StellaOps Concelier — NOT PRODUCTION (service retired 2026-08-04)

The Concelier service no longer runs. The SPRINT_20260722_008 VULN-G1 cutover window (2026-08-04) stopped it, dropped the concelier and vuln schemas, and removed all of its gateway routes. Production advisory ingestion and serving is the vulnerability hub — ../vulnerabilities/architecture.md, serving /api/vulnerabilities/v1/*.

FROZEN 2026-09-11 (SPRINT_20260722_008 VULN-G6). The final compile-only WebService host and its host tests moved to src/__Obsoleted/Concelier/; no solution, build target, release component, compose service, or CI workflow can build it. Federation survives through the Vulnerabilities hub’s content-addressed corpus publication and the digest-verified, Signer-custodied OfflineKit carrier. Everything below is historical reference and must not be used as an operator procedure.

Source retirement (VULN-B1, 2026-09-11). All remaining source moved to src/__Obsoleted/Concelier/ after external compiled consumers were removed. Current mirror seeding and compact export consume the Vulnerabilities publication/API; current VEX wire serializers live in Vulnerabilities.Contracts. This dossier remains as historical design context, not a supported build or operator path.

How to read what follows: everything below describes the retired service as it was built. Connector catalogs, endpoint lists, job names and operator runbooks here are a record, not instructions — none of those endpoints answer today.

Concelier is the StellaOps advisory aggregation service. It fetches vulnerability advisories from a wide catalog of upstream sources and converts every signed advisory into immutable, provenance-tagged observations plus correlation linksets under the Aggregation-Only Contract (AOC) — without making any precedence, merge, or promotion decision. Downstream, the Policy Engine and Export Center consume that evidence.

Audience: operators wiring advisory connectors and offline mirrors, and integrators consuming Concelier exports or the advisory-chunk API.

Catalog at a glance (source of record is the code, not this README — see the references below):

The two counts above are reconciled against source. connectors.md still quotes 79; the code-of-record catalog now holds 74.

Operator references

Responsibilities

Key components

Recent updates

Integrations & dependencies

Operational notes

Backlog references

Epic alignment

Implementation Status

Delivery Phases:

Acceptance Criteria:

Key Risks & Mitigations:

Recent Milestones: