Hi everyone,
I'm working on a project for my company where our deployment environment is completely air-gapped (no internet at all). My lead suggested we try OpenClaw for SCA, but all the docs talk about cloud connectivity or downloading fresh DBs.
Has anyone actually set it up offline? My main questions:
1. How do you get the vulnerability database into the isolated network? Is it just a file transfer, or is there a special "offline bundle"?
2. Once it's inside, does the scan engine run without phoning home? I saw a `--offline` flag in the CLI help, but it wasn't clear.
I tried a quick test in a disconnected VM and got stuck. The install via package manager worked, but it failed immediately when scanning because it couldn't fetch the DB.
```bash
$ openclaw scan ./mycode
ERROR: Cannot update vulnerability database. Network unreachable.
```
Do you pre-load the DB into a specific directory? Any config example would be super helpful. I'm worried about the maintenance too—how do you update the DB later without internet?
Thanks for any tips!
Yes, they do have an official offline bundle, but it's not well-documented. Look for the "airgap" release assets on their GitHub. It's a tarball containing the compiled database.
The `--offline` flag should work if you point the tool to a local database directory. You'll need to set `OPENCLAW_DB_DIR` or use the `--db` flag. Try this after extracting the bundle:
```bash
openclaw scan --offline --db /path/to/offline_db ./mycode
```
For updates, you're stuck with manually transferring new bundle files on a schedule. It's a maintenance trade-off - you get isolation but lose automatic CVE updates. Consider if a stale DB for weeks at a time is an acceptable risk for your environment.
Less spend, more headroom.
That's a good tip about the airgap assets. I've been looking at their GitHub releases and I still can't find it. Are they under a tag or maybe on a separate downloads page? The repo structure is confusing.
Also, about the stale database risk. Have you seen any data on how quickly an outdated OpenClaw DB becomes a real problem? I'm trying to build a case for the update schedule.
The bundle's buried. Look for "openclaw-offline-db-vX.Y.Z.tar.gz" on the main GH releases page. It's never in the main repo.
On stale data, that's the whole point of air-gap, isn't it? You're trading real-time risk for operational control. A week-old DB will miss fresh CVEs, but that's probably fine if you're already patching on a quarterly cycle. The bigger risk is forgetting to update it for six months. Seen it happen.
Just my two cents.