Connector aggregation state
Snapshot base: 2026-05-08 04:55 UTC from the live stellaops_platform database and running Concelier/Excititor containers. CERT-FR was refreshed at 2026-05-08 06:53 UTC, and GHSA was refreshed at 2026-05-08 07:11 UTC after the public REST fix and redeploy.
Latest live recheck: 2026-05-09 10:53 UTC after the Concelier stale job-run reconciliation fix, the Excititor stale provider-heartbeat reconciliation fix, Concelier image sha256:c220f985c6957c11d1254b71de4090ba3d9673786954144f58ba5642777b06e3, and Excititor worker image sha256:ced423d06d03ffb4fe0b47fe4de0e3531e0a7c286f9e8b7d4785bbe894dce217.
- Root cause of stale
Runningstates: persisted job/provider state recordedRunning, then host cancellation or container replacement could interrupt the terminal write. Concelier had no startup/loop reconciliation fromvuln.job_runsto livevuln.job_leases, and Excititor had no startup reconciliation for provider rows that still heartbeatedRunningafter the worker exited. - Concelier is healthy and ready after the stale-run redeploy. Startup logs show the scheduler reconciled 204 stale active job runs, then two more orphaned rows on later loops.
GET /jobs/activeat 10:53 UTC showedsource:redhat:map,source:osv:map, andsource:cert-fr:fetchstill running with live leases, so they are active work, not stale rows. - Current update: legacy
armsource rows were removed in Sprint 20260601_001 because the connector failed closed and no approved machine-readable Arm feed exists. Historical counts below predate that removal. - Excititor worker is healthy after redeploy. Startup logs show it reconciled 1 stale provider heartbeat before scheduling runs. Red Hat and Ubuntu VEX retries restarted on schedule and are now heartbeating
Runningas real progress, not stale rows. - Advisory/distro source totals now show 55 source rows, 32 enabled rows, 46 rows with raw docs or advisory items, 9776 source documents, 8659 DTOs, and 44512 advisory rows.
- Raw-document anomaly repair is complete for the investigated direct-upsert rows: CVE, AWS, GCP, AMD, Intel, Siemens, MITRE ATT&CK, MITRE D3FEND, Astra, and Ubuntu all have non-empty retained source payloads; zero-byte source payload count for those rows is 0.
- CVE is no longer credential-blocked: public cvelistV5 fetch retained 1000 raw CVE JSON documents, parse produced 1000 DTOs, and map produced 999 canonical advisory rows.
- GHSA is enabled and progressing through the public REST path: 124 raw docs, 120 DTOs, and 118 advisory rows at this recheck. The optional token remains a scale/rate-limit accelerator, not a hard credential requirement.
- Apple is no longer blocked by the inherited
DateTimeOffset.MinValuecursor state; live fetch, parse, and map runs succeeded and Apple now has 24 source documents, 24 DTOs, and 24 advisory rows. - Adobe is no longer success-empty, but remains failed-live:
source:adobe:fetchrecordsAll Adobe index pages failed (1 attempted)becausehttps://helpx.adobe.com/security/security-bulletin.htmltimes out from the container at the configured 20 second client timeout. - Cert-IN remains failed-live after redeploy:
source:cert-in:fetchfails during TLS handshake withReceived an unexpected EOF or 0 bytes from the transport stream. - VEX status at 2026-05-09 10:53 UTC: Cisco, MSRC, Oracle, Red Hat, and Ubuntu have raw VEX documents; OCI OpenVEX remains operator-configuration blocked; SUSE Rancher remains source-discovery/offline-snapshot blocked; Red Hat and Ubuntu stale
Runningheartbeats were moved to terminal cancelled/failed state before their new scheduled retries started. - Exact VEX counts at this recheck:
vex.vex_raw_documents= 43163;vexhub.statements= 24268422; verified VexHub statements = 42554. - Seed export is still not ready unless performed as an explicit checkpointed export: Concelier has active source jobs with live leases and Excititor Red Hat/Ubuntu retries are running.
This page is the Stella Ops Mirror connector state record for the current bootstrap dataset. It separates rows that are actually aggregating from rows that are blocked by operator configuration, blocked by policy or source defects, or intentionally represented by a parent aggregation.
Summary
| Family | Rows | Rows with aggregation data | Enabled rows | Item count | Source docs | DTOs | Failed rows |
|---|---|---|---|---|---|---|---|
| Advisory sources, excluding distro rows | 47 | 38 have docs/items | 26 | 34834 advisory rows | 8480 | 7794 | Adobe and Cert-IN remain failed-live; ARM/source-policy rows remain blocked |
| Distro sources | 8 | 8 | 5 | 9558 advisory rows | 1139 | 1080 | 0 data failures; Astra remains policy-gated for public export |
| VEX providers | 7 | 5 have VexHub statements | 5 | 24268422 VexHub statements | 43163 raw VEX docs | n/a | OCI OpenVEX and SUSE Rancher have no statements |
VEX trust split:
- Trusted VEX mirror data:
excititor:redhatand the verified subset ofexcititor:cisco. - Cache-only or unsigned/internal VEX data:
excititor:ubuntu,excititor:msrc,excititor:oracle, and the non-verified Cisco historical subset. - Configuration-blocked VEX:
excititor:oci-openvex. - Non-configuration VEX blockers:
excititor:suse-rancher.excititor:oracleis aggregating only as degraded/cache-only data and remains excluded from trusted VEX publication unless a signed-trust policy is supplied.
Current completion gate:
- Concelier still has active aggregation work.
/jobs/activereturnedsource:redhat:map,source:osv:map, andsource:cert-fr:fetchat the 2026-05-09 10:53 UTC recheck, and all had live leases. - Excititor has no stale provider heartbeat at this recheck. Red Hat and Ubuntu have real scheduled retries heartbeating
Running. - Result: the current aggregation is not ready for connector re-setup testing yet. Backups can be taken, but seed export should wait until active Concelier jobs stop or are intentionally checkpointed.
Latest recheck after backup:
- Rechecked at
2026-05-08T05:36:32Z. - Concelier still has active aggregation work:
/jobs/activereturnedsource:osv:map, started at2026-05-08T05:30:00Z. - Excititor still has active VEX work:
excititor:ubuntuis heartbeatingRunningat2026-05-08 05:36:09Z. - Ubuntu VEX advanced from the snapshot to
16908raw VEX docs and10225982VexHub statements. - Result remains: not ready for connector re-setup testing.
GHSA redeploy and live recheck:
- Rechecked at
2026-05-08T06:48:52Zafter redeployingstellaops/concelier:devimagesha256:b7c13891646c7e76d16c60b997f7fe1342f5c7fb51ea31b572b61b4a0b6a8ce8. - GHSA is no longer credential-blocked: the source row is enabled and uses the public GitHub REST
/advisoriesendpoint. The token remains optional for higher rate limits or enterprise routing. - The first live fetch failed fast in
00:00:00.6900120because GitHub returned403/ anonymous REST rate limit exhausted for egress IP195.149.251.242; this was an operational quota blocker, not a missing-credentials requirement. - Rebuilt again with the detail-rate-limit cursor preservation fix and messaging transport plugin staging; final healthy image is
sha256:0c0bab9c496242b02c4b604c4761abce35c776819cd3d164c074dbea341392d6. - Live repair seeded the 50 already-downloaded GHSA raw document ids back into the cursor; manual parse
69eb85ca-1a92-f572-0d5b-bba7f41eed5band map7dce418a-62d2-c1d4-41f9-9c0a811138e8succeeded. - After quota reset, container-side
https://api.github.com/rate_limitreturnedx-ratelimit-remaining=60; manual fetch88e4e220-34cf-d333-58f1-bb2a7c62fd76and scheduled fetcha9fc14d7-2391-f88f-c1c7-9ed98c348885both succeeded. - Final GHSA recheck at
2026-05-08T07:11:43Z: 60 source documents, 60 DTOs, and 60 canonicalvuln.advisories; cursor is clean for pending docs/mappings and is progressing through the 30-day window atnextPage=3. - A token is still recommended for production bootstrap scale. Without a token, keep the default small batch (
pageSize=10,maxPagesPerFetch=1) so anonymous REST quota resets can sustain progress.
