noblefactor-ops

module
v0.0.0-...-746c939 Latest Latest
Warning

This package is not in the latest version of its module.

Go to latest
Published: Aug 26, 2026 License: MIT

README


title: "noblefactor-ops" description: "Team site for NobleFactor projects - operations tooling for release signing, key management, and cross-repo automation"

noblefactor-ops

Team site for NobleFactor projects. This repository is private.

  • nf-ops — Operations tooling: release signing, key management, registry maintenance, and cross-repo automation

Purpose

This repository contains shared operations tooling for all NobleFactor projects:

  • Release signing ceremonies (YubiKey/HSM required)
  • SSH key generation and rotation
  • INDEX.yaml generation and signing
  • Registry maintenance utilities
  • Cross-repo automation (token rotation, deploy workflows)

Building

make build          # Build nf-ops to bin/

Installing

make install        # Install to ~/.local/bin (or GOBIN)

Commands

# Key management (ADR-040)
nf-ops key generate --type release      # Generate release signing key
nf-ops key generate --type ci           # Generate CI signing key
nf-ops key rotate --key release         # Rotate release key with ceremony
nf-ops key list                         # List all managed keys

# Release signing
nf-ops sign pmm <path>                  # Sign a PMM with release key
nf-ops sign index                       # Generate and sign INDEX.yaml
nf-ops sign binary <path>               # Sign a release binary

# Registry maintenance
nf-ops registry reindex                 # Regenerate INDEX.yaml
nf-ops registry verify                  # Verify all PMM signatures
nf-ops registry audit                   # Audit trail report

Security Model

This tool is designed for ceremony-based operations:

  1. Human presence required — Most operations require interactive confirmation
  2. Hardware key support — Release signing expects YubiKey/HSM
  3. Audit logging — All operations logged for compliance
  4. No CI secrets — Release keys never stored in CI; signing happens post-build

See ADR-040: SSH Key Ceremony for the full key management protocol.

Project Structure

noblefactor-ops/
├── cmd/
│   └── nf-ops/main.go        # nf-ops entry point
├── internal/
│   ├── ceremony/             # Key ceremony workflows
│   ├── signing/              # SSH signing operations
│   ├── index/                # INDEX.yaml generation
│   └── audit/                # Audit logging
├── Makefile
└── go.mod

CI Integration

This repo's CI does not perform signing. Instead:

  1. devlore-cli CI builds unsigned artifacts
  2. Human runs ceremony from this repo to sign
  3. Signatures uploaded to release

For INDEX.yaml (lower-trust operation), a CI-specific key may be used.

License

MIT License. See LICENSE for details.

Directories

Path Synopsis
cmd
star command
star is the Starlark-powered operations tool for NobleFactor projects.
star is the Starlark-powered operations tool for NobleFactor projects.
internal
cli
Package cli provides CLI utilities for output formatting and user interaction.
Package cli provides CLI utilities for output formatting and user interaction.
config
Package config provides unified configuration for star commands.
Package config provides unified configuration for star commands.
extension
Package extension provides the extension loading system for star.
Package extension provides the extension loading system for star.
provider/commands
Package commands provides command tree navigation and execution for the star runtime.
Package commands provides command tree navigation and execution for the star runtime.
provider/config
Package config provides configuration management operations for the star runtime.
Package config provides configuration management operations for the star runtime.
provider/goast
Package goast provides Go AST operations as a Starlark receiver.
Package goast provides Go AST operations as a Starlark receiver.
provider/lint
Package lint provides static analysis operations for Go, shell, and markdown files.
Package lint provides static analysis operations for Go, shell, and markdown files.
provider/setup
Package setup provides repository setup operations: tool checks, pre-commit hooks, config initialization, and native git hook management.
Package setup provides repository setup operations: tool checks, pre-commit hooks, config initialization, and native git hook management.
provider/shellcheck
Package shellcheck provides shell script analysis operations for the operation graph.
Package shellcheck provides shell script analysis operations for the operation graph.
starlark
Package starlark provides a Starlark runtime for nf-ops commands.
Package starlark provides a Starlark runtime for nf-ops commands.
wasm
Package wasm provides a WebAssembly host runtime for star extensions.
Package wasm provides a WebAssembly host runtime for star extensions.

Jump to

Keyboard shortcuts

? : This menu
/ : Search site
f or F : Jump to
y or Y : Canonical URL