Statecraft
OverviewProductsPapersRegistryDocsGet Started
spec-governedSign in

docs

Docs

Short, honest entry points into the family, each summarizing a repo's own specs rather than restating them. For the full picture, the specs are the documentation: browse them in the registry.

What is EnRaHiTu→

The single-container application chassis every stamped app is built from.

enrahitu · Apache-2.0·shipping
The template contract→

A versioned template.toml that binds what a stamped app is, and the agentic posture it is born with.

enrahitu · Apache-2.0·in progress
Self-hosting the control plane (AGPL)→

What AGPL-3.0 means for the plane, what you can run today, and what is on the ladder.

statecraft · AGPL-3.0·planned
StatecraftAGPL-3.0

the governed delivery control plane

enrahituApache-2.0

the EnRaHiTu template chassis (Encore.ts + rauthy + hiqlite + Turso)

statecraft-cliApache-2.0

the CLI and MCP server

spec-spineApache-2.0

the spec-governance toolchain everything above is governed by

tenant-emitApache-2.0

the tenant certificate emitter: signs a produced app's governance certificate

tenant-tailApache-2.0

the tenant certificate verifier: re-checks the factory's paperwork, no trust in the producer

action-gateApache-2.0

a pure, deterministic decision gate: evaluate(context, checks) returns Allow, Deny, or Degrade

attest-ledgerApache-2.0

a tamper-evident record ledger: append-only, hash-linked, Ed25519-signed, with an independent verifier

canonical-keysort-jsonApache-2.0

deterministic canonical JSON: a lexicographic key sort at the serialization boundary, so record hashes agree

trust-windowApache-2.0

a rolling-window trust scorer: weighted samples map to a graduated privilege level

governed by spec-spine
RegistryGitHubStatic, spec-governed, no tracking.