Skip to main content

vsp-otel — Python operational layer (vsp_otel)

Verifiable Span Provenance via OpenTelemetry. This is the operational OTel layer for the SZL mesh. It closes the honest gap left by the in-process TypeScript exporter: organs could Λ-sign spans in-process, but there was no real OTLP wire export and no cross-pod broker. vsp_otel ships:

  • a real OTLP/gRPC span exporter (opentelemetry-exporter-otlp-proto-grpc) wired to an OpenTelemetry Collector,
  • a DSSE-aware span processor that binds every span into the Khipu receipt chain (each span carries szl.mesh.receipt_hash; the receipt is DSSE-bound), with an optional szl.mesh.rekor_log_index transparency attribute,
  • a drop-in middleware (vsp_otel.middleware.install(app)) any organ imports,
  • a cross-pod collector config (deploy/otel-collector-config.yaml) that receives from N organs and exports to Jaeger + Tempo + a SZL custom Khipu exporter.

This README-python.md documents the Python layer. The repo's root README.md is a historical MOVED-redirect; the Python layer lives under src/vsp_otel/.

Quick start

pip install -e ".[test]"        # editable install + test extras
pytest -q                        # runs the suite incl. a real in-process OTLP/gRPC round-trip

In an organ's serve.py:

import vsp_otel.middleware
status = vsp_otel.middleware.install(app)   # FastAPI/ASGI app
print(status.as_dict())                      # honest report of what was wired

Point organs at the collector via the standard env var:

export OTEL_EXPORTER_OTLP_ENDPOINT=http://otel-collector:4317

Architecture

 organ(s) ──OTLP/gRPC──▶ OTel Collector ──▶ Jaeger (UI)
   │  DSSEKhipuSpanProcessor              ├▶ Tempo (store)
   │  (receipt_hash, DSSE envelope,       └▶ SZL Khipu exporter (DSSE receipts)
   │   Khipu hash-chain, rekor index)
   └─ BatchSpanProcessor → VSPSpanExporter (Welford fan-out variance)

See ARCH.md (in the squad workspace) for the full spec, including the DSSE v1 PAE contract and the formula tie-ins.

Formula tie-ins (honest)

  • Welford online variance — exporter.Welford tracks the variance of trace fan-out (spans per export batch) without retaining samples. Live and tested.
  • PAC-Bayes confidence bound on aggregated span coverage — roadmap: the bound is specified in ARCH.md; the runtime currently emits the inputs (coverage counts) but does not yet compute the closed-form bound.
  • Holevo bound on a quantum-resistant channel — roadmap/honest gap: documented as the capacity ceiling for a future PQ-encrypted OTLP channel; not implemented in code.

Honest gaps (read before claiming anything)

  1. Signer. The default DSSE signer is a deterministic HMAC test signer so the chain is testable offline. It is NOT a cosign/ECDSA signature. Production must inject a real signer via VSPConfig(signer=...) (the mesh's szl_dsse provides one). When no production key is present we keep an honest HMAC marker — we never claim a cosign signature we did not make.
  2. Rekor inclusion. szl.mesh.rekor_log_index is stamped only when a rekor_submit callable is configured. Absent that, the attribute is omitted — we never fabricate a transparency-log index.
  3. Custom Khipu collector exporter. The collector pipeline shape is real, but the szl/khipu custom exporter requires an ocb-built binary; until published, route to the debug exporter (the config ships commented + a working debug fallback).
  4. Docker integration test is opt-in. tests/test_integration.py does a real in-process OTLP/gRPC round-trip by default (no Docker). The real-collector-container path is gated behind VSP_OTEL_IT_DOCKER=1 and runs in CI (GitHub Actions has Docker).
  5. PAC-Bayes / Holevo are specified, not yet computed in code (see above).

