ADORSYS-GIS / ADORSYS-GIS/lightbridge-governance
[Story]: AIBOM export pipeline from ai-helm-values model and GPU fleet catalogs
- Langage dominant
- Rust
- Étoiles
- 1
- Forks
- 2
- Merge moyen
- 13 h 13 min
- PR mergées (30 j)
- 110
Description
## Summary
Build the export pipeline that reads ai-helm-values models.yaml (model catalog, per-model provenance) and inference.yaml (GPU fleet catalog) and generates a valid AIBOM.
## Intent / Source of truth
This is the core deliverable of the epic — turning already-tracked internal config into an exportable artifact, per the epic's evidence. Part of [Epic] AIBOM and model-provenance export.
## Scope
- [ ] Automated pipeline pulling current production values from ai-helm-values (read-only; this epic does not modify that repo's role as source of truth)
- [ ] SPDX 3.0 AI Profile and CycloneDX ML-BOM output generation
- [ ] Schema validation of generated output
- [ ] Scheduled regeneration so the export stays current with catalog changes
## Out of scope
- Modifying ai-helm-values's data model to add AIBOM-specific fields beyond what g3s1 identifies as gaps
## Verification
Generated AIBOM validates against the SPDX 3.0 AI Profile JSON schema; diff-check confirms it reflects the current production models.yaml/inference.yaml contents after a catalog change.
## Risk assessment
A stale export (not regenerated after a catalog change) would misrepresent what's actually deployed; the regeneration cadence needs to be tight enough to stay trustworthy for a customer security review.
## AI Usage Declaration
Drafted with AI assistance during the 2026-08-13 cross-repo backlog consolidation and enterprise-readiness research. A human owns intent, verification and consequences.
Guide de contribution
Ouvrir le guide de contribution
Évaluation
Cette issue n'a pas encore été évaluée.