Attestor agent guide
Mission
Attestor moves signed evidence through the trust chain by accepting DSSE bundles from trusted Stella services, registering them with the Stella local transparency log by default, optionally syncing to Rekor-compatible external logs when configured, and serving deterministic verification payloads to other services.
Key docs
- Module README
- Architecture
- Implementation plan
- Task board
- Observability runbook (offline import friendly)
How to get started
- Open sprint file
/docs/implplan/SPRINT_*.mdand locate the stories referencing this module. - Review ./TASKS.md for local follow-ups and confirm status transitions (TODO → DOING → DONE/BLOCKED).
- Read the architecture and README for domain context before editing code or docs.
- Coordinate cross-module changes in the main /AGENTS.md description and through the sprint plan.
Guardrails
- Honour the Aggregation-Only Contract where applicable (see …/…/aoc/aggregation-only-contract.md).
- Preserve determinism: sort outputs, normalise timestamps (UTC ISO-8601), and avoid machine-specific artefacts.
- Keep Offline Kit parity in mind—document air-gapped workflows for any new feature.
- Treat local transparency anchoring as the sealed-deployment primary. External Rekor sync is optional and must remain operator-configured.
- Update runbooks/observability assets when operational characteristics change.
Required Reading
docs/modules/attestor/README.mddocs/modules/attestor/architecture.mddocs/modules/attestor/implementation_plan.mddocs/modules/platform/architecture-overview.md
Working Agreement
- Update task status to
DOING/DONEin both correspoding sprint file/docs/implplan/SPRINT_*.mdand the localTASKS.mdwhen you start or finish work.
- Update task status to
- Review this charter and the Required Reading documents before coding; confirm prerequisites are met.
- Keep changes deterministic (stable ordering, timestamps, hashes) and align with offline/air-gap expectations.
- Coordinate doc updates, tests, and cross-guild communication whenever contracts or workflows change.
- Revert to
TODOif you pause the task without shipping changes; leave notes in commit/PR descriptions for context.
- Revert to
