Many planes.
One operational truth.
Multi-platform engineering, modular factories, publisher adapters, emulation targets, maintenance and evidence-based AI critique—all separated into explicit capabilities and verifiable states.
System planes
Independent surfaces, connected by bounded dependencies and policy gates.
Experience
experience
Open existing public module ↗Compute & Containers
compute
No public control surfaceHypervisors & Emulators
virtualization
No public control surfaceCross-Platform Compatibility
compatibility
Open existing public module ↗Models & Routing
inference
Open existing public module ↗Artifact Factory
factory
Open existing public module ↗Publishers & Releases
publishing
Open existing public module ↗Evidence & Telemetry
observability
Open existing public module ↗Knowledge & Provenance
knowledge
Open existing public module ↗Identity & IT Labs
identity
Open existing public module ↗Hygiene, Trimming & Backups
maintenance
No public control surfacePolicy, Tenancy & Security
governance
No public control surfaceCritique & Meta-Prompting
metacognition
Open existing public module ↗Schedules & DAGs
orchestration
No public control surfaceExternal Providers & Plugins
connectors
No public control surfaceResource, Quota & Cost Budgets
economy
No public control surfacePlatform & hypervisor matrix
A target is not an installed emulator. Each state reflects installed capabilities or declared intent.
| Platform target | Type | Observed state |
|---|---|---|
| linux-x64 | native | native-observed |
| linux-arm64 | cross-platform | declared-not-verified |
| windows-x64 | foreign-os | declared-not-verified |
| macos-arm64 | foreign-os | declared-not-verified |
| android | mobile | declared-not-verified |
| ios | mobile | declared-not-verified |
| browser | web | declared-not-verified |
| webassembly | portable | not-installed |
| qemu-tcg | emulated-cpu | not-installed |
| qemu-kvm | hypervisor | blocked-no-dev-kvm |
| docker | containers | unavailable |
| lxc | containers | cli-installed-not-proven |
/dev/kvm. Foreign operating systems require properly licensed and compatible remote runners, simulators or physical devices.Multi-publisher fabric
Publisher integrations are distinguished from working deployment channels.
local-stage
Internal distribution target.
existing-public-gateway
External publication requires approval.
gitea
Internal distribution target.
github
Internal distribution target.
vercel
External publication requires approval.
cloudflare-pages
External publication requires approval.
docker-registry
Internal distribution target.
static-cdn
External publication requires approval.
Factory & metacognition loop
Every improvement is specified, tested, critiqued and recorded before release.
These are defined workflow stages, not proof that autonomous AI agents have executed all ten steps.
Operations with boundaries
Status and compatibility metadata only. No root commands, credential stores or privileged APIs.
Scratch-only cleanup defaults to dry run. Eligible stale files move to quarantine, not permanent deletion.
Content-hashed local staging is operational. External publication remains permission- and provider-gated.
Prompt-generated claims never count as independent tests or provider execution receipts.