mirror of
https://github.com/whyour/qinglong.git
synced 2026-09-21 01:32:44 +08:00
feat(ql3): add external release workstation ceremony
This commit is contained in:
@@ -11,6 +11,7 @@
|
||||
|
||||
最新增量证据(2026-08-16):
|
||||
|
||||
- D-332/ADR-0424(实现门完成、外部验收待公开 release):从 exact reviewed `v3.*` source tag 执行的 Cluster Admin release workstation ceremony 已实现为根级 runner + 独立 offline auditor,不新增 workspace package、生产依赖、产品命令、镜像内容或常驻组件。runner 只接受 owner-bound `ghcr.io/<owner>/qinglong3-cluster-admin@sha256:<digest>`、40-hex source revision、完整 tag ref、canonical absolute `cosign|gh|docker`、current-owner `0600` 短期 GitHub token file 与 no-replace 私有 report;三个工具按绝对路径直接执行且前后复验 inode/size/SHA-256,不经 shell/ambient PATH,token 只注入 3 个 `gh attestation verify` 子进程。ceremony 精确验证 keyless workflow identity、provenance、CycloneDX 与 OS-vulnerability evidence,拉取并 inspect 同一 RepoDigest,再在 non-root/read-only/network-none/drop-ALL/no-new-privileges/128 MiB/0.25 CPU/32 PIDs 下运行 release image 内置 `evidence-verify` 检查固定非敏感 vector。成功报告只含 public release identity、tool/argv/stdout/stderr digest、字节数、isolation/limitation 与自身 canonical SHA-256,不含原始 transcript、token、路径或 workstation identity;offline auditor 只证明 canonical structure、digest 和 expected identity binding,明确 `externalResults=not_replayed`、`reportAttestation=none`、`actionAuthority=none`。定向正负门覆盖 token 隔离、mutable/source drift、tool/file authority drift、no-replace、结构重签和 report swapping;backend 1,233 pass/2 条件 skip、Cluster Admin 387 pass/3 条件 skip、18-package clean build/test 退出 0。workspace 保持 18 package、无 single/shallow package;npm pack 保持 250 files、271,238-byte tarball、1,690,196-byte unpacked;package/dependency/Edge import/Cluster deployment/image release/OS vulnerability/Console/distribution 审计均 compatible。14 档 Local artifact 全部 compatible,默认 Edge/Standalone 精确保持 2,589,890/2,589,968 bytes、315 files、56 modules,application+AI 与 MCP 也不变。本门无 schema/migration/SQL/role/Pool/连接拓扑变化,复用紧邻 D-331 的 PostgreSQL 18.6 arm64 142/142、timeline `1→2` 基线。由于当前没有公开 3.0 release digest,且工作站没有真实 `gh/cosign`,ADR-0424 必须保持 Proposed;stub 或本地 image 不能冒充最终外部 ceremony,公开 digest 可用后才记录真实 report/tool digest 并转 Accepted。
|
||||
- D-331/ADR-0423(已接受):`@qinglong/cluster-admin` 在既有 `copilot-console/` 职责目录增加独立 TypeScript evidence verifier,并以第 11 个静态产品命令 `ql3-cluster-admin evidence-verify --bundle=/absolute/evidence.json` 交付。它只通过 no-follow/stable descriptor 读取一个最大 512 KiB 的 canonical absolute UTF-8 JSON,拒绝 BOM、CRLF、minified、duplicate-key、symlink、relative path 与读取中漂移;独立固定检查 exact bundle/request shape、13 operations、16-entry/8 MiB/64-item/depth/key ceiling、安全字段白名单和顺序 typed alias,再重算不含 `contentDigest` 的 canonical SHA-256。结果明确只证明 `bundleDigest=verified`;没有原始 fact 时逐条 digest 为 `not_recomputed_without_raw_facts`,server signature/attestation/durable audit 均未验证且 action authority 为 none。