Skip to content

[TRACE] Config schema for TRACE emission (ADR-0032, step 4/5) #3089

Description

Summary

Add the trace: config block to AGT configuration schema. Fail fast at startup if trace.emit: true but required fields are absent.

Scope

Extend the existing config schema (find the canonical config dataclass or schema file).

New trace: block:

trace:
  emit: false                     # default off
  output_path: ""                 # directory for .jwt files; optional
  endpoint: ""                    # POST endpoint; optional
  model:
    provider: ""
    model_id: ""
    version: ""
    weights_digest: ""            # sha256: or sha384: prefixed
  build_provenance:
    slsa_level: 0
    builder: ""
    digest: ""
  appraisal_verifier: ""          # URI of the verifier; optional

Note: No agent_svid field. TRACE v0.2 accepts did: URIs natively -- subject is derived from session.agent_did at session close. Key material via TRACE_PRIVATE_KEY_PEM env var only.

Startup validation (when emit: true):

  • model.provider and model.model_id must be present
  • build_provenance.slsa_level must be 0, 1, 2, or 3
  • At least one of output_path or endpoint must be set (or warn that output goes to stdout)

Acceptance criteria

  • Config dataclass / schema extended with trace: block (no agent_svid)
  • Startup raises ConfigurationError with a clear message for each missing required field
  • Config is serializable to dict for passing to session_to_trust_record
  • Unit tests: valid config passes, missing model.provider raises, invalid slsa_level raises

References

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Labels

enhancementNew feature or requestpythonPull requests that update python code

Type

No type

Projects

No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions