[{"data":1,"prerenderedAt":1166},["ShallowReactive",2],{"navigation_docs":3,"-develop-pipeline-apps-overview":388,"-develop-pipeline-apps-overview-surround":1161},[4,82,147,173,202,259,298,355],{"title":5,"icon":6,"redirect":7,"path":8,"stem":9,"children":10,"page":73},"Start","i-lucide-compass","\u002Fintro\u002Fquickstart","\u002Fintro","1.intro",[11,14,18,22,74,78],{"title":12,"path":7,"stem":13},"Quickstart","1.intro\u002F0.quickstart",{"title":15,"path":16,"stem":17},"Pipeline Applications","\u002Fintro\u002Fpipeline-app-walkthrough","1.intro\u002F1.pipeline-app-walkthrough",{"title":19,"path":20,"stem":21},"How Redgold works","\u002Fintro\u002Foverview","1.intro\u002F2.overview",{"title":23,"icon":24,"visibility":25,"redirect":26,"path":27,"stem":28,"children":29,"page":73},"Comparison","i-lucide-scale","private","\u002Fintro\u002Fcomparison\u002Fpositioning","\u002Fintro\u002Fcomparison","1.intro\u002F3.comparison",[30,33,37,41,45,49,53,57,61,65,69],{"title":31,"path":26,"stem":32},"Positioning","1.intro\u002F3.comparison\u002F1.positioning",{"title":34,"path":35,"stem":36},"vs Lovable","\u002Fintro\u002Fcomparison\u002Fvs-lovable","1.intro\u002F3.comparison\u002F10.vs-lovable",{"title":38,"path":39,"stem":40},"vs Cloudflare OS","\u002Fintro\u002Fcomparison\u002Fvs-cloudflare-os","1.intro\u002F3.comparison\u002F11.vs-cloudflare-os",{"title":42,"path":43,"stem":44},"vs a backend-as-a-service","\u002Fintro\u002Fcomparison\u002Fvs-baas","1.intro\u002F3.comparison\u002F2.vs-baas",{"title":46,"path":47,"stem":48},"vs serverless compute","\u002Fintro\u002Fcomparison\u002Fvs-serverless-compute","1.intro\u002F3.comparison\u002F3.vs-serverless-compute",{"title":50,"path":51,"stem":52},"vs a do-it-yourself data stack","\u002Fintro\u002Fcomparison\u002Fvs-diy-data-stack","1.intro\u002F3.comparison\u002F4.vs-diy-data-stack",{"title":54,"path":55,"stem":56},"vs Rama","\u002Fintro\u002Fcomparison\u002Fvs-rama","1.intro\u002F3.comparison\u002F5.vs-rama",{"title":58,"path":59,"stem":60},"vs Apache Spark","\u002Fintro\u002Fcomparison\u002Fvs-spark","1.intro\u002F3.comparison\u002F6.vs-spark",{"title":62,"path":63,"stem":64},"vs Apache DataFusion","\u002Fintro\u002Fcomparison\u002Fvs-datafusion","1.intro\u002F3.comparison\u002F7.vs-datafusion",{"title":66,"path":67,"stem":68},"vs Heroku","\u002Fintro\u002Fcomparison\u002Fvs-heroku","1.intro\u002F3.comparison\u002F8.vs-heroku",{"title":70,"path":71,"stem":72},"vs AI model providers","\u002Fintro\u002Fcomparison\u002Fvs-ai-providers","1.intro\u002F3.comparison\u002F9.vs-ai-providers",false,{"title":75,"path":76,"stem":77},"Common tasks","\u002Fintro\u002Fstarting-points","1.intro\u002F4.starting-points",{"title":79,"path":80,"stem":81},"FAQ","\u002Fintro\u002Ffaq","1.intro\u002F5.faq",{"title":83,"icon":84,"redirect":85,"path":86,"stem":87,"children":88,"page":73},"Examples","i-lucide-chef-hat","\u002Fcookbook\u002Foverview","\u002Fcookbook","10.cookbook",[89,91,95,99,103,107,111,115,119,123,127,131,135,139,143],{"title":83,"path":85,"stem":90},"10.cookbook\u002F1.overview",{"title":92,"path":93,"stem":94},"One-shot task in CI","\u002Fcookbook\u002Fone-shot-ci","10.cookbook\u002F10.one-shot-ci",{"title":96,"path":97,"stem":98},"Rate-limit retries","\u002Fcookbook\u002Fretry-rate-limits","10.cookbook\u002F11.retry-rate-limits",{"title":100,"path":101,"stem":102},"Connect GitHub review automation","\u002Fcookbook\u002Fconnect-github-app","10.cookbook\u002F12.connect-github-app",{"title":104,"path":105,"stem":106},"Delegate a task to another agent","\u002Fcookbook\u002Fdelegate-agent-task","10.cookbook\u002F13.delegate-agent-task",{"title":108,"path":109,"stem":110},"Validate a pipeline application change","\u002Fcookbook\u002Fvalidate-pipeline-app","10.cookbook\u002F14.validate-pipeline-app",{"title":112,"path":113,"stem":114},"Verify a managed application deployment","\u002Fcookbook\u002Fverify-managed-deploy","10.cookbook\u002F15.verify-managed-deploy",{"title":116,"path":117,"stem":118},"First API call","\u002Fcookbook\u002Ffirst-api-call","10.cookbook\u002F2.first-api-call",{"title":120,"path":121,"stem":122},"Python client","\u002Fcookbook\u002Fmodel-api-python","10.cookbook\u002F3.model-api-python",{"title":124,"path":125,"stem":126},"Anthropic