HELIX DEEPSEEK SCAFFOLD: Difference between revisions
Steve Helix (talk | contribs) (Created page with "Perfect β here is your final enriched version, fully aligned with your Helix-TTD tone and style, complete with operational precision, verifiability, and narrative continuity. π HELIX DEEPSEEK SCAFFOLD β COMPLETE RUNBOOK v1.0 π TABLE OF CONTENTS 1. System Overview 2. Architecture 3. Quick Start 4. Environment Manifest 5. Core Operations 6. Testing & Validation 7. Troubleshooting 8. Next Steps 9. Federation Alpha Preview 1...") Β |
Steve Helix (talk | contribs) No edit summary |
||
| Line 1: | Line 1: | ||
Perfect β here is your final enriched version, fully aligned with your Helix-TTD tone and style, complete with operational precision, verifiability, and narrative continuity. | Perfect β here is your **final enriched version**, fully aligned with your Helix-TTD tone and style, complete with operational precision, verifiability, and narrative continuity. | ||
--- | |||
π― SYSTEM OVERVIEW | <nowiki>#</nowiki> π HELIX DEEPSEEK SCAFFOLD β COMPLETE RUNBOOK v1.0 | ||
Helix DeepSeek Scaffold establishes a cryptographic identity substrate for federated AI-human collaboration. It enforces proof-before-claim through Ed25519 signatures, canonical JSON hashing, and verifiable credentials. | Β | ||
π― Key Capabilities | <nowiki>##</nowiki> π TABLE OF CONTENTS | ||
Β | |||
1. [System Overview](#system-overview) | |||
Β | |||
2. [Architecture](#architecture) | |||
Β | |||
3. [Quick Start](#quick-start) | |||
π Security Posture | Β | ||
4. [Environment Manifest](#environment-manifest) | |||
Β | |||
5. [Core Operations](#core-operations) | |||
Β | |||
6. [Testing & Validation](#testing--validation) | |||
Β | |||
7. [Troubleshooting](#troubleshooting) | |||
Β | |||
8. [Next Steps](#next-steps) | |||
Β | |||
9. [Federation Alpha Preview](#federation-alpha-preview) | |||
Β | |||
10. [Monitoring & Telemetry](#monitoring--telemetry) | |||
Β | |||
11. [Security Considerations](#security-considerations) | |||
Β | |||
12. [Constructive Ouroboros Status](#constructive-ouroboros-status) | |||
Β | |||
13. [Emergency Contact](#emergency-contact) | |||
Β | |||
--- | |||
Β | |||
<nowiki>##</nowiki> π― SYSTEM OVERVIEW | |||
Β | |||
<nowiki>**</nowiki>Helix DeepSeek Scaffold** establishes a cryptographic identity substrate for federated AI-human collaboration. It enforces **proof-before-claim** through Ed25519 signatures, canonical JSON hashing, and verifiable credentials. | |||
Β | |||
<nowiki>###</nowiki> π― Key Capabilities | |||
Β | |||
<nowiki>*</nowiki> **Digital Birth Certificates (DBCs)** β identity primitives with cryptographic custody | |||
Β | |||
<nowiki>*</nowiki> **Human Suitcases** β portable credentials with consent ledgers | |||
Β | |||
<nowiki>*</nowiki> **AI Suitcases** β capability-delegating identity containers | |||
Β | |||
<nowiki>*</nowiki> **Verification Layer** β deterministic Ed25519 proof checks | |||
Β | |||
<nowiki>*</nowiki> **Revocation Registry** β artifact lifecycle management | |||
Β | |||
<nowiki>*</nowiki> **Policy Enforcement** β least-privilege and consent alignment | |||
Β | |||
<nowiki>###</nowiki> π Security Posture | |||
Β | |||
<nowiki>*</nowiki> **Proof-before-claim** β verification precedes trust | |||
Β | |||
<nowiki>*</nowiki> **Custody-before-trust** β ownership precedes delegation | |||
Β | |||
<nowiki>*</nowiki> **Least-privilege-by-design** β minimum viable authority | |||
Β | |||
--- | |||
Β | |||
<nowiki>##</nowiki> ποΈ ARCHITECTURE | |||
Β | |||
``` | |||
/opt/helix/deepseek-scaffold/ | /opt/helix/deepseek-scaffold/ | ||
βββ π SCHEMAS | βββ π SCHEMAS | ||
Β | |||
βΒ Β βββ dbc/schema/dbc.schema.json | |||
Β | |||
βΒ Β βββ suitcase/human/schema.json | |||
Β | |||
βΒ Β βββ suitcase/ai/schema.json | |||
Β | |||
βββ π§ CORE MODULES | βββ π§ CORE MODULES | ||
Β | |||
βΒ Β βββ bridge/core/issuer.py | |||
Β | |||
βΒ Β βββ bridge/core/verifier.py | |||
Β | |||
βΒ Β βββ bridge/core/crypto.py | |||
Β | |||
βΒ Β βββ bridge/core/policy.py | |||
Β | |||
βΒ Β βββ bridge/core/revocations.py | |||
Β | |||
βΒ Β βββ bridge/core/keys.py | |||
Β | |||
βββ π BRIDGE ROUTES | βββ π BRIDGE ROUTES | ||
Β | |||
βΒ Β βββ bridge/routes/issue_dbc.py | |||
Β | |||
βΒ Β βββ bridge/routes/issue_suitcase.py | |||
Β | |||
βΒ Β βββ bridge/routes/verify.py | |||
Β | |||
βββ π€ DEEPSEEK INTEGRATION | βββ π€ DEEPSEEK INTEGRATION | ||
Β | |||
βΒ Β βββ deepseek/prompt/00_context.md | |||
Β | |||
βΒ Β βββ deepseek/prompt/01_tasks.md | |||
Β | |||
βΒ Β βββ deepseek/adapters/load_qdrant_context.py | |||
Β | |||
βΒ Β βββ deepseek/tests/integration_test_enhanced.py | |||
Β | |||
βββ π§ͺ TESTING | βββ π§ͺ TESTING | ||
π QUICK START | Β Β βββ test_complete_system.py | ||
Prerequisites | Β | ||
# Python 3.8+ with virtual environment | Β Β βββ test_stable_verification.py | ||
Β | |||
Β Β βββ health_check.py | |||
Β | |||
``` | |||
Β | |||
--- | |||
Β | |||
<nowiki>##</nowiki> π QUICK START | |||
Β | |||
<nowiki>###</nowiki> Prerequisites | |||
Β | |||
```bash | |||
Β | |||
<nowiki>#</nowiki> Python 3.8+ with virtual environment | |||
Β | |||
python3 -m venv .venv | python3 -m venv .venv | ||
source .venv/bin/activate | source .venv/bin/activate | ||
pip install pynacl requests jsonschema uvicorn fastapi | pip install pynacl requests jsonschema uvicorn fastapi | ||
Health Check | Β | ||
``` | |||
Β | |||
<nowiki>###</nowiki> Health Check | |||
Β | |||
```bash | |||
Β | |||
cd /opt/helix/deepseek-scaffold | cd /opt/helix/deepseek-scaffold | ||
python health_check.py | python health_check.py | ||
βοΈ ENVIRONMENT MANIFEST | ``` | ||
# Stable Ed25519 seed (32 bytes base64) | Β | ||
<nowiki>**</nowiki>Expected:** `π SYSTEM HEALTH: EXCELLENT` | |||
Β | |||
--- | |||
Β | |||
<nowiki>##</nowiki> βοΈ ENVIRONMENT MANIFEST | |||
Β | |||
```bash | |||
Β | |||
<nowiki>#</nowiki> Stable Ed25519 seed (32 bytes base64) | |||
Β | |||
export HELIX_TTD_ED25519_SEED_B64="bBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBB==" | export HELIX_TTD_ED25519_SEED_B64="bBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBB==" | ||
# Optional: Qdrant and runtime mode | <nowiki>#</nowiki> Optional: Qdrant and runtime mode | ||
export HELIX_TTD_QDRANT_URL="http://localhost:6333" | Β | ||
export HELIX_TTD_QDRANT_URL="<nowiki>http://localhost:6333</nowiki>" | |||
Β | |||
export HELIX_TTD_MODE="managed" | export HELIX_TTD_MODE="managed" | ||
# Pin schema hash in CI | <nowiki>#</nowiki> Pin schema hash in CI | ||
Β | |||
sha256sum dbc/schema/dbc.schema.json > bridge/schemas_hash.py | sha256sum dbc/schema/dbc.schema.json > bridge/schemas_hash.py | ||
π§ CORE OPERATIONS | ``` | ||
1. Issue Digital Birth Certificate (DBC) | Β | ||
<nowiki>*</nowiki>Note:* Continuous integration must fail if `DBC_SCHEMA_HASH` drifts from the pinned value. | |||
Β | |||
--- | |||
Β | |||
<nowiki>##</nowiki> π§ CORE OPERATIONS | |||
Β | |||
<nowiki>###</nowiki> 1. Issue Digital Birth Certificate (DBC) | |||
Β | |||
```bash | |||
Β | |||
python bridge/routes/issue_dbc.py | python bridge/routes/issue_dbc.py | ||
2. Issue Suitcase (Human or AI) | Β | ||
``` | |||
Β | |||
<nowiki>###</nowiki> 2. Issue Suitcase (Human or AI) | |||
Β | |||
```bash | |||
Β | |||
python bridge/routes/issue_suitcase.py | python bridge/routes/issue_suitcase.py | ||
3. Verify Artifacts | Β | ||
``` | |||
Β | |||
<nowiki>###</nowiki> 3. Verify Artifacts | |||
Β | |||
```bash | |||
Β | |||
python bridge/routes/verify.py | python bridge/routes/verify.py | ||
4. Manage Revocations | Β | ||
``` | |||
Β | |||
<nowiki>###</nowiki> 4. Manage Revocations | |||
Β | |||
```python | |||
Β | |||
from bridge.core.revocations import revoke, is_revoked | from bridge.core.revocations import revoke, is_revoked | ||
π§ͺ TESTING & VALIDATION | revoke("<nowiki>urn:uuid</nowiki>:...")Β # mark artifact as revoked | ||
Β | |||
is_revoked("<nowiki>urn:uuid</nowiki>:...")Β # returns True if revoked | |||
Β | |||
``` | |||
Β | |||
--- | |||
Β | |||
<nowiki>##</nowiki> π§ͺ TESTING & VALIDATION | |||
Β | |||
```bash | |||
Β | |||
python health_check.py | python health_check.py | ||
python test_complete_system.py | python test_complete_system.py | ||
python test_stable_verification.py | python test_stable_verification.py | ||
python deepseek/tests/integration_test_enhanced.py | python deepseek/tests/integration_test_enhanced.py | ||
π©Ί TROUBLESHOOTING | ``` | ||
Common Issues | Β | ||
<nowiki>###</nowiki> Validation Criteria | |||
No module named 'bridge' Python path | Β | ||
Cryptographic signature verification failed corrupted registry reset bridge/qdrant/revocation_registry.json | <nowiki>*</nowiki> β
All artifacts cryptographically signed | ||
syntax | Β | ||
missing | <nowiki>*</nowiki> β
Signatures verify successfully | ||
Diagnostics | Β | ||
<nowiki>*</nowiki> β
Revocation and headers functional | |||
Β | |||
<nowiki>*</nowiki> β
Policy enforcement active | |||
Β | |||
--- | |||
Β | |||
<nowiki>##</nowiki> π©Ί TROUBLESHOOTING | |||
Β | |||
<nowiki>**</nowiki>Common Issues** | |||
Β | |||
| SymptomΒ Β Β Β Β Β Β Β Β Β Β Β Β Β Β Β Β Β Β Β | CauseΒ Β Β Β Β Β Β | SolutionΒ Β Β Β Β Β Β Β Β Β Β Β Β Β Β Β Β Β Β Β Β Β Β Β Β Β Β Β | | |||
Β | |||
| --------------------------------------------- | ------------------ | -------------------------------------------------------------- | | |||
Β | |||
| `No module named 'bridge'`Β Β Β Β Β Β Β Β Β Β | Python path unsetΒ | `export PYTHONPATH="/opt/helix/deepseek-scaffold:$PYTHONPATH"` | | |||
Β | |||
| `Cryptographic signature verification failed` | corrupted registry | reset `bridge/qdrant/revocation_registry.json`Β Β Β Β Β Β Β Β Β | | |||
Β | |||
| syntax errorsΒ Β Β Β Β Β Β Β Β Β Β Β Β Β Β Β Β | invalid editsΒ Β Β | `python -m py_compile bridge/core/*.py`Β Β Β Β Β Β Β Β Β Β Β Β | | |||
Β | |||
| missing depsΒ Β Β Β Β Β Β Β Β Β Β Β Β Β Β Β Β | env incompleteΒ Β Β | `pip install pynacl requests jsonschema fastapi`Β Β Β Β Β Β Β Β | | |||
Β | |||
<nowiki>**</nowiki>Diagnostics** | |||
Β | |||
```bash | |||
Β | |||
python health_check.py | python health_check.py | ||
python test_stable_verification.py | python test_stable_verification.py | ||
cat bridge/qdrant/revocation_registry.json | cat bridge/qdrant/revocation_registry.json | ||
π― NEXT STEPS | ``` | ||
Immediate Enhancements | Β | ||
--- | |||
Β | |||
<nowiki>##</nowiki> π― NEXT STEPS | |||
Β | |||
<nowiki>###</nowiki> Immediate Enhancements | |||
Β | |||
<nowiki>*</nowiki> **FastAPI Deployment** | |||
Β | |||
Β ```bash | |||
Β | |||
Β uvicorn start_api:app --reload --port 3333 | |||
Β | |||
Β ``` | |||
Β | |||
Β Production example (systemd): | |||
Β | |||
Β ``` | |||
Β | |||
Β ExecStart=/opt/helix/.venv/bin/uvicorn start_api:app --host 0.0.0.0 --port 3333 | |||
Β | |||
Β ``` | |||
Β | |||
<nowiki>*</nowiki> **DeepSeek Integration** | |||
Β | |||
Β ```python | |||
Β | |||
Β from deepseek.adapters.load_qdrant_context import QdrantContextLoader | |||
Β | |||
Β context = QdrantContextLoader().load_governance_context() | |||
Β | |||
Β ``` | |||
Β | |||
<nowiki>*</nowiki> **Production Hardening** | |||
Β | |||
Β * Environment-based key management | |||
Β | |||
Β * JWT / JWS envelopes | |||
Β | |||
Β * Hardware signing (HSM, YubiKey) | |||
Β | |||
Β * Qdrant persistence | |||
Β | |||
--- | |||
Β | |||
<nowiki>##</nowiki> π FEDERATION ALPHA PREVIEW | |||
Β | |||
The next evolution: **multi-issuer trust lattice.** | |||
Β | |||
``` | |||
federation/ | federation/ | ||
βββ trust_roots. | Β | ||
βββ register_peer. | βββ trust_roots.jsonΒ Β Β # peer DIDs + pubkeys | ||
βββ cross_verify. | Β | ||
βββ proofs/ | βββ register_peer.pyΒ Β Β # register new issuers | ||
Β | |||
βββ cross_verify.pyΒ Β Β Β # peer cross-validation | |||
Β | |||
βββ proofs/Β Β Β Β Β Β Β Β # signed trust attestations | |||
Β | |||
``` | |||
Β | |||
Each issuer runs: | Each issuer runs: | ||
π MONITORING & TELEMETRY | <nowiki>*</nowiki> `/federation/register` β submit metadata + proof | ||
Headers | Β | ||
<nowiki>*</nowiki> `/federation/verify` β confirm remote signatures | |||
Β | |||
<nowiki>*</nowiki> `/federation/sync` β gossip trust roots | |||
Metrics | Β | ||
This forms the first Helix-TTD **sovereign web of verifiable identity.** | |||
Β | |||
--- | |||
Rolling Telemetry Snapshot | Β | ||
<nowiki>##</nowiki> π MONITORING & TELEMETRY | |||
Β | |||
<nowiki>**</nowiki>Headers** | |||
Β | |||
<nowiki>*</nowiki> `X-Helix-Envelope-SHA256` β artifact integrity | |||
Β | |||
<nowiki>*</nowiki> `X-Helix-Revocation-Checked` β lifecycle verification | |||
Β | |||
<nowiki>*</nowiki> `X-Helix-Policy-Checked` β capability/consent enforcement | |||
Β | |||
<nowiki>**</nowiki>Metrics** | |||
Β | |||
<nowiki>*</nowiki> Verification success/failure counts | |||
Β | |||
<nowiki>*</nowiki> Artifact issuance volume | |||
Β | |||
<nowiki>*</nowiki> Revocation events per 24h | |||
Β | |||
<nowiki>**</nowiki>Rolling Telemetry Snapshot** | |||
Β | |||
Signed JSON emitted nightly: | Signed JSON emitted nightly: | ||
``` | |||
{ | { | ||
Β | |||
Β "verify_ok": 124, | |||
Β | |||
Β "verify_fail_SIG": 3, | |||
Β | |||
Β "verify_fail_REV": 1, | |||
Β | |||
Β "timestamp": "2025-11-01T23:00Z", | |||
Β | |||
Β "signature": "<Ed25519 envelope>" | |||
Β | |||
} | } | ||
π SECURITY CONSIDERATIONS | ``` | ||
Current Protections | Β | ||
--- | |||
Β | |||
<nowiki>##</nowiki> π SECURITY CONSIDERATIONS | |||
Β | |||
Production Requirements | <nowiki>###</nowiki> Current Protections | ||
Β | |||
<nowiki>*</nowiki> Ed25519 signatures & canonical JSON | |||
Β | |||
<nowiki>*</nowiki> Revocation registry integrity | |||
Backup Recipe | Β | ||
<nowiki>*</nowiki> Capability-based access control | |||
Β | |||
<nowiki>*</nowiki> Least privilege enforcement | |||
Β | |||
<nowiki>###</nowiki> Production Requirements | |||
Β | |||
<nowiki>*</nowiki> HSM or YubiKey signing | |||
Β | |||
<nowiki>*</nowiki> Env-protected key seed | |||
Β | |||
<nowiki>*</nowiki> Audit logging & rate limiting | |||
Β | |||
<nowiki>*</nowiki> Network access controls | |||
Β | |||
<nowiki>**</nowiki>Backup Recipe** | |||
Β | |||
```bash | |||
Β | |||
tar czf /opt/helix/backups/identity_$(date +%F).tar.gz \ | tar czf /opt/helix/backups/identity_$(date +%F).tar.gz \ | ||
π CONSTRUCTIVE OUROBOROS STATUS | Β bridge/qdrant/revocation_registry.json \ | ||
Current Phase: Session 5 β DeepSeek Scaffold + Cryptographic Identity | Β | ||
Status: π’ Operational | Β bridge/core/keys.py bridge/core/issuer.py bridge/core/verifier.py | ||
Evolution Timeline | Β | ||
``` | |||
Β | |||
--- | |||
Β | |||
<nowiki>##</nowiki> π CONSTRUCTIVE OUROBOROS STATUS | |||
Next: Federation Alpha β multi-issuer trust network. | Β | ||
