Skip to content

5. Building Block View

This view describes the named application from outside, then opens its logical boundaries. The blocks are responsibilities defined by accepted ADRs, not prescribed packages, processes or separate servers.

As a black box, the application lets people and approved agent clients discover and invoke the same declared commands. The CLI owner supplies trusted implementations and configuration; extension authors supply independently verified releases. People and external services are participants and dependencies, not internal components. ADR-0007, ADR-0010, ADR-0013

BoundaryExternally visible responsibility
CLI and optional MCPPresent approved commands, validate input and return the finalized outcome through the selected interface
Extension supplyDiscover approved releases, verify their declarations and artifacts, and activate a complete command generation
Identity and protected resourcesUse selected owner integrations and current authority; installation and listing do not grant access to every action
ExecutionOwn each foreground call, its declared environment and supported restrictions, cancellation and cleanup

These responsibilities are common to the local baseline and integrated configurations. They do not require every optional provider or a separate MCP server for each extension. ADR-0004, ADR-0005, ADR-0009, ADR-0013

The white-box view separates the application entry points from the embedded core’s command, execution and access responsibilities. It omits individual stores and providers to keep control boundaries visible. Arrows are logical dependencies, not a new protocol. Detailed implementation packages are not selected by this view.

Core responsibilities and control boundaries
Core responsibilities and control boundariesLogical dependencies between loading, command dispatch, lifecycle, execution, environment preparation and action admission. Nodes are responsibilities, not separate servers.Extension loaderProfile and resource stateCommand model anddispatcherSecurity Broker and actionadmissionLifecycle ownerRuntime providerExecutorCore facilitiesCredentials and sign-insessionsAtomic profile publicationPinned command and releaseDiscovery and admissionImmutable invocationExact verified environmentLaunch, supervision, finalizationCurrent action admissionAdmitted core operationBound identity and credentialsCore responsibilities and control boundariesLogical dependencies between loading, command dispatch, lifecycle, execution, environment preparation and action admission. Nodes are responsibilities, not separate servers.Extension loaderProfile and resource stateCommand model anddispatcherSecurity Broker and actionadmissionLifecycle ownerRuntime providerExecutorCore facilitiesCredentials and sign-insessionsAtomic profile publicationPinned command and releaseDiscovery and admissionImmutable invocationExact verified environmentLaunch, supervision, finalizationCurrent action admissionAdmitted core operationBound identity and credentials
Components and decisions

Command model and dispatcher · Extension loader · Lifecycle owner · Executor · Runtime provider · Security Broker and action admission · Credentials and sign-in sessions · Core facilities · Profile and resource state

ADR-0001 · ADR-0002 · ADR-0003 · ADR-0004 · ADR-0005 · ADR-0007 · ADR-0008 · ADR-0009 · ADR-0010 · ADR-0011 · ADR-0012 · ADR-0013 · ADR-0014 · ADR-0015 · ADR-0016

The directory is generated from the same model as the diagrams. It distinguishes internal blocks, environment/resources and participants; each entry gives its responsibility, relationships and defining ADRs. An external participant listed here does not become part of the core.

CLI and core

Named CLI application named-cli

Owner-built application embedding Rukh, a CLI entry point and an optional MCP host; local stdio needs no separate service.

Defined by: ADR-0010 · ADR-0013

Relationships

Rukh core library rukh-core
Command model and dispatcher command-model

Validated canonical commands and common typed inputs/results, projected into CLI routes and owner-approved MCP tools from one committed generation.

Defined by: ADR-0002 · ADR-0006 · ADR-0013

Relationships

Extension loader extension-loader

Permitted discovery, release verification, immutable installation and atomic publication of owner configuration, CLI routes and eligible MCP projections.

Defined by: ADR-0005 · ADR-0007 · ADR-0009 · ADR-0013

Relationships

Lifecycle owner lifecycle-owner

Logical in-core owner of invocation ordering, cancellation, admission and one final outcome.

Defined by: ADR-0002 · ADR-0004

Relationships

Executor executor

Registered foreground execution with private managed IPC and an explicit host-trusted or verified confined profile; mandatory unsupported restrictions reject launch.

Defined by: ADR-0001 · ADR-0003 · ADR-0004 · ADR-0015

Relationships

Runtime provider runtime-provider

Trusted integration for exact environment resolution, authorized preparation and held references; not a mandatory external manager.

Defined by: ADR-0008 · ADR-0010

Relationships

Security Broker and action admission security-broker

In-core identity, authorization, permitted discovery and final admission intersecting current rights with task authority and required effect checks; no broker server is mandatory.

Defined by: ADR-0005 · ADR-0009 · ADR-0012 · ADR-0014 · ADR-0016

Relationships

Credentials and sign-in sessions credentials

Core-owned protected credential use, verified subject binding, coordinated renewal and logout when identity is required.

Defined by: ADR-0011

Relationships

Core facilities core-facilities

Trusted registered operations, core-owned presentation, typed results, logs and audit; consequential operations declare effect and reconciliation support.

Defined by: ADR-0002 · ADR-0010 · ADR-0013 · ADR-0016

Relationships

CLI adapter cli-adapter

Projects canonical commands into routes, parses terminal arguments into the shared input record and presents committed results.

Defined by: ADR-0002 · ADR-0013

Relationships

MCP adapter mcp-adapter

Trusted host adapter exposing approved tools from the current generation, validating exact tool bindings and returning bounded machine results through the common invocation path.

Defined by: ADR-0010 · ADR-0013

Relationships

Task authority and shared budgets task-authority

Core-owned issuer and coordinator of local or integrated task grants, attenuated delegation, revocation and shared measurable reservations. It does not plan agent work.

Defined by: ADR-0014

Relationships

Effect commitment and reconciliation effect-coordinator

Coordinates trusted effect preparation, exact request/resource binding, required authorization or approval, durable dispatch state and authorized reconciliation of uncertain outcomes without repeating the effect.

Defined by: ADR-0016

Relationships

Environment and resources

Profile and resource state profile-state

Owner-controlled profile revisions, artifact/environment references, invalidation metadata and coordinated task/budget/effect records. Local durable storage is the baseline, not a database service.

Defined by: ADR-0007 · ADR-0008 · ADR-0009 · ADR-0011 · ADR-0012 · ADR-0013 · ADR-0014 · ADR-0016

Relationships

Extension process extension-process

Native or script command instance supervised under the selected execution profile. Host-trusted retains ambient OS authority; confinement is claimed only for enforced declared dimensions.

Defined by: ADR-0001 · ADR-0003 · ADR-0004 · ADR-0015

Relationships

Approved artifact sources artifact-sources

Configured OCI, hosted HTTPS, Git or approved local delivery bindings supplying release bytes.

Defined by: ADR-0007

Relationships

Approved catalogs and local rules catalog-rules

Owner-authored validated declarations; one static catalog and explicit local policy form the baseline.

Defined by: ADR-0009

Relationships

External identity service identity-service

Optional approved standard, domain or custom identity integration; only selected configurations require it.

Defined by: ADR-0005 · ADR-0011

Relationships

External permission service permission-service

Optional authoritative AuthZEN or custom provider; local rules may instead be selected deliberately.

Defined by: ADR-0005 · ADR-0009 · ADR-0012

Relationships

Protected resources protected-resources

Resources reached by admitted trusted core operations, retaining their own access enforcement.

Defined by: ADR-0002 · ADR-0005 · ADR-0012

Relationships

Participants

CLI owner cli-owner

Assembles trusted implementations and controls profile authority.

Defined by: ADR-0010

Relationships

CLI user cli-user

Discovers, installs and invokes commands within the selected policy.

Defined by: ADR-0002 · ADR-0007 · ADR-0009

Relationships

Extension author extension-author

Publishes declared commands and immutable release artifacts.

Defined by: ADR-0006 · ADR-0007

Relationships

Agent or machine client agent-client

Calls the named CLI through MCP with independently bound authority; model output and client-provided names do not establish identity or consent.

Defined by: ADR-0013 · ADR-0014

Relationships

Built-in handlers and owner adapters are trusted code with cooperative cancellation requirements. Ordinary extensions cannot promote themselves to this path. User configuration can narrow constraints or change explicitly delegated preferences, but cannot expand the set of trusted implementations. ADR-0010

Security Broker selects identity, authorization and discovery independently. Standard integrations use OIDC/OAuth for sign-in and AuthZEN for permission evaluation; domain or proprietary services use owner-registered adapters or protocol bridges. Local catalogs and rules implement the same boundaries without remote services. ADR-0005, ADR-0009

The host, core and adapters have distinct operational obligations. Embedding the library does not transfer ownership of the application’s lifetime to Rukh.

BoundaryObligation of the owning implementation
Host → coreDelegate streams, one terminal coordinator and OS cancellation explicitly; keep invocation scopes alive, close them and release finished handles. The library returns results instead of exiting the application or taking global signal handlers
Core → trusted providerValidate dependency and lifetime compatibility before initialization; initialize admitted providers in order and dispose only owned instances in reverse order on failure. Sign-in and package/runtime installation are separate operations, not hidden startup work
Loader/runtime provider → state storageCoordinate publication, references and collection through the same supported storage boundary; do not treat a partial directory or a missing numeric process identifier as proof of readiness or safe deletion
Core → in-process handlerRequire cooperative cancellation and bounded completion. An uncooperative callback needs a declared supervised binding; moving it to another thread does not provide forced cleanup

These obligations are defined by ADR-0007, ADR-0008 and ADR-0010. Operational limits belong to those contracts, not to a presumed separate administrator or server component.

Task authority and action admission
Task authority and action admissionTask authority narrows existing rights and coordinates shared budgets. Nodes are logical core responsibilities, not required remote services.CLI ownerTask authority and sharedbudgetsMCP adapterSecurity Broker and actionadmissionProfile and resource stateLifecycle ownerEffect commitment andreconciliationApproved policy or authorizedconsentBind caller and task scopeScope, revocation and budgetreservationShared task and budget stateCurrent action admissionRecheck before effect dispatchTask authority and action admissionTask authority narrows existing rights and coordinates shared budgets. Nodes are logical core responsibilities, not required remote services.CLI ownerTask authority and sharedbudgetsMCP adapterSecurity Broker and actionadmissionProfile and resource stateLifecycle ownerEffect commitment andreconciliationApproved policy or authorizedconsentBind caller and task scopeScope, revocation and budgetreservationShared task and budget stateCurrent action admissionRecheck before effect dispatch
Components and decisions

CLI owner · Lifecycle owner · Security Broker and action admission · Profile and resource state · MCP adapter · Task authority and shared budgets · Effect commitment and reconciliation

ADR-0002 · ADR-0005 · ADR-0012 · ADR-0013 · ADR-0014 · ADR-0016

Command adapters normalize inputs; task authority constrains what a caller may request; Security Broker resolves current identity and permission decisions; final admission coordinates those decisions with shared reservations. A purpose string is diagnostic data, not a grant. ADR-0013, ADR-0014

The effect coordinator binds a consequential action to its exact implementation, resource and payload, then records dispatch and the observed result. It reuses final admission and protected local state rather than requiring a new service. An unknown result retains protective records and reservations until justified reconciliation. ADR-0016

The executor enforces only the guarantees declared by a verified execution profile. Direct OS activity in a host-trusted process is outside mediated core checks. ADR-0015

Diagram

Drag to move · + / − to zoom · 0 to fit · Esc to closeDrag to move and pinch to zoom

100%