Air-gapped install
The same steps install SegAudit the first time and update it later. Your license file is never touched.
On a single offline workstation, the desktop installer is simpler: carry the installer across and run it. The steps below are for a jump host or server running the container image.
-
On a connected machine, download the bundle for the jump host’s CPU with its
.sha256,.sigstore.jsonandtrusted_root.jsonfiles, and verify the signature. -
Move the four files across with your approved transfer process and keep them in one folder.
-
On the jump host, in the folder that holds (or will hold)
docker-compose.ymlandlicence/:Terminal window tar -xzf segaudit-X.Y.Z-linux-amd64.tar.gz ./segaudit-update # first time only./segaudit-update segaudit-X.Y.Z-linux-amd64.tar.gzIt refuses a bundle whose SHA-256 does not match or that was built for another CPU type. If Cosign is installed on the jump host, it checks the signature again offline with
trusted_root.json. Then it loads the image and starts it. -
Open the app from a browser that can reach the jump host. Load the XML and CSV from local disk. Nothing is posted off the host.
To roll back, run segaudit-update with the older bundle. Every release stays downloadable for at least 10 years.
When a release ships a changed docker-compose.yml, segaudit-update saves it as docker-compose.yml.new and leaves yours in place. A newer segaudit-update arrives the same way, as segaudit-update.new.
The app makes no network requests of its own: fonts and assets are bundled, and there is no telemetry or update check. Check the updates page or its feed for new releases, and security advisories for fixes. Usage counts for renewal stay in the browser until you save a usage report from the License page and carry it out yourself.