Air-gapped data sources — populate these before installing. They are not shipped:
each is licensed by its upstream and must be obtained with your own entitlement.

  geoip/       GeoLite2 Country/City/ASN + IPInfo-Lite MMDBs  (geoip-update, geodb-updater, telemetry-api)
  ids-rules/   Emerging Threats / Suricata ruleset            (etrules-ingestor, ids-rules-publisher)
  models/      ML ONNX models                                 (model-publisher)
  indicators/  CTI indicator snapshots                        (no live feeds air-gapped)

Load them into the in-cluster RustFS store under the platform-data bucket; the
services read from there and never from an outside CDN, in connected installs too.
