Exercise · Pico Identity

A short, guided task. Complete it before moving on to the lab.

See the Open Engineering Language Server (OELS) onboarding guide for the local install and editor setup.

TipOELS in your editor

While you work through this content, keep the Open Engineering Language Server (OELS) active in VS Code (or any LSP-capable editor). See the OELS onboarding guide linked at the top of this page (also linked from the academy Resources page) for the one-time install and configuration steps.

What OELS validates. OELS only recognizes OE-shaped YAML/JSON: files with a mapping root that declare an apiVersion beginning with open-engineering.io/, a non-empty kind, and a DNS-1123 metadata.name. Ordinary academy metadata.yaml, Quarto/QMD pages and front matter, Kubernetes/Crossplane/runtime manifests, JSON payload samples, and shell scripts are intentionally non-OE — OELS ignores them silently and you should not add synthetic apiVersion/kind headers to force recognition.

Where you see diagnostics. OELS surfaces UnknownProperty, MissingRequiredProperty, IncorrectType, InvalidEnumValue, MalformedIdentifier, UnknownDefinition, and reference-shape hints in the editor Problems panel as you type. These are independent of quarto render: OELS diagnostics do not block rendering, and Quarto errors do not appear in the Problems panel.

The executable check still comes from this exercise. OELS speeds up editing, but the exercise’s own parser, verifier, or verify.sh (for example the pico parse … command shown below) remains the authoritative success check. Run it as usual.

Task

For a Pico you care about, write the YAML identity declaration that separates its public identity from its relationship identities.

Start with the public identity:

# identity-public.yaml
identity:
  type: did
  public:
    method: webvh
    url: https://engine.example.com/picos/alice/did.json

Then add two placeholder relationships:

# identity-relationships.yaml
relationships:
  - did:peer:rel-alice-bob
  - did:peer:rel-alice-carol

Answer the questions below for your chosen Pico.

Note

There is no single correct answer. The goal is to internalize the two-DID model from the lesson: a stable public identity for introduction plus isolated per-relationship identities.

Success criteria

Automatable check

Save both snippets under a scratch working directory and confirm they parse:

mkdir -p scratch-part3-01
cat > scratch-part3-01/identity.yaml <<'EOF'
identity:
  type: did
  public:
    method: webvh
    url: https://engine.example.com/picos/alice/did.json
relationships:
  - did:peer:rel-alice-bob
  - did:peer:rel-alice-carol
EOF
pico parse scratch-part3-01/identity.yaml --out /tmp/identity.json \
  && echo "OK: identity declaration parses"

The command exits with status 0 and prints an OK: line when the declaration is well-formed.

Reflect

  • Which of your relationships would you most want to isolate if it were compromised, and why?
  • How would your declaration change if you added a third relationship?

Next

Continue with the Lab.