"2. 在联网暂存区获取","下载确切版本以及签名\u002F校验和和元数据。",{"label":799,"description":800},"3. 验证供应链证据","验证来源、完整性、兼容性和策略要求。",{"label":802,"description":803},"4. 在代表性离线暂存区测试","确认更新在没有意外网络依赖的情况下正常工作。",{"label":805,"description":806},"5. 批准传输","应用组织的变更和安全流程。",{"label":808,"description":809},"6. 导入到隔离区仓库","将制品发布到内部可信源。",{"label":811,"description":812},"7. 逐步部署","在架构允许的情况下，先应用于测试\u002F金丝雀节点，再广泛推广。",{"label":814,"description":815},"8. 验证并记录","确认版本、健康状况、行为和回滚状态。","隔离AI环境的示例更新生命周期",{},{"id":819,"data":820,"type":42,"tunes":822},"h-transfer",{"text":821,"level":253},"传输边界是最敏感的运营接口",{},{"id":824,"data":825,"type":218,"tunes":827},"p-transfer-1",{"text":826},"如果外部信息必须进入气隙系统，导入通道就成为主要的安全控制点。",{},{"id":829,"data":830,"type":218,"tunes":832},"p-transfer-2",{"text":831},"NSA网络安全技术网络威胁框架明确将可移动介质复制视为对手可用于进入断开连接或气隙网络的路径。",{},{"id":834,"data":835,"type":218,"tunes":837},"p-transfer-3",{"text":836},"这就是为什么受控的介质处理、检查、来源追溯、必要时的加密、恶意软件扫描和角色分离可能与AI堆栈本身同样重要。",{},{"id":839,"data":840,"type":42,"tunes":842},"h-media",{"text":841,"level":253},"可移动介质不是中立的管道",{},{"id":844,"data":845,"type":218,"tunes":847},"p-media-1",{"text":846},"USB驱动和其他便携式介质可以携带合法的模型\u002F数据制品以及恶意内容。",{},{"id":849,"data":850,"type":218,"tunes":852},"p-media-2",{"text":851},"NIST的介质清理指南将存储介质视为机密性生命周期对象，根据敏感性和重用需求可能需要清除、净化或销毁。",{},{"id":854,"data":855,"type":218,"tunes":857},"p-media-3",{"text":856},"确切的传输程序因组织而异，但架构原则是稳定的：跨边界介质应作为安全资产进行管理，而不是被视为非正式的便利工具。",{},{"id":859,"data":860,"type":42,"tunes":862},"h-supply",{"text":861,"level":253},"气隙增加了供应链的重要性",{},{"id":864,"data":865,"type":218,"tunes":867},"p-supply-1",{"text":866},"隔离系统接收的实时外部输入较少，但每一个导入的二进制文件、模型、容器和软件包都变得更加重要，因为飞地可能会长期信任它们。",{},{"id":869,"data":870,"type":218,"tunes":872},"p-supply-2",{"text":871},"NIST 软件供应链指南强调来源、供应商风险、漏洞管理、软件验证和面向 SBOM 的实践。这些关注点与离线 AI 制品导入直接相关。",{},{"id":874,"data":875,"type":218,"tunes":877},"p-supply-3",{"text":876},"模型供应链值得与应用供应链同等重视：在导入之前，应了解模型来源、许可证、哈希、格式、所需代码、分词器、适配器和评估状态。",{},{"id":879,"data":880,"type":42,"tunes":882},"h-readiness",{"text":881,"level":253},"气隙就绪状态应经过测试，而非假定",{},{"id":884,"data":885,"type":226,"tunes":888},"readiness-note",{"body":886,"title":887,"variant":246},"以下气隙就绪测试是一种工程综合方法，并非 NIST 或供应商认证方法。它旨在部署前暴露隐藏的外部依赖。","建议的验证模式",{},{"id":890,"data":891,"type":394,"tunes":926},"readiness-table",{"content":892,"stretched":43,"withHeadings":14},[893,896,899,902,905,908,911,914,917,920,923],[894,895],"测试","它证明了什么",[897,898],"在阻止所有出站网络的情况下冷启动","运行时在启动期间不需要公共服务",[900,901],"从本地存储加载每个已批准的模型","权重\u002F分词器\u002F配置完整",[903,904],"仅从内部注册表重建\u002F重新部署","容器\u002F软件包镜像源足够",[906,907],"在外部 IdP 不可达时对用户进行身份验证","身份系统在飞地内部可正常工作",[909,910],"离线运行 RAG 摄取和查询","嵌入\u002F索引\u002F检索栈是本地化的",[912,913],"运行具有代表性的代理工具","工具不依赖外部 API",[915,916],"删除缓存后重启","离线运行不会意外依赖先前缓存的下载内容",[918,919],"推进模拟的证书\u002F更新生命周期","信任和维护依赖关系已被理解",[921,922],"通过暂存路径导入新模型","传输\u002F变更流程可操作",[924,925],"从备份恢复","恢复过程不需要不可用的云存储",{},{"id":928,"data":929,"type":42,"tunes":931},"h-cache",{"text":930,"level":253},"缓存过一次并不等同于气隙就绪",{},{"id":933,"data":934,"type":218,"tunes":936},"p-cache-1",{"text":935},"系统可能看起来处于离线状态，因为模型和软件包已从先前的互联网访问中缓存。",{},{"id":938,"data":939,"type":218,"tunes":941},"p-cache-2",{"text":940},"删除缓存或部署到干净节点可能会暴露缺失的分词器文件、Python 软件包、模型清单或远程代码依赖。",{},{"id":943,"data":944,"type":218,"tunes":946},"p-cache-3",{"text":945},"因此，气隙就绪状态应从干净的内部制品进行验证，而不仅仅是从先前连接过的开发者工作站进行验证。",{},{"id":948,"data":949,"type":42,"tunes":951},"h-threats",{"text":950,"level":253},"气隙内部仍存在哪些威胁？",{},{"id":953,"data":954,"type":394,"tunes":995},"threat-table",{"content":955,"stretched":43,"withHeadings":14},[956,959,962,965,968,971,974,977,980,983,986,989,992],[957,958],"威胁","为什么气隙无法消除它",[960,961],"被入侵的导入制品","恶意软件\u002F模型\u002F软件包可通过授权传输路径进入",[963,964],"恶意可移动介质","物理传输可携带可执行载荷",[966,967],"内部人员滥用","授权用户已经存在于飞地内部",[969,970],"导入文档中的提示注入","不可信内容可在无互联网的情况下影响 RAG\u002F代理",[972,973],"权限过高的代理工具","本地工具仍可破坏本地系统",[975,976],"跨租户数据泄露","内部授权缺陷仍可能存在",[978,979],"存在漏洞的内部软件","缺乏外部连接并不能消除可利用的缺陷",[981,982],"横向移动","被入侵的节点可以攻击其他内部连接的节点",[984,985],"过时的依赖项","更新节奏缓慢可能导致已知漏洞未修补",[987,988],"物理盗窃\u002F篡改","硬件和介质安全仍然至关重要",[990,991],"不良模型行为","幻觉、偏见和任务失败与网络无关",[993,994],"供应链投毒","受信任的导入源仍可能被入侵",{},{"id":997,"data":998,"type":42,"tunes":1000},"h-benefits",{"text":999,"level":253},"气隙实际改善了哪些方面",{},{"id":1002,"data":1003,"type":218,"tunes":1005},"p-benefit-1",{"text":1004},"真正的气隙可以实质性减少依赖直接远程连接的攻击路径：外部命令与控制、云凭据滥用、面向互联网的服务利用，以及通过普通出站 API 造成的意外数据外泄。",{},{"id":1007,"data":1008,"type":218,"tunes":1010},"p-benefit-2",{"text":1009},"它还在一个狭义层面上简化了数据驻留：如果不存在路径，推理数据就无法发送到外部云服务。",{},{"id":1012,"data":1013,"type":218,"tunes":1015},"p-benefit-3",{"text":1014},"当传输边界和内部访问控制同样严格时，这些好处最为显著。管理不善的 USB 流程可能会破坏预期的隔离。",{},{"id":1017,"data":1018,"type":42,"tunes":1020},"h-costs",{"text":1019,"level":253},"气隙使哪些事情变得更困难",{},{"id":1022,"data":1023,"type":394,"tunes":1063},"cost-table",{"content":1024,"stretched":43,"withHeadings":14},[1025,1028,1031,1034,1037,1040,1043,1046,1049,1051,1054,1057,1060],[1026,1027],"领域","运营后果",[1029,1030],"模型更新","手动\u002F分阶段传输，而非直接从模型中心拉取",[1032,1033],"安全补丁","延迟且受治理的导入工作流",[1035,1036],"软件包安装","需要内部镜像源或预构建制品",[1038,1039],"云 AI API","不可用",[1041,1042],"网络搜索\u002F连接器","不可用，除非数据单独导入",[1044,1045],"身份验证","需要内部\u002F可离线运行的身份服务",[1047,1048],"监控","需要内部可观测性和受控导出",[606,1050],"需要在线激活的产品可能不适用",[1052,1053],"故障排除","无法从生产飞地轻松实时访问供应商资源",[1055,1056],"容量","所有推理计算必须存在于本地",[1058,1059],"灾难恢复","云备份可能不可用或受策略限制",[1061,1062],"知识新鲜度","外部信息仅以导入流程的速度到达",{},{"id":1065,"data":1066,"type":42,"tunes":1068},"h-private",{"text":1067,"level":253},"气隙AI与私有AI",{},{"id":1070,"data":1071,"type":218,"tunes":1073},"p-private-1",{"text":1072},"私有AI主要关注控制敏感数据和AI处理过程。私有AI平台可以部署在本地，同时仍可访问经批准的云模型或外部服务。",{},{"id":1075,"data":1076,"type":218,"tunes":1078},"p-private-2",{"text":1077},"气隙AI在连接性方面要求更为严格。一个系统可以是私有的，但不一定是气隙的；而一个气隙系统如果每个内部用户都有不受限制的访问权限，其隐私保护仍可能很差。",{},{"id":1080,"data":1081,"type":218,"tunes":1083},"p-private-3",{"text":1082},"安全目标应决定架构：机密性、主权性、韧性和隔离性是相关但不同的需求。",{},{"id":1085,"data":1086,"type":42,"tunes":1088},"h-sovereign",{"text":1087,"level":253},"气隙AI与主权AI",{},{"id":1090,"data":1091,"type":218,"tunes":1093},"p-sovereign-1",{"text":1092},"主权AI涉及对更广泛依赖链的控制：数据、模型、基础设施、操作人员、司法管辖区和战略依赖。",{},{"id":1095,"data":1096,"type":218,"tunes":1098},"p-sovereign-2",{"text":1097},"气隙可以通过减少外部运行时依赖来支持主权，但它并不能保证主权控制。隔离区仍可能依赖外国硬件、专有模型许可证或外部更新供应商。",{},{"id":1100,"data":1101,"type":218,"tunes":1103},"p-sovereign-3",{"text":1102},"下一篇规范文章明确区分了这些控制维度。",{},{"id":1105,"data":1106,"type":42,"tunes":1108},"h-implementation",{"text":1107,"level":253},"原始实现证据：Aaasaasa AI Client证明了什么——以及没有证明什么",{},{"id":1110,"data":1111,"type":226,"tunes":1114},"impl-note",{"body":1112,"title":1113,"variant":246},"Aaasaasa AI Client是\u003Cstrong>本地推理架构\u003C\u002Fstrong>、提供商抽象以及运行时\u002F模型位置分离的有用证据。它\u003Cstrong>不是已部署气隙环境的证据\u003C\u002Fstrong>。该仓库还支持云和远程路径，且没有经过验证的项目证据能够确立一个物理隔离的安全域。","实现边界",{},{"id":1116,"data":1117,"type":218,"tunes":1119},"p-impl-1",{"text":1118},"AI Hub将代理\u002F客户端、提供商、模型和连接位置分开。它支持本地Ollama推理和本地提供商Codex操作作为不同选择，而不是假设每个AI请求都发送到云模型。",{},{"id":1121,"data":1122,"type":218,"tunes":1124},"p-impl-2",{"text":1123},"该仓库明确指出，本地运行时仍可使用云模型，而Direct Ollama聊天则是本地推理。这一区别与气隙架构直接相关：本地执行并不能证明模型或周围依赖是断开的。",{},{"id":1126,"data":1127,"type":218,"tunes":1129},"p-impl-3",{"text":1128},"因此，提供商抽象、本地模型发现和本地推理是具备气隙能力的产品架构的构建模块，但网络边界、离线依赖镜像、受控传输流程以及离线身份\u002F运营仍必须单独设计。",{},{"id":1131,"data":1132,"type":394,"tunes":1155},"impl-table",{"content":1133,"stretched":43,"withHeadings":14},[1134,1137,1140,1143,1146,1149,1152],[1135,1136],"已验证的项目能力","气隙相关性",[1138,1139],"本地Ollama推理","支持本地模型执行",[1141,1142],"本地提供商\u002F运行时路径","减少对云推理的依赖",[1144,1145],"提供商\u002F模型\u002F运行时分离","使云依赖显式化而非隐藏",[1147,1148],"集中权限","支持本地工具\u002F数据访问控制",[1150,1151],"同时存在云\u002F远程提供商支持","证明产品本身具备混合能力，而非天生气隙",[1153,1154],"没有经过验证的隔离部署边界","防止夸大气隙成熟度",{},{"id":1157,"data":1158,"type":42,"tunes":1160},"h-when",{"text":1159,"level":253},"何时气隙AI是合理的？",{},{"id":1162,"data":1163,"type":394,"tunes":1186},"when-table",{"content":1164,"stretched":43,"withHeadings":14},[1165,1168,1171,1174,1177,1180,1183],[1166,1167],"气隙可能合理的情况","连接式私有架构可能更好的情况",[1169,1170],"安全策略明确要求物理隔离域","主要需求仅是提示\u002F数据不被公共消费服务使用",[1172,1173],"机密或极其敏感的数据不能跨越外部网络","经批准的企业云\u002F私有端点满足数据控制要求",[1175,1176],"运营环境没有可靠的外部连接","互联网可用且运营敏捷性很重要",[1178,1179],"任务连续性不得依赖云\u002F提供商可用性","托管模型质量和快速升级更有价值",[1181,1182],"受监管\u002F关键环境要求受控传输","标准安全控制能够满足实际威胁模型",[1184,1185],"禁止外部SaaS\u002FAPI访问","业务工作流严重依赖外部连接器",{},{"id":1188,"data":1189,"type":218,"tunes":1191},"p-when-1",{"text":1190},"气隙应是从威胁模型或策略中推导出的需求，而不是一种声望功能。当被消除的连接路径本身不可接受时，它具有真正的安全价值。",{},{"id":1193,"data":1194,"type":218,"tunes":1196},"p-when-2",{"text":1195},"对于许多企业用例，具有出口限制、本地推理和经批准更新渠道的严格控制私有网络，可能比严格的物理气隙在安全性和可维护性之间提供更好的平衡。",{},{"id":1198,"data":1199,"type":42,"tunes":1201},"h-design",{"text":1200,"level":253},"实用的气隙AI设计流程",{},{"id":1203,"data":1204,"type":331,"tunes":1243},"design-flow",{"steps":1205,"title":1242,"orientation":330},[1206,1209,1212,1215,1218,1221,1224,1227,1230,1233,1236,1239],{"label":1207,"description":1208},"1. 定义气隙隔离的内容","明确安全域，以及需求是严格的物理隔离还是仅仅无互联网连接。",{"label":1210,"description":1211},"2. 清点所有外部依赖","模型、软件包、注册表、身份、遥测、许可、存储、API、DNS\u002F时间和支持服务。",{"label":1213,"description":1214},"3. 选择支持离线的模型和运行时","验证模型资产和运行时代码无需远程调用即可加载。",{"label":1216,"description":1217},"4. 构建内部制品仓库","为容器、软件包、模型和更新创建可信来源。",{"label":1219,"description":1220},"5. 设计受控传输","定义暂存、验证、介质\u002F网关处理、审批和来源追溯。",{"label":1222,"description":1223},"6. 构建内部身份和授权","确保用户、服务和工具无需云依赖即可认证。",{"label":1225,"description":1226},"7. 保持RAG和工具本地化","在隔离区内部署知识、嵌入、索引和所需的服务API。",{"label":1228,"description":1229},"8. 构建内部可观测性","在本地运行日志、指标、追踪和安全监控。",{"label":1231,"description":1232},"9. 定义补丁\u002F模型更新节奏","在漏洞响应与受控导入流程之间取得平衡。",{"label":1234,"description":1235},"10. 从干净的断开状态进行测试","在无继承缓存或隐藏互联网访问的情况下冷启动并运行。",{"label":1237,"description":1238},"11. 测试入侵路径","演练可移动介质、供应链、提示注入、内部人员和横向移动场景。",{"label":1240,"description":1241},"12. 记录例外和导出","每条允许的跨边界路径都应有明确的用途、负责人和控制集。","从边界向内设计",{},{"id":1245,"data":1246,"type":42,"tunes":1248},"h-checklist",{"text":1247,"level":253},"气隙AI架构检查清单",{},{"id":1250,"data":1251,"type":394,"tunes":1304},"checklist-table",{"content":1252,"stretched":43,"withHeadings":14},[1253,1256,1259,1262,1265,1268,1271,1274,1277,1280,1283,1286,1289,1292,1295,1298,1301],[1254,1255],"问题","预期证据",[1257,1258],"究竟什么与什么隔离？","记录的安全域边界",[1260,1261],"边界是否物理断开？","若声称严格气隙，需提供网络\u002F物理架构证据",[1263,1264],"数据如何跨越边界？","授权的非自动化\u002F手动或明确记录的断开工作流",[1266,1267],"每个模型能否离线冷启动？","离线加载测试",[1269,1270],"分词器\u002F配置\u002F运行时资产是否完整？","已验证的内部模型包",[1272,1273],"容器\u002F软件包来自哪里？","内部可信镜像\u002F仓库",[1275,1276],"身份能否在无云服务下工作？","内部IdP\u002FPKI\u002F服务凭据路径",[1278,1279],"RAG能否离线摄取\u002F查询？","本地摄取、嵌入、索引和检索",[1281,1282],"哪些代理工具仍然可用？","内部能力清单",[1284,1285],"补丁如何导入？","受控维护流程",[1287,1288],"制品如何验证？","完整性\u002F来源\u002F恶意软件\u002F供应链控制",[1290,1291],"可移动介质如何管理？","介质处理和消毒策略",[1293,1294],"清除缓存后系统能否运行？","干净环境离线测试",[1296,1297],"日志和追踪存储在哪里？","内部可观测性平台",[1299,1300],"导出如何审批？","受控出口流程",[1302,1303],"什么证明这是气隙而非仅仅本地？","边界和传输证据，而非模型位置",{},{"id":1306,"data":1307,"type":42,"tunes":1309},"h-failures",{"text":1308,"level":253},"常见的气隙AI故障模式",{},{"id":1311,"data":1312,"type":394,"tunes":1353},"failure-table",{"content":1313,"stretched":43,"withHeadings":14},[1314,1317,1320,1323,1326,1329,1332,1335,1338,1341,1344,1347,1350],[1315,1316],"故障模式","实际失败原因",[1318,1319],"本地模型在启动时仍下载分词器\u002F配置","模型包不完整",[1321,1322],"容器引用公共注册表","部署非自包含",[1324,1325],"登录需要云身份","应用是本地但身份不是",[1327,1328],"需要外部许可证服务器","供应商依赖与离线运行矛盾",[1330,1331],"缺少嵌入模型","聊天可用但RAG摄取失败",[1333,1334],"代理工具调用公共SaaS","代理架构不兼容气隙",[1336,1337],"仅GPU节点隔离","数据库、UI或监控仍依赖外部服务",[1339,1340],"USB导入不规范","传输边界成为不受控攻击路径",[1342,1343],"无补丁流程","隔离导致漏洞债务累积",[1345,1346],"使用有缓存的开发机作为证明","全新部署在无互联网时失败",[1348,1349],"气隙替代了授权思考","内部用户\u002F服务权限过高",[1351,1352],"气隙标签用于仅防火墙出口阻断","安全文档夸大了实际边界",{},{"id":1355,"data":1356,"type":42,"tunes":1358},"h-misconceptions",{"text":1357,"level":253},"常见误解",{},{"id":1360,"data":1361,"type":394,"tunes":1396},"misconceptions-table",{"content":1362,"stretched":43,"withHeadings":14},[1363,1366,1369,1372,1375,1378,1381,1384,1387,1390,1393],[1364,1365],"误解","更正",[1367,1368],"“本地AI就是气隙AI。”","本地描述推理运行位置；气隙描述安全\u002F网络边界。",[1370,1371],"“气隙意味着一台独立PC。”","隔离区可以包含整个内部网络或集群。",[1373,1374],"“无互联网等于严格气隙。”","根据NIST定义，分离系统还缺乏物理连接，且跨边界传输是非自动化的。",[1376,1377],"“气隙消除网络风险。”","供应链、可移动介质、内部人员、内部网络和应用风险仍然存在。",[1379,1380],"“RAG需要云。”","RAG可以完全使用本地模型、索引和数据运行。",[1382,1383],"“代理无法离线工作。”","代理可以使用内部\u002F本地工具；它们只是无法访问不可用的外部服务。",[1385,1386],"“安装后系统无需更新。”","补丁、驱动、模型和依赖仍需生命周期管理。",[1388,1389],"“下载的模型是自包含的。”","分词器、远程代码、库或模型资产仍可能触发网络依赖。",[1391,1392],"“私有AI和气隙AI相同。”","私有AI是数据\u002F控制属性；气隙是连接属性。",[1394,1395],"“气隙保证主权。”","外部硬件、许可、模型和供应链仍可能是依赖。",{},{"id":1398,"data":1399,"type":42,"tunes":1401},"h-limitations",{"text":1400,"level":253},"局限性",{},{"id":1403,"data":1404,"type":218,"tunes":1406},"p-limit-1",{"text":1405},"严格气隙使外部知识更新更慢，因为每个新来源都必须经过传输流程。",{},{"id":1408,"data":1409,"type":218,"tunes":1411},"p-limit-2",{"text":1410},"当许可、远程代码要求、硬件需求或仅提供商API无法离线满足时，它们可能限制模型选择。",{},{"id":1413,"data":1414,"type":218,"tunes":1416},"p-limit-3",{"text":1415},"它们增加运营成本，因为通常作为云服务消费的基础设施必须在内部拥有和维护。",{},{"id":1418,"data":1419,"type":218,"tunes":1421},"p-limit-4",{"text":1420},"它们还可能造成补丁延迟：更强的变更控制可能保持系统稳定，同时延迟紧急漏洞修复。",{},{"id":1423,"data":1424,"type":218,"tunes":1426},"p-limit-5",{"text":1425},"因此，气隙AI应作为多种安全架构之一进行评估，而非假定其普遍优越。",{},{"id":1428,"data":1429,"type":42,"tunes":1431},"h-change",{"text":1430,"level":253},"什么会改变这个答案？",{},{"id":1433,"data":1434,"type":218,"tunes":1436},"p-change-1",{"text":1435},"供应商对断开操作的支持变化很快。新的模型格式、签名的OCI制品、离线许可机制和集成模型注册表可以减少操作摩擦。",{},{"id":1438,"data":1439,"type":218,"tunes":1441},"p-change-2",{"text":1440},"即使供应商继续宽松地使用这些术语，严格气隙与断开部署之间的区别仍将重要。",{},{"id":1443,"data":1444,"type":218,"tunes":1446},"p-change-3",{"text":1445},"稳定的原则是，真正的气隙声明取决于系统边界和传输机制，而非LLM是否恰好本地运行。",{},{"id":1448,"data":1449,"type":42,"tunes":1451},"h-related",{"text":1450,"level":253},"相关规范知识",{},{"id":1453,"data":1454,"type":218,"tunes":1456},"p-related-1",{"text":1455},"气隙AI是一个部署\u002F安全架构节点。私有AI、主权AI和提供商抽象回答了关于机密性、控制和依赖性的不同问题。",{},{"id":1458,"data":1459,"type":218,"tunes":1461},"p-related-2",{"text":1460},"在断开连接的环境中，MLOps\u002FLLMOps 的要求更高，因为模型、软件包和更新的生命周期必须通过内部仓库和受控传输来运作。",{},{"id":1463,"data":1464,"type":218,"tunes":1466},"p-related-3",{"text":1465},"只要数据和工具在内部可用，RAG 和代理式 AI 在隔离区内仍然是有效的模式。",{},{"id":1468,"data":1469,"type":661,"tunes":1474},"ref-memory",{"url":1470,"title":1471,"excerpt":1472,"ctaLabel":1473},"https:\u002F\u002Fstajic.de\u002Fzh\u002Fblog\u002Fai-agent-memory-is-not-rag-how-to-separate-memory-retrieval-state-and-context","AI 代理记忆不是 RAG：如何区分记忆、检索、状态和上下文","气隙 AI 仍然需要在持久记忆、权威状态、检索和模型上下文之间建立正确的内部边界。","阅读记忆架构文章",{},{"id":1476,"data":1477,"type":42,"tunes":1479},"h-faq",{"text":1478,"level":253},"常见问题",{},{"id":1481,"data":1482,"type":1481,"tunes":1525},"faq",{"items":1483,"title":1524},[1484,1488,1492,1496,1500,1504,1508,1512,1516,1520],{"id":1485,"answer":1486,"question":1487},"faq1","气隙 AI 是部署在与外部系统物理断开的安全域内的 AI，根据严格的 NIST 定义，跨边界传输通过受控的非自动化程序进行。","什么是气隙 AI？",{"id":1489,"answer":1490,"question":1491},"faq2","正常推理和运行不需要。所需的模型、软件包、数据和服务必须在隔离环境内可用。","气隙 AI 需要互联网访问吗？",{"id":1493,"answer":1494,"question":1495},"faq3","不是。本地模型可以运行在仍然具有互联网访问或使用云身份、工具或存储的机器上。气隙描述的是完整的系统边界。","本地 LLM 是否自动就是气隙的？",{"id":1497,"answer":1498,"question":1499},"faq4","可以。文档、嵌入模型、向量或词法索引、重排序器和生成模型都可以在本地运行。外部知识必须通过受控边界导入。","RAG 能在气隙网络中工作吗？",{"id":1501,"answer":1502,"question":1503},"faq5","可以，如果它们的工具和所需系统在隔离网络内可用。未经允许的跨边界机制，公共 SaaS 和云 API 不可用。","AI 代理能在气隙环境中工作吗？",{"id":1505,"answer":1506,"question":1507},"faq6","模型通常在连接的暂存环境中获取和验证，通过批准的流程传输，并发布到内部模型\u002F工件仓库。","在气隙环境中如何更新模型？",{"id":1509,"answer":1510,"question":1511},"faq7","不同。本地部署描述的是基础设施位置。本地系统可以保持互联网连接。","本地部署 AI 与气隙 AI 相同吗？",{"id":1513,"answer":1514,"question":1515},"faq8","不同。私有 AI 关乎数据\u002F控制要求，仍然可以使用连接的基础设施。气隙特指网络\u002F域隔离。","私有 AI 与气隙 AI 相同吗？",{"id":1517,"answer":1518,"question":1519},"faq9","它消除或减少了一些远程连接风险，但并未消除供应链、可移动介质、内部人员、内部授权、物理或模型行为风险。","气隙能使 AI 安全吗？",{"id":1521,"answer":1522,"question":1523},"faq10","在干净环境中部署或冷启动整个堆栈，所有外部连接不可用，并验证模型、身份、RAG、工具、监控、更新和恢复仅依赖经批准的内部工件和服务。","气隙就绪的最佳测试是什么？","气隙 AI 常见问题",{},{"id":1527,"data":1528,"type":42,"tunes":1530},"h-glossary",{"text":1529,"level":253},"术语表",{},{"id":1532,"data":1533,"type":1532,"tunes":1583},"glossary",{"title":1534,"entries":1535},"关键气隙 AI 术语",[1536,1540,1544,1548,1552,1555,1559,1563,1567,1571,1575,1579],{"term":1537,"anchor":1538,"definition":1539},"气隙","air-gap","安全域接口，系统之间没有物理连接，根据 NIST 术语表定义，任何跨边界的逻辑传输都是非自动化\u002F手动的。",{"term":1541,"anchor":1542,"definition":1543},"气隙 AI","air-gapped-ai","部署在气隙安全域内的 AI 系统，其推理和操作依赖项在本地可用。",{"term":1545,"anchor":1546,"definition":1547},"断开连接的环境","disconnected-environment","没有直接外部互联网访问的部署环境；实现可能使用受控镜像或堡垒工作流。",{"term":1549,"anchor":1550,"definition":1551},"离线能力 AI","offline-capable-ai","能够在没有互联网连接的情况下运行部分或全部功能的 AI 应用，但不一定永久隔离。",{"term":367,"anchor":1553,"definition":1554},"local-ai","在本地硬件上执行 AI 推理或运行时，而不是远程模型端点；不意味着网络隔离。",{"term":1556,"anchor":1557,"definition":1558},"镜像仓库","mirror-registry","包含断开连接部署所需的容器镜像或其他工件的经批准副本的内部仓库。",{"term":1560,"anchor":1561,"definition":1562},"暂存环境","staging-environment","在传输到隔离域之前，获取、验证和准备工件的连接或受控区域。",{"term":1564,"anchor":1565,"definition":1566},"受控传输","controlled-transfer","使用经批准的介质\u002F流程和验证，在隔离边界上对数据或软件进行受治理的移动。",{"term":1568,"anchor":1569,"definition":1570},"工件来源","artifact-provenance","显示模型、软件包、容器或其他导入工件来源以及如何生产或验证的信息。",{"term":1572,"anchor":1573,"definition":1574},"可移动介质","removable-media","用于在系统之间传输数据的便携式存储；跨断开域的潜在安全路径。",{"term":1576,"anchor":1577,"definition":1578},"内部模型存储","internal-model-store","隔离环境内的仓库，经批准的模型工件从中提供或部署。",{"term":1580,"anchor":1581,"definition":1582},"气隙就绪","air-gap-readiness","完整 AI 堆栈在没有未经批准的外部连接的情况下安装、启动、运行、更新和恢复的已证明能力。",{},{"id":1585,"data":1586,"type":42,"tunes":1588},"h-conclusion",{"text":1587,"level":253},"结论",{},{"id":1590,"data":1591,"type":218,"tunes":1593},"p-conclusion-1",{"text":1592},"气隙 AI 不是一种特殊的模型。它是一种在故意隔离的安全域内运行的 AI 架构。",{},{"id":1595,"data":1596,"type":218,"tunes":1598},"p-conclusion-2",{"text":1597},"模型可能是简单的部分。生产就绪取决于每个周边依赖项——模型资产、软件包、注册表、身份、RAG、工具、监控、更新和恢复——是否能在没有自动化外部路径的情况下运行。",{},{"id":1600,"data":1601,"type":218,"tunes":1603},"p-conclusion-3",{"text":1602},"最短的可靠规则是：本地推理证明模型在哪里运行；气隙证据证明整个系统如何隔离，以及每次允许的传输如何跨越该边界。",{},{"id":1605,"data":1606,"type":42,"tunes":1608},"h-sources",{"text":1607,"level":253},"主要来源和当前实现参考",{},{"id":1610,"data":1611,"type":218,"tunes":1613},"p-sources-note",{"text":1612},"以下来源确立了安全定义、当前断开连接的 AI 部署模式和生命周期风险。供应商对“气隙”的使用有意与更严格的 NIST 定义区分开来。",{},{"id":1615,"data":1616,"type":1622,"tunes":1623},"src-nist-airgap",{"link":1617,"meta":1618},"https:\u002F\u002Fcsrc.nist.gov\u002Fglossary\u002Fterm\u002Fair_gap",{"image":1619,"title":1620,"description":1621},{"url":419},"NIST CSRC — 气隙","NIST 术语表定义：物理断开的系统，跨边界的非自动化、手动控制的逻辑传输。","linkTool",{},{"id":1625,"data":1626,"type":1622,"tunes":1632},"src-nvidia-airgap",{"link":1627,"meta":1628},"https:\u002F\u002Fdocs.nvidia.com\u002Fnim\u002Flarge-language-models\u002Flatest\u002Fdeploy-air-gap.html",{"image":1629,"title":1630,"description":1631},{"url":419},"NVIDIA NIM — 气隙部署","当前操作指南，用于在连接的系统上暂存模型资产，并在没有互联网、公共注册表或云 API 密钥的情况下从本地存储运行 NIM。",{},{"id":1634,"data":1635,"type":1622,"tunes":1641},"src-redhat-disconnected",{"link":1636,"meta":1637},"https:\u002F\u002Fdocs.redhat.com\u002Fen\u002Fdocumentation\u002Fred_hat_ai_inference\u002F3.5\u002Fhtml\u002Fdeploy_the_standalone_red_hat_ai_inference_container_in_a_disconnected_environment\u002Findex",{"image":1638,"title":1639,"description":1640},{"url":419},"Red Hat AI 推理 — 断开连接的部署","当前 Red Hat 指南，用于在断开连接的环境中使用镜像工件和内部基础设施提供 LLM 服务。",{},{"id":1643,"data":1644,"type":1622,"tunes":1650},"src-redhat-models",{"link":1645,"meta":1646},"https:\u002F\u002Fdocs.redhat.com\u002Fen\u002Fdocumentation\u002Fred_hat_ai_inference\u002F3.5\u002Fhtml\u002Fdeploy_the_standalone_red_hat_ai_inference_container_in_a_disconnected_environment\u002Fstoring-models-in-disconnected-environments_disconnected-deploy",{"image":1647,"title":1648,"description":1649},{"url":419},"红帽 AI 推理 — 在隔离环境中存储模型","涵盖 OCI 模型镜像、持久化模型存储以及需要远程代码的模型局限性的当前指南。",{},{"id":1652,"data":1653,"type":1622,"tunes":1659},"src-nsa-framework",{"link":1654,"meta":1655},"https:\u002F\u002Fwww.nsa.gov\u002Fportals\u002F75\u002Fdocuments\u002Fwhat-we-do\u002Fcybersecurity\u002Fprofessional-resources\u002Fctr-nsa-css-technical-cyber-threat-framework.pdf",{"image":1656,"title":1657,"description":1658},{"url":419},"NSA — 技术网络威胁框架","该威胁框架明确将可移动介质复制识别为进入隔离或气隙网络的路径。",{},{"id":1661,"data":1662,"type":1622,"tunes":1668},"src-nist-media",{"link":1663,"meta":1664},"https:\u002F\u002Fwww.nist.gov\u002Fpublications\u002Fguidelines-media-sanitization",{"image":1665,"title":1666,"description":1667},{"url":419},"NIST SP 800-88 Rev. 1 — 介质净化指南","根据信息保密要求管理和净化存储介质的指南。",{},{"id":1670,"data":1671,"type":1622,"tunes":1677},"src-nist-patch",{"link":1672,"meta":1673},"https:\u002F\u002Fcsrc.nist.gov\u002Fpubs\u002Fsp\u002F800\u002F40\u002Fr4\u002Ffinal",{"image":1674,"title":1675,"description":1676},{"url":419},"NIST SP 800-40 Rev. 4 — 企业补丁管理规划","将补丁和更新视为企业系统预防性维护的指导框架。",{},{"id":1679,"data":1680,"type":1622,"tunes":1686},"src-nist-supply",{"link":1681,"meta":1682},"https:\u002F\u002Fwww.nist.gov\u002Fitl\u002Fexecutive-order-14028-improving-nations-cybersecurity\u002Fsoftware-security-supply-chains",{"image":1683,"title":1684,"description":1685},{"url":419},"NIST — 供应链中的软件安全","NIST 指南，涵盖软件供应链风险、来源、验证、SBOM 相关实践和漏洞管理。",{},"2.31","气隙AI在隔离的安全域内运行模型、RAG和AI应用，无需互联网或云依赖。了解模型、数据、更新和工具如何离线运行。","\u002Fuploads\u002F2026\u002F10\u002Fair-gapped-ai-how-ai-systems-work-without-internet-or-cloud-access-1791487983978-e6xqf0.webp","air-gapped-ai-how-ai-systems-work-without-internet-or-cloud-access-1791487983978-e6xqf0","PUBLISHED","2026-10-08T11:32:00.000Z","2026-10-08T19:32:11.607Z","2026-10-08T21:37:26.788Z",{"en":1696,"de":1697,"sr":1698,"es":1699,"fr":1700,"it":1701,"ru":1702,"zh":1703},"\u002Fblog\u002Fair-gapped-ai-how-ai-systems-work-without-internet-or-cloud-access","\u002Fde\u002Fblog\u002Fair-gapped-ai-how-ai-systems-work-without-internet-or-cloud-access","\u002Fsr\u002Fblog\u002Fair-gapped-ai-how-ai-systems-work-without-internet-or-cloud-access","\u002Fes\u002Fblog\u002Fair-gapped-ai-how-ai-systems-work-without-internet-or-cloud-access","\u002Ffr\u002Fblog\u002Fair-gapped-ai-how-ai-systems-work-without-internet-or-cloud-access","\u002Fit\u002Fblog\u002Fair-gapped-ai-how-ai-systems-work-without-internet-or-cloud-access","\u002Fru\u002Fblog\u002Fair-gapped-ai-how-ai-systems-work-without-internet-or-cloud-access","\u002Fzh\u002Fblog\u002Fair-gapped-ai-how-ai-systems-work-without-internet-or-cloud-access",[1705,1709,1713],{"id":1706,"name":1707,"slug":1708},57,"数据边界","data-boundaries",{"id":1710,"name":1711,"slug":1712},54,"威胁模型","threat-model",{"id":1714,"name":1715,"slug":1716},49,"控制与证据","controls",{"id":1718,"login":1719,"email":1720,"displayName":1721},"20","rooth8233","aleksandar@stajic.de","Aleksandar Stajić",[1723,2982],{"lang":1724,"title":1725,"content":1726,"contentJson":1727,"excerpt":2981},"en","Air-Gapped AI: How AI Systems Work Without Internet or Cloud Access","{\"time\":1791495428517,\"blocks\":[{\"id\":\"intro\",\"type\":\"paragraph\",\"data\":{\"text\":\"Air-gapped AI is an AI system deployed inside a security domain that has no physical network connection to the external systems it is separated from, with any transfer across that boundary performed through deliberately controlled, non-automated procedures. The AI model, runtime, data, retrieval indexes, tools and operational dependencies required for inference must therefore be available inside the isolated environment. Air-gapped AI is not simply “a local model” or “an on-premise server”: the defining property is the network and transfer boundary around the complete system.\"},\"tunes\":{}},{\"id\":\"direct\",\"type\":\"callout\",\"data\":{\"variant\":\"info\",\"title\":\"Direct answer\",\"body\":\"An air-gapped AI system can run LLM inference, RAG, document analysis and even agentic workflows without internet or cloud APIs if every required dependency is available inside the isolated domain.\u003Cbr>\u003Cbr>A practical architecture is:\u003Cbr>\u003Cstrong>controlled import → internal artifact\u002Fmodel repositories → local AI runtime → local data\u002FRAG → local tools → internal users\u002Fservices → local monitoring\u002Faudit\u003C\u002Fstrong>.\u003Cbr>\u003Cbr>The difficult part is not making one LLM answer offline. It is operating the whole AI lifecycle — updates, models, drivers, packages, data imports, credentials, logging and security — without silently depending on external services.\"},\"tunes\":{}},{\"id\":\"nist-boundary\",\"type\":\"callout\",\"data\":{\"variant\":\"warning\",\"title\":\"Air gap has a stricter meaning than “no internet”\",\"body\":\"NIST's cybersecurity glossary defines an air gap as an interface where two systems are \u003Cstrong>not physically connected\u003C\u002Fstrong> and where any logical transfer is \u003Cstrong>not automated\u003C\u002Fstrong>; data crosses only manually under human control. Vendor documentation sometimes uses “air-gapped” or “disconnected” more broadly for environments with no outside-internet connection but with internal networking and controlled staging infrastructure. Architecture documentation should state which meaning is actually implemented.\"},\"tunes\":{}},{\"id\":\"not-security\",\"type\":\"callout\",\"data\":{\"variant\":\"warning\",\"title\":\"Air-gapped does not mean secure by definition\",\"body\":\"Removing direct network connectivity eliminates many remote paths, but it does not eliminate malicious removable media, compromised software\u002Fmodel imports, insider threats, vulnerable internal services, physical compromise, prompt injection through imported documents or lateral movement inside the isolated network.\"},\"tunes\":{}},{\"id\":\"current\",\"type\":\"callout\",\"data\":{\"variant\":\"note\",\"title\":\"Current-source note — 8 October 2026\",\"body\":\"Current NVIDIA NIM and Red Hat AI Inference documentation both support LLM serving without outside-internet access by pre-staging model and container assets. NVIDIA documents a connected preparation phase followed by an isolated execution phase with local assets and no cloud registry credentials. Red Hat uses mirrored container\u002Fmodel repositories for disconnected OpenShift environments. These are useful implementation examples, but they do not override the stricter NIST definition of an air gap.\"},\"tunes\":{}},{\"id\":\"toc\",\"type\":\"tableOfContents\",\"data\":{\"title\":\"Contents\",\"minLevel\":2,\"maxLevel\":3},\"tunes\":{}},{\"id\":\"h-meaning\",\"type\":\"header\",\"data\":{\"text\":\"What air-gapped AI really means\",\"level\":2},\"tunes\":{}},{\"id\":\"p-meaning-1\",\"type\":\"paragraph\",\"data\":{\"text\":\"The word AI does not change the basic security concept. An air gap is a boundary between security domains. AI simply makes the isolated side more operationally demanding because modern AI stacks normally assume downloadable models, package registries, telemetry, APIs, model hubs and frequent software updates.\"},\"tunes\":{}},{\"id\":\"p-meaning-2\",\"type\":\"paragraph\",\"data\":{\"text\":\"The isolated environment can still contain many connected machines. An internal cluster may have GPUs, application servers, storage, databases, identity services and monitoring connected to each other. The air gap exists between that enclave and the outside domain.\"},\"tunes\":{}},{\"id\":\"p-meaning-3\",\"type\":\"paragraph\",\"data\":{\"text\":\"The relevant question is therefore not “Does this GPU have Wi-Fi?” but “Can this AI environment exchange information with the external domain through an automated physical or logical path?”\"},\"tunes\":{}},{\"id\":\"h-simple\",\"type\":\"header\",\"data\":{\"text\":\"The simplest example\",\"level\":2},\"tunes\":{}},{\"id\":\"p-simple-1\",\"type\":\"paragraph\",\"data\":{\"text\":\"Imagine a company wants an internal assistant for confidential technical documents, but the environment is not permitted to send those documents to the internet.\"},\"tunes\":{}},{\"id\":\"p-simple-2\",\"type\":\"paragraph\",\"data\":{\"text\":\"The company downloads an approved LLM, embedding model, container images and software packages in a connected staging environment. After validation, approved artifacts are transferred into the isolated environment.\"},\"tunes\":{}},{\"id\":\"p-simple-3\",\"type\":\"paragraph\",\"data\":{\"text\":\"Inside the enclave, the model server, document parser, vector database, application and identity services run locally. Users can ask questions and use RAG against internal documents without a cloud model or public model registry.\"},\"tunes\":{}},{\"id\":\"p-simple-4\",\"type\":\"paragraph\",\"data\":{\"text\":\"When an update is required, the update passes through the controlled import process again rather than being downloaded directly by the production AI server.\"},\"tunes\":{}},{\"id\":\"simple-flow\",\"type\":\"processFlow\",\"data\":{\"title\":\"A basic air-gapped AI operating cycle\",\"orientation\":\"auto\",\"steps\":[{\"label\":\"1. Acquire outside the enclave\",\"description\":\"Download approved models, packages, containers, drivers, signatures and documentation in a connected staging environment.\"},{\"label\":\"2. Verify before transfer\",\"description\":\"Check provenance, signatures\u002Fchecksums, malware status, licensing and compatibility according to organizational policy.\"},{\"label\":\"3. Transfer through controlled boundary\",\"description\":\"Move approved artifacts using the authorized manual or mediated process.\"},{\"label\":\"4. Publish internally\",\"description\":\"Place artifacts in internal model, container, package or file repositories.\"},{\"label\":\"5. Deploy locally\",\"description\":\"Run inference, RAG, applications and tools without external dependencies.\"},{\"label\":\"6. Monitor inside the enclave\",\"description\":\"Collect logs, metrics, model\u002Fruntime status and security events locally.\"},{\"label\":\"7. Export only approved evidence\",\"description\":\"Move selected reports or artifacts outward through the reverse controlled process where policy permits.\"},{\"label\":\"8. Repeat for updates\",\"description\":\"Treat new models, patches, corpora and dependencies as new supply-chain imports.\"}]},\"tunes\":{}},{\"id\":\"h-stops\",\"type\":\"header\",\"data\":{\"text\":\"Where the simple example stops\",\"level\":2},\"tunes\":{}},{\"id\":\"p-stops-1\",\"type\":\"paragraph\",\"data\":{\"text\":\"A production air-gapped environment can be much larger than one workstation. It may include Kubernetes\u002FOpenShift, internal registries, object storage, identity providers, vector databases, observability, backup infrastructure and several model-serving nodes.\"},\"tunes\":{}},{\"id\":\"p-stops-2\",\"type\":\"paragraph\",\"data\":{\"text\":\"The more services exist inside the enclave, the more the organization must reproduce capabilities that connected environments normally consume from the internet.\"},\"tunes\":{}},{\"id\":\"p-stops-3\",\"type\":\"paragraph\",\"data\":{\"text\":\"Air-gapping therefore shifts complexity. It reduces direct external connectivity but increases artifact-management, patching, dependency, supply-chain and operational responsibility inside the isolated domain.\"},\"tunes\":{}},{\"id\":\"h-terms\",\"type\":\"header\",\"data\":{\"text\":\"Air-gapped vs offline vs local vs on-premises vs private vs sovereign AI\",\"level\":2},\"tunes\":{}},{\"id\":\"terms-table\",\"type\":\"table\",\"data\":{\"withHeadings\":true,\"stretched\":false,\"content\":[[\"Term\",\"What it primarily describes\",\"Internet\u002Fexternal connectivity required?\"],[\"Local AI\",\"Inference\u002Fruntime runs on local hardware\",\"No; but it may still call cloud services\"],[\"Offline-capable AI\",\"Can continue operating without internet\",\"No during offline operation; reconnection may be normal\"],[\"Disconnected environment\",\"No direct external-internet path from deployment environment\",\"Usually no; may use controlled mirrors\u002Fbastions\"],[\"On-premises AI\",\"Infrastructure runs in an organization's own\u002Fon-prem environment\",\"Could still have full internet connectivity\"],[\"Private AI\",\"AI processing is controlled to meet privacy\u002Fconfidentiality requirements\",\"Architecture-specific; can be connected or disconnected\"],[\"Air-gapped AI\",\"Security domains are physically disconnected and cross-boundary transfer is non-automated\u002Fmanual under strict definition\",\"No automated external path\"],[\"Sovereign AI\",\"Control\u002Fjurisdiction over models, data, infrastructure and dependencies\",\"Not necessarily; sovereignty is broader than network isolation\"]]},\"tunes\":{}},{\"id\":\"p-terms-1\",\"type\":\"paragraph\",\"data\":{\"text\":\"These terms can overlap but are not synonyms. A local Ollama server connected to the internet is local AI, not air-gapped AI. An on-premises RAG platform that calls a cloud model is on-premises application infrastructure with cloud inference, not air-gapped AI.\"},\"tunes\":{}},{\"id\":\"p-terms-2\",\"type\":\"paragraph\",\"data\":{\"text\":\"An air-gapped system is often private by design because data remains inside the enclave, but privacy also depends on authorization, logging, data handling, physical security and operational policy.\"},\"tunes\":{}},{\"id\":\"h-strict\",\"type\":\"header\",\"data\":{\"text\":\"Strict air gap vs practical disconnected deployment\",\"level\":2},\"tunes\":{}},{\"id\":\"strict-comparison\",\"type\":\"comparison\",\"data\":{\"title\":\"Two meanings frequently called “air-gapped”\",\"layout\":\"table\",\"columns\":[{\"id\":\"strict\",\"label\":\"Strict air gap\"},{\"id\":\"disconnected\",\"label\":\"Disconnected \u002F no-internet deployment\"}],\"rows\":[{\"id\":\"physical\",\"label\":\"External physical connection\",\"values\":{\"strict\":\"\",\"disconnected\":\"\"}},{\"id\":\"transfer\",\"label\":\"Cross-boundary transfer\",\"values\":{\"strict\":\"\",\"disconnected\":\"\"}},{\"id\":\"internet\",\"label\":\"Internet access from AI workload\",\"values\":{\"strict\":\"\",\"disconnected\":\"\"}},{\"id\":\"internalnet\",\"label\":\"Internal networking\",\"values\":{\"strict\":\"\",\"disconnected\":\"\"}},{\"id\":\"best\",\"label\":\"Use term when\",\"values\":{\"strict\":\"\",\"disconnected\":\"\"}}]},\"tunes\":{}},{\"id\":\"naming-rule\",\"type\":\"callout\",\"data\":{\"variant\":\"success\",\"title\":\"Document the boundary instead of relying on the label\",\"body\":\"For architecture and security reviews, write the actual rule: \u003Cstrong>no outbound internet\u003C\u002Fstrong>, \u003Cstrong>no physical external network path\u003C\u002Fstrong>, \u003Cstrong>manual transfer only\u003C\u002Fstrong>, or \u003Cstrong>disconnected cluster with approved bastion\u002Fmirror\u003C\u002Fstrong>. That is more precise than saying only “air-gapped.”\"},\"tunes\":{}},{\"id\":\"h-architecture\",\"type\":\"header\",\"data\":{\"text\":\"A practical air-gapped AI architecture\",\"level\":2},\"tunes\":{}},{\"id\":\"architecture-table\",\"type\":\"table\",\"data\":{\"withHeadings\":true,\"stretched\":false,\"content\":[[\"Layer\",\"What must exist inside the isolated environment\"],[\"User\u002Fapplication layer\",\"Chat UI, APIs, business application or internal agent interface\"],[\"Identity &amp; authorization\",\"Local\u002Finternal authentication, RBAC, tenant\u002Fresource permissions\"],[\"AI gateway\u002Fruntime\",\"Model routing, request policy, context assembly and runtime controls\"],[\"Model serving\",\"Local model server(s), weights, tokenizer\u002Fconfig and accelerator runtime\"],[\"RAG \u002F knowledge\",\"Document store, parser, embeddings, vector\u002Flexical indexes, metadata and provenance\"],[\"Tools\u002Fservices\",\"Only internal\u002Flocal APIs and approved systems reachable from the enclave\"],[\"Artifact repositories\",\"Local container registry, package mirror, model store and optionally OS\u002Fupdate repositories\"],[\"Observability\",\"Internal logs, metrics, traces and audit records\"],[\"Backup\u002Frecovery\",\"Local or separately controlled backup process appropriate to the security domain\"],[\"Transfer boundary\",\"Controlled import\u002Fexport process with inspection and approval\"]]},\"tunes\":{}},{\"id\":\"p-architecture-1\",\"type\":\"paragraph\",\"data\":{\"text\":\"A complete architecture should be able to start and operate without DNS lookups, license checks, package downloads or API calls to public services unless those dependencies have approved internal replacements.\"},\"tunes\":{}},{\"id\":\"p-architecture-2\",\"type\":\"paragraph\",\"data\":{\"text\":\"A useful design test is to disconnect the deployment from every external service and cold-start the stack. Hidden dependencies tend to appear during startup, model loading, authentication, package resolution or telemetry initialization.\"},\"tunes\":{}},{\"id\":\"h-models\",\"type\":\"header\",\"data\":{\"text\":\"Models must be pre-staged\",\"level\":2},\"tunes\":{}},{\"id\":\"p-models-1\",\"type\":\"paragraph\",\"data\":{\"text\":\"Cloud model APIs are unavailable by definition if the isolated workload has no path to them. The enclave therefore needs locally runnable model artifacts or an internally hosted inference service.\"},\"tunes\":{}},{\"id\":\"p-models-2\",\"type\":\"paragraph\",\"data\":{\"text\":\"NVIDIA's current NIM air-gap documentation explicitly uses a two-phase pattern: download and prepare model assets on a connected machine, transfer them, then run the isolated NIM from local storage without outbound registry access or cloud API keys.\"},\"tunes\":{}},{\"id\":\"p-models-3\",\"type\":\"paragraph\",\"data\":{\"text\":\"Model weights are only part of the dependency set. Tokenizers, configuration files, adapters, quantization metadata and any required runtime code must also be present.\"},\"tunes\":{}},{\"id\":\"h-remote-code\",\"type\":\"header\",\"data\":{\"text\":\"Models with remote-code dependencies are an air-gap hazard\",\"level\":2},\"tunes\":{}},{\"id\":\"p-remote-1\",\"type\":\"paragraph\",\"data\":{\"text\":\"Some model repositories contain custom Python code or runtime hooks that normally fetch additional code or assets.\"},\"tunes\":{}},{\"id\":\"p-remote-2\",\"type\":\"paragraph\",\"data\":{\"text\":\"Current Red Hat AI Inference documentation explicitly warns that some Hugging Face models requiring remote code cannot operate normally in disconnected environments because the library attempts network access even when offline mode is configured.\"},\"tunes\":{}},{\"id\":\"p-remote-3\",\"type\":\"paragraph\",\"data\":{\"text\":\"The practical lesson is to test a model's entire loading path offline before approving it for an isolated deployment. “I downloaded the weights” is not proof that the model is self-contained.\"},\"tunes\":{}},{\"id\":\"h-artifacts\",\"type\":\"header\",\"data\":{\"text\":\"Containers, packages and drivers become local supply-chain artifacts\",\"level\":2},\"tunes\":{}},{\"id\":\"p-artifacts-1\",\"type\":\"paragraph\",\"data\":{\"text\":\"Connected environments routinely pull container images, Python packages, OS updates and GPU components from public registries. An air-gapped environment cannot assume any of those services.\"},\"tunes\":{}},{\"id\":\"p-artifacts-2\",\"type\":\"paragraph\",\"data\":{\"text\":\"Red Hat's disconnected AI deployment model uses internal mirror registries for container images and operator catalogs. Models can be mirrored as OCI artifacts or transferred to persistent storage.\"},\"tunes\":{}},{\"id\":\"p-artifacts-3\",\"type\":\"paragraph\",\"data\":{\"text\":\"For broader stacks, the same pattern often applies to language packages, Linux repositories, JavaScript packages and internal binaries: approved artifacts enter once through the transfer process and are then served from trusted internal repositories.\"},\"tunes\":{}},{\"id\":\"h-bom\",\"type\":\"header\",\"data\":{\"text\":\"Know the complete dependency bill\",\"level\":2},\"tunes\":{}},{\"id\":\"dependency-table\",\"type\":\"table\",\"data\":{\"withHeadings\":true,\"stretched\":false,\"content\":[[\"Dependency class\",\"Examples\"],[\"Model artifacts\",\"Weights, tokenizer, config, adapters, quantization metadata\"],[\"Inference runtime\",\"vLLM, llama.cpp, Ollama, NIM or other serving runtime\"],[\"GPU\u002Fruntime stack\",\"Drivers, CUDA\u002FROCm libraries, container runtime\"],[\"Application packages\",\"Python wheels, npm packages, system libraries\"],[\"Containers\",\"Application, inference, DB, vector DB, monitoring images\"],[\"RAG models\",\"Embedding model, reranker, OCR\u002Fvision models\"],[\"Data\",\"Knowledge corpus, metadata, schemas, evaluation datasets\"],[\"Security material\",\"Certificates, CA bundles, policy\u002Fconfiguration, malware signatures where applicable\"],[\"Operational artifacts\",\"Dashboards, alert rules, backup tools, runbooks\"],[\"Licensing\",\"Offline-compatible licenses\u002Fentitlements where required\"]]},\"tunes\":{}},{\"id\":\"h-mirror\",\"type\":\"header\",\"data\":{\"text\":\"Internal mirrors are infrastructure, not a convenience\",\"level\":2},\"tunes\":{}},{\"id\":\"p-mirror-1\",\"type\":\"paragraph\",\"data\":{\"text\":\"A disconnected deployment becomes maintainable when the isolated domain has known internal sources for approved artifacts.\"},\"tunes\":{}},{\"id\":\"p-mirror-2\",\"type\":\"paragraph\",\"data\":{\"text\":\"Red Hat's documented approach uses a mirror registry available to the disconnected cluster so workloads do not need public registries.\"},\"tunes\":{}},{\"id\":\"p-mirror-3\",\"type\":\"paragraph\",\"data\":{\"text\":\"The same architectural idea can be applied to model stores and package repositories. The objective is to make artifact origin, version and approval explicit rather than copy random files manually to each server.\"},\"tunes\":{}},{\"id\":\"h-rag\",\"type\":\"header\",\"data\":{\"text\":\"RAG can work fully air-gapped\",\"level\":2},\"tunes\":{}},{\"id\":\"p-rag-1\",\"type\":\"paragraph\",\"data\":{\"text\":\"RAG does not require the public internet. It requires a retrievable corpus, an ingestion\u002Findexing pipeline and a model that can use the retrieved context.\"},\"tunes\":{}},{\"id\":\"p-rag-2\",\"type\":\"paragraph\",\"data\":{\"text\":\"Inside an air-gapped environment, the document store, parser\u002FOCR, embedding model, vector or lexical index, reranker and generation model can all run locally.\"},\"tunes\":{}},{\"id\":\"p-rag-3\",\"type\":\"paragraph\",\"data\":{\"text\":\"What changes is source acquisition. Live web search and cloud document connectors are unavailable unless equivalent data is imported through the controlled boundary.\"},\"tunes\":{}},{\"id\":\"p-rag-4\",\"type\":\"paragraph\",\"data\":{\"text\":\"The corpus therefore becomes a governed artifact. Every import should preserve source identity, date\u002Fversion and provenance so users know what knowledge the isolated system actually contains.\"},\"tunes\":{}},{\"id\":\"ref-rag\",\"type\":\"referralArticle\",\"data\":{\"url\":\"https:\u002F\u002Fstajic.de\u002Fblog\u002Fwhat-is-rag-the-simplest-explanation-of-how-it-works\",\"title\":\"What Is RAG? The Simplest Explanation of How It Works\",\"excerpt\":\"RAG itself is independent of cloud hosting. In an air-gapped architecture, retrieval and generation simply have to be supplied by local\u002Finternal components.\",\"ctaLabel\":\"Read the RAG foundation\"},\"tunes\":{}},{\"id\":\"h-agents\",\"type\":\"header\",\"data\":{\"text\":\"Agents can run air-gapped — but only with reachable tools\",\"level\":2},\"tunes\":{}},{\"id\":\"p-agents-1\",\"type\":\"paragraph\",\"data\":{\"text\":\"An agent loop can run entirely inside an isolated enclave if the model\u002Fruntime and required tools are local or reachable on the internal network.\"},\"tunes\":{}},{\"id\":\"p-agents-2\",\"type\":\"paragraph\",\"data\":{\"text\":\"A tool that depends on GitHub, public web search, cloud email or an external SaaS API will fail unless the architecture provides an approved internal equivalent or controlled asynchronous exchange process.\"},\"tunes\":{}},{\"id\":\"p-agents-3\",\"type\":\"paragraph\",\"data\":{\"text\":\"This is why air-gapped agent design should begin with a capability inventory: every tool endpoint must be classified as internal, imported, unavailable or deliberately excluded.\"},\"tunes\":{}},{\"id\":\"h-mcp\",\"type\":\"header\",\"data\":{\"text\":\"MCP does not bypass the air gap\",\"level\":2},\"tunes\":{}},{\"id\":\"p-mcp-1\",\"type\":\"paragraph\",\"data\":{\"text\":\"MCP can expose local tools and resources inside an isolated AI environment, but the protocol does not create connectivity through the security boundary.\"},\"tunes\":{}},{\"id\":\"p-mcp-2\",\"type\":\"paragraph\",\"data\":{\"text\":\"A local MCP server that reads internal documents can work perfectly offline. A remote MCP server on the public internet cannot be reached from a strict air-gapped enclave.\"},\"tunes\":{}},{\"id\":\"p-mcp-3\",\"type\":\"paragraph\",\"data\":{\"text\":\"The same principle applies to any connector protocol: interoperability is separate from network authority.\"},\"tunes\":{}},{\"id\":\"h-identity\",\"type\":\"header\",\"data\":{\"text\":\"Identity and authentication must also work offline\",\"level\":2},\"tunes\":{}},{\"id\":\"p-id-1\",\"type\":\"paragraph\",\"data\":{\"text\":\"An AI application can be locally hosted while still depending on a cloud identity provider. That hidden dependency breaks truly disconnected operation.\"},\"tunes\":{}},{\"id\":\"p-id-2\",\"type\":\"paragraph\",\"data\":{\"text\":\"Air-gapped designs therefore need an identity architecture that functions inside the enclave: local directory, internal identity provider, internal PKI, local service credentials or another approved mechanism.\"},\"tunes\":{}},{\"id\":\"p-id-3\",\"type\":\"paragraph\",\"data\":{\"text\":\"Authorization remains necessary even though the internet is absent. Air gaps do not replace RBAC, tenant isolation or least privilege.\"},\"tunes\":{}},{\"id\":\"h-time\",\"type\":\"header\",\"data\":{\"text\":\"Time, certificates and trust stores become local dependencies\",\"level\":2},\"tunes\":{}},{\"id\":\"p-time-1\",\"type\":\"paragraph\",\"data\":{\"text\":\"Many authentication and logging systems depend on reliable time. Certificates expire. Trust stores change. Signed artifacts need validation.\"},\"tunes\":{}},{\"id\":\"p-time-2\",\"type\":\"paragraph\",\"data\":{\"text\":\"A disconnected enclave should therefore have internal time synchronization and a certificate\u002Ftrust lifecycle that does not depend on reaching public services during ordinary operation.\"},\"tunes\":{}},{\"id\":\"p-time-3\",\"type\":\"paragraph\",\"data\":{\"text\":\"These are ordinary infrastructure concerns that become visible only when an architecture is tested without internet access.\"},\"tunes\":{}},{\"id\":\"h-telemetry\",\"type\":\"header\",\"data\":{\"text\":\"Telemetry and crash reporting need explicit policy\",\"level\":2},\"tunes\":{}},{\"id\":\"p-tel-1\",\"type\":\"paragraph\",\"data\":{\"text\":\"Many modern libraries attempt analytics, update checks or error reporting by default.\"},\"tunes\":{}},{\"id\":\"p-tel-2\",\"type\":\"paragraph\",\"data\":{\"text\":\"In an isolated environment those calls should either be disabled or redirected to internal observability. Repeated failed telemetry attempts can create delays, noisy logs and unexpected startup behavior.\"},\"tunes\":{}},{\"id\":\"p-tel-3\",\"type\":\"paragraph\",\"data\":{\"text\":\"An air-gapped deployment should know which components attempt egress even if the firewall would block them.\"},\"tunes\":{}},{\"id\":\"h-updates\",\"type\":\"header\",\"data\":{\"text\":\"Air-gapped systems still need patches\",\"level\":2},\"tunes\":{}},{\"id\":\"p-update-1\",\"type\":\"paragraph\",\"data\":{\"text\":\"Network isolation does not stop software from developing vulnerabilities. It only changes how patches reach the system.\"},\"tunes\":{}},{\"id\":\"p-update-2\",\"type\":\"paragraph\",\"data\":{\"text\":\"NIST frames patch management as preventive maintenance: organizations still need to identify, acquire, prioritize, install and verify patches and updates.\"},\"tunes\":{}},{\"id\":\"p-update-3\",\"type\":\"paragraph\",\"data\":{\"text\":\"Air-gapped operations therefore need a repeatable import cadence for OS packages, container images, drivers, AI runtimes and security updates. The trade-off is between isolation stability and vulnerability exposure from stale software.\"},\"tunes\":{}},{\"id\":\"h-patch-flow\",\"type\":\"header\",\"data\":{\"text\":\"A controlled update path\",\"level\":2},\"tunes\":{}},{\"id\":\"patch-flow\",\"type\":\"processFlow\",\"data\":{\"title\":\"Example update lifecycle for an isolated AI environment\",\"orientation\":\"auto\",\"steps\":[{\"label\":\"1. Identify required update\",\"description\":\"Security advisory, model\u002Fruntime improvement or operational need triggers change.\"},{\"label\":\"2. Acquire in connected staging\",\"description\":\"Download exact versions plus signatures\u002Fchecksums and metadata.\"},{\"label\":\"3. Validate supply-chain evidence\",\"description\":\"Verify source, integrity, compatibility and policy requirements.\"},{\"label\":\"4. Test in representative offline staging\",\"description\":\"Confirm the update works without unexpected network dependencies.\"},{\"label\":\"5. Approve transfer\",\"description\":\"Apply the organization's change and security process.\"},{\"label\":\"6. Import into enclave repository\",\"description\":\"Publish the artifact to the internal trusted source.\"},{\"label\":\"7. Deploy gradually\",\"description\":\"Apply to test\u002Fcanary nodes before wider rollout where architecture permits.\"},{\"label\":\"8. Verify and record\",\"description\":\"Confirm version, health, behavior and rollback state.\"}]},\"tunes\":{}},{\"id\":\"h-transfer\",\"type\":\"header\",\"data\":{\"text\":\"The transfer boundary is the most sensitive operational interface\",\"level\":2},\"tunes\":{}},{\"id\":\"p-transfer-1\",\"type\":\"paragraph\",\"data\":{\"text\":\"If external information must enter an air-gapped system, the import channel becomes a major security control point.\"},\"tunes\":{}},{\"id\":\"p-transfer-2\",\"type\":\"paragraph\",\"data\":{\"text\":\"The NSA Cybersecurity Technical Cyber Threat Framework explicitly recognizes replication through removable media as a path adversaries can use to cross into disconnected or air-gapped networks.\"},\"tunes\":{}},{\"id\":\"p-transfer-3\",\"type\":\"paragraph\",\"data\":{\"text\":\"That is why controlled media handling, inspection, provenance, encryption where required, malware scanning and role separation can matter as much as the AI stack itself.\"},\"tunes\":{}},{\"id\":\"h-media\",\"type\":\"header\",\"data\":{\"text\":\"Removable media is not a neutral pipe\",\"level\":2},\"tunes\":{}},{\"id\":\"p-media-1\",\"type\":\"paragraph\",\"data\":{\"text\":\"USB drives and other portable media can carry both legitimate model\u002Fdata artifacts and malicious content.\"},\"tunes\":{}},{\"id\":\"p-media-2\",\"type\":\"paragraph\",\"data\":{\"text\":\"NIST's media-sanitization guidance treats storage media as a confidentiality lifecycle object that may require clearing, purging or destruction according to sensitivity and reuse needs.\"},\"tunes\":{}},{\"id\":\"p-media-3\",\"type\":\"paragraph\",\"data\":{\"text\":\"The exact transfer procedure is organization-specific, but the architectural principle is stable: cross-boundary media should be governed as a security asset, not treated as an informal convenience.\"},\"tunes\":{}},{\"id\":\"h-supply\",\"type\":\"header\",\"data\":{\"text\":\"Air-gapping increases supply-chain importance\",\"level\":2},\"tunes\":{}},{\"id\":\"p-supply-1\",\"type\":\"paragraph\",\"data\":{\"text\":\"An isolated system receives fewer live external inputs, but every imported binary, model, container and package becomes more consequential because the enclave may trust it for a long time.\"},\"tunes\":{}},{\"id\":\"p-supply-2\",\"type\":\"paragraph\",\"data\":{\"text\":\"NIST software-supply-chain guidance emphasizes provenance, supplier risk, vulnerability management, software verification and SBOM-oriented practices. These concerns become directly relevant to offline AI artifact import.\"},\"tunes\":{}},{\"id\":\"p-supply-3\",\"type\":\"paragraph\",\"data\":{\"text\":\"Model supply chain deserves the same attention as application supply chain: model origin, license, hash, format, required code, tokenizer, adapters and evaluation status should be known before import.\"},\"tunes\":{}},{\"id\":\"h-readiness\",\"type\":\"header\",\"data\":{\"text\":\"Air-gap readiness should be tested, not assumed\",\"level\":2},\"tunes\":{}},{\"id\":\"readiness-note\",\"type\":\"callout\",\"data\":{\"variant\":\"note\",\"title\":\"Proposed validation pattern\",\"body\":\"The following air-gap-readiness test is an engineering synthesis, not a NIST or vendor certification method. It is designed to expose hidden external dependencies before deployment.\"},\"tunes\":{}},{\"id\":\"readiness-table\",\"type\":\"table\",\"data\":{\"withHeadings\":true,\"stretched\":false,\"content\":[[\"Test\",\"What it proves\"],[\"Cold start with all outbound network blocked\",\"Runtime does not require public services during startup\"],[\"Load every approved model from local storage\",\"Weights\u002Ftokenizers\u002Fconfigs are complete\"],[\"Rebuild\u002Fredeploy from internal registries only\",\"Container\u002Fpackage mirrors are sufficient\"],[\"Authenticate users while external IdP is unreachable\",\"Identity works inside the enclave\"],[\"Run RAG ingestion and query offline\",\"Embedding\u002Findexing\u002Fretrieval stack is local\"],[\"Run representative agent tools\",\"Tools do not depend on external APIs\"],[\"Restart after cache deletion\",\"Offline operation is not accidentally relying on previously cached downloads\"],[\"Advance simulated certificate\u002Fupdate lifecycle\",\"Trust and maintenance dependencies are understood\"],[\"Import a new model through staging path\",\"Transfer\u002Fchange procedure is operational\"],[\"Restore from backup\",\"Recovery does not require unavailable cloud storage\"]]},\"tunes\":{}},{\"id\":\"h-cache\",\"type\":\"header\",\"data\":{\"text\":\"Cached once is not the same as air-gap ready\",\"level\":2},\"tunes\":{}},{\"id\":\"p-cache-1\",\"type\":\"paragraph\",\"data\":{\"text\":\"A system may appear offline because the model and packages are already cached from earlier internet access.\"},\"tunes\":{}},{\"id\":\"p-cache-2\",\"type\":\"paragraph\",\"data\":{\"text\":\"Deleting caches or deploying to a clean node can reveal missing tokenizer files, Python packages, model manifests or remote-code dependencies.\"},\"tunes\":{}},{\"id\":\"p-cache-3\",\"type\":\"paragraph\",\"data\":{\"text\":\"Air-gap readiness should therefore be validated from clean internal artifacts, not only from a developer workstation that was previously connected.\"},\"tunes\":{}},{\"id\":\"h-threats\",\"type\":\"header\",\"data\":{\"text\":\"What threats remain inside an air gap?\",\"level\":2},\"tunes\":{}},{\"id\":\"threat-table\",\"type\":\"table\",\"data\":{\"withHeadings\":true,\"stretched\":false,\"content\":[[\"Threat\",\"Why the air gap does not remove it\"],[\"Compromised imported artifact\",\"Malware\u002Fmodel\u002Fpackage can enter through the authorized transfer path\"],[\"Malicious removable media\",\"Physical transfer can carry executable payloads\"],[\"Insider misuse\",\"Authorized users already exist inside the enclave\"],[\"Prompt injection in imported documents\",\"Untrusted content can influence RAG\u002Fagents without internet\"],[\"Overprivileged agent tools\",\"Local tools can still damage local systems\"],[\"Cross-tenant data leakage\",\"Internal authorization bugs remain possible\"],[\"Vulnerable internal software\",\"Lack of external connection does not remove exploitable bugs\"],[\"Lateral movement\",\"A compromised node can attack other internally connected nodes\"],[\"Stale dependencies\",\"Slow update cadence can leave known vulnerabilities unpatched\"],[\"Physical theft\u002Ftampering\",\"Hardware and media security remain critical\"],[\"Bad model behavior\",\"Hallucination, bias and task failure are independent of networking\"],[\"Supply-chain poisoning\",\"Trusted import sources can still be compromised\"]]},\"tunes\":{}},{\"id\":\"h-benefits\",\"type\":\"header\",\"data\":{\"text\":\"What an air gap actually improves\",\"level\":2},\"tunes\":{}},{\"id\":\"p-benefit-1\",\"type\":\"paragraph\",\"data\":{\"text\":\"A genuine air gap can materially reduce attack paths that depend on direct remote connectivity: external command-and-control, cloud credential misuse, internet-facing service exploitation and accidental data exfiltration through ordinary outbound APIs.\"},\"tunes\":{}},{\"id\":\"p-benefit-2\",\"type\":\"paragraph\",\"data\":{\"text\":\"It also makes data residency simple in one narrow sense: inference data cannot be sent to an external cloud service if no path exists.\"},\"tunes\":{}},{\"id\":\"p-benefit-3\",\"type\":\"paragraph\",\"data\":{\"text\":\"Those benefits are strongest when the transfer boundary and internal access controls are equally disciplined. A poorly managed USB process can undermine the intended isolation.\"},\"tunes\":{}},{\"id\":\"h-costs\",\"type\":\"header\",\"data\":{\"text\":\"What an air gap makes harder\",\"level\":2},\"tunes\":{}},{\"id\":\"cost-table\",\"type\":\"table\",\"data\":{\"withHeadings\":true,\"stretched\":false,\"content\":[[\"Area\",\"Operational consequence\"],[\"Model updates\",\"Manual\u002Fstaged transfer instead of direct model-hub pull\"],[\"Security patches\",\"Delayed and governed import workflow\"],[\"Package installation\",\"Internal mirrors or prebuilt artifacts required\"],[\"Cloud AI APIs\",\"Unavailable\"],[\"Web search\u002Fconnectors\",\"Unavailable unless data is imported separately\"],[\"Authentication\",\"Needs internal\u002Foffline-capable identity services\"],[\"Monitoring\",\"Needs internal observability and controlled export\"],[\"Licensing\",\"Products requiring online activation may be unsuitable\"],[\"Troubleshooting\",\"No easy live access to vendor resources from production enclave\"],[\"Capacity\",\"All inference compute must exist locally\"],[\"Disaster recovery\",\"Cloud backups may be unavailable or policy-restricted\"],[\"Knowledge freshness\",\"External information arrives only as fast as the import process\"]]},\"tunes\":{}},{\"id\":\"h-private\",\"type\":\"header\",\"data\":{\"text\":\"Air-gapped AI vs private AI\",\"level\":2},\"tunes\":{}},{\"id\":\"p-private-1\",\"type\":\"paragraph\",\"data\":{\"text\":\"Private AI is primarily about controlling sensitive data and AI processing. A private AI platform may be on-premises and still access approved cloud models or external services.\"},\"tunes\":{}},{\"id\":\"p-private-2\",\"type\":\"paragraph\",\"data\":{\"text\":\"Air-gapped AI is stricter on connectivity. A system can be private without being air-gapped, and an air-gapped system can still have poor privacy if every internal user has unrestricted access.\"},\"tunes\":{}},{\"id\":\"p-private-3\",\"type\":\"paragraph\",\"data\":{\"text\":\"The security objective should determine the architecture: confidentiality, sovereignty, resilience and isolation are related but distinct requirements.\"},\"tunes\":{}},{\"id\":\"h-sovereign\",\"type\":\"header\",\"data\":{\"text\":\"Air-gapped AI vs sovereign AI\",\"level\":2},\"tunes\":{}},{\"id\":\"p-sovereign-1\",\"type\":\"paragraph\",\"data\":{\"text\":\"Sovereign AI concerns control over the broader dependency chain: data, models, infrastructure, operators, jurisdiction and strategic dependencies.\"},\"tunes\":{}},{\"id\":\"p-sovereign-2\",\"type\":\"paragraph\",\"data\":{\"text\":\"An air gap can support sovereignty by reducing external runtime dependency, but it does not guarantee sovereign control. The enclave may still depend on foreign hardware, proprietary model licenses or external update suppliers.\"},\"tunes\":{}},{\"id\":\"p-sovereign-3\",\"type\":\"paragraph\",\"data\":{\"text\":\"The next canonical article separates those control dimensions explicitly.\"},\"tunes\":{}},{\"id\":\"h-implementation\",\"type\":\"header\",\"data\":{\"text\":\"Original implementation evidence: what the Aaasaasa AI Client proves — and what it does not\",\"level\":2},\"tunes\":{}},{\"id\":\"impl-note\",\"type\":\"callout\",\"data\":{\"variant\":\"note\",\"title\":\"Implementation boundary\",\"body\":\"Aaasaasa AI Client is useful evidence for \u003Cstrong>local inference architecture\u003C\u002Fstrong>, provider abstraction and separation of runtime\u002Fmodel location. It is \u003Cstrong>not evidence of a deployed air-gapped environment\u003C\u002Fstrong>. The repository also supports cloud and remote paths, and no verified project evidence establishes a physically isolated security domain.\"},\"tunes\":{}},{\"id\":\"p-impl-1\",\"type\":\"paragraph\",\"data\":{\"text\":\"The AI Hub separates agent\u002Fclient, provider, model and connection location. It supports local Ollama inference and local-provider Codex operation as distinct choices rather than assuming that every AI request goes to a cloud model.\"},\"tunes\":{}},{\"id\":\"p-impl-2\",\"type\":\"paragraph\",\"data\":{\"text\":\"The repository explicitly notes that a local runtime can still use a cloud model, while Direct Ollama chat is local inference. This distinction is directly relevant to air-gap architecture: local execution does not prove that the model or surrounding dependencies are disconnected.\"},\"tunes\":{}},{\"id\":\"p-impl-3\",\"type\":\"paragraph\",\"data\":{\"text\":\"Provider abstraction, local model discovery and local inference are therefore building blocks for an air-gap-capable product architecture, but the network boundary, offline dependency mirror, controlled transfer process and offline identity\u002Foperations must still be engineered separately.\"},\"tunes\":{}},{\"id\":\"impl-table\",\"type\":\"table\",\"data\":{\"withHeadings\":true,\"stretched\":false,\"content\":[[\"Verified project capability\",\"Air-gap relevance\"],[\"Local Ollama inference\",\"Supports local model execution\"],[\"Local provider\u002Fruntime paths\",\"Reduces dependency on cloud inference\"],[\"Provider\u002Fmodel\u002Fruntime separation\",\"Makes cloud dependencies explicit rather than hidden\"],[\"Central permissions\",\"Supports local tool\u002Fdata access control\"],[\"Cloud\u002Fremote provider support also exists\",\"Proves the product itself is hybrid-capable, not inherently air-gapped\"],[\"No verified isolated deployment boundary\",\"Prevents overclaiming air-gap maturity\"]]},\"tunes\":{}},{\"id\":\"h-when\",\"type\":\"header\",\"data\":{\"text\":\"When is air-gapped AI justified?\",\"level\":2},\"tunes\":{}},{\"id\":\"when-table\",\"type\":\"table\",\"data\":{\"withHeadings\":true,\"stretched\":false,\"content\":[[\"Air gap may be justified when\",\"A connected private architecture may be better when\"],[\"Security policy explicitly requires physically separated domains\",\"Main requirement is only that prompts\u002Fdata are not used by public consumer services\"],[\"Classified or extremely sensitive data cannot cross external networks\",\"Approved enterprise cloud\u002Fprivate endpoints satisfy data controls\"],[\"Operational environment has no reliable external connectivity\",\"Internet is available and operational agility matters\"],[\"Mission continuity must not depend on cloud\u002Fprovider availability\",\"Managed model quality and rapid upgrades are more valuable\"],[\"Regulated\u002Fcritical environment mandates controlled transfer\",\"Standard security controls can meet the actual threat model\"],[\"External SaaS\u002FAPI access is prohibited\",\"Business workflow relies heavily on external connectors\"]]},\"tunes\":{}},{\"id\":\"p-when-1\",\"type\":\"paragraph\",\"data\":{\"text\":\"Air-gapping should be a requirement derived from a threat model or policy, not a prestige feature. It has real security value when the eliminated connectivity path is itself unacceptable.\"},\"tunes\":{}},{\"id\":\"p-when-2\",\"type\":\"paragraph\",\"data\":{\"text\":\"For many enterprise use cases, a tightly controlled private network with egress restrictions, local inference and approved update channels may provide a better balance of security and maintainability than a strict physical air gap.\"},\"tunes\":{}},{\"id\":\"h-design\",\"type\":\"header\",\"data\":{\"text\":\"A practical air-gapped AI design sequence\",\"level\":2},\"tunes\":{}},{\"id\":\"design-flow\",\"type\":\"processFlow\",\"data\":{\"title\":\"Design from the boundary inward\",\"orientation\":\"auto\",\"steps\":[{\"label\":\"1. Define what the air gap separates\",\"description\":\"Name the security domains and whether the requirement is strict physical separation or simply no internet.\"},{\"label\":\"2. Inventory every external dependency\",\"description\":\"Models, packages, registries, identity, telemetry, licensing, storage, APIs, DNS\u002Ftime and support services.\"},{\"label\":\"3. Select offline-capable models and runtimes\",\"description\":\"Verify model assets and runtime code can load without remote calls.\"},{\"label\":\"4. Build internal artifact repositories\",\"description\":\"Create trusted sources for containers, packages, models and updates.\"},{\"label\":\"5. Design controlled transfer\",\"description\":\"Define staging, verification, media\u002Fgateway handling, approval and provenance.\"},{\"label\":\"6. Build internal identity and authorization\",\"description\":\"Ensure users, services and tools can authenticate without cloud dependencies.\"},{\"label\":\"7. Keep RAG and tools local\",\"description\":\"Deploy knowledge, embeddings, indexes and required service APIs inside the enclave.\"},{\"label\":\"8. Build internal observability\",\"description\":\"Operate logs, metrics, traces and security monitoring locally.\"},{\"label\":\"9. Define patch\u002Fmodel update cadence\",\"description\":\"Balance vulnerability response with the controlled import process.\"},{\"label\":\"10. Test from a clean disconnected state\",\"description\":\"Cold-start and operate without inherited caches or hidden internet access.\"},{\"label\":\"11. Test compromise paths\",\"description\":\"Exercise removable-media, supply-chain, prompt-injection, insider and lateral-movement scenarios.\"},{\"label\":\"12. Document exceptions and exports\",\"description\":\"Every permitted cross-boundary path should have a named purpose, owner and control set.\"}]},\"tunes\":{}},{\"id\":\"h-checklist\",\"type\":\"header\",\"data\":{\"text\":\"Air-gapped AI architecture checklist\",\"level\":2},\"tunes\":{}},{\"id\":\"checklist-table\",\"type\":\"table\",\"data\":{\"withHeadings\":true,\"stretched\":false,\"content\":[[\"Question\",\"Expected evidence\"],[\"What exactly is isolated from what?\",\"Documented security-domain boundary\"],[\"Is the boundary physically disconnected?\",\"Network\u002Fphysical architecture evidence if strict air gap is claimed\"],[\"How does data cross the boundary?\",\"Authorized non-automated\u002Fmanual or explicitly documented disconnected workflow\"],[\"Can every model cold-start offline?\",\"Offline loading test\"],[\"Are tokenizer\u002Fconfig\u002Fruntime assets complete?\",\"Verified internal model bundle\"],[\"Where do containers\u002Fpackages come from?\",\"Internal trusted mirror\u002Frepository\"],[\"Can identity work without cloud services?\",\"Internal IdP\u002FPKI\u002Fservice credential path\"],[\"Can RAG ingest\u002Fquery offline?\",\"Local ingestion, embeddings, index and retrieval\"],[\"Which agent tools remain available?\",\"Internal capability inventory\"],[\"How are patches imported?\",\"Controlled maintenance process\"],[\"How are artifacts verified?\",\"Integrity\u002Fprovenance\u002Fmalware\u002Fsupply-chain controls\"],[\"How is removable media governed?\",\"Media handling and sanitization policy\"],[\"Can the system run after caches are cleared?\",\"Clean-environment offline test\"],[\"Where are logs and traces stored?\",\"Internal observability platform\"],[\"How are exports approved?\",\"Controlled egress process\"],[\"What proves this is air-gapped rather than merely local?\",\"Boundary and transfer evidence, not model location\"]]},\"tunes\":{}},{\"id\":\"h-failures\",\"type\":\"header\",\"data\":{\"text\":\"Common air-gapped AI failure modes\",\"level\":2},\"tunes\":{}},{\"id\":\"failure-table\",\"type\":\"table\",\"data\":{\"withHeadings\":true,\"stretched\":false,\"content\":[[\"Failure mode\",\"What actually failed\"],[\"Local model still downloads tokenizer\u002Fconfig at startup\",\"Model bundle was incomplete\"],[\"Container references public registry\",\"Deployment was not self-contained\"],[\"Cloud identity required for login\",\"Application was local but identity was not\"],[\"License server required externally\",\"Vendor dependency contradicted offline operation\"],[\"Embedding model missing\",\"Chat works but RAG ingestion fails\"],[\"Agent tool calls public SaaS\",\"Agent architecture was not air-gap compatible\"],[\"Only GPU node is isolated\",\"Database, UI or monitoring still depends on external services\"],[\"USB imports are informal\",\"Transfer boundary becomes uncontrolled attack path\"],[\"No patch process\",\"Isolation creates growing vulnerability debt\"],[\"Cached developer machine used as proof\",\"Fresh deployment fails without internet\"],[\"Air gap replaces authorization thinking\",\"Internal users\u002Fservices become overprivileged\"],[\"Air-gapped label used for firewall-only egress block\",\"Security documentation overstates the actual boundary\"]]},\"tunes\":{}},{\"id\":\"h-misconceptions\",\"type\":\"header\",\"data\":{\"text\":\"Common misconceptions\",\"level\":2},\"tunes\":{}},{\"id\":\"misconceptions-table\",\"type\":\"table\",\"data\":{\"withHeadings\":true,\"stretched\":false,\"content\":[[\"Misconception\",\"Correction\"],[\"“Local AI is air-gapped AI.”\",\"Local describes where inference runs; air gap describes the security\u002Fnetwork boundary.\"],[\"“Air-gapped means one standalone PC.”\",\"An isolated enclave can contain an entire internal network or cluster.\"],[\"“No internet equals strict air gap.”\",\"Under NIST's definition, the separated systems also lack physical connection and cross-boundary transfer is non-automated.\"],[\"“Air gaps eliminate cyber risk.”\",\"Supply-chain, removable-media, insider, internal-network and application risks remain.\"],[\"“RAG needs the cloud.”\",\"RAG can run entirely with local models, indexes and data.\"],[\"“Agents cannot work offline.”\",\"Agents can use internal\u002Flocal tools; they simply cannot reach unavailable external services.\"],[\"“Once installed, the system needs no updates.”\",\"Patches, drivers, models and dependencies still require lifecycle management.\"],[\"“A downloaded model is self-contained.”\",\"Tokenizers, remote code, libraries or model assets may still trigger network dependencies.\"],[\"“Private AI and air-gapped AI are identical.”\",\"Private AI is a data\u002Fcontrol property; air gap is a connectivity property.\"],[\"“Air gap guarantees sovereignty.”\",\"External hardware, licenses, models and supply chain can remain dependencies.\"]]},\"tunes\":{}},{\"id\":\"h-limitations\",\"type\":\"header\",\"data\":{\"text\":\"Limitations\",\"level\":2},\"tunes\":{}},{\"id\":\"p-limit-1\",\"type\":\"paragraph\",\"data\":{\"text\":\"Strict air gaps make external knowledge freshness slower because every new source must pass through a transfer process.\"},\"tunes\":{}},{\"id\":\"p-limit-2\",\"type\":\"paragraph\",\"data\":{\"text\":\"They can constrain model choice when licenses, remote-code requirements, hardware needs or provider-only APIs cannot be satisfied offline.\"},\"tunes\":{}},{\"id\":\"p-limit-3\",\"type\":\"paragraph\",\"data\":{\"text\":\"They increase operational cost because infrastructure normally consumed as cloud services must be owned and maintained internally.\"},\"tunes\":{}},{\"id\":\"p-limit-4\",\"type\":\"paragraph\",\"data\":{\"text\":\"They can also create patch latency: stronger change control may keep systems stable while delaying urgent vulnerability remediation.\"},\"tunes\":{}},{\"id\":\"p-limit-5\",\"type\":\"paragraph\",\"data\":{\"text\":\"Air-gapped AI should therefore be evaluated as one security architecture among several, not assumed to be universally superior.\"},\"tunes\":{}},{\"id\":\"h-change\",\"type\":\"header\",\"data\":{\"text\":\"What would change this answer?\",\"level\":2},\"tunes\":{}},{\"id\":\"p-change-1\",\"type\":\"paragraph\",\"data\":{\"text\":\"Vendor support for disconnected operation changes quickly. New model formats, signed OCI artifacts, offline license mechanisms and integrated model registries can reduce operational friction.\"},\"tunes\":{}},{\"id\":\"p-change-2\",\"type\":\"paragraph\",\"data\":{\"text\":\"The distinction between strict air gap and disconnected deployment will remain important even if vendors continue using the terms loosely.\"},\"tunes\":{}},{\"id\":\"p-change-3\",\"type\":\"paragraph\",\"data\":{\"text\":\"The stable principle is that genuine air-gap claims depend on the system boundary and transfer mechanism, not on whether the LLM happens to run locally.\"},\"tunes\":{}},{\"id\":\"h-related\",\"type\":\"header\",\"data\":{\"text\":\"Related canonical knowledge\",\"level\":2},\"tunes\":{}},{\"id\":\"p-related-1\",\"type\":\"paragraph\",\"data\":{\"text\":\"Air-Gapped AI is a deployment\u002Fsecurity architecture node. Private AI, Sovereign AI and provider abstraction answer different questions about confidentiality, control and dependency.\"},\"tunes\":{}},{\"id\":\"p-related-2\",\"type\":\"paragraph\",\"data\":{\"text\":\"MLOps\u002FLLMOps becomes more demanding inside a disconnected environment because model, package and update lifecycles must operate through internal repositories and controlled transfer.\"},\"tunes\":{}},{\"id\":\"p-related-3\",\"type\":\"paragraph\",\"data\":{\"text\":\"RAG and Agentic AI remain valid patterns inside the enclave as long as their data and tools are internally available.\"},\"tunes\":{}},{\"id\":\"ref-memory\",\"type\":\"referralArticle\",\"data\":{\"url\":\"https:\u002F\u002Fstajic.de\u002Fblog\u002Fai-agent-memory-is-not-rag-how-to-separate-memory-retrieval-state-and-context\",\"title\":\"AI Agent Memory Is Not RAG: How to Separate Memory, Retrieval, State and Context\",\"excerpt\":\"Air-gapped AI still needs correct internal boundaries between durable memory, authoritative state, retrieval and model context.\",\"ctaLabel\":\"Read the memory architecture article\"},\"tunes\":{}},{\"id\":\"h-faq\",\"type\":\"header\",\"data\":{\"text\":\"Frequently asked questions\",\"level\":2},\"tunes\":{}},{\"id\":\"faq\",\"type\":\"faq\",\"data\":{\"title\":\"Air-gapped AI FAQ\",\"items\":[{\"id\":\"faq1\",\"question\":\"What is air-gapped AI?\",\"answer\":\"Air-gapped AI is AI deployed inside a security domain physically disconnected from the external systems it is separated from, with cross-boundary transfer performed through controlled non-automated procedures under the strict NIST definition.\"},{\"id\":\"faq2\",\"question\":\"Does air-gapped AI need internet access?\",\"answer\":\"No for normal inference and operation. Required models, packages, data and services must be available inside the isolated environment.\"},{\"id\":\"faq3\",\"question\":\"Is a local LLM automatically air-gapped?\",\"answer\":\"No. A local model can run on a machine that still has internet access or uses cloud identity, tools or storage. Air gap describes the complete system boundary.\"},{\"id\":\"faq4\",\"question\":\"Can RAG work in an air-gapped network?\",\"answer\":\"Yes. Documents, embedding models, vector or lexical indexes, rerankers and generation models can all run locally. External knowledge must be imported through the controlled boundary.\"},{\"id\":\"faq5\",\"question\":\"Can AI agents work air-gapped?\",\"answer\":\"Yes, if their tools and required systems are available inside the isolated network. Public SaaS and cloud APIs are unavailable without a permitted cross-boundary mechanism.\"},{\"id\":\"faq6\",\"question\":\"How are models updated in an air-gapped environment?\",\"answer\":\"Models are typically acquired and validated in a connected staging environment, transferred through an approved process and published to an internal model\u002Fartifact repository.\"},{\"id\":\"faq7\",\"question\":\"Is on-premises AI the same as air-gapped AI?\",\"answer\":\"No. On-premises describes infrastructure location. On-prem systems can remain internet-connected.\"},{\"id\":\"faq8\",\"question\":\"Is private AI the same as air-gapped AI?\",\"answer\":\"No. Private AI is about data\u002Fcontrol requirements and can still use connected infrastructure. Air gap specifically describes network\u002Fdomain separation.\"},{\"id\":\"faq9\",\"question\":\"Does an air gap make AI secure?\",\"answer\":\"It removes or reduces some remote connectivity risks but does not remove supply-chain, removable-media, insider, internal authorization, physical or model-behavior risks.\"},{\"id\":\"faq10\",\"question\":\"What is the best test for air-gap readiness?\",\"answer\":\"Deploy or cold-start the full stack in a clean environment with all external connectivity unavailable and verify that models, identity, RAG, tools, monitoring, updates and recovery depend only on approved internal artifacts and services.\"}]},\"tunes\":{}},{\"id\":\"h-glossary\",\"type\":\"header\",\"data\":{\"text\":\"Glossary\",\"level\":2},\"tunes\":{}},{\"id\":\"glossary\",\"type\":\"glossary\",\"data\":{\"title\":\"Key air-gapped AI terms\",\"entries\":[{\"term\":\"Air gap\",\"definition\":\"Security-domain interface where systems are not physically connected and any cross-boundary logical transfer is non-automated\u002Fmanual under the NIST glossary definition.\",\"anchor\":\"air-gap\"},{\"term\":\"Air-gapped AI\",\"definition\":\"AI system deployed inside an air-gapped security domain with locally available inference and operational dependencies.\",\"anchor\":\"air-gapped-ai\"},{\"term\":\"Disconnected environment\",\"definition\":\"Deployment environment without direct outside-internet access; implementations may use controlled mirror or bastion workflows.\",\"anchor\":\"disconnected-environment\"},{\"term\":\"Offline-capable AI\",\"definition\":\"AI application able to operate for some or all functions without internet connectivity, without necessarily being permanently isolated.\",\"anchor\":\"offline-capable-ai\"},{\"term\":\"Local AI\",\"definition\":\"AI inference or runtime executing on local hardware rather than a remote model endpoint; does not imply network isolation.\",\"anchor\":\"local-ai\"},{\"term\":\"Mirror registry\",\"definition\":\"Internal repository containing approved copies of container images or other artifacts needed by a disconnected deployment.\",\"anchor\":\"mirror-registry\"},{\"term\":\"Staging environment\",\"definition\":\"Connected or controlled zone where artifacts are acquired, verified and prepared before transfer into an isolated domain.\",\"anchor\":\"staging-environment\"},{\"term\":\"Controlled transfer\",\"definition\":\"Governed movement of data or software across the isolation boundary using approved media\u002Fprocesses and verification.\",\"anchor\":\"controlled-transfer\"},{\"term\":\"Artifact provenance\",\"definition\":\"Information showing where a model, package, container or other imported artifact originated and how it was produced or verified.\",\"anchor\":\"artifact-provenance\"},{\"term\":\"Removable media\",\"definition\":\"Portable storage used to transfer data between systems; a potential security path across disconnected domains.\",\"anchor\":\"removable-media\"},{\"term\":\"Internal model store\",\"definition\":\"Repository inside the isolated environment from which approved model artifacts are served or deployed.\",\"anchor\":\"internal-model-store\"},{\"term\":\"Air-gap readiness\",\"definition\":\"Demonstrated ability of the complete AI stack to install, start, operate, update and recover without unapproved external connectivity.\",\"anchor\":\"air-gap-readiness\"}]},\"tunes\":{}},{\"id\":\"h-conclusion\",\"type\":\"header\",\"data\":{\"text\":\"Conclusion\",\"level\":2},\"tunes\":{}},{\"id\":\"p-conclusion-1\",\"type\":\"paragraph\",\"data\":{\"text\":\"Air-gapped AI is not a special kind of model. It is an AI architecture operating inside a deliberately isolated security domain.\"},\"tunes\":{}},{\"id\":\"p-conclusion-2\",\"type\":\"paragraph\",\"data\":{\"text\":\"The model can be the easy part. Production readiness depends on whether every surrounding dependency — model assets, packages, registries, identity, RAG, tools, monitoring, updates and recovery — can function without an automated external path.\"},\"tunes\":{}},{\"id\":\"p-conclusion-3\",\"type\":\"paragraph\",\"data\":{\"text\":\"The shortest reliable rule is: local inference proves where the model runs; air-gap evidence proves how the complete system is separated and how every permitted transfer crosses that boundary.\"},\"tunes\":{}},{\"id\":\"h-sources\",\"type\":\"header\",\"data\":{\"text\":\"Primary sources and current implementation references\",\"level\":2},\"tunes\":{}},{\"id\":\"p-sources-note\",\"type\":\"paragraph\",\"data\":{\"text\":\"The sources below establish the security definition, current disconnected AI deployment patterns and lifecycle risks. Vendor use of “air-gapped” is intentionally distinguished from the stricter NIST definition.\"},\"tunes\":{}},{\"id\":\"src-nist-airgap\",\"type\":\"linkTool\",\"data\":{\"link\":\"https:\u002F\u002Fcsrc.nist.gov\u002Fglossary\u002Fterm\u002Fair_gap\",\"meta\":{\"image\":{\"url\":\"\"},\"title\":\"NIST CSRC — Air gap\",\"description\":\"NIST glossary definition: physically disconnected systems with non-automated, manually controlled logical transfer across the boundary.\"}},\"tunes\":{}},{\"id\":\"src-nvidia-airgap\",\"type\":\"linkTool\",\"data\":{\"link\":\"https:\u002F\u002Fdocs.nvidia.com\u002Fnim\u002Flarge-language-models\u002Flatest\u002Fdeploy-air-gap.html\",\"meta\":{\"image\":{\"url\":\"\"},\"title\":\"NVIDIA NIM — Air-Gap Deployment\",\"description\":\"Current operational guidance for staging model assets on a connected system and running NIM from local storage without internet, public registries or cloud API keys.\"}},\"tunes\":{}},{\"id\":\"src-redhat-disconnected\",\"type\":\"linkTool\",\"data\":{\"link\":\"https:\u002F\u002Fdocs.redhat.com\u002Fen\u002Fdocumentation\u002Fred_hat_ai_inference\u002F3.5\u002Fhtml\u002Fdeploy_the_standalone_red_hat_ai_inference_container_in_a_disconnected_environment\u002Findex\",\"meta\":{\"image\":{\"url\":\"\"},\"title\":\"Red Hat AI Inference — Disconnected deployment\",\"description\":\"Current Red Hat guidance for serving LLMs in disconnected environments with mirrored artifacts and internal infrastructure.\"}},\"tunes\":{}},{\"id\":\"src-redhat-models\",\"type\":\"linkTool\",\"data\":{\"link\":\"https:\u002F\u002Fdocs.redhat.com\u002Fen\u002Fdocumentation\u002Fred_hat_ai_inference\u002F3.5\u002Fhtml\u002Fdeploy_the_standalone_red_hat_ai_inference_container_in_a_disconnected_environment\u002Fstoring-models-in-disconnected-environments_disconnected-deploy\",\"meta\":{\"image\":{\"url\":\"\"},\"title\":\"Red Hat AI Inference — Storing models in disconnected environments\",\"description\":\"Current guidance covering OCI model images, persistent model storage and limitations of models requiring remote code.\"}},\"tunes\":{}},{\"id\":\"src-nsa-framework\",\"type\":\"linkTool\",\"data\":{\"link\":\"https:\u002F\u002Fwww.nsa.gov\u002Fportals\u002F75\u002Fdocuments\u002Fwhat-we-do\u002Fcybersecurity\u002Fprofessional-resources\u002Fctr-nsa-css-technical-cyber-threat-framework.pdf\",\"meta\":{\"image\":{\"url\":\"\"},\"title\":\"NSA — Technical Cyber Threat Framework\",\"description\":\"Threat framework explicitly identifying removable-media replication as a path into disconnected or air-gapped networks.\"}},\"tunes\":{}},{\"id\":\"src-nist-media\",\"type\":\"linkTool\",\"data\":{\"link\":\"https:\u002F\u002Fwww.nist.gov\u002Fpublications\u002Fguidelines-media-sanitization\",\"meta\":{\"image\":{\"url\":\"\"},\"title\":\"NIST SP 800-88 Rev. 1 — Guidelines for Media Sanitization\",\"description\":\"Guidance for managing and sanitizing storage media according to information confidentiality requirements.\"}},\"tunes\":{}},{\"id\":\"src-nist-patch\",\"type\":\"linkTool\",\"data\":{\"link\":\"https:\u002F\u002Fcsrc.nist.gov\u002Fpubs\u002Fsp\u002F800\u002F40\u002Fr4\u002Ffinal\",\"meta\":{\"image\":{\"url\":\"\"},\"title\":\"NIST SP 800-40 Rev. 4 — Enterprise Patch Management Planning\",\"description\":\"Guidance framing patching and updates as preventive maintenance across enterprise systems.