Red Queen · GovCloud Advanced

Salesforce Government Cloud Advanced

Air-gapped Hyperforce on AWS Secret Cloud (us-isob-east-1) for U.S. SECRET-level government workloads.

StatusActive Development
ClassificationSECRET / IL5+
Regionus-isob-east-1
Paved Path Stds19

Executive Summary

Fully air-gapped Hyperforce on AWS Secret Cloud (us-isob-east-1) for U.S. government SECRET / IL5+ workloads. Sold as Salesforce Government Cloud Advanced.

Why it matters commercially: unlocks classified government customer workloads Salesforce cannot serve today. Requires a fundamentally different operating model — no internet, no VPN, no direct commercial-cloud connectivity, no debug SSH.

Why it matters to APS/Missionforce: onboarding requires 19 paved-path standards (categories: build, config, data, security, observability, change management, continuity). Every artifact enters via Airlock (low→high); every data extraction exits via Vantage (high→low) under DLP review. Your teams must plan dev workflows around this air-gap — access requests, no on-demand debug — and complete GCP paved path first.

Status◐ Active Dev — Onboarding Wave 1
RegionAWS us-isob-east-1
EnvironmentsRDev1 → RStage1 → RStage2 → RProd1
ComplianceSECRET / IL5+; 14 FDs; 19 standards

What is Red Queen?

Red Queen is the program codename for Salesforce Government Cloud Advanced — a fully air-gapped deployment of Hyperforce on AWS Secret Cloud. It is designed for U.S. government SECRET classification (IL5 and above). The environment is physically and logically isolated from Salesforce commercial infrastructure.

Air-gapped means air-gapped. No internet access, no direct connectivity to Salesforce commercial AWS regions. All artifact transfers, patches, and data flows in/out must use approved Airlock (low→high) or Vantage (high→low) mechanisms.

Naming

Red Queen is the program codename. The customer-facing product name is Salesforce Government Cloud Advanced. Both refer to the same program covered on this page.
Note on Blackjack: Blackjack is a different program — a separate air-gapped GovCloud effort that also uses AWS Secret Cloud tooling. Some Falcon docs (e.g., the "release to isolated / air-gapped" page) were written for Blackjack; the operational mechanics overlap with Red Queen, but they are not the same program. When reading platform docs, check whether the source is Red Queen-specific, Blackjack-specific, or generic to air-gapped GovCloud. If unsure, ask in #gov-can-be-weird-again before assuming an artifact applies to Red Queen.

See Vs. Blackjack A/J below for the full dimension-by-dimension comparison.

Vs. Blackjack A/J

Red Queen is not built from scratch — it forks from the same air-gapped GovCloud lineage as Blackjack A and Blackjack J (BJ-A / BJ-J), the two prior AWS Top Secret Cloud programs. But it can't simply inherit their infrastructure or tooling.

Why nothing carries over directly: Red Queen targets a different classification level — AWS Secret Cloud, not AWS Top Secret Cloud. Infrastructure, network, and transfer mechanisms cannot be shared across classification boundaries, so most BJ-A/BJ-J capabilities have to be rebuilt for the new partition rather than reused.
DimensionBlackjack ABlackjack JRed Queen
Classification / substrateAWS Top Secret CloudAWS Top Secret CloudAWS Secret Cloud (us-isob-east-1) — infra & transfer can't be shared with BJ
Environment modelExtra low-side stagingNo high-side stagingRDev1 → RStage1 → RStage2 → RProd1 (adds both low- and high-side staging)
EmulationSequoia (3rd-party vendor)Sequoia (3rd-party vendor)GovCloud-owned, no vendor
Artifact transfer coverageNot in all envsNot in all envsAirlock required in all environments incl. Dev — surfaces transfer bugs weeks earlier
Paved path parityPartialPartialDay-1 parity target with Hyperforce Commercial and GCP
Access modelSFSS-IAM-005SFSS-IAM-005 (dev access auto-grants RDev1)Same standard — no RQ-specific access model
New capabilitiesBaseline service / BOM starting listNet-new: CDP, Edge, Einstein, Field Service, GID, Warden AI, DRMC, and more never in BJ-A/BJ-J

Why it forks instead of inheriting

Inception

New air-gapped partition needs its own bootstrap sequence to establish trust/identity between the Hyperforce Grid and Falcon instances before software can be delivered.

Net-New

Partition

Different classification level than Blackjack — dedicated infrastructure, no shared resources or network.

No Sharing

Emulation

Emulated environments provisioned and managed entirely by GovCloud — departs from the third-party vendor (Sequoia) used in Blackjack.

Vendor Change

Innerloop

First-ever innerloop experience for Service Owners to test/iterate builds from local dev into emulated substrate(s) — Blackjack never had this.

First of Its Kind

Observability

New governed high→low telemetry egress mechanism, giving service owners Day-2 signal without breaching the air-gap.

Net-New

Full budget-side detail on this delta is in the Funding Strategy — Why Funding Is Needed.

Scope & Domains

Environments

RDev1 → RStage1 → RStage2 → RProd1. Strict promotion gates between each.

Air-Gapped

Fault Domains

14 FDs across the production environment for blast-radius containment.

Classified

19 Paved Path Standards

Mandatory compliance checklist before any service runs in Red Queen.

Required

Airlock (Low→High)

Secure one-way transfer mechanism for moving artifacts into the air-gapped environment.

Critical Path

Vantage (High→Low)

Controlled downward data transfer for approved data extraction.

Critical Path

FedX Add-ons (RQ)

Same FedX substrate-agnostic add-ons, backed by AWS Secret Cloud implementations.

In Flight

Paved Path Standards (19 Required)

Every service must meet all 19 standards documented in the Red Queen onboarding page before being admitted to any RQ environment. The definitive checklist lives in the design doc — search wasn't able to surface a canonical Falcon list. Categories from the design doc:

CategoryStandardsNotes
Build & DeployManaged Pipelines, Artifact Transfer via Airlock, BOM complianceNo direct artifact pushes; use Airlock pipeline
ConfigurationStructured Config V2, RQ-specific environment profileConfig must declare RQ as a target environment
Data AccessFedX add-ons only (no direct AWS Secret Cloud SDK), data residency attestationChameleon SDK usage for AWS Secret Cloud
SecurityVault/PKI via Airlock bootstrap, KMS integration, zero-trust networkingCertificate chains must be pre-seeded via Airlock
ObservabilityAir-gapped logging pipeline, no external telemetry egressAll telemetry stays within the air-gapped boundary
Change ManagementSafe Change / SRS with RQ-specific stagger, 4-environment promotion chainProduction promotions require explicit government stakeholder approval
ContinuityDR runbooks, FD-aware deployment topology, classified incident responseMust work without commercial cloud connectivity
The full list of 19 standards is in the design doc. Use it as the compliance source of truth.

Airlock & Vantage: The Air-Gap Bridges

Because Red Queen is fully air-gapped, all artifact and data movement requires explicit approval and transfer via two mechanisms:

Airlock (Low → High)

Moves approved artifacts into the classified environment. Used for: container images, binaries, config patches, certificate seeds, OS patches, dependency updates.

All inbound must pass security scanning before Airlock transfer is approved.

One-Way In

Vantage (High → Low)

Controlled downward transfer out of the classified environment. Used for: approved log exports, audit records, anonymized telemetry, post-incident analysis.

Every Vantage transfer requires explicit DLP review and government-side approval.

Controlled Out
Dev workflow implication: No direct SSH, no VPN tunneling, no on-demand access into RQ environments. All changes go through the Airlock pipeline. Debug access requires a formal access request. Plan accordingly.

Teams & Leads

DomainLeads
Program ManagementRed Queen PMO (GovCloud org)
Platform / FKPYoung Bu Park / Jacob Delorme
Managed Pipelines + SDKJosh Giron
FedX Add-ons (AWS Secret)Amit Kumar / Bo Yang
Airlock / VantageGovCloud Safe Export team (govcloud-safe-export)
Service MeshShakti Das
GovCloud AccreditationSecurity / Accreditation team
Your Org OnboardingAPS / Missionforce leads per service area

Key Milestones

2025
RDev1 Stood Up
Development environment live in us-isob-east-1.
Early 2026
Airlock & Vantage Operational
Both transfer mechanisms through security accreditation.
2026
Service Onboarding Wave 1
Priority services completing the 19-standard paved path.
Late 2026
RProd1 Full Operations
Production environment handling classified customer workloads.

Sources & Curated Docs

Primary Design & Onboarding

Airlock & Vantage

Compliance & Accreditation

Slack Channels

  • #gov-can-be-weird-again
    Red Queen / GovCloud program discussion (from your DM context).
  • #gat
    Government artifact transfer tool — Airlock fallback discussions.
  • #ask-govcloud-dev-platform
    Recommended by Airlock/Vantage docs for support. Search Slack to join.
  • #help-govcloud
    General GovCloud help channel. Search Slack to join.
  • #govcloud-onboarding
    Onboarding-specific support. Search Slack to join.

Not Indexed — Ask Team

  • Definitive list of 19 paved path standards
    Not surfaced as a canonical Falcon page. Source: Red Queen design doc.
  • 14 Fault Domains architecture
    Not indexed. Likely in the design doc or classified. Ask Platform / FKP team.
  • RDev1 / RStage1 / RStage2 / RProd1 specifics
    Not surfaced in doc search. Ask GovCloud PMO or check the Red Queen design doc.
  • Staffing sheet
    Not indexed by search. This is the sheet backing the Staffing Model App. Source is in the Red Queen design doc's link.