Repository navigation
feat(trace): export session evidence to disk - #3584
Draft
matiasinsaurralde wants to merge 2 commits into
Draft
matiasinsaurralde wants to merge 2 commits into
matiasinsaurralde wants to merge 2 commits into
Conversation
Add an export mode to `chainloop trace run` that runs the full push-time evidence assembly and writes the result to a local directory instead of pushing a signed attestation. It makes no call to the control plane and needs no credentials: every material is crafted offline with an inline CAS backend, so the exported evidence record and the material digests equal what a push would upload, apart from the signature and the attestation wrapper. Each material is written under its content digest, with a top-level manifest indexing them, so a reader or a test finds each one by its reference in the evidence record. Redaction stays on by default, matching a push; --no-redact opts out for a trusted local run. Usage: `chainloop trace run --export <dir> -- <agent command>`. Signed-off-by: Matías Insaurralde <matias@chainloop.dev>
In export mode, `chainloop trace run` only wrote the evidence when the wrapped agent exited with status zero, so a session the user interrupted (for example by closing the agent with Ctrl-C) produced no output and no message. Export is for inspecting what a session produced, so it now runs whatever the agent's exit status was, warns when no session was recorded or the export failed, and still propagates the agent's exit code. Signed-off-by: Matías Insaurralde <matias@chainloop.dev>
Contributor
AI Session Checks —
|
| return nil | ||
| } | ||
|
|
||
| merged := make(map[string]string, len(crafted)+len(extra)) |
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
Closes #3583
Summary
Adds an export mode to
chainloop trace runthat assembles the full push-time evidence for an agent session and writes it to a local directory instead of pushing a signed attestation.