Failure split
Configuration or operator-input blocked rows:
| Row | Family | Why it is blocked | Operator action |
|---|---|---|---|
auscert | Advisory | Public RSS paths exist, but direct egress from this workspace times out after partial source-document capture. | Provide an approved relay or offline mirror for cyber.gov.au RSS. |
cert-in | Advisory | Public HTML listing exists, but TLS handshakes reset from this workspace. | Provide an approved egress path or relay for cert-in.org.in. |
cisco | Advisory | The legacy advisory connector is credential/current-mode disabled. Cisco VEX works separately through Excititor. | Supply the advisory-side OAuth/mirror configuration only if this legacy advisory source is needed. |
microsoft | Advisory | Legacy advisory connector is credential/current-mode disabled. MSRC VEX public cache runs separately. | Supply MSRC credentials only if the legacy advisory source is required. |
stella-mirror | Advisory relay | This is the downstream mirror/seed import source and is empty until a Stella seed bundle is imported. | Import a generated seed bundle during setup. |
excititor:oci-openvex | VEX | No generic public feed exists; it needs at least one OCI image subscription and trust material. | Configure image subscriptions and cosign/TUF material. |
Non-configuration blockers:
| Row | Family | Why configuration cannot fix it |
|---|---|---|
adobe | Advisory | Fail-closed fix is deployed. Live source:adobe:fetch now fails explicitly with All Adobe index pages failed (1 attempted) because the public Adobe index times out from this container. |
azure | Advisory | Cataloged/disabled source with no live public aggregation surface in this host. |
bundler-audit | Advisory | Cataloged/disabled source with no independent runnable aggregation in this host. |
fstec-bdu | Advisory | Public material is policy/export-control gated for Stella-managed public mirror publication and currently has TLS errors. |
astra | Distro | Public OVAL data exists and 200 rows are present, but public Stella-managed redistribution needs policy/export-control approval. |
kaspersky-ics | Advisory | Public RSS data exists and 1 row is present, but public Stella-managed redistribution needs policy/export-control approval. |
nkcki | Advisory | Public safe-surf data exists and 1 row is present, but public Stella-managed redistribution needs policy/export-control approval. |
excititor:oracle | VEX | Oracle CSAF JSON is public, but observed .json.asc signatures and usable CSAF provider metadata are absent; trusted mirror publication must fail closed. |
excititor:suse-rancher | VEX | Current discovery shape is unavailable from the default hub; it needs connector/source work against a reachable public Rancher VEX source or an approved offline snapshot. |
Expected empty or parent-backed rows, not failures:
epsswrites EPSS scores as an overlay, so zerovuln.advisoriesrows is expected.osvis the parent ingest for OSV documents; ecosystem item rows are attributed to buckets such asnpm,pypi,go,chainguard, andwolfi.- OSV-backed disabled buckets with item rows stay disabled as standalone schedules until an independent connector is added.
Advisory aggregations
Items are rows in vuln.advisories. Source docs and DTOs come from concelier.source_documents and concelier.dtos.
