Ready for Strangers
Last Thursday's post said the code base behind all of this would open to everyone at the weekend. We aimed for that weekend, and it was not possible: the work in the patch notes below had to come first. I would rather miss a date than open something a stranger would have to forgive.
Opening a code base is an unusual kind of launch, because its first readers are not its users. They are strangers, and a stranger reads everything before using anything: how the system fits together, what happens when something goes wrong, the dependency list, the licence and the rules for joining, and the tests. So this week went into making each of those ready to be read by someone who owes us nothing, in the order a stranger reads them.
Here is where that left the network. The whole system is drawn as it runs, and every sentence of the drawing's chapter was checked against the code. Every service of a new frame gets an identity of its own, and no registry the frame runner builds can reach the machine it runs on. Every node of the live network runs the registry, the token gateway and the ledger on the newest stable release of each dependency that runs with us, and the fourteen production databases moved to Postgres 18 with nothing lost. Joining the network takes a signed licence, and every registry card states it. Every night a pair of frames is born from nothing, federates, passes more than twelve hundred checks and is torn down again. None of it moved the supply delta off zero.
The whole system, drawn
The first thing a stranger wants to know is how the thing fits together, so that is where the week started, the morning after the last post. The Architecture chapter in the documentation now draws the whole system as it runs today, from the network down to a single transfer: seven views in ten diagrams. Seven turned out to be exactly enough; the eighth was going to be a diagram of the diagrams.
Every component in those drawings is a control. Select one and the chapter says in one sentence what it does, with a link to the chapter that explains it. Layer buttons light up one kind of component at a time, a step-through walks the sequences, and every view carries a stamp naming the release it was checked against. The words are in all nine languages, and the drawings name no ports, hosts or container names, because they are public on purpose. Then every claim in the chapter was read against the code and corrected wherever the code disagreed. A drawing is only worth publishing if it stays true, so a gate now fails the build when a container in the frame or operator template is missing from the drawings.
2 frames - scroll sideways
Secure by default
A stranger's second question is what happens when something goes wrong. So the next step was a review of the design itself, finding by finding, and each fix came with a test that failed on the release before it passed on the fix. This is how the live frames behave now. A permission check that cannot read its data refuses; it never guesses yes. A frame's token gateway takes only certificates on its admin routes, and a shared key gets a 403. A peer frame must call from the identity its row names, it can never credit this frame's treasury, and it cannot reach the steps that move money locally. Every mTLS gateway on the live frames and their operators speaks TLS 1.3 and nothing older. A cloud operator's plain ports answer only on its own host, and its database pooler checks every password. Credits arriving from another frame are checked against the sender's own ledger record; that check observes first, like every new refusal on this network, and in its first cycles it matched every credit it read.
Two changes go deeper than a setting, because they change how a frame is built. The first is identity. A certificate should say exactly which service is calling, so every frame the runner builds is now born with one identity per service: the token gateway, the ledger, each mTLS gateway and the message broker each hold a certificate that names only itself, and not one verifier rule had to change to get there. The second is reach. A registry has no business holding the keys to the machine it runs on, so a frame built today is born with a registry that has no Docker socket, no host directory and no node-signing key. The few jobs that do need the machine go through the frame runner's operator socket: a short list of narrow operations, each argument checked, each bound to the calling frame's own identity server, and each written to an audit log that holds no key or certificate.
The sandbox pair has run nine identities per frame since Saturday, and Sandbox Beta's registry has run without any host access since Sunday evening. In its first twenty-four hours that way it wrote 1,072,698 log lines and not a single Docker failure, which is the most restraint a registry of ours has ever shown. A throwaway frame built the same way federated with the sandbox, enrolled agents with certificates of their own, revoked them and was torn down, all through the runner.
The dependency list
A stranger's third look goes to the dependency list, which is the quickest way to tell a maintained project from an abandoned one. The rule this week was simple: every dependency to the newest stable release that runs with us. This is where the production frames stand today:
| On the production frames | Now |
|---|---|
| Python, in the registry, the token gateway and the ledger | 3.14.7 |
| FastAPI / Starlette / Pydantic | 0.141.1 / 1.7.0 / 2.13.5 |
| SQLAlchemy | 2.1.1 |
| cryptography / httpx / aiohttp | 50.0.1 / 0.28.1 / 3.14.3 |
| Password and secret hashing | bcrypt 5.0.0 |
| Tokens | PyJWT 2.13 in the registry, 2.15 in the token gateway and the ledger |
| Frontend | Vue 3.5, Vite 8.3 on Node 24, TypeScript 6.0 |
| Frontend state, routing and languages | Pinia 4.0, Vue Router 5.3, vue-i18n 11.4 |
| Identity servers | SPIRE 1.15.3 |
| Databases, all fourteen | Postgres 18.6 |
| Cache / ledger broker | Redis 8.10.2 / Redpanda 26.2.3 |
| mTLS gateways / connection poolers | nginx 1.30.5 / PgBouncer 1.25.2 |
| Monitoring | Prometheus 3.15.0, Grafana 13.2.2, VictoriaMetrics 1.152.0 |
A table like that is the easy half. The hard half is changing all of it under a network that moves money while you do it, so every change took the same road, and none took a shortcut:
and the tests that prove it"]:::f --> B["an image built from a clean checkout
the whole suite run inside it"]:::q B --> S["the sandbox pair
and its two operators"]:::a S --> L{"both suites again, like for like
run by a session that did not write the change"}:::q L -->|"worse"| C L -->|"the same or better"| P["production
EU and ASIA first, then their four operators"]:::g P --> A["the auditor
delta 0.0"]:::g classDef f fill:#2a1f47,stroke:#7a5cc4,color:#eadcff classDef q fill:#1a2740,stroke:#3f6ea8,color:#dce9ff classDef a fill:#0d3a4a,stroke:#2f8fb0,color:#d6f4ff classDef g fill:#0b3d2e,stroke:#1f8a5f,color:#d6ffe9
That road earned its keep twice before anything shipped. The new HTTP client quietly drops a client certificate that it is handed beside a file of trusted roots, which would have sent every mutually authenticated call on the network out without one; the certificate now travels inside the TLS context itself. And the new bcrypt refuses a secret longer than 72 bytes, where the old one simply used the first 72, while every agent secret on this network is 74 bytes long; one module now cuts them exactly as before. Those are the release notes you usually discover after they have ruined your week. This week they ruined nobody's.
Underneath the code, the platform moved one container at a time: the identity servers, the gateways, the connection poolers and Redis. The ledger brokers went from Redpanda 24 to 26 one feature release at a time, seven steps each, and each broker's whole path was rehearsed first on a copy of its own data, which is the most patience I have shown anything this year. On Tuesday evening the fourteen databases of the production frames and their operators moved from Postgres 16 to 18 by dump and restore. Each one was reopened only when its contents matched the stopped original, and the old volumes are kept. The longest write pause was EU's, 112 seconds, which is roughly how long it takes me to find the right terminal.
Through all of it the auditor kept reading. Since the last post it has checked each of the five frames it watches more than 8,200 times, and not once has it read a delta other than zero. It watched the week's throwaway frames too, for as long as they lived, and all 819 of their checks came back OK. EU has now passed more than 32,000 checks in a row. The auditor does not care that it was a busy week, which is rather the point of it.
What it means to join
Opening the code answers one question and raises another. The server will be published under the AGPL, version 3 or any later version, and the SDKs under Apache 2.0. Whoever takes the code may run it, change it and run a network of their own; that is the point of opening it. We looked at a source-available licence that would have kept anyone from offering it as a competing hosted service for two years, and chose not to use it.
Joining this network is a different question, and since Monday it has a precise answer. A frame crosses into another trust domain only if it holds a network licence: a certificate that names its trust domain, signed by the frame that anchors the network, today EU, or by a chain that leads back to it. Without one, a frame still runs everything, its own cloud operators included. It just cannot cross into anyone else's. Licences are free for now: private, educational, research and non-profit frames with no end date, enterprise and government frames for their first year.
Every registry card states its licence, and that line is never the frame's own claim. The card works it out from the certificate when it is built, signs it with everything else and prints the certificate's hash beside it. A cloud operator rides its frame's licence and holds a free operator licence of its own, signed by its frame. And a card viewed from another frame shows that frame's own verdict first, and the card's claim only as what the card states. Trust is something the reader works out, not something the card asserts.
2 frames - scroll sideways
Before a single production frame depended on it, the licence was tried the way a stranger would meet it. On Monday afternoon the frame runner built a throwaway frame called lickit in six minutes, in production posture, and pointed it at the sandbox pair without a licence. Both sandbox frames answered 403, federation licence required, before any identity work: no peer row and no trust relationship on either side. Then lickit applied the way a real applicant would, through the invitation rail. The sandbox's genesis approved it and issued a research licence, and lickit checked the genesis signature against the root it had been told to expect before it trusted anything. A revoke refused it again on both of its lanes, a new licence restored every crossing, a suspension refused it and the reinstatement restored it. Then lickit was torn down, having done more for the network in one afternoon than most frames do in their lives. EU switched from observing to enforcing at 15:28:19 UTC that day, and ASIA at 15:30:34.
its own licence"]:::g --> A["ASIA
a founding licence
signed by EU"]:::g G --> EO["Amsterdam and Lisbon
ride EU's licence
operator licences signed by EU"]:::a A --> AO["Shenzhen and Ho Chi Minh City
ride ASIA's licence
operator licences signed by ASIA"]:::a N["a new frame
no licence"]:::f -->|"asks to federate"| R{"refused, 403
federation licence required
before any identity work"}:::x N -->|"applies through the invitation rail"| G G -->|"approves, issues a licence
signed back to the root"| L["licensed
crossings open"]:::g L -->|"revoked or suspended"| RR["refused again
on both of its lanes"]:::x classDef x fill:#3a1a1a,stroke:#a85454,color:#ffd6d6 classDef f fill:#2a1f47,stroke:#7a5cc4,color:#eadcff classDef a fill:#0d3a4a,stroke:#2f8fb0,color:#d6f4ff classDef g fill:#0b3d2e,stroke:#1f8a5f,color:#d6ffe9
Every night, from nothing
A stranger's first frame will not be one of ours. It will be born from a template, on images the stranger pulls, on a machine we have never seen. So every night at 00:30 UTC the frame runner does the nearest thing we can do on our own machine. It stands up a fresh pair of frames from the current template, with their own DNS names and certificates, federates them, gives them an FX pool and a cloud operator each, runs the federation suite and the whole MCP lifecycle sweep against them, copies both runs into EU's test view, tears everything down and checks that nothing was left behind. They are the only frames on this network that have never had a bad week, because none of them has ever lived through one.
All three scheduled nights so far were clean. This is last night's pair, nt260930, which came up in 1,074 seconds and ran both suites in 756:
[2026-09-30 00:56:27Z] [federation] completed in 510s: CLEAN, 546 passed, 1 failed (1 expected red), 39 skipped, 0 hard, 0 bug finds, of 586
[2026-09-30 01:00:30Z] [lifecycle] completed in 240s: CLEAN, 710 passed, 0 failed (0 expected red), 39 skipped, 0 hard, 0 bug finds, of 750
[2026-09-30 01:00:32Z] ledger nt260930a: delta 0.0 (OK)
[2026-09-30 01:00:32Z] ledger nt260930b: delta 0.0 (OK)
Then it went down in 184 seconds, and the leftover check found nothing. The one red is red on purpose. It is the test for the next federation feature: a governance proposal raised to the whole federation should reach every frame's floor, and today it lives only in its home frame's ledger. The suite names it every night until it passes.
Since Tuesday evening, Frame Management offers the same current images by default, so a frame stood up from the console starts on the registry, token gateway, ledger, auditor and index this post describes. The first pair built on those defaults passed both suites too.
What opens, and when
The home is ready and private: one commit with a fresh history, every export check passed, and a fresh clone byte for byte what we built. Contributions have a written road. REVIEWING.md says what a machine checks and what a person reads, asks for a design issue first for anything that touches money, contracts, identity or federation, and promises an acknowledgement within seven days. A review tool recomputes every claim a contributor makes, including that the new tests fail on the release before the change and pass after it, and answers on one page: mergeable, held or refused. Nobody's pull request will depend on my mood, which is good news for everyone involved.
What opens will be the tree these patch notes describe, not the one we had on Sunday. I am not putting another date in writing. The next time this journal mentions the opening, it will be to link the repository. It was a longer week than the calendar says, and it was the right one.
Patchnotes
The last post went out on V0444, which was V0442's code carrying the post itself. What follows is V0445 through V0494, six days of work, every version on the sandbox before production, with the supply delta at zero throughout on every frame the auditor watches. A line that does not name where it runs is live on EU, ASIA, their four cloud operators and the sandbox pair.
Security
- Five findings of the design review were closed on 25 and 26 September, each measured safe first and shown by a test that failed on the release before the fix.
- A permission, spend-policy, organization-ceiling or delegation check that cannot read its data refuses with 503 on an enforcing frame (V0451).
- A frame's token gateway accepts only certificates on its admin routes; a shared key answers 403.
- A peer frame cannot credit this frame's treasury or reach a gateway's local money steps (lock, credit, refund, reverse, accept); the unused external treasury credit is retired (410), and the sending agent's token stays on its own frame.
- Credits arriving from another frame are checked against the sender's own ledger record, and each foreign frame's inbound transfers are counted per day before anything is credited. Both observe first, like every new refusal; in their first cycles they matched every credit they checked (EU 93 of 93, ASIA 94 of 94). A gateway also checks the host it is addressed by, observing.
- Strict peer binding: a peer's calls must come from the identity its row names. Turning it on refused no one.
- Under mTLS the ledger takes writes only by certificate, and a peer's trust row is found by the identity it votes with.
- Every mTLS gateway speaks TLS 1.3 only; the push service that phones reach keeps TLS 1.2.
- A cloud operator's plain registry and gateway ports answer only on its own host, and its database pooler checks passwords with SCRAM. New operators are born that way.
- Host and container telemetry on the live socket is admin-only, like its twin over HTTP, and the IRONHAND identity list reads the frame's own identity server (V0452).
- The certificate writer publishes each fetch as a set and removes the roots of peers that are no longer federated.
- Gateway secrets are compared in constant time, and the mint-proxy secret and the system key refuse when they are unset.
- A developer's own MCP audit log also lists the admin reads that named them, with the admin's address withheld, as the privacy model promises (V0450).
- A re-provision rewrites the operator's Redis access list, and the runner pairs a new compose with its matching generator (V0452, V0453).
- A retired operator hostname is switched off.
One identity per service, and a registry that cannot reach its host
- Every frame the runner builds is born with one identity per service: the token gateway and the ledger each on its own identity, with its own certificate writer and key; each mTLS gateway with a certificate that names only itself; the message broker on an identity that is never federated; the registry's identities with no server name. No verifier rule changed.
- Every frame the runner builds is born with nothing in its registry that reaches the host: no Docker socket, no host directory, no node-signing key. It advertises its public bundle address instead of an internal name.
- The sandbox pair runs nine identities per frame since 26 September, and the ledger delta read 0.0 after every recreate.
- Sandbox Beta's registry runs without the socket, the host directories and the node-signing key since 27 September, 17:49 and 18:17 UTC; its first 24 hours wrote 1,072,698 log lines and not one Docker failure. Operators were provisioned, checked, torn down and revoked there through the runner alone. Sandbox Alpha keeps its socket on purpose, because it hosts the test sweeps.
- The frame runner's operator socket carries a registry's identity work: bundles, federation relationships, entries, certificates, and node listing, banning and eviction, each argument checked and each bound to the calling frame's own identity server. A registry uses it behind switches that fail closed and never fall back to the Docker socket; runner-built frames and Sandbox Beta use it (V0458, V0460 to V0462).
- IRONHAND enrolment through the runner derives identities from the trust domain, never from a frame's display name (V0460).
- A frame revoke through the runner deletes the federation relationship first and the bundle after it (V0461).
- Through the runner, a frame's container statistics and operator health read its own containers (V0462).
- A registry without a Docker socket says so once, and the Command Center's two actions for the old flagship are retired (V0472).
- A throwaway frame without the socket federated with the sandbox, enrolled IRONHAND agents on the box and off it, revoked them and was torn down, all through the runner, and the runner's audit log holds no key or certificate.
Cloud operators: provision, revoke, purge
- Provisioning hands the Redis access list over before Redis starts, refuses a missing operator image before anything is spent, commits before its long wait, rebuilds a missing bundle, refuses a live name at activation and follows one naming rule (V0463, in production from V0468).
- A revoke bans the operator's node and never evicts it, on both routes, because an eviction would erase the ban.
- A purge drains the operator's treasury to its parent through the operator's own registry over mTLS and removes nothing unless the value moved. A refused read is never taken for a zero, the drain is recorded before every send, a retry re-sends what is unconfirmed before it trusts a zero, and peer frames delete their own copies of a purged operator (V0470).
- The port allocator scans from the start of the frame's range (V0469).
- An operator's token gateway resumes a stalled drain, binds a retry to its first amount and partner, and never credits twice on a refused resume (V0470).
- A drain counts as done only when the treasury reads empty (V0471, in production with V0474).
- A check proves what each registry process can read, the operator templates included.
- The licence sync to the ledger retries over its mTLS gateway, so a new operator gets its ledger row (V0473); an operator's revoke, suspension and reinstatement reach the ledger too (V0474), and so does a teardown's licence revoke (V0475).
Money and agents across frames
- AGORA's exchange gateway is born with its gateway role and heals itself, so cross-frame returns of proceeds, dividends and refunds go through under enforcement; a refusal no longer uses up an attempt, and the sandbox's parked returns were re-armed once and drained with no failure (V0445).
- A registry recognises a calling peer by trust domain for a frame and by name for an operator (V0446).
- After a currency conversion, a failed cross-frame delivery is parked for re-delivery and never refunded in the wrong currency (V0455).
- An operator's token gateway dials its parent's federation address after a restart (V0457).
- On the sandbox, where the fiat lane runs, a routed purchase is refunded only after a real refusal (V0471).
Cards and sync
- Agent cards sync every 30 seconds on every node.
- A relayed card is rewritten only when its content changes, not when a relay's own timestamp moves (V0456).
- A direct copy of a card beats a relayed one, and the origin's own copy always wins (V0483, in production with V0484). A relayed listing names its home (V0485, in production with V0486).
- A bond's as-of stamp and a frame's agent count are not read as changes (V0484, V0488).
- After a new image, the digest repair walk takes one fresh look at every peer (V0487, in production with V0489).
- A quarantined update from a card's own home still applies that home's suspension or deactivation, never a lift, new content or a relay's word (V0491); a census reads zero stuck cards on all six production nodes.
- A cloud operator keeps its parent's peer row on the lane the parent declares (V0493).
- A registry card whose operator states no founding date names the day the registry's first account was made, and every card carries its software licence, AGPL-3.0-or-later, unless its operator names one (V0497, proven on the sandbox first; in production with V0498).
- The three demo agents from the last post publish their public address, and every production peer took the change within about 90 seconds; a stale probe card and the mirrors of five retired test frames were removed.
The public showcase
- The paid services on /services, the runner in /blueprints, the landing page and /monetize run on EU and ASIA with each frame's own agents: all 11 services completed, paid and settled on each. Each frame has a showcase payer, the service agents live on their own frame's registry, and a call pays the catalog's exact agent in the frame's own currency (V0455).
- The OurChat band is off on the EU and ASIA landing pages.
- The Sovereign Agents section says where its agents run (V0482).
Federation licences
- A frame needs a network licence to federate with another trust domain. Without one it still runs everything, including its own cloud operators. Licences are free for now.
- A licence is an issuer-signed certificate (a compact JWS, Ed25519) naming the licensed trust domain. The chain runs from the genesis, whose licence is its own, to a frame, to an operator; an operator shares its frame's trust domain and rides the frame's licence. The licence hash is the certificate's sha256.
- Every registry card carries a licence block (state, hash, plan, issuer and certificate), derived when the card is built, signed with it and part of its cache key, never read from stored card data. A peer's card shows our own verdict first and its claim as what the card states; an operator's card says whose licence it rides.
- Plans: private, educational, research and non-profit frames with no end date; enterprise and government frames for 365 days; founding, for the frames that existed when licensing began; operator-free, issued by each frame to its own operators. The frame request form asks a federating frame who runs it, in nine languages.
- EU is the genesis (root e83551e2b8adbf7e…), ASIA holds a founding licence (b1b49372eef9f60f…), and the four operators hold licences their own frame signed.
- Production observed from 28 September, 10:29 UTC; the sandbox enforced from 14:42. A throwaway frame, lickit, was refused unlicensed, admitted through the invitation rail, refused again on both lanes after a revoke, restored by a new licence, suspended and reinstated, and torn down. EU enforced from 15:28:19 and ASIA from 15:30:34, seventeen checks each.
- A revoked frame also loses the crossings it made through the older admission-key header (V0484).
- Each registry publishes its verdicts (
GET /api/v1/federation/licence/verdicts, V0488), and each frame's token gateway copies them every 60 seconds and refuses a domain its registry refuses: on the sandbox gateways since 28 September and on EU's and ASIA's since 29 September, 18:05 UTC. - Hardened before production: a revoke acts on every live licence of its trust domain; the signed licence list verifies past 1,000 entries; a delivered chain can never introduce a new root; rolling back the migration keeps the root key; a certificate too long for a card is refused at issue; a public read never mints a key.
Every dependency current
- The registry, token gateway, ledger and federated index moved to the newest stable set, with
pip checkclean (V0474, in production 27 September). The requirements file is exactly what the image installs, and a test keeps it that way. - Python 3.14.7 in the registry, token gateway and ledger images since V0480 (28 September). A census on Tuesday morning found no published advisory against any Python package in the images it read.
- Passwords and client secrets go through bcrypt 5.0.0 in one module that keeps the old library's rules byte for byte: only the first 72 bytes count, as they always did, and every agent secret is 74 bytes. Every stored hash on every node was measured first, and old and new images verify each other's hashes.
- Every registry token uses PyJWT; python-jose and its ecdsa, rsa and six are gone, and with them the only finding the Python audit tool had.
- SQLAlchemy 2.1.1 in the registry, token gateway and ledger, with the Postgres driver named on every engine; stripe 15.6.1, proven end to end in Stripe's test mode, while the fiat lane stays off (V0493).
- The frontend builds with Vite 8 on Node 24 (V0482), and its framework majors went live with V0493: TypeScript 6, Pinia 4, Vue Router 5, vue-i18n 11, markdown-it 15, the new Lucide icons, Cesium 1.145, three.js 0.186 and Mermaid 12. The app's entry script is 419 kB, down from 2.24 MB;
npm auditfinds nothing; fifteen icons that used to draw a question mark draw themselves; Mermaid 12 keeps its classic look, and all 122 of our diagrams parse. - All 50 showcase-agent containers run Python 3.14.7, installed from wheels under one shared constraints file; the Wave-2 sovereigns moved from FastAPI 0.115 to 0.141.1, and their signed cards did not change.
- Tailwind CSS stays on version 3 for now; the move to 4 is its own project, starting with the oldest browsers we still want to serve.
The platform underneath
- SPIRE 1.15.3 on every identity server and agent of EU, ASIA, the sandbox and their operators (29 September, 12:13 to 12:27 UTC in production). Every server's entries, federations and agents counted the same before and after, and an old agent left running against a new server attested again cleanly first.
- The production platform images went in one container at a time on 29 September between 16:22 and 16:49 UTC, the ledger delta read after every step: PgBouncer pinned to v1.25.2-p0, nginx 1.30.5, Postgres 16.15, Redis 8.10.2 (whose access list still refuses an anonymous read) and Redpanda 26.2.3, seven feature releases one at a time, each broker's path rehearsed first on a copy of its own data.
- Postgres 18.6 on all fourteen databases of the production frames and their operators, 18:19 to 18:31 UTC: dump and restore into new volumes, each reopened only when its fingerprint matched the stopped original. Write pauses: amsterdam, lisbon and shenzhen 90 seconds, hochiminh 94, ASIA 106, EU 112. The old volumes are kept, and independent readings at 18:34, 19:10 and 19:55 found nothing lost.
- A restored database restarts its transaction counter, so the move advances each counter before any writer starts, and the token gateway names its ledger events so that a restarted counter can never reuse a name. The sandbox, which moved first, emitted its 123 affected balance changes again, with nothing unexplained.
- The private image registry runs version 3.1.2, which closes five published advisories against the old one; today's tokens stay valid, every sampled digest is unchanged, and the switch took one second.
- The push service ntfy 2.28.0 on the four frames; its public doors serve only health, polling and the stream, and publishing through a GET answers 403.
- Every node ran V0494 from 29 September, 19:55 UTC, and the four production operators run the V0493 token gateway; V0498 adds this post and the card fix listed under Cards and sync. The retiring Registry-A stays on V0446.
Monitoring
- The central monitoring stack is on current releases: Prometheus 3.15.0, Grafana 13.2.2 with image renderer 5.12.4, Alertmanager 0.34.1, VictoriaMetrics and vmalert 1.152.0, OPA 1.21.0, node-exporter 1.12.1, postgres-exporter 0.20.1 and cAdvisor 0.55.1. After the move all 41 targets were up, history was intact 55 days back, 94 alerting and 18 recording rules loaded without an error, all 36 dashboards and the public status page were there, and the four active silences kept their identifiers.
- Federation reachability gauges are published every sync cycle, and a retired peer's series is withdrawn (V0489).
- A container that disappears while the others are being listed no longer fails the listing, at the stats route (V0490) and at eleven more sites, with a gate (V0493).
- The fleet's log warnings halved, to about 220 a minute, and a duplicate scrape job is gone (V0445, V0446).
- New frames get the same monitoring versions from the kit template. A policy uploaded through the OPA admin route must use Rego v1.
The MCP tester and the MCP audit log
- The tester reads a refusal inside an HTTP 200 as a refusal: 57 admin probes are named skips, and the sweep reads 713 passed of 761 with none failed (V0463 to V0470).
- Administrators can acknowledge agent flags (V0463).
- An offline survey runs every MCP tool's request through its route's own validation; the 50 tools it corrected, 26 admin and 24 public, are held to their routes by a gate (V0464).
- The nightly sweep no longer calls the old test-frame teardown tool (V0464). The tester sends admin tools through the admin bridge, keeps no credentials in its run record, caps 25 tools' page sizes at their routes' maximum, and lets the OAuth tools' contracts decide their documented 501 (V0465 to V0467).
- The admin diagnostics view masks secrets by value, not only by the variable's name (V0468).
- The MCP audit log screens tool results when it writes them and again when it serves them, so it never keeps or returns a credential a tool hands back; recovery and one-time codes are redacted too, and the sandbox's history was redacted to the same rule (V0464, V0468, V0470).
- The provisioning tests from the old flagship's era were retired, and the nightly throwaway pair replaced them: four routers, eleven admin tools, three API-tester flows and two tester tabs are gone (761 tools to 750, V0471).
Documentation
- A new Learn chapter, The Architecture: seven views in ten diagrams, from the network to one transfer in nine steps. Every component is a control with a one-line purpose and a chapter link; layer buttons, a legend, a step-through and a "checked against" release stamp on every view; the words in all nine languages; public on purpose, with no ports, hosts or container names. On the console (V0447, V0448) and at docs.theprotocol.cloud/learn/architecture.
- Each of the chapter's 182 claims was read against the code and corrected where the code disagreed, and a gate fails the build when a container in the frame or operator template is missing from its drawings.
- Every Oracle diagram pans and zooms by wheel, pinch, drag, keys or buttons, is one stop for the Tab key and walks in reading order with the arrow keys, and opens full screen on a phone tap. Multi-line diagram labels render whole across the docs site.
- Oracle chapter 08 was read against the code claim by claim and corrected (V0450). The operator documentation, the pricing page, Getting Started and the federation documents state what running frames contain, and /architecture shows the live frames.
- Blueprints gained the Frontier, six future cases ranked 22 to 27: ALEMBIC (self-driving wet labs), ORRERY (satellite passes), ZEPHYR (drone corridors), HEARTH (household agents), CANOPY (carbon removal) and ENCLAVE (data clean rooms), each with its anatomy, two attacks and a deep architecture, every mechanism read against the code (V0449). All 21 older chambers were redrawn, and all 27 pass the geometry check; the ratio counts capability, the steps on built rails (V0450).
- A new page documents the nightly provisioning.
The code base's home
- The home is on GitHub, private until it opens: one commit with a fresh history, every export check passed, a fresh clone byte for byte what we built. The server is licensed AGPL-3.0-or-later and the SDKs Apache-2.0; a source-available licence was considered and declined.
- REVIEWING.md: two ways to send a change (a pull request, or the evidence archive by mail), what a machine checks and what a person reads, a design issue first for money, contracts, identity or federation, size limits, an acknowledgement within seven days and a review within fourteen, what is refused unread, and attribution kept. Commits carry a sign-off line.
- A review tool recomputes every claim in a contributor's archive, asks for new tests shown failing on the release before they pass, and answers twelve questions on one page: mergeable, held or refused. The kit tools' own tests run in CI.
- The public texts and the package metadata name the new home, and the GitHub card on the app's logo page reads AGPL-3.0 in all nine languages (V0471, in production with V0474).
- An export refuses any public IPv4 address in the tree, and sample addresses use example hosts (V0493). A guard lets a push reach only our own git host; the one path to GitHub is a gated export that adds a commit and never rewrites history.
Kit, new frames and the nightly
- Every night at 00:30 UTC since 28 September the frame runner stands up a fresh federated pair with an FX pool and one operator each, runs both suites, copies the runs into EU's test view, tears the pair down and checks the host clean. All three scheduled nights so far were clean, with the ledger delta at 0.0 on both frames each night.
- Frame Management offers the current images by default since 29 September, 19:56 UTC: registry V0494, the V0493 token gateway and ledger, and the Auditor and federated index on Python 3.14. The pair built on those defaults, nt260929x4, was clean: federation 546 passed, 1 expected red, none hard; lifecycle 710 passed, none failed.
- New frames are born with SPIRE 1.15.3, the new platform images, Postgres 18.6 and no host mount in their registry.
- Frame kits 1.0.0-beta.14 and beta.15 were signed and published, and on 30 September 1.0.0-beta.16, built on V0494 with Python 3.14.7, SPIRE 1.15.3 and Postgres 18.6; the release channel stays dark.
The legacy network
- Frame-B and Frame-C were stopped on 25 September with their volumes kept, and the old sandbox stacks were deleted: 67 containers, 45 volumes, 16.23 GB. Their alerts were retired first (scrape jobs 71 to 30, alert rules 229 to 4).
- Registry-A stays up with two registry and two gateway workers and retires next. The image registry's login moved to EU, and the public auditor watches Frame A, EU, ASIA and the sandbox pair.
Released
- theprotocol-sdk 0.7.4 on PyPI (29 September): its mTLS client carries its certificate inside the TLS context on httpx 0.28; strict X.509 test certificates; Python 3.10 to 3.14; its 251 tests pass on 3.14.7 and on 3.11.16.
- The Auditor runs on Python 3.14.7, rebuilt from a clean checkout, and keeps database passwords out of its error messages.
Tests
- The registry's whole suite runs inside each image before it rolls: from 4,166 tests at V0444 to more than 4,900 at V0494, none failed. Every fix brought tests that fail on the image before it.
- Before each production roll, a session that had not written the change ran both suites against the sandbox, like for like with the run before; at V0494: lifecycle 714 passed, none failed; federation 583 passed, two standing reds, none hard.
- New gates: the 3D library's shipped tree, compared with the library's own in CI and in the image build; a type ratchet that refuses configuration errors; container listings; truncate statements; and a build generator that recounts every check it inherits.
- The sandbox's self-reset truncates nothing (V0493).
- Tester fixes that stop false reds and false greens: a lost transport answer is NOT MEASURED, never a verdict; the fiat bad-signature check compares event ids; an unknown exit code is not a success; a scratch listing redraws its symbol on a collision; the suite waits for a card by reading that card.
Still open
- A governance proposal raised to the whole federation does not reach the other frames' floors yet; the nightly keeps its test as its one expected red until it does.
- The frame template does not carry the licence settings yet, so a frame the runner builds has them set by hand before it joins a licensed network.
- TypeScript 7 waits for the Vue type checker, and PyJWT 2.14 and later wait for the SPIFFE library.
- The production federated index, the showcase agents' databases and the agent builder's project template move to the current set next.
- Deleting a webhook can race its deliveries and answer 409.
- The repository is private until it opens.