Skip to main content

Air-gapped mode

Air-gapped mode runs Cloud Cost Analyzer's rule engine entirely on your own host. Your scan data (resource inventory, metrics, findings) never leaves your environment: the CLI analyzes locally and only a signed license file is fetched from the control plane. This is the deployment enterprises reach for when cloud account data can't transit a third-party service.

Honest by design

Air-gapped enforcement is inherently client-side, so it is an anti-casual-sharing control, not a hard security boundary. Licenses are short-lived and scoped; renew before expiry. We tell you this plainly rather than overselling it.

What stays local​

Runs on your hostLeaves your host
Resource collection, metrics, rule evaluation, findings, reportsOnly the activation-code exchange that fetches your signed license

Because scan data stays on the host, our control plane holds only licenses, entitlements, and metadata, which is a meaningful confidentiality posture for regulated buyers.

Prerequisites​

  • The air-gapped add-on enabled on your plan (see the License page in your dashboard, or contact us).
  • The standard cca binary. Released binaries include the offline rule engine, so no special build is needed.

Setup​

1. Get an activation code from the air-gapped License page in your dashboard. Codes are single-use and short-lived.

2. Redeem it on the target host:

cca license fetch <activation-code>

This writes your signed license to ~/.cloud-cost-analyzer/license.json (mode 0600) and prints the path.

3. Run scans locally with --mode local (or export CCA_MODE=local):

cca --mode local scan --provider aws --regions us-east-1

All rules run on the host; no findings are sent anywhere.

4. Check license status any time:

cca license show    # scopes, expiry, and network profile
cca license path # print the resolved license path

Renewal and revocation​

Licenses carry an expiry (cca license show reports it). Fetch a fresh activation code and re-run cca license fetch before it lapses. To force a refresh of the revocation list on a connected host:

cca license refresh-crl

Environment variables​

VariablePurpose
CCA_MODESet to local for air-gapped scans (default managed).
CCA_LICENSE_FILEPath to the license file, if not the default location.
CCA_LICENSEBase64-encoded license, as an alternative to a file.
CCA_BUNDLE_PATHPath to a signed rule bundle, for fully offline rule updates.

Compliance​

Air-gapped mode keeps customer scan data on the customer host, shrinking the data we are accountable for. Cloud Cost Analyzer does not claim SOC 2 certification; the on-host data posture is a genuine confidentiality benefit independent of any attestation.

Troubleshooting​

--mode local errors that it requires an air-gapped build: update to the latest release; current binaries ship the offline rule engine compiled in.

cca license fetch fails: activation codes are single-use and expire quickly; generate a fresh one from the dashboard and retry.