Directories
¶
| Path | Synopsis |
|---|---|
|
Package afkevidence validates bounded, secret-safe direct-main evidence logs.
|
Package afkevidence validates bounded, secret-safe direct-main evidence logs. |
|
Package agentspecbackfill owns the pure immutable request, verification, and archive seam for Agent-spec backfill.
|
Package agentspecbackfill owns the pure immutable request, verification, and archive seam for Agent-spec backfill. |
|
Package agentspecbackfillcr owns the structural, canonical AgentSpecBackfill request and status wires.
|
Package agentspecbackfillcr owns the structural, canonical AgentSpecBackfill request and status wires. |
|
Package agentspecbackfillcrd renders and validates the structural AgentSpecBackfill Kubernetes CRD.
|
Package agentspecbackfillcrd renders and validates the structural AgentSpecBackfill Kubernetes CRD. |
|
Package agentspecbackfillexportprocess composes the separately-authorized terminal archive exporter.
|
Package agentspecbackfillexportprocess composes the separately-authorized terminal archive exporter. |
|
Package agentspecbackfillkube adapts the fixed AgentSpecBackfill Kubernetes resource to controller ports.
|
Package agentspecbackfillkube adapts the fixed AgentSpecBackfill Kubernetes resource to controller ports. |
|
Package agentspecbackfillprocess composes the AgentSpecBackfill controller from explicit, narrow ports.
|
Package agentspecbackfillprocess composes the AgentSpecBackfill controller from explicit, narrow ports. |
|
Package approval owns the pure, persistence-free human-approval state machine.
|
Package approval owns the pure, persistence-free human-approval state machine. |
|
Package clock provides explicit time sources for deterministic runtime decisions.
|
Package clock provides explicit time sources for deterministic runtime decisions. |
|
Package docsrefresh deterministically renders allow-listed public documentation.
|
Package docsrefresh deterministically renders allow-listed public documentation. |
|
Package egressproxy provides an exact-target forward proxy for trust-scoped workloads.
|
Package egressproxy provides an exact-target forward proxy for trust-scoped workloads. |
|
Package firecracker owns the Linux/KVM-only, internal Firecracker host profile.
|
Package firecracker owns the Linux/KVM-only, internal Firecracker host profile. |
|
Package firecrackerbootprobejournal owns the host-instance-exclusive durable launch-intent record required before an M4 Jailer may start.
|
Package firecrackerbootprobejournal owns the host-instance-exclusive durable launch-intent record required before an M4 Jailer may start. |
|
Package firecrackerbootprobelease owns the private persisted lease guard for one sealed Firecracker boot probe.
|
Package firecrackerbootprobelease owns the private persisted lease guard for one sealed Firecracker boot probe. |
|
Package firecrackerbootprobeprotocol owns the private signed M3-to-M4 boot-probe command and M4 observation wire.
|
Package firecrackerbootprobeprotocol owns the private signed M3-to-M4 boot-probe command and M4 observation wire. |
|
Package firecrackerbootprobev2 owns the private, persisted successor and acknowledgement contract for one sealed Firecracker boot-probe lease.
|
Package firecrackerbootprobev2 owns the private, persisted successor and acknowledgement contract for one sealed Firecracker boot-probe lease. |
|
Package firecrackerlaunchgrant owns the private, operator-only M3/M4 boot-probe binding.
|
Package firecrackerlaunchgrant owns the private, operator-only M3/M4 boot-probe binding. |
|
Package identity defines runtime-owned opaque identifiers.
|
Package identity defines runtime-owned opaque identifiers. |
|
Package milestone builds retained status evidence and notification attempts.
|
Package milestone builds retained status evidence and notification attempts. |
|
Package nowait checks owned Go code for nondeterministic real-time waiting.
|
Package nowait checks owned Go code for nondeterministic real-time waiting. |
|
Package openapicontract validates the repository-owned public Agent Runtime OpenAPI contract.
|
Package openapicontract validates the repository-owned public Agent Runtime OpenAPI contract. |
|
Package roles validates trust-scoped runtime process composition.
|
Package roles validates trust-scoped runtime process composition. |
|
runtime
|
|
|
kernel
Package kernel owns deterministic Agent, Session, Input, Turn, and Product-event transitions.
