History of Data Prism
io.github.AindriuB/data-prism · Registry status: active
Every published change to this entry, most recent first.
| 2026-10-10 | Declared version: 0.5.0 → 0.6.0 |
|---|---|
| 2026-10-10 | Last changed in the registry (raw): 2026-10-08 → 2026-10-09 |
| 2026-10-10 | First listed in the registry (raw): 2026-10-08 → 2026-10-09 |
| 2026-10-10 | Connection paths (source structure): {"packages":[{"registryType":"oci","identifier":"ghcr.io/aindriub/data-prism-server:0.5.0","runtimeHint":"docker","transport":"streamable-http","environment":[{"name":"LOADER_PATH","description":"Directory Spring Boot's PropertiesLauncher scans for extension jars; already set to /app/adapters by the image, but startup still fails with MISSING_SOURCE_ADAPTER until you bind-mount a reviewed DataSourceAdapter/IdentityResolver jar there (see the -v arguments above)","required":true,"secret":false},{"name":"DATAPRISM_SECURITY_JWT_ISSUER","description":"OAuth2/OIDC issuer that mints the caller's JWT; required for every protected deployment","required":true,"secret":false},{"name":"DATAPRISM_SECURITY_JWT_AUDIENCE","description":"Expected JWT audience claim for this deployment; required for every protected deployment","required":true,"secret":false},{"name":"DATAPRISM_SECURITY_JWT_JWK_SET_URI","description":"HTTPS JWKS location used to verify caller JWTs; exactly one of this or DATAPRISM_SECURITY_JWT_ISSUER_DISCOVERY_URI is required, never both","required":true,"secret":false},{"name":"DATAPRISM_SECURITY_JWT_ISSUER_DISCOVERY_URI","description":"Alternative HTTPS OIDC issuer-discovery location; set this instead of DATAPRISM_SECURITY_JWT_JWK_SET_URI, never both","required":false,"secret":false},{"name":"DATAPRISM_SECURITY_CALLER_CLAIMS_PRINCIPAL","description":"JWT claim name that carries the caller's principal identifier; required, must differ from the roles and investigation claims","required":true,"secret":false},{"name":"DATAPRISM_SECURITY_CALLER_CLAIMS_ROLES","description":"JWT claim name that carries the caller's roles; required, must differ from the principal and investigation claims","required":true,"secret":false},{"name":"DATAPRISM_SECURITY_CALLER_CLAIMS_INVESTIGATION","description":"JWT claim name that carries the trusted investigation/case identifier; required, must differ from the principal and roles claims","required":true,"secret":false},{"name":"DATAPRISM_SECURITY_POLICY_PURPOSES","description":"Comma-separated list of permitted purposes; at least one is required","required":true,"secret":false},{"name":"DATAPRISM_SECURITYPOLICY_ROLES_INVESTIGATOR","description":"Example only — declare DATAPRISM_SECURITYPOLICY_ROLES_<ROLE> per operator-defined role (no underscore between SECURITY and POLICY: Spring Boot's map-key enumeration under a hyphenated dataprism.security-policy.roles.<role> segment only binds the concatenated prefix, verified by binding this property directly against Spring Boot 4.1.1), a comma-separated list of known MCP tool capabilities; at least one role-to-capability mapping is required","required":true,"secret":false},{"name":"DATAPRISM_PRIVACY_PROFILE","description":"Name of the reviewed privacy profile implementation to apply; required","required":true,"secret":false},{"name":"DATAPRISM_PRIVACY_SCOPE_LIFETIME","description":"Positive duration (e.g. 8h) a privacy scope's synthetic identities remain valid; required","required":true,"secret":false},{"name":"DATAPRISM_PRIVACY_HMAC_KEY_KEY_ID","description":"Identifier of the pinned HMAC key used to derive synthetic identities; required","required":true,"secret":false},{"name":"DATAPRISM_PRIVACY_HMAC_KEY_ENVIRONMENT_VARIABLE","description":"Name of the environment variable holding the HMAC key material; exactly one of this or DATAPRISM_PRIVACY_HMAC_KEY_PROVIDER_REFERENCE is required, never both, and never a literal key value","required":true,"secret":false},{"name":"DATAPRISM_PRIVACY_HMAC_KEY_PROVIDER_REFERENCE","description":"Reference to an approved secret provider holding the HMAC key material; set this instead of DATAPRISM_PRIVACY_HMAC_KEY_ENVIRONMENT_VARIABLE, never both","required":false,"secret":false},{"name":"DATAPRISM_AUDIT_SINK","description":"Audit sink implementation: one of approved-sink, slf4j, hash-chained; required, never downgraded to no-op","required":true,"secret":false},{"name":"DATAPRISM_AUDIT_WRITER_ID","description":"Writer/instance identity recorded on every audit entry; required","required":true,"secret":false},{"name":"DATAPRISM_AUDIT_FILE_PATH","description":"Path to the durable, hash-chained audit log; required when DATAPRISM_AUDIT_SINK=hash-chained, refused as MISSING_AUDIT_FILE_PATH if absent for that sink, ignored otherwise","required":false,"secret":false},{"name":"DATAPRISM_METRICS_SINK","description":"Metrics sink binding, currently only micrometer; required in production, never the framework no-op","required":true,"secret":false},{"name":"DATAPRISM_HAZELCAST_TOPOLOGY","description":"Cluster read-budget topology: embedded (shared across members that have joined one cluster; set cluster name and join mode) or single-node (enforced per process); required, never defaulted","required":true,"secret":false},{"name":"DATAPRISM_HAZELCAST_CLUSTERNAME","description":"Hazelcast cluster name; required when DATAPRISM_HAZELCAST_TOPOLOGY=embedded, never dev, refused if set with single-node","required":false,"secret":false},{"name":"DATAPRISM_HAZELCAST_JOIN_MODE","description":"How cluster members find each other: tcp-ip, kubernetes or none; required when DATAPRISM_HAZELCAST_TOPOLOGY=embedded (none is an explicit single member bound to 127.0.0.1), refused if set with single-node","required":false,"secret":false},{"name":"DATAPRISM_HAZELCAST_JOIN_MEMBERS","description":"Comma-separated member addresses (host or host:port); required when DATAPRISM_HAZELCAST_JOIN_MODE=tcp-ip, otherwise unused","required":false,"secret":false},{"name":"DATAPRISM_HAZELCAST_MEMBER_PORT","description":"Hazelcast member port, default 5701, never auto-incremented; must differ from the server, management and operator ports. Member traffic is unencrypted, so keep it on a private network. Optional","required":false,"secret":false},{"name":"DATAPRISM_OPERATOR_ENABLED","description":"Enables the operator surface; optional, off by default","required":false,"secret":false},{"name":"DATAPRISM_OPERATOR_PORT","description":"Port of the operator listener; required when DATAPRISM_OPERATOR_ENABLED=true, must differ from the server, management (OPERATOR_PORT_SHARED otherwise) and member ports, and has no fixed default (publish it explicitly)","required":false,"secret":false},{"name":"DATAPRISM_OPERATOR_REQUIREDAUDIENCE","description":"JWT audience an operator token must carry; required when DATAPRISM_OPERATOR_ENABLED=true","required":false,"secret":false},{"name":"DATAPRISM_OPERATOR_REQUIREDSCOPE","description":"JWT scope an operator token must carry; required when DATAPRISM_OPERATOR_ENABLED=true","required":false,"secret":false},{"name":"DATAPRISM_SOURCES_CUSTOMER_BASE_URL","description":"Example only — declare DATAPRISM_SOURCES_<NAME>_BASE_URL (HTTPS) per configured source; at least one source, each with its own reviewed DataSourceAdapter bean, is required","required":true,"secret":false},{"name":"DATAPRISM_SOURCES_CUSTOMER_TIMEOUT","description":"Example only — declare DATAPRISM_SOURCES_<NAME>_TIMEOUT (positive duration) per configured source; required alongside its base URL","required":true,"secret":false}],"additional_arguments_declared":true}],"remotes":[]} → {"packages":[{"registryType":"oci","identifier":"ghcr.io/aindriub/data-prism-server:0.6.0","runtimeHint":"docker","transport":"streamable-http","environment":[{"name":"LOADER_PATH","description":"Directory Spring Boot's PropertiesLauncher scans for extension jars; already set to /app/adapters by the image, but startup still fails with MISSING_SOURCE_ADAPTER until you bind-mount a reviewed DataSourceAdapter/IdentityResolver jar there (see the -v arguments above)","required":true,"secret":false},{"name":"DATAPRISM_SECURITY_JWT_ISSUER","description":"OAuth2/OIDC issuer that mints the caller's JWT; required for every protected deployment","required":true,"secret":false},{"name":"DATAPRISM_SECURITY_JWT_AUDIENCE","description":"Expected JWT audience claim for this deployment; required for every protected deployment","required":true,"secret":false},{"name":"DATAPRISM_SECURITY_JWT_JWK_SET_URI","description":"HTTPS JWKS location used to verify caller JWTs; exactly one of this or DATAPRISM_SECURITY_JWT_ISSUER_DISCOVERY_URI is required, never both","required":true,"secret":false},{"name":"DATAPRISM_SECURITY_JWT_ISSUER_DISCOVERY_URI","description":"Alternative HTTPS OIDC issuer-discovery location; set this instead of DATAPRISM_SECURITY_JWT_JWK_SET_URI, never both","required":false,"secret":false},{"name":"DATAPRISM_SECURITY_CALLER_CLAIMS_PRINCIPAL","description":"JWT claim name that carries the caller's principal identifier; required, must differ from the roles and investigation claims","required":true,"secret":false},{"name":"DATAPRISM_SECURITY_CALLER_CLAIMS_ROLES","description":"JWT claim name that carries the caller's roles; required, must differ from the principal and investigation claims","required":true,"secret":false},{"name":"DATAPRISM_SECURITY_CALLER_CLAIMS_INVESTIGATION","description":"JWT claim name that carries the trusted investigation/case identifier; required, must differ from the principal and roles claims","required":true,"secret":false},{"name":"DATAPRISM_SECURITY_POLICY_PURPOSES","description":"Comma-separated list of permitted purposes; at least one is required","required":true,"secret":false},{"name":"DATAPRISM_SECURITYPOLICY_ROLES_INVESTIGATOR","description":"Example only — declare DATAPRISM_SECURITYPOLICY_ROLES_<ROLE> per operator-defined role (no underscore between SECURITY and POLICY: Spring Boot's map-key enumeration under a hyphenated dataprism.security-policy.roles.<role> segment only binds the concatenated prefix, verified by binding this property directly against Spring Boot 4.1.1), a comma-separated list of known MCP tool capabilities; at least one role-to-capability mapping is required","required":true,"secret":false},{"name":"DATAPRISM_PRIVACY_PROFILE","description":"Name of the reviewed privacy profile implementation to apply; required","required":true,"secret":false},{"name":"DATAPRISM_PRIVACY_SCOPE_LIFETIME","description":"Positive duration (e.g. 8h) a privacy scope's synthetic identities remain valid; required","required":true,"secret":false},{"name":"DATAPRISM_PRIVACY_HMAC_KEY_KEY_ID","description":"Identifier of the pinned HMAC key used to derive synthetic identities; required","required":true,"secret":false},{"name":"DATAPRISM_PRIVACY_HMAC_KEY_ENVIRONMENT_VARIABLE","description":"Name of the environment variable holding the HMAC key material; exactly one of this or DATAPRISM_PRIVACY_HMAC_KEY_PROVIDER_REFERENCE is required, never both, and never a literal key value","required":true,"secret":false},{"name":"DATAPRISM_PRIVACY_HMAC_KEY_PROVIDER_REFERENCE","description":"Reference to an approved secret provider holding the HMAC key material; set this instead of DATAPRISM_PRIVACY_HMAC_KEY_ENVIRONMENT_VARIABLE, never both","required":false,"secret":false},{"name":"DATAPRISM_AUDIT_SINK","description":"Audit sink implementation: one of approved-sink, slf4j, hash-chained; required, never downgraded to no-op","required":true,"secret":false},{"name":"DATAPRISM_AUDIT_WRITER_ID","description":"Writer/instance identity recorded on every audit entry; required","required":true,"secret":false},{"name":"DATAPRISM_AUDIT_FILE_PATH","description":"Path to the durable, hash-chained audit log; required when DATAPRISM_AUDIT_SINK=hash-chained, refused as MISSING_AUDIT_FILE_PATH if absent for that sink, ignored otherwise","required":false,"secret":false},{"name":"DATAPRISM_METRICS_SINK","description":"Metrics sink binding, currently only micrometer; required in production, never the framework no-op","required":true,"secret":false},{"name":"DATAPRISM_HAZELCAST_TOPOLOGY","description":"Cluster read-budget topology: embedded (shared across members that have joined one cluster; set cluster name and join mode) or single-node (enforced per process); required, never defaulted","required":true,"secret":false},{"name":"DATAPRISM_HAZELCAST_CLUSTERNAME","description":"Hazelcast cluster name; required when DATAPRISM_HAZELCAST_TOPOLOGY=embedded, never dev, refused if set with single-node","required":false,"secret":false},{"name":"DATAPRISM_HAZELCAST_JOIN_MODE","description":"How cluster members find each other: tcp-ip, kubernetes or none; required when DATAPRISM_HAZELCAST_TOPOLOGY=embedded (none is an explicit single member bound to 127.0.0.1), refused if set with single-node","required":false,"secret":false},{"name":"DATAPRISM_HAZELCAST_JOIN_MEMBERS","description":"Comma-separated member addresses (host or host:port); required when DATAPRISM_HAZELCAST_JOIN_MODE=tcp-ip, otherwise unused","required":false,"secret":false},{"name":"DATAPRISM_HAZELCAST_MEMBER_PORT","description":"Hazelcast member port, default 5701, never auto-incremented; must differ from the server, management and operator ports. Member traffic is unencrypted, so keep it on a private network. Optional","required":false,"secret":false},{"name":"DATAPRISM_OPERATOR_ENABLED","description":"Enables the operator surface; optional, off by default","required":false,"secret":false},{"name":"DATAPRISM_OPERATOR_PORT","description":"Port of the operator listener; required when DATAPRISM_OPERATOR_ENABLED=true, must differ from the server, management (OPERATOR_PORT_SHARED otherwise) and member ports, and has no fixed default (publish it explicitly)","required":false,"secret":false},{"name":"DATAPRISM_OPERATOR_REQUIREDAUDIENCE","description":"JWT audience an operator token must carry; required when DATAPRISM_OPERATOR_ENABLED=true","required":false,"secret":false},{"name":"DATAPRISM_OPERATOR_REQUIREDSCOPE","description":"JWT scope an operator token must carry; required when DATAPRISM_OPERATOR_ENABLED=true","required":false,"secret":false},{"name":"DATAPRISM_SOURCES_CUSTOMER_BASE_URL","description":"Example only — declare DATAPRISM_SOURCES_<NAME>_BASE_URL (HTTPS) per configured source; at least one source, each with its own reviewed DataSourceAdapter bean, is required","required":true,"secret":false},{"name":"DATAPRISM_SOURCES_CUSTOMER_TIMEOUT","description":"Example only — declare DATAPRISM_SOURCES_<NAME>_TIMEOUT (positive duration) per configured source; required alongside its base URL","required":true,"secret":false}],"additional_arguments_declared":true}],"remotes":[]} |
| 2026-10-10 | Package identifiers (raw): ghcr.io/aindriub/data-prism-server:0.5.0 → ghcr.io/aindriub/data-prism-server:0.6.0 |
| 2026-10-10 | Package coordinate: oci:ghcr.io/aindriub/data-prism-server:0.5.0 → oci:ghcr.io/aindriub/data-prism-server:0.6.0 |
| 2026-10-09 | Declared version: 0.4.1 → 0.5.0 |
| 2026-10-09 | Last changed in the registry (raw): 2026-10-07 → 2026-10-08 |
| 2026-10-09 | First listed in the registry (raw): 2026-10-07 → 2026-10-08 |
| 2026-10-09 | Environment variable descriptions (raw): DATAPRISM_AUDIT_FILE_PATH=Path to the durable, hash-chained audit log; required when DATAPRISM_AUDIT_SINK=hash-chained, refused as MISSING_AUDIT_FILE_PATH if absent for that sink, ignored otherwise · DATAPRISM_AUDIT_SINK=Audit sink implementation: one of approved-sink, slf4j, hash-chained; required, never downgraded to no-op · DATAPRISM_AUDIT_WRITER_ID=Writer/instance identity recorded on every audit entry; required · DATAPRISM_HAZELCAST_CLUSTERNAME=Hazelcast cluster name; required when DATAPRISM_HAZELCAST_TOPOLOGY=embedded, never dev, refused if set with single-node · DATAPRISM_HAZELCAST_JOIN_MEMBERS=Comma-separated member addresses (host or host:port); required when DATAPRISM_HAZELCAST_JOIN_MODE=tcp-ip, otherwise unused · DATAPRISM_HAZELCAST_JOIN_MODE=How cluster members find each other: tcp-ip, kubernetes or none; required when DATAPRISM_HAZELCAST_TOPOLOGY=embedded (none is an explicit single member bound to 127.0.0.1), refused if set with single-node · DATAPRISM_HAZELCAST_MEMBER_PORT=Hazelcast member port, default 5701, never auto-incremented; must differ from the server, management and operator ports. Member traffic is unencrypted, so keep it on a private network. Optional · DATAPRISM_HAZELCAST_TOPOLOGY=Cluster read-budget topology: embedded (shared across members that have joined one cluster; set cluster name and join mode) or single-node (enforced per process); required, never defaulted · DATAPRISM_METRICS_SINK=Metrics sink binding, currently only micrometer; required in production, never the framework no-op · DATAPRISM_OPERATOR_ENABLED=Enables the operator surface; optional, off by default · DATAPRISM_OPERATOR_PORT=Port of the operator listener; required when DATAPRISM_OPERATOR_ENABLED=true, must differ from the server, management (OPERATOR_PORT_SHARED otherwise) and member ports, and has no fixed default (publish it explicitly) · DATAPRISM_OPERATOR_REQUIREDAUDIENCE=JWT audience an operator token must carry; required when DATAPRISM_OPERATOR_ENABLED=true · DATAPRISM_OPERATOR_REQUIREDSCOPE=JWT scope an operator token must carry; required when DATAPRISM_OPERATOR_ENABLED=true · DATAPRISM_PRIVACY_HMAC_KEY_ENVIRONMENT_VARIABLE=Name of the environment variable holding the HMAC key material; exactly one of this or DATAPRISM_PRIVACY_HMAC_KEY_PROVIDER_REFERENCE is required, never both, and never a literal key value · DATAPRISM_PRIVACY_HMAC_KEY_KEY_ID=Identifier of the pinned HMAC key used to derive synthetic identities; required · DATAPRISM_PRIVACY_HMAC_KEY_PROVIDER_REFERENCE=Reference to an approved secret provider holding the HMAC key material; set this instead of DATAPRISM_PRIVACY_HMAC_KEY_ENVIRONMENT_VARIABLE, never both · DATAPRISM_PRIVACY_PROFILE=Name of the reviewed privacy profile implementation to apply; required · DATAPRISM_PRIVACY_SCOPE_LIFETIME=Positive duration (e.g. 8h) a privacy scope's synthetic identities remain valid; required · DATAPRISM_SECURITYPOLICY_ROLES_INVESTIGATOR=Example only — declare DATAPRISM_SECURITYPOLICY_ROLES_<ROLE> per operator-defined role (no underscore between SECURITY and POLICY: Spring Boot's map-key enumeration under a hyphenated dataprism.security-policy.roles.<role> segment only binds the concatenated prefix, verified by binding this property directly against Spring Boot 3.5.16), a comma-separated list of known MCP tool capabilities; at least one role-to-capability mapping is required · DATAPRISM_SECURITY_CALLER_CLAIMS_INVESTIGATION=JWT claim name that carries the trusted investigation/case identifier; required, must differ from the principal and roles claims · DATAPRISM_SECURITY_CALLER_CLAIMS_PRINCIPAL=JWT claim name that carries the caller's principal identifier; required, must differ from the roles and investigation claims · DATAPRISM_SECURITY_CALLER_CLAIMS_ROLES=JWT claim name that carries the caller's roles; required, must differ from the principal and investigation claims · DATAPRISM_SECURITY_JWT_AUDIENCE=Expected JWT audience claim for this deployment; required for every protected deployment · DATAPRISM_SECURITY_JWT_ISSUER=OAuth2/OIDC issuer that mints the caller's JWT; required for every protected deployment · DATAPRISM_SECURITY_JWT_ISSUER_DISCOVERY_URI=Alternative HTTPS OIDC issuer-discovery location; set this instead of DATAPRISM_SECURITY_JWT_JWK_SET_URI, never both · DATAPRISM_SECURITY_JWT_JWK_SET_URI=HTTPS JWKS location used to verify caller JWTs; exactly one of this or DATAPRISM_SECURITY_JWT_ISSUER_DISCOVERY_URI is required, never both · DATAPRISM_SECURITY_POLICY_PURPOSES=Comma-separated list of permitted purposes; at least one is required · DATAPRISM_SOURCES_CUSTOMER_BASE_URL=Example only — declare DATAPRISM_SOURCES_<NAME>_BASE_URL (HTTPS) per configured source; at least one source, each with its own reviewed DataSourceAdapter bean, is required · DATAPRISM_SOURCES_CUSTOMER_TIMEOUT=Example only — declare DATAPRISM_SOURCES_<NAME>_TIMEOUT (positive duration) per configured source; required alongside its base URL · LOADER_PATH=Directory Spring Boot's PropertiesLauncher scans for extension jars; already set to /app/adapters by the image, but startup still fails with MISSING_SOURCE_ADAPTER until you bind-mount a reviewed DataSourceAdapter/IdentityResolver jar there (see the -v arguments above) → DATAPRISM_AUDIT_FILE_PATH=Path to the durable, hash-chained audit log; required when DATAPRISM_AUDIT_SINK=hash-chained, refused as MISSING_AUDIT_FILE_PATH if absent for that sink, ignored otherwise · DATAPRISM_AUDIT_SINK=Audit sink implementation: one of approved-sink, slf4j, hash-chained; required, never downgraded to no-op · DATAPRISM_AUDIT_WRITER_ID=Writer/instance identity recorded on every audit entry; required · DATAPRISM_HAZELCAST_CLUSTERNAME=Hazelcast cluster name; required when DATAPRISM_HAZELCAST_TOPOLOGY=embedded, never dev, refused if set with single-node · DATAPRISM_HAZELCAST_JOIN_MEMBERS=Comma-separated member addresses (host or host:port); required when DATAPRISM_HAZELCAST_JOIN_MODE=tcp-ip, otherwise unused · DATAPRISM_HAZELCAST_JOIN_MODE=How cluster members find each other: tcp-ip, kubernetes or none; required when DATAPRISM_HAZELCAST_TOPOLOGY=embedded (none is an explicit single member bound to 127.0.0.1), refused if set with single-node · DATAPRISM_HAZELCAST_MEMBER_PORT=Hazelcast member port, default 5701, never auto-incremented; must differ from the server, management and operator ports. Member traffic is unencrypted, so keep it on a private network. Optional · DATAPRISM_HAZELCAST_TOPOLOGY=Cluster read-budget topology: embedded (shared across members that have joined one cluster; set cluster name and join mode) or single-node (enforced per process); required, never defaulted · DATAPRISM_METRICS_SINK=Metrics sink binding, currently only micrometer; required in production, never the framework no-op · DATAPRISM_OPERATOR_ENABLED=Enables the operator surface; optional, off by default · DATAPRISM_OPERATOR_PORT=Port of the operator listener; required when DATAPRISM_OPERATOR_ENABLED=true, must differ from the server, management (OPERATOR_PORT_SHARED otherwise) and member ports, and has no fixed default (publish it explicitly) · DATAPRISM_OPERATOR_REQUIREDAUDIENCE=JWT audience an operator token must carry; required when DATAPRISM_OPERATOR_ENABLED=true · DATAPRISM_OPERATOR_REQUIREDSCOPE=JWT scope an operator token must carry; required when DATAPRISM_OPERATOR_ENABLED=true · DATAPRISM_PRIVACY_HMAC_KEY_ENVIRONMENT_VARIABLE=Name of the environment variable holding the HMAC key material; exactly one of this or DATAPRISM_PRIVACY_HMAC_KEY_PROVIDER_REFERENCE is required, never both, and never a literal key value · DATAPRISM_PRIVACY_HMAC_KEY_KEY_ID=Identifier of the pinned HMAC key used to derive synthetic identities; required · DATAPRISM_PRIVACY_HMAC_KEY_PROVIDER_REFERENCE=Reference to an approved secret provider holding the HMAC key material; set this instead of DATAPRISM_PRIVACY_HMAC_KEY_ENVIRONMENT_VARIABLE, never both · DATAPRISM_PRIVACY_PROFILE=Name of the reviewed privacy profile implementation to apply; required · DATAPRISM_PRIVACY_SCOPE_LIFETIME=Positive duration (e.g. 8h) a privacy scope's synthetic identities remain valid; required · DATAPRISM_SECURITYPOLICY_ROLES_INVESTIGATOR=Example only — declare DATAPRISM_SECURITYPOLICY_ROLES_<ROLE> per operator-defined role (no underscore between SECURITY and POLICY: Spring Boot's map-key enumeration under a hyphenated dataprism.security-policy.roles.<role> segment only binds the concatenated prefix, verified by binding this property directly against Spring Boot 4.1.1), a comma-separated list of known MCP tool capabilities; at least one role-to-capability mapping is required · DATAPRISM_SECURITY_CALLER_CLAIMS_INVESTIGATION=JWT claim name that carries the trusted investigation/case identifier; required, must differ from the principal and roles claims · DATAPRISM_SECURITY_CALLER_CLAIMS_PRINCIPAL=JWT claim name that carries the caller's principal identifier; required, must differ from the roles and investigation claims · DATAPRISM_SECURITY_CALLER_CLAIMS_ROLES=JWT claim name that carries the caller's roles; required, must differ from the principal and investigation claims · DATAPRISM_SECURITY_JWT_AUDIENCE=Expected JWT audience claim for this deployment; required for every protected deployment · DATAPRISM_SECURITY_JWT_ISSUER=OAuth2/OIDC issuer that mints the caller's JWT; required for every protected deployment · DATAPRISM_SECURITY_JWT_ISSUER_DISCOVERY_URI=Alternative HTTPS OIDC issuer-discovery location; set this instead of DATAPRISM_SECURITY_JWT_JWK_SET_URI, never both · DATAPRISM_SECURITY_JWT_JWK_SET_URI=HTTPS JWKS location used to verify caller JWTs; exactly one of this or DATAPRISM_SECURITY_JWT_ISSUER_DISCOVERY_URI is required, never both · DATAPRISM_SECURITY_POLICY_PURPOSES=Comma-separated list of permitted purposes; at least one is required · DATAPRISM_SOURCES_CUSTOMER_BASE_URL=Example only — declare DATAPRISM_SOURCES_<NAME>_BASE_URL (HTTPS) per configured source; at least one source, each with its own reviewed DataSourceAdapter bean, is required · DATAPRISM_SOURCES_CUSTOMER_TIMEOUT=Example only — declare DATAPRISM_SOURCES_<NAME>_TIMEOUT (positive duration) per configured source; required alongside its base URL · LOADER_PATH=Directory Spring Boot's PropertiesLauncher scans for extension jars; already set to /app/adapters by the image, but startup still fails with MISSING_SOURCE_ADAPTER until you bind-mount a reviewed DataSourceAdapter/IdentityResolver jar there (see the -v arguments above) |
| 2026-10-09 | Connection paths (source structure): {"packages":[{"registryType":"oci","identifier":"ghcr.io/aindriub/data-prism-server:0.4.1","runtimeHint":"docker","transport":"streamable-http","environment":[{"name":"LOADER_PATH","description":"Directory Spring Boot's PropertiesLauncher scans for extension jars; already set to /app/adapters by the image, but startup still fails with MISSING_SOURCE_ADAPTER until you bind-mount a reviewed DataSourceAdapter/IdentityResolver jar there (see the -v arguments above)","required":true,"secret":false},{"name":"DATAPRISM_SECURITY_JWT_ISSUER","description":"OAuth2/OIDC issuer that mints the caller's JWT; required for every protected deployment","required":true,"secret":false},{"name":"DATAPRISM_SECURITY_JWT_AUDIENCE","description":"Expected JWT audience claim for this deployment; required for every protected deployment","required":true,"secret":false},{"name":"DATAPRISM_SECURITY_JWT_JWK_SET_URI","description":"HTTPS JWKS location used to verify caller JWTs; exactly one of this or DATAPRISM_SECURITY_JWT_ISSUER_DISCOVERY_URI is required, never both","required":true,"secret":false},{"name":"DATAPRISM_SECURITY_JWT_ISSUER_DISCOVERY_URI","description":"Alternative HTTPS OIDC issuer-discovery location; set this instead of DATAPRISM_SECURITY_JWT_JWK_SET_URI, never both","required":false,"secret":false},{"name":"DATAPRISM_SECURITY_CALLER_CLAIMS_PRINCIPAL","description":"JWT claim name that carries the caller's principal identifier; required, must differ from the roles and investigation claims","required":true,"secret":false},{"name":"DATAPRISM_SECURITY_CALLER_CLAIMS_ROLES","description":"JWT claim name that carries the caller's roles; required, must differ from the principal and investigation claims","required":true,"secret":false},{"name":"DATAPRISM_SECURITY_CALLER_CLAIMS_INVESTIGATION","description":"JWT claim name that carries the trusted investigation/case identifier; required, must differ from the principal and roles claims","required":true,"secret":false},{"name":"DATAPRISM_SECURITY_POLICY_PURPOSES","description":"Comma-separated list of permitted purposes; at least one is required","required":true,"secret":false},{"name":"DATAPRISM_SECURITYPOLICY_ROLES_INVESTIGATOR","description":"Example only — declare DATAPRISM_SECURITYPOLICY_ROLES_<ROLE> per operator-defined role (no underscore between SECURITY and POLICY: Spring Boot's map-key enumeration under a hyphenated dataprism.security-policy.roles.<role> segment only binds the concatenated prefix, verified by binding this property directly against Spring Boot 3.5.16), a comma-separated list of known MCP tool capabilities; at least one role-to-capability mapping is required","required":true,"secret":false},{"name":"DATAPRISM_PRIVACY_PROFILE","description":"Name of the reviewed privacy profile implementation to apply; required","required":true,"secret":false},{"name":"DATAPRISM_PRIVACY_SCOPE_LIFETIME","description":"Positive duration (e.g. 8h) a privacy scope's synthetic identities remain valid; required","required":true,"secret":false},{"name":"DATAPRISM_PRIVACY_HMAC_KEY_KEY_ID","description":"Identifier of the pinned HMAC key used to derive synthetic identities; required","required":true,"secret":false},{"name":"DATAPRISM_PRIVACY_HMAC_KEY_ENVIRONMENT_VARIABLE","description":"Name of the environment variable holding the HMAC key material; exactly one of this or DATAPRISM_PRIVACY_HMAC_KEY_PROVIDER_REFERENCE is required, never both, and never a literal key value","required":true,"secret":false},{"name":"DATAPRISM_PRIVACY_HMAC_KEY_PROVIDER_REFERENCE","description":"Reference to an approved secret provider holding the HMAC key material; set this instead of DATAPRISM_PRIVACY_HMAC_KEY_ENVIRONMENT_VARIABLE, never both","required":false,"secret":false},{"name":"DATAPRISM_AUDIT_SINK","description":"Audit sink implementation: one of approved-sink, slf4j, hash-chained; required, never downgraded to no-op","required":true,"secret":false},{"name":"DATAPRISM_AUDIT_WRITER_ID","description":"Writer/instance identity recorded on every audit entry; required","required":true,"secret":false},{"name":"DATAPRISM_AUDIT_FILE_PATH","description":"Path to the durable, hash-chained audit log; required when DATAPRISM_AUDIT_SINK=hash-chained, refused as MISSING_AUDIT_FILE_PATH if absent for that sink, ignored otherwise","required":false,"secret":false},{"name":"DATAPRISM_METRICS_SINK","description":"Metrics sink binding, currently only micrometer; required in production, never the framework no-op","required":true,"secret":false},{"name":"DATAPRISM_HAZELCAST_TOPOLOGY","description":"Cluster read-budget topology: embedded (shared across members that have joined one cluster; set cluster name and join mode) or single-node (enforced per process); required, never defaulted","required":true,"secret":false},{"name":"DATAPRISM_HAZELCAST_CLUSTERNAME","description":"Hazelcast cluster name; required when DATAPRISM_HAZELCAST_TOPOLOGY=embedded, never dev, refused if set with single-node","required":false,"secret":false},{"name":"DATAPRISM_HAZELCAST_JOIN_MODE","description":"How cluster members find each other: tcp-ip, kubernetes or none; required when DATAPRISM_HAZELCAST_TOPOLOGY=embedded (none is an explicit single member bound to 127.0.0.1), refused if set with single-node","required":false,"secret":false},{"name":"DATAPRISM_HAZELCAST_JOIN_MEMBERS","description":"Comma-separated member addresses (host or host:port); required when DATAPRISM_HAZELCAST_JOIN_MODE=tcp-ip, otherwise unused","required":false,"secret":false},{"name":"DATAPRISM_HAZELCAST_MEMBER_PORT","description":"Hazelcast member port, default 5701, never auto-incremented; must differ from the server, management and operator ports. Member traffic is unencrypted, so keep it on a private network. Optional","required":false,"secret":false},{"name":"DATAPRISM_OPERATOR_ENABLED","description":"Enables the operator surface; optional, off by default","required":false,"secret":false},{"name":"DATAPRISM_OPERATOR_PORT","description":"Port of the operator listener; required when DATAPRISM_OPERATOR_ENABLED=true, must differ from the server, management (OPERATOR_PORT_SHARED otherwise) and member ports, and has no fixed default (publish it explicitly)","required":false,"secret":false},{"name":"DATAPRISM_OPERATOR_REQUIREDAUDIENCE","description":"JWT audience an operator token must carry; required when DATAPRISM_OPERATOR_ENABLED=true","required":false,"secret":false},{"name":"DATAPRISM_OPERATOR_REQUIREDSCOPE","description":"JWT scope an operator token must carry; required when DATAPRISM_OPERATOR_ENABLED=true","required":false,"secret":false},{"name":"DATAPRISM_SOURCES_CUSTOMER_BASE_URL","description":"Example only — declare DATAPRISM_SOURCES_<NAME>_BASE_URL (HTTPS) per configured source; at least one source, each with its own reviewed DataSourceAdapter bean, is required","required":true,"secret":false},{"name":"DATAPRISM_SOURCES_CUSTOMER_TIMEOUT","description":"Example only — declare DATAPRISM_SOURCES_<NAME>_TIMEOUT (positive duration) per configured source; required alongside its base URL","required":true,"secret":false}],"additional_arguments_declared":true}],"remotes":[]} → {"packages":[{"registryType":"oci","identifier":"ghcr.io/aindriub/data-prism-server:0.5.0","runtimeHint":"docker","transport":"streamable-http","environment":[{"name":"LOADER_PATH","description":"Directory Spring Boot's PropertiesLauncher scans for extension jars; already set to /app/adapters by the image, but startup still fails with MISSING_SOURCE_ADAPTER until you bind-mount a reviewed DataSourceAdapter/IdentityResolver jar there (see the -v arguments above)","required":true,"secret":false},{"name":"DATAPRISM_SECURITY_JWT_ISSUER","description":"OAuth2/OIDC issuer that mints the caller's JWT; required for every protected deployment","required":true,"secret":false},{"name":"DATAPRISM_SECURITY_JWT_AUDIENCE","description":"Expected JWT audience claim for this deployment; required for every protected deployment","required":true,"secret":false},{"name":"DATAPRISM_SECURITY_JWT_JWK_SET_URI","description":"HTTPS JWKS location used to verify caller JWTs; exactly one of this or DATAPRISM_SECURITY_JWT_ISSUER_DISCOVERY_URI is required, never both","required":true,"secret":false},{"name":"DATAPRISM_SECURITY_JWT_ISSUER_DISCOVERY_URI","description":"Alternative HTTPS OIDC issuer-discovery location; set this instead of DATAPRISM_SECURITY_JWT_JWK_SET_URI, never both","required":false,"secret":false},{"name":"DATAPRISM_SECURITY_CALLER_CLAIMS_PRINCIPAL","description":"JWT claim name that carries the caller's principal identifier; required, must differ from the roles and investigation claims","required":true,"secret":false},{"name":"DATAPRISM_SECURITY_CALLER_CLAIMS_ROLES","description":"JWT claim name that carries the caller's roles; required, must differ from the principal and investigation claims","required":true,"secret":false},{"name":"DATAPRISM_SECURITY_CALLER_CLAIMS_INVESTIGATION","description":"JWT claim name that carries the trusted investigation/case identifier; required, must differ from the principal and roles claims","required":true,"secret":false},{"name":"DATAPRISM_SECURITY_POLICY_PURPOSES","description":"Comma-separated list of permitted purposes; at least one is required","required":true,"secret":false},{"name":"DATAPRISM_SECURITYPOLICY_ROLES_INVESTIGATOR","description":"Example only — declare DATAPRISM_SECURITYPOLICY_ROLES_<ROLE> per operator-defined role (no underscore between SECURITY and POLICY: Spring Boot's map-key enumeration under a hyphenated dataprism.security-policy.roles.<role> segment only binds the concatenated prefix, verified by binding this property directly against Spring Boot 4.1.1), a comma-separated list of known MCP tool capabilities; at least one role-to-capability mapping is required","required":true,"secret":false},{"name":"DATAPRISM_PRIVACY_PROFILE","description":"Name of the reviewed privacy profile implementation to apply; required","required":true,"secret":false},{"name":"DATAPRISM_PRIVACY_SCOPE_LIFETIME","description":"Positive duration (e.g. 8h) a privacy scope's synthetic identities remain valid; required","required":true,"secret":false},{"name":"DATAPRISM_PRIVACY_HMAC_KEY_KEY_ID","description":"Identifier of the pinned HMAC key used to derive synthetic identities; required","required":true,"secret":false},{"name":"DATAPRISM_PRIVACY_HMAC_KEY_ENVIRONMENT_VARIABLE","description":"Name of the environment variable holding the HMAC key material; exactly one of this or DATAPRISM_PRIVACY_HMAC_KEY_PROVIDER_REFERENCE is required, never both, and never a literal key value","required":true,"secret":false},{"name":"DATAPRISM_PRIVACY_HMAC_KEY_PROVIDER_REFERENCE","description":"Reference to an approved secret provider holding the HMAC key material; set this instead of DATAPRISM_PRIVACY_HMAC_KEY_ENVIRONMENT_VARIABLE, never both","required":false,"secret":false},{"name":"DATAPRISM_AUDIT_SINK","description":"Audit sink implementation: one of approved-sink, slf4j, hash-chained; required, never downgraded to no-op","required":true,"secret":false},{"name":"DATAPRISM_AUDIT_WRITER_ID","description":"Writer/instance identity recorded on every audit entry; required","required":true,"secret":false},{"name":"DATAPRISM_AUDIT_FILE_PATH","description":"Path to the durable, hash-chained audit log; required when DATAPRISM_AUDIT_SINK=hash-chained, refused as MISSING_AUDIT_FILE_PATH if absent for that sink, ignored otherwise","required":false,"secret":false},{"name":"DATAPRISM_METRICS_SINK","description":"Metrics sink binding, currently only micrometer; required in production, never the framework no-op","required":true,"secret":false},{"name":"DATAPRISM_HAZELCAST_TOPOLOGY","description":"Cluster read-budget topology: embedded (shared across members that have joined one cluster; set cluster name and join mode) or single-node (enforced per process); required, never defaulted","required":true,"secret":false},{"name":"DATAPRISM_HAZELCAST_CLUSTERNAME","description":"Hazelcast cluster name; required when DATAPRISM_HAZELCAST_TOPOLOGY=embedded, never dev, refused if set with single-node","required":false,"secret":false},{"name":"DATAPRISM_HAZELCAST_JOIN_MODE","description":"How cluster members find each other: tcp-ip, kubernetes or none; required when DATAPRISM_HAZELCAST_TOPOLOGY=embedded (none is an explicit single member bound to 127.0.0.1), refused if set with single-node","required":false,"secret":false},{"name":"DATAPRISM_HAZELCAST_JOIN_MEMBERS","description":"Comma-separated member addresses (host or host:port); required when DATAPRISM_HAZELCAST_JOIN_MODE=tcp-ip, otherwise unused","required":false,"secret":false},{"name":"DATAPRISM_HAZELCAST_MEMBER_PORT","description":"Hazelcast member port, default 5701, never auto-incremented; must differ from the server, management and operator ports. Member traffic is unencrypted, so keep it on a private network. Optional","required":false,"secret":false},{"name":"DATAPRISM_OPERATOR_ENABLED","description":"Enables the operator surface; optional, off by default","required":false,"secret":false},{"name":"DATAPRISM_OPERATOR_PORT","description":"Port of the operator listener; required when DATAPRISM_OPERATOR_ENABLED=true, must differ from the server, management (OPERATOR_PORT_SHARED otherwise) and member ports, and has no fixed default (publish it explicitly)","required":false,"secret":false},{"name":"DATAPRISM_OPERATOR_REQUIREDAUDIENCE","description":"JWT audience an operator token must carry; required when DATAPRISM_OPERATOR_ENABLED=true","required":false,"secret":false},{"name":"DATAPRISM_OPERATOR_REQUIREDSCOPE","description":"JWT scope an operator token must carry; required when DATAPRISM_OPERATOR_ENABLED=true","required":false,"secret":false},{"name":"DATAPRISM_SOURCES_CUSTOMER_BASE_URL","description":"Example only — declare DATAPRISM_SOURCES_<NAME>_BASE_URL (HTTPS) per configured source; at least one source, each with its own reviewed DataSourceAdapter bean, is required","required":true,"secret":false},{"name":"DATAPRISM_SOURCES_CUSTOMER_TIMEOUT","description":"Example only — declare DATAPRISM_SOURCES_<NAME>_TIMEOUT (positive duration) per configured source; required alongside its base URL","required":true,"secret":false}],"additional_arguments_declared":true}],"remotes":[]} |
| 2026-10-09 | Package identifiers (raw): ghcr.io/aindriub/data-prism-server:0.4.1 → ghcr.io/aindriub/data-prism-server:0.5.0 |
| 2026-10-09 | Package coordinate: oci:ghcr.io/aindriub/data-prism-server:0.4.1 → oci:ghcr.io/aindriub/data-prism-server:0.5.0 |
| 2026-10-08 | Declared version: 0.4.0 → 0.4.1 |
| 2026-10-08 | Last changed in the registry (raw): 2026-10-06 → 2026-10-07 |
| 2026-10-08 | First listed in the registry (raw): 2026-10-06 → 2026-10-07 |
| 2026-10-08 | Environment variable descriptions (raw): DATAPRISM_AUDIT_FILE_PATH=Path to the durable, hash-chained audit log; required when DATAPRISM_AUDIT_SINK=hash-chained, refused as MISSING_AUDIT_FILE_PATH if absent for that sink, ignored otherwise · DATAPRISM_AUDIT_SINK=Audit sink implementation: one of approved-sink, slf4j, hash-chained; required, never downgraded to no-op · DATAPRISM_AUDIT_WRITER_ID=Writer/instance identity recorded on every audit entry; required · DATAPRISM_HAZELCAST_TOPOLOGY=Cluster read-budget topology: embedded (shared across the cluster) or single-node (enforced per process); required, never defaulted · DATAPRISM_METRICS_SINK=Metrics sink binding, currently only micrometer; required in production, never the framework no-op · DATAPRISM_PRIVACY_HMAC_KEY_ENVIRONMENT_VARIABLE=Name of the environment variable holding the HMAC key material; exactly one of this or DATAPRISM_PRIVACY_HMAC_KEY_PROVIDER_REFERENCE is required, never both, and never a literal key value · DATAPRISM_PRIVACY_HMAC_KEY_KEY_ID=Identifier of the pinned HMAC key used to derive synthetic identities; required · DATAPRISM_PRIVACY_HMAC_KEY_PROVIDER_REFERENCE=Reference to an approved secret provider holding the HMAC key material; set this instead of DATAPRISM_PRIVACY_HMAC_KEY_ENVIRONMENT_VARIABLE, never both · DATAPRISM_PRIVACY_PROFILE=Name of the reviewed privacy profile implementation to apply; required · DATAPRISM_PRIVACY_SCOPE_LIFETIME=Positive duration (e.g. 8h) a privacy scope's synthetic identities remain valid; required · DATAPRISM_SECURITYPOLICY_ROLES_INVESTIGATOR=Example only — declare DATAPRISM_SECURITYPOLICY_ROLES_<ROLE> per operator-defined role (no underscore between SECURITY and POLICY: Spring Boot's map-key enumeration under a hyphenated dataprism.security-policy.roles.<role> segment only binds the concatenated prefix, verified by binding this property directly against Spring Boot 3.5.16), a comma-separated list of known MCP tool capabilities; at least one role-to-capability mapping is required · DATAPRISM_SECURITY_CALLER_CLAIMS_INVESTIGATION=JWT claim name that carries the trusted investigation/case identifier; required, must differ from the principal and roles claims · DATAPRISM_SECURITY_CALLER_CLAIMS_PRINCIPAL=JWT claim name that carries the caller's principal identifier; required, must differ from the roles and investigation claims · DATAPRISM_SECURITY_CALLER_CLAIMS_ROLES=JWT claim name that carries the caller's roles; required, must differ from the principal and investigation claims · DATAPRISM_SECURITY_JWT_AUDIENCE=Expected JWT audience claim for this deployment; required for every protected deployment · DATAPRISM_SECURITY_JWT_ISSUER=OAuth2/OIDC issuer that mints the caller's JWT; required for every protected deployment · DATAPRISM_SECURITY_JWT_ISSUER_DISCOVERY_URI=Alternative HTTPS OIDC issuer-discovery location; set this instead of DATAPRISM_SECURITY_JWT_JWK_SET_URI, never both · DATAPRISM_SECURITY_JWT_JWK_SET_URI=HTTPS JWKS location used to verify caller JWTs; exactly one of this or DATAPRISM_SECURITY_JWT_ISSUER_DISCOVERY_URI is required, never both · DATAPRISM_SECURITY_POLICY_PURPOSES=Comma-separated list of permitted purposes; at least one is required · DATAPRISM_SOURCES_CUSTOMER_BASE_URL=Example only — declare DATAPRISM_SOURCES_<NAME>_BASE_URL (HTTPS) per configured source; at least one source, each with its own reviewed DataSourceAdapter bean, is required · DATAPRISM_SOURCES_CUSTOMER_TIMEOUT=Example only — declare DATAPRISM_SOURCES_<NAME>_TIMEOUT (positive duration) per configured source; required alongside its base URL · LOADER_PATH=Directory Spring Boot's PropertiesLauncher scans for extension jars; already set to /app/adapters by the image, but startup still fails with MISSING_SOURCE_ADAPTER until you bind-mount a reviewed DataSourceAdapter/IdentityResolver jar there (see the -v arguments above) → DATAPRISM_AUDIT_FILE_PATH=Path to the durable, hash-chained audit log; required when DATAPRISM_AUDIT_SINK=hash-chained, refused as MISSING_AUDIT_FILE_PATH if absent for that sink, ignored otherwise · DATAPRISM_AUDIT_SINK=Audit sink implementation: one of approved-sink, slf4j, hash-chained; required, never downgraded to no-op · DATAPRISM_AUDIT_WRITER_ID=Writer/instance identity recorded on every audit entry; required · DATAPRISM_HAZELCAST_CLUSTERNAME=Hazelcast cluster name; required when DATAPRISM_HAZELCAST_TOPOLOGY=embedded, never dev, refused if set with single-node · DATAPRISM_HAZELCAST_JOIN_MEMBERS=Comma-separated member addresses (host or host:port); required when DATAPRISM_HAZELCAST_JOIN_MODE=tcp-ip, otherwise unused · DATAPRISM_HAZELCAST_JOIN_MODE=How cluster members find each other: tcp-ip, kubernetes or none; required when DATAPRISM_HAZELCAST_TOPOLOGY=embedded (none is an explicit single member bound to 127.0.0.1), refused if set with single-node · DATAPRISM_HAZELCAST_MEMBER_PORT=Hazelcast member port, default 5701, never auto-incremented; must differ from the server, management and operator ports. Member traffic is unencrypted, so keep it on a private network. Optional · DATAPRISM_HAZELCAST_TOPOLOGY=Cluster read-budget topology: embedded (shared across members that have joined one cluster; set cluster name and join mode) or single-node (enforced per process); required, never defaulted · DATAPRISM_METRICS_SINK=Metrics sink binding, currently only micrometer; required in production, never the framework no-op · DATAPRISM_OPERATOR_ENABLED=Enables the operator surface; optional, off by default · DATAPRISM_OPERATOR_PORT=Port of the operator listener; required when DATAPRISM_OPERATOR_ENABLED=true, must differ from the server, management (OPERATOR_PORT_SHARED otherwise) and member ports, and has no fixed default (publish it explicitly) · DATAPRISM_OPERATOR_REQUIREDAUDIENCE=JWT audience an operator token must carry; required when DATAPRISM_OPERATOR_ENABLED=true · DATAPRISM_OPERATOR_REQUIREDSCOPE=JWT scope an operator token must carry; required when DATAPRISM_OPERATOR_ENABLED=true · DATAPRISM_PRIVACY_HMAC_KEY_ENVIRONMENT_VARIABLE=Name of the environment variable holding the HMAC key material; exactly one of this or DATAPRISM_PRIVACY_HMAC_KEY_PROVIDER_REFERENCE is required, never both, and never a literal key value · DATAPRISM_PRIVACY_HMAC_KEY_KEY_ID=Identifier of the pinned HMAC key used to derive synthetic identities; required · DATAPRISM_PRIVACY_HMAC_KEY_PROVIDER_REFERENCE=Reference to an approved secret provider holding the HMAC key material; set this instead of DATAPRISM_PRIVACY_HMAC_KEY_ENVIRONMENT_VARIABLE, never both · DATAPRISM_PRIVACY_PROFILE=Name of the reviewed privacy profile implementation to apply; required · DATAPRISM_PRIVACY_SCOPE_LIFETIME=Positive duration (e.g. 8h) a privacy scope's synthetic identities remain valid; required · DATAPRISM_SECURITYPOLICY_ROLES_INVESTIGATOR=Example only — declare DATAPRISM_SECURITYPOLICY_ROLES_<ROLE> per operator-defined role (no underscore between SECURITY and POLICY: Spring Boot's map-key enumeration under a hyphenated dataprism.security-policy.roles.<role> segment only binds the concatenated prefix, verified by binding this property directly against Spring Boot 3.5.16), a comma-separated list of known MCP tool capabilities; at least one role-to-capability mapping is required · DATAPRISM_SECURITY_CALLER_CLAIMS_INVESTIGATION=JWT claim name that carries the trusted investigation/case identifier; required, must differ from the principal and roles claims · DATAPRISM_SECURITY_CALLER_CLAIMS_PRINCIPAL=JWT claim name that carries the caller's principal identifier; required, must differ from the roles and investigation claims · DATAPRISM_SECURITY_CALLER_CLAIMS_ROLES=JWT claim name that carries the caller's roles; required, must differ from the principal and investigation claims · DATAPRISM_SECURITY_JWT_AUDIENCE=Expected JWT audience claim for this deployment; required for every protected deployment · DATAPRISM_SECURITY_JWT_ISSUER=OAuth2/OIDC issuer that mints the caller's JWT; required for every protected deployment · DATAPRISM_SECURITY_JWT_ISSUER_DISCOVERY_URI=Alternative HTTPS OIDC issuer-discovery location; set this instead of DATAPRISM_SECURITY_JWT_JWK_SET_URI, never both · DATAPRISM_SECURITY_JWT_JWK_SET_URI=HTTPS JWKS location used to verify caller JWTs; exactly one of this or DATAPRISM_SECURITY_JWT_ISSUER_DISCOVERY_URI is required, never both · DATAPRISM_SECURITY_POLICY_PURPOSES=Comma-separated list of permitted purposes; at least one is required · DATAPRISM_SOURCES_CUSTOMER_BASE_URL=Example only — declare DATAPRISM_SOURCES_<NAME>_BASE_URL (HTTPS) per configured source; at least one source, each with its own reviewed DataSourceAdapter bean, is required · DATAPRISM_SOURCES_CUSTOMER_TIMEOUT=Example only — declare DATAPRISM_SOURCES_<NAME>_TIMEOUT (positive duration) per configured source; required alongside its base URL · LOADER_PATH=Directory Spring Boot's PropertiesLauncher scans for extension jars; already set to /app/adapters by the image, but startup still fails with MISSING_SOURCE_ADAPTER until you bind-mount a reviewed DataSourceAdapter/IdentityResolver jar there (see the -v arguments above) |
| 2026-10-08 | Connection paths (source structure): {"packages":[{"registryType":"oci","identifier":"ghcr.io/aindriub/data-prism-server:0.4.0","runtimeHint":"docker","transport":"streamable-http","environment":[{"name":"LOADER_PATH","description":"Directory Spring Boot's PropertiesLauncher scans for extension jars; already set to /app/adapters by the image, but startup still fails with MISSING_SOURCE_ADAPTER until you bind-mount a reviewed DataSourceAdapter/IdentityResolver jar there (see the -v arguments above)","required":true,"secret":false},{"name":"DATAPRISM_SECURITY_JWT_ISSUER","description":"OAuth2/OIDC issuer that mints the caller's JWT; required for every protected deployment","required":true,"secret":false},{"name":"DATAPRISM_SECURITY_JWT_AUDIENCE","description":"Expected JWT audience claim for this deployment; required for every protected deployment","required":true,"secret":false},{"name":"DATAPRISM_SECURITY_JWT_JWK_SET_URI","description":"HTTPS JWKS location used to verify caller JWTs; exactly one of this or DATAPRISM_SECURITY_JWT_ISSUER_DISCOVERY_URI is required, never both","required":true,"secret":false},{"name":"DATAPRISM_SECURITY_JWT_ISSUER_DISCOVERY_URI","description":"Alternative HTTPS OIDC issuer-discovery location; set this instead of DATAPRISM_SECURITY_JWT_JWK_SET_URI, never both","required":false,"secret":false},{"name":"DATAPRISM_SECURITY_CALLER_CLAIMS_PRINCIPAL","description":"JWT claim name that carries the caller's principal identifier; required, must differ from the roles and investigation claims","required":true,"secret":false},{"name":"DATAPRISM_SECURITY_CALLER_CLAIMS_ROLES","description":"JWT claim name that carries the caller's roles; required, must differ from the principal and investigation claims","required":true,"secret":false},{"name":"DATAPRISM_SECURITY_CALLER_CLAIMS_INVESTIGATION","description":"JWT claim name that carries the trusted investigation/case identifier; required, must differ from the principal and roles claims","required":true,"secret":false},{"name":"DATAPRISM_SECURITY_POLICY_PURPOSES","description":"Comma-separated list of permitted purposes; at least one is required","required":true,"secret":false},{"name":"DATAPRISM_SECURITYPOLICY_ROLES_INVESTIGATOR","description":"Example only — declare DATAPRISM_SECURITYPOLICY_ROLES_<ROLE> per operator-defined role (no underscore between SECURITY and POLICY: Spring Boot's map-key enumeration under a hyphenated dataprism.security-policy.roles.