Some checks failed
LNM Migration CI / build-runner (push) Has been cancelled
Ledger OpenAPI CI / deprecation-check (push) Has been cancelled
Docs CI / lint-and-preview (push) Has been cancelled
Airgap Sealed CI Smoke / sealed-smoke (push) Has been cancelled
Ledger Packs CI / build-pack (push) Has been cancelled
Export Center CI / export-ci (push) Has been cancelled
Ledger OpenAPI CI / validate-oas (push) Has been cancelled
Ledger OpenAPI CI / check-wellknown (push) Has been cancelled
Ledger Packs CI / verify-pack (push) Has been cancelled
LNM Migration CI / validate-metrics (push) Has been cancelled
AOC Guard CI / aoc-guard (push) Has been cancelled
AOC Guard CI / aoc-verify (push) Has been cancelled
59 lines
1.5 KiB
Markdown
59 lines
1.5 KiB
Markdown
# Findings Ledger Packs Infrastructure
|
|
|
|
## Scope
|
|
Infrastructure for snapshot/time-travel export packaging and signing.
|
|
|
|
## Tasks Covered
|
|
- DEVOPS-LEDGER-PACKS-42-001-REL: Snapshot/time-travel export packaging
|
|
- DEVOPS-LEDGER-PACKS-42-002-REL: Pack signing + integrity verification
|
|
|
|
## Components
|
|
|
|
### 1. Pack Builder
|
|
Creates deterministic export packs from Ledger snapshots.
|
|
|
|
```bash
|
|
# Build pack from snapshot
|
|
./ops/devops/ledger/build-pack.sh --snapshot-id <id> --output out/ledger/packs/
|
|
|
|
# Dev mode with signing
|
|
COSIGN_ALLOW_DEV_KEY=1 ./ops/devops/ledger/build-pack.sh --sign
|
|
```
|
|
|
|
### 2. Pack Verifier
|
|
Verifies pack integrity and signatures.
|
|
|
|
```bash
|
|
# Verify pack
|
|
./ops/devops/ledger/verify-pack.sh out/ledger/packs/snapshot-*.pack.tar.gz
|
|
```
|
|
|
|
### 3. Time-Travel Export
|
|
Creates point-in-time exports for compliance/audit.
|
|
|
|
```bash
|
|
# Export at specific timestamp
|
|
./ops/devops/ledger/time-travel-export.sh --timestamp 2025-12-01T00:00:00Z
|
|
```
|
|
|
|
## Pack Format
|
|
```
|
|
snapshot-<id>.pack.tar.gz
|
|
├── manifest.json # Pack metadata + checksums
|
|
├── findings/ # Finding records (NDJSON)
|
|
├── metadata/ # Scan metadata
|
|
├── provenance.json # SLSA provenance
|
|
└── signatures/
|
|
├── manifest.dsse.json # DSSE signature
|
|
└── SHA256SUMS # Checksums
|
|
```
|
|
|
|
## CI Workflows
|
|
- `ledger-packs-ci.yml` - Build and verify packs
|
|
- `ledger-packs-release.yml` - Sign and publish packs
|
|
|
|
## Prerequisites
|
|
- Ledger snapshot schema finalized
|
|
- Storage contract defined
|
|
- Pack format specification
|