Alle Artikel

Why zero CVEs matters in mobile airgapped deployments

Mike Barretta, Senior Manager, Solutions Engineering

Disconnected operation is the norm, not the exception

For a lot of the systems that matter most to national security, "always connected" was never the plan. Workloads run inside a sensitive compartmented information facility (SCIF), aboard ship, or at the tactical edge, and they routinely operate for weeks or months with no path back to the public internet.

Most modern security tooling assumes the opposite. Continuous scanning, streaming patches, and live vulnerability feeds all assume a network that's there when you need it. The day your system goes dark in a mobile environment, that assumption breaks, and your security posture freezes exactly where it was at the time of disconnect. Whatever you shipped with is what you're operating with until reconnect.

That single fact is why the state of your container images at departure matters more than almost anything else you do.

The accumulation problem

When you disconnect, your patches stop flowing. What doesn't stop is the rest of the world disclosing vulnerabilities.

Common Vulnerabilities and Exposures (CVEs) keep getting published against the exact software sitting frozen in your base images. You’re getting more vulnerable because the public record of what's wrong with your software keeps growing while you have no way to respond.

A typical open source image stack doesn't start with zero CVEs. It's common to begin with hundreds of known CVEs on day zero. Leave that stack disconnected for six months while disclosures pile up, and you can reconnect to thousands of documented, unpatched vulnerabilities. Every one of them is public, and every one is now part of your audit story.

Why the starting point decides everything

Once you're dark, the one variable you actually controlled is already locked in: the state of your images at the moment you disconnected. Two levers move that starting point.

First, start near zero. Chainguard Containers have 97.6% fewer CVEs than open source equivalents. When your curve begins at the floor instead of in the hundreds, six months of accumulation lands you somewhere a triage team can actually handle.

Second, stay fresh until departure. Chainguard rebuilds every image daily from source, and the team eliminates critical CVEs in under 20 hours on average. Pull right before you leave, and your last image is days old at most, not a quarterly snapshot that was already stale when it shipped.

Start low and start fresh, and the accumulation curve begins as low as it can.

Minimal images flatten the curve further

Starting low is one thing. How fast the count climbs while you're disconnected is another, and that's a function of how much software you carry.

Every package in an image is a potential landing spot for a future CVE. Carry a full distribution with a shell, a package manager, and hundreds of libraries you never call, and you've handed the next six months of disclosures a large target. Chainguard Containers are distroless and minimal, which is why they have an 80% lower CVE accumulation rate than industry alternatives. There's simply less surface area for new vulnerabilities to accrue.

Minimalism lowers the count at the beginning and changes the slope. Fewer packages mean fewer future disclosures apply to you at all, which matters most precisely when you can't patch.

What reconnect looks like in both worlds

The difference between these two approaches stays invisible right up until reconnect. Then it's the whole story.

The typical stack reconnects, and the scanner lights up. Now you're into Plan of Action and Milestones (POA&M) triage, risk acceptances, and the real possibility of a re-accreditation event. Redeployment slips while security and engineering grind through thousands of findings.

Chainguard Containers keeps you at zero CVEs, just as you started, runs routine image refreshes, and maintains its Authority to Operate (ATO) posture. There are no fire drills.

For federal systems integrators (FSIs) and primes who own reconnect remediation, multiply that difference across every disconnected program in a portfolio. The choice you make about base images is a portfolio-level cost you either pay over and over or design out once.

Practical guidance for teams shipping disconnected systems

If you're responsible for a system that's about to go dark, a few habits make reconnect boring in the best way:

  • Pull the latest images as close to departure as you can. The fresher your last pull, the lower your starting point.

  • Carry Software Bills of Materials (SBOMs) so offline scans and audits have ground truth without a network round trip.

  • Pre-stage Federal Information Processing Standards (FIPS) validated and Security Technical Implementation Guide (STIG) hardened variants for the Impact Levels you operate at (IL4, IL5, IL6).

  • Write the reconnect refresh runbook before you leave. Don’t wait until the scanner starts lighting up.

None of this changes the reality that disconnected systems must remain secure without a lifeline. It just means the version of that problem you face at reconnect is the small one. Starting at zero CVEs is the easiest way to stay secure in an airgapped environment, and everything downstream, from the accumulation curve to the reconnect scan to the ATO posture, is decided by where you begin.

Learn more about how Chainguard provides secure open source software for public-sector agencies and institutions.

Share this article

Verwandte Artikel

Want to learn more about Chainguard?

Contact us