ADORSYS-GIS / ADORSYS-GIS/lightbridge-governance
[Story]: AIBOM export pipeline from ai-helm-values model and GPU fleet catalogs
- Ngôn ngữ chính
- Rust
- Star
- 1
- Fork
- 2
- Merge trung bình
- 14 giờ 36 phút
- Pull request đã merge (30 ngày)
- 107
Mô tả
## Summary
Build the export pipeline that reads ai-helm-values models.yaml (model catalog, per-model provenance) and inference.yaml (GPU fleet catalog) and generates a valid AIBOM.
## Intent / Source of truth
This is the core deliverable of the epic — turning already-tracked internal config into an exportable artifact, per the epic's evidence. Part of [Epic] AIBOM and model-provenance export.
## Scope
- [ ] Automated pipeline pulling current production values from ai-helm-values (read-only; this epic does not modify that repo's role as source of truth)
- [ ] SPDX 3.0 AI Profile and CycloneDX ML-BOM output generation
- [ ] Schema validation of generated output
- [ ] Scheduled regeneration so the export stays current with catalog changes
## Out of scope
- Modifying ai-helm-values's data model to add AIBOM-specific fields beyond what g3s1 identifies as gaps
## Verification
Generated AIBOM validates against the SPDX 3.0 AI Profile JSON schema; diff-check confirms it reflects the current production models.yaml/inference.yaml contents after a catalog change.
## Risk assessment
A stale export (not regenerated after a catalog change) would misrepresent what's actually deployed; the regeneration cadence needs to be tight enough to stay trustworthy for a customer security review.
## AI Usage Declaration
Drafted with AI assistance during the 2026-08-13 cross-repo backlog consolidation and enterprise-readiness research. A human owns intent, verification and consequences.
Hướng dẫn đóng góp
Hướng nghiên cứu
Start by reading the ai-helm-values models.yaml and inference.yaml files to understand the catalog data available for export. Identify the project entry points for the read-only pipeline and scheduled regeneration, then verify the generated SPDX 3.0 AI Profile and CycloneDX ML-BOM outputs against their schemas. Done means validation passes and a catalog change is reflected by the diff check.
Do mô hình lập chỉ mục viết ra từ nội dung của issue.
Đánh giá
- Công nghệ
- yaml
- Lĩnh vực
- devops, security
- Loại issue
- Tính năng
- Độ khó
- 5/5
- Thời gian dự kiến
- Hơn một tuần
- Mức độ hoạt động
- Ít trao đổi
- Độ rõ ràng
- Cần làm rõ
- Mức phù hợp với người mới
- 35/100