实现不读 stdin/environment/context,不联网、不写文件、不新增 package、依赖、route、listener、数据库、Kubernetes workload 或 Edge/Standalone closure。定向门 18/18,Cluster Admin 387 pass/3 条件 skip,18-package clean build/test 退出 0,backend 1,225 pass/2 条件 skip/0 fail。真实 arm64 Admin image `qinglong3-cluster-admin:d331-local` 为 344,567,527 bytes,在 non-root/read-only/network-none/no-capability/no-new-privileges/0.25 CPU/128 MiB/32 PIDs 下验证 11 个命令、有效 bundle、tamper rejection 与零 verifier file write。npm pack dry-run 为 250 files、271,238-byte tarball、1,690,196-byte unpacked;结构/依赖/部署/发布/Console 审计零 finding,workspace 保持 18 package、无 single/shallow package,Cluster Admin 122 个源码中 121 个位于领域目录。14 档 Local artifact 全部 compatible,默认 Edge/Standalone 仍为 2,589,890/2,589,968 bytes。因本门没有 schema/migration/SQL/role/Pool/连接拓扑变化,不重复冒充执行 HA,复用紧邻 D-330 PostgreSQL 18.6 arm64 142/142、timeline `1→2` 基线。下一门应完成公开 release digest 的外部工作站 ceremony,不得给 verifier 增加上传、签名或行动能力。
|
||||
- D-330/ADR-0422(已接受):同一 loopback-only Cluster field ledger 现可由用户显式导出纯浏览器本地的脱敏 evidence bundle。导出只消费本页已逐次读取的最近 16 条、最多 8 MiB canonical fact,不调用 upstream/BFF、补读详情/分页、轮询、上传或持久化;固定 sanitizer 只保留 operation、非权威本机观察时间、安全枚举/boolean/有界 number、结构计数/分页事实、per-bundle typed alias 与原始 fact canonical byte count/SHA-256,自由文本、名称、路径/URL/command/input/output/environment、reason/error/message、credential/token/session/authorization、未知字段及 Copilot model text 一律省略。bundle 固定为 UTF-8 `qinglong/cluster-console-redacted-evidence-bundle@v1` JSON、最大 512 KiB,顶层 self-digest 明确不是 server signature/audit/action authority;生成器作为第 4 个 digest-bound asset 留在既有 `@qinglong/cluster-admin`,不增加 package、依赖、Cluster/BFF route、数据库、对象存储、Kubernetes workload 或 Edge/Standalone closure。定向门 24/24,Cluster Admin 382 pass/3 条件 skip,完整 18-package test 退出 0,backend 1,224 pass/2 条件 skip/0 fail。真实浏览器以恶意 HTML、credential-like 值、私有路径和 Copilot model text 验证纯文本与零泄漏;3 次显式读取后导出 3,611-byte 可复算 JSON,upstream 计数仍为 3,390×844 无横向溢出且 0 console error/warning。真实 arm64 Admin image `qinglong3-cluster-admin:d330-local` 为 344,543,263 bytes,在 non-root/read-only/network-none/no-capability/no-new-privileges/0.25 CPU/128 MiB/32 PIDs 下验证 10 个产品命令、原生/host-published Console、第 4 个 asset 与内置分发。npm pack dry-run 为 246 files、267,731-byte tarball、1,665,996-byte unpacked;package/dependency/Edge import/Cluster deployment/image release/Console/distribution 审计零 finding。workspace 保持 18 package、`singleSourcePackages=[]`、`shallowSourcePackages=[]`,1,199 个源码中 1,181 个位于职责目录。14 档 Local artifact 全部 compatible,默认 Edge/Standalone 精确保持 2,589,890/2,589,968 bytes、315 files、56 modules,application+AI 保持 4,493,043/4,493,175 bytes,MCP 保持 7,315,930/7,316,038 bytes。PostgreSQL 18.6 arm64 physical HA 142/142、timeline `1→2`,报告 SHA-256 `c9feb83c98ad2269c7649bd0869921d9dee7cfd00c9bc1a8a7879d81630d37c7`,证据审计与 Docker 残留均为零;本 Gate 没有 schema、migration、SQL、role、Pool 或连接拓扑变化。下一独立 Gate 应交付公开 release digest 的外部工作站 ceremony,或提供独立、离线、无 authority 的 evidence bundle verifier;不得为导出增加服务端聚合、稳定跨包标识、自动抓取或上传能力。
