Install the contained exporter
- Resolve the current public
@xerg/cliversion from npm and pin that exact version in the QM core image for contained export. - Run
xerg connect qm --print-views-sqllocally and have QM’s Flyschema_adminapply the reviewed views and bounded-query indexes. Do not create or use Fly’s managed reader for Xerg. - Store a backed-up 32-byte
XERG_QM_IDENTITY_KEYin QM core’s Fly secrets. - Set
XERG_QM_TRUSTED_EXPORT=1in QM core to enable the one-shot exporter deliberately.
DATABASE_URL, identity key, Fly token, or Xerg credential by default. Even when the CLI is installed for offline snapshot audit, the skill forbids the sandbox from invoking live collection.
Provision a private Fly Sprite for offline Slack audit
QM’s current Fly Sprites backend resumes persistent Sprites and does not apply the configured sandbox OCI image to them. PinningFLY_BASE_IMAGE therefore does not make xerg available inside an existing private Sprite. This does not affect the core exporter.
If a QM Slack agent must audit an attached snapshot, an operator must explicitly approve and install the exact release into that administrator-owned private Sprite, then make its npm-global binary visible on the Sprite’s normal path:
Collect from the operator machine
fly authentication. Xerg spawns Fly without a local shell and invokes a hidden, version-matched exporter in QM core. Fly credentials remain on the operator’s machine. QM’s existing DATABASE_URL remains inside core and is accepted only by that hidden command.
The exporter validates its Fly environment, explicit opt-in, views, fingerprint, indexes, and identity continuity. It starts a read-only repeatable-read transaction, runs fixed bounded queries, HMACs identifiers before streaming, and exits. It has no listening service.
Every resulting manifest discloses: