internal/

directory
v0.40.0 Latest Latest
Warning

This package is not in the latest version of its module.

Go to latest
Published: Sep 24, 2026 License: Apache-2.0

Directories

Path Synopsis
Package actionableerror owns the stable CLI/MCP recovery guidance envelope.
Package actionableerror owns the stable CLI/MCP recovery guidance envelope.
Package advancedcapability verifies the short-lived, secret-free capabilities which authorize individual StackKits advanced operations.
Package advancedcapability verifies the short-lived, secret-free capabilities which authorize individual StackKits advanced operations.
Package advancedchangeset owns the immutable, owner-signed description of one already-rendered advanced change.
Package advancedchangeset owns the immutable, owner-signed description of one already-rendered advanced change.
Package advancedtrust imports and owns the local, Owner-approved trust roots used by offline Advanced capability verification.
Package advancedtrust imports and owns the local, Owner-approved trust roots used by offline Advanced capability verification.
cmd/gen command
Package api provides the HTTP API server for kombify StackKits.
Package api provides the HTTP API server for kombify StackKits.
Package applicationlifecycle persists the resumable state of every selected Application Kit.
Package applicationlifecycle persists the resumable state of every selected Application Kit.
Package apply orchestrates post-deployment bootstrap of identity resources.
Package apply orchestrates post-deployment bootstrap of identity resources.
Package applyevidence defines the provider-neutral producer wire contract for StackKits Architecture-v2 pre-Apply evidence.
Package applyevidence defines the provider-neutral producer wire contract for StackKits Architecture-v2 pre-Apply evidence.
Package applyledger records what one Apply actually did, unit by unit.
Package applyledger records what one Apply actually did, unit by unit.
Package applyoutcome owns the StackKits failure-class taxonomy for local runtime execution.
Package applyoutcome owns the StackKits failure-class taxonomy for local runtime execution.
Package architecturecontractproof verifies the non-graduating public Architecture v2 contract fixture against the binary's embedded authority.
Package architecturecontractproof verifies the non-graduating public Architecture v2 contract fixture against the binary's embedded authority.
Package architecturev2 is the single integration boundary from StackSpec documents to the governed Architecture v2 ResolvedPlan compiler.
Package architecturev2 is the single integration boundary from StackSpec documents to the governed Architecture v2 ResolvedPlan compiler.
cmd/bundlegen command
Command bundlegen builds the deterministic embedded Architecture v2 authority projection.
Command bundlegen builds the deterministic embedded Architecture v2 authority projection.
internal/execution
Package execution owns the held-root installation transaction used by the Architecture v2 authority boundary.
Package execution owns the held-root installation transaction used by the Architecture v2 authority boundary.
Package architecturev2renderer renders only governed Architecture v2 ResolvedPlans.
Package architecturev2renderer renders only governed Architecture v2 ResolvedPlans.
Package auth provides shared authentication primitives for the stackkit CLI and supporting libraries.
Package auth provides shared authentication primitives for the stackkit CLI and supporting libraries.
Package backupcustody owns the local Kopia repository passphrase without adding it to the Basement runtime-custody inventory.
Package backupcustody owns the local Kopia repository passphrase without adding it to the Basement runtime-custody inventory.
Package backupexec holds the Kopia backup engine primitives shared by the `stackkit backup` CLI and the node-local StackAction endpoints.
Package backupexec holds the Kopia backup engine primitives shared by the `stackkit backup` CLI and the node-local StackAction endpoints.
Package backuphooks materializes its package-local database quiesce-hook contract (db-hooks.cue, embedded at build time) into the generated backup-hooks.json manifest, and gives the node-side backup engine a typed view of it.
Package backuphooks materializes its package-local database quiesce-hook contract (db-hooks.cue, embedded at build time) into the generated backup-hooks.json manifest, and gives the node-side backup engine a typed view of it.
Package backuplifecycle owns the local, owner-authorized backup lifecycle journal while delegating repository mechanics to a narrow runtime boundary.
Package backuplifecycle owns the local, owner-authorized backup lifecycle journal while delegating repository mechanics to a narrow runtime boundary.
Package backupplan builds the non-secret recovery plan emitted by `stackkit generate`.
Package backupplan builds the non-secret recovery plan emitted by `stackkit generate`.
Package clibinding binds local process dispatch to an explicit StackKit CLI from one build.
Package clibinding binds local process dispatch to an explicit StackKit CLI from one build.
Package cluster contains local cluster bootstrap primitives.
Package cluster contains local cluster bootstrap primitives.
Package composition resolves module dependencies and determines deployment order.
Package composition resolves module dependencies and determines deployment order.
Package config handles configuration file parsing and management.
Package config handles configuration file parsing and management.
Package confinedfs provides held-root, root-relative filesystem operations.
Package confinedfs provides held-root, root-relative filesystem operations.
contractgen
stackactiongen
Package stackactiongen generates StackAction Go and OpenAPI projections from the canonical StackKits CUE authority.
Package stackactiongen generates StackAction Go and OpenAPI projections from the canonical StackKits CUE authority.
Package crypto provides cryptographic helpers used by stackkit for password generation, hashing, and bundle encryption.
Package crypto provides cryptographic helpers used by stackkit for password generation, hashing, and bundle encryption.
Package cue provides CUE schema validation and Terraform bridge for StackKits.
Package cue provides CUE schema validation and Terraform bridge for StackKits.
Package docker provides Docker operations for StackKits.
Package docker provides Docker operations for StackKits.
Package errors provides standardized error handling for StackKit operations.
Package errors provides standardized error handling for StackKit operations.
Package executionchannelbundle verifies the short-lived, offline-authorized handoff into one exact StackKits execution channel.
Package executionchannelbundle verifies the short-lived, offline-authorized handoff into one exact StackKits execution channel.
Package federationbinding owns account-free local admission of opaque, externally realized Federation-link bindings.
Package federationbinding owns account-free local admission of opaque, externally realized Federation-link bindings.
Package federationcontrol binds the existing StackKits server to Home-issued Federation actions.
Package federationcontrol binds the existing StackKits server to Home-issued Federation actions.
Package generationartifact binds renderer outputs to one verified Architecture v2 ResolvedPlan.
Package generationartifact binds renderer outputs to one verified Architecture v2 ResolvedPlan.
Package hostconformance produces StackKits-owned, provider-neutral evidence about the host on which the probe is running.
Package hostconformance produces StackKits-owned, provider-neutral evidence about the host on which the probe is running.
Package hostpreflight observes a target host and admits or refuses a local Apply before it mutates anything.
Package hostpreflight observes a target host and admits or refuses a local Apply before it mutates anything.
Package iac provides a unified interface for IaC execution.
Package iac provides a unified interface for IaC execution.
Package identity provisions PocketID owner and break-glass accounts.
Package identity provisions PocketID owner and break-glass accounts.
Package identityprojection owns the credential-free desired identity projection accepted by a standalone StackKits installation.
Package identityprojection owns the credential-free desired identity projection accepted by a standalone StackKits installation.
Package kitio imports Git-owned stackkit.yaml definitions and generates reviewable CUE, Terraform, Docker Compose, and YAML artifacts.
Package kitio imports Git-owned stackkit.yaml definitions and generates reviewable CUE, Terraform, Docker Compose, and YAML artifacts.
Package kittemplates renders the per-kit OpenTofu/Terramate template trees from the single canonical source under foundation/templates/.
Package kittemplates renders the per-kit OpenTofu/Terramate template trees from the single canonical source under foundation/templates/.
Package lifecyclemutation owns the one local cross-process mutation authority shared by StackSpec authoring, generation, Apply, drift reconcile, and upgrade recovery.
Package lifecyclemutation owns the one local cross-process mutation authority shared by StackSpec authoring, generation, Apply, drift reconcile, and upgrade recovery.
Package lint implements `stackkit module lint` (ADR-0027 Decision 3, gates G1+G3): the deterministic module-hygiene checks that gate proposal PRs and tool-update PRs.
Package lint implements `stackkit module lint` (ADR-0027 Decision 3, gates G1+G3): the deterministic module-hygiene checks that gate proposal PRs and tool-update PRs.
Package localbackuppolicy owns the secret-free, generated contract between the Basement renderer and the native local backup lifecycle.
Package localbackuppolicy owns the secret-free, generated contract between the Basement renderer and the native local backup lifecycle.
Package localbackupruntime adapts the owner-bound local backup lifecycle to the fixed Kopia container runtime without retaining repository secrets.
Package localbackupruntime adapts the owner-bound local backup lifecycle to the fixed Kopia container runtime without retaining repository secrets.
Package localbackupschedule lowers the CUE-governed UTC backup cadence to a bounded pair of local systemd units.
Package localbackupschedule lowers the CUE-governed UTC backup cadence to a bounded pair of local systemd units.
Package localevidence produces Architecture-v2 pre-Apply evidence under the local homelab owner's own signing custody.
Package localevidence produces Architecture-v2 pre-Apply evidence under the local homelab owner's own signing custody.
Package localorigin realizes the node-local mTLS publication inside the existing StackKits server.
Package localorigin realizes the node-local mTLS publication inside the existing StackKits server.
Package localowner realizes and verifies the init-owned human identity in the local PocketID runtime without exposing its bootstrap credential.
Package localowner realizes and verifies the init-owned human identity in the local PocketID runtime without exposing its bootstrap credential.
Package logging provides structured deploy logging for StackKits CLI.
Package logging provides structured deploy logging for StackKits CLI.
Package managedentitlement is the fail-closed availability gate for publisher-tagged managed (S2/S3) StackKits surfaces.
Package managedentitlement is the fail-closed availability gate for publisher-tagged managed (S2/S3) StackKits surfaces.
Package netenv provides network environment detection and NodeContext resolution.
Package netenv provides network environment detection and NodeContext resolution.
Package operations validates and describes StackKits operation specs.
Package operations validates and describes StackKits operation specs.
Package placement resolves the S1 (StackKit-Standalone) capability bindings for a StackSpec.
Package placement resolves the S1 (StackKit-Standalone) capability bindings for a StackSpec.
Package platformdeploy contains the StackKit boundary for PaaS delivery.
Package platformdeploy contains the StackKit boundary for PaaS delivery.
Package pocketid is a thin HTTP client for the PocketID admin API.
Package pocketid is a thin HTTP client for the PocketID admin API.
Package productkits owns the active product allowlist used by CLI execution, discovery, and registry projections.
Package productkits owns the active product allowlist used by CLI execution, discovery, and registry projections.
Package referenceid contains the closed grammars shared by otherwise independent provider-free wire packages.
Package referenceid contains the closed grammars shared by otherwise independent provider-free wire packages.
Package registry exposes the StackKits catalog (tools, module versions, curated stackkits) to the CLI in an OSS-safe way.
Package registry exposes the StackKits catalog (tools, module versions, curated stackkits) to the CLI in an OSS-safe way.
Package resolvedplan compiles the Architecture v2 intent, immutable kit definition, observed inventory, and a governed contract catalog into the one deterministic plan consumed by later generators and runtimes.
Package resolvedplan compiles the Architecture v2 intent, immutable kit definition, observed inventory, and a governed contract catalog into the one deterministic plan consumed by later generators and runtimes.
Package restoreactivation derives and executes the fail-closed authority for promoting an owner-verified staged restore into the live Basement runtime.
Package restoreactivation derives and executes the fail-closed authority for promoting an owner-verified staged restore into the live Basement runtime.
Package rollout records rollout manifests and functional evidence.
Package rollout records rollout manifests and functional evidence.
Package runtimeapply defines the provider-neutral durable operation journal contract for a sealed runtimeexecutor Apply.
Package runtimeapply defines the provider-neutral durable operation journal contract for a sealed runtimeexecutor Apply.
Package runtimeexecutordispatch routes an already-authorized shared runtime request across exact opaque execution channels.
Package runtimeexecutordispatch routes an already-authorized shared runtime request across exact opaque execution channels.
Package runtimeexecutorprocess implements the account-free, digest-pinned standard execution-channel process boundary.
Package runtimeexecutorprocess implements the account-free, digest-pinned standard execution-channel process boundary.
Package runtimeexecutor defines the provider-neutral v1beta1 contract for executing already-authorized governed runtime targets.
Package runtimeexecutor defines the provider-neutral v1beta1 contract for executing already-authorized governed runtime targets.
Package runtimeobservation projects the CUE-owned provider-neutral runtime observation contract onto the standalone Go CLI and MCP surfaces.
Package runtimeobservation projects the CUE-owned provider-neutral runtime observation contract onto the standalone Go CLI and MCP surfaces.
Package scaffold renders module artifacts deterministically from a schema-validated module_facts.json (ADR-0027 Decision 1: "agents emit facts, a deterministic templater renders CUE").
Package scaffold renders module artifacts deterministically from a schema-validated module_facts.json (ADR-0027 Decision 1: "agents emit facts, a deterministic templater renders CUE").
Package securitybaseline renders the host security baseline script shared by legacy StackKit execution and architecture-v2 renderers.
Package securitybaseline renders the host security baseline script shared by legacy StackKit execution and architecture-v2 renderers.
Package servicecatalog normalizes StackKit service identity across CUE, the Admin registry snapshot, generated URLs, and kombify.me registration.
Package servicecatalog normalizes StackKit service identity across CUE, the Admin registry snapshot, generated URLs, and kombify.me registration.
Package servicecontrol owns the local, owner-approved desired state and bounded execution contract for StackKits-managed services.
Package servicecontrol owns the local, owner-approved desired state and bounded execution contract for StackKits-managed services.
Package ssh provides SSH operations for remote system management.
Package ssh provides SSH operations for remote system management.
Package stackaction contains the generated Go projection of StackKits' canonical CUE StackAction contract.
Package stackaction contains the generated Go projection of StackKits' canonical CUE StackAction contract.
Package stackspecadmission owns the release-policy boundary between the bounded StackSpec v1 compatibility minor and canonical Architecture v2.
Package stackspecadmission owns the release-policy boundary between the bounded StackSpec v1 compatibility minor and canonical Architecture v2.
Package stackspeccompletion binds a losslessly read v1 StackSpec to one complete, explicit v2 candidate and resolves it through the governed Architecture v2 service.
Package stackspeccompletion binds a losslessly read v1 StackSpec to one complete, explicit v2 candidate and resolves it through the governed Architecture v2 service.
Package stackspecintent owns the only first-party persistence contract for canonical StackSpec v2 intent.
Package stackspecintent owns the only first-party persistence contract for canonical StackSpec v2 intent.
Package stackspecmigration contains the bounded compatibility seam for the one-minor StackSpec v1 -> v2 migration described by ADR-0029.
Package stackspecmigration contains the bounded compatibility seam for the one-minor StackSpec v1 -> v2 migration described by ADR-0029.
Package standaloneoperations owns the public standalone lifecycle operation catalog shared by the StackKits CLI, MCP connector, and State Console.
Package standaloneoperations owns the public standalone lifecycle operation catalog shared by the StackKits CLI, MCP connector, and State Console.
Package system provides host system detection for StackKits.
Package system provides host system detection for StackKits.
Package telemetry contains opt-in runtime telemetry setup helpers.
Package telemetry contains opt-in runtime telemetry setup helpers.
Package terramate provides Terramate execution capabilities for Day 2 operations.
Package terramate provides Terramate execution capabilities for Day 2 operations.
Package tofu provides OpenTofu execution capabilities.
Package tofu provides OpenTofu execution capabilities.
Package validation provides 3-layer architecture validation for StackKits.
Package validation provides 3-layer architecture validation for StackKits.
Package verify implements post-deployment StackKit verification.
Package verify implements post-deployment StackKit verification.
Package windowstoken exposes the two process-token principals Windows uses for local custody: TokenUser receives the private DACL grant, while TokenOwner is stamped as the owner of newly created objects.
Package windowstoken exposes the two process-token principals Windows uses for local custody: TokenUser receives the private DACL grant, while TokenOwner is stamped as the owner of newly created objects.
Package workloadremoval preserves the pre-public internal import path.
Package workloadremoval preserves the pre-public internal import path.

Jump to

Keyboard shortcuts

? : This menu
/ : Search site
f or F : Jump to
y or Y : Canonical URL