kbd-runtime
substrate/kbd-runtime is the canonical workflow-authority library shared by
prometheus kbd and Sovereign Sync.
Responsibilities
- immutable
.prometheus/project.jsonidentity; - signed and hash-chained canonical events;
- deterministic
KbdStateV2replay; - lifecycle, checkpoint, plan, phase, stage, change, and task transitions;
- independent completion dimensions;
- decisions, blockers, and device trust;
- command idempotency and optimistic revisions;
- exclusive journal transactions and idempotent command replay;
- atomic compatibility projections;
- legacy-ledger migration with checksummed backups;
- non-authoritative shadow/canary rollout evidence.
Security primitives
Events use canonical JSON, SHA-256 hash chaining, and Ed25519 signatures.
Interactive runtimes use the supported platform credential store; headless
services require an explicit mode-0600 device-key file. The optional
loopback-TCP bearer token is a separate project-scoped secret. The default
local transport is a same-user Unix-domain socket.
Canonical runtime
The repository stores only the immutable project manifest and compatibility projections. The event journal, locks, token, deferred hooks, and consensus storage live in the platform application-data directory under the project UUID.
Public interfaces
The crate is not normally called directly by an operator. Use:
prometheus kbd --path "/path/to/project" status --json
or the Sovereign Sync REST/MCP surfaces.
Detailed runbooks:
Canonical source:
substrate/kbd-runtime.