Inspiration
What it doe## Inspiration
We wanted to answer a concrete question: can a real, agent-driven pipeline take generative and rendered media, land it in Backblaze B2 with verifiable provenance, and prove every step independently — not just trust a script's own "success" message.
What it does
Rootcheck is a real, working pipeline that produces media (via HyperFrames' headless Puppeteer rendering, and generative image/video via GMI Cloud/Replicate) and lands every asset in B2 through Genblaze, with a real SHA256 hash and canonical provenance manifest for each one. It also includes a soil-cross-section Gaussian-splat viewer pipeline (SPZ → SOG → B2), independently verifiable in a browser with no plugin required.
How we built it
Node/TypeScript handles the splat pipeline and Cloudflare Worker routing (rootcheck-router, a standalone VMFE). Python + Genblaze (genblaze-core, genblaze-gmicloud, genblaze-s3) handles generative-media orchestration and B2 upload via ObjectStorageSink. For non-generative media (a real HyperFrames-rendered MP4, or a screen-recorded live composition), we used Genblaze's ingest_assets() API — the correct, documented API for bringing already-produced bytes into a tracked, provenance-complete manifest, deliberately chosen over Pipeline.step(). A Replicate credential is proxied through a dedicated Cloudflare Worker (replicate-proxy) reading from Cloudflare Secrets Store, so the real API token never touches a client or a local .env.
Challenges we ran into
HyperFrames' automated duration-discovery correctly reported one of our real compositions as near-zero duration — it was scroll-driven, not timeline-authored, and we didn't force a misleading render. Instead we built a second, honest capture path: a real Playwright-scripted scroll-through, screen-recorded live and ingested through the same Genblaze/B2 pipeline. We also hit and fixed a real B2 authentication failure that traced back to a single mistyped character in a copied application key — resolved by testing directly against B2's native b2_authorize_account endpoint to isolate the fault from region/signing red herrings.
Accomplishments that we're proud of
Every claim in this submission is backed by an independent check, not just trusted output: real HTTP HEAD/GET requests confirming B2 assets are live, ffprobe confirming actual video codec/resolution/duration, and manifest reads confirming provenance data matches what was actually uploaded.
What we learned
That "the SDK said success" and "the artifact is actually correct" are two different claims, and treating them as the same thing is where real pipelines quietly go wrong. Verifying independently at every step caught two real bugs (a missing settings.json causing a silent render failure, and the credential typo above) that would otherwise have shipped broken.
What's next for Rootcheck
Wiring the upstream Pencil design-generation step (currently stub-mode server-side) so custom compositions can drive HyperFrames renders end-to-end, and completing the Replicate credential handoff to close the loop on the generative-image half of the pipeline.
Built With
- gcp.
- genblaze
Log in or sign up for Devpost to join the conversation.