Layout

src/vsp_otel/__init__.py         # public API, doctrine constants, attr keys
src/vsp_otel/exporter.py         # real OTLP/gRPC exporter + Welford fan-out
src/vsp_otel/dsse_processor.py   # DSSE v1 PAE + Khipu hash-chain SpanProcessor
src/vsp_otel/middleware.py       # install(app) drop-in + honest /vsp/provenance board
tests/test_exporter.py           # mock OTLP receiver asserts export correctness
tests/test_dsse_binding.py       # DSSE v1 PAE well-formedness + chain linking
tests/test_integration.py        # real OTLP/gRPC round-trip (+ opt-in container)
deploy/otel-collector-config.yaml# cross-pod broker config
Dockerfile                       # per-file COPY, minimal slim image
.github/workflows/python-ci.yml  # test matrix + container integration + image build

Doctrine v11 LOCKED — 749 / 14 / 163 · replay hash c7c0ba17 · Λ = Conjecture 1 (NEVER a theorem) · SLSA L1 honest + L2 attested · per-file Dockerfile COPY · DCO. HONESTY OVER CHECKLIST.

Signed-off-by: Yachay yachay@szlholdings.ai Co-Authored-By: Perplexity Computer Agent agent@perplexity.ai

Metadata

Release files for vsp-otel 0.1.2

For a detailed explanation of source distributions (sdists) and built distributions (wheels), please see the package formats documentation.

Source distribution (sdist)

Source distribution for vsp-otel 0.1.2
File Size Uploaded
vsp_otel-0.1.2.tar.gz 34.3 kB Details

Built distribution (wheel)

Table of built distributions (wheels) for vsp-otel 0.1.2
File Interpreter ABI Platform
vsp_otel-0.1.2-py3-none-any.whl Python 3 none any Details

Total release size: 57.7 kB

Release files / vsp_otel-0.1.2.tar.gz

Download URL vsp_otel-0.1.2.tar.gz
Size 34.3 kB
Tags Source
SHA-256 checksum
How to use checksums
88f3df63a9621c559204a22bb9723ffcc09c2324de5684301af91da457ac7d70
BLAKE2b-256 checksum
How to use checksums
3d3bcd51b59e02ba591ae04c5c81070893f0eee20941e8c6c67ccd487904a2e8
Upload date
Uploaded using Trusted Publishing?
What is trusted publishing?
Yes
Uploaded via twine/7.0.0 CPython/3.13.14

Provenance

Provenance describes where a file came from. On PyPI, provenance is shared via attestations, which provide a verifiable record of the build or publishing details. View details, limitations and caveats.

PyPI Publish Attestation

PyPI verified that this artifact, at this checksum, originated from the publisher listed below.

Signed by GitHub Actions, verified by PyPI on Oct 1, 2026.

Transparency log

Release files / vsp_otel-0.1.2-py3-none-any.whl

Download URL vsp_otel-0.1.2-py3-none-any.whl
Size 23.5 kB
Tags Python 3
SHA-256 checksum
How to use checksums
d8ea08922a83c6d05f37cc532f9627748816f54a3d072bdd745274622dbde59f
BLAKE2b-256 checksum
How to use checksums
9aca4fa8585a3961bde43b4e3bf1a2284b31b6c1dbd267caa77c1874d48b315c
Upload date
Uploaded using Trusted Publishing?
What is trusted publishing?
Yes
Uploaded via twine/7.0.0 CPython/3.13.14

Provenance

Provenance describes where a file came from. On PyPI, provenance is shared via attestations, which provide a verifiable record of the build or publishing details. View details, limitations and caveats.

PyPI Publish Attestation

PyPI verified that this artifact, at this checksum, originated from the publisher listed below.

Signed by GitHub Actions, verified by PyPI on Oct 1, 2026.

Transparency log

Release history Release notifications | RSS feed

This release

0.1.2 This release

2 release files

0.1.1

2 release files

0.1.0

2 release files

Anthropic, PBC Visionary sponsor Bloomberg Visionary sponsor Hudson River Trading Visionary sponsor Meta Visionary sponsor NVIDIA Visionary sponsor Microsoft Sustainability sponsor Depot Continuous Integration AWS Cloud computing and Security Sponsor Datadog Monitoring Fastly CDN Google Download Analytics Sentry Error logging StatusPage Status page