Case study

Air-Gapped Observability Platform for Critical Infrastructure

How SquareShift deployed a production-grade, air-gapped Elastic Stack to meet strict compliance, security, and one-year log-retention requirements.

Book a session
6High-volume data nodes deployed in the production cluster
1 yearMandated log-retention window met for compliance
v9.0.1Elastic Stack deployed fully air-gapped, secured with SSL/TLS and LDAP-based RBAC

A critical-infrastructure operator running mandatory air-gapped systems for compliance and operational visibility.

Its environment has no external network access, so every registry, update, and data feed had to be sourced and verified internally.

Impact

High-volume data nodes deployed in the production cluster. Mandated log-retention window met for compliance. Elastic Stack deployed fully air-gapped, secured with SSL/TLS and LDAP-based RBAC.

Key services
ClCloud Modernization
PePlatform & Software Engineering
Industry

Critical Infrastructure

Key technologies / platforms

Elasticsearch · Kibana · Logstash · Fleet Server · Red Hat OpenShift · LDAP

The engagement

How SquareShift delivered it.

The challenge

The client operates in a critical-infrastructure environment with no tolerance for external network dependencies, so any observability platform had to run fully air-gapped — no live connection to public package registries, no outside path for updates or telemetry.

On top of that isolation, the platform had to satisfy a mandatory one-year log-retention rule and give the team real visibility across a mix of OpenShift, Windows, Linux, and network infrastructure from Cisco and Fortinet.

What we delivered

SquareShift stood up a highly available, multi-node production Elastic cluster — Elasticsearch, Kibana, Logstash, and Fleet Server — backed by a separate monitoring cluster watching the main stack’s own health, all on Elastic Stack v9.0.1.

Because nothing could reach the public internet, the team built local, air-gapped package and artifact registries (EPR/EAR) for internal distribution, secured every connection with client-issued CA-signed SSL/TLS certificates, and integrated the cluster with LDAP for centralized authentication and role-based access. Data sources came in through Elastic Agents on OpenShift, Linux, and Windows, plus Logstash pipelines for Cisco and Fortinet syslog, with centralized pipeline management to keep it maintainable.

The payoff

The client now runs a production-grade observability platform that never has to reach an external network to operate, update, or distribute packages — a hard requirement in this environment, not a nice-to-have.

Six high-volume data nodes carry the load, the one-year retention mandate is met, and LDAP-based access control plus end-to-end TLS keep the platform’s own security posture consistent with the systems it’s watching.

An air-gapped deployment isn't just Elastic without internet access — every registry, certificate, and integration has to be re-earned locally before day one.

Cloud Modernization Practice Lead, SquareShift