Stratum is now BakeX
This package has been renamed. Install bakex instead.
pip install bakex
stratumoss is no longer developed. Everything that was Stratum lives on as BakeX, built by
the same people, in the open, under Apache-2.0.
What changed
| Was | Now |
|---|---|
pip install stratumoss |
pip install bakex |
import stratum |
import bakex |
STRATUM_* environment variables |
BAKEX_* |
stratum_version: in a blueprint |
bakex_version: |
github.com/StratumOSS/Stratum |
github.com/invicton/bakex |
Installing this package pulls in bakex for you, so nothing breaks — but import stratum
will raise with a pointer to the new name. Update your imports and depend on bakex
directly.
Why the rename
"Stratum" is a common word and collided with existing projects, including an unrelated
stratum package on PyPI. The tool is now BakeX: you bake a declarative blueprint into
a rigid, ready-to-deploy golden image. It is published under the Invicton org.
This happened pre-launch, at v0.6.0. The full rationale is in the changelog.
What BakeX does
Describe a hardened OS in one YAML blueprint; BakeX builds the CIS/STIG-benchmarked golden image on any cloud — or locally on KVM — and hands you the compliance evidence.
bakex validate blueprints/ubuntu/22.04/cis-l1-aws.yaml
bakex build blueprints/ubuntu/22.04/cis-l1-aws.yaml
Provision → harden with Ansible-Lockdown → scan with OpenSCAP → snapshot → tear down. You get a golden image, an A–F grade, and a SARIF report.
- Repository: https://github.com/invicton/bakex
- Blueprint library: https://github.com/invicton/bakex/tree/main/blueprints
- Blueprint JSON Schema: https://github.com/invicton/bakex/blob/main/docs/schema/hardening-blueprint.schema.json
- Changelog: https://github.com/invicton/bakex/blob/main/CHANGELOG.md
Contributions are welcome — the blueprint library is deliberately pure YAML, and there are good first issues open for new OS/provider combinations.
Download files
Download the file for your platform. If you're not sure which to choose, learn more about installing packages.
Source Distribution
Built Distribution
Filter files by name, interpreter, ABI, and platform.
If you're not sure about the file name format, learn more about wheel file names.
Copy a direct link to the current filters
File details
Details for the file stratumoss-0.6.0.tar.gz.
File metadata
- Download URL: stratumoss-0.6.0.tar.gz
- Upload date:
- Size: 3.3 kB
- Tags: Source
- Uploaded using Trusted Publishing? Yes
- Uploaded via:
twine/6.1.0 CPython/3.13.13
File hashes
| Algorithm | Hash digest | |
|---|---|---|
| SHA256 |
471054026fd1386fd906a32d3d0f7a6353007a8cb3f2dde75ee165cb42dd1f36
|
|
| MD5 |
f8d97283641042f6593495168dbbd17c
|
|
| BLAKE2b-256 |
e09c6c74cc6f217e89c01bc2d25e5edd5bbff76a3d041d73905c993c7eba5ef3
|
Provenance
The following attestation bundles were made for stratumoss-0.6.0.tar.gz:
Publisher:
release-stratumoss.yml on invicton/bakex
-
Statement:
-
Statement type:
https://in-toto.io/Statement/v1 -
Predicate type:
https://docs.pypi.org/attestations/publish/v1 -
Subject name:
stratumoss-0.6.0.tar.gz -
Subject digest:
471054026fd1386fd906a32d3d0f7a6353007a8cb3f2dde75ee165cb42dd1f36 - Sigstore transparency entry: 2256182864
- Sigstore integration time:
-
Permalink:
invicton/bakex@d5be96475ceb1a0f102dedb6bb468228a4411dfe -
Branch / Tag:
refs/heads/main - Owner: https://github.com/invicton
-
Access:
public
-
Token Issuer:
https://token.actions.githubusercontent.com -
Runner Environment:
github-hosted -
Publication workflow:
release-stratumoss.yml@d5be96475ceb1a0f102dedb6bb468228a4411dfe -
Trigger Event:
workflow_dispatch
-
Statement type:
File details
Details for the file stratumoss-0.6.0-py3-none-any.whl.
File metadata
- Download URL: stratumoss-0.6.0-py3-none-any.whl
- Upload date:
- Size: 2.9 kB
- Tags: Python 3
- Uploaded using Trusted Publishing? Yes
- Uploaded via:
twine/6.1.0 CPython/3.13.13
File hashes
| Algorithm | Hash digest | |
|---|---|---|
| SHA256 |
0d4aee5cbef3b5c92563f3cbf83ae2cf735e25fdef9da9d33f39df7dd48a19c9
|
|
| MD5 |
956daeede6745236742a41ce0b72fbf8
|
|
| BLAKE2b-256 |
de0974e12961bc0293a309f1f6b74e654ee3014c3418ac0e1cd3f66a112dcbf6
|
Provenance
The following attestation bundles were made for stratumoss-0.6.0-py3-none-any.whl:
Publisher:
release-stratumoss.yml on invicton/bakex
-
Statement:
-
Statement type:
https://in-toto.io/Statement/v1 -
Predicate type:
https://docs.pypi.org/attestations/publish/v1 -
Subject name:
stratumoss-0.6.0-py3-none-any.whl -
Subject digest:
0d4aee5cbef3b5c92563f3cbf83ae2cf735e25fdef9da9d33f39df7dd48a19c9 - Sigstore transparency entry: 2256182879
- Sigstore integration time:
-
Permalink:
invicton/bakex@d5be96475ceb1a0f102dedb6bb468228a4411dfe -
Branch / Tag:
refs/heads/main - Owner: https://github.com/invicton
-
Access:
public
-
Token Issuer:
https://token.actions.githubusercontent.com -
Runner Environment:
github-hosted -
Publication workflow:
release-stratumoss.yml@d5be96475ceb1a0f102dedb6bb468228a4411dfe -
Trigger Event:
workflow_dispatch
-
Statement type: