This repository contains my proposed solution for deploying the OpenFn platform (Lightning, Worker, Postgres) in a highly secure government environment that is completely disconnected from the internet (air-gapped).
In line with the project requirements, the focus has been on operational simplicity, low resource consumption (suited to the server’s 8 GB of RAM) and complete autonomy for a local IT maintenance technician, achieved through a pragmatic approach based on Docker Compose.
-
bundle/: Contains the technical piping for the connected machine.-
build-bundle.sh: The Bash script that automates the downloading, saving and packaging of components. -
docker-compose.yml: The multi-container configuration has been set up and is ready for production. -
.env.complete.example: Default template configuration for environment variables/secrets
-
-
RUNBOOK.md: A step-by-step user guide for the Ministry’s IT officer covering installation, validation and troubleshooting (specifically regarding the Crash Loop). -
DECISIONS.md: A brief strategic note outlining the rationale behind my architectural choices (image management, secrets, updates, observability) and the associated trade-offs.
You can simulate the entire deployment workflow directly on your local machine in two main steps:
Navigate to the bundle/ directory and run the build script:
cd bundle
chmod +x build-bundle.sh
./build-bundle.shThe script will download the stable images, export them, inject a .env.example template, and generate two files in the project root directory: openfn-lightning-airgap-bundle.tar.gz and its security fingerprint, openfn-lightning-airgap-bundle.tar.gz.sha256.
To test the behaviour of the Ministry’s IT agent:
-
Move the two generated files (
.tar.gzand.sha256) to a completely empty folder or an isolated VM. -
(Optional) Disable your Wi-Fi/Internet connection to ensure 100% offline operation.
-
Follow the step-by-step instructions provided in the RUNBOOK.md file carefully to verify the checksum, load the images, configure the secrets and validate the application startup.
Note for the assessor: To help you mark this exercise, here is the actual time spent on this task.
-
Total time spent:
~5 hours-
Research & Understanding the brief:
~30 mins -
Writing the packaging script and composition:
~2 hours -
Drafting the documentation (Runbook, Decisions & README):
~2 hours -
Polishing (docs enhancement, code cleaning, etc) :
~30 mins
-