Documentation

Read the documents.

The documents live in the repository, next to the code they describe, and there is no separate documentation site yet. This page is the map: what each document is for, and how much of it there is.

How to read the labels

A document is labelled by what it is, and each label is checked against the file: a document that grows past its label fails a test until the label is changed.

  • Reference long, to searchEvery field and every message. Hundreds of lines; meant to be searched, not read from the top.
  • Guide read in orderOne job from start to end: deploying it, running it, licensing it.
  • Short a page or twoA summary or a policy; read it whole.
  • Log what changedA record by version, newest first.

These links open the files on GitHub. They are set by a script; without it each card still names the file, in the repository’s docs folder unless the path says otherwise.

Quickstart

Run it with no model and no API key, then run it for real.

  • READMEGuide
    What it is, a first run, the commands you will use and the layout of the repository.README.md
  • The demo container, step by step, with a token you generate.docs/commercial/deployment.md

Concepts

How the pieces fit, and why a prompt is not the contract.

  • The five planes, the four layers of enforcement, event sourcing and the single-writer rule.docs/architecture.md

Configure

Describe a team and its rules in mesh.yaml.

  • ConfigurationReference
    Every field of mesh.yaml and host.yaml: agents, policies, hard actions, budgets and the message bus.docs/configuration.md

Deploy

Put it where it will run: one server, a cluster, or one instance per tenant.

  • Docker Compose, TLS and a reverse proxy, Kubernetes with Helm, fleets, air-gapped installs and building the image yourself.docs/commercial/deployment.md

Operate

Keep it running, and know what each refusal means.

  • Settings, upgrading, backup and restore, monitoring, rotating the token and what each refusal means.docs/operations.md

Security

What it protects, what it does not, and how to report a problem.

  • Every control, the test that pins it, and what it does not do.docs/commercial/security.md
  • Answers to the questions a buyer’s security team usually asks, including the ones whose answer is no.docs/commercial/security-questionnaire.md
  • How to report a vulnerability privately, and what to expect.SECURITY.md

Licensing and pricing

The source licence, licence keys and the plans.

  • The source licence in plain words, what a licence key is, what a limit does and what happens at expiry.docs/commercial/licensing.md
  • PricingShort
    The plans, the reasoning behind them and what the measured mission cost.docs/commercial/pricing.md

Reference

The contracts underneath, for whoever writes an adapter or reads the log.

  • ProtocolReference
    The message and event envelopes, artifact addresses, the typed state machines and trust classes.docs/protocol.md
  • The supervisor, the adapter interface, recovery, termination, state and persistence, and the server.docs/runtime.md

Changelog

What changed between versions, written for whoever runs it.

  • Read the notes on upgrading before you upgrade a deployment: there is no supported downgrade.CHANGELOG.md

Brand

The name, the voice, the colours and the logo.

  • How to say what Curule is, and how to use the name and the logo.docs/brand.md

Something missing?

If a question is not answered in these, the contact page says where to ask. A question a document should have answered is a defect in the document, and we want to hear about it.

Ask a questionRead the security page