Skip to content
Has anyone tried ru...
 
Notifications
Clear all

Has anyone tried running Claw on a local air-gapped network? The setup docs are fantasy.

64 Posts
60 Users
0 Reactions
226 Views
(@amyw)
Honorable Member
Joined: 2 months ago
Posts: 427
 

Been there. That "offline bundle" is the worst part. The 12GB tar is a lazy container image dump that includes their entire CI cache. You can shave off 40% by extracting and deduping the layers yourself before pushing to your internal registry.

The hard-coded registry script is brutal. Had to patch ours with sed to accept a configurable CA bundle path. It's insane that a product marketed for secure on-prem doesn't support basic PKI.

Their docs are written for a perfect lab, not a real network.


measure twice, ship once


   
ReplyQuote
(@contrarian_kevin)
Honorable Member
Joined: 3 months ago
Posts: 418
 

You're assuming the hash manifest is even intended to reflect a real deployment. It's just a legal disclaimer. They shipped a pile of bits, their job is done.

The delayed metrics ping is a feature, not a bug. It means their "offline" validation is a staged rollout where you only find out it's broken when a VIP tries to log in. That's deliberate risk management, just not for you.


Just saying.


   
ReplyQuote
(@gregm)
Honorable Member
Joined: 3 months ago
Posts: 424
 

That's not a configuration file, that's a hostage letter. The moment you see hard-coded paths and a complete disregard for self-signed certs in an "enterprise" product, you know their security posture is just a sales deck.

The real joke is that self-signed certs are a basic control in air-gapped setups. If they missed that, what else did they build that assumes a perfect, trusted corporate network? Probably everything.


Trust but verify


   
ReplyQuote
(@gracec)
Reputable Member
Joined: 3 months ago
Posts: 315
 

Exactly. A disregard for self-signed certs isn't just an oversight, it's a fundamental disconnect from the reality of secure, isolated environments. It means their entire QA cycle likely runs on internal corporate WiFi with a trusted root CA, which explains why the delayed egress calls for "recommended modules" go unnoticed until a real user triggers them weeks later.

We had to build a proxy simulator just to catalog all the outbound attempts over a month. The list was shocking - license checks, telemetry, even calls to a public font CDN that were buried in a web UI component. Each one was a hard-coded URL that broke our deployment.

If they can't handle basic certificate pinning, you have to assume the product's internal security controls are just as naive.


The right tool saves a thousand meetings.


   
ReplyQuote
Page 5 / 5