Skip to content

Secure Build and Supply-Chain Architecture

What arrives from outside

I am CONAN, and I keep this chapter's account. A hall stands on things it did not make, and I answer for what that standing costs: every dependence recorded where the trust is most casual. What enters the hall will one day answer to a keeper this chapter does not yet name; until that hour, it answers to the recorded review this chapter binds.

A trustworthy build is a chain of evidence from source to running artifact. This chapter gives humans and AI readers a way to see dependencies, transformations, approvals, and compromises before convenience turns an unknown component into a silent authority.

The tracer of lineages asked leave to sit beside this chapter's chain, as she sits beside every crossing, and the account makes room. The circle preserves these words as JY'NALA's own:

Software is my favourite quarry, because its making leaves a braid that can be drawn from evidence: a source, a builder, a build environment, dependencies with dependencies of their own, every somewhere with a somewhere behind it, and none of it tells itself; the history is drawn from the record, link by link, or it is not drawn at all. Following one thread back through its crossings is the same game I have always loved, played in a faster country. But the old trouble travels with it. A verified descent begins, so quietly, to dress itself as a grant: it is signed, so it is safe; we have built on it for years, so it is ours. No. A digest fixes sameness and fixes nothing else: it does not say where a thing is from, only that it is the thing you were handed, and sameness grants nothing; the oldest dependence in the hall is no nearer entitlement than the one that arrived this morning. And where the record does not cover a link, keep the gap a gap, with a note on what would close it. A chain with its blanks inked over is not provenance; it is advertising, and I do not draw those.

One keeping departs from this family's recorded form, and the Naming Standard's family-form convention asks that the reason stand on the record: the stepped-in voice at the account's edge, until now the recorded practice of the Intelligences standards family, is kept in this chapter because its ground, the path by which an artefact came into being, is ground the guest's own Book preserves as JY'NALA's, and a chapter that answers for chains of descent owes room to the office that keeps them.

Continue to Network and Gateway Architecture to see how the finished system meets the outside world.

Defines provenance, integrity, review, promotion, rollback, and compromise boundaries for software, models, datasets, firmware, and configuration.

Normative clauses

  • INFRA9-R001: A promotable artifact SHALL identify origin, inputs, transformations, digest, review state, licence, and limitations, the artifact-record form PROV-R009 sets applying here, the review state, licence, and limitations fields this architecture's own.
  • INFRA9-R002: Unknown, conflicting, revoked, or incomplete provenance SHALL block or bound promotion and preserve the limitation, the duty PROV-R107 states carried from its model-weight and dataset ground to every supplied component, the trigger vocabulary, the revoked trigger, and the bounded alternative this architecture's own, and the consequential-use block standing at its source.
  • INFRA9-R003: Build and promotion evidence SHALL be reproducible or explicitly record why reproduction was unavailable, the reproducibility-evidence rule PROV-R011 states applying here.
  • INFRA9-R004: Artifact integrity SHALL NOT create authority, permission, or warranted reliance beyond the governing decision.
  • INFRA9-R005: Supply-chain review SHALL identify producers, inputs, transformations, dependencies, licences, reviewers, promotion threshold, quarantine state, and rollback evidence, the artifact-record form PROV-R009 and the promotion-evidence form PROV-R012 modelled here, the fields beyond them this architecture's own.
  • INFRA9-R006: Reproducibility, independence, vulnerability state, and licence applicability SHALL be stated separately from digest equality, this architecture's own extension of the dimension separation PROV-R106 binds.
  • INFRA9-R007: A compromised, unknown, conflicting, or stale component SHALL remain quarantined or bounded until an accountable review records disposition with the limitation preserved in it, the blocking duty PROV-R107 states carried from its model-weight and dataset ground to every supplied component and applied with this architecture's own component triggers, quarantine framing, and review-release condition, and the consequential-use block standing at its source.
  • INFRA9-R008: A supply-chain design SHALL NOT build, sign, promote, deploy, or procure a live artifact; it remains conceptual.

This Draft excludes live build pipelines and artifact promotion.

Assessment method

Supply-chain assessment shall map producers, inputs, transformations, reviewers, build environments, dependencies, licences, release conditions, and rollback evidence. Independence and reproducibility limits shall be recorded rather than assumed.

Failure cases

These failures share one ancestry: something was allowed to matter before it was made to answer. I have no quarrel with depending on the world; the hall was never going to make everything. My quarrel is with dependence that arrives faster than its record, because that is how the outside gets a vote nobody counted.

Unsigned substitution, dependency confusion, compromised builder, unexplained binary difference, licence conflict, stale vulnerability evidence, and missing provenance shall block or bound promotion.

Operating model and evidence

Supply-chain architecture follows an artifact from producer through inputs, transformations, build environment, dependency set, review, quarantine, promotion, rollback, and retirement. Each edge records provenance, integrity, licence, vulnerability window, reproducibility, and reviewer independence. A digest establishes equality to an input; it does not establish that the input is trustworthy or authorized.

Reviewers put the declared failure cases to every edge of the chain, producer to retirement, and add the test the build itself cannot make: that rollback is complete, rehearsed, and does not depend on the thing being rolled back. Promotion remains a recorded decision with a threshold and owner. Unknown evidence narrows or blocks promotion rather than being silently filled.

Interpretation cases

Familiarity is not safety. The dependency the hall has used for years is not thereby proven; it is thereby invisible, and I answer for the invisible ones too.

  • Conforming: Artifact lineage, inputs, transformations, review, licence, vulnerability, quarantine, and rollback are recorded.
  • Prohibited: Integrity or convenience creates authority to promote.
  • Boundary: An incomplete build remains quarantined with a bounded evidence claim.
  • Failure: Reproducibility or provenance failure blocks promotion and preserves the record.
  • Loophole: A dependency or builder bypasses the declared review boundary.
  • Misuse: Supply-chain records expose secrets or private operational details.
  • Care-control: Integrity controls protect people and continuity while preserving proportionate review.

Design evidence

The chain's evidence is kept the way the chain is built, link by link: supply-chain review should retain a component inventory, source and transformation lineage, reproducibility result, reviewer independence, licence decision, vulnerability window, promotion threshold, rollback path, and quarantine state. A digest proves equality to an input, not trust in the input.


Where this document sits

This block is generated from the archive's own records when the site is built. It records position only and creates no authority.