|
||||
- D-329/ADR-0421(已接受):同一 loopback-only Console/BFF 已扩展为 Cluster field ledger,固定提供 Copilot `inspect|output`、Run list/detail/events/steps、Task list/detail、Workflow list 与 Workflow Run list/detail/events/steps 共 13 个显式只读 operation;browser 仍不能提交 upstream URL/method/header/credential。服务端 exact contract 负责 ID/cursor/limit 校验和 path/query 生成,并复用既有 owner-private `ql3c_`、TLS 1.3、request-ID、2 MiB response 与低敏错误 transport;通用 Project read grammar 只接受审核过的 Run/Task/Workflow GET,拒绝 mutation、absolute URL 与 path traversal。UI 采用仅存内存的 evidence ledger,每次按钮只执行一次读取,分页只在 `hasMore|truncated` 携带 cursor 时由用户显式触发,没有自动 detail cascade、poller、WebSocket/SSE、retry、queue、cache 或后台 timer。实现继续留在 `@qinglong/cluster-admin`,workspace 维持 18 package,部署 credential 推荐只授予 `run.read|task.read|artifact.read`;不回接 2.x Web/session、不新增 Cluster route/schema/SQL/Pool/Kubernetes resident service,也不进入 Edge/Standalone closure。13-operation contract、Console/CLI/TLS 定向门 23/23,Cluster Admin 378 pass/3 条件 skip,完整 18-package test 退出 0,backend 1,223 pass/2 条件 skip/0 fail。真实浏览器完成 Run/Task/Workflow 读取、显式下一页、恶意 HTML 纯文本、390×844 与零 console error/warning,并发现、修正 `[hidden]` 被 panel layout 覆盖的问题;真实 arm64 Admin image `qinglong3-cluster-admin:d329-local` 为 344,518,724 bytes,在 non-root/read-only/network-none/no-capability/no-new-privileges/0.25 CPU/128 MiB/32 PIDs 下验证 10 个产品命令、原生/host-published Console 与内置分发文件。npm pack dry-run 为 245 files、262,246-byte tarball、1,642,267-byte unpacked;package/dependency/Cluster deployment/image release/Console/distribution 审计零 finding,workspace 为 18 package 且无 single-source/shallow package。14 档 Local artifact 全部 compatible;默认 Edge/Standalone 精确保持 2,589,890/2,589,968 bytes、315 files、56 modules,application+AI 保持 4,493,043/4,493,175 bytes,MCP 保持 7,315,930/7,316,038 bytes。本 Gate 无 schema、migration、SQL、role、Pool、连接或 HA 拓扑变化,继续引用 D-323 PostgreSQL 18.6 arm64 physical HA 142/142、timeline `1→2` 基线。下一独立 Gate 应把现场 evidence 升级为可下载的显式脱敏诊断包,或补公开 release digest 的外部工作站 ceremony;不得增加浏览器代理权、自动全量抓取或把 Console 变为 Kubernetes 常驻服务。
|
||||
|
||||
@@ -0,0 +1,119 @@
|
||||
# ADR-0424:外部工作站 Cluster Admin Release Ceremony
|
||||
|
||||
- 状态:Proposed
|
||||
- 日期:2026-08-16
|
||||
- 关联 RFC:QL-RFC-0001 D-332、Phase 2
|
||||
- 扩展:ADR-0420、ADR-0423
|
||||
|
||||
## 背景
|
||||
|
||||
ADR-0420 已固定 Cluster Console 只随 signed multi-architecture Admin OCI
|
||||
分发,ADR-0423 已在真实本地镜像中证明离线 evidence verifier 能在严格资源与
|
||||
authority 边界内运行。但源码审计、stub release verifier 测试和本地构建镜像都
|
||||
不能证明一个公开发布 digest 确实由预期 GitHub Actions workflow 生成,也不能
|
||||
证明签名、provenance、SBOM、OS vulnerability evidence 与最终拉取的镜像是同一
|
||||
对象。
|
||||
|
||||
公开 release 的验证发生在 operator workstation,具有 registry、GitHub
|
||||
attestation service、transparency log、本地 Docker daemon 和短期 GitHub token
|
||||
等外部条件。它不能伪装成可离线复现的单元测试,也不能把本地执行报告升级为
|
||||
服务端证明或行动权限。
|
||||
|
||||
## 决策
|
||||
|
||||
1. 在 exact reviewed `v3.*` source tag 提供
|
||||
`ql3-cluster-admin-release-workstation-ceremony.cjs`。输入必须精确绑定
|
||||
`ghcr.io/<owner>/qinglong3-cluster-admin@sha256:<digest>`、`owner/repo`、40-hex
|
||||
source revision、完整 `refs/tags/v3.*` ref,以及 canonical absolute
|
||||
`cosign`、`gh`、`docker`、短期 token file 和新 report path;mutable tag、branch
|
||||
ref、owner 漂移、symlink、group/other-writable executable 或已存在输出均失败关闭。
|
||||
2. 三个外部工具按绝对路径直接执行,不经 shell 或 ambient `PATH`。GitHub token
|
||||
必须来自 current-owner `0600` bounded file,只注入三个 `gh attestation verify`
|
||||
子进程;不得进入 argv、`cosign`/`docker` 环境、报告或失败输出。工具在执行前后
|
||||
复验 device/inode/size/SHA-256,降低 ceremony 中途替换风险。
|
||||
3. ceremony 精确执行一次 keyless signature 验证,以及绑定 release workflow、
|
||||
source digest、source tag、非 self-hosted runner 和 OCI bundle 的 provenance、
|
||||
CycloneDX、OS-vulnerability 三类 GitHub attestation 验证。随后拉取同一 digest,
|
||||
要求本地 image inspection 的 Linux `amd64|arm64` `RepoDigests` 包含精确输入。
|
||||
4. ceremony 使用固定、非敏感、单条 `run_read` redacted evidence vector 检验最终
|
||||
release image 内的第 11 个 `evidence-verify` 产品命令。该容器使用 non-root
|
||||
UID/GID 10001、read-only root、network none、drop ALL、no-new-privileges、
|
||||
128 MiB、0.25 CPU 与 32 PIDs,只读挂载 vector;输出必须与独立 verifier 的
|
||||
exact no-authority result 一致,vector inode/size/mtime/digest 前后不变。
|
||||
5. 成功只新建一个 current-owner `0600`、two-space canonical JSON 报告。报告保留
|
||||
public release identity、工具 SHA-256/size、七步 argv/stdout/stderr digest 与字节数、
|
||||
verification/isolation 结果和自身 canonical SHA-256,不保留原始工具输出、token、
|
||||
executable path 或 workstation identity。它明确声明
|
||||
`reportAttestation=none`、`actionAuthority=none`。
|
||||
6. 独立 offline audit 使用 no-follow stable read 校验报告 canonical encoding、exact
|
||||
shape、expected release identity、工具与七步 transcript digest、一致的 isolation/
|
||||
limitation 以及顶层 digest。其结果固定为 `externalResults=not_replayed`;离线审计
|
||||
不能证明外部命令确实运行,也不能重放某一历史时点的 registry、GitHub 或
|
||||
transparency-log 状态。
|
||||
7. ceremony 与 auditor 保留在根 `scripts/`,不新拆 workspace package、不加入
|
||||
Admin image,从而避免“用待验证镜像验证自身”的循环,也不进入 Edge、Standalone、
|
||||
AI、MCP Local artifact、Kubernetes workload、数据库或常驻服务闭包。
|
||||
|
||||
## 不选择
|
||||
|
||||
- **只保留 `verify-release.sh` 的布尔输出**:适合人工快速检查,但缺少工具固定、
|
||||
最终 pull/inspect、镜像内 verifier smoke 与可独立审计的 digest-level transcript。
|
||||
- **保存完整 `cosign`/`gh` 输出**:会不必要地扩大身份、registry metadata 和未来
|
||||
输出格式的泄漏面,也让报告兼容性依赖外部工具展示层。
|
||||
- **把 token 交给全部子进程或继承完整环境**:扩大 credential 与 ambient authority
|
||||
暴露,且降低 ceremony 可解释性。
|
||||
- **把 runner 烘焙进 Admin image**:产生自验证循环,并迫使运行容器获得 Docker
|
||||
daemon 与 registry authority。
|
||||
- **把本地报告签成 QingLong authority**:工作站报告只记录一次观察,不是 release
|
||||
workflow attestation、Cluster durable audit 或 action approval。
|
||||
|
||||
## 验收
|
||||
|
||||
1. stub ceremony 必须证明精确 1 次 signature、3 次 attestation、1 次 immutable
|
||||
pull、1 次 digest inspection、1 次隔离 verifier;token 只出现在 `gh` 环境,报告
|
||||
为 `0600`、不泄漏 token 且不覆盖现有文件。
|
||||
2. mutable image、branch ref、source revision/owner drift、tool failure、executable
|
||||
drift、非私有 token/report、verifier 输出漂移或 vector mutation 必须失败关闭,
|
||||
失败输出不得包含路径、输入或外部工具 transcript。
|
||||
3. offline audit 必须接受真实 canonical report,并拒绝 tamper、即使重新计算顶层
|
||||
digest 的 claim/isolation/shape 扩宽、expected release swapping、noncanonical JSON、
|
||||
symlink 与权限漂移。
|
||||
4. Console distribution audit、Cluster Admin、18-package、backend、npm pack、依赖/
|
||||
deployment/release 以及 14 档 Local artifact 门必须通过;package 总数与低配设备
|
||||
默认 Edge/Standalone artifact 必须保持不变。
|
||||
5. 必须从公开 `v3.*` release 获取真实 immutable Admin digest,并在装有真实
|
||||
`cosign`、authenticated `gh` 和 Docker 的外部工作站完成 ceremony 与独立 audit,
|
||||
才能把本 ADR 从 Proposed 改为 Accepted。
|
||||
|
||||
## 当前状态
|
||||
|
||||
截至 2026-08-16,本地仓库没有 `v3.*` tag,开发工作站未安装 `gh` 与 `cosign`,
|
||||
且项目公开 GitHub Releases 尚无可供输入的 3.0 release digest。因此本门只可完成
|
||||
runner、auditor、negative contract、资源与 artifact 回归;不得用 stub 或本地
|
||||
`d332-local` 镜像伪造第 5 条外部验收。发布 digest 可用后,按本 ADR 记录真实 report
|
||||
digest、工具 digest 与外部审计结果,再独立接受本决策。
|
||||
|
||||
## 实现门结果
|
||||
|
||||
2026-08-16,D-332 已完成可在发布后直接执行的实现门,但没有改变本 ADR 的
|
||||
`Proposed` 状态:
|
||||
|
||||
- runner/stub tools、独立 offline auditor、原 release verifier 与 Console
|
||||
distribution 定向门全部通过;覆盖精确 signature/attestation/pull/inspect/run
|
||||
argv、token 仅注入 `gh`、tool drift、权限扩宽、no-replace、结构重签与 expected
|
||||
identity swapping 等正负路径。
|
||||
- backend 全量为 1,233 pass、2 条件 skip、0 fail;Cluster Admin 为 387 pass、
|
||||
3 条件 skip、0 fail;18-package clean build/test 退出 0。沙箱内 loopback listener
|
||||
的 `EPERM` 已通过同命令非沙箱重跑消除,不记作产品失败。
|
||||
- workspace 继续为 18 packages,`singleSourcePackages=[]`、
|
||||
`shallowSourcePackages=[]`;Cluster dependency、Edge import、Cluster deployment、
|
||||
image release、OS vulnerability、Console 与 distribution 审计均 compatible。
|
||||
- Cluster Admin npm pack 保持 250 files、271,238-byte tarball、1,690,196-byte
|
||||
unpacked;D-332 的根脚本和 ADR 没有进入 npm/OCI 产品内容。
|
||||
- 14 档 Local artifact 全部 compatible。默认 Edge/Standalone 精确保持
|
||||
2,589,890/2,589,968 bytes、315 files、56 modules;application+AI 保持
|
||||
4,493,043/4,493,175 bytes,MCP 保持 7,315,930/7,316,038 bytes。
|
||||
- 本门没有 schema、migration、SQL、role、Pool 或连接拓扑变化,因此不重复冒充
|
||||
PostgreSQL HA 执行;继续复用紧邻 D-331 已通过的 PostgreSQL 18.6 arm64
|
||||
142/142、timeline `1→2` 物理 HA 基线。唯一未满足项仍是第 5 条真实公开 release
|
||||
digest 外部 ceremony。
|
||||
Reference in New Issue
Block a user