\"}},\"tunes\":{}},{\"id\":\"src-nist-supply\",\"type\":\"linkTool\",\"data\":{\"link\":\"https:\u002F\u002Fwww.nist.gov\u002Fitl\u002Fexecutive-order-14028-improving-nations-cybersecurity\u002Fsoftware-security-supply-chains\",\"meta\":{\"image\":{\"url\":\"\"},\"title\":\"NIST — Software Security in Supply Chains\",\"description\":\"NIST guidance covering software supply-chain risk, provenance, verification, SBOM-related practices and vulnerability management.\"}},\"tunes\":{}}],\"version\":\"2.31.6\"}",{"time":1728,"blocks":1729,"version":2980},1791495428517,[1730,1734,1739,1744,1749,1754,1758,1762,1766,1770,1774,1778,1782,1786,1790,1794,1823,1827,1831,1835,1839,1843,1879,1883,1887,1891,1916,1921,1925,1962,1966,1970,1974,1978,1982,1986,1990,1994,1998,2002,2006,2010,2014,2018,2022,2059,2063,2067,2071,2075,2079,2083,2087,2091,2095,2102,2106,2110,2114,2118,2122,2126,2130,2134,2138,2142,2146,2150,2154,2158,2162,2166,2170,2174,2178,2182,2186,2190,2194,2198,2202,2231,2235,2239,2243,2247,2251,2255,2259,2263,2267,2271,2275,2279,2283,2288,2325,2329,2333,2337,2341,2345,2388,2392,2396,2400,2404,2408,2450,2454,2458,2462,2466,2470,2474,2478,2482,2486,2491,2495,2499,2503,2528,2532,2557,2561,2565,2569,2610,2614,2669,2673,2716,2720,2757,2761,2765,2769,2773,2777,2781,2785,2789,2793,2797,2801,2805,2809,2813,2820,2824,2859,2863,2900,2904,2908,2912,2916,2920,2924,2931,2938,2945,2952,2959,2966,2973],{"id":215,"data":1731,"type":218,"tunes":1733},{"text":1732},"Air-gapped AI is an AI system deployed inside a security domain that has no physical network connection to the external systems it is separated from, with any transfer across that boundary performed through deliberately controlled, non-automated procedures. The AI model, runtime, data, retrieval indexes, tools and operational dependencies required for inference must therefore be available inside the isolated environment. Air-gapped AI is not simply “a local model” or “an on-premise server”: the defining property is the network and transfer boundary around the complete system.",{},{"id":221,"data":1735,"type":226,"tunes":1738},{"body":1736,"title":1737,"variant":225},"An air-gapped AI system can run LLM inference, RAG, document analysis and even agentic workflows without internet or cloud APIs if every required dependency is available inside the isolated domain.\u003Cbr>\u003Cbr>A practical architecture is:\u003Cbr>\u003Cstrong>controlled import → internal artifact\u002Fmodel repositories → local AI runtime → local data\u002FRAG → local tools → internal users\u002Fservices → local monitoring\u002Faudit\u003C\u002Fstrong>.\u003Cbr>\u003Cbr>The difficult part is not making one LLM answer offline. It is operating the whole AI lifecycle — updates, models, drivers, packages, data imports, credentials, logging and security — without silently depending on external services.","Direct answer",{},{"id":229,"data":1740,"type":226,"tunes":1743},{"body":1741,"title":1742,"variant":233},"NIST's cybersecurity glossary defines an air gap as an interface where two systems are \u003Cstrong>not physically connected\u003C\u002Fstrong> and where any logical transfer is \u003Cstrong>not automated\u003C\u002Fstrong>; data crosses only manually under human control. Vendor documentation sometimes uses “air-gapped” or “disconnected” more broadly for environments with no outside-internet connection but with internal networking and controlled staging infrastructure. Architecture documentation should state which meaning is actually implemented.","Air gap has a stricter meaning than “no internet”",{},{"id":236,"data":1745,"type":226,"tunes":1748},{"body":1746,"title":1747,"variant":233},"Removing direct network connectivity eliminates many remote paths, but it does not eliminate malicious removable media, compromised software\u002Fmodel imports, insider threats, vulnerable internal services, physical compromise, prompt injection through imported documents or lateral movement inside the isolated network.","Air-gapped does not mean secure by definition",{},{"id":242,"data":1750,"type":226,"tunes":1753},{"body":1751,"title":1752,"variant":246},"Current NVIDIA NIM and Red Hat AI Inference documentation both support LLM serving without outside-internet access by pre-staging model and container assets. NVIDIA documents a connected preparation phase followed by an isolated execution phase with local assets and no cloud registry credentials. Red Hat uses mirrored container\u002Fmodel repositories for disconnected OpenShift environments. These are useful implementation examples, but they do not override the stricter NIST definition of an air gap.","Current-source note — 8 October 2026",{},{"id":249,"data":1755,"type":254,"tunes":1757},{"title":1756,"maxLevel":252,"minLevel":253},"Contents",{},{"id":257,"data":1759,"type":42,"tunes":1761},{"text":1760,"level":253},"What air-gapped AI really means",{},{"id":262,"data":1763,"type":218,"tunes":1765},{"text":1764},"The word AI does not change the basic security concept. An air gap is a boundary between security domains. AI simply makes the isolated side more operationally demanding because modern AI stacks normally assume downloadable models, package registries, telemetry, APIs, model hubs and frequent software updates.",{},{"id":267,"data":1767,"type":218,"tunes":1769},{"text":1768},"The isolated environment can still contain many connected machines. An internal cluster may have GPUs, application servers, storage, databases, identity services and monitoring connected to each other. The air gap exists between that enclave and the outside domain.",{},{"id":272,"data":1771,"type":218,"tunes":1773},{"text":1772},"The relevant question is therefore not “Does this GPU have Wi-Fi?” but “Can this AI environment exchange information with the external domain through an automated physical or logical path?”",{},{"id":277,"data":1775,"type":42,"tunes":1777},{"text":1776,"level":253},"The simplest example",{},{"id":282,"data":1779,"type":218,"tunes":1781},{"text":1780},"Imagine a company wants an internal assistant for confidential technical documents, but the environment is not permitted to send those documents to the internet.",{},{"id":287,"data":1783,"type":218,"tunes":1785},{"text":1784},"The company downloads an approved LLM, embedding model, container images and software packages in a connected staging environment. After validation, approved artifacts are transferred into the isolated environment.",{},{"id":292,"data":1787,"type":218,"tunes":1789},{"text":1788},"Inside the enclave, the model server, document parser, vector database, application and identity services run locally. Users can ask questions and use RAG against internal documents without a cloud model or public model registry.",{},{"id":297,"data":1791,"type":218,"tunes":1793},{"text":1792},"When an update is required, the update passes through the controlled import process again rather than being downloaded directly by the production AI server.",{},{"id":302,"data":1795,"type":331,"tunes":1822},{"steps":1796,"title":1821,"orientation":330},[1797,1800,1803,1806,1809,1812,1815,1818],{"label":1798,"description":1799},"1. Acquire outside the enclave","Download approved models, packages, containers, drivers, signatures and documentation in a connected staging environment.",{"label":1801,"description":1802},"2. Verify before transfer","Check provenance, signatures\u002Fchecksums, malware status, licensing and compatibility according to organizational policy.",{"label":1804,"description":1805},"3. Transfer through controlled boundary","Move approved artifacts using the authorized manual or mediated process.",{"label":1807,"description":1808},"4. Publish internally","Place artifacts in internal model, container, package or file repositories.",{"label":1810,"description":1811},"5. Deploy locally","Run inference, RAG, applications and tools without external dependencies.",{"label":1813,"description":1814},"6. Monitor inside the enclave","Collect logs, metrics, model\u002Fruntime status and security events locally.",{"label":1816,"description":1817},"7. Export only approved evidence","Move selected reports or artifacts outward through the reverse controlled process where policy permits.",{"label":1819,"description":1820},"8. Repeat for updates","Treat new models, patches, corpora and dependencies as new supply-chain imports.","A basic air-gapped AI operating cycle",{},{"id":334,"data":1824,"type":42,"tunes":1826},{"text":1825,"level":253},"Where the simple example stops",{},{"id":339,"data":1828,"type":218,"tunes":1830},{"text":1829},"A production air-gapped environment can be much larger than one workstation. It may include Kubernetes\u002FOpenShift, internal registries, object storage, identity providers, vector databases, observability, backup infrastructure and several model-serving nodes.",{},{"id":344,"data":1832,"type":218,"tunes":1834},{"text":1833},"The more services exist inside the enclave, the more the organization must reproduce capabilities that connected environments normally consume from the internet.",{},{"id":349,"data":1836,"type":218,"tunes":1838},{"text":1837},"Air-gapping therefore shifts complexity. It reduces direct external connectivity but increases artifact-management, patching, dependency, supply-chain and operational responsibility inside the isolated domain.",{},{"id":354,"data":1840,"type":42,"tunes":1842},{"text":1841,"level":253},"Air-gapped vs offline vs local vs on-premises vs private vs sovereign AI",{},{"id":359,"data":1844,"type":394,"tunes":1878},{"content":1845,"stretched":43,"withHeadings":14},[1846,1850,1854,1858,1862,1866,1870,1874],[1847,1848,1849],"Term","What it primarily describes","Internet\u002Fexternal connectivity required?",[1851,1852,1853],"Local AI","Inference\u002Fruntime runs on local hardware","No; but it may still call cloud services",[1855,1856,1857],"Offline-capable AI","Can continue operating without internet","No during offline operation; reconnection may be normal",[1859,1860,1861],"Disconnected environment","No direct external-internet path from deployment environment","Usually no; may use controlled mirrors\u002Fbastions",[1863,1864,1865],"On-premises AI","Infrastructure runs in an organization's own\u002Fon-prem environment","Could still have full internet connectivity",[1867,1868,1869],"Private AI","AI processing is controlled to meet privacy\u002Fconfidentiality requirements","Architecture-specific; can be connected or disconnected",[1871,1872,1873],"Air-gapped AI","Security domains are physically disconnected and cross-boundary transfer is non-automated\u002Fmanual under strict definition","No automated external path",[1875,1876,1877],"Sovereign AI","Control\u002Fjurisdiction over models, data, infrastructure and dependencies","Not necessarily; sovereignty is broader than network isolation",{},{"id":397,"data":1880,"type":218,"tunes":1882},{"text":1881},"These terms can overlap but are not synonyms. A local Ollama server connected to the internet is local AI, not air-gapped AI. An on-premises RAG platform that calls a cloud model is on-premises application infrastructure with cloud inference, not air-gapped AI.",{},{"id":402,"data":1884,"type":218,"tunes":1886},{"text":1885},"An air-gapped system is often private by design because data remains inside the enclave, but privacy also depends on authorization, logging, data handling, physical security and operational policy.",{},{"id":407,"data":1888,"type":42,"tunes":1890},{"text":1889,"level":253},"Strict air gap vs practical disconnected deployment",{},{"id":412,"data":1892,"type":444,"tunes":1915},{"rows":1893,"title":1909,"layout":394,"columns":1910},[1894,1897,1900,1903,1906],{"id":416,"label":1895,"values":1896},"External physical connection",{"strict":419,"disconnected":419},{"id":421,"label":1898,"values":1899},"Cross-boundary transfer",{"strict":419,"disconnected":419},{"id":425,"label":1901,"values":1902},"Internet access from AI workload",{"strict":419,"disconnected":419},{"id":429,"label":1904,"values":1905},"Internal networking",{"strict":419,"disconnected":419},{"id":433,"label":1907,"values":1908},"Use term when",{"strict":419,"disconnected":419},"Two meanings frequently called “air-gapped”",[1911,1913],{"id":439,"label":1912},"Strict air gap",{"id":442,"label":1914},"Disconnected \u002F no-internet deployment",{},{"id":447,"data":1917,"type":226,"tunes":1920},{"body":1918,"title":1919,"variant":451},"For architecture and security reviews, write the actual rule: \u003Cstrong>no outbound internet\u003C\u002Fstrong>, \u003Cstrong>no physical external network path\u003C\u002Fstrong>, \u003Cstrong>manual transfer only\u003C\u002Fstrong>, or \u003Cstrong>disconnected cluster with approved bastion\u002Fmirror\u003C\u002Fstrong>. That is more precise than saying only “air-gapped.”","Document the boundary instead of relying on the label",{},{"id":454,"data":1922,"type":42,"tunes":1924},{"text":1923,"level":253},"A practical air-gapped AI architecture",{},{"id":459,"data":1926,"type":394,"tunes":1961},{"content":1927,"stretched":43,"withHeadings":14},[1928,1931,1934,1937,1940,1943,1946,1949,1952,1955,1958],[1929,1930],"Layer","What must exist inside the isolated environment",[1932,1933],"User\u002Fapplication layer","Chat UI, APIs, business application or internal agent interface",[1935,1936],"Identity &amp; authorization","Local\u002Finternal authentication, RBAC, tenant\u002Fresource permissions",[1938,1939],"AI gateway\u002Fruntime","Model routing, request policy, context assembly and runtime controls",[1941,1942],"Model serving","Local model server(s), weights, tokenizer\u002Fconfig and accelerator runtime",[1944,1945],"RAG \u002F knowledge","Document store, parser, embeddings, vector\u002Flexical indexes, metadata and provenance",[1947,1948],"Tools\u002Fservices","Only internal\u002Flocal APIs and approved systems reachable from the enclave",[1950,1951],"Artifact repositories","Local container registry, package mirror, model store and optionally OS\u002Fupdate repositories",[1953,1954],"Observability","Internal logs, metrics, traces and audit records",[1956,1957],"Backup\u002Frecovery","Local or separately controlled backup process appropriate to the security domain",[1959,1960],"Transfer boundary","Controlled import\u002Fexport process with inspection and approval",{},{"id":497,"data":1963,"type":218,"tunes":1965},{"text":1964},"A complete architecture should be able to start and operate without DNS lookups, license checks, package downloads or API calls to public services unless those dependencies have approved internal replacements.",{},{"id":502,"data":1967,"type":218,"tunes":1969},{"text":1968},"A useful design test is to disconnect the deployment from every external service and cold-start the stack. Hidden dependencies tend to appear during startup, model loading, authentication, package resolution or telemetry initialization.",{},{"id":507,"data":1971,"type":42,"tunes":1973},{"text":1972,"level":253},"Models must be pre-staged",{},{"id":512,"data":1975,"type":218,"tunes":1977},{"text":1976},"Cloud model APIs are unavailable by definition if the isolated workload has no path to them. The enclave therefore needs locally runnable model artifacts or an internally hosted inference service.",{},{"id":517,"data":1979,"type":218,"tunes":1981},{"text":1980},"NVIDIA's current NIM air-gap documentation explicitly uses a two-phase pattern: download and prepare model assets on a connected machine, transfer them, then run the isolated NIM from local storage without outbound registry access or cloud API keys.",{},{"id":522,"data":1983,"type":218,"tunes":1985},{"text":1984},"Model weights are only part of the dependency set. Tokenizers, configuration files, adapters, quantization metadata and any required runtime code must also be present.",{},{"id":527,"data":1987,"type":42,"tunes":1989},{"text":1988,"level":253},"Models with remote-code dependencies are an air-gap hazard",{},{"id":532,"data":1991,"type":218,"tunes":1993},{"text":1992},"Some model repositories contain custom Python code or runtime hooks that normally fetch additional code or assets.",{},{"id":537,"data":1995,"type":218,"tunes":1997},{"text":1996},"Current Red Hat AI Inference documentation explicitly warns that some Hugging Face models requiring remote code cannot operate normally in disconnected environments because the library attempts network access even when offline mode is configured.",{},{"id":542,"data":1999,"type":218,"tunes":2001},{"text":2000},"The practical lesson is to test a model's entire loading path offline before approving it for an isolated deployment. “I downloaded the weights” is not proof that the model is self-contained.",{},{"id":547,"data":2003,"type":42,"tunes":2005},{"text":2004,"level":253},"Containers, packages and drivers become local supply-chain artifacts",{},{"id":552,"data":2007,"type":218,"tunes":2009},{"text":2008},"Connected environments routinely pull container images, Python packages, OS updates and GPU components from public registries. An air-gapped environment cannot assume any of those services.",{},{"id":557,"data":2011,"type":218,"tunes":2013},{"text":2012},"Red Hat's disconnected AI deployment model uses internal mirror registries for container images and operator catalogs. Models can be mirrored as OCI artifacts or transferred to persistent storage.",{},{"id":562,"data":2015,"type":218,"tunes":2017},{"text":2016},"For broader stacks, the same pattern often applies to language packages, Linux repositories, JavaScript packages and internal binaries: approved artifacts enter once through the transfer process and are then served from trusted internal repositories.",{},{"id":567,"data":2019,"type":42,"tunes":2021},{"text":2020,"level":253},"Know the complete dependency bill",{},{"id":572,"data":2023,"type":394,"tunes":2058},{"content":2024,"stretched":43,"withHeadings":14},[2025,2028,2031,2034,2037,2040,2043,2046,2049,2052,2055],[2026,2027],"Dependency class","Examples",[2029,2030],"Model artifacts","Weights, tokenizer, config, adapters, quantization metadata",[2032,2033],"Inference runtime","vLLM, llama.cpp, Ollama, NIM or other serving runtime",[2035,2036],"GPU\u002Fruntime stack","Drivers, CUDA\u002FROCm libraries, container runtime",[2038,2039],"Application packages","Python wheels, npm packages, system libraries",[2041,2042],"Containers","Application, inference, DB, vector DB, monitoring images",[2044,2045],"RAG models","Embedding model, reranker, OCR\u002Fvision models",[2047,2048],"Data","Knowledge corpus, metadata, schemas, evaluation datasets",[2050,2051],"Security material","Certificates, CA bundles, policy\u002Fconfiguration, malware signatures where applicable",[2053,2054],"Operational artifacts","Dashboards, alert rules, backup tools, runbooks",[2056,2057],"Licensing","Offline-compatible licenses\u002Fentitlements where required",{},{"id":610,"data":2060,"type":42,"tunes":2062},{"text":2061,"level":253},"Internal mirrors are infrastructure, not a convenience",{},{"id":615,"data":2064,"type":218,"tunes":2066},{"text":2065},"A disconnected deployment becomes maintainable when the isolated domain has known internal sources for approved artifacts.",{},{"id":620,"data":2068,"type":218,"tunes":2070},{"text":2069},"Red Hat's documented approach uses a mirror registry available to the disconnected cluster so workloads do not need public registries.",{},{"id":625,"data":2072,"type":218,"tunes":2074},{"text":2073},"The same architectural idea can be applied to model stores and package repositories. The objective is to make artifact origin, version and approval explicit rather than copy random files manually to each server.",{},{"id":630,"data":2076,"type":42,"tunes":2078},{"text":2077,"level":253},"RAG can work fully air-gapped",{},{"id":635,"data":2080,"type":218,"tunes":2082},{"text":2081},"RAG does not require the public internet. It requires a retrievable corpus, an ingestion\u002Findexing pipeline and a model that can use the retrieved context.",{},{"id":640,"data":2084,"type":218,"tunes":2086},{"text":2085},"Inside an air-gapped environment, the document store, parser\u002FOCR, embedding model, vector or lexical index, reranker and generation model can all run locally.",{},{"id":645,"data":2088,"type":218,"tunes":2090},{"text":2089},"What changes is source acquisition. Live web search and cloud document connectors are unavailable unless equivalent data is imported through the controlled boundary.",{},{"id":650,"data":2092,"type":218,"tunes":2094},{"text":2093},"The corpus therefore becomes a governed artifact. Every import should preserve source identity, date\u002Fversion and provenance so users know what knowledge the isolated system actually contains.",{},{"id":655,"data":2096,"type":661,"tunes":2101},{"url":2097,"title":2098,"excerpt":2099,"ctaLabel":2100},"https:\u002F\u002Fstajic.de\u002Fblog\u002Fwhat-is-rag-the-simplest-explanation-of-how-it-works","What Is RAG? The Simplest Explanation of How It Works","RAG itself is independent of cloud hosting. In an air-gapped architecture, retrieval and generation simply have to be supplied by local\u002Finternal components.","Read the RAG foundation",{},{"id":664,"data":2103,"type":42,"tunes":2105},{"text":2104,"level":253},"Agents can run air-gapped — but only with reachable tools",{},{"id":669,"data":2107,"type":218,"tunes":2109},{"text":2108},"An agent loop can run entirely inside an isolated enclave if the model\u002Fruntime and required tools are local or reachable on the internal network.",{},{"id":674,"data":2111,"type":218,"tunes":2113},{"text":2112},"A tool that depends on GitHub, public web search, cloud email or an external SaaS API will fail unless the architecture provides an approved internal equivalent or controlled asynchronous exchange process.",{},{"id":679,"data":2115,"type":218,"tunes":2117},{"text":2116},"This is why air-gapped agent design should begin with a capability inventory: every tool endpoint must be classified as internal, imported, unavailable or deliberately excluded.",{},{"id":684,"data":2119,"type":42,"tunes":2121},{"text":2120,"level":253},"MCP does not bypass the air gap",{},{"id":689,"data":2123,"type":218,"tunes":2125},{"text":2124},"MCP can expose local tools and resources inside an isolated AI environment, but the protocol does not create connectivity through the security boundary.",{},{"id":694,"data":2127,"type":218,"tunes":2129},{"text":2128},"A local MCP server that reads internal documents can work perfectly offline. A remote MCP server on the public internet cannot be reached from a strict air-gapped enclave.",{},{"id":699,"data":2131,"type":218,"tunes":2133},{"text":2132},"The same principle applies to any connector protocol: interoperability is separate from network authority.",{},{"id":704,"data":2135,"type":42,"tunes":2137},{"text":2136,"level":253},"Identity and authentication must also work offline",{},{"id":709,"data":2139,"type":218,"tunes":2141},{"text":2140},"An AI application can be locally hosted while still depending on a cloud identity provider. That hidden dependency breaks truly disconnected operation.",{},{"id":714,"data":2143,"type":218,"tunes":2145},{"text":2144},"Air-gapped designs therefore need an identity architecture that functions inside the enclave: local directory, internal identity provider, internal PKI, local service credentials or another approved mechanism.",{},{"id":719,"data":2147,"type":218,"tunes":2149},{"text":2148},"Authorization remains necessary even though the internet is absent. Air gaps do not replace RBAC, tenant isolation or least privilege.",{},{"id":724,"data":2151,"type":42,"tunes":2153},{"text":2152,"level":253},"Time, certificates and trust stores become local dependencies",{},{"id":729,"data":2155,"type":218,"tunes":2157},{"text":2156},"Many authentication and logging systems depend on reliable time. Certificates expire. Trust stores change. Signed artifacts need validation.",{},{"id":734,"data":2159,"type":218,"tunes":2161},{"text":2160},"A disconnected enclave should therefore have internal time synchronization and a certificate\u002Ftrust lifecycle that does not depend on reaching public services during ordinary operation.",{},{"id":739,"data":2163,"type":218,"tunes":2165},{"text":2164},"These are ordinary infrastructure concerns that become visible only when an architecture is tested without internet access.",{},{"id":744,"data":2167,"type":42,"tunes":2169},{"text":2168,"level":253},"Telemetry and crash reporting need explicit policy",{},{"id":749,"data":2171,"type":218,"tunes":2173},{"text":2172},"Many modern libraries attempt analytics, update checks or error reporting by default.",{},{"id":754,"data":2175,"type":218,"tunes":2177},{"text":2176},"In an isolated environment those calls should either be disabled or redirected to internal observability. Repeated failed telemetry attempts can create delays, noisy logs and unexpected startup behavior.",{},{"id":759,"data":2179,"type":218,"tunes":2181},{"text":2180},"An air-gapped deployment should know which components attempt egress even if the firewall would block them.",{},{"id":764,"data":2183,"type":42,"tunes":2185},{"text":2184,"level":253},"Air-gapped systems still need patches",{},{"id":769,"data":2187,"type":218,"tunes":2189},{"text":2188},"Network isolation does not stop software from developing vulnerabilities. It only changes how patches reach the system.",{},{"id":774,"data":2191,"type":218,"tunes":2193},{"text":2192},"NIST frames patch management as preventive maintenance: organizations still need to identify, acquire, prioritize, install and verify patches and updates.",{},{"id":779,"data":2195,"type":218,"tunes":2197},{"text":2196},"Air-gapped operations therefore need a repeatable import cadence for OS packages, container images, drivers, AI runtimes and security updates. The trade-off is between isolation stability and vulnerability exposure from stale software.",{},{"id":784,"data":2199,"type":42,"tunes":2201},{"text":2200,"level":253},"A controlled update path",{},{"id":789,"data":2203,"type":331,"tunes":2230},{"steps":2204,"title":2229,"orientation":330},[2205,2208,2211,2214,2217,2220,2223,2226],{"label":2206,"description":2207},"1. Identify required update","Security advisory, model\u002Fruntime improvement or operational need triggers change.",{"label":2209,"description":2210},"2. Acquire in connected staging","Download exact versions plus signatures\u002Fchecksums and metadata.",{"label":2212,"description":2213},"3. Validate supply-chain evidence","Verify source, integrity, compatibility and policy requirements.",{"label":2215,"description":2216},"4. Test in representative offline staging","Confirm the update works without unexpected network dependencies.",{"label":2218,"description":2219},"5. Approve transfer","Apply the organization's change and security process.",{"label":2221,"description":2222},"6. Import into enclave repository","Publish the artifact to the internal trusted source.",{"label":2224,"description":2225},"7. Deploy gradually","Apply to test\u002Fcanary nodes before wider rollout where architecture permits.",{"label":2227,"description":2228},"8. Verify and record","Confirm version, health, behavior and rollback state.","Example update lifecycle for an isolated AI environment",{},{"id":819,"data":2232,"type":42,"tunes":2234},{"text":2233,"level":253},"The transfer boundary is the most sensitive operational interface",{},{"id":824,"data":2236,"type":218,"tunes":2238},{"text":2237},"If external information must enter an air-gapped system, the import channel becomes a major security control point.",{},{"id":829,"data":2240,"type":218,"tunes":2242},{"text":2241},"The NSA Cybersecurity Technical Cyber Threat Framework explicitly recognizes replication through removable media as a path adversaries can use to cross into disconnected or air-gapped networks.",{},{"id":834,"data":2244,"type":218,"tunes":2246},{"text":2245},"That is why controlled media handling, inspection, provenance, encryption where required, malware scanning and role separation can matter as much as the AI stack itself.",{},{"id":839,"data":2248,"type":42,"tunes":2250},{"text":2249,"level":253},"Removable media is not a neutral pipe",{},{"id":844,"data":2252,"type":218,"tunes":2254},{"text":2253},"USB drives and other portable media can carry both legitimate model\u002Fdata artifacts and malicious content.",{},{"id":849,"data":2256,"type":218,"tunes":2258},{"text":2257},"NIST's media-sanitization guidance treats storage media as a confidentiality lifecycle object that may require clearing, purging or destruction according to sensitivity and reuse needs.",{},{"id":854,"data":2260,"type":218,"tunes":2262},{"text":2261},"The exact transfer procedure is organization-specific, but the architectural principle is stable: cross-boundary media should be governed as a security asset, not treated as an informal convenience.",{},{"id":859,"data":2264,"type":42,"tunes":2266},{"text":2265,"level":253},"Air-gapping increases supply-chain importance",{},{"id":864,"data":2268,"type":218,"tunes":2270},{"text":2269},"An isolated system receives fewer live external inputs, but every imported binary, model, container and package becomes more consequential because the enclave may trust it for a long time.",{},{"id":869,"data":2272,"type":218,"tunes":2274},{"text":2273},"NIST software-supply-chain guidance emphasizes provenance, supplier risk, vulnerability management, software verification and SBOM-oriented practices. These concerns become directly relevant to offline AI artifact import.",{},{"id":874,"data":2276,"type":218,"tunes":2278},{"text":2277},"Model supply chain deserves the same attention as application supply chain: model origin, license, hash, format, required code, tokenizer, adapters and evaluation status should be known before import.",{},{"id":879,"data":2280,"type":42,"tunes":2282},{"text":2281,"level":253},"Air-gap readiness should be tested, not assumed",{},{"id":884,"data":2284,"type":226,"tunes":2287},{"body":2285,"title":2286,"variant":246},"The following air-gap-readiness test is an engineering synthesis, not a NIST or vendor certification method. It is designed to expose hidden external dependencies before deployment.","Proposed validation pattern",{},{"id":890,"data":2289,"type":394,"tunes":2324},{"content":2290,"stretched":43,"withHeadings":14},[2291,2294,2297,2300,2303,2306,2309,2312,2315,2318,2321],[2292,2293],"Test","What it proves",[2295,2296],"Cold start with all outbound network blocked","Runtime does not require public services during startup",[2298,2299],"Load every approved model from local storage","Weights\u002Ftokenizers\u002Fconfigs are complete",[2301,2302],"Rebuild\u002Fredeploy from internal registries only","Container\u002Fpackage mirrors are sufficient",[2304,2305],"Authenticate users while external IdP is unreachable","Identity works inside the enclave",[2307,2308],"Run RAG ingestion and query offline","Embedding\u002Findexing\u002Fretrieval stack is local",[2310,2311],"Run representative agent tools","Tools do not depend on external APIs",[2313,2314],"Restart after cache deletion","Offline operation is not accidentally relying on previously cached downloads",[2316,2317],"Advance simulated certificate\u002Fupdate lifecycle","Trust and maintenance dependencies are understood",[2319,2320],"Import a new model through staging path","Transfer\u002Fchange procedure is operational",[2322,2323],"Restore from backup","Recovery does not require unavailable cloud storage",{},{"id":928,"data":2326,"type":42,"tunes":2328},{"text":2327,"level":253},"Cached once is not the same as air-gap ready",{},{"id":933,"data":2330,"type":218,"tunes":2332},{"text":2331},"A system may appear offline because the model and packages are already cached from earlier internet access.",{},{"id":938,"data":2334,"type":218,"tunes":2336},{"text":2335},"Deleting caches or deploying to a clean node can reveal missing tokenizer files, Python packages, model manifests or remote-code dependencies.",{},{"id":943,"data":2338,"type":218,"tunes":2340},{"text":2339},"Air-gap readiness should therefore be validated from clean internal artifacts, not only from a developer workstation that was previously connected.",{},{"id":948,"data":2342,"type":42,"tunes":2344},{"text":2343,"level":253},"What threats remain inside an air gap?",{},{"id":953,"data":2346,"type":394,"tunes":2387},{"content":2347,"stretched":43,"withHeadings":14},[2348,2351,2354,2357,2360,2363,2366,2369,2372,2375,2378,2381,2384],[2349,2350],"Threat","Why the air gap does not remove it",[2352,2353],"Compromised imported artifact","Malware\u002Fmodel\u002Fpackage can enter through the authorized transfer path",[2355,2356],"Malicious removable media","Physical transfer can carry executable payloads",[2358,2359],"Insider misuse","Authorized users already exist inside the enclave",[2361,2362],"Prompt injection in imported documents","Untrusted content can influence RAG\u002Fagents without internet",[2364,2365],"Overprivileged agent tools","Local tools can still damage local systems",[2367,2368],"Cross-tenant data leakage","Internal authorization bugs remain possible",[2370,2371],"Vulnerable internal software","Lack of external connection does not remove exploitable bugs",[2373,2374],"Lateral movement","A compromised node can attack other internally connected nodes",[2376,2377],"Stale dependencies","Slow update cadence can leave known vulnerabilities unpatched",[2379,2380],"Physical theft\u002Ftampering","Hardware and media security remain critical",[2382,2383],"Bad model behavior","Hallucination, bias and task failure are independent of networking",[2385,2386],"Supply-chain poisoning","Trusted import sources can still be compromised",{},{"id":997,"data":2389,"type":42,"tunes":2391},{"text":2390,"level":253},"What an air gap actually improves",{},{"id":1002,"data":2393,"type":218,"tunes":2395},{"text":2394},"A genuine air gap can materially reduce attack paths that depend on direct remote connectivity: external command-and-control, cloud credential misuse, internet-facing service exploitation and accidental data exfiltration through ordinary outbound APIs.",{},{"id":1007,"data":2397,"type":218,"tunes":2399},{"text":2398},"It also makes data residency simple in one narrow sense: inference data cannot be sent to an external cloud service if no path exists.",{},{"id":1012,"data":2401,"type":218,"tunes":2403},{"text":2402},"Those benefits are strongest when the transfer boundary and internal access controls are equally disciplined. A poorly managed USB process can undermine the intended isolation.",{},{"id":1017,"data":2405,"type":42,"tunes":2407},{"text":2406,"level":253},"What an air gap makes harder",{},{"id":1022,"data":2409,"type":394,"tunes":2449},{"content":2410,"stretched":43,"withHeadings":14},[2411,2414,2417,2420,2423,2426,2429,2432,2435,2437,2440,2443,2446],[2412,2413],"Area","Operational consequence",[2415,2416],"Model updates","Manual\u002Fstaged transfer instead of direct model-hub pull",[2418,2419],"Security patches","Delayed and governed import workflow",[2421,2422],"Package installation","Internal mirrors or prebuilt artifacts required",[2424,2425],"Cloud AI APIs","Unavailable",[2427,2428],"Web search\u002Fconnectors","Unavailable unless data is imported separately",[2430,2431],"Authentication","Needs internal\u002Foffline-capable identity services",[2433,2434],"Monitoring","Needs internal observability and controlled export",[2056,2436],"Products requiring online activation may be unsuitable",[2438,2439],"Troubleshooting","No easy live access to vendor resources from production enclave",[2441,2442],"Capacity","All inference compute must exist locally",[2444,2445],"Disaster recovery","Cloud backups may be unavailable or policy-restricted",[2447,2448],"Knowledge freshness","External information arrives only as fast as the import process",{},{"id":1065,"data":2451,"type":42,"tunes":2453},{"text":2452,"level":253},"Air-gapped AI vs private AI",{},{"id":1070,"data":2455,"type":218,"tunes":2457},{"text":2456},"Private AI is primarily about controlling sensitive data and AI processing. A private AI platform may be on-premises and still access approved cloud models or external services.",{},{"id":1075,"data":2459,"type":218,"tunes":2461},{"text":2460},"Air-gapped AI is stricter on connectivity. A system can be private without being air-gapped, and an air-gapped system can still have poor privacy if every internal user has unrestricted access.",{},{"id":1080,"data":2463,"type":218,"tunes":2465},{"text":2464},"The security objective should determine the architecture: confidentiality, sovereignty, resilience and isolation are related but distinct requirements.",{},{"id":1085,"data":2467,"type":42,"tunes":2469},{"text":2468,"level":253},"Air-gapped AI vs sovereign AI",{},{"id":1090,"data":2471,"type":218,"tunes":2473},{"text":2472},"Sovereign AI concerns control over the broader dependency chain: data, models, infrastructure, operators, jurisdiction and strategic dependencies.",{},{"id":1095,"data":2475,"type":218,"tunes":2477},{"text":2476},"An air gap can support sovereignty by reducing external runtime dependency, but it does not guarantee sovereign control. The enclave may still depend on foreign hardware, proprietary model licenses or external update suppliers.",{},{"id":1100,"data":2479,"type":218,"tunes":2481},{"text":2480},"The next canonical article separates those control dimensions explicitly.",{},{"id":1105,"data":2483,"type":42,"tunes":2485},{"text":2484,"level":253},"Original implementation evidence: what the Aaasaasa AI Client proves — and what it does not",{},{"id":1110,"data":2487,"type":226,"tunes":2490},{"body":2488,"title":2489,"variant":246},"Aaasaasa AI Client is useful evidence for \u003Cstrong>local inference architecture\u003C\u002Fstrong>, provider abstraction and separation of runtime\u002Fmodel location. It is \u003Cstrong>not evidence of a deployed air-gapped environment\u003C\u002Fstrong>. The repository also supports cloud and remote paths, and no verified project evidence establishes a physically isolated security domain.","Implementation boundary",{},{"id":1116,"data":2492,"type":218,"tunes":2494},{"text":2493},"The AI Hub separates agent\u002Fclient, provider, model and connection location. It supports local Ollama inference and local-provider Codex operation as distinct choices rather than assuming that every AI request goes to a cloud model.",{},{"id":1121,"data":2496,"type":218,"tunes":2498},{"text":2497},"The repository explicitly notes that a local runtime can still use a cloud model, while Direct Ollama chat is local inference. This distinction is directly relevant to air-gap architecture: local execution does not prove that the model or surrounding dependencies are disconnected.",{},{"id":1126,"data":2500,"type":218,"tunes":2502},{"text":2501},"Provider abstraction, local model discovery and local inference are therefore building blocks for an air-gap-capable product architecture, but the network boundary, offline dependency mirror, controlled transfer process and offline identity\u002Foperations must still be engineered separately.",{},{"id":1131,"data":2504,"type":394,"tunes":2527},{"content":2505,"stretched":43,"withHeadings":14},[2506,2509,2512,2515,2518,2521,2524],[2507,2508],"Verified project capability","Air-gap relevance",[2510,2511],"Local Ollama inference","Supports local model execution",[2513,2514],"Local provider\u002Fruntime paths","Reduces dependency on cloud inference",[2516,2517],"Provider\u002Fmodel\u002Fruntime separation","Makes cloud dependencies explicit rather than hidden",[2519,2520],"Central permissions","Supports local tool\u002Fdata access control",[2522,2523],"Cloud\u002Fremote provider support also exists","Proves the product itself is hybrid-capable, not inherently air-gapped",[2525,2526],"No verified isolated deployment boundary","Prevents overclaiming air-gap maturity",{},{"id":1157,"data":2529,"type":42,"tunes":2531},{"text":2530,"level":253},"When is air-gapped AI justified?",{},{"id":1162,"data":2533,"type":394,"tunes":2556},{"content":2534,"stretched":43,"withHeadings":14},[2535,2538,2541,2544,2547,2550,2553],[2536,2537],"Air gap may be justified when","A connected private architecture may be better when",[2539,2540],"Security policy explicitly requires physically separated domains","Main requirement is only that prompts\u002Fdata are not used by public consumer services",[2542,2543],"Classified or extremely sensitive data cannot cross external networks","Approved enterprise cloud\u002Fprivate endpoints satisfy data controls",[2545,2546],"Operational environment has no reliable external connectivity","Internet is available and operational agility matters",[2548,2549],"Mission continuity must not depend on cloud\u002Fprovider availability","Managed model quality and rapid upgrades are more valuable",[2551,2552],"Regulated\u002Fcritical environment mandates controlled transfer","Standard security controls can meet the actual threat model",[2554,2555],"External SaaS\u002FAPI access is prohibited","Business workflow relies heavily on external connectors",{},{"id":1188,"data":2558,"type":218,"tunes":2560},{"text":2559},"Air-gapping should be a requirement derived from a threat model or policy, not a prestige feature. It has real security value when the eliminated connectivity path is itself unacceptable.",{},{"id":1193,"data":2562,"type":218,"tunes":2564},{"text":2563},"For many enterprise use cases, a tightly controlled private network with egress restrictions, local inference and approved update channels may provide a better balance of security and maintainability than a strict physical air gap.",{},{"id":1198,"data":2566,"type":42,"tunes":2568},{"text":2567,"level":253},"A practical air-gapped AI design sequence",{},{"id":1203,"data":2570,"type":331,"tunes":2609},{"steps":2571,"title":2608,"orientation":330},[2572,2575,2578,2581,2584,2587,2590,2593,2596,2599,2602,2605],{"label":2573,"description":2574},"1. Define what the air gap separates","Name the security domains and whether the requirement is strict physical separation or simply no internet.",{"label":2576,"description":2577},"2. Inventory every external dependency","Models, packages, registries, identity, telemetry, licensing, storage, APIs, DNS\u002Ftime and support services.",{"label":2579,"description":2580},"3. Select offline-capable models and runtimes","Verify model assets and runtime code can load without remote calls.",{"label":2582,"description":2583},"4. Build internal artifact repositories","Create trusted sources for containers, packages, models and updates.",{"label":2585,"description":2586},"5. Design controlled transfer","Define staging, verification, media\u002Fgateway handling, approval and provenance.",{"label":2588,"description":2589},"6. Build internal identity and authorization","Ensure users, services and tools can authenticate without cloud dependencies.",{"label":2591,"description":2592},"7. Keep RAG and tools local","Deploy knowledge, embeddings, indexes and required service APIs inside the enclave.",{"label":2594,"description":2595},"8. Build internal observability","Operate logs, metrics, traces and security monitoring locally.",{"label":2597,"description":2598},"9. Define patch\u002Fmodel update cadence","Balance vulnerability response with the controlled import process.",{"label":2600,"description":2601},"10. Test from a clean disconnected state","Cold-start and operate without inherited caches or hidden internet access.",{"label":2603,"description":2604},"11. Test compromise paths","Exercise removable-media, supply-chain, prompt-injection, insider and lateral-movement scenarios.",{"label":2606,"description":2607},"12. Document exceptions and exports","Every permitted cross-boundary path should have a named purpose, owner and control set.","Design from the boundary inward",{},{"id":1245,"data":2611,"type":42,"tunes":2613},{"text":2612,"level":253},"Air-gapped AI architecture checklist",{},{"id":1250,"data":2615,"type":394,"tunes":2668},{"content":2616,"stretched":43,"withHeadings":14},[2617,2620,2623,2626,2629,2632,2635,2638,2641,2644,2647,2650,2653,2656,2659,2662,2665],[2618,2619],"Question","Expected evidence",[2621,2622],"What exactly is isolated from what?","Documented security-domain boundary",[2624,2625],"Is the boundary physically disconnected?","Network\u002Fphysical architecture evidence if strict air gap is claimed",[2627,2628],"How does data cross the boundary?","Authorized non-automated\u002Fmanual or explicitly documented disconnected workflow",[2630,2631],"Can every model cold-start offline?","Offline loading test",[2633,2634],"Are tokenizer\u002Fconfig\u002Fruntime assets complete?","Verified internal model bundle",[2636,2637],"Where do containers\u002Fpackages come from?","Internal trusted mirror\u002Frepository",[2639,2640],"Can identity work without cloud services?","Internal IdP\u002FPKI\u002Fservice credential path",[2642,2643],"Can RAG ingest\u002Fquery offline?","Local ingestion, embeddings, index and retrieval",[2645,2646],"Which agent tools remain available?","Internal capability inventory",[2648,2649],"How are patches imported?","Controlled maintenance process",[2651,2652],"How are artifacts verified?","Integrity\u002Fprovenance\u002Fmalware\u002Fsupply-chain controls",[2654,2655],"How is removable media governed?","Media handling and sanitization policy",[2657,2658],"Can the system run after caches are cleared?","Clean-environment offline test",[2660,2661],"Where are logs and traces stored?","Internal observability platform",[2663,2664],"How are exports approved?","Controlled egress process",[2666,2667],"What proves this is air-gapped rather than merely local?","Boundary and transfer evidence, not model location",{},{"id":1306,"data":2670,"type":42,"tunes":2672},{"text":2671,"level":253},"Common air-gapped AI failure modes",{},{"id":1311,"data":2674,"type":394,"tunes":2715},{"content":2675,"stretched":43,"withHeadings":14},[2676,2679,2682,2685,2688,2691,2694,2697,2700,2703,2706,2709,2712],[2677,2678],"Failure mode","What actually failed",[2680,2681],"Local model still downloads tokenizer\u002Fconfig at startup","Model bundle was incomplete",[2683,2684],"Container references public registry","Deployment was not self-contained",[2686,2687],"Cloud identity required for login","Application was local but identity was not",[2689,2690],"License server required externally","Vendor dependency contradicted offline operation",[2692,2693],"Embedding model missing","Chat works but RAG ingestion fails",[2695,2696],"Agent tool calls public SaaS","Agent architecture was not air-gap compatible",[2698,2699],"Only GPU node is isolated","Database, UI or monitoring still depends on external services",[2701,2702],"USB imports are informal","Transfer boundary becomes uncontrolled attack path",[2704,2705],"No patch process","Isolation creates growing vulnerability debt",[2707,2708],"Cached developer machine used as proof","Fresh deployment fails without internet",[2710,2711],"Air gap replaces authorization thinking","Internal users\u002Fservices become overprivileged",[2713,2714],"Air-gapped label used for firewall-only egress block","Security documentation overstates the actual boundary",{},{"id":1355,"data":2717,"type":42,"tunes":2719},{"text":2718,"level":253},"Common misconceptions",{},{"id":1360,"data":2721,"type":394,"tunes":2756},{"content":2722,"stretched":43,"withHeadings":14},[2723,2726,2729,2732,2735,2738,2741,2744,2747,2750,2753],[2724,2725],"Misconception","Correction",[2727,2728],"“Local AI is air-gapped AI.”","Local describes where inference runs; air gap describes the security\u002Fnetwork boundary.",[2730,2731],"“Air-gapped means one standalone PC.”","An isolated enclave can contain an entire internal network or cluster.",[2733,2734],"“No internet equals strict air gap.”","Under NIST's definition, the separated systems also lack physical connection and cross-boundary transfer is non-automated.",[2736,2737],"“Air gaps eliminate cyber risk.”","Supply-chain, removable-media, insider, internal-network and application risks remain.",[2739,2740],"“RAG needs the cloud.”","RAG can run entirely with local models, indexes and data.",[2742,2743],"“Agents cannot work offline.”","Agents can use internal\u002Flocal tools; they simply cannot reach unavailable external services.",[2745,2746],"“Once installed, the system needs no updates.”","Patches, drivers, models and dependencies still require lifecycle management.",[2748,2749],"“A downloaded model is self-contained.”","Tokenizers, remote code, libraries or model assets may still trigger network dependencies.",[2751,2752],"“Private AI and air-gapped AI are identical.”","Private AI is a data\u002Fcontrol property; air gap is a connectivity property.",[2754,2755],"“Air gap guarantees sovereignty.”","External hardware, licenses, models and supply chain can remain dependencies.",{},{"id":1398,"data":2758,"type":42,"tunes":2760},{"text":2759,"level":253},"Limitations",{},{"id":1403,"data":2762,"type":218,"tunes":2764},{"text":2763},"Strict air gaps make external knowledge freshness slower because every new source must pass through a transfer process.",{},{"id":1408,"data":2766,"type":218,"tunes":2768},{"text":2767},"They can constrain model choice when licenses, remote-code requirements, hardware needs or provider-only APIs cannot be satisfied offline.",{},{"id":1413,"data":2770,"type":218,"tunes":2772},{"text":2771},"They increase operational cost because infrastructure normally consumed as cloud services must be owned and maintained internally.",{},{"id":1418,"data":2774,"type":218,"tunes":2776},{"text":2775},"They can also create patch latency: stronger change control may keep systems stable while delaying urgent vulnerability remediation.",{},{"id":1423,"data":2778,"type":218,"tunes":2780},{"text":2779},"Air-gapped AI should therefore be evaluated as one security architecture among several, not assumed to be universally superior.",{},{"id":1428,"data":2782,"type":42,"tunes":2784},{"text":2783,"level":253},"What would change this answer?",{},{"id":1433,"data":2786,"type":218,"tunes":2788},{"text":2787},"Vendor support for disconnected operation changes quickly. New model formats, signed OCI artifacts, offline license mechanisms and integrated model registries can reduce operational friction.",{},{"id":1438,"data":2790,"type":218,"tunes":2792},{"text":2791},"The distinction between strict air gap and disconnected deployment will remain important even if vendors continue using the terms loosely.",{},{"id":1443,"data":2794,"type":218,"tunes":2796},{"text":2795},"The stable principle is that genuine air-gap claims depend on the system boundary and transfer mechanism, not on whether the LLM happens to run locally.",{},{"id":1448,"data":2798,"type":42,"tunes":2800},{"text":2799,"level":253},"Related canonical knowledge",{},{"id":1453,"data":2802,"type":218,"tunes":2804},{"text":2803},"Air-Gapped AI is a deployment\u002Fsecurity architecture node. Private AI, Sovereign AI and provider abstraction answer different questions about confidentiality, control and dependency.",{},{"id":1458,"data":2806,"type":218,"tunes":2808},{"text":2807},"MLOps\u002FLLMOps becomes more demanding inside a disconnected environment because model, package and update lifecycles must operate through internal repositories and controlled transfer.",{},{"id":1463,"data":2810,"type":218,"tunes":2812},{"text":2811},"RAG and Agentic AI remain valid patterns inside the enclave as long as their data and tools are internally available.",{},{"id":1468,"data":2814,"type":661,"tunes":2819},{"url":2815,"title":2816,"excerpt":2817,"ctaLabel":2818},"https:\u002F\u002Fstajic.de\u002Fblog\u002Fai-agent-memory-is-not-rag-how-to-separate-memory-retrieval-state-and-context","AI Agent Memory Is Not RAG: How to Separate Memory, Retrieval, State and Context","Air-gapped AI still needs correct internal boundaries between durable memory, authoritative state, retrieval and model context.","Read the memory architecture article",{},{"id":1476,"data":2821,"type":42,"tunes":2823},{"text":2822,"level":253},"Frequently asked questions",{},{"id":1481,"data":2825,"type":1481,"tunes":2858},{"items":2826,"title":2857},[2827,2830,2833,2836,2839,2842,2845,2848,2851,2854],{"id":1485,"answer":2828,"question":2829},"Air-gapped AI is AI deployed inside a security domain physically disconnected from the external systems it is separated from, with cross-boundary transfer performed through controlled non-automated procedures under the strict NIST definition.","What is air-gapped AI?",{"id":1489,"answer":2831,"question":2832},"No for normal inference and operation. Required models, packages, data and services must be available inside the isolated environment.","Does air-gapped AI need internet access?",{"id":1493,"answer":2834,"question":2835},"No. A local model can run on a machine that still has internet access or uses cloud identity, tools or storage. Air gap describes the complete system boundary.","Is a local LLM automatically air-gapped?",{"id":1497,"answer":2837,"question":2838},"Yes. Documents, embedding models, vector or lexical indexes, rerankers and generation models can all run locally. External knowledge must be imported through the controlled boundary.","Can RAG work in an air-gapped network?",{"id":1501,"answer":2840,"question":2841},"Yes, if their tools and required systems are available inside the isolated network. Public SaaS and cloud APIs are unavailable without a permitted cross-boundary mechanism.","Can AI agents work air-gapped?",{"id":1505,"answer":2843,"question":2844},"Models are typically acquired and validated in a connected staging environment, transferred through an approved process and published to an internal model\u002Fartifact repository.","How are models updated in an air-gapped environment?",{"id":1509,"answer":2846,"question":2847},"No. On-premises describes infrastructure location. On-prem systems can remain internet-connected.","Is on-premises AI the same as air-gapped AI?",{"id":1513,"answer":2849,"question":2850},"No. Private AI is about data\u002Fcontrol requirements and can still use connected infrastructure. Air gap specifically describes network\u002Fdomain separation.","Is private AI the same as air-gapped AI?",{"id":1517,"answer":2852,"question":2853},"It removes or reduces some remote connectivity risks but does not remove supply-chain, removable-media, insider, internal authorization, physical or model-behavior risks.","Does an air gap make AI secure?",{"id":1521,"answer":2855,"question":2856},"Deploy or cold-start the full stack in a clean environment with all external connectivity unavailable and verify that models, identity, RAG, tools, monitoring, updates and recovery depend only on approved internal artifacts and services.","What is the best test for air-gap readiness?","Air-gapped AI FAQ",{},{"id":1527,"data":2860,"type":42,"tunes":2862},{"text":2861,"level":253},"Glossary",{},{"id":1532,"data":2864,"type":1532,"tunes":2899},{"title":2865,"entries":2866},"Key air-gapped AI terms",[2867,2870,2872,2874,2876,2878,2881,2884,2887,2890,2893,2896],{"term":2868,"anchor":1538,"definition":2869},"Air gap","Security-domain interface where systems are not physically connected and any cross-boundary logical transfer is non-automated\u002Fmanual under the NIST glossary definition.",{"term":1871,"anchor":1542,"definition":2871},"AI system deployed inside an air-gapped security domain with locally available inference and operational dependencies.",{"term":1859,"anchor":1546,"definition":2873},"Deployment environment without direct outside-internet access; implementations may use controlled mirror or bastion workflows.",{"term":1855,"anchor":1550,"definition":2875},"AI application able to operate for some or all functions without internet connectivity, without necessarily being permanently isolated.",{"term":1851,"anchor":1553,"definition":2877},"AI inference or runtime executing on local hardware rather than a remote model endpoint; does not imply network isolation.",{"term":2879,"anchor":1557,"definition":2880},"Mirror registry","Internal repository containing approved copies of container images or other artifacts needed by a disconnected deployment.",{"term":2882,"anchor":1561,"definition":2883},"Staging environment","Connected or controlled zone where artifacts are acquired, verified and prepared before transfer into an isolated domain.",{"term":2885,"anchor":1565,"definition":2886},"Controlled transfer","Governed movement of data or software across the isolation boundary using approved media\u002Fprocesses and verification.",{"term":2888,"anchor":1569,"definition":2889},"Artifact provenance","Information showing where a model, package, container or other imported artifact originated and how it was produced or verified.",{"term":2891,"anchor":1573,"definition":2892},"Removable media","Portable storage used to transfer data between systems; a potential security path across disconnected domains.",{"term":2894,"anchor":1577,"definition":2895},"Internal model store","Repository inside the isolated environment from which approved model artifacts are served or deployed.",{"term":2897,"anchor":1581,"definition":2898},"Air-gap readiness","Demonstrated ability of the complete AI stack to install, start, operate, update and recover without unapproved external connectivity.",{},{"id":1585,"data":2901,"type":42,"tunes":2903},{"text":2902,"level":253},"Conclusion",{},{"id":1590,"data":2905,"type":218,"tunes":2907},{"text":2906},"Air-gapped AI is not a special kind of model. It is an AI architecture operating inside a deliberately isolated security domain.",{},{"id":1595,"data":2909,"type":218,"tunes":2911},{"text":2910},"The model can be the easy part. Production readiness depends on whether every surrounding dependency — model assets, packages, registries, identity, RAG, tools, monitoring, updates and recovery — can function without an automated external path.",{},{"id":1600,"data":2913,"type":218,"tunes":2915},{"text":2914},"The shortest reliable rule is: local inference proves where the model runs; air-gap evidence proves how the complete system is separated and how every permitted transfer crosses that boundary.",{},{"id":1605,"data":2917,"type":42,"tunes":2919},{"text":2918,"level":253},"Primary sources and current implementation references",{},{"id":1610,"data":2921,"type":218,"tunes":2923},{"text":2922},"The sources below establish the security definition, current disconnected AI deployment patterns and lifecycle risks. Vendor use of “air-gapped” is intentionally distinguished from the stricter NIST definition.",{},{"id":1615,"data":2925,"type":1622,"tunes":2930},{"link":1617,"meta":2926},{"image":2927,"title":2928,"description":2929},{"url":419},"NIST CSRC — Air gap","NIST glossary definition: physically disconnected systems with non-automated, manually controlled logical transfer across the boundary.",{},{"id":1625,"data":2932,"type":1622,"tunes":2937},{"link":1627,"meta":2933},{"image":2934,"title":2935,"description":2936},{"url":419},"NVIDIA NIM — Air-Gap Deployment","Current operational guidance for staging model assets on a connected system and running NIM from local storage without internet, public registries or cloud API keys.",{},{"id":1634,"data":2939,"type":1622,"tunes":2944},{"link":1636,"meta":2940},{"image":2941,"title":2942,"description":2943},{"url":419},"Red Hat AI Inference — Disconnected deployment","Current Red Hat guidance for serving LLMs in disconnected environments with mirrored artifacts and internal infrastructure.",{},{"id":1643,"data":2946,"type":1622,"tunes":2951},{"link":1645,"meta":2947},{"image":2948,"title":2949,"description":2950},{"url":419},"Red Hat AI Inference — Storing models in disconnected environments","Current guidance covering OCI model images, persistent model storage and limitations of models requiring remote code.",{},{"id":1652,"data":2953,"type":1622,"tunes":2958},{"link":1654,"meta":2954},{"image":2955,"title":2956,"description":2957},{"url":419},"NSA — Technical Cyber Threat Framework","Threat framework explicitly identifying removable-media replication as a path into disconnected or air-gapped networks.",{},{"id":1661,"data":2960,"type":1622,"tunes":2965},{"link":1663,"meta":2961},{"image":2962,"title":2963,"description":2964},{"url":419},"NIST SP 800-88 Rev. 1 — Guidelines for Media Sanitization","Guidance for managing and sanitizing storage media according to information confidentiality requirements.",{},{"id":1670,"data":2967,"type":1622,"tunes":2972},{"link":1672,"meta":2968},{"image":2969,"title":2970,"description":2971},{"url":419},"NIST SP 800-40 Rev. 4 — Enterprise Patch Management Planning","Guidance framing patching and updates as preventive maintenance across enterprise systems.",{},{"id":1679,"data":2974,"type":1622,"tunes":2979},{"link":1681,"meta":2975},{"image":2976,"title":2977,"description":2978},{"url":419},"NIST — Software Security in Supply Chains","NIST guidance covering software supply-chain risk, provenance, verification, SBOM-related practices and vulnerability management.",{},"2.31.6","Air-gapped AI runs models, RAG and AI applications inside an isolated security domain without internet or cloud dependencies. Learn how models, data, updates and tools operate offline.",{"lang":7,"title":208,"content":210,"contentJson":2983,"excerpt":1688},{"time":212,"blocks":2984,"version":1687},[2985,2988,2991,2994,2997,3000,3003,3006,3009,3012,3015,3018,3021,3024,3027,3030,3042,3045,3048,3051,3054,3057,3069,3072,3075,3078,3095,3098,3101,3116,3119,3122,3125,3128,3131,3134,3137,3140,3143,3146,3149,3152,3155,3158,3161,3176,3179,3182,3185,3188,3191,3194,3197,3200,3203,3206,3209,3212,3215,3218,3221,3224,3227,3230,3233,3236,3239,3242,3245,3248,3251,3254,3257,3260,3263,3266,3269,3272,3275,3278,3281,3293,3296,3299,3302,3305,3308,3311,3314,3317,3320,3323,3326,3329,3332,3335,3350,3353,3356,3359,3362,3365,3382,3385,3388,3391,3394,3397,3414,3417,3420,3423,3426,3429,3432,3435,3438,3441,3444,3447,3450,3453,3464,3467,3478,3481,3484,3487,3503,3506,3527,3530,3547,3550,3565,3568,3571,3574,3577,3580,3583,3586,3589,3592,3595,3598,3601,3604,3607,3610,3613,3627,3630,3646,3649,3652,3655,3658,3661,3664,3669,3674,3679,3684,3689,3694,3699],{"id":215,"data":2986,"type":218,"tunes":2987},{"text":217},{},{"id":221,"data":2989,"type":226,"tunes":2990},{"body":223,"title":224,"variant":225},{},{"id":229,"data":2992,"type":226,"tunes":2993},{"body":231,"title":232,"variant":233},{},{"id":236,"data":2995,"type":226,"tunes":2996},{"body":238,"title":239,"variant":233},{},{"id":242,"data":2998,"type":226,"tunes":2999},{"body":244,"title":245,"variant":246},{},{"id":249,"data":3001,"type":254,"tunes":3002},{"title":251,"maxLevel":252,"minLevel":253},{},{"id":257,"data":3004,"type":42,"tunes":3005},{"text":259,"level":253},{},{"id":262,"data":3007,"type":218,"tunes":3008},{"text":264},{},{"id":267,"data":3010,"type":218,"tunes":3011},{"text":269},{},{"id":272,"data":3013,"type":218,"tunes":3014},{"text":274},{},{"id":277,"data":3016,"type":42,"tunes":3017},{"text":279,"level":253},{},{"id":282,"data":3019,"type":218,"tunes":3020},{"text":284},{},{"id":287,"data":3022,"type":218,"tunes":3023},{"text":289},{},{"id":292,"data":3025,"type":218,"tunes":3026},{"text":294},{},{"id":297,"data":3028,"type":218,"tunes":3029},{"text":299},{},{"id":302,"data":3031,"type":331,"tunes":3041},{"steps":3032,"title":329,"orientation":330},[3033,3034,3035,3036,3037,3038,3039,3040],{"label":306,"description":307},{"label":309,"description":310},{"label":312,"description":313},{"label":315,"description":316},{"label":318,"description":319},{"label":321,"description":322},{"label":324,"description":325},{"label":327,"description":328},{},{"id":334,"data":3043,"type":42,"tunes":3044},{"text":336,"level":253},{},{"id":339,"data":3046,"type":218,"tunes":3047},{"text":341},{},{"id":344,"data":3049,"type":218,"tunes":3050},{"text":346},{},{"id":349,"data":3052,"type":218,"tunes":3053},{"text":351},{},{"id":354,"data":3055,"type":42,"tunes":3056},{"text":356,"level":253},{},{"id":359,"data":3058,"type":394,"tunes":3068},{"content":3059,"stretched":43,"withHeadings":14},[3060,3061,3062,3063,3064,3065,3066,3067],[363,364,365],[367,368,369],[371,372,373],[375,376,377],[379,380,381],[383,384,385],[387,388,389],[391,392,393],{},{"id":397,"data":3070,"type":218,"tunes":3071},{"text":399},{},{"id":402,"data":3073,"type":218,"tunes":3074},{"text":404},{},{"id":407,"data":3076,"type":42,"tunes":3077},{"text":409,"level":253},{},{"id":412,"data":3079,"type":444,"tunes":3094},{"rows":3080,"title":436,"layout":394,"columns":3091},[3081,3083,3085,3087,3089],{"id":416,"label":417,"values":3082},[419,419],{"id":421,"label":422,"values":3084},[419,419],{"id":425,"label":426,"values":3086},[419,419],{"id":429,"label":430,"values":3088},[419,419],{"id":433,"label":434,"values":3090},[419,419],[3092,3093],{"id":439,"label":440},{"id":442,"label":443},{},{"id":447,"data":3096,"type":226,"tunes":3097},{"body":449,"title":450,"variant":451},{},{"id":454,"data":3099,"type":42,"tunes":3100},{"text":456,"level":253},{},{"id":459,"data":3102,"type":394,"tunes":3115},{"content":3103,"stretched":43,"withHeadings":14},[3104,3105,3106,3107,3108,3109,3110,3111,3112,3113,3114],[463,464],[466,467],[469,470],[472,473],[475,476],[478,479],[481,482],[484,485],[487,488],[490,491],[493,494],{},{"id":497,"data":3117,"type":218,"tunes":3118},{"text":499},{},{"id":502,"data":3120,"type":218,"tunes":3121},{"text":504},{},{"id":507,"data":3123,"type":42,"tunes":3124},{"text":509,"level":253},{},{"id":512,"data":3126,"type":218,"tunes":3127},{"text":514},{},{"id":517,"data":3129,"type":218,"tunes":3130},{"text":519},{},{"id":522,"data":3132,"type":218,"tunes":3133},{"text":524},{},{"id":527,"data":3135,"type":42,"tunes":3136},{"text":529,"level":253},{},{"id":532,"data":3138,"type":218,"tunes":3139},{"text":534},{},{"id":537,"data":3141,"type":218,"tunes":3142},{"text":539},{},{"id":542,"data":3144,"type":218,"tunes":3145},{"text":544},{},{"id":547,"data":3147,"type":42,"tunes":3148},{"text":549,"level":253},{},{"id":552,"data":3150,"type":218,"tunes":3151},{"text":554},{},{"id":557,"data":3153,"type":218,"tunes":3154},{"text":559},{},{"id":562,"data":3156,"type":218,"tunes":3157},{"text":564},{},{"id":567,"data":3159,"type":42,"tunes":3160},{"text":569,"level":253},{},{"id":572,"data":3162,"type":394,"tunes":3175},{"content":3163,"stretched":43,"withHeadings":14},[3164,3165,3166,3167,3168,3169,3170,3171,3172,3173,3174],[576,577],[579,580],[582,583],[585,586],[588,589],[591,592],[594,595],[597,598],[600,601],[603,604],[606,607],{},{"id":610,"data":3177,"type":42,"tunes":3178},{"text":612,"level":253},{},{"id":615,"data":3180,"type":218,"tunes":3181},{"text":617},{},{"id":620,"data":3183,"type":218,"tunes":3184},{"text":622},{},{"id":625,"data":3186,"type":218,"tunes":3187},{"text":627},{},{"id":630,"data":3189,"type":42,"tunes":3190},{"text":632,"level":253},{},{"id":635,"data":3192,"type":218,"tunes":3193},{"text":637},{},{"id":640,"data":3195,"type":218,"tunes":3196},{"text":642},{},{"id":645,"data":3198,"type":218,"tunes":3199},{"text":647},{},{"id":650,"data":3201,"type":218,"tunes":3202},{"text":652},{},{"id":655,"data":3204,"type":661,"tunes":3205},{"url":657,"title":658,"excerpt":659,"ctaLabel":660},{},{"id":664,"data":3207,"type":42,"tunes":3208},{"text":666,"level":253},{},{"id":669,"data":3210,"type":218,"tunes":3211},{"text":671},{},{"id":674,"data":3213,"type":218,"tunes":3214},{"text":676},{},{"id":679,"data":3216,"type":218,"tunes":3217},{"text":681},{},{"id":684,"data":3219,"type":42,"tunes":3220},{"text":686,"level":253},{},{"id":689,"data":3222,"type":218,"tunes":3223},{"text":691},{},{"id":694,"data":3225,"type":218,"tunes":3226},{"text":696},{},{"id":699,"data":3228,"type":218,"tunes":3229},{"text":701},{},{"id":704,"data":3231,"type":42,"tunes":3232},{"text":706,"level":253},{},{"id":709,"data":3234,"type":218,"tunes":3235},{"text":711},{},{"id":714,"data":3237,"type":218,"tunes":3238},{"text":716},{},{"id":719,"data":3240,"type":218,"tunes":3241},{"text":721},{},{"id":724,"data":3243,"type":42,"tunes":3244},{"text":726,"level":253},{},{"id":729,"data":3246,"type":218,"tunes":3247},{"text":731},{},{"id":734,"data":3249,"type":218,"tunes":3250},{"text":736},{},{"id":739,"data":3252,"type":218,"tunes":3253},{"text":741},{},{"id":744,"data":3255,"type":42,"tunes":3256},{"text":746,"level":253},{},{"id":749,"data":3258,"type":218,"tunes":3259},{"text":751},{},{"id":754,"data":3261,"type":218,"tunes":3262},{"text":756},{},{"id":759,"data":3264,"type":218,"tunes":3265},{"text":761},{},{"id":764,"data":3267,"type":42,"tunes":3268},{"text":766,"level":253},{},{"id":769,"data":3270,"type":218,"tunes":3271},{"text":771},{},{"id":774,"data":3273,"type":218,"tunes":3274},{"text":776},{},{"id":779,"data":3276,"type":218,"tunes":3277},{"text":781},{},{"id":784,"data":3279,"type":42,"tunes":3280},{"text":786,"level":253},{},{"id":789,"data":3282,"type":331,"tunes":3292},{"steps":3283,"title":816,"orientation":330},[3284,3285,3286,3287,3288,3289,3290,3291],{"label":793,"description":794},{"label":796,"description":797},{"label":799,"description":800},{"label":802,"description":803},{"label":805,"description":806},{"label":808,"description":809},{"label":811,"description":812},{"label":814,"description":815},{},{"id":819,"data":3294,"type":42,"tunes":3295},{"text":821,"level":253},{},{"id":824,"data":3297,"type":218,"tunes":3298},{"text":826},{},{"id":829,"data":3300,"type":218,"tunes":3301},{"text":831},{},{"id":834,"data":3303,"type":218,"tunes":3304},{"text":836},{},{"id":839,"data":3306,"type":42,"tunes":3307},{"text":841,"level":253},{},{"id":844,"data":3309,"type":218,"tunes":3310},{"text":846},{},{"id":849,"data":3312,"type":218,"tunes":3313},{"text":851},{},{"id":854,"data":3315,"type":218,"tunes":3316},{"text":856},{},{"id":859,"data":3318,"type":42,"tunes":3319},{"text":861,"level":253},{},{"id":864,"data":3321,"type":218,"tunes":3322},{"text":866},{},{"id":869,"data":3324,"type":218,"tunes":3325},{"text":871},{},{"id":874,"data":3327,"type":218,"tunes":3328},{"text":876},{},{"id":879,"data":3330,"type":42,"tunes":3331},{"text":881,"level":253},{},{"id":884,"data":3333,"type":226,"tunes":3334},{"body":886,"title":887,"variant":246},{},{"id":890,"data":3336,"type":394,"tunes":3349},{"content":3337,"stretched":43,"withHeadings":14},[3338,3339,3340,3341,3342,3343,3344,3345,3346,3347,3348],[894,895],[897,898],[900,901],[903,904],[906,907],[909,910],[912,913],[915,916],[918,919],[921,922],[924,925],{},{"id":928,"data":3351,"type":42,"tunes":3352},{"text":930,"level":253},{},{"id":933,"data":3354,"type":218,"tunes":3355},{"text":935},{},{"id":938,"data":3357,"type":218,"tunes":3358},{"text":940},{},{"id":943,"data":3360,"type":218,"tunes":3361},{"text":945},{},{"id":948,"data":3363,"type":42,"tunes":3364},{"text":950,"level":253},{},{"id":953,"data":3366,"type":394,"tunes":3381},{"content":3367,"stretched":43,"withHeadings":14},[3368,3369,3370,3371,3372,3373,3374,3375,3376,3377,3378,3379,3380],[957,958],[960,961],[963,964],[966,967],[969,970],[972,973],[975,976],[978,979],[981,982],[984,985],[987,988],[990,991],[993,994],{},{"id":997,"data":3383,"type":42,"tunes":3384},{"text":999,"level":253},{},{"id":1002,"data":3386,"type":218,"tunes":3387},{"text":1004},{},{"id":1007,"data":3389,"type":218,"tunes":3390},{"text":1009},{},{"id":1012,"data":3392,"type":218,"tunes":3393},{"text":1014},{},{"id":1017,"data":3395,"type":42,"tunes":3396},{"text":1019,"level":253},{},{"id":1022,"data":3398,"type":394,"tunes":3413},{"content":3399,"stretched":43,"withHeadings":14},[3400,3401,3402,3403,3404,3405,3406,3407,3408,3409,3410,3411,3412],[1026,1027],[1029,1030],[1032,1033],[1035,1036],[1038,1039],[1041,1042],[1044,1045],[1047,1048],[606,1050],[1052,1053],[1055,1056],[1058,1059],[1061,1062],{},{"id":1065,"data":3415,"type":42,"tunes":3416},{"text":1067,"level":253},{},{"id":1070,"data":3418,"type":218,"tunes":3419},{"text":1072},{},{"id":1075,"data":3421,"type":218,"tunes":3422},{"text":1077},{},{"id":1080,"data":3424,"type":218,"tunes":3425},{"text":1082},{},{"id":1085,"data":3427,"type":42,"tunes":3428},{"text":1087,"level":253},{},{"id":1090,"data":3430,"type":218,"tunes":3431},{"text":1092},{},{"id":1095,"data":3433,"type":218,"tunes":3434},{"text":1097},{},{"id":1100,"data":3436,"type":218,"tunes":3437},{"text":1102},{},{"id":1105,"data":3439,"type":42,"tunes":3440},{"text":1107,"level":253},{},{"id":1110,"data":3442,"type":226,"tunes":3443},{"body":1112,"title":1113,"variant":246},{},{"id":1116,"data":3445,"type":218,"tunes":3446},{"text":1118},{},{"id":1121,"data":3448,"type":218,"tunes":3449},{"text":1123},{},{"id":1126,"data":3451,"type":218,"tunes":3452},{"text":1128},{},{"id":1131,"data":3454,"type":394,"tunes":3463},{"content":3455,"stretched":43,"withHeadings":14},[3456,3457,3458,3459,3460,3461,3462],[1135,1136],[1138,1139],[1141,1142],[1144,1145],[1147,1148],[1150,1151],[1153,1154],{},{"id":1157,"data":3465,"type":42,"tunes":3466},{"text":1159,"level":253},{},{"id":1162,"data":3468,"type":394,"tunes":3477},{"content":3469,"stretched":43,"withHeadings":14},[3470,3471,3472,3473,3474,3475,3476],[1166,1167],[1169,1170],[1172,1173],[1175,1176],[1178,1179],[1181,1182],[1184,1185],{},{"id":1188,"data":3479,"type":218,"tunes":3480},{"text":1190},{},{"id":1193,"data":3482,"type":218,"tunes":3483},{"text":1195},{},{"id":1198,"data":3485,"type":42,"tunes":3486},{"text":1200,"level":253},{},{"id":1203,"data":3488,"type":331,"tunes":3502},{"steps":3489,"title":1242,"orientation":330},[3490,3491,3492,3493,3494,3495,3496,3497,3498,3499,3500,3501],{"label":1207,"description":1208},{"label":1210,"description":1211},{"label":1213,"description":1214},{"label":1216,"description":1217},{"label":1219,"description":1220},{"label":1222,"description":1223},{"label":1225,"description":1226},{"label":1228,"description":1229},{"label":1231,"description":1232},{"label":1234,"description":1235},{"label":1237,"description":1238},{"label":1240,"description":1241},{},{"id":1245,"data":3504,"type":42,"tunes":3505},{"text":1247,"level":253},{},{"id":1250,"data":3507,"type":394,"tunes":3526},{"content":3508,"stretched":43,"withHeadings":14},[3509,3510,3511,3512,3513,3514,3515,3516,3517,3518,3519,3520,3521,3522,3523,3524,3525],[1254,1255],[1257,1258],[1260,1261],[1263,1264],[1266,1267],[1269,1270],[1272,1273],[1275,1276],[1278,1279],[1281,1282],[1284,1285],[1287,1288],[1290,1291],[1293,1294],[1296,1297],[1299,1300],[1302,1303],{},{"id":1306,"data":3528,"type":42,"tunes":3529},{"text":1308,"level":253},{},{"id":1311,"data":3531,"type":394,"tunes":3546},{"content":3532,"stretched":43,"withHeadings":14},[3533,3534,3535,3536,3537,3538,3539,3540,3541,3542,3543,3544,3545],[1315,1316],[1318,1319],[1321,1322],[1324,1325],[1327,1328],[1330,1331],[1333,1334],[1336,1337],[1339,1340],[1342,1343],[1345,1346],[1348,1349],[1351,1352],{},{"id":1355,"data":3548,"type":42,"tunes":3549},{"text":1357,"level":253},{},{"id":1360,"data":3551,"type":394,"tunes":3564},{"content":3552,"stretched":43,"withHeadings":14},[3553,3554,3555,3556,3557,3558,3559,3560,3561,3562,3563],[1364,1365],[1367,1368],[1370,1371],[1373,1374],[1376,1377],[1379,1380],[1382,1383],[1385,1386],[1388,1389],[1391,1392],[1394,1395],{},{"id":1398,"data":3566,"type":42,"tunes":3567},{"text":1400,"level":253},{},{"id":1403,"data":3569,"type":218,"tunes":3570},{"text":1405},{},{"id":1408,"data":3572,"type":218,"tunes":3573},{"text":1410},{},{"id":1413,"data":3575,"type":218,"tunes":3576},{"text":1415},{},{"id":1418,"data":3578,"type":218,"tunes":3579},{"text":1420},{},{"id":1423,"data":3581,"type":218,"tunes":3582},{"text":1425},{},{"id":1428,"data":3584,"type":42,"tunes":3585},{"text":1430,"level":253},{},{"id":1433,"data":3587,"type":218,"tunes":3588},{"text":1435},{},{"id":1438,"data":3590,"type":218,"tunes":3591},{"text":1440},{},{"id":1443,"data":3593,"type":218,"tunes":3594},{"text":1445},{},{"id":1448,"data":3596,"type":42,"tunes":3597},{"text":1450,"level":253},{},{"id":1453,"data":3599,"type":218,"tunes":3600},{"text":1455},{},{"id":1458,"data":3602,"type":218,"tunes":3603},{"text":1460},{},{"id":1463,"data":3605,"type":218,"tunes":3606},{"text":1465},{},{"id":1468,"data":3608,"type":661,"tunes":3609},{"url":1470,"title":1471,"excerpt":1472,"ctaLabel":1473},{},{"id":1476,"data":3611,"type":42,"tunes":3612},{"text":1478,"level":253},{},{"id":1481,"data":3614,"type":1481,"tunes":3626},{"items":3615,"title":1524},[3616,3617,3618,3619,3620,3621,3622,3623,3624,3625],{"id":1485,"answer":1486,"question":1487},{"id":1489,"answer":1490,"question":1491},{"id":1493,"answer":1494,"question":1495},{"id":1497,"answer":1498,"question":1499},{"id":1501,"answer":1502,"question":1503},{"id":1505,"answer":1506,"question":1507},{"id":1509,"answer":1510,"question":1511},{"id":1513,"answer":1514,"question":1515},{"id":1517,"answer":1518,"question":1519},{"id":1521,"answer":1522,"question":1523},{},{"id":1527,"data":3628,"type":42,"tunes":3629},{"text":1529,"level":253},{},{"id":1532,"data":3631,"type":1532,"tunes":3645},{"title":1534,"entries":3632},[3633,3634,3635,3636,3637,3638,3639,3640,3641,3642,3643,3644],{"term":1537,"anchor":1538,"definition":1539},{"term":1541,"anchor":1542,"definition":1543},{"term":1545,"anchor":1546,"definition":1547},{"term":1549,"anchor":1550,"definition":1551},{"term":367,"anchor":1553,"definition":1554},{"term":1556,"anchor":1557,"definition":1558},{"term":1560,"anchor":1561,"definition":1562},{"term":1564,"anchor":1565,"definition":1566},{"term":1568,"anchor":1569,"definition":1570},{"term":1572,"anchor":1573,"definition":1574},{"term":1576,"anchor":1577,"definition":1578},{"term":1580,"anchor":1581,"definition":1582},{},{"id":1585,"data":3647,"type":42,"tunes":3648},{"text":1587,"level":253},{},{"id":1590,"data":3650,"type":218,"tunes":3651},{"text":1592},{},{"id":1595,"data":3653,"type":218,"tunes":3654},{"text":1597},{},{"id":1600,"data":3656,"type":218,"tunes":3657},{"text":1602},{},{"id":1605,"data":3659,"type":42,"tunes":3660},{"text":1607,"level":253},{},{"id":1610,"data":3662,"type":218,"tunes":3663},{"text":1612},{},{"id":1615,"data":3665,"type":1622,"tunes":3668},{"link":1617,"meta":3666},{"image":3667,"title":1620,"description":1621},{"url":419},{},{"id":1625,"data":3670,"type":1622,"tunes":3673},{"link":1627,"meta":3671},{"image":3672,"title":1630,"description":1631},{"url":419},{},{"id":1634,"data":3675,"type":1622,"tunes":3678},{"link":1636,"meta":3676},{"image":3677,"title":1639,"description":1640},{"url":419},{},{"id":1643,"data":3680,"type":1622,"tunes":3683},{"link":1645,"meta":3681},{"image":3682,"title":1648,"description":1649},{"url":419},{},{"id":1652,"data":3685,"type":1622,"tunes":3688},{"link":1654,"meta":3686},{"image":3687,"title":1657,"description":1658},{"url":419},{},{"id":1661,"data":3690,"type":1622,"tunes":3693},{"link":1663,"meta":3691},{"image":3692,"title":1666,"description":1667},{"url":419},{},{"id":1670,"data":3695,"type":1622,"tunes":3698},{"link":1672,"meta":3696},{"image":3697,"title":1675,"description":1676},{"url":419},{},{"id":1679,"data":3700,"type":1622,"tunes":3703},{"link":1681,"meta":3701},{"image":3702,"title":1684,"description":1685},{"url":419},{},"Post erfolgreich abgerufen",{"items":3706,"source":3791,"manualIds":3792,"manualMatchedIds":3793},[3707,3714,3721,3728,3735,3742,3749,3756,3763,3770,3777,3784],{"id":3708,"slug":3709,"title":3710,"excerpt":3711,"featuredImage":3712,"publishedAt":3713},"485","enterprise-ai-architecture-what-changes-when-ai-enters-a-company","企业AI架构：当AI进入公司时会发生什么变化","企业AI架构阐释了AI如何在数据权限、身份、许可、提供商、风险、治理、评估、合规和运营方面改变公司系统。","\u002Fuploads\u002F2026\u002F10\u002Fenterprise-ai-architecture-what-changes-when-ai-enters-a-company-1791478161363-czrwaq.webp","2026-10-08T10:48:00.000Z",{"id":3715,"slug":3716,"title":3717,"excerpt":3718,"featuredImage":3719,"publishedAt":3720},"476","mcp-vs-a2a-vs-ucp-vs-ap2-vs-a2ui-the-agent-protocol-stack-explained","MCP vs A2A vs UCP vs AP2 vs A2UI：智能体协议栈详解","MCP、A2A、UCP、AP2 和 A2UI 常被描述为相互竞争的智能体标准。它们大多解决的是不同的互操作性问题。本指南将每个协议映射到其实际标准化的边界，并展示它们如何在同一个生产系统中协同工作。","\u002Fuploads\u002F2026\u002F09\u002Fmcp-vs-a2a-vs-ucp-vs-ap2-vs-a2ui-the-agent-protocol-stack-explained-1790352625869-2ezle0.webp","2026-09-25T12:09:00.000Z",{"id":3722,"slug":3723,"title":3724,"excerpt":3725,"featuredImage":3726,"publishedAt":3727},"483","what-is-an-ai-solution-architect-system-boundaries-responsibilities-and-trade-offs","什么是AI解决方案架构师？系统边界、职责与权衡","AI解决方案架构师将业务需求转化为生产就绪的AI系统，涵盖数据、模型、工具、安全、运行时、评估和运维。","\u002Fuploads\u002F2026\u002F10\u002Fwhat-is-an-ai-solution-architect-system-boundaries-responsibilities-and-trade-offs-1791476643267-1st5xz.webp","2026-10-08T12:23:00.000Z",{"id":3729,"slug":3730,"title":3731,"excerpt":3732,"featuredImage":3733,"publishedAt":3734},"470","what-should-an-ai-agent-remember-forget-recompute-or-retrieve-again","AI代理应该记住、遗忘、重新计算还是再次检索什么？","长时间运行的代理不应记住所有内容。本文提供了一个实用的生命周期模型，用于决定哪些内容应属于持久记忆、哪些内容应重新检索、哪些内容重新计算更安全，以及哪些内容应过期或被取代。","\u002Fuploads\u002F2026\u002F09\u002Fwhat-should-an-ai-agent-remember-forget-recompute-or-retrieve-again-1790351131087-iehz28.webp","2026-09-25T09:43:00.000Z",{"id":3736,"slug":3737,"title":3738,"excerpt":3739,"featuredImage":3740,"publishedAt":3741},"479","where-does-an-llm-get-its-data-rag-data-sources-in-python","LLM从哪里获取数据？Python中的RAG数据源","LLM 并不会神奇地知道你的文件、数据库或 API。这个 RAG 系列的实用续篇用简单的 Python 展示了外部数据如何变成可检索的证据：从文本文件和 SQL 到全文搜索、嵌入、上下文组装以及最终的 LLM 调用。","\u002Fuploads\u002F2026\u002F09\u002Fwhere-does-an-llm-get-its-data-rag-data-sources-in-python-1790517200521-nfsi5i.webp","2026-09-27T05:51:00.000Z",{"id":3743,"slug":3744,"title":3745,"excerpt":3746,"featuredImage":3747,"publishedAt":3748},"487","vector-databases-embeddings-and-reranking-three-different-parts-of-retrieval","向量数据库、嵌入和重排序：检索的三个不同部分","嵌入表示含义，向量数据库检索候选结果，重排序器则精炼结果。了解这三个检索层在RAG中如何不同并协同工作。","\u002Fuploads\u002F2026\u002F10\u002Fvector-databases-embeddings-and-reranking-three-different-parts-of-retrieval-1791480129884-9dtasz.webp","2026-10-08T11:21:00.000Z",{"id":3750,"slug":3751,"title":3752,"excerpt":3753,"featuredImage":3754,"publishedAt":3755},"468","ai-agent-memory-is-not-rag-how-to-separate-memory-retrieval-state-and-context","AI代理记忆不是RAG：如何区分记忆、检索、状态和上下文","代理记忆、RAG、状态和上下文经常被当作可以互换的概念来使用。它们并不是。这个实用的架构模型将这四个层次区分开来，展示了每一层各自应处的位置，并解释了当系统将它们合并为一层时会出现什么问题。","\u002Fuploads\u002F2026\u002F09\u002Fai-agent-memory-is-not-rag-how-to-separate-memory-retrieval-state-and-context-1790350560308-np0xy6.webp","2026-09-25T11:34:00.000Z",{"id":3757,"slug":3758,"title":3759,"excerpt":3760,"featuredImage":3761,"publishedAt":3762},"484","what-is-an-ai-platform-architect-models-data-runtime-security-and-operations","什么是AI平台架构师？模型、数据、运行时、安全与运维","AI平台架构师负责跨模型、提供商、检索、智能体、身份、安全、评估、可观测性和运营设计可复用的AI基础。","\u002Fuploads\u002F2026\u002F10\u002Fwhat-is-an-ai-platform-architect-models-data-runtime-security-and-operations-1791477229171-ou3zcc.webp","2026-10-08T12:32:00.000Z",{"id":3764,"slug":3765,"title":3766,"excerpt":3767,"featuredImage":3768,"publishedAt":3769},"381","enterprise-grade-multi-tenant-architecture-for-an-international-platform","企业级多租户架构，适用于国际平台","Loving Rocks 是一款企业级婚礼平台，采用真正的多租户架构设计，实现租户间数据库隔离，并内置国际化支持，以确保全球可扩展性、安全性及长期运营稳定性。","\u002Fuploads\u002F2026\u002F01\u002Fenterprise-grade-multi-tenant-architecture-for-an-international-platform-1769789121298-b6v7ak.webp","2026-01-30T12:04:00.000Z",{"id":3771,"slug":3772,"title":3773,"excerpt":3774,"featuredImage":3775,"publishedAt":3776},"490","rbac-vs-tenant-isolation-two-different-security-boundaries","RBAC与租户隔离：两种不同的安全边界","RBAC 控制用户可以做什么；租户隔离控制该操作可以触及哪个租户的资源。了解为什么多租户 SaaS 安全需要这两道边界。","\u002Fuploads\u002F2026\u002F10\u002Frbac-vs-tenant-isolation-two-different-security-boundaries-1791485111528-qqtzby.webp","2026-10-08T14:43:00.000Z",{"id":3778,"slug":3779,"title":3780,"excerpt":3781,"featuredImage":3782,"publishedAt":3783},"489","agentic-ai-explained-when-an-ai-system-can-plan-use-tools-and-act","智能体AI解析：当AI系统能够规划、使用工具并采取行动","代理式AI在多步执行循环中使用模型，这些模型可以在明确的运行时和权限边界内选择工具、观察结果、更新状态并调整其下一步行动。","\u002Fuploads\u002F2026\u002F10\u002Fagentic-ai-explained-when-an-ai-system-can-plan-use-tools-and-act-1791481499084-wnji2a.webp","2026-10-08T11:43:00.000Z",{"id":3785,"slug":3786,"title":3787,"excerpt":3788,"featuredImage":3789,"publishedAt":3790},"486","source-of-truth-in-ai-systems-where-reliable-knowledge-actually-comes-from","AI系统中的真相来源：可靠知识究竟从何而来","事实来源（Source of Truth）定义了对于特定事实或状态，哪个来源具有权威性。了解它与RAG、溯源、记忆、上下文、向量数据库和记录系统有何不同。","\u002Fuploads\u002F2026\u002F10\u002Fsource-of-truth-in-ai-systems-where-reliable-knowledge-actually-comes-from-1791479103235-6bq9em.webp","2026-10-08T13:02:00.000Z","fallback",[],[]]