Connector aggregation state

Snapshot base: 2026-05-08 04:55 UTC from the live stellaops_platform database and running Concelier/Excititor containers. CERT-FR was refreshed at 2026-05-08 06:53 UTC, and GHSA was refreshed at 2026-05-08 07:11 UTC after the public REST fix and redeploy.

Latest live recheck: 2026-05-09 10:53 UTC after the Concelier stale job-run reconciliation fix, the Excititor stale provider-heartbeat reconciliation fix, Concelier image sha256:c220f985c6957c11d1254b71de4090ba3d9673786954144f58ba5642777b06e3, and Excititor worker image sha256:ced423d06d03ffb4fe0b47fe4de0e3531e0a7c286f9e8b7d4785bbe894dce217.

This page is the Stella Ops Mirror connector state record for the current bootstrap dataset. It separates rows that are actually aggregating from rows that are blocked by operator configuration, blocked by policy or source defects, or intentionally represented by a parent aggregation.

Summary

FamilyRowsRows with aggregation dataEnabled rowsItem countSource docsDTOsFailed rows
Advisory sources, excluding distro rows4738 have docs/items2634834 advisory rows84807794Adobe and Cert-IN remain failed-live; ARM/source-policy rows remain blocked
Distro sources8859558 advisory rows113910800 data failures; Astra remains policy-gated for public export
VEX providers75 have VexHub statements524268422 VexHub statements43163 raw VEX docsn/aOCI OpenVEX and SUSE Rancher have no statements

VEX trust split:

Current completion gate:

Latest recheck after backup:

GHSA redeploy and live recheck:

Failure split

Configuration or operator-input blocked rows:

RowFamilyWhy it is blockedOperator action
auscertAdvisoryPublic RSS paths exist, but direct egress from this workspace times out after partial source-document capture.Provide an approved relay or offline mirror for cyber.gov.au RSS.
cert-inAdvisoryPublic HTML listing exists, but TLS handshakes reset from this workspace.Provide an approved egress path or relay for cert-in.org.in.
ciscoAdvisoryThe legacy advisory connector is credential/current-mode disabled. Cisco VEX works separately through Excititor.Supply the advisory-side OAuth/mirror configuration only if this legacy advisory source is needed.
microsoftAdvisoryLegacy advisory connector is credential/current-mode disabled. MSRC VEX public cache runs separately.Supply MSRC credentials only if the legacy advisory source is required.
stella-mirrorAdvisory relayThis is the downstream mirror/seed import source and is empty until a Stella seed bundle is imported.Import a generated seed bundle during setup.
excititor:oci-openvexVEXNo generic public feed exists; it needs at least one OCI image subscription and trust material.Configure image subscriptions and cosign/TUF material.

Non-configuration blockers:

RowFamilyWhy configuration cannot fix it
adobeAdvisoryFail-closed fix is deployed. Live source:adobe:fetch now fails explicitly with All Adobe index pages failed (1 attempted) because the public Adobe index times out from this container.
azureAdvisoryCataloged/disabled source with no live public aggregation surface in this host.
bundler-auditAdvisoryCataloged/disabled source with no independent runnable aggregation in this host.
fstec-bduAdvisoryPublic material is policy/export-control gated for Stella-managed public mirror publication and currently has TLS errors.
astraDistroPublic OVAL data exists and 200 rows are present, but public Stella-managed redistribution needs policy/export-control approval.
kaspersky-icsAdvisoryPublic RSS data exists and 1 row is present, but public Stella-managed redistribution needs policy/export-control approval.
nkckiAdvisoryPublic safe-surf data exists and 1 row is present, but public Stella-managed redistribution needs policy/export-control approval.
excititor:oracleVEXOracle CSAF JSON is public, but observed .json.asc signatures and usable CSAF provider metadata are absent; trusted mirror publication must fail closed.
excititor:suse-rancherVEXCurrent discovery shape is unavailable from the default hub; it needs connector/source work against a reachable public Rancher VEX source or an approved offline snapshot.

Expected empty or parent-backed rows, not failures:

Advisory aggregations

Items are rows in vuln.advisories. Source docs and DTOs come from concelier.source_documents and concelier.dtos.

SourceEnabledItemsSource docsDTOsLast aggregation UTCStatus
adobetrue0002026-05-09 00:09:39Failed-live: fail-closed path deployed; public Adobe index times out from this container.
amdtrue101102026-05-09 00:09:00Success; raw index/detail HTML retained.
appletrue2424242026-05-09 00:12:00Success.
auscerttrue0202026-05-06 00:25:00Config/ops blocked: direct egress timeout, relay/offline mirror required.
awstrue20102026-05-09 00:02:57Success; feed payload retained.
azurefalse000Fails other: cataloged/disabled in this host.
bundler-auditfalse000Fails other: no independent runnable aggregation in this host.
cccstrue4135424642462026-05-08 04:52:04Progressing with 80 pending docs and 27 failed docs.
cert-cctrue77323772026-05-08 04:55:04Success.
cert-detrue2503562502026-05-08 04:51:00Success with 106 old failed WID docs retained.
cert-frtrue1010102026-05-08 06:53:36Success from public CERT-FR feed.
cert-infalse0002026-05-09 00:09:42Config/ops blocked: TLS EOF during handshake from this container.
chromiumtrue1821192026-05-08 04:49:00Success with 2 failed docs retained.
ciscofalse000Config blocked for legacy advisory source; Cisco VEX works separately.
cratesfalse119002026-05-08 04:44:41Covered by OSV parent; standalone disabled.
cvetrue999100010002026-05-09 00:13:02Success: public no-credential cvelistV5 backend retained 1000 raw CVE JSON records and mapped 999 canonical advisories.
epsstrue0222026-05-06 23:05:27Overlay source, not an advisory-row source.
fstec-bdufalse000Fails other: policy/export-control gate plus TLS error.
gcptrue30102026-05-09 00:02:57Success; feed payload retained.
ghsatrue1181241202026-05-09 00:15:02Success/progressing through public REST. Optional token recommended for faster bootstrap scale.
gofalse141002026-05-08 04:44:39Covered by OSV parent; standalone disabled.
govulnfalse15002026-05-08 04:53:28Covered by OSV parent; standalone disabled.
hexfalse8002026-05-07 19:47:31Covered by OSV parent; standalone disabled.
inteltrue23823902026-05-09 00:04:00Success from public Intel Security Center CSAF; GitHub directory and CSAF payloads retained.
jpcerttrue1112026-05-08 04:49:01Success.
kaspersky-icsfalse1112026-05-08 04:37:04Has data, but policy/export-control gated for public Stella mirror.
kevtrue1592112026-05-06 23:05:28Success with 1 pending doc retained.
krcerttrue1111112026-05-09 00:07:00Success from public Boho RSS.
mavenfalse101002026-05-07 19:47:31Covered by OSV parent; standalone disabled.
microsoftfalse000Config blocked for legacy advisory source; MSRC VEX cache runs separately.
mitre-attacktrue50102026-05-09 00:03:19Success; STIX/TAXII payload retained.
mitre-d3fendtrue100102026-05-09 00:05:00Success; STIX/TAXII payload retained.
nkckifalse1112026-05-08 04:35:00Has data, but policy/export-control gated for public Stella mirror.
npmfalse334002026-05-08 04:44:39Covered by OSV parent; standalone disabled.
nvdtrue2567631292026-05-09 00:06:02Success.
oracletrue5757572026-05-09 00:13:10Success for advisory Oracle. This is not the blocked Oracle VEX provider.
osvtrue0162515762026-05-09 00:05:01Parent aggregation running/progressing; child ecosystem rows carry the item counts.
packagistfalse39002026-05-08 04:53:29Covered by OSV parent; standalone disabled.
pypafalse2002026-05-08 04:44:41Covered by OSV parent; standalone disabled.
pypifalse158002026-05-08 04:44:35Covered by OSV parent; standalone disabled.
rubygemsfalse9002026-05-07 19:43:56Covered by OSV parent; standalone disabled.
rustsecfalse4002026-05-07 09:50:01Covered by OSV parent; standalone disabled.
siemenstrue252602026-05-09 00:15:00Success; CSAF feed/detail payloads retained.
stella-mirrortrue000Seed import target; empty until the generated seed bundle is imported.
us-certtrue58222026-05-08 04:53:07Success.
vmwaretrue2222026-05-08 04:40:05Success.

Distro aggregations

SourceEnabledItemsSource docsDTOsLast aggregation UTCStatus
alpinetrue831116162026-05-09 00:12:00Success/progressing.
astrafalse200202026-05-09 00:11:36Has local data and retained OVAL XML, but public Stella mirror export remains policy/export-control gated.
chainguardfalse10000Covered by OSV parent; standalone disabled.
debiantrue5253512026-05-09 00:12:00Success with resilient DSA retry fallback.
redhattrue6568408402026-05-09 00:15:00Progressing; scheduler map work still active at this recheck.
susetrue74125742026-05-09 00:10:00Success/progressing.
ubuntutrue99103992026-05-09 00:10:00Success; historical zero-byte payload anomaly remains fixed.
wolfifalse6600Covered by OSV parent; standalone disabled.

VEX aggregations

Items are vexhub.statements. Raw docs are rows in vex.vex_raw_documents.

ProviderEnabledKindRaw docsVexHub statementsVerified statementsLast aggregation UTCStatus
excititor:ciscotruevendor7942363214442026-05-09 09:48:36Success. Verified Cisco PSIRT OpenPGP data is present, but older non-verified Cisco rows remain cache-only.
excititor:msrctruevendor1691517302026-05-09 09:56:13Success as cache-only/internal unsigned data; Microsoft detached signatures/redistribution posture are unresolved.
excititor:oci-openvexfalseattestation000Config blocked: image subscriptions and trust artifacts required.
excititor:oracletruevendor201452202026-05-09 00:01:06Blocked/degraded for trusted VEX: public CSAF cache data exists, but latest run quarantined malformed UTF-8 and no detached trust material is available.
excititor:redhattruedistro2111021110211102026-05-09 10:53:27 heartbeatTrusted data exists; stale Running was reconciled, and the current heartbeat is a real scheduled PGP-verified retry.
excititor:suse-rancherfalsehub0002026-05-08 21:40:29Fails other: discovery metadata unavailable or offline snapshot required.
excititor:ubuntutruedistro20260+24167842+02026-05-09 10:53:27 heartbeatUnsigned Canonical OpenVEX cache data exists; stale Running heartbeat was reconciled, and the current heartbeat is a real scheduled retry.

Configuration surface cleanup

Only sources that are actually fixable by operator configuration should appear as configuration choices.

Keep configuration surfaces for:

Remove or suppress configuration surfaces for:

Seed export/import format

The export/import format is a Stella Ops Mirror seed archive, not a plain database dump. Format name: stellaops-mirror-seed-v1.

Archive layout:

stellaops-mirror-seed-v1/
  manifest.json
  data/
    vuln.sources.copy.zst
    vuln.source_states.copy.zst
    vuln.feed_snapshots.copy.zst
    vuln.advisory_snapshots.copy.zst
    vuln.advisories.copy.zst
    vuln.advisory_aliases.copy.zst
    vuln.advisory_cvss.copy.zst
    vuln.advisory_affected.copy.zst
    vuln.advisory_references.copy.zst
    vuln.advisory_credits.copy.zst
    vuln.advisory_weaknesses.copy.zst
    vuln.kev_flags.copy.zst
    vuln.advisory_canonical.copy.zst
    vuln.advisory_source_payload.copy.zst
    vuln.advisory_source_edge.copy.zst
    vuln.issue_observations.copy.zst
    vuln.issue_linksets.copy.zst
    vuln.issue_evidence_refs.copy.zst
    concelier.source_documents.copy.zst
    concelier.dtos.copy.zst
    vex.providers.copy.zst
    vex.connector_states.copy.zst
    vex.vex_raw_documents.copy.zst
    vex.vex_raw_blobs.copy.zst
    vex.vex_raw_attachments.copy.zst
    vex.linksets.copy.zst
    vex.linkset_observations.copy.zst
    vex.linkset_disagreements.copy.zst
    vex.linkset_mutations.copy.zst
    vex.claims.copy.zst
    vex.deltas.copy.zst
    vex.checkpoint_states.copy.zst
    vex.checkpoint_mutations.copy.zst
    vex.attestations.copy.zst
    vexhub.sources.copy.zst
    vexhub.statements.copy.zst
    vexhub.provenance.copy.zst
    vexhub.conflicts.copy.zst

Manifest requirements:

Exporter behavior:

  1. Refuse export while active work exists unless allowCheckpointedActiveJobs=true, in which case the active work is listed in manifest.json.
  2. Run a read-only transaction at repeatable-read isolation.
  3. Export table data through PostgreSQL COPY to Zstandard-compressed CSV chunks, preserving tenant/source IDs.
  4. Export only mapped raw source documents and DTOs for clean setup replay. concelier.source_documents is filtered to status = 'mapped'; concelier.dtos is filtered to DTOs whose document is mapped. Failed, pending-parse, and pending-map raw work is operational residue, not completed aggregate data, and is reported through manifest.json warnings.
  5. Export advisory source payloads through vuln.advisory_source_payload when present. Legacy archives that still carry vuln.advisory_source_edge.raw_payload are imported through a staging transform that writes one payload row per source_doc_hash and keeps edge raw_payload null.
  6. Hash every chunk before writing manifest.json.
  7. For space-constrained live exports, skipVexHubProjection=true omits vexhub.statements, vexhub.provenance, and vexhub.conflicts with manifest skip reasons. Full/compact seeds retain vex.claims, and the VexHub projection is rebuilt locally from that retained serving tier after import. A non-empty VEX source-only export fails closed: re-normalizing raw vendor documents can expand them into hundreds or thousands of product-grain rows and recreate the storage incident.

Importer/setup behavior:

  1. During setup, enable Mirror:SeedImport so Concelier imports the seed before mirror export and source scheduler hosted services start.
  2. Validate migration watermark and schema compatibility before copying data.
  3. Restore successful public/no-credential rows and blocked-state explanations.
  4. Do not import secret values; leave credential-required sources disabled or configuration-blocked.
  5. Resume schedules from imported cursors/checkpoints so the next setup fetches only deltas.
  6. Disable client command timeout and PostgreSQL statement_timeout for the archive import/export session because full setup seeds can contain multi-GB COPY chunks. Host shutdown or tool cancellation remains the cancellation boundary.
  7. Accept older advisory_cvss chunks that predate the cve_id column. New exports include cve_id; older chunks import through a conflict-tolerant staging path so duplicate legacy CVSS rows do not block first setup.
  8. Accept older vex.claims chunks that predate compact document columns. Legacy document_json values are staged, split into document_format, document_source_uri, document_revision, and document_signature_json, and imported with document_json set to null.
  9. Destructive local clean-replay runs pause stellaops-excititor-web, stellaops-excititor-worker, and stellaops-vexhub-web while Concelier imports the seed, then restart those writers after the Concelier import marker. This keeps VEX checkpoint writers from contending with the first-load claims import.

Startup import configuration:

A destination is not reader-ready merely because import returned success. Keep the front door out of rotation until local VEX repair reports completed=true, the enforced claim-to-VexHub anti-join is empty, and one canonical CVE/product sample is readable through Excititor, VexHub, and the Concelier issue reader. Advisory-only claims are intentionally absent from VexHub and are excluded from that parity condition.

Scoped and delta bundles:

  1. Export a sealed baseline first. Use --profile source-only for the smallest re-derivable distribution bundle. A scoped baseline can repeat --source and --ecosystem; selector resolution is fail-closed, so an unknown selector aborts instead of producing an empty archive.
  2. After source rows advance, export a delta with --delta-baseline <baseline>/manifest.json. The manifest records the baseline bundle digest, strict-after watermarks, and changed row counts. A no-change delta contains no data rows.
  3. Import the baseline normally. This records its sealed digest in vuln.mirror_seed_state.
  4. Apply the next bundle with --delta-apply. The importer compares the delta’s baseline digest with the locally recorded digest before writing, then natural-key UPSERTs changed rows and preserves unchanged rows. A missing or mismatched anchor is a hard failure.
stella mirror seed export --connection-string $dsn --output-directory C:\mirror\ubuntu-baseline --profile source-only --source ubuntu
stella mirror seed export --connection-string $dsn --output-directory C:\mirror\ubuntu-delta-001 --profile source-only --source ubuntu --delta-baseline C:\mirror\ubuntu-baseline\manifest.json
stella mirror seed import --connection-string $targetDsn --seed-directory C:\mirror\ubuntu-baseline
stella mirror seed import --connection-string $targetDsn --seed-directory C:\mirror\ubuntu-delta-001 --delta-apply

The lower-level StellaOps.Concelier.MirrorSeedTool exposes the same --profile, repeatable --source/--ecosystem, --delta-baseline, and --delta-apply contract for repository and recovery workflows. Both surfaces reuse PostgresMirrorSeedArchiveService; neither fetches from an external network.

Operational scripts:

API surface:

Operational checkpoint: