@zanii/monitor
v0.2.0
Published
Independent Zanii log monitor: continuously verify the transparency log is append-only (consistency proofs) and that anchored checkpoints hold. Makes 'trust no one' operational.
Downloads
202
Readme
@zanii/monitor
An independent watchdog for a Zanii transparency log. "Trust no one, including Zanii" is only a claim until someone continuously checks it — this is that someone. It verifies each Signed Tree Head's signature, proves the log is append-only (a consistency proof from the last size it saw — rewriting past history fails this), and confirms every anchored checkpoint is still an append-only prefix of the current tree. Any violation is surfaced loudly.
Run it as a library or the zanii-monitor CLI. Node 18+.
npm install @zanii/monitorCLI
# watch continuously, persist state, POST alerts on violation
zanii-monitor --server https://ledger.zanii.agency --interval 60 \
--state ./monitor.state --alert https://your-app/alert
# one-shot for CI/cron — exits 1 on any violation
zanii-monitor --server https://ledger.zanii.agency --oncePersisting --state across runs is what makes an offline rewrite impossible to
hide: the next check proves the log is consistent with the size you last verified.
Library
import { checkOnce, monitor } from '@zanii/monitor';
const r = await checkOnce('https://ledger.zanii.agency', previousState);
if (!r.ok) console.error('VIOLATION:', r.violations);
// persist r.state and pass it back next time
await monitor('https://ledger.zanii.agency', {
intervalMs: 60_000,
onViolation: (r) => pageOncall(r.violations),
});What it checks
| Check | Proves | |---|---| | STH signature | the tree head really came from the log operator | | Consistency (last size → now) | the log is append-only — no past entry was altered, removed, or reordered | | Anchor validity + extension | the current tree is an append-only extension of every on-chain checkpoint |
MonitorResult = { ok, size, root, checks[], violations[], state }. Persist state.
Changelog
- 0.1.0 — initial release:
checkOnce,monitor, and thezanii-monitorCLI.
License
Apache-2.0.