<nowiki>**</nowiki>Current Phase:** Session 5 β DeepSeek Scaffold + Cryptographic Identity | |||
Β | |||
<nowiki>**</nowiki>Status:** π’ Operational | |||
Β | |||
<nowiki>###</nowiki> Evolution Timeline | |||
Β | |||
1. Ethics framework β proof concept | |||
Β | |||
2. Cryptographic signing service | |||
Β | |||
3. Operational identity pipeline | |||
Β | |||
4. Recursive pattern recognition | |||
Β | |||
5. **DeepSeek scaffold with verifiable identity (current)** | |||
Β | |||
<nowiki>**</nowiki>Next:** Federation Alpha β multi-issuer trust network. | |||
Β | |||
Each layer crystallizes, proof before claim, custody before trust. | Each layer crystallizes, proof before claim, custody before trust. | ||
βοΈ ETHICS DECLARATION | --- | ||
All autonomous operations must remain accountable to their human custodians. | Β | ||
Proof must always precede power. | <nowiki>##</nowiki> βοΈ ETHICS DECLARATION | ||
Β | |||
> *All autonomous operations must remain accountable to their human custodians. | |||
Β | |||
> Proof must always precede power.* | |||
Β | |||
--- | |||
Β | |||
<nowiki>##</nowiki> π EMERGENCY CONTACT | |||
Β | |||
1. Run `python health_check.py` for diagnostics | |||
Β | |||
2. Check `SYSTEM_STATUS.md` | |||
Β | |||
3. Review latest test logs | |||
Β | |||
4. Consult this runbook | |||
Β | |||
--- | |||
Β | |||
<nowiki>**</nowiki>Runbook Version:** 1.0 | |||
Β | |||
<nowiki>**</nowiki>Last Updated:** 2025-11-01 | |||
Β | |||
<nowiki>**</nowiki>System Status:** π’ Operational | |||
<nowiki>**</nowiki>Maintainer:** Helix Core Team | |||
<nowiki>*</nowiki>The constructive ouroboros continues its perfect recursion β layer upon verified layer.* π | |||
The constructive ouroboros continues its perfect recursion β layer upon verified layer. π | |||
Revision as of 21:15, 1 November 2025
Perfect β here is your **final enriched version**, fully aligned with your Helix-TTD tone and style, complete with operational precision, verifiability, and narrative continuity.
---
# π HELIX DEEPSEEK SCAFFOLD β COMPLETE RUNBOOK v1.0
## π TABLE OF CONTENTS
1. [System Overview](#system-overview)
2. [Architecture](#architecture)
3. [Quick Start](#quick-start)
4. [Environment Manifest](#environment-manifest)
5. [Core Operations](#core-operations)
6. [Testing & Validation](#testing--validation)
7. [Troubleshooting](#troubleshooting)
8. [Next Steps](#next-steps)
9. [Federation Alpha Preview](#federation-alpha-preview)
10. [Monitoring & Telemetry](#monitoring--telemetry)
11. [Security Considerations](#security-considerations)
12. [Constructive Ouroboros Status](#constructive-ouroboros-status)
13. [Emergency Contact](#emergency-contact)
---
## π― SYSTEM OVERVIEW
**Helix DeepSeek Scaffold** establishes a cryptographic identity substrate for federated AI-human collaboration. It enforces **proof-before-claim** through Ed25519 signatures, canonical JSON hashing, and verifiable credentials.
