9. Architecture Decisions
Accepted ADRs record the architectural choices, their context, alternatives, consequences and verification status. They are the source of the architecture description; the other views explain those choices together without replacing their contracts.
9.1 Accepted decision records
Section titled “9.1 Accepted decision records”The register is generated from accepted records and preserves each decision’s acceptance date. Dated refinements remain explicit in the affected records. Acceptance does not establish a completed implementation: executed experiments and outstanding checks are recorded in each ADR.
9.2 Traceability to architecture
Section titled “9.2 Traceability to architecture”This view connects each decision to the modeled blocks and scenarios it defines. It is generated from the same CALM model as the architecture diagrams; it does not maintain a second set of decisions.
ADR-0001: Extension execution model
- Rukh core library
- Command model and dispatcher
- Extension loader
- Lifecycle owner
- Executor
- Runtime provider
- Security Broker and action admission
- Credentials and sign-in sessions
- Core facilities
- Profile and resource state
- Extension process
- Protected resources
- Task authority and shared budgets
- Effect commitment and reconciliation
ADR-0002: Core–extension interaction contract
- CLI user
- Named CLI application
- Rukh core library
- Command model and dispatcher
- Extension loader
- Lifecycle owner
- Executor
- Runtime provider
- Security Broker and action admission
- Credentials and sign-in sessions
- Core facilities
- Profile and resource state
- Extension process
- Protected resources
- Agent or machine client
- CLI adapter
- MCP adapter
- Task authority and shared budgets
- Effect commitment and reconciliation
ADR-0003: Process IPC and session authentication
ADR-0004: Execution lifecycle
ADR-0005: Security Broker integration
- Rukh core library
- Command model and dispatcher
- Extension loader
- Lifecycle owner
- Executor
- Runtime provider
- Security Broker and action admission
- Credentials and sign-in sessions
- Core facilities
- Profile and resource state
- Extension process
- Approved artifact sources
- Approved catalogs and local rules
- External identity service
- External permission service
- Protected resources
- Task authority and shared budgets
- Effect commitment and reconciliation
ADR-0006: Extension descriptor and KCL
ADR-0007: Extension loading and updates
- CLI user
- Extension author
- Named CLI application
- Rukh core library
- Command model and dispatcher
- Extension loader
- Lifecycle owner
- Executor
- Runtime provider
- Security Broker and action admission
- Credentials and sign-in sessions
- Core facilities
- Profile and resource state
- Extension process
- Approved artifact sources
- Agent or machine client
- MCP adapter
- Task authority and shared budgets
- Effect commitment and reconciliation
ADR-0008: Runtime and environment preparation
ADR-0009: Catalogs and access rules as code
ADR-0010: Core library and branded CLI composition
- CLI owner
- Named CLI application
- Rukh core library
- Command model and dispatcher
- Extension loader
- Lifecycle owner
- Executor
- Runtime provider
- Security Broker and action admission
- Credentials and sign-in sessions
- Core facilities
- Profile and resource state
- Extension process
- Agent or machine client
- CLI adapter
- MCP adapter
- Task authority and shared budgets
- Effect commitment and reconciliation
ADR-0011: Credentials and sign-in sessions
- Rukh core library
- Command model and dispatcher
- Extension loader
- Lifecycle owner
- Executor
- Runtime provider
- Security Broker and action admission
- Credentials and sign-in sessions
- Core facilities
- Profile and resource state
- External identity service
- Task authority and shared budgets
- Effect commitment and reconciliation
ADR-0012: Authorization validity and access revocation
- Rukh core library
- Command model and dispatcher
- Extension loader
- Lifecycle owner
- Executor
- Runtime provider
- Security Broker and action admission
- Credentials and sign-in sessions
- Core facilities
- Profile and resource state
- Extension process
- Approved artifact sources
- External permission service
- Protected resources
- Task authority and shared budgets
- Effect commitment and reconciliation
ADR-0013: One command model for CLI and MCP
- CLI user
- Named CLI application
- Rukh core library
- Command model and dispatcher
- Extension loader
- Lifecycle owner
- Executor
- Runtime provider
- Security Broker and action admission
- Credentials and sign-in sessions
- Core facilities
- Profile and resource state
- Extension process
- Approved artifact sources
- Agent or machine client
- CLI adapter
- MCP adapter
- Task authority and shared budgets
- Effect commitment and reconciliation
ADR-0014: Task authority and delegation
- CLI owner
- Rukh core library
- Command model and dispatcher
- Extension loader
- Lifecycle owner
- Executor
- Runtime provider
- Security Broker and action admission
- Credentials and sign-in sessions
- Core facilities
- Profile and resource state
- Extension process
- Protected resources
- Agent or machine client
- MCP adapter
- Task authority and shared budgets
- Effect commitment and reconciliation
ADR-0015: Execution confinement
- Rukh core library
- Command model and dispatcher
- Extension loader
- Lifecycle owner
- Executor
- Runtime provider
- Security Broker and action admission
- Credentials and sign-in sessions
- Core facilities
- Profile and resource state
- Extension process
- Protected resources
- Task authority and shared budgets
- Effect commitment and reconciliation
ADR-0016: Effect commitment and reconciliation
- Rukh core library
- Command model and dispatcher
- Extension loader
- Lifecycle owner
- Executor
- Runtime provider
- Security Broker and action admission
- Credentials and sign-in sessions
- Core facilities
- Profile and resource state
- Extension process
- Protected resources
- Task authority and shared budgets
- Effect commitment and reconciliation