|
Package kernel owns deterministic Agent, Session, Input, Turn, and Product-event transitions. |
|
Package runtimeadmission owns the content-reference and durable SendInput admission seam.
|
Package runtimeadmission owns the content-reference and durable SendInput admission seam. |
|
Package runtimeapi exposes the public, Temporal-free HTTP boundary of Agent Runtime.
|
Package runtimeapi exposes the public, Temporal-free HTTP boundary of Agent Runtime. |
|
Package runtimeapiprocess composes the separately runnable public API role from explicit operator configuration.
|
Package runtimeapiprocess composes the separately runnable public API role from explicit operator configuration. |
|
Package runtimeconfig defines explicit, validated process configuration.
|
Package runtimeconfig defines explicit, validated process configuration. |
|
Package runtimecontent owns runtime-scoped immutable Agent specification and Input content.
|
Package runtimecontent owns runtime-scoped immutable Agent specification and Input content. |
|
Package runtimeerror adds safe context at runtime boundaries.
|
Package runtimeerror adds safe context at runtime boundaries. |
|
Package runtimemodel owns the narrow model-effect worker seam.
|
Package runtimemodel owns the narrow model-effect worker seam. |
|
Package runtimeoperations owns the protected operational-evidence drill.
|
Package runtimeoperations owns the protected operational-evidence drill. |
|
Package runtimeorchestration contains the private Temporal composition for state-backed Session work.
|
Package runtimeorchestration contains the private Temporal composition for state-backed Session work. |
|
Package runtimepostgres owns the PostgreSQL implementation of runtime-state persistence.
|
Package runtimepostgres owns the PostgreSQL implementation of runtime-state persistence. |
|
Package runtimestate defines the metadata-only S2/S7 runtime lifecycle authority.
|
Package runtimestate defines the metadata-only S2/S7 runtime lifecycle authority. |
|
Package runtimetool owns capability-bound external tool execution.
|
Package runtimetool owns capability-bound external tool execution. |
|
Package sandboxcontrolapi serves the private sandbox.control/v1 control process without exposing persistence, authentication, or transport types in the public sandbox SDK.
|
Package sandboxcontrolapi serves the private sandbox.control/v1 control process without exposing persistence, authentication, or transport types in the public sandbox SDK. |
|
Package sandboxcontrolprocess composes the separately runnable sandbox control role from one strict operator document and explicit secret sources.
|
Package sandboxcontrolprocess composes the separately runnable sandbox control role from one strict operator document and explicit secret sources. |
|
Package sandboxhostapi exposes the private mutually authenticated host control surface.
|
Package sandboxhostapi exposes the private mutually authenticated host control surface. |
|
Package sandboxhostjournal persists the reference host's receipt journal before any fake effect.
|
Package sandboxhostjournal persists the reference host's receipt journal before any fake effect. |
|
Package sandboxhostprocess composes the separately runnable reference host.
|
Package sandboxhostprocess composes the separately runnable reference host. |
|
Package sandboxhostprotocol owns the private, bounded host-control wire contract.
|
Package sandboxhostprotocol owns the private, bounded host-control wire contract. |
|
Package sandboxreaperprocess composes the independently deployable durable sandbox reconciliation owner.
|
Package sandboxreaperprocess composes the independently deployable durable sandbox reconciliation owner. |
|
Package stack defines the typed desired-state input for operator-owned infrastructure.
|
Package stack defines the typed desired-state input for operator-owned infrastructure. |
|
Package temporalpayloadruntime owns the sole runtime Temporal client and worker converter factory.
|
Package temporalpayloadruntime owns the sole runtime Temporal client and worker converter factory. |
|
Package temporalpayloaduiprocess composes the local Temporal UI payload-inspection handler from explicit policy.
|
Package temporalpayloaduiprocess composes the local Temporal UI payload-inspection handler from explicit policy. |
|
Package toolpolicy evaluates one already-normalized tool intent against one immutable operator-authored policy projection.
|
Package toolpolicy evaluates one already-normalized tool intent against one immutable operator-authored policy projection. |
Click to show internal directories.
Click to hide internal directories.