Skip to content

feat(trace): export session evidence to disk - #3584

Draft
matiasinsaurralde wants to merge 2 commits into
mainfrom
matias/issue-3582-trace-evidence-export
Draft

matiasinsaurralde wants to merge 2 commits into
mainfrom
matias/issue-3582-trace-evidence-export

Conversation

@matiasinsaurralde

@matiasinsaurralde matiasinsaurralde commented Oct 9, 2026 •

Copy link
Copy Markdown
Contributor

Closes #3583

Summary

Adds an export mode to chainloop trace run that assembles the full push-time evidence for an agent session and writes it to a local directory instead of pushing a signed attestation.

  • Runs entirely offline: no control plane call and no credentials. Every material is crafted with an inline CAS backend, so the exported evidence record and material digests match what a push would upload, apart from the signature and attestation wrapper.
  • Each material is written under its content digest with a top-level manifest indexing them, so each can be found by its reference in the evidence record. Redaction is on by default; --no-redact opts out for a trusted local run.
  • Exports whatever the agent produced even when it exits non-zero (e.g. an interrupted session), while still propagating the agent's exit code.

View guided diff

Add an export mode to `chainloop trace run` that runs the full push-time
evidence assembly and writes the result to a local directory instead of
pushing a signed attestation. It makes no call to the control plane and
needs no credentials: every material is crafted offline with an inline
CAS backend, so the exported evidence record and the material digests
equal what a push would upload, apart from the signature and the
attestation wrapper.

Each material is written under its content digest, with a top-level
manifest indexing them, so a reader or a test finds each one by its
reference in the evidence record. Redaction stays on by default, matching
a push; --no-redact opts out for a trusted local run.

Usage: `chainloop trace run --export <dir> -- <agent command>`.

Signed-off-by: Matías Insaurralde <matias@chainloop.dev>
In export mode, `chainloop trace run` only wrote the evidence when the
wrapped agent exited with status zero, so a session the user interrupted
(for example by closing the agent with Ctrl-C) produced no output and no
message. Export is for inspecting what a session produced, so it now runs
whatever the agent's exit status was, warns when no session was recorded
or the export failed, and still propagates the agent's exit code.

Signed-off-by: Matías Insaurralde <matias@chainloop.dev>
@chainloop-platform

Copy link
Copy Markdown
Contributor

AI Session Checks — ⚠️ no AI session found

Missing AI Coding Sessions

This organization requires every PR to be backed by a Chainloop Trace AI coding session, and none was found for this one.

Please make sure the AI coding session evidence has been sent by the Chainloop CLI, or add the skip-ai-session label to this PR to bypass this check.

Learn more about Chainloop Trace.


Powered by Chainloop and Chainloop Trace

return nil
}

merged := make(map[string]string, len(crafted)+len(extra))
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants