{"id":17228,"date":"2026-07-24T16:21:58","date_gmt":"2026-07-24T16:21:58","guid":{"rendered":"https:\/\/dmsretail.com\/RetailNews\/the-journey-towards-logically-air-gapped-deployment\/"},"modified":"2026-07-24T16:21:58","modified_gmt":"2026-07-24T16:21:58","slug":"the-journey-towards-logically-air-gapped-deployment","status":"publish","type":"post","link":"https:\/\/dmsretail.com\/RetailNews\/the-journey-towards-logically-air-gapped-deployment\/","title":{"rendered":"The Journey towards Logically Air-Gapped Deployment"},"content":{"rendered":"<p> <p><a href=\"https:\/\/dmsretail.com\/online-workshops-list\/\"><img loading=\"lazy\" decoding=\"async\" class=\"alignnone size-full wp-image-496\" src=\"https:\/\/dmsretail.com\/RetailNews\/wp-content\/uploads\/2022\/05\/RETAIL-ONLINE-TRAINING-728-X-90.png\" alt=\"Retail Online Training\" width=\"729\" height=\"91\" srcset=\"https:\/\/dmsretail.com\/RetailNews\/wp-content\/uploads\/2022\/05\/RETAIL-ONLINE-TRAINING-728-X-90.png 729w, https:\/\/dmsretail.com\/RetailNews\/wp-content\/uploads\/2022\/05\/RETAIL-ONLINE-TRAINING-728-X-90-300x37.png 300w\" sizes=\"auto, (max-width: 729px) 100vw, 729px\" \/><\/a><\/p><br \/>\n<\/p>\n<div>\n<h2>The need and ability to face the challenge with a clear plan<\/h2>\n<p>In today\u2019s technological landscape, organizations managing critical infrastructure face a complex paradox: how to leverage the agility of cloud-native environments while maintaining the absolute control and security typical of a traditional isolated, or \u201cair-gapped,\u201d infrastructure. Simultaneously, the intensification of regulatory pressures such as GDPR, NIS2, and DORA reinforces the need for digital autonomy. This document proposes a \u201clogically air-gapped\u201d governance model designed to address this challenge by extending the principles established by AWS and IBM for Data Vault scenarios across the entire application stack and its associated workflows, enabling organizations to capture cloud-native benefits while ensuring complete, autonomous, and authoritative governance of their data and infrastructure.<\/p>\n<p>This model of autonomy is built upon three core requirements that serve as the foundation for the proposed framework:<\/p>\n<ul>\n<li>Data Residency: ensuring full control over where information is stored, who can access it, and the governing legal framework.<\/li>\n<li>Technological Autonomy: mitigating vendor lock-in by embracing open standards and independent infrastructure.<\/li>\n<li>Operational Autonomy: maintaining the ability to manage digital services independently, free from the interference of third parties.<\/li>\n<\/ul>\n<p>The central challenge remains the tension between cloud agility and the necessity for such autonomy, as traditional air-gapping\u2014which requires the physical disconnection of systems\u2014is often incompatible with the dynamic nature of modern containerized applications. Consequently, the approach shifts toward a logically air-gapped architecture based on a full-stack governance model, which replaces physical barriers with a robust, software-defined cryptographic perimeter. At the heart of this innovation lies eBPF, or extended Berkeley Packet Filter, a Linux-based technology that enables high-performance, low-impact security and observability at the kernel level, effectively transforming the infrastructure into an environment that remains invisible and inaccessible to unauthorized entities.<\/p>\n<p><img loading=\"lazy\" decoding=\"async\" class=\"lazy lazy-hidden wp-image-494812 size-full aligncenter\" data-lazy-type=\"image\" src=\"https:\/\/blogs.cisco.com\/gcs\/ciscoblogs\/1\/2026\/07\/air-gap1.png\" alt=\"\" width=\"512\" height=\"306\"\/><noscript><img loading=\"lazy\" decoding=\"async\" class=\"wp-image-494812 size-full aligncenter\" src=\"https:\/\/blogs.cisco.com\/gcs\/ciscoblogs\/1\/2026\/07\/air-gap1.png\" alt=\"\" width=\"512\" height=\"306\"\/><\/noscript><\/p>\n<p style=\"text-align: center;\">Reference Books<\/p>\n<p>A concrete example of this approach\u2019s efficacy is OpenAI, which has adopted the Isovalent networking platform\u2014powered by Cilium\u2014as the standard for its Kubernetes stack. This choice has provided OpenAI with a unified foundation for managing CNI, IPAM, and L4\/L7 filtering, ensuring operational consistency across both cloud and bare-metal environments.