Some checks failed
Docs CI / lint-and-preview (push) Has been cancelled
- Added `LedgerMetrics` class to record write latency and total events for ledger operations. - Created comprehensive tests for Ruby packages endpoints, covering scenarios for missing inventory, successful retrieval, and identifier handling. - Introduced `TestSurfaceSecretsScope` for managing environment variables during tests. - Developed `ProvenanceMongoExtensions` for attaching DSSE provenance and trust information to event documents. - Implemented `EventProvenanceWriter` and `EventWriter` classes for managing event provenance in MongoDB. - Established MongoDB indexes for efficient querying of events based on provenance and trust. - Added models and JSON parsing logic for DSSE provenance and trust information.
3.2 KiB
3.2 KiB
Sprint 165 - Export & Evidence · 160.C) TimelineIndexer
Active items only. Completed/historic work now resides in docs/implplan/archived/tasks.md (updated 2025-11-08).
[Export & Evidence] 160.C) TimelineIndexer Depends on: Sprint 110.A - AdvisoryAI, Sprint 120.A - AirGap, Sprint 130.A - Scanner, Sprint 150.A - Orchestrator Summary: Export & Evidence focus on TimelineIndexer).
| Task ID | State | Task description | Owners (Source) |
|---|---|---|---|
| TIMELINE-OBS-52-001 | TODO | Bootstrap StellaOps.Timeline.Indexer service with Postgres migrations for timeline_events, timeline_event_details, timeline_event_digests; enable RLS scaffolding and deterministic migration scripts. |
Timeline Indexer Guild (src/TimelineIndexer/StellaOps.TimelineIndexer) |
| TIMELINE-OBS-52-002 | TODO | Implement event ingestion pipeline (NATS/Redis consumers) with ordering guarantees, dedupe on (event_id, tenant_id), correlation to trace IDs, and backpressure metrics. Dependencies: TIMELINE-OBS-52-001. |
Timeline Indexer Guild (src/TimelineIndexer/StellaOps.TimelineIndexer) |
| TIMELINE-OBS-52-003 | TODO | Expose REST/gRPC APIs for timeline queries (GET /timeline, /timeline/{id}) with filters, pagination, and tenant enforcement. Provide OpenAPI + contract tests. Dependencies: TIMELINE-OBS-52-002. |
Timeline Indexer Guild (src/TimelineIndexer/StellaOps.TimelineIndexer) |
| TIMELINE-OBS-52-004 | TODO | Finalize RLS policies, scope checks (timeline:read), and audit logging for query access. Include integration tests for cross-tenant isolation and legal hold markers. Dependencies: TIMELINE-OBS-52-003. |
Timeline Indexer Guild, Security Guild (src/TimelineIndexer/StellaOps.TimelineIndexer) |
| TIMELINE-OBS-53-001 | TODO | Link timeline events to evidence bundle digests + attestation subjects; expose /timeline/{id}/evidence endpoint returning signed manifest references. Dependencies: TIMELINE-OBS-52-004. |
Timeline Indexer Guild, Evidence Locker Guild (src/TimelineIndexer/StellaOps.TimelineIndexer) |
Task snapshot (2025-11-12)
- Core service:
TIMELINE-OBS-52-001/002cover Postgres migrations/RLS scaffolding and NATS/Redis ingestion with deterministic ordering + metrics. - API surface:
TIMELINE-OBS-52-003/004expose REST/gRPC query endpoints, RLS policies, audit logging, and legal-hold tests. - Evidence linkage:
TIMELINE-OBS-53-001joins timeline events to EvidenceLocker digests for/timeline/{id}/evidence.
Dependencies & blockers
- Waiting on orchestrator + notifications schema (Wave 150/140) to finalize ingestion payload and event IDs.
- Requires EvidenceLocker bundle digest schema to link timeline entries to sealed manifests.
- Needs Scheduler/Orchestrator queue readiness for ingestion ordering semantics (impacting 52-002).
- Security/Compliance review required for Postgres RLS migrations before coding begins.
Ready-to-start checklist
- Obtain sample orchestrator capsule events + notifications once schema drops; attach to this doc for reference.
- Draft Postgres migration + RLS design and share with Security/Compliance for approval.
- Define ingestion ordering tests (NATS to Postgres) and expected metrics/alerts.
- Align evidence linkage contract with EvidenceLocker (bundle IDs, DSSE references) prior to implementing
TIMELINE-OBS-53-001.