35 lines
		
	
	
		
			2.2 KiB
		
	
	
	
		
			Markdown
		
	
	
		
			Executable File
		
	
	
	
	
			
		
		
	
	
			35 lines
		
	
	
		
			2.2 KiB
		
	
	
	
		
			Markdown
		
	
	
		
			Executable File
		
	
	
	
	
| # StellaOps Concelier & CLI
 | |
| 
 | |
| This repository hosts the StellaOps Concelier service, its plug-in ecosystem, and the
 | |
| first-party CLI (`stellaops-cli`). Concelier ingests vulnerability advisories from
 | |
| authoritative sources, stores them in MongoDB, and exports deterministic JSON and
 | |
| Trivy DB artefacts. The CLI drives scanner distribution, scan execution, and job
 | |
| control against the Concelier API.
 | |
| 
 | |
| ## Quickstart
 | |
| 
 | |
| 1. Prepare a MongoDB instance and (optionally) install `trivy-db`/`oras`.
 | |
| 2. Copy `etc/concelier.yaml.sample` to `etc/concelier.yaml` and update the storage + telemetry
 | |
|    settings.
 | |
| 3. Copy `etc/authority.yaml.sample` to `etc/authority.yaml`, review the issuer, token
 | |
|    lifetimes, and plug-in descriptors, then edit the companion manifests under
 | |
|    `etc/authority.plugins/*.yaml` to match your deployment.
 | |
| 4. Start the web service with `dotnet run --project src/StellaOps.Concelier.WebService`.
 | |
| 5. Configure the CLI via environment variables (e.g. `STELLAOPS_BACKEND_URL`) and trigger
 | |
|    jobs with `dotnet run --project src/StellaOps.Cli -- db merge`.
 | |
| 
 | |
| Detailed operator guidance is available in `docs/10_CONCELIER_CLI_QUICKSTART.md`. API and
 | |
| command reference material lives in `docs/09_API_CLI_REFERENCE.md`.
 | |
| 
 | |
| Pipeline note: deployment workflows should template `etc/concelier.yaml` during CI/CD,
 | |
| injecting environment-specific Mongo credentials and telemetry endpoints. Upcoming
 | |
| releases will add Microsoft OAuth (Entra ID) authentication support—track the quickstart
 | |
| for integration steps once available.
 | |
| 
 | |
| ## Documentation
 | |
| 
 | |
| - `docs/README.md` now consolidates the platform index and points to the updated high-level architecture.
 | |
| - Module architecture dossiers live under `docs/ARCHITECTURE_*.md`; the most relevant here are `docs/ARCHITECTURE_CONCELIER.md` (service layout, merge engine, exports) and `docs/ARCHITECTURE_CLI.md` (command surface, AOT packaging, auth flows). Related services such as the Signer, Attestor, Authority, Scanner, UI, Excititor, Zastava, and DevOps pipeline each have their own dossier.
 | |
| - Offline operation guidance moved to `docs/24_OFFLINE_KIT.md`, which details bundle composition, verification, and delta workflows. Concelier-specific connector operations stay in `docs/ops/concelier-certbund-operations.md` and companion runbooks under `docs/ops/`.
 | |
| 
 |