Adds the manifest layer per ADR-0003. The canonical wire format is CBOR with deterministic encoding (cbor2 canonical=True: definite-length, shortest-form integers, sorted map keys); JCS (RFC 8785) is the JSON projection. src/artifactstore/manifest/: - model.py: frozen dataclasses for Manifest (manifest_version=1, package, files, storage_receipts, retention_summary, provenance) with restricted types (str/int/bool/None/list/dict) so CBOR and JCS round-trip losslessly. - codec.py: encode (Manifest -> canonical CBOR bytes) and decode (CBOR bytes -> Manifest) via cbor2. - projection.py: jcs_projection (Manifest -> RFC 8785 canonical JSON) plus cbor_from_jcs for cross-format round-trip verification. - digest.py: manifest_digest returns the BLAKE3 content address of the manifest's canonical CBOR bytes (ADR-0001). - __init__.py: re-exports the public surface. tests/unit/test_manifest.py: - decode(encode(m)) == m round-trip (hypothesis-parameterised). - JCS↔CBOR round-trip: encode(decode(cbor_from_jcs(jcs(m)))) == encode(m). - Byte stability of the canonical CBOR encoder across calls. - manifest_digest matches independent BLAKE3 over encode(m). - Decode rejects non-map CBOR. - JCS projection sorts keys lexicographically. Deps: jcs added to project requirements; mypy override for the jcs package (no stubs published yet). Gates: ruff clean, mypy --strict clean on 26 files, 26 tests pass. Co-Authored-By: Claude Opus 4.7 <noreply@anthropic.com>
artifact-store
Generic artifact registry and storage gateway for generated outputs, evidence packages, reports, logs, snapshots, exports, and release artifacts.
The registry owns artifact identity, metadata, provenance, retention policy, and retrieval records. Bytes are delegated to configured storage backends (local filesystem in v1, S3-compatible / Ceph RGW next).
The shape is library-first (artifactstore Python package); the HTTP
server and the CLI are thin consumers. Content is addressed by digest;
state is authoritative in an append-only event log; materialised views
are rebuildable.
Status
Scaffold landed. The core kernels and local FS backend follow in the remaining tasks of WP-0001.
Develop
Requires Python ≥ 3.12 and uv on the path.
make install # uv sync --all-extras
cp .env.example .env
make dev # uvicorn artifactstore.api.http:app --reload
make test # pytest
make lint # ruff check + ruff format --check
make type # mypy --strict
make migrate # alembic upgrade head (configured in WP-0001-T002)
The dev server listens on 127.0.0.1:8000. The scaffold root route
returns {"service": "artifact-store", "status": "scaffold"}; the real
/health endpoint lands in WP-0001-T014.
Documentation
- INTENT.md — purpose, product thesis, scope, boundary.
- SCOPE.md — lightweight orientation.
- docs/ARCHITECTURE-BLUEPRINT.md — v2 architecture: modules, data model, API shape.
- docs/PLATFORM-AMBITION.md — longer-horizon thesis and v1 schema commitments.
- docs/ROADMAP.md — workplan sequencing across phases.
- docs/adr/ — architecture decision records.
- docs/ASSEMBLY-EXPERIMENT.md — opt-in research line on hand-tuned asm for hot kernels.
Active workplans
- WP-0001 — Foundation: scaffold, core kernels, local FS backend
- WP-0002 — Ingestion API and manifest surface (planned)
- WP-0003 — Retention lifecycle (planned)
- WP-0004 — S3-compatible backend (planned)
- WP-0005 — Guide-board pilot ingestion (planned)
Agent operating notes
See AGENTS.md for the StateHub-integrated session protocol, workplan conventions, and progress-logging contract.