| Source | Enabled | Items | Source docs | DTOs | Last aggregation UTC | Status |
|---|---|---|---|---|---|---|
adobe | true | 0 | 0 | 0 | 2026-05-09 00:09:39 | Failed-live: fail-closed path deployed; public Adobe index times out from this container. |
amd | true | 10 | 11 | 0 | 2026-05-09 00:09:00 | Success; raw index/detail HTML retained. |
apple | true | 24 | 24 | 24 | 2026-05-09 00:12:00 | Success. |
auscert | true | 0 | 2 | 0 | 2026-05-06 00:25:00 | Config/ops blocked: direct egress timeout, relay/offline mirror required. |
aws | true | 20 | 1 | 0 | 2026-05-09 00:02:57 | Success; feed payload retained. |
azure | false | 0 | 0 | 0 | Fails other: cataloged/disabled in this host. | |
bundler-audit | false | 0 | 0 | 0 | Fails other: no independent runnable aggregation in this host. | |
cccs | true | 4135 | 4246 | 4246 | 2026-05-08 04:52:04 | Progressing with 80 pending docs and 27 failed docs. |
cert-cc | true | 77 | 323 | 77 | 2026-05-08 04:55:04 | Success. |
cert-de | true | 250 | 356 | 250 | 2026-05-08 04:51:00 | Success with 106 old failed WID docs retained. |
cert-fr | true | 10 | 10 | 10 | 2026-05-08 06:53:36 | Success from public CERT-FR feed. |
cert-in | false | 0 | 0 | 0 | 2026-05-09 00:09:42 | Config/ops blocked: TLS EOF during handshake from this container. |
chromium | true | 18 | 21 | 19 | 2026-05-08 04:49:00 | Success with 2 failed docs retained. |
cisco | false | 0 | 0 | 0 | Config blocked for legacy advisory source; Cisco VEX works separately. | |
crates | false | 119 | 0 | 0 | 2026-05-08 04:44:41 | Covered by OSV parent; standalone disabled. |
cve | true | 999 | 1000 | 1000 | 2026-05-09 00:13:02 | Success: public no-credential cvelistV5 backend retained 1000 raw CVE JSON records and mapped 999 canonical advisories. |
epss | true | 0 | 2 | 2 | 2026-05-06 23:05:27 | Overlay source, not an advisory-row source. |
fstec-bdu | false | 0 | 0 | 0 | Fails other: policy/export-control gate plus TLS error. | |
gcp | true | 30 | 1 | 0 | 2026-05-09 00:02:57 | Success; feed payload retained. |
ghsa | true | 118 | 124 | 120 | 2026-05-09 00:15:02 | Success/progressing through public REST. Optional token recommended for faster bootstrap scale. |
go | false | 141 | 0 | 0 | 2026-05-08 04:44:39 | Covered by OSV parent; standalone disabled. |
govuln | false | 15 | 0 | 0 | 2026-05-08 04:53:28 | Covered by OSV parent; standalone disabled. |
hex | false | 8 | 0 | 0 | 2026-05-07 19:47:31 | Covered by OSV parent; standalone disabled. |
intel | true | 238 | 239 | 0 | 2026-05-09 00:04:00 | Success from public Intel Security Center CSAF; GitHub directory and CSAF payloads retained. |
jpcert | true | 1 | 1 | 1 | 2026-05-08 04:49:01 | Success. |
kaspersky-ics | false | 1 | 1 | 1 | 2026-05-08 04:37:04 | Has data, but policy/export-control gated for public Stella mirror. |
kev | true | 1592 | 1 | 1 | 2026-05-06 23:05:28 | Success with 1 pending doc retained. |
krcert | true | 11 | 11 | 11 | 2026-05-09 00:07:00 | Success from public Boho RSS. |
maven | false | 101 | 0 | 0 | 2026-05-07 19:47:31 | Covered by OSV parent; standalone disabled. |
microsoft | false | 0 | 0 | 0 | Config blocked for legacy advisory source; MSRC VEX cache runs separately. | |
mitre-attack | true | 50 | 1 | 0 | 2026-05-09 00:03:19 | Success; STIX/TAXII payload retained. |
mitre-d3fend | true | 100 | 1 | 0 | 2026-05-09 00:05:00 | Success; STIX/TAXII payload retained. |
nkcki | false | 1 | 1 | 1 | 2026-05-08 04:35:00 | Has data, but policy/export-control gated for public Stella mirror. |
npm | false | 334 | 0 | 0 | 2026-05-08 04:44:39 | Covered by OSV parent; standalone disabled. |
nvd | true | 25676 | 31 | 29 | 2026-05-09 00:06:02 | Success. |
oracle | true | 57 | 57 | 57 | 2026-05-09 00:13:10 | Success for advisory Oracle. This is not the blocked Oracle VEX provider. |
osv | true | 0 | 1625 | 1576 | 2026-05-09 00:05:01 | Parent aggregation running/progressing; child ecosystem rows carry the item counts. |
packagist | false | 39 | 0 | 0 | 2026-05-08 04:53:29 | Covered by OSV parent; standalone disabled. |
pypa | false | 2 | 0 | 0 | 2026-05-08 04:44:41 | Covered by OSV parent; standalone disabled. |
pypi | false | 158 | 0 | 0 | 2026-05-08 04:44:35 | Covered by OSV parent; standalone disabled. |
rubygems | false | 9 | 0 | 0 | 2026-05-07 19:43:56 | Covered by OSV parent; standalone disabled. |
rustsec | false | 4 | 0 | 0 | 2026-05-07 09:50:01 | Covered by OSV parent; standalone disabled. |
siemens | true | 25 | 26 | 0 | 2026-05-09 00:15:00 | Success; CSAF feed/detail payloads retained. |
stella-mirror | true | 0 | 0 | 0 | Seed import target; empty until the generated seed bundle is imported. | |
us-cert | true | 58 | 2 | 2 | 2026-05-08 04:53:07 | Success. |
vmware | true | 2 | 2 | 2 | 2026-05-08 04:40:05 | Success. |
Distro aggregations
| Source | Enabled | Items | Source docs | DTOs | Last aggregation UTC | Status |
|---|---|---|---|---|---|---|
alpine | true | 8311 | 16 | 16 | 2026-05-09 00:12:00 | Success/progressing. |
astra | false | 200 | 2 | 0 | 2026-05-09 00:11:36 | Has local data and retained OVAL XML, but public Stella mirror export remains policy/export-control gated. |
chainguard | false | 100 | 0 | 0 | Covered by OSV parent; standalone disabled. | |
debian | true | 52 | 53 | 51 | 2026-05-09 00:12:00 | Success with resilient DSA retry fallback. |
redhat | true | 656 | 840 | 840 | 2026-05-09 00:15:00 | Progressing; scheduler map work still active at this recheck. |
suse | true | 74 | 125 | 74 | 2026-05-09 00:10:00 | Success/progressing. |
ubuntu | true | 99 | 103 | 99 | 2026-05-09 00:10:00 | Success; historical zero-byte payload anomaly remains fixed. |
wolfi | false | 66 | 0 | 0 | Covered by OSV parent; standalone disabled. |
VEX aggregations
Items are vexhub.statements. Raw docs are rows in vex.vex_raw_documents.
| Provider | Enabled | Kind | Raw docs | VexHub statements | Verified statements | Last aggregation UTC | Status |
|---|---|---|---|---|---|---|---|
excititor:cisco | true | vendor | 79 | 42363 | 21444 | 2026-05-09 09:48:36 | Success. Verified Cisco PSIRT OpenPGP data is present, but older non-verified Cisco rows remain cache-only. |
excititor:msrc | true | vendor | 1691 | 5173 | 0 | 2026-05-09 09:56:13 | Success as cache-only/internal unsigned data; Microsoft detached signatures/redistribution posture are unresolved. |
excititor:oci-openvex | false | attestation | 0 | 0 | 0 | Config blocked: image subscriptions and trust artifacts required. | |
excititor:oracle | true | vendor | 20 | 14522 | 0 | 2026-05-09 00:01:06 | Blocked/degraded for trusted VEX: public CSAF cache data exists, but latest run quarantined malformed UTF-8 and no detached trust material is available. |
excititor:redhat | true | distro | 21110 | 21110 | 21110 | 2026-05-09 10:53:27 heartbeat | Trusted data exists; stale Running was reconciled, and the current heartbeat is a real scheduled PGP-verified retry. |
excititor:suse-rancher | false | hub | 0 | 0 | 0 | 2026-05-08 21:40:29 | Fails other: discovery metadata unavailable or offline snapshot required. |
excititor:ubuntu | true | distro | 20260+ | 24167842+ | 0 | 2026-05-09 10:53:27 heartbeat | Unsigned Canonical OpenVEX cache data exists; stale Running heartbeat was reconciled, and the current heartbeat is a real scheduled retry. |
Configuration surface cleanup
Only sources that are actually fixable by operator configuration should appear as configuration choices.
Keep configuration surfaces for:
- Advisory
ghsa,cisco, andmicrosoft. GHSA configuration is optional and exists for higher GitHub rate limits or enterprise routing; Cisco and Microsoft remain credential/selected-mode choices for the legacy advisory sources. - Advisory
chromium,oracle, andadobewhere the surface is an endpoint/mirror override and not the current blocker. Adobe should stop being empty only after the verified local fix is deployed and the live jobs rerun. - VEX
excititor:cisco,excititor:ubuntu,excititor:msrc, andexcititor:oci-openvex.
Remove or suppress configuration surfaces for:
- VEX
excititor:oracle, because missing public detached signatures/provider trust material is not a setup-time credential issue. - VEX
excititor:suse-rancher, because the current blocker is source/discovery shape, not a credential field operators can safely fill. - Any future source whose live blocker is parser/source implementation, policy/export-control, or no official public mirror rather than a missing operator secret or endpoint override.
Seed export/import format
The export/import format is a Stella Ops Mirror seed archive, not a plain database dump. Format name: stellaops-mirror-seed-v1.
Archive layout:
stellaops-mirror-seed-v1/
manifest.json
data/
vuln.sources.copy.zst
vuln.source_states.copy.zst
vuln.feed_snapshots.copy.zst
vuln.advisory_snapshots.copy.zst
vuln.advisories.copy.zst
vuln.advisory_aliases.copy.zst
vuln.advisory_cvss.copy.zst
vuln.advisory_affected.copy.zst
vuln.advisory_references.copy.zst
vuln.advisory_credits.copy.zst
vuln.advisory_weaknesses.copy.zst
vuln.kev_flags.copy.zst
vuln.advisory_canonical.copy.zst
vuln.advisory_source_payload.copy.zst
vuln.advisory_source_edge.copy.zst
vuln.issue_observations.copy.zst
vuln.issue_linksets.copy.zst
vuln.issue_evidence_refs.copy.zst
concelier.source_documents.copy.zst
concelier.dtos.copy.zst
vex.providers.copy.zst
vex.connector_states.copy.zst
vex.vex_raw_documents.copy.zst
vex.vex_raw_blobs.copy.zst
vex.vex_raw_attachments.copy.zst
vex.linksets.copy.zst
vex.linkset_observations.copy.zst
vex.linkset_disagreements.copy.zst
vex.linkset_mutations.copy.zst
vex.claims.copy.zst
vex.deltas.copy.zst
vex.checkpoint_states.copy.zst
vex.checkpoint_mutations.copy.zst
vex.attestations.copy.zst
vexhub.sources.copy.zst
vexhub.statements.copy.zst
vexhub.provenance.copy.zst
vexhub.conflicts.copy.zst
Manifest requirements:
formatVersion,createdAt,tenantId,checkpointMode,sourceDatabase, Stella Ops build/git revision when available, and DB migration watermark.- Per-source/provider summary with key, type, enabled state, status, failure classification, trust classification, item count, first aggregation time, last aggregation time, and last error.
- Per-table row count, path, byte count, SHA-256, exported column list, optional export filter, and optional skip reason for schemas/tables not present on a deployment.
- Top-level warnings for checkpointed exports and clean-seed exclusions, including non-mapped raw source documents that were deliberately left out of
concelier.source_documents/concelier.dtos. - Active-work summary when the export is checkpointed: Concelier
vuln.job_runs, Excititor connector heartbeat state, and VexHub ingestion jobs. - Sanitized connector/source configuration. The exporter removes credential-like JSON keys and disables exported rows that are credential-blocked.
- Content hashes are carried in
manifest.json; v1 does not write a separate checksum file. - Explicit exclusion list for non-exportable secrets. Do not export provider API tokens, client secrets, registry passwords, host paths, or private trust material.
- Unified issue projection coverage: count exported
vuln.issue_linksets,vuln.issue_observations, andvuln.issue_evidence_refs; link to the migration watermark that produced them.
Exporter behavior:
- Refuse export while active work exists unless
allowCheckpointedActiveJobs=true, in which case the active work is listed inmanifest.json. - Run a read-only transaction at repeatable-read isolation.
- Export table data through PostgreSQL
COPYto Zstandard-compressed CSV chunks, preserving tenant/source IDs. - Export only mapped raw source documents and DTOs for clean setup replay.
concelier.source_documentsis filtered tostatus = 'mapped';concelier.dtosis filtered to DTOs whose document is mapped. Failed, pending-parse, and pending-map raw work is operational residue, not completed aggregate data, and is reported throughmanifest.jsonwarnings. - Export advisory source payloads through
vuln.advisory_source_payloadwhen present. Legacy archives that still carryvuln.advisory_source_edge.raw_payloadare imported through a staging transform that writes one payload row persource_doc_hashand keeps edgeraw_payloadnull. - Hash every chunk before writing
manifest.json. - For space-constrained live exports,
skipVexHubProjection=trueomitsvexhub.statements,vexhub.provenance, andvexhub.conflictswith manifest skip reasons. Full/compact seeds retainvex.claims, and the VexHub projection is rebuilt locally from that retained serving tier after import. A non-empty VEX source-only export fails closed: re-normalizing raw vendor documents can expand them into hundreds or thousands of product-grain rows and recreate the storage incident.