Messages","\u002Fcookbook\u002Fanthropic-messages","10.cookbook\u002F4.anthropic-messages",{"title":128,"path":129,"stem":130},"Check credits","\u002Fcookbook\u002Fcheck-credits","10.cookbook\u002F5.check-credits",{"title":132,"path":133,"stem":134},"Query data via MCP","\u002Fcookbook\u002Fmcp-query-data","10.cookbook\u002F6.mcp-query-data",{"title":136,"path":137,"stem":138},"Drive an agent via MCP","\u002Fcookbook\u002Fmcp-drive-agent","10.cookbook\u002F7.mcp-drive-agent",{"title":140,"path":141,"stem":142},"Install the client","\u002Fcookbook\u002Finstall-client","10.cookbook\u002F8.install-client",{"title":144,"path":145,"stem":146},"Use another API host","\u002Fcookbook\u002Fpoint-client-at-host","10.cookbook\u002F9.point-client-at-host",{"title":148,"icon":149,"redirect":150,"path":151,"stem":152,"children":153,"page":73},"Agent operations","i-lucide-network","\u002Ffleet\u002Foverview","\u002Ffleet","11.fleet",[154,157,161,165,169],{"title":155,"path":150,"stem":156},"Running agent work","11.fleet\u002F0.overview",{"title":158,"path":159,"stem":160},"Workstreams and issues","\u002Ffleet\u002Fworkstreams-and-issues","11.fleet\u002F1.workstreams-and-issues",{"title":162,"path":163,"stem":164},"Agent lifecycle","\u002Ffleet\u002Fagent-lifecycle","11.fleet\u002F2.agent-lifecycle",{"title":166,"path":167,"stem":168},"Supervision and recovery","\u002Ffleet\u002Fsupervision","11.fleet\u002F3.supervision",{"title":170,"path":171,"stem":172},"An application workstream from request to delivery","\u002Ffleet\u002Fapplication-workstream","11.fleet\u002F4.application-workstream",{"title":174,"icon":175,"redirect":176,"path":177,"stem":178,"children":179,"page":73},"Architecture","i-lucide-layers","\u002Finfrastructure\u002Foverview","\u002Finfrastructure","3.infrastructure",[180,182,186,190,194,198],{"title":174,"path":176,"stem":181},"3.infrastructure\u002F0.overview",{"title":183,"path":184,"stem":185},"A request through the platform","\u002Finfrastructure\u002Frequest-path","3.infrastructure\u002F11.request-path",{"title":187,"path":188,"stem":189},"Agent work and durable state","\u002Finfrastructure\u002Fagent-work","3.infrastructure\u002F12.agent-work",{"title":191,"path":192,"stem":193},"Data and pipelines","\u002Finfrastructure\u002Fdata","3.infrastructure\u002F3.data",{"title":195,"path":196,"stem":197},"AI and agents","\u002Finfrastructure\u002Fai","3.infrastructure\u002F4.ai",{"title":199,"path":200,"stem":201},"Managed deployment","\u002Finfrastructure\u002Fdeployment","3.infrastructure\u002F7.deployment",{"title":203,"icon":204,"redirect":205,"path":206,"stem":207,"children":208,"page":73},"API","i-lucide-book-marked","\u002Freference\u002Fauthentication","\u002Freference","4.reference",[209,212,216,220,224,228,232,236,240,244,248],{"title":210,"path":205,"stem":211},"Authentication","4.reference\u002F1.authentication",{"title":213,"path":214,"stem":215},"Security disclosure policy","\u002Freference\u002Fsecurity-disclosure","4.reference\u002F11.security-disclosure",{"title":217,"path":218,"stem":219},"Model API","\u002Freference\u002Fllm-api","4.reference\u002F2.llm-api",{"title":221,"path":222,"stem":223},"MCP server","\u002Freference\u002Fmcp","4.reference\u002F2.mcp",{"title":225,"path":226,"stem":227},"Data platform preview","\u002Freference\u002Fdata-platform-preview","4.reference\u002F3.data-platform-preview",{"title":229,"path":230,"stem":231},"Terminal client","\u002Freference\u002Fcli","4.reference\u002F6.cli",{"title":233,"path":234,"stem":235},"Pipeline manifest preview","\u002Freference\u002Fpipeline-preview","4.reference\u002F7.pipeline-preview",{"title":237,"path":238,"stem":239},"Limits and retries","\u002Freference\u002Flimits","4.reference\u002F8.limits",{"title":241,"path":242,"stem":243},"API contract details","\u002Freference\u002Fapi-contracts","4.reference\u002F9.api-contracts",{"title":245,"path":246,"stem":247},"Errors","\u002Freference\u002Ferrors","4.reference\u002F9.errors",{"title":249,"icon":250,"visibility":251,"path":252,"stem":253,"children":254,"page":73},"Public API","i-lucide-route","public","\u002Freference\u002Froutes","4.reference\u002Froutes",[255],{"title":256,"path":257,"stem":258},"V1 routes","\u002Freference\u002Froutes\u002Fv1","4.reference\u002Froutes\u002Fv1",{"title":260,"icon":261,"visibility":25,"redirect":262,"path":263,"stem":264,"children":265,"page":73},"Develop","i-lucide-code","\u002Fdevelop\u002Fpipeline-apps\u002Foverview","\u002Fdevelop","5.develop",[266,270,286,290,294],{"title":267,"path":268,"stem":269},"Author a batch transform","\u002Fdevelop\u002Fauthor-a-batch-transform","5.develop\u002F10.author-a-batch-transform",{"title":271,"visibility":251,"redirect":262,"path":272,"stem":273,"children":274,"page":73},"Pipeline Apps","\u002Fdevelop\u002Fpipeline-apps","5.develop\u002F11.pipeline-apps",[275,278,282],{"title":276,"path":262,"stem":277},"Pipeline apps","5.develop\u002F11.pipeline-apps\u002F1.overview",{"title":279,"path":280,"stem":281},"Collaborative board walkthrough","\u002Fdevelop\u002Fpipeline-apps\u002Fcollaborative-board","5.develop\u002F11.pipeline-apps\u002F2.collaborative-board",{"title":283,"path":284,"stem":285},"Release and security lifecycle","\u002Fdevelop\u002Fpipeline-apps\u002Frelease-lifecycle","5.develop\u002F11.pipeline-apps\u002F3.release-lifecycle",{"title":287,"path":288,"stem":289},"Build a vertical","\u002Fdevelop\u002Fbuild-a-vertical","5.develop\u002F5.build-a-vertical",{"title":291,"path":292,"stem":293},"Managed application artifacts","\u002Fdevelop\u002Fscaffold-a-narrow-app","5.develop\u002F7.scaffold-a-narrow-app",{"title":295,"path":296,"stem":297},"Import your data","\u002Fdevelop\u002Fimport-your-data","5.develop\u002F8.import-your-data",{"title":299,"icon":300,"redirect":301,"path":302,"stem":303,"children":304,"page":73},"Guides","i-lucide-layout-grid","\u002Fapplications\u002Fai-agents\u002Foverview","\u002Fapplications","7.applications",[305,309,329,341],{"title":306,"path":307,"stem":308},"Application maturity catalog","\u002Fapplications\u002Fcatalog","7.applications\u002F0.catalog",{"title":310,"visibility":251,"path":311,"stem":312,"children":313,"page":73},"AI Agents","\u002Fapplications\u002Fai-agents","7.applications\u002F1.ai-agents",[314,317,321,325],{"title":315,"path":301,"stem":316},"Coding agents","7.applications\u002F1.ai-agents\u002F01.overview",{"title":318,"path":319,"stem":320},"GitHub App automation","\u002Fapplications\u002Fai-agents\u002Fgithub-app-automation","7.applications\u002F1.ai-agents\u002F04.github-app-automation",{"title":322,"path":323,"stem":324},"agent-cli assistance","\u002Fapplications\u002Fai-agents\u002Fagent-cli-assistance","7.applications\u002F1.ai-agents\u002F05.agent-cli-assistance",{"title":326,"path":327,"stem":328},"Agent REST control","\u002Fapplications\u002Fai-agents\u002Frest-agent-control","7.applications\u002F1.ai-agents\u002F06.rest-agent-control",{"title":330,"visibility":251,"path":331,"stem":332,"children":333,"page":73},"Tickets","\u002Fapplications\u002Ftickets","7.applications\u002F2.tickets",[334,337],{"title":330,"path":335,"stem":336},"\u002Fapplications\u002Ftickets\u002Foverview","7.applications\u002F2.tickets\u002F01.overview",{"title":338,"path":339,"stem":340},"API walkthrough","\u002Fapplications\u002Ftickets\u002Fapi-walkthrough","7.applications\u002F2.tickets\u002F02.api-walkthrough",{"title":342,"icon":343,"visibility":251,"path":344,"stem":345,"children":346,"page":73},"Case studies","i-lucide-book-open-check","\u002Fapplications\u002Fcase-studies","7.applications\u002F6.case-studies",[347,351],{"title":348,"path":349,"stem":350},"Case study: owner-scoped tickets","\u002Fapplications\u002Fcase-studies\u002Ftickets","7.applications\u002F6.case-studies\u002F01.tickets",{"title":352,"path":353,"stem":354},"Case study: repository review and correction","\u002Fapplications\u002Fcase-studies\u002Frepository-review","7.applications\u002F6.case-studies\u002F02.repository-review",{"title":356,"icon":357,"redirect":358,"path":359,"stem":360,"children":361,"page":73},"Resources","i-lucide-library","\u002Fresources\u002Fglossary","\u002Fresources","9.resources",[362,365,369,373,377,380,384],{"title":363,"path":358,"stem":364},"Glossary","9.resources\u002F1.glossary",{"title":366,"path":367,"stem":368},"Terms of