If you run a regulated, air-gapped compute fleet on RHEL-family instances, you have probably felt three requirements pulling against each other. Your organization must configure the network to remove internet access from the instances. Your team must review and approve new packages or version upgrades before you adopt them. Your team removes public repository definitions, restricts network paths, and configures instances to use only the internal repository your team has approved.

Teams in chip design, finance, healthcare, defense, and the public sector often face this combination while still needing operating system updates. This post describes a two-account pattern that separates the connected package-ingestion path from the air-gapped fleet. You create an authorized initial baseline and approve later changes to form a versioned package snapshot in Amazon Simple Storage Service (Amazon S3) . EC2 Image Builder uses the frozen snapshot to build Amazon Machine Images (AMIs) .

Your team configures AWS Systems Manager Patch Manager to patch the instances your organization runs from the same internal package source. The accompanying reference implementation demonstrates the pattern for RPM-based RHEL-family systems (AlmaLinux for example). It is a reference, not a substitute for distribution of licensing, vulnerability analysis, testing, or an organization’s change-management process. Common delivery models each assume something an air-gapped fleet might not provide: The objective is not to replace these products universally.

It is to show a serverless AWS pattern for teams that need an authorized repository baseline, explicit approval for later package changes, and a fleet with no public package source. Choose one package lineage end to end. The parent AMI, repository content, and trusted signing keys must belong to that same lineage. The reference implementation defaults to AlmaLinux vault content plus EPEL and an AlmaLinux parent AMI. The AlmaLinux OS Foundation states that AlmaLinux aims for binary and application binary interface (ABI) compatibility with RHEL.