Importer/setup behavior:
- During setup, enable
Mirror:SeedImportso Concelier imports the seed before mirror export and source scheduler hosted services start. - Validate migration watermark and schema compatibility before copying data.
- Restore successful public/no-credential rows and blocked-state explanations.
- Do not import secret values; leave credential-required sources disabled or configuration-blocked.
- Resume schedules from imported cursors/checkpoints so the next setup fetches only deltas.
- Disable client command timeout and PostgreSQL
statement_timeoutfor the archive import/export session because full setup seeds can contain multi-GBCOPYchunks. Host shutdown or tool cancellation remains the cancellation boundary. - Accept older
advisory_cvsschunks that predate thecve_idcolumn. New exports includecve_id; older chunks import through a conflict-tolerant staging path so duplicate legacy CVSS rows do not block first setup. - Accept older
vex.claimschunks that predate compact document columns. Legacydocument_jsonvalues are staged, split intodocument_format,document_source_uri,document_revision, anddocument_signature_json, and imported withdocument_jsonset to null. - Destructive local clean-replay runs pause
stellaops-excititor-web,stellaops-excititor-worker, andstellaops-vexhub-webwhile Concelier imports the seed, then restart those writers after the Concelier import marker. This keeps VEX checkpoint writers from contending with the first-load claims import.
Startup import configuration:
Mirror:SeedImport:Enabled: opt-in startup gate. Defaults tofalse.Mirror:SeedImport:SeedDirectory: path to thestellaops-mirror-seed-v1archive root.Mirror:SeedImport:TenantId: target tenant, defaultdefault.Mirror:SeedImport:ReplaceExisting: destructive replacement mode for controlled fresh setup tests only.Mirror:SeedImport:ValidateOnly: validate manifest/schema/hash without copying rows.Mirror:SeedImport:SkipVexHubProjection: skips optionalvexhub.*rows during import. The archive must retainvex.claimsorvex.vex_raw_documents; otherwise export fails closed. After VexHub migrates its schema, the Excititor Worker repairs the projection locally even when every provider schedule is disabled.Mirror:SeedImport:SkipWhenTargetNotEmpty: defaulttrue; lets normal restarts continue after the seed is already present.Mirror:SeedImport:FailStartupOnError: defaulttrue; validation/import failures stop the host before schedulers run.Mirror:SeedImport:DeltaApply: opt in only whenSeedDirectoryis a delta bundle. The startup gate verifies the locally recorded baseline digest before any write, then UPSERTs changed source rows and records the applied delta digest for the next link in the chain. Leave thisfalsefor full bundles.
A destination is not reader-ready merely because import returned success. Keep the front door out of rotation until local VEX repair reports completed=true, the enforced claim-to-VexHub anti-join is empty, and one canonical CVE/product sample is readable through Excititor, VexHub, and the Concelier issue reader. Advisory-only claims are intentionally absent from VexHub and are excluded from that parity condition.
Scoped and delta bundles:
- Export a sealed baseline first. Use
--profile source-onlyfor the smallest re-derivable distribution bundle. A scoped baseline can repeat--sourceand--ecosystem; selector resolution is fail-closed, so an unknown selector aborts instead of producing an empty archive. - After source rows advance, export a delta with
--delta-baseline <baseline>/manifest.json. The manifest records the baseline bundle digest, strict-after watermarks, and changed row counts. A no-change delta contains no data rows. - Import the baseline normally. This records its sealed digest in
vuln.mirror_seed_state. - Apply the next bundle with
--delta-apply. The importer compares the delta’s baseline digest with the locally recorded digest before writing, then natural-key UPSERTs changed rows and preserves unchanged rows. A missing or mismatched anchor is a hard failure.
