csf

module
v0.1.3 Latest Latest
Warning

This package is not in the latest version of its module.

Go to latest
Published: Oct 1, 2026 License: Apache-2.0

README

One Go runtime for agent work, typed tools, shared knowledge and observable experiments.

Developer preview. The first release makes no stability or compatibility promise.

Why CSF · Proofs · Architecture · Quick start · CSF guide · Agent instructions · Citation


1. Introduction

CSF — The Cerebrospinal Fluid is a Go library and runtime for the coordination around an agent system: typed tools, sessions and worktrees, schedules, knowledge ingestion and search, traces and retained evidence. Its services are libraries mounted into one Go process through functional options, and its operations are generated once and served as HTTP, CLI and MCP.

The name comes from the architecture that shaped it. In LITHE (Lim and Clites, 2026), a best-effort Brain proposes and a real-time Spine executes, on one partitioned computer. CSF is the fluid around them: the housekeeping layer that carries tools, records and experiments between decisions.

LITHE, Figure 2 (Lim and Clites, 2026).

This repository is one Go module with a root Bazel build and the separate csfc compiler build: the public half of a private infrastructure monorepo, published whole. It is not a framework and not a grab bag. It is a working agent-operated deployment system and the pieces it is built from, released together so that the pieces are usable on their own and the system is reproducible as a whole.

CSF — The Cerebrospinal Fluid Shared Go coordination for agents, typed tools, knowledge and simulation evidence. Start with the consumer example.
CandaceOS An agent-operated app lab: a harness proposes, Core approves and fences, a node executor reconciles Compose applications, and an operator UI watches. Its deployment kit is candaceos/.
Warden A fleet watchdog: Raft-style leader election over a static peer set, liveness, incidents, and an authoritative view every mutation is fenced against.
gotth-live Server-driven live user interfaces from Go. State and rendering stay in your process; one WebSocket per tab carries events up and re-rendered fragments down. No npm, no CDN.
xetcas A self-hosted Xet content-addressable storage server with a Git LFS front door. Re-pushing a 48 MiB model after editing 2% of it costs about 1 MiB.
pkg/ The primitives the rest is built on: pgmem (a process-local PostgreSQL emulator for tests), liquidproto (protobuf refinement types), cron, config, redact, telemetry, and more.

Status: CSF's first release, 0.1.0, is a developer preview and a breaking integration baseline. It makes no stability or compatibility promise: pin a reviewed snapshot and use the examples shipped with it. The Go import is github.com/candacelabs/csf/csf; this release makes no backward-compatibility claim for earlier experimental CSF interfaces.

First-party source is Apache-2.0. Dependencies, vendor simulator images and paper figures retain their own licenses.

2. Why CSF: no IPC inside CPU 0

LITHE runs a whole robot control hierarchy on one quad-core single-board computer by partitioning its cores (LITHE §III-B):

LITHE core Role in LITHE
CPU 0 (Housekeeping) Linux housekeeping, SSH sessions and non-critical interrupts. It absorbs system jitter, and LITHE's loader thread prepares new controllers here (LITHE §III-E1).
CPU 1 (Spine) The C++ control loop, alone on an isolated core.
CPU 2 (Brain) The high-level Python runtime.
CPU 3 (Transport) Blocking SPI/CAN bus I/O, kept off the control core.

LITHE treats inter-process communication as architecture (LITHE §III-C): the Brain and Spine exchange state through lock-free, zero-copy POSIX shared memory whose layout a build-time generator owns. Its abstract names complex middleware as one cost of the conventional alternatives.

The coordination an agent system needs — tools, sessions, schedules, knowledge and observation — lands on the housekeeping side of that partition. Built the usual way, each capability is its own daemon, and every handoff inside CPU 0 becomes a socket, a serialization format and another process lifecycle to supervise.

CSF prevents that IPC problem inside CPU 0 by composing those capabilities in one Go process. Services are Go libraries selected with functional options. They exchange typed values through function calls and coordinate concurrent work with goroutines and channels; contexts and explicit ownership give each operation a cancellation and cleanup path. An internal handoff needs no socket, no wire serialization and no separate service daemon. Separate architecture checks inspect selected Go ownership and process boundaries in source; they establish those source constraints, not runtime timing.

The diagram is our architectural mapping onto LITHE [1], drawn by hand; it is not generated from the architecture model. Its boundaries are exact:

  • PostgreSQL, OpenSearch, Langfuse and external model or simulator processes keep their protocol boundaries. CSF removes IPC between its own capabilities, not IPC with systems that genuinely live elsewhere.
  • LITHE's Brain–Spine shared-memory IPC remains a separate integration boundary.
  • CPU affinity and isolation are deployment configuration. CSF does not implement LITHE's loader, CPU isolation or real-time controller hot swap.

examples/csf-consumer shows the composition: CSF, its generated routes, its MCP server and the consumer's own endpoint in one router owned by the consumer's process.

3. Proofs, not just hardware: CSF and LITHE's safety problem

LITHE is explicit about where its guarantee stops. Its user-space real-time approach "provides a functional margin of safety, even if it lacks the formal mathematical guarantees of a verified real-time operating system" (LITHE §V-A). For model-written controllers, "it remains an area of active research to implement appropriate safety and verification bounds on the model's output" (LITHE §V-B); "theoretical stability guarantees remain an open challenge", so safety "must be enforced via strict hardware-level limits on torque and velocity" (LITHE §V-C).

A hardware limit is enforced per device. A proof about a language holds for every program written in it. CSF's direction is to narrow what a model may author to a typed, bounded language, and to prove what that language's compiled code computes. The model then chooses among checked options instead of emitting arbitrary code. That is how we think LITHE's idea scales past one robot on one bench.

What is proved today. csf/examples/proof/BrainSpine.lean models the arithmetic slice of brainspine.proto: a typed expression language with constants, four observation slots, addition, integer scaling and clamping over saturating integers, compiled to a postfix stack machine. Lean machine-checks four theorems:

Theorem Guarantee
compile_correct For every expression, inputs and existing stack, the compiled instructions push exactly the evaluated value and preserve the stack.
evaluate_bounds Every expression evaluates within the saturation bound [-1000000000, 1000000000].
compiled_actuator_correct Compiled code run from an empty stack, then through the actuator clamp, agrees exactly with the clamped source evaluator.
compiled_actuator_bounds Every compiled expression produces an actuator value in [-1000, 1000].

bash csf/examples/proof/check.sh downloads the pinned Lean release, verifies its SHA-256, runs Lean with --trust=0, and audits the axioms of all four theorems: only Lean's standard propext, Classical.choice and Quot.sound are admitted, and sorryAx or custom axioms fail the check. CI runs it in its own job.

What is not proved. Be precise about the gap:

  • Agreement between the Lean model and the canonical wire semantics is a reviewed translation boundary. The Go and Rust evaluators have conformance tests, not equivalence proofs.
  • The csfc compiler verifier is a stub: CSFC.Verification.verify returns notImplemented for every input and issues no certificate.
  • The actuator clamp proves a numeric range only. Timing, stability, collision avoidance, safe controller switching and physical safety are outside every theorem here. A hardware watchdog remains necessary.
  • The Lean kernel, its official release build, the standard library, the operating system and the hardware remain trusted.

The improvement loop below is generated from the same architecture model as every CSF diagram. Choose is still planned: today the bounded controller search selects between episodes, and an agent choosing among proved options is the next step, not a shipped one.

%% Generated from csf/compiler/language/architecture.csf; do not edit.
%% Documentation model only; status labels do not establish runtime verification.
flowchart LR
  classDef csf_existing fill:#0F766E,stroke:#115E59,stroke-width:2px,color:#FFFFFF;
  classDef csf_planned fill:#FEF3C7,stroke:#B45309,stroke-width:2px,color:#78350F;
  n_observe["Observe (existing)"]:::csf_existing
  n_retrieve["Retrieve (existing)"]:::csf_existing
  n_choose["Choose (planned)"]:::csf_planned
  n_check["Check (existing)"]:::csf_existing
  n_execute["Execute (existing)"]:::csf_existing
  n_evaluate["Evaluate (existing)"]:::csf_existing
  n_save_evidence["Save evidence (existing)"]:::csf_existing
  n_improve["Improve (planned)"]:::csf_planned
  n_select_controller["Select a controller between episodes (existing)"]:::csf_existing
  n_observe -.-> n_retrieve
  n_retrieve -.-> n_choose
  n_choose -.-> n_check
  n_check --> n_execute
  n_execute --> n_evaluate
  n_evaluate --> n_save_evidence
  n_evaluate --> n_select_controller
  n_select_controller -.->|"next agent iteration"| n_choose
  n_save_evidence -.-> n_improve
  n_improve -.->|"next iteration"| n_observe
  linkStyle 0 stroke:#B45309,stroke-width:2px,stroke-dasharray:5 5
  linkStyle 1 stroke:#B45309,stroke-width:2px,stroke-dasharray:5 5
  linkStyle 2 stroke:#B45309,stroke-width:2px,stroke-dasharray:5 5
  linkStyle 3 stroke:#0F766E,stroke-width:2px
  linkStyle 4 stroke:#0F766E,stroke-width:2px
  linkStyle 5 stroke:#0F766E,stroke-width:2px
  linkStyle 6 stroke:#0F766E,stroke-width:2px
  linkStyle 7 stroke:#B45309,stroke-width:2px,stroke-dasharray:5 5
  linkStyle 8 stroke:#B45309,stroke-width:2px,stroke-dasharray:5 5
  linkStyle 9 stroke:#B45309,stroke-width:2px,stroke-dasharray:5 5

4. Architecture

The diagram is generated from csf/compiler/language/architecture.csf by the CSF documentation compiler, which also produces the shared vocabulary. Solid connections are existing components or configurable integrations; dotted connections are planned. An integration shown here still needs its dependencies and configuration; it is not automatically running when you import CSF.

%% Generated from csf/compiler/language/architecture.csf; do not edit.
%% Documentation model only; status labels do not establish runtime verification.
flowchart TB
  classDef csf_existing fill:#0F766E,stroke:#115E59,stroke-width:2px,color:#FFFFFF;
  classDef csf_planned fill:#FEF3C7,stroke:#B45309,stroke-width:2px,color:#78350F;
  n_human["Human or agent client (existing)"]:::csf_existing
  n_brain["Models and agents (existing)"]:::csf_existing
  n_contracts["Shared typed contracts (existing)"]:::csf_existing
  n_stores["PostgreSQL and artifact storage (existing)"]:::csf_existing
  n_jobs["Simulator and AWS Batch adapters (existing)"]:::csf_existing
  n_views["Prometheus#44; Grafana and Langfuse (existing)"]:::csf_existing
  n_experiments["Training results and optional MLflow (existing)"]:::csf_existing
  n_vendor["Consumer Copilot backend (existing)"]:::csf_existing
  n_spine["Consumer C#43;#43; control loop (planned)"]:::csf_planned
  n_hardware["Consumer sensors and actuators (planned)"]:::csf_planned
  subgraph g_host["CSF#58; one Go application process"]
    n_bench["Workbench (existing)"]:::csf_existing
    n_api["Generated HTTP#44; CLI and MCP operations (existing)"]:::csf_existing
    n_knowledge["Knowledge and retrieval (existing)"]:::csf_existing
    n_compiler["Bounded controller compiler (existing)"]:::csf_existing
    n_workers["Configured worker goroutines (existing)"]:::csf_existing
    n_inspect["Inspection (existing)"]:::csf_existing
    n_widgets["Widget SDK and gotth#45;live (existing)"]:::csf_existing
  end
  style g_host fill:#EEF2FF,stroke:#4338CA,stroke-width:2px,color:#1E1B4B
  n_human --> n_bench
  n_brain --> n_api
  n_contracts --> n_api
  n_bench --> n_api
  n_bench --> n_vendor
  n_api --> n_knowledge
  n_api --> n_compiler
  n_api --> n_workers
  n_api --> n_inspect
  n_knowledge --> n_stores
  n_workers --> n_jobs
  n_jobs --> n_stores
  n_inspect --> n_views
  n_brain --> n_experiments
  n_widgets -->|"keyed Kanban cards"| n_bench
  n_compiler -.->|"planned external adapter"| n_spine
  n_spine -.-> n_hardware
  linkStyle 0 stroke:#0F766E,stroke-width:2px
  linkStyle 1 stroke:#0F766E,stroke-width:2px
  linkStyle 2 stroke:#0F766E,stroke-width:2px
  linkStyle 3 stroke:#0F766E,stroke-width:2px
  linkStyle 4 stroke:#0F766E,stroke-width:2px
  linkStyle 5 stroke:#0F766E,stroke-width:2px
  linkStyle 6 stroke:#0F766E,stroke-width:2px
  linkStyle 7 stroke:#0F766E,stroke-width:2px
  linkStyle 8 stroke:#0F766E,stroke-width:2px
  linkStyle 9 stroke:#0F766E,stroke-width:2px
  linkStyle 10 stroke:#0F766E,stroke-width:2px
  linkStyle 11 stroke:#0F766E,stroke-width:2px
  linkStyle 12 stroke:#0F766E,stroke-width:2px
  linkStyle 13 stroke:#0F766E,stroke-width:2px
  linkStyle 14 stroke:#0F766E,stroke-width:2px
  linkStyle 15 stroke:#B45309,stroke-width:2px,stroke-dasharray:5 5
  linkStyle 16 stroke:#B45309,stroke-width:2px,stroke-dasharray:5 5

What is in here

candace/
├── csf/          typed coordination library, contracts, examples and consumer guide
├── pkg/          domain-neutral primitives — nothing in them knows what CandaceOS is
├── services/     composable business logic — candaceos, warden
├── app/          runnable compositions — candaceos-core, candaceos-agent, warden
├── proto/        .proto sources and their committed Go bindings
├── candaceos/    the deployment kit: Compose stack, installer, fleet driver, updater
├── xetcas/       a Rust workspace (xetcasd) plus its generated Go bindings
├── examples/     one worked consumer per extension seam, each with its own suite
├── extensions/   copilot-pair, a GitHub Copilot CLI extension
├── docs/         extending.md — the four compile-time seams
└── bazel/        the legacy WORKSPACE shim

The three Go trees are separated by one rule, about who may import whom:

Imports Allowed direction
Runnable compositions (app/) Services, CSF and shared packages
Domain services and CSF Shared packages
Domain-neutral packages (pkg/) No import of services or application compositions

Nothing in pkg/ imports services/ or app/, which is what makes the primitives usable on their own:

Package What it is
gotth Server-driven live UI. Large enough to have its own documentation set.
pgmem A process-local PostgreSQL emulator for fast tests — real PostgreSQL AST, no server.
cron Durable in-process scheduling with human-readable declarations and an explicit state store.
liquidproto The runtime for Liquid Proto: protobuf with refinement predicates compiled into the generated Go.
telemetry Trace propagation and structured JSONL over the candace.telemetry.v1 contracts, with no observability SDK.
config Configuration-boundary parsing: environment lookup, private-origin validation, provider/model strings.
mailbox Serializes ownership of a mutable value onto one goroutine — commands run in turn, so no field needs a lock.
boundedbuffer An io.Writer that retains at most a fixed number of bytes while still reporting the true write lengths.
redact Removes caller-declared sensitive values, and their URL-userinfo spellings, from log-bound text.
labels Canonicalizes case-insensitive label lists so services compare and deduplicate them one way.
core The zerolog logger the Go trees log through, plus the few formatters operator pages share.
patience The one typed await for tests: poll a value, judge it with a predicate, get the value that satisfied it back.
widget The widget dialect and its toolchain: interpreter, validator, generator, and the typed SDK that mounts generated cards into a gotth-live host.

pkg/proto and pkg/scripts hold tooling rather than a package.

5. Quick start

Use Go 1.26. The smallest CSF example needs no database, GPU, model account or extra service process:

go run ./examples/csf-theme --listen 127.0.0.1:8089 --theme-dir ./examples/csf-theme

That mounts the generated HTTP API and MCP at http://127.0.0.1:8089/mcp. The caller owns the process; CSF only registers routes and hands back a handler. From examples/csf-consumer/main.go:

service, err := csf.New(options...)
if err != nil {
	return nil, fmt.Errorf("create CSF: %w", err)
}
router := httpserver.NewEngine(applicationName)
service.Register(router)
router.Any(mcpPath, gin.WrapH(service.MCPHandler()))
registerConsumerSummary(router, service)

Agent-native onboarding. The intended first instruction to your agent is “Learn about CSF.” The LearnAboutCSF MCP operation explains the pinned version's capabilities and extension points and, when knowledge is configured, submits the embedded guidance plus selected consumer files for indexing. Your own tools join the same MCP server with typed inputs and outputs; the pinned MCP SDK derives and validates their schemas, and CSF rejects name collisions with its own operations. The signature, from csf/service.go:

func WithMCPTool[In, Out any](tool mcp.Tool, handler mcp.ToolHandlerFor[In, Out]) Option

The host still owns listener startup, authentication, repository authorization and consumer checks. The CSF guide covers the Workbench, onboarding and every example with its boundary.

gotth-live, the web layer CSF's Workbench uses, runs with no npm or code generation:

go run ./examples/gotth/counter
counter: http://127.0.0.1:8080
counter: allowed origins [http://127.0.0.1:8080 http://localhost:8080]

Open that URL in two browser tabs. The number lives in the Go process and neither tab holds a copy of it: click in one and the other repaints, reload either and the count survives, and the client runtime that carried the patch was compiled into the binary and served by the same handler that serves the WebSocket. examples/gotth/counter/README.md follows one click all the way through and names the file each step lives in. The optional CSF Workbench has a separate browser-asset build documented in its README.

6. Consume it

This repository is generated

It is a one-way snapshot of a private monorepo's candace/ folder at one exact revision, published with no upstream history. Snapshot updates arrive as ready pull requests from candace-export against main. Make source changes in the canonical repository; editing the generated destination directly would conflict with its next snapshot.

After its review PR is merged, the publisher verifies that tree and creates immutable v<version> and export-<sha12> tags. The GitHub Release uses the semantic-version tag; .candace-export.json records the exact source revision. Cite a tag, not a branch.

Consume it in 60 seconds

Public URLs below apply only once v0.1.0 is published on candacelabs/csf; a private staging release does not publish it there. For staging, download the release assets with authenticated access and use the verified local-archive consumer. The Go module path remains github.com/candacelabs/csf in both stages.

New releases carry csf-<sha12>.tar.gz and its .sha256; historical releases retain their original archive names. The tarball is this tree re-rooted so MODULE.bazel is at the archive root, plus a deterministic .candace-source.json recording the source revision and selected tree, built twice and byte-compared before it is kept.

Download both files from the same Release. In their directory, replace <sha12> with the 12-character revision from its tag and verify the hexadecimal checksum, then compute the base64 SRI value required by Bazel (Bash, sha256sum and OpenSSL):

set -euo pipefail
archive='csf-<sha12>.tar.gz'
sha256sum --check "$archive.sha256"
printf 'sha256-'
openssl dgst -sha256 -binary "$archive" | openssl base64 -A
printf '\n'

Copy the complete sha256-... output line into integrity in your own MODULE.bazel; the .sha256 file's hexadecimal value is not an SRI value:

bazel_dep(name = "csf", version = "0.1.0")

archive_override(
    module_name = "csf",
    integrity = "sha256-...",          # base64 SRI output from the command above
    strip_prefix = "csf-<sha12>",
    urls = ["https://github.com/candacelabs/csf/releases/download/v0.1.0/csf-<sha12>.tar.gz"],
)

Then depend on what you use — @csf//services/candaceos/component, @csf//pkg/gotth/live, @csf//services/warden — and build.

Not a Bazel repository? The module path is the repository path:

go get github.com/candacelabs/csf@v0.1.0

Use the published semantic version matching your archive, not @latest. The accompanying export-<sha12> tag identifies its exact source snapshot.

docs/extending.md covers both shapes in full, plus the http_archive fallback and the legacy WORKSPACE path.

7. Examples

Every extension seam has a worked example with its own test suite. They are the contract's executable half — the documentation says what is guaranteed, and these fail if it stops being true.

Example Shows
csf-consumer CSF mounted beside a consumer's own Go endpoint in one process, its generated client, MCP tool discovery and shutdown. Its archive acceptance script builds a fresh repository with networking disabled.
external-consumer A complete outside repository choosing every seam at once: its own identity and overlay, its own sidebar entry and page, three composed services, a custom agent harness, and the Core binary linked from them — built and tested both supported Bazel ways. This is also the acceptance test every release archive passes.
custom-brand Core wearing another product's identity — name, agent, wordmark, palette, an overlay asset, an extra sidebar entry and page — with no edit to Core.
custom-ui-page The smallest useful UI extension: stock identity, one sidebar entry, one page of your own.
gotth/counter gotth-live at its smallest: a number that lives in Go, four buttons, and every open tab kept in step by the server.
gotth/chat One room in Go, several browsers, and every message reaching every session over a server push.
gotth/dashboard A feed pushing twenty times a second, three live regions patched independently, and two plain-HTMX regions on the same page.

8. Build it

Bazel is the primary build and comes from a pinned container, so the command is the same on a laptop and on a runner. Docker is the only prerequisite:

tools/bazel.sh build -- //... -//xetcas/...   # everything but the Rust workspace
tools/bazel.sh test  -- //... -//xetcas/...
tools/bazel.sh build //xetcas/...             # the Rust workspace and its Go bindings
tools/bazel.sh test  //xetcas/...

The plain go command works on the same tree and needs no Bazel:

go build ./...
go test ./...

The Rust workspace builds with plain Cargo too — that is the path its demo, container images, and just targets take:

cd xetcas && cargo build --workspace && cargo test --workspace

.bazelversion (Bazel 9.2.0) and MODULE.bazel (rules_go 0.62.0, Gazelle 0.52.2, Go SDK 1.26.5, rules_rust 0.73.0) are the only version authority. BUILD files are generated by Gazelle (tools/bazel.sh run //:gazelle) and CI fails on drift.

Run CandaceOS

The deployment kit installs and runs the whole one-box stack from this clone. The default install is deliberately harmless: a simulated harness, a dry-run executor, and no Docker socket mounted anywhere.

./candaceos/install.sh          # then open http://<host>:7780
./candaceos/status.sh
./candaceos/uninstall.sh

Core publishes on all host IPv4 interfaces with no built-in authentication: put it behind your own authenticating proxy before exposing it beyond a trusted network. candaceos/README.md is the operations manual, and candaceos/AGENTS.md states the trust model as eight invariants with their enforcement points.

9. Where to go next

  • csf/README.md — the CSF guide: Workbench, onboarding, examples and release evidence.
  • AGENTS.md — the repository's own guide: taxonomy, seams, invariants, conventions.
  • docs/extending.md — the four compile-time seams and how to pin a snapshot.
  • pkg/gotth/README.md, xetcas/README.md — each subsystem's own front page.
  • app/*/CLAUDE.md — what may not be changed casually in each binary.

10. Citation

[1] He Kai Lim and Tyler R. Clites. LITHE: Bridging Best-Effort Python and Real-Time C++ for Hot-Swapping Robotic Control Laws on Commodity Linux. arXiv:2603.07442 [cs.RO], 2026. Submitted to IROS 2026. https://doi.org/10.48550/arXiv.2603.07442

@misc{lim2026lithe,
  title         = {{LITHE}: Bridging Best-Effort {Python} and Real-Time {C++} for Hot-Swapping Robotic Control Laws on Commodity {Linux}},
  author        = {Lim, He Kai and Clites, Tyler R.},
  year          = {2026},
  eprint        = {2603.07442},
  archivePrefix = {arXiv},
  primaryClass  = {cs.RO},
  doi           = {10.48550/arXiv.2603.07442},
  url           = {https://arxiv.org/abs/2603.07442},
  note          = {Submitted to IROS 2026}
}

CSF's architecture is inspired by LITHE [1]. To cite CSF itself, name the exact release tag you used:

@software{csf2026,
  title   = {CSF — The Cerebrospinal Fluid},
  author  = {{Candace Labs}},
  version = {0.1.0},
  year    = {2026},
  url     = {https://github.com/candacelabs/csf}
}

The LITHE paper and its figures are distributed under arXiv's non-exclusive distribution license, not a Creative Commons license. © the authors; this repository's license does not cover them, and no figure file is copied into it.

License

Apache License 2.0. See LICENSE.

AI systems assisted with work in this repository. Their output is not presumed correct, secure, reviewed, or production-ready.

Directories

Path Synopsis
app
candaceos-agent/cmd command
Command candaceos-agent is the node-local CandaceOS Compose executor.
Command candaceos-agent is the node-local CandaceOS Compose executor.
candaceos-agent/internal/config
Package config loads and validates candaceos-agent process configuration.
Package config loads and validates candaceos-agent process configuration.
candaceos-agent/internal/httpapi
Package httpapi exposes the node-local JSON control API.
Package httpapi exposes the node-local JSON control API.
candaceos-core/bootstrap
Package bootstrap assembles and runs CandaceOS Core.
Package bootstrap assembles and runs CandaceOS Core.
candaceos-core/cmd command
Command candaceos-core is the single-operator CandaceOS control plane.
Command candaceos-core is the single-operator CandaceOS control plane.
csf/cmd command
The JSONL adapter is a disposable simulator boundary.
The JSONL adapter is a disposable simulator boundary.
warden/cmd command
Command warden is the candacenet fleet watchdog daemon.
Command warden is the candacenet fleet watchdog daemon.
csf
Code generated by Candacegen (csf/compiler/api_codegen).
Code generated by Candacegen (csf/compiler/api_codegen).
internal/mocks
Package csfmocks is a generated GoMock package.
Package csfmocks is a generated GoMock package.
examples
csf-agent command
csf-consumer command
This consumer owns the process, listener and custom routes.
This consumer owns the process, listener and custom routes.
csf-theme command
custom-brand command
Command custom-brand is CandaceOS Core wearing another product's identity.
Command custom-brand is CandaceOS Core wearing another product's identity.
custom-ui-page command
Command custom-ui-page is stock CandaceOS Core with one page added.
Command custom-ui-page is stock CandaceOS Core with one page added.
external-consumer/_workspace/cmd command
Command custom-candaceos is this repository's own Core binary.
Command custom-candaceos is this repository's own Core binary.
external-consumer/_workspace/composition
Package composition is this repository's composition root: the exact set of values handed to bootstrap.Run, assembled in one place so the binary and its suite cannot describe different products.
Package composition is this repository's composition root: the exact set of values handed to bootstrap.Run, assembled in one place so the binary and its suite cannot describe different products.
external-consumer/_workspace/customharness
Package customharness is a complete harness implementation compiled outside the CandaceOS source tree.
Package customharness is a complete harness implementation compiled outside the CandaceOS source tree.
external-consumer/_workspace/identity
Package identity is this repository's own product identity: the two brand-bearing names, the lockup rendered in the shell, the design tokens the operator stylesheet reads, and the one shipped template block its overlay redefines.
Package identity is this repository's own product identity: the two brand-bearing names, the lockup rendered in the shell, the design tokens the operator stylesheet reads, and the one shipped template block its overlay redefines.
external-consumer/_workspace/noteboard
Package noteboard is this repository's own service.
Package noteboard is this repository's own service.
external-consumer/_workspace/steering
Package steering composes an agent-steering service alongside CandaceOS Core.
Package steering composes an agent-steering service alongside CandaceOS Core.
gotth/chat command
Command chat is gotth-live's multi-user example: one room in Go, several browsers, and every message reaching every session over a server push.
Command chat is gotth-live's multi-user example: one room in Go, several browsers, and every message reaching every session over a server push.
gotth/counter command
Command counter is gotth-live's smallest end-to-end application: a number that lives in Go, four buttons that change it, and every open tab kept in step by the server.
Command counter is gotth-live's smallest end-to-end application: a number that lives in Go, four buttons that change it, and every open tab kept in step by the server.
gotth/dashboard command
Command dashboard is gotth-live's resilience example: a simulated metrics feed pushing from the server twenty times a second, three live regions that are patched independently, and two plain-HTMX regions on the same page.
Command dashboard is gotth-live's resilience example: a simulated metrics feed pushing from the server twenty times a second, three live regions that are patched independently, and two plain-HTMX regions on the same page.
widget command
Command widget is the widget SDK's smallest end-to-end host: two generated widgets, one registry, one page, one binary — and, behind one of them, a real consensus protocol.
Command widget is the widget SDK's smallest end-to-end host: two generated widgets, one registry, one page, one binary — and, behind one of them, a real consensus protocol.
widget/candaws command
Command candaws is the CandaWS fleet: five parody cloud services, five engines, five generated widgets, and one binary.
Command candaws is the CandaWS fleet: five parody cloud services, five engines, five generated widgets, and one binary.
widget/candaws/blobfish
Package blobfish is the generated Blobfish widget.
Package blobfish is the generated Blobfish widget.
widget/candaws/coldstart
Package coldstart is the generated Coldstart widget.
Package coldstart is the generated Coldstart widget.
widget/candaws/dashbored
Package dashbored is the generated Dashbored widget.
Package dashbored is the generated Dashbored widget.
widget/candaws/fleet
Package fleet is the part of every CandaWS engine that is the same part.
Package fleet is the part of every CandaWS engine that is the same part.
widget/candaws/queuecumber
Package queuecumber is the generated Queuecumber widget.
Package queuecumber is the generated Queuecumber widget.
widget/candaws/yakshave
Package yakshave is the generated Yakshave widget.
Package yakshave is the generated Yakshave widget.
widget/clusterheartbeats
Package clusterheartbeats is the generated ClusterHeartbeats widget.
Package clusterheartbeats is the generated ClusterHeartbeats widget.
widget/hosting
Package hosting is what both widget demo hosts do the same way.
Package hosting is what both widget demo hosts do the same way.
widget/nodestatus
Package nodestatus is the generated NodeStatus widget.
Package nodestatus is the generated NodeStatus widget.
widget/raftdemo
Package raftdemo runs a real leader election in one process, so that the raft widget beside it animates a protocol rather than a script.
Package raftdemo runs a real leader election in one process, so that the raft widget beside it animates a protocol rather than a script.
widget/relaypipeline
Package relaypipeline is the generated RelayPipeline widget.
Package relaypipeline is the generated RelayPipeline widget.
pkg
boundedbuffer
Package boundedbuffer provides an io.Writer that retains at most a fixed number of bytes while reporting the original write lengths to its producer.
Package boundedbuffer provides an io.Writer that retains at most a fixed number of bytes while reporting the original write lengths to its producer.
config
Package config provides small, domain-neutral configuration boundary primitives.
Package config provides small, domain-neutral configuration boundary primitives.
cron
Package cron provides durable in-process scheduling with human-readable declarations and explicit state stores.
Package cron provides durable in-process scheduling with human-readable declarations and explicit state stores.
cron/contract
Package contract maps the cron domain model to validated Liquid Proto messages at HTTP and messaging boundaries.
Package contract maps the cron domain model to validated Liquid Proto messages at HTTP and messaging boundaries.
cron/postgres
Package postgres provides the SQLC-backed durable cron Store.
Package postgres provides the SQLC-backed durable cron Store.
gotth/bench/apps/chat/gotth command
The gotth-live side of equivalence-spec §2.3's chat room.
The gotth-live side of equivalence-spec §2.3's chat room.
gotth/bench/apps/counter/gotth command
The gotth-live side of equivalence-spec §2.1's counter — app C-B, and only C-B.
The gotth-live side of equivalence-spec §2.1's counter — app C-B, and only C-B.
gotth/bench/apps/dashboard/gotth command
The gotth-live side of equivalence-spec §2.4's live dashboard.
The gotth-live side of equivalence-spec §2.4's live dashboard.
gotth/docs/guide/_samples
Package samples is the compiled twin of the gotth-live documentation.
Package samples is the compiled twin of the gotth-live documentation.
gotth/docs/guide/_samples/apptest
Package apptest is the compiled source for docs/guide/testing-your-app.md: a small application, and the specs that hold it to the library's contracts.
Package apptest is the compiled source for docs/guide/testing-your-app.md: a small application, and the specs that hold it to the library's contracts.
gotth/docs/guide/_samples/architecture
Package architecture is the compiled source for docs/guide/architecture.md.
Package architecture is the compiled source for docs/guide/architecture.md.
gotth/docs/guide/_samples/deploying
Package deploying is the compiled source for docs/guide/deploying.md.
Package deploying is the compiled source for docs/guide/deploying.md.
gotth/docs/guide/_samples/effects
Package effects is the compiled source for docs/guide/effects-and-server-push.md.
Package effects is the compiled source for docs/guide/effects-and-server-push.md.
gotth/docs/guide/_samples/errorhandling
Package errorhandling is the compiled source for docs/guide/error-handling.md.
Package errorhandling is the compiled source for docs/guide/error-handling.md.
gotth/docs/guide/_samples/events
Package events is the compiled source for docs/guide/events-and-forms.md.
Package events is the compiled source for docs/guide/events-and-forms.md.
gotth/docs/guide/_samples/fragments
Package fragments is the compiled source for docs/guide/fragments-and-dirty-tracking.md.
Package fragments is the compiled source for docs/guide/fragments-and-dirty-tracking.md.
gotth/docs/guide/_samples/htmxinterop
Package htmxinterop is the compiled source for docs/guide/htmx-interop.md.
Package htmxinterop is the compiled source for docs/guide/htmx-interop.md.
gotth/docs/guide/_samples/keychords
Package keychords is the compiled source for the two modifier-aware options on docs/guide/events-and-forms.md: live.Bind.NoModifiers and live.Bind.PreventDefault.
Package keychords is the compiled source for the two modifier-aware options on docs/guide/events-and-forms.md: live.Bind.NoModifiers and live.Bind.PreventDefault.
gotth/docs/guide/_samples/lifecycle
Package lifecycle is the compiled source for docs/guide/lifecycle-hooks.md.
Package lifecycle is the compiled source for docs/guide/lifecycle-hooks.md.
gotth/docs/guide/_samples/mounting
Package mounting is the compiled source for the two things docs/quickstart.md §2 explains beside its router: where the live handler is mounted, and where the first paint's state comes from.
Package mounting is the compiled source for the two things docs/quickstart.md §2 explains beside its router: where the live handler is mounted, and where the first paint's state comes from.
gotth/docs/guide/_samples/observability
Package observability is the compiled source for docs/guide/observability.md.
Package observability is the compiled source for docs/guide/observability.md.
gotth/docs/guide/_samples/payments
Package payments is the compiled source for the idempotency section of docs/guide/effects-and-server-push.md.
Package payments is the compiled source for the idempotency section of docs/guide/effects-and-server-push.md.
gotth/docs/guide/_samples/quickstart command
Command quickstart is the application docs/quickstart.md builds: a number that lives in Go, and a button that changes it.
Command quickstart is the application docs/quickstart.md builds: a number that lives in Go, and a button that changes it.
gotth/docs/guide/_samples/security
Package security is the compiled source for docs/guide/security.md.
Package security is the compiled source for docs/guide/security.md.
gotth/internal/arch
Package arch holds this module's architecture tests.
Package arch holds this module's architecture tests.
gotth/internal/clientcodec
Package clientcodec generates the browser runtime's protobuf codec, its predicate manifest, and the cross-runtime golden vectors, from the same FileDescriptorSet that drives the Go refinement generator.
Package clientcodec generates the browser runtime's protobuf codec, its predicate manifest, and the cross-runtime golden vectors, from the same FileDescriptorSet that drives the Go refinement generator.
gotth/internal/cmd/gen-clientcodec command
Command gen-clientcodec generates the browser runtime's protobuf codec.
Command gen-clientcodec generates the browser runtime's protobuf codec.
gotth/internal/cmd/gotth-live-dev command
Command gotth-live-dev is the server half of FR-57: it watches a gotth-live application's source, rebuilds it when a Go or templ file changes, and restarts it.
Command gotth-live-dev is the server half of FR-57: it watches a gotth-live application's source, rebuilds it when a Go or templ file changes, and restarts it.
gotth/internal/livebridge
Package livebridge lets live/livetest construct a value only live can build.
Package livebridge lets live/livetest construct a value only live can build.
gotth/internal/obs
Package obs is the library's instrumentation: metrics, traces and the provenance log.
Package obs is the library's instrumentation: metrics, traces and the provenance log.
gotth/internal/obstest
Package obstest records what the library actually emits, so that a spec can assert on a signal rather than on a method having been called.
Package obstest records what the library actually emits, so that a spec can assert on a signal rather than on a method having been called.
gotth/internal/protocol
Package protocol is the boundary every byte crosses in either direction.
Package protocol is the boundary every byte crosses in either direction.
gotth/internal/render
Package render turns state into whole HTML fragments.
Package render turns state into whole HTML fragments.
gotth/internal/session
Package session implements the service that maintains one WebSocket connection's widget state.
Package session implements the service that maintains one WebSocket connection's widget state.
gotth/internal/wsx
Package wsx is the WebSocket transport, and the only place it exists.
Package wsx is the WebSocket transport, and the only place it exists.
gotth/live
Package live serves server-driven live user interfaces from Go.
Package live serves server-driven live user interfaces from Go.
gotth/live/livetest
Package livetest provides testing helpers for live applications.
Package livetest provides testing helpers for live applications.
gotth/test/internal/chaos/cmd/chaossrv command
Command chaossrv is a live server in its own process, for the one chaos case that cannot be expressed inside the test binary.
Command chaossrv is a live server in its own process, for the one chaos case that cannot be expressed inside the test binary.
gotth/test/memory
Package memory is the G2 idle-connection memory harness: the arithmetic half of equivalence-spec §3.6, with the three commands beside it supplying the server under test, the synthetic session driver, and the report.
Package memory is the G2 idle-connection memory harness: the arithmetic half of equivalence-spec §3.6, with the three commands beside it supplying the server under test, the synthetic session driver, and the report.
gotth/test/memory/cmd/memdiag command
Command memdiag reports the G2 remediation diagnostic that diag.sh collects.
Command memdiag reports the G2 remediation diagnostic that diag.sh collects.
gotth/test/memory/cmd/memdrv command
Command memdrv is equivalence-spec §3.6's synthetic session driver for gotth-live: it opens N real sessions against a memsrv, holds them IDLE, and keeps them alive for as long as the harness needs them.
Command memdrv is equivalence-spec §3.6's synthetic session driver for gotth-live: it opens N real sessions against a memsrv, holds them IDLE, and keeps them alive for as long as the harness needs them.
gotth/test/memory/cmd/memsrv command
Command memsrv is the server under test for the G2 idle-connection memory baseline (RFC-0001 §6.1/§6.2, equivalence-spec §3.6).
Command memsrv is the server under test for the G2 idle-connection memory baseline (RFC-0001 §6.1/§6.2, equivalence-spec §3.6).
gotth/test/memory/cmd/memstat command
Command memstat turns the sample files measure.sh collects into the figure equivalence-spec §3.6 defines, and refuses to produce one from a window that is not §3.6's window.
Command memstat turns the sample files measure.sh collects into the figure equivalence-spec §3.6 defines, and refuses to produce one from a window that is not §3.6's window.
gotth/test/routers
Package routers holds the FR-33 three-router mount suite and nothing else.
Package routers holds the FR-33 three-router mount suite and nothing else.
gotth/test/sampling
Package sampling holds FR-36 clause 4's falsifier and nothing else.
Package sampling holds FR-36 clause 4's falsifier and nothing else.
gotth/tools/apisurface command
Command apisurface counts the library's exported surface and holds it against the ledger.
Command apisurface counts the library's exported surface and holds it against the ledger.
gotth/tools/doccheck command
Command doccheck holds every exported symbol in the tree to a doc comment, and every godoc example to an output the test runner actually checks.
Command doccheck holds every exported symbol in the tree to a doc comment, and every godoc example to an output the test runner actually checks.
gotth/tools/minify command
Command minify builds the files the library serves, and measures them.
Command minify builds the files the library serves, and measures them.
httpserver
Package httpserver provides the shared Gin HTTP surface used by Candace services.
Package httpserver provides the shared Gin HTTP surface used by Candace services.
labels
Package labels canonicalizes case-insensitive label lists, such as CI runner labels, so services compare, deduplicate, and match them with one set of semantics.
Package labels canonicalizes case-insensitive label lists, such as CI runner labels, so services compare, deduplicate, and match them with one set of semantics.
liquidproto
Package liquidproto provides the small runtime used by Liquid Proto generated code and deterministic, validating protobuf serialization.
Package liquidproto provides the small runtime used by Liquid Proto generated code and deterministic, validating protobuf serialization.
liquidproto/cmd/protoc-gen-liquidproto command
protoc-gen-liquidproto compiles Liquid Proto field refinements into native Go validation boundaries.
protoc-gen-liquidproto compiles Liquid Proto field refinements into native Go validation boundaries.
liquidproto/cmd/protoc-gen-liquidproto/internal/expr
Package expr compiles the small Liquid Proto predicate grammar to Go.
Package expr compiles the small Liquid Proto predicate grammar to Go.
liquidproto/cmd/protoc-gen-liquidproto/internal/gen
Package gen turns Liquid Proto field refinements into Go validators.
Package gen turns Liquid Proto field refinements into Go validators.
mailbox
Package mailbox serializes ownership of a mutable value onto one goroutine.
Package mailbox serializes ownership of a mutable value onto one goroutine.
patience
Package patience is the one way a test in this repository waits for something to become true.
Package patience is the one way a test in this repository waits for something to become true.
pgmem
Package pgmem provides a fast, process-local PostgreSQL emulator for Go tests.
Package pgmem provides a fast, process-local PostgreSQL emulator for Go tests.
privatefile
Package privatefile reads bounded, owner-only configuration and secret files.
Package privatefile reads bounded, owner-only configuration and secret files.
redact
Package redact removes caller-declared sensitive values from text destined for logs or operator diagnostics.
Package redact removes caller-declared sensitive values from text destined for logs or operator diagnostics.
sqlmigrate
Package sqlmigrate applies a service's embedded migration files to a database/sql handle, so a service's store directory holds its .sql files and nothing else: the files are the only schema source, and this is the one runner that reads them.
Package sqlmigrate applies a service's embedded migration files to a database/sql handle, so a service's store directory holds its .sql files and nothing else: the files are the only schema source, and this is the one runner that reads them.
telemetry
Package telemetry provides dependency-light distributed trace propagation and structured JSONL logging over the candace.telemetry.v1 protobuf contracts.
Package telemetry provides dependency-light distributed trace propagation and structured JSONL logging over the candace.telemetry.v1 protobuf contracts.
widget
Package widget is the widget SDK: the contract a widget implements, the registry a host binary mounts them through, and the interpreter for the small Mermaid dialect widgets are declared in.
Package widget is the widget SDK: the contract a widget implements, the registry a host binary mounts them through, and the interpreter for the small Mermaid dialect widgets are declared in.
widget/internal/cmd/widgetc command
Command widgetc validates widget documents and prints their findings.
Command widgetc validates widget documents and prints their findings.
widget/internal/diag
Package diag carries the widget validator's location-anchored findings and the identifiers of the error catalogue every finding belongs to.
Package diag carries the widget validator's location-anchored findings and the identifiers of the error catalogue every finding belongs to.
widget/internal/ir
Package ir holds the widget interpreter's typed intermediate representation: one resolved, ordered, total record per document.
Package ir holds the widget interpreter's typed intermediate representation: one resolved, ordered, total record per document.
widget/internal/lex
Package lex turns widget source into positioned tokens, one slice per significant line.
Package lex turns widget source into positioned tokens, one slice per significant line.
widget/internal/mocks
Package mocks is a generated GoMock package.
Package mocks is a generated GoMock package.
widget/internal/parse
Package parse turns positioned tokens into a widget document's block structure, and reports every structural finding of the catalogue's W0 group.
Package parse turns positioned tokens into a widget document's block structure, and reports every structural finding of the catalogue's W0 group.
widget/internal/uigen
Package uigen turns one resolved widget document into the files that make it a running widget: a templ view and a Go scaffold implementing the SDK's widget contract.
Package uigen turns one resolved widget document into the files that make it a running widget: a templ view and a Go scaffold implementing the SDK's widget contract.
widget/internal/validate
Package validate resolves a parsed widget document into the typed IR and reports every finding of the error catalogue.
Package validate resolves a parsed widget document into the typed IR and reports every finding of the error catalogue.
widget/widgettest
Package widgettest renders a registered widget's own live region, so a specification can assert on what a viewer receives rather than on how the markup was produced.
Package widgettest renders a registered widget's own live region, so a specification can assert on what a viewer receives rather than on how the markup was produced.
workcontinuity
Package workcontinuity validates and records task checkpoints so work can resume across agents and sessions.
Package workcontinuity validates and records task checkpoints so work can resume across agents and sessions.
proto
candace/candaceos/v1
Package candaceosv1 contains the stable protobuf contracts used to configure CandaceOS Core and to fence and reconcile desired-state assignments on node-local agents.
Package candaceosv1 contains the stable protobuf contracts used to configure CandaceOS Core and to fence and reconcile desired-state assignments on node-local agents.
candace/telemetry/v1
Package telemetryv1 contains the stable protobuf contracts for distributed trace propagation and structured JSONL logging.
Package telemetryv1 contains the stable protobuf contracts for distributed trace propagation and structured JSONL logging.
services
candaceos
Package candaceos contains the small, durable domain model shared by CandaceOS controllers and user-facing applications.
Package candaceos contains the small, durable domain model shared by CandaceOS controllers and user-facing applications.
candaceos/agentclient
Package agentclient is CandaceOS Core's transport to one node agent.
Package agentclient is CandaceOS Core's transport to one node agent.
candaceos/browserroutes
Package browserroutes is the single source of truth for CandaceOS Core's browser-facing URL space.
Package browserroutes is the single source of truth for CandaceOS Core's browser-facing URL space.
candaceos/component
Package component defines the public bring-up contract for services an embedding repository composes alongside CandaceOS Core.
Package component defines the public bring-up contract for services an embedding repository composes alongside CandaceOS Core.
candaceos/config
Package config resolves CandaceOS Core's environment into its canonical Liquid Proto contract.
Package config resolves CandaceOS Core's environment into its canonical Liquid Proto contract.
candaceos/control
Package control is CandaceOS Core's control-plane composition root beneath main.
Package control is CandaceOS Core's control-plane composition root beneath main.
candaceos/fleet
Package fleet is CandaceOS Core's read-only view of Warden's cluster membership.
Package fleet is CandaceOS Core's read-only view of Warden's cluster membership.
candaceos/harness
Package harness defines the public behavior boundary between CandaceOS Core and a compiled-in agent runtime implementation.
Package harness defines the public behavior boundary between CandaceOS Core and a compiled-in agent runtime implementation.
candaceos/harness/opencode
Package opencode implements the built-in OpenCode agent runtime behind the public CandaceOS harness seam.
Package opencode implements the built-in OpenCode agent runtime behind the public CandaceOS harness seam.
candaceos/httpapi
Package httpapi is CandaceOS Core's operator-facing HTTP transport.
Package httpapi is CandaceOS Core's operator-facing HTTP transport.
candaceos/httpserver
Package httpserver owns CandaceOS Core's single configured Gin engine.
Package httpserver owns CandaceOS Core's single configured Gin engine.
candaceos/internal/storedb
Package storedb is the sqlc-generated query layer over the CandaceOS control schema.
Package storedb is the sqlc-generated query layer over the CandaceOS control schema.
candaceos/operator
Package operator owns CandaceOS Core's agent turn: policy, approvals, and run state.
