Skip to content
Merged
Show file tree
Hide file tree
Changes from all commits
Commits
File filter

Filter by extension

Filter by extension

Conversations
Failed to load comments.
Loading
Jump to
Jump to file
Failed to load files.
Loading
Diff view
Diff view
1 change: 1 addition & 0 deletions README.md
Original file line number Diff line number Diff line change
Expand Up @@ -39,6 +39,7 @@ concretely:
| Hosted server (this repo) | Phase A code-complete, smoke-validated, deployable. |
| Scoring backend | **NEAR AI Cloud** (TEE-hosted vLLM, Intel TDX + NVIDIA GPU TEE) — chosen so a pilot host needs no local CUDA stack. Smoke-validated against `Qwen3.6-35B-A3B-FP8`. |
| Gate floors | Recalibration against the hosted model is required before first contributor traffic — see [`docs/operator/a27-perplexity-floor-calibration.md`](docs/operator/a27-perplexity-floor-calibration.md). |
| Contributor gate | Invite-code allowlist on the upload-claim issuer; off by default, enabled for the pilot — see [`docs/operator/pilot-allowlist.md`](docs/operator/pilot-allowlist.md). |
| KMS / KEK | Cloud KMS (GCP first) with envelope-encrypted per-object DEKs. Phase A trust boundary. |
| TEE trust upgrade | Phase B — move the gate service into an attested dstack enclave once dstack-GPU primitives stabilize. The current KEK boundary is honestly weaker than the Phase B target; this is documented, not papered over. |
| Contributor client | Ironclaw integration is the remaining gate before live contributor traffic. The `trace-commons-pilot-bootstrap` binary stands in as a load-generation harness against real HF agent-traces sessions so calibration and end-to-end validation can proceed without it. |
Expand Down
Original file line number Diff line number Diff line change
@@ -1,3 +1,4 @@
use trace_commons_server::trace_upload_claim_allowlist::hash_invite_code;
use trace_commons_server::trace_upload_claim_issuer::{
TraceUploadClaimIssuerConfig, UploadClaimIssuerHealthCheck,
configure_tenant_access_grants_from_env, generate_upload_claim_keypair, mint_test_upload_claim,
Expand All @@ -12,17 +13,24 @@ USAGE:
trace-commons-upload-claim-issuer [SUBCOMMAND]

SUBCOMMANDS:
(none) Start the HTTP issuer (default)
--generate-keypair Print a fresh Ed25519 keypair (PKCS#8 + SPKI PEM)
and a suggested kid (UUID v4) to stdout
--health-check Load env config, verify keys, exit 0 on success
and 1 with a hash-only reason on failure
--mint-test-claim Mint a test upload claim for a hardcoded test
tenant/principal and print the JWT to stdout
(FOR TESTING / DEPLOY PROBES ONLY)
-h, --help Print this help text
(none) Start the HTTP issuer (default)
--generate-keypair Print a fresh Ed25519 keypair (PKCS#8 + SPKI PEM)
and a suggested kid (UUID v4) to stdout
--health-check Load env config, verify keys, exit 0 on success
and 1 with a hash-only reason on failure
--mint-test-claim Mint a test upload claim for a hardcoded test
tenant/principal and print the JWT to stdout
(FOR TESTING / DEPLOY PROBES ONLY)
--hash-invite-code <CODE> Print the canonical sha256: hash of an invite
code (the value the operator pastes into the
pilot allowlist JSON file). Reads CODE from the
next argument; use this rather than rolling a
local sha256 helper so the hashing function
stays in lockstep with the issuance handler.
-h, --help Print this help text

Environment variables are documented in docs/upload-claim-issuer.md.
Pilot allowlist operator guide: docs/operator/pilot-allowlist.md.
";

fn main() -> anyhow::Result<()> {
Expand All @@ -39,6 +47,7 @@ fn main() -> anyhow::Result<()> {
Some("--generate-keypair") => run_generate_keypair(),
Some("--health-check") => run_health_check(),
Some("--mint-test-claim") => run_mint_test_claim(),
Some("--hash-invite-code") => run_hash_invite_code(args.get(1).map(String::as_str)),
Some(other) if other.starts_with("--") => {
eprintln!("unknown subcommand: {other}\n");
eprint!("{HELP_TEXT}");
Expand All @@ -48,6 +57,18 @@ fn main() -> anyhow::Result<()> {
}
}

fn run_hash_invite_code(code: Option<&str>) -> anyhow::Result<()> {
let Some(code) = code.map(str::trim).filter(|s| !s.is_empty()) else {
eprintln!(
"--hash-invite-code requires a CODE argument. Example:\n \
trace-commons-upload-claim-issuer --hash-invite-code INV-PILOT-001"
);
std::process::exit(2);
};
println!("{}", hash_invite_code(code));
Ok(())
}

fn run_generate_keypair() -> anyhow::Result<()> {
let keypair = generate_upload_claim_keypair()?;
print!("{}", keypair.private_key_pem);
Expand Down
2 changes: 2 additions & 0 deletions crates/trace-commons-server/src/lib.rs
Original file line number Diff line number Diff line change
Expand Up @@ -11,6 +11,8 @@ pub mod trace_artifact_kek;
pub mod trace_artifact_store;
pub mod trace_corpus_storage;
pub mod trace_gate_service;
pub mod trace_upload_claim_allowlist;
pub mod trace_upload_claim_issuer;
pub mod trace_upload_claim_issuer_admin;

pub const TRACE_COMMONS_SERVER_EXTRACTION_STAGE: &str = "server-storage-owned";
Loading