Files
git.stella-ops.org/ops/devops/ledger/packs-infrastructure.md
StellaOps Bot 2e70c9fdb6
Some checks failed
LNM Migration CI / build-runner (push) Has been cancelled
Ledger OpenAPI CI / deprecation-check (push) Has been cancelled
Docs CI / lint-and-preview (push) Has been cancelled
Airgap Sealed CI Smoke / sealed-smoke (push) Has been cancelled
Ledger Packs CI / build-pack (push) Has been cancelled
Export Center CI / export-ci (push) Has been cancelled
Ledger OpenAPI CI / validate-oas (push) Has been cancelled
Ledger OpenAPI CI / check-wellknown (push) Has been cancelled
Ledger Packs CI / verify-pack (push) Has been cancelled
LNM Migration CI / validate-metrics (push) Has been cancelled
AOC Guard CI / aoc-guard (push) Has been cancelled
AOC Guard CI / aoc-verify (push) Has been cancelled
up
2025-12-14 18:33:02 +02:00

1.5 KiB

Findings Ledger Packs Infrastructure

Scope

Infrastructure for snapshot/time-travel export packaging and signing.

Tasks Covered

  • DEVOPS-LEDGER-PACKS-42-001-REL: Snapshot/time-travel export packaging
  • DEVOPS-LEDGER-PACKS-42-002-REL: Pack signing + integrity verification

Components

1. Pack Builder

Creates deterministic export packs from Ledger snapshots.

# Build pack from snapshot
./ops/devops/ledger/build-pack.sh --snapshot-id <id> --output out/ledger/packs/

# Dev mode with signing
COSIGN_ALLOW_DEV_KEY=1 ./ops/devops/ledger/build-pack.sh --sign

2. Pack Verifier

Verifies pack integrity and signatures.

# Verify pack
./ops/devops/ledger/verify-pack.sh out/ledger/packs/snapshot-*.pack.tar.gz

3. Time-Travel Export

Creates point-in-time exports for compliance/audit.

# Export at specific timestamp
./ops/devops/ledger/time-travel-export.sh --timestamp 2025-12-01T00:00:00Z

Pack Format

snapshot-<id>.pack.tar.gz
├── manifest.json          # Pack metadata + checksums
├── findings/              # Finding records (NDJSON)
├── metadata/              # Scan metadata
├── provenance.json        # SLSA provenance
└── signatures/
    ├── manifest.dsse.json # DSSE signature
    └── SHA256SUMS         # Checksums

CI Workflows

  • ledger-packs-ci.yml - Build and verify packs
  • ledger-packs-release.yml - Sign and publish packs

Prerequisites

  • Ledger snapshot schema finalized
  • Storage contract defined
  • Pack format specification