Patching endpoints in an isolated, air-gapped environment
A computer-implemented method may include querying a centralized patch repository for new patch data; receiving a confirmation that there is new patch data in the centralized patch repository; spinning-up a proxy in an isolated computing environment in response to the receiving the confirmation; disabling an air-gap of the isolated computing environment configured to receive the new patch data; and receiving the new patch data at the isolated computing environment from the centralized patch repository.
1 . A method, comprising:
querying, by a computing device, a centralized patch repository for new patch data;
receiving, by the computing device, a confirmation that there is new patch data in the centralized patch repository;
spinning-up, by the computing device, a proxy in an isolated computing environment in response to the receiving the confirmation;
disabling, by the computing device, an air-gap of the isolated computing environment configured to receive the new patch data; and
receiving, by the computing device, the new patch data at the isolated computing environment from the centralized patch repository.
2 . The method of claim 1 , further comprising:
querying, by the computing device, the centralized patch repository for a success criteria of the receiving the new patch data; and
enabling, by the computing device, the air-gap based on the success criteria comprising enabling gateway firewall rules configured to block network communication with the centralized patch repository.
3 . The method of claim 1 , further comprising spinning-down the proxy based on a success criteria, wherein the spinning-down comprises powering off or disabling the proxy in the isolated environment.
4 . The method of claim 1 , wherein the spinning-up comprises powering on or enabling the proxy in the isolated environment.
5 . The method of claim 1 , wherein the air-gap comprises gateway firewall rules configured to block network communication with the centralized patch repository.
6 . The method of claim 1 , wherein the air-gap comprises a virtual network layer comprising tiered gateways configured to block network communication with the centralized patch repository.
7 . The method of claim 1 , wherein the air-gap is configured to prevent network communication between the proxy and the centralized patch repository in response to the air-gap being enabled and allow network communication between the proxy and the centralized patch repository in response to the air-gap being disabled.
8 . The method of claim 1 , wherein the centralized patch repository is external from the proxy.
9 . The method of claim 1 , wherein the computing device includes software provided as a service in a cloud environment.
10 . A computer program product comprising one or more computer readable storage media having program instructions collectively stored on the one or more computer readable storage media, the program instructions executable to:
query a centralized patch repository for new patch data;
receive a confirmation that there is new patch data in the centralized patch repository;
spin-up a proxy in an isolated computing environment in response to the receiving the confirmation;
disable an air-gap of the isolated computing environment configured to receive the new patch data; and
receive the new patch data at the isolated computing environment from the centralized patch repository.
11 . The computer program product of claim 10 , wherein the program instructions are further executable to:
query the centralized patch repository for a success criteria of the receiving the new patch data; and
enable the air-gap based on the success criteria comprising enabling gateway firewall rules configured to block network communication with the centralized patch repository.
12 . The computer program product of claim 10 , wherein the program instructions are further executable to spin-down the proxy based on a success criteria, wherein the spinning-down comprises powering off or disabling the proxy in the isolated environment.
13 . The computer program product of claim 10 , wherein the spinning-up comprises powering on or enabling the proxy in the isolated environment.
14 . The computer program product of claim 10 , wherein the air-gap comprises gateway firewall rules configured to block network communication with the centralized patch repository.
15 . The computer program product of claim 10 , wherein the air-gap comprises a virtual network layer comprising tiered gateways configured to block network communication with the centralized patch repository.
16 . The computer program product of claim 10 , wherein the air-gap is configured to prevent network communication between the proxy and the centralized patch repository in response to the air-gap being enabled and allow network communication between the proxy and the centralized patch repository in response to the air-gap being disabled.
17 . The computer program product of claim 10 , wherein the air-gap is configured to allow network communication between the proxy and the centralized patch repository.
18 . The computer program product of claim 10 , wherein the centralized patch repository is external from the proxy.
19 . The computer program product of claim 10 , wherein the computing device includes software provided as a service in a cloud environment.
20 . A system comprising:
a processor, a computer readable memory, one or more computer readable storage media, and program instructions collectively stored on the one or more computer readable storage media, the program instructions executable to:
query a centralized patch repository for new patch data;
receive a confirmation that there is new patch data in the centralized patch repository;
spin-up a proxy in an isolated computing environment in response to the receiving the confirmation;
disable an air-gap of the isolated computing environment configured to receive the new patch data; and
receive the new patch data at the isolated computing environment from the centralized patch repository.