Skip to content

Latest commit

 

History

8 Commits

Folders and files

NameName
Last commit message
Last commit date
 
 
 
 
 
 
 
 
 
 
 
 

Repository files navigation

UDS Bundle Development & Test (uds-bundle-dev-test)

Status: Active Defense Unicorns: UDS Bundle Packaging: Zarf + Syft SBOM Tier: 3 Bundle Engineering

A dedicated developer workspace for authoring, packaging, and testing Defense Unicorns UDS Bundles and Zarf Packages on a connected machine before shipping them across the air-gap barrier.

In an air-gapped delivery model, you need a clean separation of implementation layers:

  • Tier 1 (Substrate Layer): Provisions the isolated hardware or VM compute target (orangepi-airgapped / airgapped-sandbox-vm).
  • Tier 2 (Platform Prep Layer): Prepares that target with the offline Kubernetes runtime and runs zarf init to stand up the in-cluster registry (uds-platform-prep).
  • Tier 3 (Bundle & Workload Layer): This repository. It authors modular zarf.yaml packages with automated SBOM generation, aggregates them into top-level uds-bundle.yaml bundles, and compiles self-contained .tar.zst artifacts.

The resulting Tier 3 bundles are deployed directly onto the target system that was prepared by Tier 2 on top of Tier 1 infrastructure, executing uds deploy with zero external dependencies.


3-Tier Layered Hierarchy

flowchart TD
    subgraph T1 ["Tier 1: Target Substrates (Underlying Compute Targets)"]
        direction LR
        OPI["orangepi-airgapped\n(Physical Bare-Metal ARM64 SBC)"]
        KVM["airgapped-sandbox-vm\n(Nested KVM Hypervisor Sandbox)"]
        AWS["AWS Infrastructure\n(EC2 Spot K3s / Managed EKS)"]
    end

    subgraph T2 ["Tier 2: Platform Preparation (uds-platform-prep)"]
        direction LR
        PREP["uds-platform-prep\n(Toolchain Ingestion • K3s/RKE2/Talos • In-Cluster zarf init)"]
    end

    subgraph T3 ["Tier 3: Software & Bundle Engineering (This Repo: uds-bundle-dev-test)"]
        direction LR
        DEV["uds-bundle-dev-test\n• Modular Zarf Package Authoring\n• UDS Bundle Assembly (.tar.zst)\n• Pre-flight Air-Gap Validation"]
        LAKE["zarf-uds-lula-datalakehouse\n(Mission Lakehouse • Istio mTLS • Lula OSCAL ATO)"]
    end

    T1 ==>|"Clean, Isolated Target Ready"| T2
    T2 ==>|"UDS-Ready Cluster"| T3
Loading

For the architectural rationale, see ADR 0001: Separation of Environment Infrastructure and UDS Bundle Lifecycles.


Directory Structure

uds-bundle-dev-test/
├── bundles/                # Top-level UDS bundle definitions
│   ├── uds-bundle.yaml     # Bundle orchestrating Zarf packages & dependencies
│   └── zarf.yaml           # Demo / local package definition
├── packages/               # Modular Zarf packages (apps, services, tools)
├── scripts/                # Development, build, and validation scripts
│   ├── build-bundle.sh     # Builds Zarf packages and creates .tar.zst bundle
│   ├── test-deploy.sh      # Tests deploying the bundle to a cluster
│   └── verify-airgap.sh    # Audits network isolation / zero egress
├── docs/                   # Architecture decision records & guides
│   └── adr/
│       └── 0001-separation-of-environment-and-bundle-lifecycle.md
└── README.md

Getting Started

Prerequisites (Connected Machine)

  • UDS CLI (uds)
  • Zarf CLI (zarf)
  • Lula CLI (optional, for compliance validation)
  • Docker or Podman (for packaging container images)

1. Build the UDS Bundle

Run the build script on your connected workstation to package all container images and manifests into a single offline artifact:

./scripts/build-bundle.sh

The compiled bundle (uds-bundle-<name>-<arch>-<version>.tar.zst) will be generated in build/.

2. Deliver and Deploy to Air-Gapped Sandbox

Transfer the generated .tar.zst artifact to the target air-gapped test environment (e.g., your Dell T5600 sandbox node) and run:

uds deploy ./build/uds-bundle-*.tar.zst --confirm

Testing & Verification

  • Air-Gap Network Audit: Run ./scripts/verify-airgap.sh inside the target VM to assert zero WAN egress prior to deployment.
  • Cluster Deployment Test: Run ./scripts/test-deploy.sh against the active KUBECONFIG.

About

Connected workspace for authoring modular Zarf packages, assembling UDS bundles (.tar.zst), and validating zero-egress deployments.

Topics

Resources

Stars

0 stars

Watchers

0 watching

Forks

Releases

Packages

Contributors

Languages