Keyboard shortcuts

Press ← or → to navigate between chapters

Press S or / to search in the book

Press ? to show this help

Press Esc to hide this help

Control plane, Managed runtime, and CLI

AHRI_TRE exposes stable JSON protocol envelopes through authenticated trust boundaries. Domain semantics belong in ahri_tre_types and ahri_tre_core, workflow orchestration in ahri_tre_app, configuration projection in ahri_tre_config, and physical dependencies behind adapter crates.

Web

The Web service selects one Application document at startup and receives an immutable Effective configuration plus narrow Secret capabilities. It owns browser HTTP sessions and the documented metadata/access-request surface. It does not accept runtime topology or credentials from requests or environment.

Trusted and Managed runtimes

The Trusted runtime bootstraps all service dependencies from Application configuration. The user-side Managed runtime selects one Client bootstrap and forwards protocol requests over authenticated HTTPS. It cannot discover an alternate endpoint, start a local Trusted runtime, or execute workflows locally.

Named Session metadata is safe, durable journal state. Live PostgreSQL and Lake handles remain process-local. After process loss, a persisted open record is closed and its owner-bound Managed-secret references are released through the authenticated internal reconciliation path; it is never reopened from a cache or plaintext recipe.

CLI and C ABI

The CLI and C ABI are thin clients over the same protocol. Their public output uses protocol DTOs and safe diagnostics. Arrow IPC carries binary tabular data, and Parquet is the persisted dataset format. Credentials, signed URLs, Restricted local references, and runtime handles stay outside public schemas.

The CLI schema registry remains available through schema list and schema get. Product startup rejects retired environment names before operational work. Repository-only DEV_ENV_ settings and isolated Integration fixtures are not product configuration.