Package operator owns CandaceOS Core's agent turn: policy, approvals, and run state.
candaceos/reconcile
Package reconcile turns approved desired state into fenced node-agent calls.
Package reconcile turns approved desired state into fenced node-agent calls.
candaceos/store
Package store is CandaceOS Core's durable control-plane state.
Package store is CandaceOS Core's durable control-plane state.
candaceos/webui
Package webui serves CandaceOS Core's local-first operator interface and is the seam where an embedding product supplies its own branding.
Package webui serves CandaceOS Core's local-first operator interface and is the seam where an embedding product supplies its own branding.
copilot-adapter
Package copilotadapter is the HTTP adapter that fronts a Copilot CLI session with the contract in openapi.yaml.
Package copilotadapter is the HTTP adapter that fronts a Copilot CLI session with the contract in openapi.yaml.
copilot-adapter/copilotbridge
Package copilotbridge is the concrete ICopilotBridge over the Copilot Go SDK.
Package copilotbridge is the concrete ICopilotBridge over the Copilot Go SDK.
copilot-adapter/gen/api
Package api provides primitives to interact with the openapi HTTP API.
Package api provides primitives to interact with the openapi HTTP API.
copilot-adapter/kanban
Package kanban mounts shared task planning into an existing HTTP server.
Package kanban mounts shared task planning into an existing HTTP server.
copilot-adapter/kanban/card
Package card is the generated KanbanCard widget.
Package card is the generated KanbanCard widget.
copilot-adapter/store
Package store carries the adapter's schema.
Package store carries the adapter's schema.
copilot-adapter/terminaladapter
Package terminaladapter owns interactive PTYs for the Copilot workbench.
Package terminaladapter owns interactive PTYs for the Copilot workbench.
copilot-adapter/workbench
Package workbench composes the existing Copilot service for caller-owned hosts.
Package workbench composes the existing Copilot service for caller-owned hosts.
copilot-adapter/worktreeadapter
Package worktreeadapter implements configured git repository and worktree operations for the Copilot adapter.
Package worktreeadapter implements configured git repository and worktree operations for the Copilot adapter.
email
Package email provides a composable, host-configured email capability.
Package email provides a composable, host-configured email capability.
warden
Package warden defines the shared contracts for the candacenet warden service: core types, the wire protocol, and the interfaces that the election, watchdog, notification, dashboard, and configuration packages implement or consume.
Package warden defines the shared contracts for the candacenet warden service: core types, the wire protocol, and the interfaces that the election, watchdog, notification, dashboard, and configuration packages implement or consume.
warden/config
Package config loads warden node configuration from built-in defaults, an optional YAML file, and environment overrides, in that precedence order (env beats file beats defaults).
Package config loads warden node configuration from built-in defaults, an optional YAML file, and environment overrides, in that precedence order (env beats file beats defaults).
warden/dashboard
Package dashboard renders the operator-facing observability surface of a warden node: a server-side-rendered, HTMX-refreshed dashboard, an HTMX partial for live cluster refresh, and a JSON status API.
Package dashboard renders the operator-facing observability surface of a warden node: a server-side-rendered, HTMX-refreshed dashboard, an HTMX partial for live cluster refresh, and a JSON status API.
warden/discovery
Package discovery implements warden.IPeerDiscoverer: the sources that report which nodes are candidate members of the cluster.
Package discovery implements warden.IPeerDiscoverer: the sources that report which nodes are candidate members of the cluster.
warden/election
Package election implements Raft-style leader election (terms and votes, no log replication) over a static peer set, plus the peer-liveness tracking that feeds the cluster ClusterView.
Package election implements Raft-style leader election (terms and votes, no log replication) over a static peer set, plus the peer-liveness tracking that feeds the cluster ClusterView.
warden/grpcmux
Package grpcmux multiplexes the warden gRPC plane and the existing HTTP surface onto a SINGLE bound port using soheilhy/cmux.
Package grpcmux multiplexes the warden gRPC plane and the existing HTTP surface onto a SINGLE bound port using soheilhy/cmux.
warden/grpcserver
Package grpcserver implements the candacenet.warden.v1 WardenService: the three unary cluster RPCs (Vote/Heartbeat/Identify) delegating to the existing warden.IRPCHandler through the wireconv boundary, and the server-streaming WatchCluster that pushes full ClusterView snapshots from a warden.IViewSource.
Package grpcserver implements the candacenet.warden.v1 WardenService: the three unary cluster RPCs (Vote/Heartbeat/Identify) delegating to the existing warden.IRPCHandler through the wireconv boundary, and the server-streaming WatchCluster that pushes full ClusterView snapshots from a warden.IViewSource.
warden/grpctransport
Package grpctransport is the gRPC client side of the warden cluster wire protocol: it implements warden.ITransport (RequestVote/SendHeartbeat/Identify) over the candacenet.warden.v1 WardenService, replacing the retired HTTP/JSON HTTPTransport.
Package grpctransport is the gRPC client side of the warden cluster wire protocol: it implements warden.ITransport (RequestVote/SendHeartbeat/Identify) over the candacenet.warden.v1 WardenService, replacing the retired HTTP/JSON HTTPTransport.
warden/httpserver
Package httpserver builds the single gin.Engine every warden node serves its HTTP surface from (dashboard + /api/status + /metrics).
Package httpserver builds the single gin.Engine every warden node serves its HTTP surface from (dashboard + /api/status + /metrics).
warden/internal/mocks
Package mocks is a generated GoMock package.
Package mocks is a generated GoMock package.
warden/internal/transportidentity
Package transportidentity carries transport-observed peer identity between Warden's gRPC adapter and election state machine.
Package transportidentity carries transport-observed peer identity between Warden's gRPC adapter and election state machine.
warden/metrics
Package metrics exposes a warden node's cluster state as Prometheus metrics.
Package metrics exposes a warden node's cluster state as Prometheus metrics.
warden/notify
Package notify implements the warden.INotifier delivery backends used by the watchdog:
Package notify implements the warden.INotifier delivery backends used by the watchdog:
warden/proto/warden/v1
Package wardenv1 holds the generated Go bindings for the candacenet warden wire contracts (candacenet.warden.v1).
Package wardenv1 holds the generated Go bindings for the candacenet warden wire contracts (candacenet.warden.v1).
warden/store
Package store provides persistence for warden.PersistentState (the Raft current term and vote).
Package store provides persistence for warden.PersistentState (the Raft current term and vote).
warden/testclock
Package testclock provides a deterministic, manually-advanced implementation of warden.IClock for tests.
Package testclock provides a deterministic, manually-advanced implementation of warden.IClock for tests.
warden/watchdog
Package watchdog turns cluster views into operator alerts.
Package watchdog turns cluster views into operator alerts.
warden/wireconv
Package wireconv provides total, composable conversions between the frozen warden domain types (services/warden) and the generated candacenet.warden.v1 protobuf messages (services/warden/proto/warden/v1).
Package wireconv provides total, composable conversions between the frozen warden domain types (services/warden) and the generated candacenet.warden.v1 protobuf messages (services/warden/proto/warden/v1).
tools
generateopensearch command
Command generateopensearch derives one consumer client from the upstream spec-generated SDK, then delegates its test double to MockGen.
Command generateopensearch derives one consumer client from the upstream spec-generated SDK, then delegates its test double to MockGen.
ifacereturn
Package ifacereturn reports handwritten function and method declarations through whose results an interface reaches a caller.
Package ifacereturn reports handwritten function and method declarations through whose results an interface reaches a caller.
ifacereturn/cmd/ifacereturn command
Command ifacereturn reports every function and method result in a Go module through which an interface reaches a caller — the result's own type, or an interface-typed field of a struct it hands back.
Command ifacereturn reports every function and method result in a Go module through which an interface reaches a caller — the result's own type, or an interface-typed field of a struct it hands back.
xetcas

Jump to

Keyboard shortcuts

? : This menu
/ : Search site
f or F : Jump to
y or Y : Canonical URL