<\/p>\n<p>It is worth noting that Isovalent was acquired by Cisco in 2024.<\/p>\n<p>Cilium leverages eBPF in a structured and organic manner, translating the raw capabilities of the kernel into an orchestrated platform capable of managing complex data flows, transparent encryption, and network segmentation with high efficiency and scalability.<\/p>\n<p>For a rapidly scaling organization, this uniformity is crucial. It supports security and compliance by eliminating the need to treat each environment as a siloed networking challenge, thereby significantly streamlining troubleshooting for platform teams.<\/p>\n<p>eBPF acts as a fundamental catalyst, providing deep, real-time visibility into network traffic and application behavior, while enabling granular, dynamic security policy enforcement directly at the kernel level.<\/p>\n<p>This \u201cLogically Air-Gapped\u201d governance model reaches its full operational potential through the implementation of \u201cLive Protect.\u201d As a runtime security module, Live Protect elevates protection from the configuration plane to that of dynamic execution. While segmentation and encryption define the perimeter, Live Protect utilizes eBPF within the kernel to monitor, detect, and mitigate threats in real-time as they attempt to bypass perimeter controls. This approach effectively evolves the infrastructure from a merely \u201cprotected\u201d environment into a \u201cself-defending\u201d one.<\/p>\n<p><img loading=\"lazy\" decoding=\"async\" class=\"lazy lazy-hidden wp-image-494813 size-medium_large aligncenter\" data-lazy-type=\"image\" src=\"https:\/\/blogs.cisco.com\/gcs\/ciscoblogs\/1\/2026\/07\/air-gap2-768x560.png\" alt=\"\" width=\"768\" height=\"560\"\/><noscript><img loading=\"lazy\" decoding=\"async\" class=\"wp-image-494813 size-medium_large aligncenter\" src=\"https:\/\/blogs.cisco.com\/gcs\/ciscoblogs\/1\/2026\/07\/air-gap2-768x560.png\" alt=\"\" width=\"768\" height=\"560\"\/><\/noscript><\/p>\n<p style=\"text-align: center;\">Isovalent Reference Stack<\/p>\n<p>In bare metal scenarios, the solution reaches its peak, extending eBPF capabilities to provide a logically isolated environment that represents the closest digital equivalent to a physical airgap. By eliminating dependency on third-party hypervisors, the company achieves total \u201cgovernance\u201d through a private control plane and superuser administration functions across the entire application stack. This approach allows for a drastic reduction in the attack surface, ensuring that even non-containerized workloads benefit from granular segmentation, secure host networks, and end-to-end protection managed with total autonomy.<\/p>\n<p><img loading=\"lazy\" decoding=\"async\" class=\"lazy lazy-hidden wp-image-494814 size-medium_large aligncenter\" data-lazy-type=\"image\" src=\"https:\/\/blogs.cisco.com\/gcs\/ciscoblogs\/1\/2026\/07\/Blog-Hero_image-768x429.jpg\" alt=\"\" width=\"768\" height=\"429\"\/><noscript><img loading=\"lazy\" decoding=\"async\" class=\"wp-image-494814 size-medium_large aligncenter\" src=\"https:\/\/blogs.cisco.com\/gcs\/ciscoblogs\/1\/2026\/07\/Blog-Hero_image-768x429.jpg\" alt=\"\" width=\"768\" height=\"429\"\/><\/noscript><\/p>\n<p style=\"text-align: center;\">Reference Architecture<\/p>\n<p>Digital autonomy is thus exercised by shifting network and security control into the operating system kernel. This tool enables deep observability without modifying source code, an essential aspect for demonstrating regulatory compliance. Isovalent, through Cilium Enterprise, extends these capabilities with transparent encryption such as WireGuard or IPsec and Egress Gateways, which force traffic toward internal checkpoints, preventing unauthorized exfiltration and ensuring that sensitive information never leaves the defined jurisdiction.