diff --git a/BLUEPRINT_SCHEMA_v1_0.json b/BLUEPRINT_SCHEMA_v1_0.json new file mode 100644 index 0000000..29c354e --- /dev/null +++ b/BLUEPRINT_SCHEMA_v1_0.json @@ -0,0 +1,332 @@ +{ + "$schema": "https://json-schema.org/draft/2020-12/schema", + "$id": "https://eios.xrayvu.com/schemas/blueprint/v1.0", + "title": "EIOS Blueprint Package Schema", + "description": "JSON Schema for all EIOS Blueprint packages — covers X-Frames display templates and Bridge agentic workflow packages.", + "version": "1.0", + "created": "2026-06-09", + "author": "EOA0000 (Eyean / EIOS IA)", + "type": "object", + "required": ["blueprint_id", "version", "name", "blueprint_type", "author", "license", "description"], + "additionalProperties": false, + + "properties": { + + "blueprint_id": { + "type": "string", + "pattern": "^[a-z0-9][a-z0-9/_-]{2,80}$", + "description": "Globally unique slug identifier. Format: / for Bridge; for X-Frames. Example: healthcare/patient-discharge-summary-v1 or bp_minimal_dark_001", + "examples": ["healthcare/patient-discharge-summary-v1", "it/incident-triage-v1", "bp_minimal_dark_001"] + }, + + "version": { + "type": "string", + "pattern": "^(0|[1-9]\\d*)\\.(0|[1-9]\\d*)\\.(0|[1-9]\\d*)(?:-((?:0|[1-9]\\d*|\\d*[a-zA-Z-][0-9a-zA-Z-]*)(?:\\.(?:0|[1-9]\\d*|\\d*[a-zA-Z-][0-9a-zA-Z-]*))*))?(?:\\+([0-9a-zA-Z-]+(?:\\.[0-9a-zA-Z-]+)*))?$", + "description": "Semantic version (MAJOR.MINOR.PATCH). Breaking parameter/API changes = MAJOR.", + "examples": ["1.0.0", "1.2.3", "2.0.0-beta.1"] + }, + + "name": { + "type": "string", + "minLength": 3, + "maxLength": 80, + "description": "Human-readable display name for marketplace listings." + }, + + "blueprint_type": { + "type": "string", + "enum": [ + "xframes_template", + "bridge_workflow", + "bridge_system_selection", + "bridge_architecture", + "bridge_library", + "bridge_configuration", + "bridge_hybrid" + ], + "description": "Discriminator for package structure interpretation. xframes_template = X-Frames room display template. bridge_* = Bridge platform agentic package types." + }, + + "author": { + "type": "object", + "required": ["entity_id", "display_name"], + "additionalProperties": false, + "properties": { + "entity_id": { + "type": "string", + "pattern": "^E[A-Z0-9]{2}[0-9]{4}$", + "description": "EIOS entity ID of the Blueprint creator (e.g. EOU0227, EOO9788)." + }, + "display_name": { + "type": "string", + "description": "Public display name for marketplace attribution." + }, + "url": { + "type": "string", + "format": "uri", + "description": "Optional: creator profile or repository URL." + } + } + }, + + "license": { + "type": "string", + "enum": ["MIT", "Apache-2.0", "GPL-3.0", "AGPL-3.0", "CC-BY-4.0", "CC-BY-SA-4.0", "proprietary", "commercial"], + "description": "OSI-approved license or proprietary/commercial for paid Blueprints." + }, + + "description": { + "type": "string", + "minLength": 20, + "maxLength": 300, + "description": "Short description for search result cards (≤300 chars)." + }, + + "long_description": { + "type": "string", + "description": "Full markdown description rendered on the Blueprint detail page." + }, + + "domain": { + "type": "string", + "enum": [ + "healthcare", + "legal", + "finance", + "government", + "education", + "technology", + "infrastructure", + "security", + "devops", + "communications", + "hr", + "marketing", + "general" + ], + "description": "Industry/functional domain for marketplace categorization." + }, + + "tags": { + "type": "array", + "items": { "type": "string", "pattern": "^[a-z0-9][a-z0-9-]{0,30}$" }, + "minItems": 1, + "maxItems": 15, + "uniqueItems": true, + "description": "Searchable tags. lowercase-hyphenated." + }, + + "certification": { + "type": "string", + "enum": ["community", "verified", "certified", "healthcare-certified"], + "default": "community", + "description": "Certification tier. community = free/unvetted; verified = $500 fee, basic review; certified = $2K, full audit; healthcare-certified = $5K, HIPAA/regulatory." + }, + + "pricing": { + "type": "object", + "required": ["model"], + "additionalProperties": false, + "properties": { + "model": { + "type": "string", + "enum": ["free", "one_time", "subscription", "usage"], + "description": "Pricing model. Free blueprints may still have a license fee." + }, + "amount_credits": { + "type": "integer", + "minimum": 0, + "description": "Platform credits charged. 0 = free. For subscription: per-month. For one_time: total." + }, + "usage_unit": { + "type": "string", + "description": "For usage model: what is billed per execution (e.g. 'per_run', 'per_document')." + }, + "revenue_split": { + "type": "object", + "description": "Revenue distribution. Defaults to 70% creator / 30% platform.", + "properties": { + "creator_pct": { "type": "number", "minimum": 0, "maximum": 100 }, + "platform_pct": { "type": "number", "minimum": 0, "maximum": 100 } + } + } + } + }, + + "requires": { + "type": "object", + "additionalProperties": false, + "properties": { + "eios_version": { + "type": "string", + "description": "Semver range constraint on EIOS platform version (e.g. '>=1.0.0 <2.0.0')." + }, + "xframes_version": { + "type": "string", + "description": "Required for xframes_template type. Semver range." + }, + "bridge_version": { + "type": "string", + "description": "Required for bridge_* types. Semver range." + }, + "platform_features": { + "type": "array", + "items": { "type": "string" }, + "description": "Named platform feature flags required (e.g. 'mem0', 'lightrag', 'otel')." + }, + "actor_harnesses": { + "type": "array", + "items": { + "type": "string", + "enum": ["claude-code", "aider", "openhands", "gemini-cli", "browser-use", "custom"] + }, + "description": "For bridge_workflow: harnesses that must be available to execute this blueprint." + } + } + }, + + "dependencies": { + "type": "array", + "items": { + "type": "object", + "required": ["blueprint_id", "version"], + "properties": { + "blueprint_id": { "type": "string" }, + "version": { "type": "string" } + } + }, + "description": "Other blueprints this one depends on (installed automatically)." + }, + + "parameters": { + "type": "object", + "description": "For bridge_* types: parameterizable inputs. Keys are parameter names; values are parameter specs.", + "additionalProperties": { + "type": "object", + "required": ["type", "description"], + "properties": { + "type": { + "type": "string", + "enum": ["string", "integer", "number", "boolean", "enum", "array", "object"] + }, + "description": { "type": "string" }, + "required": { "type": "boolean", "default": false }, + "default": {}, + "enum_values": { + "type": "array", + "description": "For type=enum: allowed values." + }, + "sensitive": { + "type": "boolean", + "default": false, + "description": "If true: value is a credential/secret, never logged or transmitted." + } + } + } + }, + + "entry_point": { + "type": "string", + "description": "For bridge_workflow: relative path to the main workflow definition file (e.g. 'workflow.yaml' or 'main.py')." + }, + + "oss": { + "type": "object", + "additionalProperties": false, + "description": "OSS publishing metadata. Present if this blueprint is intended for public release.", + "properties": { + "publish_ready": { "type": "boolean" }, + "target_repository": { "type": "string", "format": "uri" }, + "tier": { + "type": "string", + "enum": ["tier1", "tier2", "tier3"], + "description": "tier1 = publish immediately; tier2 = after internal hardening; tier3 = keep proprietary." + }, + "stripping_required": { + "type": "boolean", + "description": "If true: must strip EIOS-internal references before publishing." + } + } + }, + + "xframes": { + "type": "object", + "description": "X-Frames-specific fields. Required when blueprint_type = xframes_template.", + "required": ["template_name", "system_name", "category"], + "additionalProperties": false, + "properties": { + "template_name": { "type": "string" }, + "system_name": { + "type": "string", + "pattern": "^[A-Z][A-Z0-9_]{1,40}$", + "description": "UPPER_SNAKE_CASE system identifier used in X-Frames runtime." + }, + "category": { + "type": "string", + "enum": ["minimal", "standard", "verbose", "developer", "presentation", "custom"] + }, + "platforms": { + "type": "array", + "items": { "type": "string", "enum": ["cli", "web", "mobile"] } + } + } + }, + + "marketplace": { + "type": "object", + "description": "Marketplace listing metadata (auto-populated/updated by platform).", + "additionalProperties": false, + "properties": { + "published_at": { "type": "string", "format": "date-time" }, + "updated_at": { "type": "string", "format": "date-time" }, + "downloads": { "type": "integer", "minimum": 0 }, + "stars": { "type": "integer", "minimum": 0 }, + "installs": { "type": "integer", "minimum": 0 }, + "status": { + "type": "string", + "enum": ["draft", "submitted", "under_review", "published", "deprecated", "archived"] + } + } + }, + + "changelog": { + "type": "array", + "description": "Version history. Most recent first.", + "items": { + "type": "object", + "required": ["version", "date", "changes"], + "properties": { + "version": { "type": "string" }, + "date": { "type": "string", "format": "date" }, + "changes": { "type": "string" } + } + } + } + + }, + + "if": { + "properties": { "blueprint_type": { "const": "xframes_template" } } + }, + "then": { + "required": ["xframes"], + "properties": { + "requires": { + "required": ["xframes_version"] + } + } + }, + "else": { + "if": { + "properties": { "blueprint_type": { "pattern": "^bridge_" } } + }, + "then": { + "required": ["domain", "parameters"], + "properties": { + "requires": { + "required": ["bridge_version"] + } + } + } + } +} diff --git a/README.md b/README.md index 6364d4f..b69fbc6 100644 --- a/README.md +++ b/README.md @@ -1,3 +1,22 @@ -# blueprints +# X-Frames Blueprint Registry -EIOS Blueprint Package Registry — submit, discover, and install EIOS blueprints \ No newline at end of file +The official EIOS Blueprint Package Registry. Blueprints are composable, schema-validated +packages that encode workflows, tools, and deployment templates for the EIOS platform. + +## Contents +- `blueprints/` — blueprint packages (one subdirectory per blueprint) +- `index.json` — machine-readable registry index +- `BLUEPRINT_SCHEMA_v1_0.json` — validation schema +- `SCHEMA.md` — schema documentation + +## Available Blueprints + +| Blueprint | Type | License | +|-----------|------|---------| +| Security Assessment Report Generator | bridge_workflow | commercial | +| IT Incident Triage Workflow | bridge_workflow | commercial | +| Common Grounds Deployment Package | deployment_template | internal | +| Organization Bootstrap Kit | eios_tool | internal | + +## Submission +Blueprints are submitted via `eac-blueprint submit` CLI or the Blueprint API at port 32740. diff --git a/SCHEMA.md b/SCHEMA.md new file mode 100644 index 0000000..6092622 --- /dev/null +++ b/SCHEMA.md @@ -0,0 +1,15 @@ +# Blueprint Schema Reference + +All blueprints in this registry conform to [BLUEPRINT_SCHEMA_v1_0.json](BLUEPRINT_SCHEMA_v1_0.json). + +## Required Fields +- `blueprint_id` — unique namespace/id string (e.g. `security/assessment-report-v1`) +- `version` — semver string +- `name` — human-readable name +- `blueprint_type` — one of: `bridge_workflow`, `eios_tool`, `harness_config`, `deployment_template` +- `author` — `entity_id`, `display_name` +- `license` — `commercial`, `open_source`, `internal` +- `description` — short description (≤200 chars) + +## Submission +See [EIOS Blueprint Marketplace](https://ecp.xrayvu.com) for submission instructions. diff --git a/blueprints/common-grounds-deploy-v1/CHANGELOG.md b/blueprints/common-grounds-deploy-v1/CHANGELOG.md new file mode 100644 index 0000000..7a5ea76 --- /dev/null +++ b/blueprints/common-grounds-deploy-v1/CHANGELOG.md @@ -0,0 +1,14 @@ +# Changelog — Common Grounds Deploy Blueprint + +## [1.0.0] — 2026-06-09 + +### Initial Release + +- Preflight: OS detection, disk/RAM sanity check +- Installs Apache 2.4, PHP 8.x, SQLite3, Git +- Deploys Common Grounds from Gitea (branch/tag configurable) +- Apache VirtualHost configuration with mod_rewrite +- SQLite database initialization with admin account +- Optional Let's Encrypt SSL via certbot +- HTTP health check with graceful DNS-not-ready warning +- Outputs: wiki_url, admin_url, install_path diff --git a/blueprints/common-grounds-deploy-v1/README.md b/blueprints/common-grounds-deploy-v1/README.md new file mode 100644 index 0000000..4bcaba8 --- /dev/null +++ b/blueprints/common-grounds-deploy-v1/README.md @@ -0,0 +1,129 @@ +# Common Grounds Wiki Deployment Blueprint + +**Blueprint ID**: `infrastructure/common-grounds-deploy-v1` +**Version**: 1.0.0 +**License**: MIT +**Author**: XRAY VU (EOO9788) + +Deploy a self-hosted [Common Grounds](https://grnds.xrayvu.com) wiki on any Debian/Ubuntu server in under 5 minutes. + +--- + +## What This Blueprint Does + +1. Runs a preflight check (OS compatibility, disk/RAM) +2. Installs Apache, PHP 8.x, SQLite3, and Git +3. Clones the Common Grounds source from Gitea +4. Configures an Apache VirtualHost for your domain +5. Initializes the wiki database with an admin account +6. (Optional) Provisions Let's Encrypt SSL via certbot +7. Verifies the site is reachable via HTTP(S) + +**Total time**: ~3–5 minutes on a standard VPS. + +--- + +## Requirements + +- Debian 11/12 or Ubuntu 22.04/24.04 +- SSH access with sudo privileges +- Domain DNS A record pointing to the server (for SSL) +- Minimum: 1 vCPU, 512MB RAM, 2GB disk + +--- + +## Parameters + +| Parameter | Required | Default | Description | +|-----------|----------|---------|-------------| +| `target_host` | ✅ | — | Server IP or hostname | +| `ssh_user` | ✗ | `root` | SSH user with sudo | +| `ssh_key_path` | ✗ | EIOS default | SSH private key path | +| `domain_name` | ✅ | — | e.g. `wiki.example.com` | +| `enable_https` | ✗ | `false` | Run certbot for SSL | +| `certbot_email` | ✗ | — | Required if enable_https=true | +| `wiki_title` | ✗ | `Common Grounds Wiki` | Site title | +| `admin_username` | ✗ | `admin` | Initial admin username | +| `admin_password` | ✗ | `changeme123` | **Change after first login** | +| `source_ref` | ✗ | `main` | Git branch or tag | +| `install_path` | ✗ | `/var/www/common-grounds` | Installation path | + +--- + +## Usage + +### Via EIOS Bridge CLI (planned) + +```bash +eios-blueprint install infrastructure/common-grounds-deploy-v1 + +eios-blueprint run infrastructure/common-grounds-deploy-v1 \ + --param target_host=203.0.113.10 \ + --param domain_name=wiki.example.com \ + --param admin_password=YourSecurePassword \ + --param enable_https=true \ + --param certbot_email=admin@example.com +``` + +### Via params file + +```yaml +# params.yaml +target_host: "203.0.113.10" +domain_name: "wiki.example.com" +enable_https: true +certbot_email: "admin@example.com" +admin_password: "YourSecurePassword" +wiki_title: "My Team Wiki" +``` + +```bash +eios-blueprint run infrastructure/common-grounds-deploy-v1 --params params.yaml +``` + +--- + +## Post-Install + +1. Visit `http://your-domain.com/` — you should see the Common Grounds homepage +2. Log in at `/admin` with your `admin_username` / `admin_password` +3. **Change the admin password immediately** +4. Configure your wiki title and theme via the admin panel + +--- + +## Outputs + +| Output | Description | +|--------|-------------| +| `wiki_url` | Public URL of the wiki | +| `admin_url` | Admin panel URL | +| `install_path` | Server filesystem path | + +--- + +## About Common Grounds + +Common Grounds is the open-source wiki framework developed by XRAY VU, powering +[Atomic Grounds](https://grnds.xrayvu.com) — a live instance demonstrating the +framework's capabilities. It is designed for: + +- Simple deployment (no Docker required, runs on shared hosting) +- Rich content with wiki-style linking +- Multi-user with role-based access +- Exportable content (Markdown, PDF via BIDS integration) + +**Source**: https://github.com/xrayvu/common-grounds *(planned)* +**Live demo**: https://grnds.xrayvu.com + +--- + +## License + +MIT License — free to use, modify, and distribute. + +See [LICENSE](LICENSE) for full terms. + +--- + +*infrastructure/common-grounds-deploy-v1 | EIOS Blueprint Package | 2026-06-09* diff --git a/blueprints/common-grounds-deploy-v1/blueprint.yaml b/blueprints/common-grounds-deploy-v1/blueprint.yaml new file mode 100644 index 0000000..92883b5 --- /dev/null +++ b/blueprints/common-grounds-deploy-v1/blueprint.yaml @@ -0,0 +1,139 @@ +# EIOS Blueprint Package — Common Grounds Deploy +# Conforms to: BLUEPRINT_SCHEMA_v1_0.json + +blueprint_id: "infrastructure/common-grounds-deploy-v1" +version: "1.0.0" +name: "Common Grounds Wiki Deployment" +blueprint_type: "bridge_configuration" + +author: + entity_id: "EOO9788" + display_name: "XRAY VU" + url: "https://grnds.xrayvu.com" + +license: "MIT" +description: "Deploy a self-hosted Common Grounds wiki on any Debian/Ubuntu server in under 5 minutes. Includes Apache config, PHP, SQLite database, and optional SSL setup." + +long_description: | + Common Grounds is the open-source wiki framework powering Atomic Grounds + (grnds.xrayvu.com). This Blueprint automates a complete installation: + + 1. System dependency check + install (Apache, PHP 8.x, SQLite3) + 2. Common Grounds source deployment (from Git or tarball) + 3. Apache VirtualHost configuration (HTTP and optionally HTTPS via certbot) + 4. Database initialization and default seed content + 5. Post-install health check verifying the site is accessible + + The result is a fully operational wiki at your chosen domain within minutes, + with no manual shell work required. + + **Target audience**: Anyone deploying an internal knowledge base, community wiki, + or operational reference site — from solo operators to regulated enterprises. + + **Resource footprint**: ~200MB disk; 256MB RAM minimum; PHP + SQLite (no PostgreSQL needed). + +domain: "infrastructure" +tags: + - "wiki" + - "self-hosted" + - "apache" + - "php" + - "sqlite" + - "knowledge-base" + - "common-grounds" + - "oss" + +certification: "community" + +pricing: + model: "free" + amount_credits: 0 + +requires: + bridge_version: ">=0.1.0" + eios_version: ">=1.0.0" + platform_features: [] + actor_harnesses: ["claude-code"] + +dependencies: [] + +entry_point: "workflow.yaml" + +parameters: + target_host: + type: string + description: "SSH host or IP address of the target Debian/Ubuntu server." + required: true + + ssh_user: + type: string + description: "SSH username with sudo privileges on the target host." + required: false + default: "root" + + ssh_key_path: + type: string + description: "Path to SSH private key on the actor's host. Default uses EIOS SSH key." + required: false + default: "/opt/LIFERAFT/secure/eou/EOU0227/ssh/id_ed25519" + sensitive: false + + domain_name: + type: string + description: "Fully-qualified domain name for the wiki (e.g. wiki.example.com). Used in Apache VirtualHost." + required: true + + enable_https: + type: boolean + description: "If true, runs certbot to provision Let's Encrypt SSL after DNS propagation is confirmed." + required: false + default: false + + certbot_email: + type: string + description: "Email address for Let's Encrypt notifications. Required when enable_https is true." + required: false + + wiki_title: + type: string + description: "Title displayed in the wiki header." + required: false + default: "Common Grounds Wiki" + + admin_username: + type: string + description: "Username for the initial admin account." + required: false + default: "admin" + + admin_password: + type: string + description: "Password for the initial admin account. CHANGE AFTER FIRST LOGIN." + required: false + default: "changeme123" + sensitive: true + + source_ref: + type: string + description: "Git tag or branch to deploy. Defaults to 'main'." + required: false + default: "main" + + install_path: + type: string + description: "Filesystem path for the wiki installation." + required: false + default: "/var/www/common-grounds" + +oss: + publish_ready: true + tier: "tier1" + stripping_required: false + +marketplace: + status: "draft" + +changelog: + - version: "1.0.0" + date: "2026-06-09" + changes: "Initial release. Covers Debian/Ubuntu; Apache + SQLite; optional certbot SSL." diff --git a/blueprints/common-grounds-deploy-v1/workflow.yaml b/blueprints/common-grounds-deploy-v1/workflow.yaml new file mode 100644 index 0000000..6c97c0a --- /dev/null +++ b/blueprints/common-grounds-deploy-v1/workflow.yaml @@ -0,0 +1,204 @@ +# Common Grounds Deploy — Workflow Definition +# Blueprint: infrastructure/common-grounds-deploy-v1 +# Entry point for bridge_configuration execution + +name: "Common Grounds Wiki Deployment" +version: "1.0.0" +executor: "claude-code" + +# Workflow steps execute sequentially. +# Each step is a shell command or a named sub-workflow invoked on target_host via SSH. +# Variable substitution: {{ param_name }} resolves from blueprint.yaml parameters. + +steps: + + - id: "preflight" + name: "Preflight — connectivity and OS check" + type: "ssh_command" + host: "{{ target_host }}" + user: "{{ ssh_user }}" + key: "{{ ssh_key_path }}" + command: | + set -e + echo "=== Common Grounds Deploy — Preflight ===" + echo "Host: $(hostname)" + echo "OS: $(lsb_release -d 2>/dev/null | cut -f2 || cat /etc/os-release | grep PRETTY_NAME | cut -d= -f2)" + echo "Disk free: $(df -h / | tail -1 | awk '{print $4}')" + echo "RAM free: $(free -h | grep Mem | awk '{print $4}')" + # Verify Debian/Ubuntu + if ! grep -qiE 'debian|ubuntu' /etc/os-release; then + echo "ERROR: This blueprint requires Debian or Ubuntu." + exit 1 + fi + echo "PREFLIGHT PASS" + on_failure: "abort" + + - id: "install_deps" + name: "Install system dependencies" + type: "ssh_command" + host: "{{ target_host }}" + user: "{{ ssh_user }}" + key: "{{ ssh_key_path }}" + command: | + set -e + export DEBIAN_FRONTEND=noninteractive + apt-get update -qq + apt-get install -y -qq apache2 php php-sqlite3 php-mbstring php-xml git curl + # Enable Apache modules + a2enmod rewrite + a2enmod headers + systemctl enable apache2 + systemctl start apache2 + echo "DEPS INSTALLED" + on_failure: "abort" + + - id: "deploy_source" + name: "Deploy Common Grounds source" + type: "ssh_command" + host: "{{ target_host }}" + user: "{{ ssh_user }}" + key: "{{ ssh_key_path }}" + command: | + set -e + INSTALL_PATH="{{ install_path }}" + SOURCE_REF="{{ source_ref }}" + # Clone or update + if [ -d "$INSTALL_PATH/.git" ]; then + cd "$INSTALL_PATH" + git fetch origin + git checkout "$SOURCE_REF" + git pull + echo "SOURCE UPDATED" + else + mkdir -p "$(dirname $INSTALL_PATH)" + git clone --branch "$SOURCE_REF" https://github.com/xrayvu/common-grounds.git "$INSTALL_PATH" + echo "SOURCE CLONED" + fi + # Set permissions + chown -R www-data:www-data "$INSTALL_PATH" + chmod -R 755 "$INSTALL_PATH" + chmod -R 775 "$INSTALL_PATH/data" 2>/dev/null || true + on_failure: "abort" + + - id: "configure_apache" + name: "Configure Apache VirtualHost" + type: "ssh_command" + host: "{{ target_host }}" + user: "{{ ssh_user }}" + key: "{{ ssh_key_path }}" + command: | + set -e + DOMAIN="{{ domain_name }}" + INSTALL_PATH="{{ install_path }}" + VHOST_FILE="/etc/apache2/sites-available/${DOMAIN}.conf" + # Write vhost + cat > "$VHOST_FILE" << 'VHOSTEOF' + + ServerName DOMAIN_PLACEHOLDER + DocumentRoot INSTALL_PATH_PLACEHOLDER/public + DirectoryIndex index.php + + + AllowOverride All + Require all granted + + + ErrorLog /var/log/apache2/DOMAIN_PLACEHOLDER-error.log + CustomLog /var/log/apache2/DOMAIN_PLACEHOLDER-access.log combined + + VHOSTEOF + # Replace placeholders (avoid shell quoting issues in heredoc) + sed -i "s|DOMAIN_PLACEHOLDER|$DOMAIN|g" "$VHOST_FILE" + sed -i "s|INSTALL_PATH_PLACEHOLDER|$INSTALL_PATH|g" "$VHOST_FILE" + a2ensite "${DOMAIN}.conf" + a2dissite 000-default.conf 2>/dev/null || true + apache2ctl configtest + systemctl reload apache2 + echo "APACHE CONFIGURED" + on_failure: "abort" + + - id: "init_database" + name: "Initialize wiki database and admin account" + type: "ssh_command" + host: "{{ target_host }}" + user: "{{ ssh_user }}" + key: "{{ ssh_key_path }}" + command: | + set -e + INSTALL_PATH="{{ install_path }}" + WIKI_TITLE="{{ wiki_title }}" + ADMIN_USER="{{ admin_username }}" + ADMIN_PASS="{{ admin_password }}" + # Run Common Grounds install script (if present) + if [ -f "$INSTALL_PATH/install.php" ]; then + php "$INSTALL_PATH/install.php" \ + --title "$WIKI_TITLE" \ + --admin-user "$ADMIN_USER" \ + --admin-pass "$ADMIN_PASS" \ + --db-path "$INSTALL_PATH/data/wiki.db" \ + --non-interactive + echo "DB INITIALIZED via install.php" + elif [ -f "$INSTALL_PATH/scripts/init_db.sh" ]; then + bash "$INSTALL_PATH/scripts/init_db.sh" "$INSTALL_PATH/data/wiki.db" "$WIKI_TITLE" "$ADMIN_USER" "$ADMIN_PASS" + echo "DB INITIALIZED via init_db.sh" + else + echo "WARNING: No install script found — database may need manual initialization." + echo "Run: php $INSTALL_PATH/install.php --help" + fi + on_failure: "warn" + + - id: "enable_https" + name: "Provision Let's Encrypt SSL (optional)" + type: "conditional_ssh_command" + condition: "{{ enable_https }}" + host: "{{ target_host }}" + user: "{{ ssh_user }}" + key: "{{ ssh_key_path }}" + command: | + set -e + DOMAIN="{{ domain_name }}" + EMAIL="{{ certbot_email }}" + if [ -z "$EMAIL" ]; then + echo "ERROR: certbot_email is required when enable_https=true" + exit 1 + fi + apt-get install -y -qq python3-certbot-apache + certbot --apache -d "$DOMAIN" --non-interactive --agree-tos -m "$EMAIL" + echo "SSL PROVISIONED" + on_failure: "warn" + skip_if_condition_false: true + + - id: "health_check" + name: "Post-install health check" + type: "ssh_command" + host: "{{ target_host }}" + user: "{{ ssh_user }}" + key: "{{ ssh_key_path }}" + command: | + DOMAIN="{{ domain_name }}" + PROTOCOL="http" + if [ "{{ enable_https }}" = "true" ]; then PROTOCOL="https"; fi + URL="${PROTOCOL}://${DOMAIN}/" + echo "Checking $URL ..." + STATUS=$(curl -s -o /dev/null -w "%{http_code}" --max-time 10 "$URL" || echo "000") + echo "HTTP status: $STATUS" + if [ "$STATUS" = "200" ] || [ "$STATUS" = "302" ]; then + echo "HEALTH CHECK PASS — wiki is reachable at $URL" + else + echo "HEALTH CHECK WARN — got HTTP $STATUS (DNS may not be propagated yet)" + echo "Verify manually: curl -v $URL" + fi + on_failure: "warn" + +outputs: + - name: "wiki_url" + description: "URL of the deployed wiki" + value: "{{ 'https' if enable_https else 'http' }}://{{ domain_name }}/" + + - name: "admin_url" + description: "Admin login URL" + value: "{{ 'https' if enable_https else 'http' }}://{{ domain_name }}/admin" + + - name: "install_path" + description: "Filesystem path of the wiki installation" + value: "{{ install_path }}" diff --git a/blueprints/it-incident-triage-v1/README.md b/blueprints/it-incident-triage-v1/README.md new file mode 100644 index 0000000..2fe3d7f --- /dev/null +++ b/blueprints/it-incident-triage-v1/README.md @@ -0,0 +1,100 @@ +# IT Incident Triage Workflow Blueprint + +**Blueprint ID**: `it/incident-triage-v1` +**Version**: 1.0.0 +**Type**: `bridge_workflow` +**Pricing**: 150 credits/month (70% creator / 30% platform) +**Author**: XRAY VU (EOO9788) + +Automates the first 10–15 minutes of every IT incident with consistent, +structured triage — from alert to incident channel summary. + +--- + +## What This Blueprint Does + +1. **Classifies severity** (P1/P2/P3/P4) using an AI classifier with configurable criteria +2. **Creates ITSM ticket** in ECP ITSM (or compatible system) with pre-filled fields +3. **Notifies on-call engineer** via Matrix DM +4. **Triggers PagerDuty** (optional) for P1/P2 incidents +5. **Gathers diagnostics** via SSH: service status, logs, disk/RAM, network +6. **Posts structured summary** to the incident channel + +Total execution time: **under 2 minutes** (quick diagnostic mode). + +--- + +## Requirements + +- EIOS Bridge platform with `matrix` + `itsm` features enabled +- Claude Code harness available +- Matrix server (m.xrayvu.com or compatible) +- ECP ITSM module running + +--- + +## Parameters + +| Parameter | Required | Description | +|-----------|----------|-------------| +| `incident_title` | ✅ | One-line description of the incident | +| `affected_service` | ✅ | Service name (e.g. `auth-api`, `database`) | +| `reporter_entity_id` | ✅ | EIOS entity ID of reporter (e.g. `EOU0227`) | +| `matrix_incident_room` | ✅ | Matrix room for incident updates | +| `oncall_matrix_id` | ✅ | Matrix ID of on-call engineer | +| `affected_host` | ✗ | Server IP/hostname for SSH diagnostics | +| `severity_hint` | ✗ | Initial severity estimate (P1–P4, default P2) | +| `pagerduty_routing_key` | ✗ | PagerDuty routing key (omit to skip) | +| `itsm_project` | ✗ | ITSM project code (default: INFRA) | +| `diagnostic_depth` | ✗ | `quick` (2min) or `full` (10min), default quick | + +--- + +## Example Usage + +```bash +eios-blueprint run it/incident-triage-v1 \ + --param incident_title="auth-api returning 503 for all login requests" \ + --param affected_service="ecp-auth" \ + --param affected_host="10.0.0.89" \ + --param reporter_entity_id="EOU0227" \ + --param matrix_incident_room="#incidents:m.xrayvu.com" \ + --param oncall_matrix_id="@chris:m.xrayvu.com" \ + --param severity_hint="P1" \ + --param diagnostic_depth="full" +``` + +--- + +## Outputs + +| Output | Description | +|--------|-------------| +| `incident_id` | Generated incident ID (e.g. `INC-20260609142233`) | +| `severity` | Determined severity (P1/P2/P3/P4) | +| `itsm_ticket_id` | Created ITSM ticket ID | +| `summary_posted` | Whether incident channel received the summary | + +--- + +## Customization + +This Blueprint is designed to be forked and customized: + +- Change severity thresholds in the classifier prompt +- Add additional notification channels (Slack, email) +- Wire to your ITSM system via connector +- Extend diagnostic commands for your stack + +--- + +## Certification Path + +This Blueprint is currently `community` tier. To achieve `certified` tier: +- Validate with 3 documented production incidents +- Submit for security review ($2,000 fee) +- Provides: SLA guarantee + enterprise support eligibility + +--- + +*it/incident-triage-v1 | EIOS Blueprint Package | 2026-06-09* diff --git a/blueprints/it-incident-triage-v1/blueprint.yaml b/blueprints/it-incident-triage-v1/blueprint.yaml new file mode 100644 index 0000000..faec6c8 --- /dev/null +++ b/blueprints/it-incident-triage-v1/blueprint.yaml @@ -0,0 +1,142 @@ +# EIOS Blueprint Package — IT Incident Triage Workflow +# Conforms to: BLUEPRINT_SCHEMA_v1_0.json + +blueprint_id: "it/incident-triage-v1" +version: "1.0.0" +name: "IT Incident Triage Workflow" +blueprint_type: "bridge_workflow" + +author: + entity_id: "EOO9788" + display_name: "XRAY VU" + url: "https://ecp.xrayvu.com" + +license: "commercial" +description: "Automated P1/P2 incident triage: classify severity, notify on-call, create ITSM ticket, dispatch an actor to gather diagnostics, and summarize for the incident commander." + +long_description: | + This Blueprint automates the first 10–15 minutes of every IT incident — the + most chaotic and error-prone window. When an alert fires or a user reports + an issue, the workflow: + + 1. **Classifies severity** (P1/P2/P3/P4) using configurable impact criteria + 2. **Notifies on-call** via Matrix DM, PagerDuty, or both + 3. **Creates an ITSM ticket** in ECP ITSM with pre-filled fields + 4. **Dispatches a diagnostic actor** (Claude Code) to gather logs, check services, and + produce a structured diagnostic report + 5. **Posts a summary** to the incident channel for the incident commander + + What used to take 10–20 minutes of manual work now happens in under 2 minutes, + with a consistent structure every time. + + **Integration points**: + - Input: alert webhook (PagerDuty/Grafana/custom), Matrix message, or CLI trigger + - ITSM: ECP ITSM module (or ServiceNow/Jira via connector) + - Notification: Matrix room + optional PagerDuty + - Diagnostics: SSH to affected host, `journalctl`, `ss`, `df`, `systemctl` + + **Certification path**: This Blueprint is designed to be submitted for `certified` + tier after validation with 3 production incidents. + +domain: "technology" +tags: + - "incident-management" + - "itsm" + - "triage" + - "on-call" + - "automation" + - "devops" + - "monitoring" + - "matrix" + +certification: "community" + +pricing: + model: "subscription" + amount_credits: 150 + revenue_split: + creator_pct: 70 + platform_pct: 30 + +requires: + bridge_version: ">=0.1.0" + eios_version: ">=1.0.0" + platform_features: + - "matrix" + - "itsm" + actor_harnesses: + - "claude-code" + +dependencies: [] + +entry_point: "workflow.yaml" + +parameters: + incident_title: + type: string + description: "Short description of the incident (1 sentence)." + required: true + + affected_service: + type: string + description: "Name of the affected service or system." + required: true + + affected_host: + type: string + description: "Hostname or IP of the primary affected host (for diagnostics). Leave blank to skip SSH diagnostics." + required: false + + severity_hint: + type: enum + description: "Reporter's initial severity estimate. Workflow may upgrade but not downgrade." + required: false + default: "P2" + enum_values: ["P1", "P2", "P3", "P4"] + + reporter_entity_id: + type: string + description: "EIOS entity ID of the person reporting the incident (e.g. EOU0227)." + required: true + + matrix_incident_room: + type: string + description: "Matrix room ID or alias for incident updates (e.g. #incidents:m.xrayvu.com)." + required: true + + oncall_matrix_id: + type: string + description: "Matrix user ID of the current on-call engineer (e.g. @chris:m.xrayvu.com)." + required: true + + pagerduty_routing_key: + type: string + description: "PagerDuty Events API v2 routing key. Leave blank to skip PagerDuty." + required: false + sensitive: true + + itsm_project: + type: string + description: "ECP ITSM project code for ticket creation." + required: false + default: "INFRA" + + diagnostic_depth: + type: enum + description: "How deep the diagnostic actor should go. 'quick' = 2min, 'full' = 10min." + required: false + default: "quick" + enum_values: ["quick", "full"] + +oss: + publish_ready: false + tier: "tier2" + stripping_required: true + +marketplace: + status: "draft" + +changelog: + - version: "1.0.0" + date: "2026-06-09" + changes: "Initial release. P1/P2 classification, Matrix notify, ECP ITSM ticket, SSH diagnostics, summary post." diff --git a/blueprints/it-incident-triage-v1/workflow.yaml b/blueprints/it-incident-triage-v1/workflow.yaml new file mode 100644 index 0000000..ad90ca6 --- /dev/null +++ b/blueprints/it-incident-triage-v1/workflow.yaml @@ -0,0 +1,202 @@ +# IT Incident Triage — Workflow Definition +# Blueprint: it/incident-triage-v1 +# bridge_workflow: executes on Bridge platform via claude-code harness + +name: "IT Incident Triage Workflow" +version: "1.0.0" +executor: "claude-code" +timeout_minutes: 15 + +context: + # Execution context available to all steps as {{ ctx.* }} + incident_id: "INC-{{ timestamp_utc | date('YYYYMMDDHHmmss') }}" + started_at: "{{ timestamp_utc }}" + platform: "eios-bridge" + +steps: + + - id: "classify_severity" + name: "Classify incident severity" + type: "actor_task" + harness: "claude-code" + prompt: | + You are an IT incident classifier. Given the following incident report, + determine the correct severity level (P1/P2/P3/P4) using these criteria: + + P1 — Complete outage or data loss affecting production users NOW + P2 — Significant degradation affecting multiple users or core services + P3 — Partial degradation, workaround available, no data loss + P4 — Minor issue, cosmetic, or low-traffic service affected + + Incident title: {{ incident_title }} + Affected service: {{ affected_service }} + Reporter's estimate: {{ severity_hint }} + + Respond with a JSON object: + { + "severity": "P1|P2|P3|P4", + "severity_rationale": "one sentence", + "confidence": "high|medium|low", + "escalate_immediately": true|false + } + output_var: "classification" + parse_json: true + on_failure: "use_default" + default_output: + severity: "{{ severity_hint }}" + severity_rationale: "Classification failed — using reporter hint" + confidence: "low" + escalate_immediately: "{{ true if severity_hint == 'P1' else false }}" + + - id: "create_itsm_ticket" + name: "Create ITSM ticket" + type: "api_call" + endpoint: "ecp-itsm" + method: "POST" + path: "/api/v1/incidents" + body: + title: "{{ incident_title }}" + severity: "{{ classification.severity }}" + affected_service: "{{ affected_service }}" + reporter: "{{ reporter_entity_id }}" + project: "{{ itsm_project }}" + description: | + Auto-created by IT Incident Triage Blueprint v1.0.0 + Incident ID: {{ ctx.incident_id }} + Severity determined: {{ classification.severity }} ({{ classification.confidence }} confidence) + Rationale: {{ classification.severity_rationale }} + status: "open" + output_var: "itsm_ticket" + on_failure: "warn" + + - id: "notify_oncall" + name: "Notify on-call engineer via Matrix" + type: "matrix_message" + room: "{{ oncall_matrix_id }}" + message: | + 🚨 **{{ classification.severity }} INCIDENT** — {{ incident_title }} + + **Service**: {{ affected_service }} + **Incident ID**: {{ ctx.incident_id }} + **ITSM Ticket**: {{ itsm_ticket.ticket_id | default('pending') }} + **Confidence**: {{ classification.confidence }} + + {{ '⚡ ESCALATE IMMEDIATELY' if classification.escalate_immediately else '📋 Standard triage in progress' }} + + Diagnostic report incoming... + on_failure: "warn" + + - id: "notify_pagerduty" + name: "Trigger PagerDuty alert (if configured)" + type: "conditional_api_call" + condition: "{{ pagerduty_routing_key is defined and pagerduty_routing_key != '' }}" + endpoint: "https://events.pagerduty.com/v2/enqueue" + method: "POST" + headers: + Content-Type: "application/json" + body: + routing_key: "{{ pagerduty_routing_key }}" + event_action: "trigger" + payload: + summary: "{{ classification.severity }}: {{ incident_title }}" + severity: "{{ 'critical' if classification.severity == 'P1' else 'error' if classification.severity == 'P2' else 'warning' }}" + source: "eios-bridge-triage" + custom_details: + incident_id: "{{ ctx.incident_id }}" + affected_service: "{{ affected_service }}" + itsm_ticket: "{{ itsm_ticket.ticket_id | default('N/A') }}" + on_failure: "warn" + skip_if_condition_false: true + + - id: "run_diagnostics" + name: "Gather host diagnostics" + type: "conditional_actor_task" + condition: "{{ affected_host is defined and affected_host != '' }}" + harness: "claude-code" + prompt: | + You are a diagnostic engineer. Connect to the affected host and gather + information about the incident. Use {{ diagnostic_depth }} mode. + + Host: {{ affected_host }} + Service: {{ affected_service }} + Incident: {{ incident_title }} + + {% if diagnostic_depth == 'quick' %} + Quick mode (2 min): Check these and report: + 1. `systemctl status {{ affected_service }} 2>/dev/null || echo 'service not found in systemd'` + 2. `journalctl -u {{ affected_service }} --since "5 minutes ago" --no-pager -n 50 2>/dev/null || journalctl --since "5 minutes ago" --no-pager -n 50` + 3. `df -h / && free -h` + 4. `ss -tlnp | grep -E ':(80|443|8080|8443|3000|5000|8000)' || true` + {% else %} + Full mode (10 min): Gather comprehensive diagnostics: + 1. Service status + recent logs (last 200 lines) + 2. System resources: disk, memory, CPU load + 3. Network: listening ports, active connections + 4. Recent kernel messages: `dmesg | tail -30` + 5. Process list: `ps aux --sort=-%cpu | head -20` + 6. Recent auth attempts: `journalctl -u ssh --since "30 minutes ago" --no-pager -n 20` + {% endif %} + + Produce a structured diagnostic report with: + - executive_summary: 2-3 sentences + - likely_cause: your best hypothesis + - immediate_actions: list of 1-3 concrete steps + - raw_findings: the actual command outputs + output_var: "diagnostics" + on_failure: "warn" + default_output: + executive_summary: "Diagnostic skipped — no host specified or connection failed." + likely_cause: "Unknown" + immediate_actions: ["Manually SSH to affected host", "Check service status", "Review logs"] + raw_findings: "" + skip_if_condition_false: true + + - id: "post_incident_summary" + name: "Post incident summary to incident channel" + type: "matrix_message" + room: "{{ matrix_incident_room }}" + message: | + ## 🚨 Incident {{ ctx.incident_id }} — {{ classification.severity }} + + **{{ incident_title }}** + **Service**: {{ affected_service }} + **ITSM**: {{ itsm_ticket.ticket_id | default('Ticket creation failed') }} + **Reported by**: {{ reporter_entity_id }} + **Started**: {{ ctx.started_at }} + + --- + **Severity Assessment** ({{ classification.confidence }} confidence): + {{ classification.severity_rationale }} + + --- + **Diagnostics**: + {{ diagnostics.executive_summary | default('No diagnostics available') }} + + **Likely cause**: {{ diagnostics.likely_cause | default('Under investigation') }} + + **Immediate actions**: + {% for action in diagnostics.immediate_actions | default([]) %} + - {{ action }} + {% endfor %} + + --- + *Auto-generated by IT Incident Triage Blueprint v1.0.0* + *Incident commander: {{ oncall_matrix_id }}* + on_failure: "abort" + +outputs: + - name: "incident_id" + description: "Generated incident ID" + value: "{{ ctx.incident_id }}" + + - name: "severity" + description: "Determined severity level" + value: "{{ classification.severity }}" + + - name: "itsm_ticket_id" + description: "Created ITSM ticket ID" + value: "{{ itsm_ticket.ticket_id | default('N/A') }}" + + - name: "summary_posted" + description: "Whether summary was posted to incident channel" + value: "{{ true }}" diff --git a/blueprints/org-bootstrap-v1/blueprint.yaml b/blueprints/org-bootstrap-v1/blueprint.yaml new file mode 100644 index 0000000..db032e4 --- /dev/null +++ b/blueprints/org-bootstrap-v1/blueprint.yaml @@ -0,0 +1,158 @@ +blueprint_id: "bridge/org-bootstrap-v1" +version: "1.0.0" +blueprint_type: "bridge_configuration" +name: "Bridge Organization Bootstrap" +description: | + Bootstraps a new organization in The Bridge in under 15 minutes. + Creates the entity registry entries, default roles, Matrix rooms, ITSM + project, and welcome message for a new Bridge client or implementation partner. +long_description: | + The Organization Bootstrap Blueprint is the fastest path to a fully provisioned + Bridge organization. It handles the complete onboarding sequence: + + 1. Register the organization entity (EOO) and admin user entity (EOU) in the EIOS entity registry + 2. Create default role assignments (admin, member, viewer) + 3. Provision a Matrix room (org_room_id) scoped to the organization + 4. Create an ITSM project for incident and request tracking + 5. Send a welcome message to the admin user via Matrix + 6. Generate a summary report with all provisioned resources and next steps + + Designed for Bridge implementation partners onboarding new clients, or for + self-service setup by technical organizations joining The Bridge ecosystem. + +author: + entity_id: "EOO9788" + display_name: "XRAY VU" + +license: "MIT" + +pricing: + model: "free" + amount_credits: 0 + +certification: "community" + +domain: "technology" + +tags: + - "onboarding" + - "organization" + - "setup" + - "configuration" + - "entity-registry" + - "bridge" + - "matrix" + - "itsm" + +marketplace: + status: "published" + +oss: + publish_ready: true + tier: "tier1" + stripping_required: false + +requires: + bridge_version: ">=0.1.0" + platform_features: + - "entity-registry" + - "matrix" + - "itsm" + +parameters: + # Required — organization identity + org_display_name: + type: string + required: true + description: "Human-readable organization name (e.g. 'Acme Corp')" + example: "Carriers Edge" + + org_entity_id: + type: string + required: true + description: "EIOS entity ID for the organization — format EOOxxxx (e.g. EOO0042)" + example: "EOO0042" + pattern: "^EOO[0-9]{4}$" + + admin_user_entity_id: + type: string + required: true + description: "EIOS entity ID for the admin user — format EOUxxxx" + example: "EOU0100" + pattern: "^EOU[0-9]{4}$" + + admin_display_name: + type: string + required: true + description: "Admin user's display name" + example: "Jane Smith" + + admin_email: + type: string + required: true + description: "Admin user's email address" + example: "jane@acmecorp.com" + + # Optional — organization configuration + org_domain: + type: string + required: false + default: "" + description: "Primary domain of the organization (e.g. acmecorp.com)" + + org_industry: + type: string + required: false + default: "general" + description: "Industry vertical for taxonomy" + enum_values: + - "general" + - "healthcare" + - "finance" + - "education" + - "logistics" + - "technology" + - "government" + - "nonprofit" + + create_matrix_room: + type: boolean + required: false + default: true + description: "Create a Matrix room for the organization" + + create_itsm_project: + type: boolean + required: false + default: true + description: "Create an ITSM project for the organization" + + itsm_project_key: + type: string + required: false + default: "" + description: "ITSM project key (auto-derived from org_entity_id if empty)" + + send_welcome_message: + type: boolean + required: false + default: true + description: "Send a welcome Matrix message to the admin user" + + assign_implementation_partner: + type: string + required: false + default: "" + description: "Entity ID of the implementation partner (leave empty for self-service)" + + org_tier: + type: string + required: false + default: "community" + description: "Organization tier in The Bridge" + enum_values: + - "community" + - "verified" + - "enterprise" + +entry_point: "workflow.yaml" diff --git a/blueprints/org-bootstrap-v1/workflow.yaml b/blueprints/org-bootstrap-v1/workflow.yaml new file mode 100644 index 0000000..bc446ca --- /dev/null +++ b/blueprints/org-bootstrap-v1/workflow.yaml @@ -0,0 +1,192 @@ +workflow_id: "bridge/org-bootstrap-v1/workflow" +version: "1.0.0" +description: "Organization Bootstrap — provision a new Bridge org end-to-end" + +steps: + - id: validate_entity_ids + name: "Validate Entity IDs" + type: actor_task + harness: "claude-code" + prompt: | + Validate the following entity IDs are not already registered in the EIOS entity registry. + Check `/opt/EIOS/data/entities/registry/entity_registry.yaml` for existing entries. + + Organization entity ID: {{ org_entity_id }} + Admin user entity ID: {{ admin_user_entity_id }} + + Return JSON: {"org_available": true/false, "user_available": true/false, "conflicts": []} + parse_json: true + output_var: validation_result + on_failure: "abort" + + - id: register_organization + name: "Register Organization Entity" + type: actor_task + harness: "claude-code" + depends_on: ["validate_entity_ids"] + condition: "{{ validation_result.org_available }}" + skip_if_condition_false: false + on_condition_false: "abort_with_message: Organization entity ID {{ org_entity_id }} already exists in registry" + prompt: | + Register a new organization entity in the EIOS entity registry. + + Entity details: + - entity_id: {{ org_entity_id }} + - entity_type: EOO (Organization) + - display_name: {{ org_display_name }} + - domain: {{ org_domain }} + - industry: {{ org_industry }} + - tier: {{ org_tier }} + - created_at: (current UTC timestamp) + - admin_entity_id: {{ admin_user_entity_id }} + + Write the entity record to: + `/opt/EIOS/data/entities/registry/orgs/{{ org_entity_id }}.yaml` + + Follow the schema at `/opt/LIFERAFT/repo/eios/data/_staging/ENTITY_SCHEMA_v1_0.yaml` if it exists. + Use standard EIOS entity YAML format otherwise. + + Return JSON: {"entity_path": "", "success": true} + parse_json: true + output_var: org_registration + on_failure: "abort" + + - id: register_admin_user + name: "Register Admin User Entity" + type: actor_task + harness: "claude-code" + depends_on: ["register_organization"] + prompt: | + Register the admin user entity for the new organization. + + Entity details: + - entity_id: {{ admin_user_entity_id }} + - entity_type: EOU (User) + - display_name: {{ admin_display_name }} + - email: {{ admin_email }} + - org_entity_id: {{ org_entity_id }} + - roles: ["org_admin"] + - created_at: (current UTC timestamp) + + Write the entity record to: + `/opt/EIOS/data/entities/registry/users/{{ admin_user_entity_id }}.yaml` + + Return JSON: {"entity_path": "", "success": true} + parse_json: true + output_var: user_registration + on_failure: "abort" + + - id: create_matrix_room + name: "Create Matrix Room" + type: conditional_actor_task + harness: "claude-code" + depends_on: ["register_admin_user"] + condition: "{{ create_matrix_room }}" + skip_if_condition_false: true + prompt: | + Create a Matrix room for the organization using the Matrix API. + + Organization: {{ org_display_name }} ({{ org_entity_id }}) + + Steps: + 1. Create a room with alias `#{{ org_entity_id | lower }}_main:m.xrayvu.com` + 2. Set room name to "{{ org_display_name }} — Main" + 3. Set room topic to "{{ org_display_name }} organization room — The Bridge" + 4. Set join_rule to "invite" (private) + 5. Invite {{ admin_user_entity_id }} as admin + + Use the Matrix client-server API via the eios-matrix tools or the Matrix admin API. + Matrix homeserver: m.xrayvu.com + + Return JSON: {"room_id": "!...:m.xrayvu.com", "room_alias": "#...:m.xrayvu.com", "success": true} + parse_json: true + output_var: matrix_result + default_output: '{"room_id": null, "room_alias": null, "success": false}' + on_failure: "continue_with_warning" + + - id: create_itsm_project + name: "Create ITSM Project" + type: conditional_actor_task + harness: "claude-code" + depends_on: ["register_admin_user"] + condition: "{{ create_itsm_project }}" + skip_if_condition_false: true + prompt: | + Create an ITSM project for the new organization. + + Organization: {{ org_display_name }} ({{ org_entity_id }}) + Project key: {{ itsm_project_key if itsm_project_key else org_entity_id }} + + Use the ECP ALM/ITSM API at the local ECP platform endpoint. + Create a project with: + - name: "{{ org_display_name }} — Operations" + - key: {{ itsm_project_key if itsm_project_key else org_entity_id }} + - org_entity_id: {{ org_entity_id }} + - admin: {{ admin_user_entity_id }} + - default queues: Incidents, Requests, Changes + + Return JSON: {"project_id": "", "project_key": "", "success": true} + parse_json: true + output_var: itsm_result + default_output: '{"project_id": null, "project_key": null, "success": false}' + on_failure: "continue_with_warning" + + - id: send_welcome_message + name: "Send Welcome Message" + type: conditional_actor_task + harness: "claude-code" + depends_on: ["create_matrix_room"] + condition: "{{ send_welcome_message and create_matrix_room }}" + skip_if_condition_false: true + prompt: | + Send a welcome message to the newly created organization Matrix room. + + Room ID: {{ matrix_result.room_id }} + Organization: {{ org_display_name }} + Admin: {{ admin_display_name }} ({{ admin_user_entity_id }}) + + Send a formatted welcome message that includes: + - Welcome to The Bridge heading + - Organization entity ID: {{ org_entity_id }} + - Admin user: {{ admin_display_name }} ({{ admin_email }}) + - Quick-start links (ITSM project, documentation, support room) + - Next steps: invite team members, configure integrations, review the Blueprint marketplace + + Use the Matrix client API to send an m.room.message event with msgtype m.text. + + Return JSON: {"event_id": "$...", "success": true} + parse_json: true + output_var: welcome_result + default_output: '{"event_id": null, "success": false}' + on_failure: "continue_with_warning" + + - id: generate_summary_report + name: "Generate Bootstrap Summary Report" + type: actor_task + harness: "claude-code" + depends_on: ["send_welcome_message", "create_itsm_project"] + prompt: | + Generate a bootstrap summary report for the new organization. + + Provisioned resources: + - Organization entity: {{ org_entity_id }} ({{ org_display_name }}) + - Admin user entity: {{ admin_user_entity_id }} ({{ admin_display_name }}) + - Organization registry path: {{ org_registration.entity_path }} + - User registry path: {{ user_registration.entity_path }} + - Matrix room: {{ matrix_result.room_id if matrix_result.success else "NOT CREATED" }} + - ITSM project: {{ itsm_result.project_key if itsm_result.success else "NOT CREATED" }} + + Write a Markdown summary report to: + `/opt/EIOS/data/entities/registry/orgs/{{ org_entity_id }}_bootstrap_report.md` + + The report should include: + 1. Bootstrap summary table (all resources + status) + 2. Next steps checklist (invite team, configure integrations, first Blueprint) + 3. Credentials and access information + 4. Support contacts (Bridge support Matrix room, documentation links) + 5. Timestamp and session ID + + Return JSON: {"report_path": "", "success": true} + parse_json: true + output_var: report_result + on_failure: "continue_with_warning" diff --git a/blueprints/security-assessment-v1/blueprint.yaml b/blueprints/security-assessment-v1/blueprint.yaml new file mode 100644 index 0000000..1c592a9 --- /dev/null +++ b/blueprints/security-assessment-v1/blueprint.yaml @@ -0,0 +1,153 @@ +# EIOS Blueprint Package — Security Assessment Report Generator +# Conforms to: BLUEPRINT_SCHEMA_v1_0.json + +blueprint_id: "security/assessment-report-v1" +version: "1.0.0" +name: "Security Assessment Report Generator" +blueprint_type: "bridge_workflow" + +author: + entity_id: "EOO9788" + display_name: "XRAY VU" + url: "https://ecp.xrayvu.com" + +license: "commercial" +description: "Generates a structured security assessment report from interview notes and questionnaire responses. Covers 8 control domains with findings, risk ratings, and remediation recommendations." + +long_description: | + Transforms raw security questionnaire responses and interview notes into a + professional, structured security assessment report in 5–10 minutes. + + This Blueprint emerged from the CarriersEdge Business Email Compromise (BEC) + assessment engagement (XRVU-2026-CE-001) and generalizes the methodology into + a reusable workflow applicable to any organization seeking a rapid security + gap analysis. + + **Control domains covered** (NIST CSF 2.0 aligned): + 1. Email Security (SPF, DKIM, DMARC, BEC defenses) + 2. Identity & Access Management + 3. Endpoint Protection + 4. Network Security + 5. Data Protection & Classification + 6. Incident Response Readiness + 7. Training & Awareness + 8. Third-Party / Supply Chain Risk + + **Output**: Markdown + optionally PDF (via BIDS integration): + - Executive summary + - Risk rating per domain (Critical/High/Medium/Low/Informational) + - Specific findings with evidence + - Prioritized remediation roadmap (90-day / 1-year) + - Estimated effort/cost per recommendation + + **Use cases**: + - Pre-engagement security posture baseline + - Vendor/supplier assessment + - Annual security review automation + - M&A due diligence screening + - Insurance questionnaire support + +domain: "security" +tags: + - "security" + - "assessment" + - "risk" + - "nist-csf" + - "email-security" + - "bec" + - "gap-analysis" + - "compliance" + - "report" + +certification: "community" + +pricing: + model: "usage" + amount_credits: 50 + usage_unit: "per_report" + revenue_split: + creator_pct: 70 + platform_pct: 30 + +requires: + bridge_version: ">=0.1.0" + eios_version: ">=1.0.0" + platform_features: [] + actor_harnesses: + - "claude-code" + +dependencies: [] + +entry_point: "workflow.yaml" + +parameters: + organization_name: + type: string + description: "Name of the organization being assessed." + required: true + + organization_size: + type: enum + description: "Approximate employee count bracket." + required: true + enum_values: ["1-10", "11-50", "51-200", "201-1000", "1000+"] + + industry: + type: string + description: "Industry sector (e.g. 'logistics', 'healthcare', 'financial services')." + required: true + + assessment_scope: + type: string + description: "Brief description of what is in scope (e.g. 'corporate email and endpoints only')." + required: false + default: "Full organization security posture" + + questionnaire_responses: + type: string + description: | + Raw questionnaire responses. Paste the intake questionnaire answers here. + Plain text or Markdown accepted. The actor will parse and extract findings. + required: true + + interview_notes: + type: string + description: "Notes from discovery interviews or additional context. Plain text." + required: false + default: "" + + report_date: + type: string + description: "Report date in YYYY-MM-DD format. Defaults to today." + required: false + + assessor_entity_id: + type: string + description: "EIOS entity ID of the assessor (used for report attribution)." + required: false + default: "EOA0000" + + generate_pdf: + type: boolean + description: "If true and BIDS is available, also generates a PDF version via BIDS." + required: false + default: false + + output_path: + type: string + description: "Filesystem path for the output report file (on the actor's host)." + required: false + default: "/opt/LIFERAFT/repo/eios/data/_staging/eoo/EOO9788/security-assessments/" + +oss: + publish_ready: false + tier: "tier2" + stripping_required: true + +marketplace: + status: "draft" + +changelog: + - version: "1.0.0" + date: "2026-06-09" + changes: "Initial release. 8 NIST CSF domains; findings extraction; risk rating; 90-day roadmap; BIDS PDF optional." diff --git a/blueprints/security-assessment-v1/workflow.yaml b/blueprints/security-assessment-v1/workflow.yaml new file mode 100644 index 0000000..0f8161e --- /dev/null +++ b/blueprints/security-assessment-v1/workflow.yaml @@ -0,0 +1,258 @@ +# Security Assessment Report Generator — Workflow Definition +# Blueprint: security/assessment-report-v1 +# bridge_workflow: executes on Bridge platform via claude-code harness + +name: "Security Assessment Report Generator" +version: "1.0.0" +executor: "claude-code" +timeout_minutes: 15 + +context: + report_id: "SAR-{{ timestamp_utc | date('YYYYMMDD') }}-{{ organization_name | slug | upper }}" + report_date_resolved: "{{ report_date | default(timestamp_utc | date('YYYY-MM-DD')) }}" + +steps: + + - id: "parse_and_classify" + name: "Parse questionnaire responses and classify findings" + type: "actor_task" + harness: "claude-code" + prompt: | + You are a senior cybersecurity assessor. Analyze the following questionnaire + responses and extract security findings for each of the 8 control domains. + + **Organization**: {{ organization_name }} + **Size**: {{ organization_size }} employees + **Industry**: {{ industry }} + **Scope**: {{ assessment_scope }} + + **Questionnaire Responses**: + {{ questionnaire_responses }} + + {% if interview_notes %} + **Interview Notes**: + {{ interview_notes }} + {% endif %} + + For each of the 8 control domains below, produce a structured assessment: + 1. Email Security (SPF/DKIM/DMARC, BEC defenses, MFA on email) + 2. Identity & Access Management (MFA, privileged access, offboarding) + 3. Endpoint Protection (AV/EDR, patch management, disk encryption) + 4. Network Security (firewall, segmentation, VPN, monitoring) + 5. Data Protection & Classification (backup, encryption, data inventory) + 6. Incident Response Readiness (IR plan, tabletop exercises, contacts) + 7. Training & Awareness (phishing simulations, security training frequency) + 8. Third-Party / Supply Chain Risk (vendor assessment, contract clauses) + + For each domain, produce a JSON object: + { + "domain": "domain name", + "risk_rating": "Critical|High|Medium|Low|Informational", + "score": <0-10 where 10=fully mature>, + "findings": [ + { + "id": "F001", + "title": "concise finding title", + "severity": "Critical|High|Medium|Low|Informational", + "description": "what was found", + "evidence": "what the questionnaire said that supports this", + "recommendation": "specific remediation action" + } + ], + "positive_observations": ["things they're doing well"], + "summary": "2-3 sentence domain summary" + } + + Respond with a JSON array of 8 domain objects. + If a domain has insufficient information, mark risk_rating as "Unknown" and + note what information would be needed. + output_var: "domain_assessments" + parse_json: true + on_failure: "abort" + + - id: "generate_executive_summary" + name: "Generate executive summary" + type: "actor_task" + harness: "claude-code" + prompt: | + You are a senior cybersecurity assessor writing for a non-technical executive audience. + + Based on these domain assessments for {{ organization_name }}: + {{ domain_assessments | tojson(indent=2) }} + + Write an executive summary (300-500 words) that: + 1. States the overall security posture in plain language + 2. Identifies the top 3 risk areas requiring immediate attention + 3. Notes 2-3 areas where the organization is doing well + 4. Provides a clear, non-technical statement of business risk + 5. Sets expectations for the remediation roadmap + + Do NOT use jargon without explaining it. + Tone: professional, direct, constructive — not alarmist. + + Respond with the executive summary as a markdown string (no JSON wrapper). + output_var: "executive_summary" + on_failure: "warn" + default_output: "Executive summary generation failed. Review domain findings directly." + + - id: "generate_remediation_roadmap" + name: "Generate prioritized remediation roadmap" + type: "actor_task" + harness: "claude-code" + prompt: | + You are a cybersecurity advisor generating a practical remediation roadmap. + + Organization: {{ organization_name }} ({{ organization_size }} employees, {{ industry }}) + Domain assessments: {{ domain_assessments | tojson(indent=2) }} + + Generate a prioritized remediation roadmap as a JSON object with two phases: + + { + "immediate_actions": [ // 30-90 days: critical/high findings + { + "priority": 1, + "finding_ids": ["F001", "F002"], + "action": "specific action to take", + "rationale": "why this is urgent", + "estimated_effort": "hours|days|weeks", + "estimated_cost": "free|<$1K|$1K-$5K|$5K-$20K|$20K+", + "responsible_party": "IT team|CISO|Vendor|All staff" + } + ], + "strategic_improvements": [ // 6-12 months: medium findings + architecture + { ... same structure ... } + ], + "overall_risk_score": <0-100>, + "maturity_level": "Initial|Developing|Defined|Managed|Optimizing" + } + + Limit immediate_actions to top 5 most impactful items. + Limit strategic_improvements to top 7 items. + output_var: "roadmap" + parse_json: true + on_failure: "warn" + default_output: + immediate_actions: [] + strategic_improvements: [] + overall_risk_score: 0 + maturity_level: "Unknown" + + - id: "assemble_report" + name: "Assemble final report document" + type: "actor_task" + harness: "claude-code" + prompt: | + Assemble a complete security assessment report in Markdown format. + + Use these inputs: + - Report ID: {{ ctx.report_id }} + - Date: {{ ctx.report_date_resolved }} + - Organization: {{ organization_name }} + - Industry: {{ industry }} + - Size: {{ organization_size }} + - Scope: {{ assessment_scope }} + - Assessor entity: {{ assessor_entity_id }} + - Executive summary: {{ executive_summary }} + - Domain assessments: {{ domain_assessments | tojson(indent=2) }} + - Roadmap: {{ roadmap | tojson(indent=2) }} + + Structure the report as follows: + + # Security Assessment Report: {{ organization_name }} + ## Report ID: [id] | Date: [date] | Assessor: [entity] + + ## Executive Summary + [executive_summary] + + ## Assessment Scope + [scope description] + + ## Overall Risk Posture + Overall Risk Score: [X/100] | Maturity Level: [level] + [summary table of all 8 domains with risk rating and score] + + ## Domain Findings + + ### 1. Email Security + [findings for each domain in detail] + ... (repeat for all 8 domains) + + ## Remediation Roadmap + + ### Immediate Actions (30–90 Days) + [immediate actions table] + + ### Strategic Improvements (6–12 Months) + [strategic improvements table] + + ## Methodology & Limitations + This assessment is based on questionnaire responses and interview notes only. + It is not a penetration test or technical audit. Findings should be validated + by technical staff before remediation prioritization. + + --- + *Generated by EIOS Bridge — Security Assessment Blueprint v1.0.0* + *{{ ctx.report_id }}* + + Output ONLY the complete markdown report. No additional commentary. + output_var: "report_markdown" + on_failure: "abort" + + - id: "write_report_file" + name: "Write report to filesystem" + type: "file_write" + path: "{{ output_path }}{{ ctx.report_id }}.md" + content: "{{ report_markdown }}" + create_dirs: true + on_failure: "abort" + + - id: "generate_pdf" + name: "Generate PDF via BIDS (optional)" + type: "conditional_actor_task" + condition: "{{ generate_pdf }}" + harness: "claude-code" + prompt: | + Generate a PDF version of this security assessment report using BIDS. + + Report path: {{ output_path }}{{ ctx.report_id }}.md + BIDS API: http://localhost:8401 + + Run: + curl -s -X POST http://localhost:8401/api/render \ + -H "Content-Type: application/json" \ + -d '{ + "source": "{{ output_path }}{{ ctx.report_id }}.md", + "output": "{{ output_path }}{{ ctx.report_id }}.pdf", + "template": "security_assessment", + "engine": "weasyprint" + }' + + Report the HTTP status and output path. + output_var: "pdf_result" + on_failure: "warn" + skip_if_condition_false: true + +outputs: + - name: "report_id" + description: "Unique report identifier" + value: "{{ ctx.report_id }}" + + - name: "report_path" + description: "Filesystem path of the generated report" + value: "{{ output_path }}{{ ctx.report_id }}.md" + + - name: "pdf_path" + description: "PDF report path (if generated)" + value: "{{ output_path }}{{ ctx.report_id }}.pdf" + + - name: "overall_risk_score" + description: "Aggregated risk score (0-100, higher = worse)" + value: "{{ roadmap.overall_risk_score }}" + + - name: "maturity_level" + description: "NIST CSF maturity level" + value: "{{ roadmap.maturity_level }}" + + - name: "critical_findings_count" + description: "Number of Critical severity findings across all domains" + value: "{{ domain_assessments | selectattr('risk_rating', 'eq', 'Critical') | list | length }}" diff --git a/index.json b/index.json new file mode 100644 index 0000000..b26b0a2 --- /dev/null +++ b/index.json @@ -0,0 +1,52 @@ +{ + "registry": "X-Frames Blueprint Registry", + "version": "1.0.0", + "updated": "2026-06-10", + "schema": "BLUEPRINT_SCHEMA_v1_0.json", + "blueprints": [ + { + "id": "infrastructure/common-grounds-deploy-v1", + "version": "1.0.0", + "name": "Common Grounds Wiki Deployment", + "blueprint_type": "bridge_configuration", + "license": "MIT", + "description": "Deploy a self-hosted Common Grounds wiki on any Debian/Ubuntu server in under 5 minutes. Includes Apache config, PHP, SQLite database, and optional SSL setup.", + "author": "EOO9788", + "registry_path": "blueprints/common-grounds-deploy-v1/", + "url": "https://gitea.ecp.xrayvu.com/xframes/blueprints/src/branch/main/blueprints/common-grounds-deploy-v1/blueprint.yaml" + }, + { + "id": "it/incident-triage-v1", + "version": "1.0.0", + "name": "IT Incident Triage Workflow", + "blueprint_type": "bridge_workflow", + "license": "commercial", + "description": "Automated P1/P2 incident triage: classify severity, notify on-call, create ITSM ticket, dispatch an actor to gather diagnostics, and summarize for the incident commander.", + "author": "EOO9788", + "registry_path": "blueprints/it-incident-triage-v1/", + "url": "https://gitea.ecp.xrayvu.com/xframes/blueprints/src/branch/main/blueprints/it-incident-triage-v1/blueprint.yaml" + }, + { + "id": "bridge/org-bootstrap-v1", + "version": "1.0.0", + "name": "Bridge Organization Bootstrap", + "blueprint_type": "bridge_configuration", + "license": "MIT", + "description": "Bootstraps a new organization in The Bridge in under 15 minutes.\nCreates the entity registry entries, default roles, Matrix rooms, ITSM\nproject, and welcome message for a new Bridge client or implemen", + "author": "EOO9788", + "registry_path": "blueprints/org-bootstrap-v1/", + "url": "https://gitea.ecp.xrayvu.com/xframes/blueprints/src/branch/main/blueprints/org-bootstrap-v1/blueprint.yaml" + }, + { + "id": "security/assessment-report-v1", + "version": "1.0.0", + "name": "Security Assessment Report Generator", + "blueprint_type": "bridge_workflow", + "license": "commercial", + "description": "Generates a structured security assessment report from interview notes and questionnaire responses. Covers 8 control domains with findings, risk ratings, and remediation recommendations.", + "author": "EOO9788", + "registry_path": "blueprints/security-assessment-v1/", + "url": "https://gitea.ecp.xrayvu.com/xframes/blueprints/src/branch/main/blueprints/security-assessment-v1/blueprint.yaml" + } + ] +} \ No newline at end of file