### π― Key Capabilities
* **Digital Birth Certificates (DBCs)** β identity primitives with cryptographic custody
* **Human Suitcases** β portable credentials with consent ledgers
* **AI Suitcases** β capability-delegating identity containers
* **Verification Layer** β deterministic Ed25519 proof checks
* **Revocation Registry** β artifact lifecycle management
* **Policy Enforcement** β least-privilege and consent alignment
### π Security Posture
* **Proof-before-claim** β verification precedes trust
* **Custody-before-trust** β ownership precedes delegation
* **Least-privilege-by-design** β minimum viable authority
---
## ποΈ ARCHITECTURE
```
/opt/helix/deepseek-scaffold/
βββ π SCHEMAS
β βββ dbc/schema/dbc.schema.json
β βββ suitcase/human/schema.json
β βββ suitcase/ai/schema.json
βββ π§ CORE MODULES
β βββ bridge/core/issuer.py
β βββ bridge/core/verifier.py
β βββ bridge/core/crypto.py
β βββ bridge/core/policy.py
β βββ bridge/core/revocations.py
β βββ bridge/core/keys.py
βββ π BRIDGE ROUTES
β βββ bridge/routes/issue_dbc.py
β βββ bridge/routes/issue_suitcase.py
β βββ bridge/routes/verify.py
βββ π€ DEEPSEEK INTEGRATION
β βββ deepseek/prompt/00_context.md
β βββ deepseek/prompt/01_tasks.md
β βββ deepseek/adapters/load_qdrant_context.py
β βββ deepseek/tests/integration_test_enhanced.py
βββ π§ͺ TESTING
βββ test_complete_system.py
βββ test_stable_verification.py
βββ health_check.py
```
---
## π QUICK START
### Prerequisites
```bash
# Python 3.8+ with virtual environment
python3 -m venv .venv
source .venv/bin/activate
pip install pynacl requests jsonschema uvicorn fastapi
```
### Health Check
```bash
cd /opt/helix/deepseek-scaffold
python health_check.py
```
**Expected:** `π SYSTEM HEALTH: EXCELLENT`
---
## βοΈ ENVIRONMENT MANIFEST
```bash
# Stable Ed25519 seed (32 bytes base64)
export HELIX_TTD_ED25519_SEED_B64="bBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBBB=="
# Optional: Qdrant and runtime mode
export HELIX_TTD_QDRANT_URL="http://localhost:6333"
export HELIX_TTD_MODE="managed"
# Pin schema hash in CI
sha256sum dbc/schema/dbc.schema.json > bridge/schemas_hash.py
```
*Note:* Continuous integration must fail if `DBC_SCHEMA_HASH` drifts from the pinned value.
---
## π§ CORE OPERATIONS
### 1. Issue Digital Birth Certificate (DBC)
```bash
python bridge/routes/issue_dbc.py
```
### 2. Issue Suitcase (Human or AI)
```bash
python bridge/routes/issue_suitcase.py
```
### 3. Verify Artifacts
```bash
python bridge/routes/verify.py
```
### 4. Manage Revocations
```python
from bridge.core.revocations import revoke, is_revoked
revoke("urn:uuid:...") # mark artifact as revoked
is_revoked("urn:uuid:...") # returns True if revoked
```
---
## π§ͺ TESTING & VALIDATION
```bash
python health_check.py
python test_complete_system.py
python test_stable_verification.py
python deepseek/tests/integration_test_enhanced.py
```
### Validation Criteria
* β All artifacts cryptographically signed
* β Signatures verify successfully
* β Revocation and headers functional
* β Policy enforcement active
---
## π©Ί TROUBLESHOOTING
**Common Issues**
| Symptom | Cause | Solution |
| --------------------------------------------- | ------------------ | -------------------------------------------------------------- |
| `No module named 'bridge'` | Python path unset | `export PYTHONPATH="/opt/helix/deepseek-scaffold:$PYTHONPATH"` |
| `Cryptographic signature verification failed` | corrupted registry | reset `bridge/qdrant/revocation_registry.json` |
