Files
git.stella-ops.org/docs/modules/attestor/implementation_plan.md
master fdf95e0f46 docs: module dossier + install/quickstart sync for truthful cutover sprints
- API_CLI_REFERENCE.md, INSTALL_GUIDE.md, quickstart.md, architecture/integrations.md, dev/DEV_ENVIRONMENT_SETUP.md, integrations/LOCAL_SERVICES.md: reflect real-service wiring.
- docs/modules/**: module dossier updates across the modules touched by SPRINT_20260415_001..007 + SPRINT_20260416_003..017 + SPRINT_20260417_018..024 + SPRINT_20260418_025 + SPRINT_20260419_026.
- docs/features/checked/web/**: update feature notes where UI changed.
- docs/qa/feature-checks/runs/web/evidence-presentation-ux/: QA evidence artifacts.
- docs/setup/**, docs/technical/**: align with setup wizard contracts.

Co-Authored-By: Claude Opus 4.7 (1M context) <noreply@anthropic.com>
2026-04-19 14:45:09 +03:00

1.7 KiB

Attestor Implementation Plan

Purpose

Provide a concise, living plan for Attestor feature delivery, timestamping, and offline verification workflows.

Active work

  • docs/implplan/SPRINT_20260416_017_Attestor_truthful_runtime_storage_cutover.md
  • docs/implplan/SPRINT_20260119_010_Attestor_tst_integration.md
  • docs/implplan/SPRINT_20260119_013_Attestor_cyclonedx_1.7_generation.md
  • docs/implplan/SPRINT_20260119_014_Attestor_spdx_3.0.1_generation.md

Near-term deliverables

  • Durable bulk verification worker/store path to replace the current truthful non-testing 501 unsupported runtime.
  • RFC-3161 timestamping integration (signing, verification, policy context).
  • CycloneDX 1.7 predicate writer updates and determinism tests.
  • SPDX 3.0.1 predicate writer updates and determinism tests.
  • CLI workflows for attestation timestamp handling.

Dependencies

  • Authority timestamping services and TSA client integrations.
  • EvidenceLocker timestamp storage and verification utilities.
  • Policy evaluation integration for timestamp assertions.

Evidence of completion

  • PostgreSQL-backed runtime proof tests for canonical entry/audit storage and watchlist persistence under src/Attestor/StellaOps.Attestor/StellaOps.Attestor.Tests/Integration/AttestorTruthfulRuntimeTests.cs.
  • Attestor timestamping library changes under src/Attestor/__Libraries/.
  • Updated CLI command handlers and tests under src/Cli/.
  • Deterministic unit tests and fixtures in src/Attestor/__Tests/.
  • Documentation updates under docs/modules/attestor/.

Reference docs

  • docs/modules/attestor/README.md
  • docs/modules/attestor/architecture.md
  • docs/modules/attestor/rekor-verification-design.md
  • docs/modules/platform/architecture-overview.md