Repository navigation
Cairn Mod v1.0.0
Cairn v1.0.0 - Initial Release
Cairn is a minimal, self-hostable AT Protocol labeler with audit integrity,
moderator authentication via PDS-mediated service auth, and single-binary
deployment backed by SQLite.
Features
- AT Protocol labeler service:
createLabel,queryLabels,subscribeLabels - PDS-mediated moderator authentication via
com.atproto.server.getServiceAuth - Admin XRPC surface:
applyLabel,negateLabel,retract,listLabels,
listReports,resolveReport,applyLabelAndResolveReport,listAuditLog - Full audit log with single-transaction atomicity
- Non-enumerating 404s (privacy-preserving)
- Configurable label taxonomy via TOML
- Single-binary deployment with SQLite backend
- Deployment templates for Caddy, nginx, systemd (see
contrib/)
Security
- Byte-exact DRISL signing parity with
@atproto/crypto - SSRF-hardened HTTP fetch
- File permissions enforced on signing keys and session files (0600)
- Signing key delivered only via file, never via environment variable
- Single-instance lease enforcement (SQLite-backed)
Documentation
- Production Checklist for operators (
README.md) - Design documentation with threat model (
cairn-design.md) - Full OSS paperwork: LICENSE (MIT + Apache), CONTRIBUTING, SECURITY,
CODE_OF_CONDUCT, MAINTAINERS
Known Issues
auth::cache::tests::doc_cache_negative_has_shorter_ttlhas a tight
timing-based assertion that can flake under CI load (tracked as
chainlink #21). Not user-facing.
Thanks
This is the first release. Documentation, architecture, and implementation
by @skydeval.