35 lines
		
	
	
		
			2.2 KiB
		
	
	
	
		
			Markdown
		
	
	
		
			Executable File
		
	
	
	
	
			
		
		
	
	
			35 lines
		
	
	
		
			2.2 KiB
		
	
	
	
		
			Markdown
		
	
	
		
			Executable File
		
	
	
	
	
# StellaOps Concelier & CLI
 | 
						|
 | 
						|
This repository hosts the StellaOps Concelier service, its plug-in ecosystem, and the
 | 
						|
first-party CLI (`stellaops-cli`). Concelier ingests vulnerability advisories from
 | 
						|
authoritative sources, stores them in MongoDB, and exports deterministic JSON and
 | 
						|
Trivy DB artefacts. The CLI drives scanner distribution, scan execution, and job
 | 
						|
control against the Concelier API.
 | 
						|
 | 
						|
## Quickstart
 | 
						|
 | 
						|
1. Prepare a MongoDB instance and (optionally) install `trivy-db`/`oras`.
 | 
						|
2. Copy `etc/concelier.yaml.sample` to `etc/concelier.yaml` and update the storage + telemetry
 | 
						|
   settings.
 | 
						|
3. Copy `etc/authority.yaml.sample` to `etc/authority.yaml`, review the issuer, token
 | 
						|
   lifetimes, and plug-in descriptors, then edit the companion manifests under
 | 
						|
   `etc/authority.plugins/*.yaml` to match your deployment.
 | 
						|
4. Start the web service with `dotnet run --project src/StellaOps.Concelier.WebService`.
 | 
						|
5. Configure the CLI via environment variables (e.g. `STELLAOPS_BACKEND_URL`) and trigger
 | 
						|
   jobs with `dotnet run --project src/StellaOps.Cli -- db merge`.
 | 
						|
 | 
						|
Detailed operator guidance is available in `docs/10_CONCELIER_CLI_QUICKSTART.md`. API and
 | 
						|
command reference material lives in `docs/09_API_CLI_REFERENCE.md`.
 | 
						|
 | 
						|
Pipeline note: deployment workflows should template `etc/concelier.yaml` during CI/CD,
 | 
						|
injecting environment-specific Mongo credentials and telemetry endpoints. Upcoming
 | 
						|
releases will add Microsoft OAuth (Entra ID) authentication support—track the quickstart
 | 
						|
for integration steps once available.
 | 
						|
 | 
						|
## Documentation
 | 
						|
 | 
						|
- `docs/README.md` now consolidates the platform index and points to the updated high-level architecture.
 | 
						|
- Module architecture dossiers live under `docs/ARCHITECTURE_*.md`; the most relevant here are `docs/ARCHITECTURE_CONCELIER.md` (service layout, merge engine, exports) and `docs/ARCHITECTURE_CLI.md` (command surface, AOT packaging, auth flows). Related services such as the Signer, Attestor, Authority, Scanner, UI, Excititor, Zastava, and DevOps pipeline each have their own dossier.
 | 
						|
- Offline operation guidance moved to `docs/24_OFFLINE_KIT.md`, which details bundle composition, verification, and delta workflows. Concelier-specific connector operations stay in `docs/ops/concelier-certbund-operations.md` and companion runbooks under `docs/ops/`.
 | 
						|
 |