Air-gap install
On the internet side:
sapctl bundle export \ --name sapctl-airgap \ --version 1.0.0 \ --include specs,recipes,binary \ --dir ./company \ --out sapctl-airgap-1.0.0.tar.gzCarry over (USB, cross-domain transfer). On the air-gap side:
sapctl bundle verify --bundle sapctl-airgap-1.0.0.tar.gzsapctl bundle install --bundle sapctl-airgap-1.0.0.tar.gz \ --dest /opt/sapctlVerification refuses on hash mismatch, signature failure, or path-traversal attempts in the tar.