File size: 2,593 Bytes
a6a5d8e
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
 
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
51
52
53
54
55
56
57
58
59
60
61
62
63
64
65
66
67
68
# OPS_NOTES.md — a11oy operational notes

Authored for SZL Holdings. Signed-off per repository DCO.
Doctrine v7 compliant — no fake-green labels, no marketing superlatives.

---

## Base image disclosure — Iron Bank gap

**Current base images are vanilla (not Iron Bank-approved):**

| Stage   | Image           | Notes                                      |
|---------|----------------|--------------------------------------------|
| builder | `node:22-alpine` | Official Docker Hub Node.js Alpine image   |
| runtime | `node:22-alpine` | Same — minimal Alpine; not hardened        |

Iron Bank-approved base images (e.g., `registry1.dso.mil/ironbank/opensource/nodejs/nodejs22`)
are **not** currently used. This is an honest gap, not a configuration oversight.

Iron Bank hardening is a Warhacker hardening item tracked in:
**[szl-holdings/a11oy#164 — chore(hardening): migrate to Iron Bank-approved base images](https://github.com/szl-holdings/a11oy/issues/164)**

Until that issue is resolved and the Dockerfile updated, do **not** label this image as
Iron Bank-compliant or DoD IL-approved. Claims of IL-5/IL-6 suitability require the
Iron Bank base plus a Platform One Continuous Authority to Operate (cATO) review.

---

## Serve mode (HTTP API)

The `serve` subcommand starts an HTTP API on `A11OY_PORT` (default `8080`).
It is implemented by `packages/receipt-substrate/src/server.ts` (serve-BE PR, pending merge).
Until that PR lands, the entrypoint exits with a clear error if `serve` is invoked and the
server module is absent — no silent hang, no fake-green probe response.

Probes:
- `GET /healthz` — liveness: returns `{"status":"ok"}` once the process is up.
- `GET /readyz`  — readiness: returns `{"status":"ready"}` after full initialisation.

---

## Container image registry

Production images: `ghcr.io/szl-holdings/a11oy`

Tagging strategy:
- `sha-<7-hex>` — every push to `main` (continuous delivery tag).
- `<semver>` + `latest` — published GitHub Releases only.
- `pr-<7-hex>` — pull-request builds (local daemon only; not pushed to GHCR).

---

## SLSA posture

Current level: **SLSA L1 (honest)** — source + build provenance documented via
`slsa-provenance.yml`. L2/L3 require Sigstore + isolated builders (roadmap item).

---

## Known gaps (tracked)

| Gap | Tracking |
|-----|----------|
| Iron Bank base images | [#164](https://github.com/szl-holdings/a11oy/issues/164) |
| `serve` subcommand server module | serve-BE PR (pending) |
| SPA routes wired to real data | SPA-repair PR (pending) |
| SLSA L2/L3 isolated builder | ROADMAP.md |