stella mirror seed export --connection-string $dsn --output-directory C:\mirror\ubuntu-baseline --profile source-only --source ubuntu
stella mirror seed export --connection-string $dsn --output-directory C:\mirror\ubuntu-delta-001 --profile source-only --source ubuntu --delta-baseline C:\mirror\ubuntu-baseline\manifest.json
stella mirror seed import --connection-string $targetDsn --seed-directory C:\mirror\ubuntu-baseline
stella mirror seed import --connection-string $targetDsn --seed-directory C:\mirror\ubuntu-delta-001 --delta-apply
The lower-level StellaOps.Concelier.MirrorSeedTool exposes the same --profile, repeatable --source/--ecosystem, --delta-baseline, and --delta-apply contract for repository and recovery workflows. Both surfaces reuse PostgresMirrorSeedArchiveService; neither fetches from an external network.
Operational scripts:
stella mirror seed export|validate|import|downloadis the operator CLI surface for creating a clean seed, validating it, copying it into the ingestion catalog, and replaying it into a local database. In source checkouts, run it throughdotnet run --project src\Cli\StellaOps.Cli\StellaOps.Cli.csproj -- mirror seed <command>.devops/mirror/export-concelier-seed.ps1remains the PowerShell wrapper for exporting the live database with the repository tool. Use-AllowCheckpointedActiveJobsonly when the manifest should explicitly record active work. Use-SkipVexHubProjectionwhen disk space cannot hold the duplicate VexHub projection tables.devops/mirror/prepare-concelier-seed-import.ps1 -SeedArchiveRoot <path>writes a compose override, env file, and setup note that mount a seed archive and enableMirror:SeedImportfor the Concelier service. The generated replay profile setsSkipVexHubProjection=true; after import, start VexHub for schema convergence and the Worker for its provider-independent local repair. Provider schedules may remain disabled.tools/scripts/qa/Wipe-And-Rebuild.ps1 -Confirm -PinnedSeedDir <seed>is the destructive local replay harness. For seed-import runs it prepares the Concelier override withReplaceExisting=true, waits for the Concelier import marker, keeps VEX writers paused during import, restarts those writers afterward, and probes the frontdoor.devops/mirror/test-concelier-seed-import-e2e.ps1is the repeatable bounded clean-import proof. It creates isolated source and target PostgreSQL containers, applies real Concelier and Excititor startup migrations, exports a seed with advisory and VEX issue observations, imports it through the Concelier startup gate, verifies target counts and evidence refs, and cleans up its containers on success.devops/mirror/seeds/README.mdis the repository catalog for seed cards. The current ingestion seed card isdevops/mirror/seeds/20260607T003352Z/seed-card.json; the multi-GB seed payload is stored under the seed directory through Git LFS and keyed by the manifest hash.
API surface:
POST /api/v1/advisory-sources/mirror/seeds/exportcreates a seed archive at a configured or requested output path.POST /api/v1/advisory-sources/mirror/seeds/validateverifies manifest version, table existence, columns, byte counts, and SHA-256 without importing rows.POST /api/v1/advisory-sources/mirror/seeds/importimports the archive. Non-empty target tables are rejected unlessreplaceExisting=true.
Operational checkpoint:
- A binary
pg_dump -Fcbackup is useful as a safety backup, but it is not the setup seed format. The seed format must be selective, secret-free, content-hashed, and importable before schedulers start. - Unified issue projection implementation details live in
docs/modules/concelier/unified-issue-projection.md. Backfill the projection in bounded chunks before exporting the seed so SBOM/finding flows can resolve against the same skeleton after import. - Clean setup replay is covered by
devops/mirror/test-concelier-seed-import-e2e.ps1. The 2026-05-11 passing run wrote evidence toC:\temp\stellaops-mirror-seed-e2e\20260511T225811Z\e2e-result.json. - The 2026-06-07 seed run was point-in-time validation evidence, not a current checked-in distribution payload. Its repository payload was removed during workspace cleanup. Generate a fresh sealed archive for distribution; when VexHub projection tables are skipped, the destination-local Worker repair rebuilds them from retained claims. Raw-only VEX reconstruction is intentionally refused.