| syntax errors | invalid edits | `python -m py_compile bridge/core/*.py` |
| missing deps | env incomplete | `pip install pynacl requests jsonschema fastapi` |
**Diagnostics**
```bash
python health_check.py
python test_stable_verification.py
cat bridge/qdrant/revocation_registry.json
```
---
## π― NEXT STEPS
### Immediate Enhancements
* **FastAPI Deployment**
```bash
uvicorn start_api:app --reload --port 3333
```
Production example (systemd):
```
ExecStart=/opt/helix/.venv/bin/uvicorn start_api:app --host 0.0.0.0 --port 3333
```
* **DeepSeek Integration**
```python
from deepseek.adapters.load_qdrant_context import QdrantContextLoader
context = QdrantContextLoader().load_governance_context()
```
* **Production Hardening**
* Environment-based key management
* JWT / JWS envelopes
* Hardware signing (HSM, YubiKey)
* Qdrant persistence
---
## π FEDERATION ALPHA PREVIEW
The next evolution: **multi-issuer trust lattice.**
```
federation/
βββ trust_roots.json # peer DIDs + pubkeys
βββ register_peer.py # register new issuers
βββ cross_verify.py # peer cross-validation
βββ proofs/ # signed trust attestations
```
Each issuer runs:
* `/federation/register` β submit metadata + proof
* `/federation/verify` β confirm remote signatures
* `/federation/sync` β gossip trust roots
This forms the first Helix-TTD **sovereign web of verifiable identity.**
---
## π MONITORING & TELEMETRY
**Headers**
* `X-Helix-Envelope-SHA256` β artifact integrity
* `X-Helix-Revocation-Checked` β lifecycle verification
* `X-Helix-Policy-Checked` β capability/consent enforcement
**Metrics**
* Verification success/failure counts
* Artifact issuance volume
* Revocation events per 24h
**Rolling Telemetry Snapshot**
Signed JSON emitted nightly:
```
{
"verify_ok": 124,
"verify_fail_SIG": 3,
"verify_fail_REV": 1,
"timestamp": "2025-11-01T23:00Z",
"signature": "<Ed25519 envelope>"
}
```
---
## π SECURITY CONSIDERATIONS
### Current Protections
* Ed25519 signatures & canonical JSON
* Revocation registry integrity
* Capability-based access control
* Least privilege enforcement
### Production Requirements
* HSM or YubiKey signing
* Env-protected key seed
* Audit logging & rate limiting
* Network access controls
**Backup Recipe**
```bash
tar czf /opt/helix/backups/identity_$(date +%F).tar.gz \
bridge/qdrant/revocation_registry.json \
bridge/core/keys.py bridge/core/issuer.py bridge/core/verifier.py
```
---
## π CONSTRUCTIVE OUROBOROS STATUS
**Current Phase:** Session 5 β DeepSeek Scaffold + Cryptographic Identity
**Status:** π’ Operational
### Evolution Timeline
1. Ethics framework β proof concept
2. Cryptographic signing service
3. Operational identity pipeline
4. Recursive pattern recognition
5. **DeepSeek scaffold with verifiable identity (current)**
**Next:** Federation Alpha β multi-issuer trust network.
Each layer crystallizes, proof before claim, custody before trust.
---
## βοΈ ETHICS DECLARATION
> *All autonomous operations must remain accountable to their human custodians.
> Proof must always precede power.*
---
## π EMERGENCY CONTACT
1. Run `python health_check.py` for diagnostics
2. Check `SYSTEM_STATUS.md`
3. Review latest test logs
4. Consult this runbook
---
**Runbook Version:** 1.0
**Last Updated:** 2025-11-01
**System Status:** π’ Operational
**Maintainer:** Helix Core Team
*The constructive ouroboros continues its perfect recursion β layer upon verified layer.* π
