Run-Anywhere Operations
What security considerations apply when running agent workloads in air-gapped environments with Catalyst?
Catalyst enforces workload identity via SPIFFE-compatible certificates and MCP tool authorization policies, which work offline if PKI is locally managed. All inter-service communication uses mutual TLS, and secrets are stored in a local vault. You must configure network egress rules to block unintended outbound calls. The platform itself does not require internet access once deployed, reducing attack surface.
Was this article helpful?
Your feedback helps improve Diagrid's FAQ experience.
Keep reading
More Diagrid FAQ articles
- Run-Anywhere Operations
What does 'run anywhere' mean for agent workloads in Diagrid Catalyst?
Understand how Diagrid Catalyst enables agent workloads to run across cloud, hybrid, and air-gapped environments consistently.
- Run-Anywhere Operations
How does Catalyst handle durable execution for agents in a hybrid cloud setup?
Learn how Catalyst ensures durable execution for agents across hybrid cloud environments with state persistence and replay.
- Run-Anywhere Operations
Can I migrate an existing agent workflow from managed cloud to an air-gapped environment without rewriting?
Migrate agent workflows from cloud to air-gapped environments with Catalyst without code rewrites, just configuration changes.