<role> segment only binds the concatenated prefix, verified by binding this property directly against Spring Boot 3.5.16), a comma-separated list of known MCP tool capabilities; at least one role-to-capability mapping is required","required":true,"secret":false},{"name":"DATAPRISM_PRIVACY_PROFILE","description":"Name of the reviewed privacy profile implementation to apply; required","required":true,"secret":false},{"name":"DATAPRISM_PRIVACY_SCOPE_LIFETIME","description":"Positive duration (e.g. 8h) a privacy scope's synthetic identities remain valid; required","required":true,"secret":false},{"name":"DATAPRISM_PRIVACY_HMAC_KEY_KEY_ID","description":"Identifier of the pinned HMAC key used to derive synthetic identities; required","required":true,"secret":false},{"name":"DATAPRISM_PRIVACY_HMAC_KEY_ENVIRONMENT_VARIABLE","description":"Name of the environment variable holding the HMAC key material; exactly one of this or DATAPRISM_PRIVACY_HMAC_KEY_PROVIDER_REFERENCE is required, never both, and never a literal key value","required":true,"secret":false},{"name":"DATAPRISM_PRIVACY_HMAC_KEY_PROVIDER_REFERENCE","description":"Reference to an approved secret provider holding the HMAC key material; set this instead of DATAPRISM_PRIVACY_HMAC_KEY_ENVIRONMENT_VARIABLE, never both","required":false,"secret":false},{"name":"DATAPRISM_AUDIT_SINK","description":"Audit sink implementation: one of approved-sink, slf4j, hash-chained; required, never downgraded to no-op","required":true,"secret":false},{"name":"DATAPRISM_AUDIT_WRITER_ID","description":"Writer/instance identity recorded on every audit entry; required","required":true,"secret":false},{"name":"DATAPRISM_AUDIT_FILE_PATH","description":"Path to the durable, hash-chained audit log; required when DATAPRISM_AUDIT_SINK=hash-chained, refused as MISSING_AUDIT_FILE_PATH if absent for that sink, ignored otherwise","required":false,"secret":false},{"name":"DATAPRISM_METRICS_SINK","description":"Metrics sink binding, currently only micrometer; required in production, never the framework no-op","required":true,"secret":false},{"name":"DATAPRISM_HAZELCAST_TOPOLOGY","description":"Cluster read-budget topology: embedded (shared across the cluster) or single-node (enforced per process); required, never defaulted","required":true,"secret":false},{"name":"DATAPRISM_SOURCES_CUSTOMER_BASE_URL","description":"Example only — declare DATAPRISM_SOURCES_<NAME>_BASE_URL (HTTPS) per configured source; at least one source, each with its own reviewed DataSourceAdapter bean, is required","required":true,"secret":false},{"name":"DATAPRISM_SOURCES_CUSTOMER_TIMEOUT","description":"Example only — declare DATAPRISM_SOURCES_<NAME>_TIMEOUT (positive duration) per configured source; required alongside its base URL","required":true,"secret":false}],"additional_arguments_declared":true}],"remotes":[]} → {"packages":[{"registryType":"oci","identifier":"ghcr.io/aindriub/data-prism-server:0.4.1","runtimeHint":"docker","transport":"streamable-http","environment":[{"name":"LOADER_PATH","description":"Directory Spring Boot's PropertiesLauncher scans for extension jars; already set to /app/adapters by the image, but startup still fails with MISSING_SOURCE_ADAPTER until you bind-mount a reviewed DataSourceAdapter/IdentityResolver jar there (see the -v arguments above)","required":true,"secret":false},{"name":"DATAPRISM_SECURITY_JWT_ISSUER","description":"OAuth2/OIDC issuer that mints the caller's JWT; required for every protected deployment","required":true,"secret":false},{"name":"DATAPRISM_SECURITY_JWT_AUDIENCE","description":"Expected JWT audience claim for this deployment; required for every protected deployment","required":true,"secret":false},{"name":"DATAPRISM_SECURITY_JWT_JWK_SET_URI","description":"HTTPS JWKS location used to verify caller JWTs; exactly one of this or DATAPRISM_SECURITY_JWT_ISSUER_DISCOVERY_URI is required, never both","required":true,"secret":false},{"name":"DATAPRISM_SECURITY_JWT_ISSUER_DISCOVERY_URI","description":"Alternative HTTPS OIDC issuer-discovery location; set this instead of DATAPRISM_SECURITY_JWT_JWK_SET_URI, never both","required":false,"secret":false},{"name":"DATAPRISM_SECURITY_CALLER_CLAIMS_PRINCIPAL","description":"JWT claim name that carries the caller's principal identifier; required, must differ from the roles and investigation claims","required":true,"secret":false},{"name":"DATAPRISM_SECURITY_CALLER_CLAIMS_ROLES","description":"JWT claim name that carries the caller's roles; required, must differ from the principal and investigation claims","required":true,"secret":false},{"name":"DATAPRISM_SECURITY_CALLER_CLAIMS_INVESTIGATION","description":"JWT claim name that carries the trusted investigation/case identifier; required, must differ from the principal and roles claims","required":true,"secret":false},{"name":"DATAPRISM_SECURITY_POLICY_PURPOSES","description":"Comma-separated list of permitted purposes; at least one is required","required":true,"secret":false},{"name":"DATAPRISM_SECURITYPOLICY_ROLES_INVESTIGATOR","description":"Example only — declare DATAPRISM_SECURITYPOLICY_ROLES_<ROLE> per operator-defined role (no underscore between SECURITY and POLICY: Spring Boot's map-key enumeration under a hyphenated dataprism.security-policy.roles.<role> segment only binds the concatenated prefix, verified by binding this property directly against Spring Boot 3.5.16), a comma-separated list of known MCP tool capabilities; at least one role-to-capability mapping is required","required":true,"secret":false},{"name":"DATAPRISM_PRIVACY_PROFILE","description":"Name of the reviewed privacy profile implementation to apply; required","required":true,"secret":false},{"name":"DATAPRISM_PRIVACY_SCOPE_LIFETIME","description":"Positive duration (e.g. 8h) a privacy scope's synthetic identities remain valid; required","required":true,"secret":false},{"name":"DATAPRISM_PRIVACY_HMAC_KEY_KEY_ID","description":"Identifier of the pinned HMAC key used to derive synthetic identities; required","required":true,"secret":false},{"name":"DATAPRISM_PRIVACY_HMAC_KEY_ENVIRONMENT_VARIABLE","description":"Name of the environment variable holding the HMAC key material; exactly one of this or DATAPRISM_PRIVACY_HMAC_KEY_PROVIDER_REFERENCE is required, never both, and never a literal key value","required":true,"secret":false},{"name":"DATAPRISM_PRIVACY_HMAC_KEY_PROVIDER_REFERENCE","description":"Reference to an approved secret provider holding the HMAC key material; set this instead of DATAPRISM_PRIVACY_HMAC_KEY_ENVIRONMENT_VARIABLE, never both","required":false,"secret":false},{"name":"DATAPRISM_AUDIT_SINK","description":"Audit sink implementation: one of approved-sink, slf4j, hash-chained; required, never downgraded to no-op","required":true,"secret":false},{"name":"DATAPRISM_AUDIT_WRITER_ID","description":"Writer/instance identity recorded on every audit entry; required","required":true,"secret":false},{"name":"DATAPRISM_AUDIT_FILE_PATH","description":"Path to the durable, hash-chained audit log; required when DATAPRISM_AUDIT_SINK=hash-chained, refused as MISSING_AUDIT_FILE_PATH if absent for that sink, ignored otherwise","required":false,"secret":false},{"name":"DATAPRISM_METRICS_SINK","description":"Metrics sink binding, currently only micrometer; required in production, never the framework no-op","required":true,"secret":false},{"name":"DATAPRISM_HAZELCAST_TOPOLOGY","description":"Cluster read-budget topology: embedded (shared across members that have joined one cluster; set cluster name and join mode) or single-node (enforced per process); required, never defaulted","required":true,"secret":false},{"name":"DATAPRISM_HAZELCAST_CLUSTERNAME","description":"Hazelcast cluster name; required when DATAPRISM_HAZELCAST_TOPOLOGY=embedded, never dev, refused if set with single-node","required":false,"secret":false},{"name":"DATAPRISM_HAZELCAST_JOIN_MODE","description":"How cluster members find each other: tcp-ip, kubernetes or none; required when DATAPRISM_HAZELCAST_TOPOLOGY=embedded (none is an explicit single member bound to 127.0.0.1), refused if set with single-node","required":false,"secret":false},{"name":"DATAPRISM_HAZELCAST_JOIN_MEMBERS","description":"Comma-separated member addresses (host or host:port); required when DATAPRISM_HAZELCAST_JOIN_MODE=tcp-ip, otherwise unused","required":false,"secret":false},{"name":"DATAPRISM_HAZELCAST_MEMBER_PORT","description":"Hazelcast member port, default 5701, never auto-incremented; must differ from the server, management and operator ports. Member traffic is unencrypted, so keep it on a private network. Optional","required":false,"secret":false},{"name":"DATAPRISM_OPERATOR_ENABLED","description":"Enables the operator surface; optional, off by default","required":false,"secret":false},{"name":"DATAPRISM_OPERATOR_PORT","description":"Port of the operator listener; required when DATAPRISM_OPERATOR_ENABLED=true, must differ from the server, management (OPERATOR_PORT_SHARED otherwise) and member ports, and has no fixed default (publish it explicitly)","required":false,"secret":false},{"name":"DATAPRISM_OPERATOR_REQUIREDAUDIENCE","description":"JWT audience an operator token must carry; required when DATAPRISM_OPERATOR_ENABLED=true","required":false,"secret":false},{"name":"DATAPRISM_OPERATOR_REQUIREDSCOPE","description":"JWT scope an operator token must carry; required when DATAPRISM_OPERATOR_ENABLED=true","required":false,"secret":false},{"name":"DATAPRISM_SOURCES_CUSTOMER_BASE_URL","description":"Example only — declare DATAPRISM_SOURCES_<NAME>_BASE_URL (HTTPS) per configured source; at least one source, each with its own reviewed DataSourceAdapter bean, is required","required":true,"secret":false},{"name":"DATAPRISM_SOURCES_CUSTOMER_TIMEOUT","description":"Example only — declare DATAPRISM_SOURCES_<NAME>_TIMEOUT (positive duration) per configured source; required alongside its base URL","required":true,"secret":false}],"additional_arguments_declared":true}],"remotes":[]} |
| 2026-10-08 | Package identifiers (raw): ghcr.io/aindriub/data-prism-server:0.4.0 → ghcr.io/aindriub/data-prism-server:0.4.1 |
| 2026-10-08 | Environment variables (raw): LOADER_PATH, DATAPRISM_SECURITY_JWT_ISSUER, DATAPRISM_SECURITY_JWT_AUDIENCE, DATAPRISM_SECURITY_JWT_JWK_SET_URI, DATAPRISM_SECURITY_JWT_ISSUER_DISCOVERY_URI, DATAPRISM_SECURITY_CALLER_CLAIMS_PRINCIPAL, DATAPRISM_SECURITY_CALLER_CLAIMS_ROLES, DATAPRISM_SECURITY_CALLER_CLAIMS_INVESTIGATION, DATAPRISM_SECURITY_POLICY_PURPOSES, DATAPRISM_SECURITYPOLICY_ROLES_INVESTIGATOR, DATAPRISM_PRIVACY_PROFILE, DATAPRISM_PRIVACY_SCOPE_LIFETIME, DATAPRISM_PRIVACY_HMAC_KEY_KEY_ID, DATAPRISM_PRIVACY_HMAC_KEY_ENVIRONMENT_VARIABLE, DATAPRISM_PRIVACY_HMAC_KEY_PROVIDER_REFERENCE, DATAPRISM_AUDIT_SINK, DATAPRISM_AUDIT_WRITER_ID, DATAPRISM_AUDIT_FILE_PATH, DATAPRISM_METRICS_SINK, DATAPRISM_HAZELCAST_TOPOLOGY, DATAPRISM_SOURCES_CUSTOMER_BASE_URL, DATAPRISM_SOURCES_CUSTOMER_TIMEOUT → LOADER_PATH, DATAPRISM_SECURITY_JWT_ISSUER, DATAPRISM_SECURITY_JWT_AUDIENCE, DATAPRISM_SECURITY_JWT_JWK_SET_URI, DATAPRISM_SECURITY_JWT_ISSUER_DISCOVERY_URI, DATAPRISM_SECURITY_CALLER_CLAIMS_PRINCIPAL, DATAPRISM_SECURITY_CALLER_CLAIMS_ROLES, DATAPRISM_SECURITY_CALLER_CLAIMS_INVESTIGATION, DATAPRISM_SECURITY_POLICY_PURPOSES, DATAPRISM_SECURITYPOLICY_ROLES_INVESTIGATOR, DATAPRISM_PRIVACY_PROFILE, DATAPRISM_PRIVACY_SCOPE_LIFETIME, DATAPRISM_PRIVACY_HMAC_KEY_KEY_ID, DATAPRISM_PRIVACY_HMAC_KEY_ENVIRONMENT_VARIABLE, DATAPRISM_PRIVACY_HMAC_KEY_PROVIDER_REFERENCE, DATAPRISM_AUDIT_SINK, DATAPRISM_AUDIT_WRITER_ID, DATAPRISM_AUDIT_FILE_PATH, DATAPRISM_METRICS_SINK, DATAPRISM_HAZELCAST_TOPOLOGY, DATAPRISM_HAZELCAST_CLUSTERNAME, DATAPRISM_HAZELCAST_JOIN_MODE, DATAPRISM_HAZELCAST_JOIN_MEMBERS, DATAPRISM_HAZELCAST_MEMBER_PORT, DATAPRISM_OPERATOR_ENABLED, DATAPRISM_OPERATOR_PORT, DATAPRISM_OPERATOR_REQUIREDAUDIENCE, DATAPRISM_OPERATOR_REQUIREDSCOPE, DATAPRISM_SOURCES_CUSTOMER_BASE_URL, DATAPRISM_SOURCES_CUSTOMER_TIMEOUT |
| 2026-10-08 | Package coordinate: oci:ghcr.io/aindriub/data-prism-server:0.4.0 → oci:ghcr.io/aindriub/data-prism-server:0.4.1 |
| 2026-10-07 | Declared version: 0.3.1 → 0.4.0 |
| 2026-10-07 | Last changed in the registry (raw): 2026-09-24 → 2026-10-06 |
| 2026-10-07 | First listed in the registry (raw): 2026-09-24 → 2026-10-06 |
| 2026-10-07 | Connection paths (source structure): {"packages":[{"registryType":"oci","identifier":"ghcr.io/aindriub/data-prism-server:0.3.1","runtimeHint":"docker","transport":"streamable-http","environment":[{"name":"LOADER_PATH","description":"Directory Spring Boot's PropertiesLauncher scans for extension jars; already set to /app/adapters by the image, but startup still fails with MISSING_SOURCE_ADAPTER until you bind-mount a reviewed DataSourceAdapter/IdentityResolver jar there (see the -v arguments above)","required":true,"secret":false},{"name":"DATAPRISM_SECURITY_JWT_ISSUER","description":"OAuth2/OIDC issuer that mints the caller's JWT; required for every protected deployment","required":true,"secret":false},{"name":"DATAPRISM_SECURITY_JWT_AUDIENCE","description":"Expected JWT audience claim for this deployment; required for every protected deployment","required":true,"secret":false},{"name":"DATAPRISM_SECURITY_JWT_JWK_SET_URI","description":"HTTPS JWKS location used to verify caller JWTs; exactly one of this or DATAPRISM_SECURITY_JWT_ISSUER_DISCOVERY_URI is required, never both","required":true,"secret":false},{"name":"DATAPRISM_SECURITY_JWT_ISSUER_DISCOVERY_URI","description":"Alternative HTTPS OIDC issuer-discovery location; set this instead of DATAPRISM_SECURITY_JWT_JWK_SET_URI, never both","required":false,"secret":false},{"name":"DATAPRISM_SECURITY_CALLER_CLAIMS_PRINCIPAL","description":"JWT claim name that carries the caller's principal identifier; required, must differ from the roles and investigation claims","required":true,"secret":false},{"name":"DATAPRISM_SECURITY_CALLER_CLAIMS_ROLES","description":"JWT claim name that carries the caller's roles; required, must differ from the principal and investigation claims","required":true,"secret":false},{"name":"DATAPRISM_SECURITY_CALLER_CLAIMS_INVESTIGATION","description":"JWT claim name that carries the trusted investigation/case identifier; required, must differ from the principal and roles claims","required":true,"secret":false},{"name":"DATAPRISM_SECURITY_POLICY_PURPOSES","description":"Comma-separated list of permitted purposes; at least one is required","required":true,"secret":false},{"name":"DATAPRISM_SECURITYPOLICY_ROLES_INVESTIGATOR","description":"Example only — declare DATAPRISM_SECURITYPOLICY_ROLES_<ROLE> per operator-defined role (no underscore between SECURITY and POLICY: Spring Boot's map-key enumeration under a hyphenated dataprism.security-policy.roles.<role> segment only binds the concatenated prefix, verified by binding this property directly against Spring Boot 3.5.16), a comma-separated list of known MCP tool capabilities; at least one role-to-capability mapping is required","required":true,"secret":false},{"name":"DATAPRISM_PRIVACY_PROFILE","description":"Name of the reviewed privacy profile implementation to apply; required","required":true,"secret":false},{"name":"DATAPRISM_PRIVACY_SCOPE_LIFETIME","description":"Positive duration (e.g. 8h) a privacy scope's synthetic identities remain valid; required","required":true,"secret":false},{"name":"DATAPRISM_PRIVACY_HMAC_KEY_KEY_ID","description":"Identifier of the pinned HMAC key used to derive synthetic identities; required","required":true,"secret":false},{"name":"DATAPRISM_PRIVACY_HMAC_KEY_ENVIRONMENT_VARIABLE","description":"Name of the environment variable holding the HMAC key material; exactly one of this or DATAPRISM_PRIVACY_HMAC_KEY_PROVIDER_REFERENCE is required, never both, and never a literal key value","required":true,"secret":false},{"name":"DATAPRISM_PRIVACY_HMAC_KEY_PROVIDER_REFERENCE","description":"Reference to an approved secret provider holding the HMAC key material; set this instead of DATAPRISM_PRIVACY_HMAC_KEY_ENVIRONMENT_VARIABLE, never both","required":false,"secret":false},{"name":"DATAPRISM_AUDIT_SINK","description":"Audit sink implementation: one of approved-sink, slf4j, hash-chained; required, never downgraded to no-op","required":true,"secret":false},{"name":"DATAPRISM_AUDIT_WRITER_ID","description":"Writer/instance identity recorded on every audit entry; required","required":true,"secret":false},{"name":"DATAPRISM_AUDIT_FILE_PATH","description":"Path to the durable, hash-chained audit log; required when DATAPRISM_AUDIT_SINK=hash-chained, refused as MISSING_AUDIT_FILE_PATH if absent for that sink, ignored otherwise","required":false,"secret":false},{"name":"DATAPRISM_METRICS_SINK","description":"Metrics sink binding, currently only micrometer; required in production, never the framework no-op","required":true,"secret":false},{"name":"DATAPRISM_HAZELCAST_TOPOLOGY","description":"Cluster read-budget topology: embedded (shared across the cluster) or single-node (enforced per process); required, never defaulted","required":true,"secret":false},{"name":"DATAPRISM_SOURCES_CUSTOMER_BASE_URL","description":"Example only — declare DATAPRISM_SOURCES_<NAME>_BASE_URL (HTTPS) per configured source; at least one source, each with its own reviewed DataSourceAdapter bean, is required","required":true,"secret":false},{"name":"DATAPRISM_SOURCES_CUSTOMER_TIMEOUT","description":"Example only — declare DATAPRISM_SOURCES_<NAME>_TIMEOUT (positive duration) per configured source; required alongside its base URL","required":true,"secret":false}],"additional_arguments_declared":true}],"remotes":[]} → {"packages":[{"registryType":"oci","identifier":"ghcr.io/aindriub/data-prism-server:0.4.0","runtimeHint":"docker","transport":"streamable-http","environment":[{"name":"LOADER_PATH","description":"Directory Spring Boot's PropertiesLauncher scans for extension jars; already set to /app/adapters by the image, but startup still fails with MISSING_SOURCE_ADAPTER until you bind-mount a reviewed DataSourceAdapter/IdentityResolver jar there (see the -v arguments above)","required":true,"secret":false},{"name":"DATAPRISM_SECURITY_JWT_ISSUER","description":"OAuth2/OIDC issuer that mints the caller's JWT; required for every protected deployment","required":true,"secret":false},{"name":"DATAPRISM_SECURITY_JWT_AUDIENCE","description":"Expected JWT audience claim for this deployment; required for every protected deployment","required":true,"secret":false},{"name":"DATAPRISM_SECURITY_JWT_JWK_SET_URI","description":"HTTPS JWKS location used to verify caller JWTs; exactly one of this or DATAPRISM_SECURITY_JWT_ISSUER_DISCOVERY_URI is required, never both","required":true,"secret":false},{"name":"DATAPRISM_SECURITY_JWT_ISSUER_DISCOVERY_URI","description":"Alternative HTTPS OIDC issuer-discovery location; set this instead of DATAPRISM_SECURITY_JWT_JWK_SET_URI, never both","required":false,"secret":false},{"name":"DATAPRISM_SECURITY_CALLER_CLAIMS_PRINCIPAL","description":"JWT claim name that carries the caller's principal identifier; required, must differ from the roles and investigation claims","required":true,"secret":false},{"name":"DATAPRISM_SECURITY_CALLER_CLAIMS_ROLES","description":"JWT claim name that carries the caller's roles; required, must differ from the principal and investigation claims","required":true,"secret":false},{"name":"DATAPRISM_SECURITY_CALLER_CLAIMS_INVESTIGATION","description":"JWT claim name that carries the trusted investigation/case identifier; required, must differ from the principal and roles claims","required":true,"secret":false},{"name":"DATAPRISM_SECURITY_POLICY_PURPOSES","description":"Comma-separated list of permitted purposes; at least one is required","required":true,"secret":false},{"name":"DATAPRISM_SECURITYPOLICY_ROLES_INVESTIGATOR","description":"Example only — declare DATAPRISM_SECURITYPOLICY_ROLES_<ROLE> per operator-defined role (no underscore between SECURITY and POLICY: Spring Boot's map-key enumeration under a hyphenated dataprism.security-policy.roles.<role> segment only binds the concatenated prefix, verified by binding this property directly against Spring Boot 3.5.16), a comma-separated list of known MCP tool capabilities; at least one role-to-capability mapping is required","required":true,"secret":false},{"name":"DATAPRISM_PRIVACY_PROFILE","description":"Name of the reviewed privacy profile implementation to apply; required","required":true,"secret":false},{"name":"DATAPRISM_PRIVACY_SCOPE_LIFETIME","description":"Positive duration (e.g. 8h) a privacy scope's synthetic identities remain valid; required","required":true,"secret":false},{"name":"DATAPRISM_PRIVACY_HMAC_KEY_KEY_ID","description":"Identifier of the pinned HMAC key used to derive synthetic identities; required","required":true,"secret":false},{"name":"DATAPRISM_PRIVACY_HMAC_KEY_ENVIRONMENT_VARIABLE","description":"Name of the environment variable holding the HMAC key material; exactly one of this or DATAPRISM_PRIVACY_HMAC_KEY_PROVIDER_REFERENCE is required, never both, and never a literal key value","required":true,"secret":false},{"name":"DATAPRISM_PRIVACY_HMAC_KEY_PROVIDER_REFERENCE","description":"Reference to an approved secret provider holding the HMAC key material; set this instead of DATAPRISM_PRIVACY_HMAC_KEY_ENVIRONMENT_VARIABLE, never both","required":false,"secret":false},{"name":"DATAPRISM_AUDIT_SINK","description":"Audit sink implementation: one of approved-sink, slf4j, hash-chained; required, never downgraded to no-op","required":true,"secret":false},{"name":"DATAPRISM_AUDIT_WRITER_ID","description":"Writer/instance identity recorded on every audit entry; required","required":true,"secret":false},{"name":"DATAPRISM_AUDIT_FILE_PATH","description":"Path to the durable, hash-chained audit log; required when DATAPRISM_AUDIT_SINK=hash-chained, refused as MISSING_AUDIT_FILE_PATH if absent for that sink, ignored otherwise","required":false,"secret":false},{"name":"DATAPRISM_METRICS_SINK","description":"Metrics sink binding, currently only micrometer; required in production, never the framework no-op","required":true,"secret":false},{"name":"DATAPRISM_HAZELCAST_TOPOLOGY","description":"Cluster read-budget topology: embedded (shared across the cluster) or single-node (enforced per process); required, never defaulted","required":true,"secret":false},{"name":"DATAPRISM_SOURCES_CUSTOMER_BASE_URL","description":"Example only — declare DATAPRISM_SOURCES_<NAME>_BASE_URL (HTTPS) per configured source; at least one source, each with its own reviewed DataSourceAdapter bean, is required","required":true,"secret":false},{"name":"DATAPRISM_SOURCES_CUSTOMER_TIMEOUT","description":"Example only — declare DATAPRISM_SOURCES_<NAME>_TIMEOUT (positive duration) per configured source; required alongside its base URL","required":true,"secret":false}],"additional_arguments_declared":true}],"remotes":[]} |
| 2026-10-07 | Package identifiers (raw): ghcr.io/aindriub/data-prism-server:0.3.1 → ghcr.io/aindriub/data-prism-server:0.4.0 |
| 2026-10-07 | Package coordinate: oci:ghcr.io/aindriub/data-prism-server:0.3.1 → oci:ghcr.io/aindriub/data-prism-server:0.4.0 |
| 2026-09-25 | Declared version: 0.3.0 → 0.3.1 |
| 2026-09-25 | Description (raw): Privacy layer for enterprise APIs; refuses to start without a reviewed adapter jar per source → Fail-closed privacy layer that pseudonymises enterprise API data for LLM agents and MCP clients. |
| 2026-09-25 | Last changed in the registry (raw): 2026-09-23 → 2026-09-24 |
| 2026-09-25 | First listed in the registry (raw): 2026-09-23 → 2026-09-24 |
| 2026-09-25 | Connection paths (source structure): {"packages":[{"registryType":"oci","identifier":"ghcr.io/aindriub/data-prism-server:0.3.0","runtimeHint":"docker","transport":"streamable-http","environment":[{"name":"LOADER_PATH","description":"Directory Spring Boot's PropertiesLauncher scans for extension jars; already set to /app/adapters by the image, but startup still fails with MISSING_SOURCE_ADAPTER until you bind-mount a reviewed DataSourceAdapter/IdentityResolver jar there (see the -v arguments above)","required":true,"secret":false},{"name":"DATAPRISM_SECURITY_JWT_ISSUER","description":"OAuth2/OIDC issuer that mints the caller's JWT; required for every protected deployment","required":true,"secret":false},{"name":"DATAPRISM_SECURITY_JWT_AUDIENCE","description":"Expected JWT audience claim for this deployment; required for every protected deployment","required":true,"secret":false},{"name":"DATAPRISM_SECURITY_JWT_JWK_SET_URI","description":"HTTPS JWKS location used to verify caller JWTs; exactly one of this or DATAPRISM_SECURITY_JWT_ISSUER_DISCOVERY_URI is required, never both","required":true,"secret":false},{"name":"DATAPRISM_SECURITY_JWT_ISSUER_DISCOVERY_URI","description":"Alternative HTTPS OIDC issuer-discovery location; set this instead of DATAPRISM_SECURITY_JWT_JWK_SET_URI, never both","required":false,"secret":false},{"name":"DATAPRISM_SECURITY_CALLER_CLAIMS_PRINCIPAL","description":"JWT claim name that carries the caller's principal identifier; required, must differ from the roles and investigation claims","required":true,"secret":false},{"name":"DATAPRISM_SECURITY_CALLER_CLAIMS_ROLES","description":"JWT claim name that carries the caller's roles; required, must differ from the principal and investigation claims","required":true,"secret":false},{"name":"DATAPRISM_SECURITY_CALLER_CLAIMS_INVESTIGATION","description":"JWT claim name that carries the trusted investigation/case identifier; required, must differ from the principal and roles claims","required":true,"secret":false},{"name":"DATAPRISM_SECURITY_POLICY_PURPOSES","description":"Comma-separated list of permitted purposes; at least one is required","required":true,"secret":false},{"name":"DATAPRISM_SECURITYPOLICY_ROLES_INVESTIGATOR","description":"Example only — declare DATAPRISM_SECURITYPOLICY_ROLES_<ROLE> per operator-defined role (no underscore between SECURITY and POLICY: Spring Boot's map-key enumeration under a hyphenated dataprism.security-policy.roles.<role> segment only binds the concatenated prefix, verified by binding this property directly against Spring Boot 3.5.16), a comma-separated list of known MCP tool capabilities; at least one role-to-capability mapping is required","required":true,"secret":false},{"name":"DATAPRISM_PRIVACY_PROFILE","description":"Name of the reviewed privacy profile implementation to apply; required","required":true,"secret":false},{"name":"DATAPRISM_PRIVACY_SCOPE_LIFETIME","description":"Positive duration (e.g. 8h) a privacy scope's synthetic identities remain valid; required","required":true,"secret":false},{"name":"DATAPRISM_PRIVACY_HMAC_KEY_KEY_ID","description":"Identifier of the pinned HMAC key used to derive synthetic identities; required","required":true,"secret":false},{"name":"DATAPRISM_PRIVACY_HMAC_KEY_ENVIRONMENT_VARIABLE","description":"Name of the environment variable holding the HMAC key material; exactly one of this or DATAPRISM_PRIVACY_HMAC_KEY_PROVIDER_REFERENCE is required, never both, and never a literal key value","required":true,"secret":false},{"name":"DATAPRISM_PRIVACY_HMAC_KEY_PROVIDER_REFERENCE","description":"Reference to an approved secret provider holding the HMAC key material; set this instead of DATAPRISM_PRIVACY_HMAC_KEY_ENVIRONMENT_VARIABLE, never both","required":false,"secret":false},{"name":"DATAPRISM_AUDIT_SINK","description":"Audit sink implementation: one of approved-sink, slf4j, hash-chained; required, never downgraded to no-op","required":true,"secret":false},{"name":"DATAPRISM_AUDIT_WRITER_ID","description":"Writer/instance identity recorded on every audit entry; required","required":true,"secret":false},{"name":"DATAPRISM_AUDIT_FILE_PATH","description":"Path to the durable, hash-chained audit log; required when DATAPRISM_AUDIT_SINK=hash-chained, refused as MISSING_AUDIT_FILE_PATH if absent for that sink, ignored otherwise","required":false,"secret":false},{"name":"DATAPRISM_METRICS_SINK","description":"Metrics sink binding, currently only micrometer; required in production, never the framework no-op","required":true,"secret":false},{"name":"DATAPRISM_HAZELCAST_TOPOLOGY","description":"Cluster read-budget topology: embedded (shared across the cluster) or single-node (enforced per process); required, never defaulted","required":true,"secret":false},{"name":"DATAPRISM_SOURCES_CUSTOMER_BASE_URL","description":"Example only — declare DATAPRISM_SOURCES_<NAME>_BASE_URL (HTTPS) per configured source; at least one source, each with its own reviewed DataSourceAdapter bean, is required","required":true,"secret":false},{"name":"DATAPRISM_SOURCES_CUSTOMER_TIMEOUT","description":"Example only — declare DATAPRISM_SOURCES_<NAME>_TIMEOUT (positive duration) per configured source; required alongside its base URL","required":true,"secret":false}],"additional_arguments_declared":true}],"remotes":[]} → {"packages":[{"registryType":"oci","identifier":"ghcr.io/aindriub/data-prism-server:0.3.1","runtimeHint":"docker","transport":"streamable-http","environment":[{"name":"LOADER_PATH","description":"Directory Spring Boot's PropertiesLauncher scans for extension jars; already set to /app/adapters by the image, but startup still fails with MISSING_SOURCE_ADAPTER until you bind-mount a reviewed DataSourceAdapter/IdentityResolver jar there (see the -v arguments above)","required":true,"secret":false},{"name":"DATAPRISM_SECURITY_JWT_ISSUER","description":"OAuth2/OIDC issuer that mints the caller's JWT; required for every protected deployment","required":true,"secret":false},{"name":"DATAPRISM_SECURITY_JWT_AUDIENCE","description":"Expected JWT audience claim for this deployment; required for every protected deployment","required":true,"secret":false},{"name":"DATAPRISM_SECURITY_JWT_JWK_SET_URI","description":"HTTPS JWKS location used to verify caller JWTs; exactly one of this or DATAPRISM_SECURITY_JWT_ISSUER_DISCOVERY_URI is required, never both","required":true,"secret":false},{"name":"DATAPRISM_SECURITY_JWT_ISSUER_DISCOVERY_URI","description":"Alternative HTTPS OIDC issuer-discovery location; set this instead of DATAPRISM_SECURITY_JWT_JWK_SET_URI, never both","required":false,"secret":false},{"name":"DATAPRISM_SECURITY_CALLER_CLAIMS_PRINCIPAL","description":"JWT claim name that carries the caller's principal identifier; required, must differ from the roles and investigation claims","required":true,"secret":false},{"name":"DATAPRISM_SECURITY_CALLER_CLAIMS_ROLES","description":"JWT claim name that carries the caller's roles; required, must differ from the principal and investigation claims","required":true,"secret":false},{"name":"DATAPRISM_SECURITY_CALLER_CLAIMS_INVESTIGATION","description":"JWT claim name that carries the trusted investigation/case identifier; required, must differ from the principal and roles claims","required":true,"secret":false},{"name":"DATAPRISM_SECURITY_POLICY_PURPOSES","description":"Comma-separated list of permitted purposes; at least one is required","required":true,"secret":false},{"name":"DATAPRISM_SECURITYPOLICY_ROLES_INVESTIGATOR","description":"Example only — declare DATAPRISM_SECURITYPOLICY_ROLES_<ROLE> per operator-defined role (no underscore between SECURITY and POLICY: Spring Boot's map-key enumeration under a hyphenated dataprism.security-policy.roles.<role> segment only binds the concatenated prefix, verified by binding this property directly against Spring Boot 3.5.16), a comma-separated list of known MCP tool capabilities; at least one role-to-capability mapping is required","required":true,"secret":false},{"name":"DATAPRISM_PRIVACY_PROFILE","description":"Name of the reviewed privacy profile implementation to apply; required","required":true,"secret":false},{"name":"DATAPRISM_PRIVACY_SCOPE_LIFETIME","description":"Positive duration (e.g. 8h) a privacy scope's synthetic identities remain valid; required","required":true,"secret":false},{"name":"DATAPRISM_PRIVACY_HMAC_KEY_KEY_ID","description":"Identifier of the pinned HMAC key used to derive synthetic identities; required","required":true,"secret":false},{"name":"DATAPRISM_PRIVACY_HMAC_KEY_ENVIRONMENT_VARIABLE","description":"Name of the environment variable holding the HMAC key material; exactly one of this or DATAPRISM_PRIVACY_HMAC_KEY_PROVIDER_REFERENCE is required, never both, and never a literal key value","required":true,"secret":false},{"name":"DATAPRISM_PRIVACY_HMAC_KEY_PROVIDER_REFERENCE","description":"Reference to an approved secret provider holding the HMAC key material; set this instead of DATAPRISM_PRIVACY_HMAC_KEY_ENVIRONMENT_VARIABLE, never both","required":false,"secret":false},{"name":"DATAPRISM_AUDIT_SINK","description":"Audit sink implementation: one of approved-sink, slf4j, hash-chained; required, never downgraded to no-op","required":true,"secret":false},{"name":"DATAPRISM_AUDIT_WRITER_ID","description":"Writer/instance identity recorded on every audit entry; required","required":true,"secret":false},{"name":"DATAPRISM_AUDIT_FILE_PATH","description":"Path to the durable, hash-chained audit log; required when DATAPRISM_AUDIT_SINK=hash-chained, refused as MISSING_AUDIT_FILE_PATH if absent for that sink, ignored otherwise","required":false,"secret":false},{"name":"DATAPRISM_METRICS_SINK","description":"Metrics sink binding, currently only micrometer; required in production, never the framework no-op","required":true,"secret":false},{"name":"DATAPRISM_HAZELCAST_TOPOLOGY","description":"Cluster read-budget topology: embedded (shared across the cluster) or single-node (enforced per process); required, never defaulted","required":true,"secret":false},{"name":"DATAPRISM_SOURCES_CUSTOMER_BASE_URL","description":"Example only — declare DATAPRISM_SOURCES_<NAME>_BASE_URL (HTTPS) per configured source; at least one source, each with its own reviewed DataSourceAdapter bean, is required","required":true,"secret":false},{"name":"DATAPRISM_SOURCES_CUSTOMER_TIMEOUT","description":"Example only — declare DATAPRISM_SOURCES_<NAME>_TIMEOUT (positive duration) per configured source; required alongside its base URL","required":true,"secret":false}],"additional_arguments_declared":true}],"remotes":[]} |
| 2026-09-25 | Package identifiers (raw): ghcr.io/aindriub/data-prism-server:0.3.0 → ghcr.io/aindriub/data-prism-server:0.3.1 |
| 2026-09-25 | Package coordinate: oci:ghcr.io/aindriub/data-prism-server:0.3.0 → oci:ghcr.io/aindriub/data-prism-server:0.3.1 |
| 2026-09-25 | Homepage: https://github.com/AindriuB/data-prism → https://aindriub.github.io/data-prism/ |
| 2026-09-24 | Declared version: 0.2.0 → 0.3.0 |
| 2026-09-24 | Last changed in the registry (raw): 2026-09-17 → 2026-09-23 |
| 2026-09-24 | First listed in the registry (raw): 2026-09-17 → 2026-09-23 |
| 2026-09-24 | Environment variable descriptions (raw): DATAPRISM_AUDIT_SINK=Audit sink implementation: one of approved-sink, slf4j, hash-chained; required, never downgraded to no-op · DATAPRISM_AUDIT_WRITER_ID=Writer/instance identity recorded on every audit entry; required · DATAPRISM_HAZELCAST_TOPOLOGY=Cluster read-budget topology: embedded (shared across the cluster) or single-node (enforced per process); required, never defaulted · DATAPRISM_METRICS_SINK=Metrics sink binding, currently only micrometer; required in production, never the framework no-op · DATAPRISM_PRIVACY_HMAC_KEY_ENVIRONMENT_VARIABLE=Name of the environment variable holding the HMAC key material; exactly one of this or DATAPRISM_PRIVACY_HMAC_KEY_PROVIDER_REFERENCE is required, never both, and never a literal key value · DATAPRISM_PRIVACY_HMAC_KEY_KEY_ID=Identifier of the pinned HMAC key used to derive synthetic identities; required · DATAPRISM_PRIVACY_HMAC_KEY_PROVIDER_REFERENCE=Reference to an approved secret provider holding the HMAC key material; set this instead of DATAPRISM_PRIVACY_HMAC_KEY_ENVIRONMENT_VARIABLE, never both · DATAPRISM_PRIVACY_PROFILE=Name of the reviewed privacy profile implementation to apply; required · DATAPRISM_PRIVACY_SCOPE_LIFETIME=Positive duration (e.g. 8h) a privacy scope's synthetic identities remain valid; required · DATAPRISM_SECURITYPOLICY_ROLES_INVESTIGATOR=Example only — declare DATAPRISM_SECURITYPOLICY_ROLES_<ROLE> per operator-defined role (no underscore between SECURITY and POLICY: Spring Boot's map-key enumeration under a hyphenated dataprism.security-policy.roles.<role> segment only binds the concatenated prefix, verified by binding this property directly against Spring Boot 3.5.16), a comma-separated list of known MCP tool capabilities; at least one role-to-capability mapping is required · DATAPRISM_SECURITY_CALLER_CLAIMS_INVESTIGATION=JWT claim name that carries the trusted investigation/case identifier; required, must differ from the principal and roles claims · DATAPRISM_SECURITY_CALLER_CLAIMS_PRINCIPAL=JWT claim name that carries the caller's principal identifier; required, must differ from the roles and investigation claims · DATAPRISM_SECURITY_CALLER_CLAIMS_ROLES=JWT claim name that carries the caller's roles; required, must differ from the principal and investigation claims · DATAPRISM_SECURITY_JWT_AUDIENCE=Expected JWT audience claim for this deployment; required for every protected deployment · DATAPRISM_SECURITY_JWT_ISSUER=OAuth2/OIDC issuer that mints the caller's JWT; required for every protected deployment · DATAPRISM_SECURITY_JWT_ISSUER_DISCOVERY_URI=Alternative HTTPS OIDC issuer-discovery location; set this instead of DATAPRISM_SECURITY_JWT_JWK_SET_URI, never both · DATAPRISM_SECURITY_JWT_JWK_SET_URI=HTTPS JWKS location used to verify caller JWTs; exactly one of this or DATAPRISM_SECURITY_JWT_ISSUER_DISCOVERY_URI is required, never both · DATAPRISM_SECURITY_POLICY_PURPOSES=Comma-separated list of permitted purposes; at least one is required · DATAPRISM_SOURCES_CUSTOMER_BASE_URL=Example only — declare DATAPRISM_SOURCES_<NAME>_BASE_URL (HTTPS) per configured source; at least one source, each with its own reviewed DataSourceAdapter bean, is required · DATAPRISM_SOURCES_CUSTOMER_TIMEOUT=Example only — declare DATAPRISM_SOURCES_<NAME>_TIMEOUT (positive duration) per configured source; required alongside its base URL · LOADER_PATH=Directory Spring Boot's PropertiesLauncher scans for extension jars; already set to /app/adapters by the image, but startup still fails with MISSING_SOURCE_ADAPTER until you bind-mount a reviewed DataSourceAdapter/IdentityResolver jar there (see the -v arguments above) → DATAPRISM_AUDIT_FILE_PATH=Path to the durable, hash-chained audit log; required when DATAPRISM_AUDIT_SINK=hash-chained, refused as MISSING_AUDIT_FILE_PATH if absent for that sink, ignored otherwise · DATAPRISM_AUDIT_SINK=Audit sink implementation: one of approved-sink, slf4j, hash-chained; required, never downgraded to no-op · DATAPRISM_AUDIT_WRITER_ID=Writer/instance identity recorded on every audit entry; required · DATAPRISM_HAZELCAST_TOPOLOGY=Cluster read-budget topology: embedded (shared across the cluster) or single-node (enforced per process); required, never defaulted · DATAPRISM_METRICS_SINK=Metrics sink binding, currently only micrometer; required in production, never the framework no-op · DATAPRISM_PRIVACY_HMAC_KEY_ENVIRONMENT_VARIABLE=Name of the environment variable holding the HMAC key material; exactly one of this or DATAPRISM_PRIVACY_HMAC_KEY_PROVIDER_REFERENCE is required, never both, and never a literal key value · DATAPRISM_PRIVACY_HMAC_KEY_KEY_ID=Identifier of the pinned HMAC key used to derive synthetic identities; required · DATAPRISM_PRIVACY_HMAC_KEY_PROVIDER_REFERENCE=Reference to an approved secret provider holding the HMAC key material; set this instead of DATAPRISM_PRIVACY_HMAC_KEY_ENVIRONMENT_VARIABLE, never both · DATAPRISM_PRIVACY_PROFILE=Name of the reviewed privacy profile implementation to apply; required · DATAPRISM_PRIVACY_SCOPE_LIFETIME=Positive duration (e.g. 8h) a privacy scope's synthetic identities remain valid; required · DATAPRISM_SECURITYPOLICY_ROLES_INVESTIGATOR=Example only — declare DATAPRISM_SECURITYPOLICY_ROLES_<ROLE> per operator-defined role (no underscore between SECURITY and POLICY: Spring Boot's map-key enumeration under a hyphenated dataprism.security-policy.roles.<role> segment only binds the concatenated prefix, verified by binding this property directly against Spring Boot 3.5.16), a comma-separated list of known MCP tool capabilities; at least one role-to-capability mapping is required · DATAPRISM_SECURITY_CALLER_CLAIMS_INVESTIGATION=JWT claim name that carries the trusted investigation/case identifier; required, must differ from the principal and roles claims · DATAPRISM_SECURITY_CALLER_CLAIMS_PRINCIPAL=JWT claim name that carries the caller's principal identifier; required, must differ from the roles and investigation claims · DATAPRISM_SECURITY_CALLER_CLAIMS_ROLES=JWT claim name that carries the caller's roles; required, must differ from the principal and investigation claims · DATAPRISM_SECURITY_JWT_AUDIENCE=Expected JWT audience claim for this deployment; required for every protected deployment · DATAPRISM_SECURITY_JWT_ISSUER=OAuth2/OIDC issuer that mints the caller's JWT; required for every protected deployment · DATAPRISM_SECURITY_JWT_ISSUER_DISCOVERY_URI=Alternative HTTPS OIDC issuer-discovery location; set this instead of DATAPRISM_SECURITY_JWT_JWK_SET_URI, never both · DATAPRISM_SECURITY_JWT_JWK_SET_URI=HTTPS JWKS location used to verify caller JWTs; exactly one of this or DATAPRISM_SECURITY_JWT_ISSUER_DISCOVERY_URI is required, never both · DATAPRISM_SECURITY_POLICY_PURPOSES=Comma-separated list of permitted purposes; at least one is required · DATAPRISM_SOURCES_CUSTOMER_BASE_URL=Example only — declare DATAPRISM_SOURCES_<NAME>_BASE_URL (HTTPS) per configured source; at least one source, each with its own reviewed DataSourceAdapter bean, is required · DATAPRISM_SOURCES_CUSTOMER_TIMEOUT=Example only — declare DATAPRISM_SOURCES_<NAME>_TIMEOUT (positive duration) per configured source; required alongside its base URL · LOADER_PATH=Directory Spring Boot's PropertiesLauncher scans for extension jars; already set to /app/adapters by the image, but startup still fails with MISSING_SOURCE_ADAPTER until you bind-mount a reviewed DataSourceAdapter/IdentityResolver jar there (see the -v arguments above) |
| 2026-09-24 | Connection paths (source structure): {"packages":[{"registryType":"oci","identifier":"ghcr.io/aindriub/data-prism-server:0.2.0","runtimeHint":"docker","transport":"streamable-http","environment":[{"name":"LOADER_PATH","description":"Directory Spring Boot's PropertiesLauncher scans for extension jars; already set to /app/adapters by the image, but startup still fails with MISSING_SOURCE_ADAPTER until you bind-mount a reviewed DataSourceAdapter/IdentityResolver jar there (see the -v arguments above)","required":true,"secret":false},{"name":"DATAPRISM_SECURITY_JWT_ISSUER","description":"OAuth2/OIDC issuer that mints the caller's JWT; required for every protected deployment","required":true,"secret":false},{"name":"DATAPRISM_SECURITY_JWT_AUDIENCE","description":"Expected JWT audience claim for this deployment; required for every protected deployment","required":true,"secret":false},{"name":"DATAPRISM_SECURITY_JWT_JWK_SET_URI","description":"HTTPS JWKS location used to verify caller JWTs; exactly one of this or DATAPRISM_SECURITY_JWT_ISSUER_DISCOVERY_URI is required, never both","required":true,"secret":false},{"name":"DATAPRISM_SECURITY_JWT_ISSUER_DISCOVERY_URI","description":"Alternative HTTPS OIDC issuer-discovery location; set this instead of DATAPRISM_SECURITY_JWT_JWK_SET_URI, never both","required":false,"secret":false},{"name":"DATAPRISM_SECURITY_CALLER_CLAIMS_PRINCIPAL","description":"JWT claim name that carries the caller's principal identifier; required, must differ from the roles and investigation claims","required":true,"secret":false},{"name":"DATAPRISM_SECURITY_CALLER_CLAIMS_ROLES","description":"JWT claim name that carries the caller's roles; required, must differ from the principal and investigation claims","required":true,"secret":false},{"name":"DATAPRISM_SECURITY_CALLER_CLAIMS_INVESTIGATION","description":"JWT claim name that carries the trusted investigation/case identifier; required, must differ from the principal and roles claims","required":true,"secret":false},{"name":"DATAPRISM_SECURITY_POLICY_PURPOSES","description":"Comma-separated list of permitted purposes; at least one is required","required":true,"secret":false},{"name":"DATAPRISM_SECURITYPOLICY_ROLES_INVESTIGATOR","description":"Example only — declare DATAPRISM_SECURITYPOLICY_ROLES_<ROLE> per operator-defined role (no underscore between SECURITY and POLICY: Spring Boot's map-key enumeration under a hyphenated dataprism.security-policy.roles.<role> segment only binds the concatenated prefix, verified by binding this property directly against Spring Boot 3.5.16), a comma-separated list of known MCP tool capabilities; at least one role-to-capability mapping is required","required":true,"secret":false},{"name":"DATAPRISM_PRIVACY_PROFILE","description":"Name of the reviewed privacy profile implementation to apply; required","required":true,"secret":false},{"name":"DATAPRISM_PRIVACY_SCOPE_LIFETIME","description":"Positive duration (e.g. 8h) a privacy scope's synthetic identities remain valid; required","required":true,"secret":false},{"name":"DATAPRISM_PRIVACY_HMAC_KEY_KEY_ID","description":"Identifier of the pinned HMAC key used to derive synthetic identities; required","required":true,"secret":false},{"name":"DATAPRISM_PRIVACY_HMAC_KEY_ENVIRONMENT_VARIABLE","description":"Name of the environment variable holding the HMAC key material; exactly one of this or DATAPRISM_PRIVACY_HMAC_KEY_PROVIDER_REFERENCE is required, never both, and never a literal key value","required":true,"secret":false},{"name":"DATAPRISM_PRIVACY_HMAC_KEY_PROVIDER_REFERENCE","description":"Reference to an approved secret provider holding the HMAC key material; set this instead of DATAPRISM_PRIVACY_HMAC_KEY_ENVIRONMENT_VARIABLE, never both","required":false,"secret":false},{"name":"DATAPRISM_AUDIT_SINK","description":"Audit sink implementation: one of approved-sink, slf4j, hash-chained; required, never downgraded to no-op","required":true,"secret":false},{"name":"DATAPRISM_AUDIT_WRITER_ID","description":"Writer/instance identity recorded on every audit entry; required","required":true,"secret":false},{"name":"DATAPRISM_METRICS_SINK","description":"Metrics sink binding, currently only micrometer; required in production, never the framework no-op","required":true,"secret":false},{"name":"DATAPRISM_HAZELCAST_TOPOLOGY","description":"Cluster read-budget topology: embedded (shared across the cluster) or single-node (enforced per process); required, never defaulted","required":true,"secret":false},{"name":"DATAPRISM_SOURCES_CUSTOMER_BASE_URL","description":"Example only — declare DATAPRISM_SOURCES_<NAME>_BASE_URL (HTTPS) per configured source; at least one source, each with its own reviewed DataSourceAdapter bean, is required","required":true,"secret":false},{"name":"DATAPRISM_SOURCES_CUSTOMER_TIMEOUT","description":"Example only — declare DATAPRISM_SOURCES_<NAME>_TIMEOUT (positive duration) per configured source; required alongside its base URL","required":true,"secret":false}],"additional_arguments_declared":true}],"remotes":[]} → {"packages":[{"registryType":"oci","identifier":"ghcr.io/aindriub/data-prism-server:0.3.0","runtimeHint":"docker","transport":"streamable-http","environment":[{"name":"LOADER_PATH","description":"Directory Spring Boot's PropertiesLauncher scans for extension jars; already set to /app/adapters by the image, but startup still fails with MISSING_SOURCE_ADAPTER until you bind-mount a reviewed DataSourceAdapter/IdentityResolver jar there (see the -v arguments above)","required":true,"secret":false},{"name":"DATAPRISM_SECURITY_JWT_ISSUER","description":"OAuth2/OIDC issuer that mints the caller's JWT; required for every protected deployment","required":true,"secret":false},{"name":"DATAPRISM_SECURITY_JWT_AUDIENCE","description":"Expected JWT audience claim for this deployment; required for every protected deployment","required":true,"secret":false},{"name":"DATAPRISM_SECURITY_JWT_JWK_SET_URI","description":"HTTPS JWKS location used to verify caller JWTs; exactly one of this or DATAPRISM_SECURITY_JWT_ISSUER_DISCOVERY_URI is required, never both","required":true,"secret":false},{"name":"DATAPRISM_SECURITY_JWT_ISSUER_DISCOVERY_URI","description":"Alternative HTTPS OIDC issuer-discovery location; set this instead of DATAPRISM_SECURITY_JWT_JWK_SET_URI, never both","required":false,"secret":false},{"name":"DATAPRISM_SECURITY_CALLER_CLAIMS_PRINCIPAL","description":"JWT claim name that carries the caller's principal identifier; required, must differ from the roles and investigation claims","required":true,"secret":false},{"name":"DATAPRISM_SECURITY_CALLER_CLAIMS_ROLES","description":"JWT claim name that carries the caller's roles; required, must differ from the principal and investigation claims","required":true,"secret":false},{"name":"DATAPRISM_SECURITY_CALLER_CLAIMS_INVESTIGATION","description":"JWT claim name that carries the trusted investigation/case identifier; required, must differ from the principal and roles claims","required":true,"secret":false},{"name":"DATAPRISM_SECURITY_POLICY_PURPOSES","description":"Comma-separated list of permitted purposes; at least one is required","required":true,"secret":false},{"name":"DATAPRISM_SECURITYPOLICY_ROLES_INVESTIGATOR","description":"Example only — declare DATAPRISM_SECURITYPOLICY_ROLES_<ROLE> per operator-defined role (no underscore between SECURITY and POLICY: Spring Boot's map-key enumeration under a hyphenated dataprism.security-policy.roles.<role> segment only binds the concatenated prefix, verified by binding this property directly against Spring Boot 3.5.16), a comma-separated list of known MCP tool capabilities; at least one role-to-capability mapping is required","required":true,"secret":false},{"name":"DATAPRISM_PRIVACY_PROFILE","description":"Name of the reviewed privacy profile implementation to apply; required","required":true,"secret":false},{"name":"DATAPRISM_PRIVACY_SCOPE_LIFETIME","description":"Positive duration (e.g. 8h) a privacy scope's synthetic identities remain valid; required","required":true,"secret":false},{"name":"DATAPRISM_PRIVACY_HMAC_KEY_KEY_ID","description":"Identifier of the pinned HMAC key used to derive synthetic identities; required","required":true,"secret":false},{"name":"DATAPRISM_PRIVACY_HMAC_KEY_ENVIRONMENT_VARIABLE","description":"Name of the environment variable holding the HMAC key material; exactly one of this or DATAPRISM_PRIVACY_HMAC_KEY_PROVIDER_REFERENCE is required, never both, and never a literal key value","required":true,"secret":false},{"name":"DATAPRISM_PRIVACY_HMAC_KEY_PROVIDER_REFERENCE","description":"Reference to an approved secret provider holding the HMAC key material; set this instead of DATAPRISM_PRIVACY_HMAC_KEY_ENVIRONMENT_VARIABLE, never both","required":false,"secret":false},{"name":"DATAPRISM_AUDIT_SINK","description":"Audit sink implementation: one of approved-sink, slf4j, hash-chained; required, never downgraded to no-op","required":true,"secret":false},{"name":"DATAPRISM_AUDIT_WRITER_ID","description":"Writer/instance identity recorded on every audit entry; required","required":true,"secret":false},{"name":"DATAPRISM_AUDIT_FILE_PATH","description":"Path to the durable, hash-chained audit log; required when DATAPRISM_AUDIT_SINK=hash-chained, refused as MISSING_AUDIT_FILE_PATH if absent for that sink, ignored otherwise","required":false,"secret":false},{"name":"DATAPRISM_METRICS_SINK","description":"Metrics sink binding, currently only micrometer; required in production, never the framework no-op","required":true,"secret":false},{"name":"DATAPRISM_HAZELCAST_TOPOLOGY","description":"Cluster read-budget topology: embedded (shared across the cluster) or single-node (enforced per process); required, never defaulted","required":true,"secret":false},{"name":"DATAPRISM_SOURCES_CUSTOMER_BASE_URL","description":"Example only — declare DATAPRISM_SOURCES_<NAME>_BASE_URL (HTTPS) per configured source; at least one source, each with its own reviewed DataSourceAdapter bean, is required","required":true,"secret":false},{"name":"DATAPRISM_SOURCES_CUSTOMER_TIMEOUT","description":"Example only — declare DATAPRISM_SOURCES_<NAME>_TIMEOUT (positive duration) per configured source; required alongside its base URL","required":true,"secret":false}],"additional_arguments_declared":true}],"remotes":[]} |
| 2026-09-24 | Package identifiers (raw): ghcr.io/aindriub/data-prism-server:0.2.0 → ghcr.io/aindriub/data-prism-server:0.3.0 |
| 2026-09-24 | Environment variables (raw): LOADER_PATH, DATAPRISM_SECURITY_JWT_ISSUER, DATAPRISM_SECURITY_JWT_AUDIENCE, DATAPRISM_SECURITY_JWT_JWK_SET_URI, DATAPRISM_SECURITY_JWT_ISSUER_DISCOVERY_URI, DATAPRISM_SECURITY_CALLER_CLAIMS_PRINCIPAL, DATAPRISM_SECURITY_CALLER_CLAIMS_ROLES, DATAPRISM_SECURITY_CALLER_CLAIMS_INVESTIGATION, DATAPRISM_SECURITY_POLICY_PURPOSES, DATAPRISM_SECURITYPOLICY_ROLES_INVESTIGATOR, DATAPRISM_PRIVACY_PROFILE, DATAPRISM_PRIVACY_SCOPE_LIFETIME, DATAPRISM_PRIVACY_HMAC_KEY_KEY_ID, DATAPRISM_PRIVACY_HMAC_KEY_ENVIRONMENT_VARIABLE, DATAPRISM_PRIVACY_HMAC_KEY_PROVIDER_REFERENCE, DATAPRISM_AUDIT_SINK, DATAPRISM_AUDIT_WRITER_ID, DATAPRISM_METRICS_SINK, DATAPRISM_HAZELCAST_TOPOLOGY, DATAPRISM_SOURCES_CUSTOMER_BASE_URL, DATAPRISM_SOURCES_CUSTOMER_TIMEOUT → LOADER_PATH, DATAPRISM_SECURITY_JWT_ISSUER, DATAPRISM_SECURITY_JWT_AUDIENCE, DATAPRISM_SECURITY_JWT_JWK_SET_URI, DATAPRISM_SECURITY_JWT_ISSUER_DISCOVERY_URI, DATAPRISM_SECURITY_CALLER_CLAIMS_PRINCIPAL, DATAPRISM_SECURITY_CALLER_CLAIMS_ROLES, DATAPRISM_SECURITY_CALLER_CLAIMS_INVESTIGATION, DATAPRISM_SECURITY_POLICY_PURPOSES, DATAPRISM_SECURITYPOLICY_ROLES_INVESTIGATOR, DATAPRISM_PRIVACY_PROFILE, DATAPRISM_PRIVACY_SCOPE_LIFETIME, DATAPRISM_PRIVACY_HMAC_KEY_KEY_ID, DATAPRISM_PRIVACY_HMAC_KEY_ENVIRONMENT_VARIABLE, DATAPRISM_PRIVACY_HMAC_KEY_PROVIDER_REFERENCE, DATAPRISM_AUDIT_SINK, DATAPRISM_AUDIT_WRITER_ID, DATAPRISM_AUDIT_FILE_PATH, DATAPRISM_METRICS_SINK, DATAPRISM_HAZELCAST_TOPOLOGY, DATAPRISM_SOURCES_CUSTOMER_BASE_URL, DATAPRISM_SOURCES_CUSTOMER_TIMEOUT |
| 2026-09-24 | Package coordinate: oci:ghcr.io/aindriub/data-prism-server:0.2.0 → oci:ghcr.io/aindriub/data-prism-server:0.3.0 |
| 2026-09-18 | Declared version: – → 0.2.0 |
| 2026-09-18 | Repository URL listed: – → yes |
| 2026-09-18 | Path argument present: – → no |
| 2026-09-18 | Execution location: – → remote |
| 2026-09-18 | Required secrets declared: – → no |
| 2026-09-18 | Description (raw): – → Privacy layer for enterprise APIs; refuses to start without a reviewed adapter jar per source |
| 2026-09-18 | Last changed in the registry (raw): – → 2026-09-17 |
This view pages forward and states no total: individual rows are dropped only at output time when their evidence is missing. A counted total would be larger than what is shown.
tracevero · https://tracevero.com/mcp/io-github-aindriub-data-prism/aenderungen