ADORSYS-GIS / ADORSYS-GIS/lightbridge-governance

[Story]: AIBOM export pipeline from ai-helm-values model and GPU fleet catalogs

Ouverte
#116 0 commentaires 0 réactions 0 personnes assignées Voir sur GitHub
user-story
Langage dominant
Rust
Étoiles
1
Forks
2
Merge moyen
13 h 13 min
PR mergées (30 j)
110

Description

## Summary
Build the export pipeline that reads ai-helm-values models.yaml (model catalog, per-model provenance) and inference.yaml (GPU fleet catalog) and generates a valid AIBOM.

## Intent / Source of truth
This is the core deliverable of the epic — turning already-tracked internal config into an exportable artifact, per the epic's evidence. Part of [Epic] AIBOM and model-provenance export.

## Scope
- [ ] Automated pipeline pulling current production values from ai-helm-values (read-only; this epic does not modify that repo's role as source of truth)
- [ ] SPDX 3.0 AI Profile and CycloneDX ML-BOM output generation
- [ ] Schema validation of generated output
- [ ] Scheduled regeneration so the export stays current with catalog changes

## Out of scope
- Modifying ai-helm-values's data model to add AIBOM-specific fields beyond what g3s1 identifies as gaps

## Verification
Generated AIBOM validates against the SPDX 3.0 AI Profile JSON schema; diff-check confirms it reflects the current production models.yaml/inference.yaml contents after a catalog change.

## Risk assessment
A stale export (not regenerated after a catalog change) would misrepresent what's actually deployed; the regeneration cadence needs to be tight enough to stay trustworthy for a customer security review.

## AI Usage Declaration
Drafted with AI assistance during the 2026-08-13 cross-repo backlog consolidation and enterprise-readiness research. A human owns intent, verification and consequences.

Guide de contribution

Ouvrir le guide de contribution

Évaluation

Cette issue n'a pas encore été évaluée.

Recevez les nouvelles issues par e-mail

Un résumé court des issues GitHub adaptées aux débutants.