<\/p>\n<p>Cisco integrates the execution power of Isovalent with the governance of Cisco Secure Workload to offer a unified security model that covers containerized, virtualized, and bare metal environments. Thanks to the integration between Cilium and systems like SPIRE, the infrastructure assigns unique cryptographic identities to workloads, eliminating dependence on the cloud provider\u2019s proprietary IAM. The integration between Hubble and analytics platforms allows for real-time flow mapping, enabling operators to identify bottlenecks or unauthorized connection attempts in seconds, drastically reducing resolution times.<\/p>\n<p>To ensure technical rigor, this governance model is based on established industry standards. The model aligns with global standards such as NIST SP 800-210, the Gaia-X trust framework, and ENISA\u2019s EUCS requirements, integrating trusted execution environments as recommended by the Confidential Computing Consortium.<\/p>\n<p>In conclusion, digital autonomy does not represent a static state, but a continuous process of control, trust, and resilience. By adopting a \u201cpresume breach\u201d mentality and leveraging the combined power of eBPF and Cisco\u2019s governance tools, enterprises can embrace innovation with confidence, while maintaining the rigorous autonomy required to protect critical infrastructure in a transparent and scalable way.<\/p>\n<h2>References:<\/h2>\n<\/p><\/div>\n<p><p><a href=\"https:\/\/dmsretail.com\/online-workshops-list\/\"><img loading=\"lazy\" decoding=\"async\" class=\"alignnone size-full wp-image-496\" src=\"https:\/\/dmsretail.com\/RetailNews\/wp-content\/uploads\/2022\/05\/RETAIL-ONLINE-TRAINING-728-X-90.png\" alt=\"Retail Online Training\" width=\"729\" height=\"91\" srcset=\"https:\/\/dmsretail.com\/RetailNews\/wp-content\/uploads\/2022\/05\/RETAIL-ONLINE-TRAINING-728-X-90.png 729w, https:\/\/dmsretail.com\/RetailNews\/wp-content\/uploads\/2022\/05\/RETAIL-ONLINE-TRAINING-728-X-90-300x37.png 300w\" sizes=\"auto, (max-width: 729px) 100vw, 729px\" \/><\/a><\/p><br \/><\/p>\n","protected":false},"excerpt":{"rendered":"<p>The need and ability to face the challenge with a clear plan In today\u2019s technological landscape, organizations managing critical infrastructure face a complex paradox: how [&hellip;]<\/p>\n","protected":false},"author":1,"featured_media":17229,"comment_status":"","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[5],"tags":[],"class_list":["post-17228","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-technology"],"_links":{"self":[{"href":"https:\/\/dmsretail.com\/RetailNews\/wp-json\/wp\/v2\/posts\/17228","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/dmsretail.com\/RetailNews\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/dmsretail.com\/RetailNews\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/dmsretail.com\/RetailNews\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/dmsretail.com\/RetailNews\/wp-json\/wp\/v2\/comments?post=17228"}],"version-history":[{"count":0,"href":"https:\/\/dmsretail.com\/RetailNews\/wp-json\/wp\/v2\/posts\/17228\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/dmsretail.com\/RetailNews\/wp-json\/wp\/v2\/media\/17229"}],"wp:attachment":[{"href":"https:\/\/dmsretail.com\/RetailNews\/wp-json\/wp\/v2\/media?parent=17228"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/dmsretail.com\/RetailNews\/wp-json\/wp\/v2\/categories?post=17228"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/dmsretail.com\/RetailNews\/wp-json\/wp\/v2\/tags?post=17228"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}