ADORSYS-GIS / ADORSYS-GIS/lightbridge-governance

[Story]: AIBOM export pipeline from ai-helm-values model and GPU fleet catalogs

Đang mở
#116 0 bình luận 0 reaction 0 người được giao Xem trên GitHub
user-story
Ngôn ngữ chính
Rust
Star
1
Fork
2
Merge trung bình
14 giờ 36 phút
Pull request đã merge (30 ngày)
107

Mô tả

## Summary
Build the export pipeline that reads ai-helm-values models.yaml (model catalog, per-model provenance) and inference.yaml (GPU fleet catalog) and generates a valid AIBOM.

## Intent / Source of truth
This is the core deliverable of the epic — turning already-tracked internal config into an exportable artifact, per the epic's evidence. Part of [Epic] AIBOM and model-provenance export.

## Scope
- [ ] Automated pipeline pulling current production values from ai-helm-values (read-only; this epic does not modify that repo's role as source of truth)
- [ ] SPDX 3.0 AI Profile and CycloneDX ML-BOM output generation
- [ ] Schema validation of generated output
- [ ] Scheduled regeneration so the export stays current with catalog changes

## Out of scope
- Modifying ai-helm-values's data model to add AIBOM-specific fields beyond what g3s1 identifies as gaps

## Verification
Generated AIBOM validates against the SPDX 3.0 AI Profile JSON schema; diff-check confirms it reflects the current production models.yaml/inference.yaml contents after a catalog change.

## Risk assessment
A stale export (not regenerated after a catalog change) would misrepresent what's actually deployed; the regeneration cadence needs to be tight enough to stay trustworthy for a customer security review.

## AI Usage Declaration
Drafted with AI assistance during the 2026-08-13 cross-repo backlog consolidation and enterprise-readiness research. A human owns intent, verification and consequences.

Hướng dẫn đóng góp

Mở hướng dẫn đóng góp

Hướng nghiên cứu

Start by reading the ai-helm-values models.yaml and inference.yaml files to understand the catalog data available for export. Identify the project entry points for the read-only pipeline and scheduled regeneration, then verify the generated SPDX 3.0 AI Profile and CycloneDX ML-BOM outputs against their schemas. Done means validation passes and a catalog change is reflected by the diff check.

Do mô hình lập chỉ mục viết ra từ nội dung của issue.

Đánh giá

Công nghệ
yaml
Lĩnh vực
devops, security
Loại issue
Tính năng
Độ khó
5/5
Thời gian dự kiến
Hơn một tuần
Mức độ hoạt động
Ít trao đổi
Độ rõ ràng
Cần làm rõ
Mức phù hợp với người mới
35/100

Nhận issue mới trong hộp thư của bạn

Bản tóm tắt ngắn những issue GitHub phù hợp với người mới.