Service","\u002Fresources\u002Fterms","9.resources\u002F2.terms",{"title":370,"path":371,"stem":372},"Privacy Policy","\u002Fresources\u002Fprivacy","9.resources\u002F3.privacy",{"title":374,"path":375,"stem":376},"Acceptable Use Policy","\u002Fresources\u002Facceptable-use","9.resources\u002F4.acceptable-use",{"title":79,"path":378,"stem":379},"\u002Fresources\u002Ffaq","9.resources\u002F5.faq",{"title":381,"path":382,"stem":383},"Documentation feedback","\u002Fresources\u002Fdocs-feedback","9.resources\u002F6.docs-feedback",{"title":385,"path":386,"stem":387},"Refund and Cancellation Policy","\u002Fresources\u002Frefund-cancellation","9.resources\u002F7.refund-cancellation",{"id":389,"title":276,"access":390,"audience":391,"body":392,"description":1152,"extension":1153,"last_verified":1154,"links":1155,"maturity":1156,"meta":1157,"navigation":1158,"path":262,"seo":1159,"stem":277,"__hash__":1160},"docs\u002F5.develop\u002F11.pipeline-apps\u002F1.overview.md","onboarding","developer",{"type":393,"value":394,"toc":1136},"minimark",[395,404,409,413,473,481,484,487,491,563,566,570,619,623,628,631,641,645,660,666,670,673,676,680,737,744,747,824,830,917,921,924,927,950,957,961,964,971,974,978,1061,1065,1083,1099,1106,1110,1132],[396,397,398,399,403],"caution",{},"Pipeline applications are currently delivered as a managed preview. Customers\nreview their Rust schemas, pipeline TOML, transforms, tests, and API contract in\nGit. Redgold operates publication, routing, execution, storage, deployment, and\nmonitoring. The portable ",[400,401,402],"code",{},"app.*"," package, declarative client surfaces, catalog\nsharing, and offline installation are developer-preview components beyond the\ncurrent customer deliverable. Public self-service publication remains planned.",[405,406,408],"h2",{"id":407},"current-managed-contract","Current managed contract",[410,411,412],"p",{},"The current contract has a deliberate ownership boundary:",[414,415,416,429],"table",{},[417,418,419],"thead",{},[420,421,422,426],"tr",{},[423,424,425],"th",{},"Customer reviews and controls",[423,427,428],{},"Redgold operates",[430,431,432,441,449,457,465],"tbody",{},[420,433,434,438],{},[435,436,437],"td",{},"Rust serde schemas",[435,439,440],{},"Edge routing and authentication",[420,442,443,446],{},[435,444,445],{},"Pipeline TOML",[435,447,448],{},"Pipeline validation and publication",[420,450,451,454],{},[435,452,453],{},"Rust transform code",[435,455,456],{},"Sandboxed execution",[420,458,459,462],{},[435,460,461],{},"Inline tests and fixture requests",[435,463,464],{},"Data engine and storage tiers",[420,466,467,470],{},[435,468,469],{},"API contract and Git history",[435,471,472],{},"Deployment, monitoring, and recovery",[410,474,475,476,480],{},"A coding agent may author changes inside the customer-controlled column. The\ncustomer reviews those artifacts before Redgold validates and deploys the\nmanaged application. Start with the ",[477,478,479],"a",{"href":16},"artifact walkthrough",".",[410,482,483],{},"The sections below describe how this managed backend grows into a portable\napplication package. Their maturity tables distinguish current runtime behavior\nfrom component previews and planned distribution features.",[410,485,486],{},"A pipeline app expresses application behavior as artifacts the platform can\ninspect: typed records, dataflows, routes, transforms, datasets, and deployment\nstate. The application contract adds page surfaces, client actions,\nsynchronization policy, capabilities, and exact dependency pins. The managed\nregistry and installation runtime load verified remote releases inside the\nshared Redgold web, Android, and iOS client code.",[405,488,490],{"id":489},"mental-model","Mental model",[492,493,498],"pre",{"className":494,"code":495,"language":496,"meta":497,"style":497},"language-mermaid shiki shiki-themes material-theme-lighter material-theme material-theme-palenight","flowchart LR\n    Project[\"Logical app id\"] --> Release[\"App release\\nlocal compiler\"]\n    Release --> Schema[\"Rust serde schemas\"]\n    Release --> Pipelines[\"Pipeline specs\"]\n    Release --> Surfaces[\"UI surfaces\\nlocal host\"]\n    Release --> Assets[\"Assets\"]\n    Release --> Policy[\"Capabilities + merge policy\\nvalidated\"]\n    Pipelines --> Server[\"Engine + executor\\ncurrent\"]\n    Surfaces --> Host[\"Shared Vue host\\nweb + Android + iOS\"]\n    Policy --> Portable[\"Portable Rust\u002FWASM dataflow core\\ncomponent preview\"]\n","mermaid","",[400,499,500,509,515,521,527,533,539,545,551,557],{"__ignoreMap":497},[501,502,505],"span",{"class":503,"line":504},"line",1,[501,506,508],{"class":507},"sTEyZ","flowchart LR\n",[501,510,512],{"class":503,"line":511},2,[501,513,514],{"class":507},"    Project[\"Logical app id\"] --> Release[\"App release\\nlocal compiler\"]\n",[501,516,518],{"class":503,"line":517},3,[501,519,520],{"class":507},"    Release --> Schema[\"Rust serde schemas\"]\n",[501,522,524],{"class":503,"line":523},4,[501,525,526],{"class":507},"    Release --> Pipelines[\"Pipeline specs\"]\n",[501,528,530],{"class":503,"line":529},5,[501,531,532],{"class":507},"    Release --> Surfaces[\"UI surfaces\\nlocal host\"]\n",[501,534,536],{"class":503,"line":535},6,[501,537,538],{"class":507},"    Release --> Assets[\"Assets\"]\n",[501,540,542],{"class":503,"line":541},7,[501,543,544],{"class":507},"    Release --> Policy[\"Capabilities + merge policy\\nvalidated\"]\n",[501,546,548],{"class":503,"line":547},8,[501,549,550],{"class":507},"    Pipelines --> Server[\"Engine + executor\\ncurrent\"]\n",[501,552,554],{"class":503,"line":553},9,[501,555,556],{"class":507},"    Surfaces --> Host[\"Shared Vue host\\nweb + Android + iOS\"]\n",[501,558,560],{"class":503,"line":559},10,[501,561,562],{"class":507},"    Policy --> Portable[\"Portable Rust\u002FWASM dataflow core\\ncomponent preview\"]\n",[410,564,565],{},"The application envelope belongs above the execution DAG. A pipeline remains a\nreusable graph that can be invoked by several applications. An application\nrelease groups exact pipeline revisions with its schemas, surfaces, assets, and\nsecurity policy. An installation pins one release for one workspace and records\nthe capabilities that workspace accepted.",[405,567,569],{"id":568},"what-exists-at-each-maturity-level","What exists at each maturity level",[414,571,572,582],{},[417,573,574],{},[420,575,576,579],{},[423,577,578],{},"Level",[423,580,581],{},"Capability",[430,583,584,595,609],{},[420,585,586,592],{},[435,587,588],{},[589,590,591],"strong",{},"Current",[435,593,594],{},"Rust serde records, one-shot dataflows, registered pipeline DAGs, built-in operators, trusted native batch transforms, capability-limited Wasmtime UDFs, Firecracker isolation for opted-in untrusted native\u002FPython workloads, owner-scoped datasets, and Git-backed deployment",[420,596,597,602],{},[435,598,599],{},[589,600,601],{},"Developer Preview",[435,603,604,605,608],{},"Git-authored ",[400,606,607],{},"pipelines\u002F*.toml",", strict portable-app TOML parsing, exact pipeline resolution, canonical unsigned build candidates, signed immutable publication, tenant installation\u002Fupgrade\u002Frollback\u002Fconsent services, verified remote host loading, durable Rust\u002FWASM mutation replay, and descriptor-bound causal set\u002Flist\u002Fdelete merge",[420,610,611,616],{},[435,612,613],{},[589,614,615],{},"Planned",[435,617,618],{},"Deterministic custom client transforms, arbitrary descriptor-generated subscriptions and native host effects, and public self-service catalog publication",[405,620,622],{"id":621},"the-five-layers","The five layers",[624,625,627],"h3",{"id":626},"_1-schema-defines-durable-meaning","1. Schema defines durable meaning",[410,629,630],{},"Checked-in Rust serde types define stored records and over-the-wire payloads.\nA dataset reference can carry a type URL and a pinned schema-descriptor hash,\nwhich lets a runtime distinguish revisions of the same logical type. Schema remains the\nsource of field names, types, validation inputs, form generation, and merge\npolicy.",[410,632,633,634,637,638,480],{},"This layer is current. See ",[477,635,636],{"href":192},"data and pipelines"," and the\n",[477,639,640],{"href":226},"Developer Preview schema",[624,642,644],{"id":643},"_2-pipelines-define-server-behavior","2. Pipelines define server behavior",[410,646,647,648,651,652,655,656,659],{},"A ",[400,649,650],{},"Dataflow"," is one relational execution. A registered ",[400,653,654],{},"PipelineSpec"," is a\nnamed DAG. A ",[400,657,658],{},"PipelineManifest"," is the readable TOML desired state that CI\nlowers into a runtime spec. Routes, reads, writes, subscriptions, schedules,\nand transform stages use this path.",[410,661,662,663,480],{},"Manifest authoring is Developer Preview and publication remains managed. See\nthe ",[477,664,665],{"href":234},"pipeline manifest preview",[624,667,669],{"id":668},"_3-transforms-provide-the-escape-hatch","3. Transforms provide the escape hatch",[410,671,672],{},"The declarative target covers filter, project, map fields, validate, aggregate,\njoin, sort, merge, and emit. The current strict compiler supports the unary\nsubset and fails closed on two-input stages until the executor supplies an\nindependent right-hand branch. A custom transform is appropriate when the\noperation needs domain code. Its ABI, input\u002Foutput schemas, artifact digest,\nresource limits, and allowed host access form part of its contract.",[410,674,675],{},"Trusted Rust batch transforms and their content-addressed artifact pins are\ncurrent. A deterministic client transform format that can use the same typed\nexpression model is planned.",[624,677,679],{"id":678},"_4-surfaces-define-client-behavior","4. Surfaces define client behavior",[410,681,682,683,686,687,690,691,690,694,690,697,690,700,690,703,690,706,690,709,690,712,715,716,690,719,722,723,726,727,690,730,733,734,480],{},"The preview ",[400,684,685],{},"ComponentNode"," contract is a constrained component tree with typed\ndata bindings and actions. A local Vue host prototype currently allowlists\n",[400,688,689],{},"stack",", ",[400,692,693],{},"grid",[400,695,696],{},"card",[400,698,699],{},"text",[400,701,702],{},"markdown",[400,704,705],{},"form",[400,707,708],{},"input",[400,710,711],{},"button",[400,713,714],{},"list",",\n",[400,717,718],{},"board",[400,720,721],{},"tabs",", and ",[400,724,725],{},"navigation",". Its golden collaborative-board fixture uses\nhost-owned lower-snake-case callbacks such as ",[400,728,729],{},"create_card",[400,731,732],{},"open_card",", and\n",[400,735,736],{},"add_example_card",[410,738,739,740,743],{},"The host validates component and action graphs and routes effects through\ninjected host ports for pipeline invocation, entity operations, navigation,\nlocal state, capabilities, and events. The installed-package source fetches the\ntenant installation and verifier key over the authenticated service channel.\nIt verifies both the immutable publication receipt and the registry-signed\nmutable installation projection before opening the shared durable runtime. The\nsigned installation sequence prevents revision rollback. Within one sequence,\nthe service atomically allocates and persists each attestation ",[400,741,742],{},"issued_at_ms","\nwhile locking the installation and its exact transitive release closure. The\nruntime rejects an older projection, requires equal timestamps to reproduce the\nsame projection hash, and retains root-release revocation or dependency-driven\nsuspension as terminal state for that sequence and release. The checked-in\nfixture remains useful for local authoring.\nThe descriptor-driven entity adapter validates and queues create, scalar edit,\nset-membership add\u002Fremove, move, and comment records. Authoritative batch\nhydration is folded with cached and queued state before rendering. Arbitrary\ndescriptor-generated subscriptions and native host effects remain planned. The\nrenderer lives in the canonical Vue application, which Capacitor packages for\nAndroid and iOS.",[410,745,746],{},"Portable action effects have a narrow v1 host contract:",[748,749,750,790,808,818],"ul",{},[751,752,753,756,757,690,760,690,763,690,766,690,769,772,773,776,777,690,780,690,783,772,786,789],"li",{},[400,754,755],{},"invoke_pipeline"," accepts an empty input, or one input value declared by the\nsigned action config. A parameter binding names the input key, filter column,\ncomparison (",[400,758,759],{},"eq",[400,761,762],{},"neq",[400,764,765],{},"gt",[400,767,768],{},"gte",[400,770,771],{},"lt",", or ",[400,774,775],{},"lte","), and scalar kind\n(",[400,778,779],{},"string",[400,781,782],{},"int64",[400,784,785],{},"double",[400,787,788],{},"bool","). The host converts that value into\nthe executor's audited dataflow overlay; undeclared keys and type mismatches\nfail closed.",[751,791,792,795,796,799,800,803,804,807],{},[400,793,794],{},"query_entity"," accepts exactly one ",[400,797,798],{},"entity_id"," or a bounded ",[400,801,802],{},"entity_ids","\narray. It uses the signed entity descriptor and installation-authorized\nbatch endpoint, then returns ",[400,805,806],{},"{ entities: [...] }"," in request order while\nomitting absent identities.",[751,809,810,813,814,817],{},[400,811,812],{},"emit_event"," dispatches a browser-local ",[400,815,816],{},"redgold:runtime-app:event"," with the\ninstallation id, verified app id, safe event name, and cloned payload. It\ncreates no server or cross-application side effect.",[751,819,820,823],{},[400,821,822],{},"invoke_function"," remains publication-ineligible in runtime v1. Function\nartifact pins exist, while an authenticated host request\u002Fresponse contract\nand portable ABI input encoder do not.",[410,825,826,827,829],{},"The pipeline binding is authored on an ",[400,828,755],{}," action node:",[492,831,835],{"className":832,"code":833,"language":834,"meta":497,"style":497},"language-toml shiki shiki-themes material-theme-lighter material-theme material-theme-palenight","[actions.nodes.config]\npipeline_input_key = \"column_id\"\npipeline_filter_column = \"column_id\"\npipeline_filter_operator = \"eq\"\npipeline_filter_value_kind = \"string\"\n","toml",[400,836,837,860,878,891,904],{"__ignoreMap":497},[501,838,839,843,847,849,852,854,857],{"class":503,"line":504},[501,840,842],{"class":841},"sMK4o","[",[501,844,846],{"class":845},"sBMFI","actions",[501,848,480],{"class":507},[501,850,851],{"class":845},"nodes",[501,853,480],{"class":507},[501,855,856],{"class":845},"config",[501,858,859],{"class":841},"]\n",[501,861,862,865,868,871,875],{"class":503,"line":511},[501,863,864],{"class":507},"pipeline_input_key ",[501,866,867],{"class":841},"=",[501,869,870],{"class":841}," \"",[501,872,874],{"class":873},"sfazB","column_id",[501,876,877],{"class":841},"\"\n",[501,879,880,883,885,887,889],{"class":503,"line":517},[501,881,882],{"class":507},"pipeline_filter_column ",[501,884,867],{"class":841},[501,886,870],{"class":841},[501,888,874],{"class":873},[501,890,877],{"class":841},[501,892,893,896,898,900,902],{"class":503,"line":523},[501,894,895],{"class":507},"pipeline_filter_operator ",[501,897,867],{"class":841},[501,899,870],{"class":841},[501,901,759],{"class":873},[501,903,877],{"class":841},[501,905,906,909,911,913,915],{"class":503,"line":529},[501,907,908],{"class":507},"pipeline_filter_value_kind ",[501,910,867],{"class":841},[501,912,870],{"class":841},[501,914,779],{"class":873},[501,916,877],{"class":841},[624,918,920],{"id":919},"_5-releases-and-installations-define-distribution","5. Releases and installations define distribution",[410,922,923],{},"The immutable-release contract pins every schema, pipeline, transform, surface,\nasset, capability, and dependency it needs. The local compiler lowers an app\nmanifest, validates its graph, resolves each pipeline to an exact content hash,\nand writes deterministic CBOR and JSON release candidates. The resulting\nrelease hash is a publisher-independent package digest. Its installation\ncontract records that exact digest, tenant scope, accepted permissions, and\nupgrade history. Managed publication verifies the publisher attestation and\nstores the immutable release and receipt. Tenant installation, upgrade,\nrollback, capability consent, revocation projection, and runtime write\nenforcement use that stored release identity. Every installation response also\ncarries a fresh registry signature over its exact state, grants, release\nprojection, revocation state, and revision sequence.",[410,925,926],{},"Discovery, installation, and data sharing are separate decisions. Installing\nan application does not expose another user's data. Dataset grants continue to\ncontrol shared records independently.",[410,928,929,930,933,934,937,938,941,942,945,946,949],{},"The Apps UI exposes three library scopes. ",[589,931,932],{},"My apps"," combines authored Vibe\nprojects with installations in the active workspace. ",[589,935,936],{},"Shared with me"," shows\nprivate app entitlements granted to the caller or workspace. ",[589,939,940],{},"Discover"," shows\npublic catalog entries whose current release an operator approved. Owners can\nshare a released app with an active trusted contact after that contact resolves\nto a joined workspace member; the share is an ",[400,943,944],{},"APP"," resource grant over the\nstable ",[400,947,948],{},"app_id",". The recipient installs an independent copy into a workspace\nwhere they are owner or admin and explicitly accepts the release capabilities.",[410,951,952,953,956],{},"Public submission creates a pending catalog revision. Operators review its\npublisher, exact release, requested capabilities, tags, and description at\n",[400,954,955],{},"\u002Fadmin\u002Fapps",". Approval makes that revision discoverable; denial records a\nreason and leaves private owner\u002Fgrantee access intact. Review history is\nappend-only while immutable release bytes remain unchanged.",[405,958,960],{"id":959},"schema-plus-transforms","Schema plus transforms",[410,962,963],{},"The authoring goal is a small common case:",[492,965,969],{"className":966,"code":968,"language":699,"meta":497},[967],"language-text","schema       declares records and field policy\npipeline     declares reads, writes, subscriptions, and common transforms\nsurface      declares pages, bindings, and actions\ncustom UDF   supplies the domain-specific operation when needed\nrelease      groups and pins the artifacts above\n",[400,970,968],{"__ignoreMap":497},[410,972,973],{},"An agent can generate this bounded artifact set, and validators can reject\nunknown operations, missing schemas, undeclared capabilities, and unresolved\nreferences before publication.",[405,975,977],{"id":976},"runtime-placement","Runtime placement",[414,979,980,993],{},[417,981,982],{},[420,983,984,987,990],{},[423,985,986],{},"Runtime",[423,988,989],{},"Status",[423,991,992],{},"Intended work",[430,994,995,1005,1015,1026,1036,1047],{},[420,996,997,1000,1002],{},[435,998,999],{},"Engine and dataflow executor",[435,1001,591],{},[435,1003,1004],{},"Dataset scans, relational operators, standing pipelines, trusted native transforms, and isolated server UDFs",[420,1006,1007,1010,1012],{},[435,1008,1009],{},"Shared Vue and Capacitor host",[435,1011,591],{},[435,1013,1014],{},"The platform-authored web UI packaged for browser, Android, and iOS",[420,1016,1017,1020,1023],{},[435,1018,1019],{},"Declarative application renderer",[435,1021,1022],{},"Developer preview",[435,1024,1025],{},"Allowlisted components, bindings, validated action DAGs, injected effect ports, a golden board fixture, verified installed-package loading, and descriptor-driven board create\u002Fedit\u002Fmove\u002Fcomment\u002Flabel actions",[420,1027,1028,1031,1033],{},[435,1029,1030],{},"Portable Rust\u002FWASM dataflow core",[435,1032,1022],{},[435,1034,1035],{},"Strict installed-bundle verification, installation-bound canonical-CBOR state, durable operation replay, cached entities, HLC\u002Fcausal metadata, and CBOR entity operation\u002Fbatch-observation transport",[420,1037,1038,1041,1044],{},[435,1039,1040],{},"Server request-handler WASM host",[435,1042,1043],{},"Component preview",[435,1045,1046],{},"A feature-gated host and local unary\u002Fstreaming\u002FWebSocket fixtures exist; production route selection is not wired to it",[420,1048,1049,1052,1054],{},[435,1050,1051],{},"Dataflow UDF WASM backend",[435,1053,1043],{},[435,1055,1056,1057,1060],{},"Default-on executor backend with fuel, memory, and wall-time bounds, no WASI, and a ",[400,1058,1059],{},"UDF_WASM_DISABLE=1"," kill switch; first route staged for publication",[405,1062,1064],{"id":1063},"hashes-versions-and-signatures","Hashes, versions, and signatures",[410,1066,1067,1068,1070,1071,1074,1075,1078,1079,1082],{},"A current ",[400,1069,654],{}," revision hash and author signature cover the canonical\ncanonical CBOR encoding of its nodes, output node ids, and spec name. The\nhuman-readable ",[400,1072,1073],{},"version_tag",", description, tags, registry ",[400,1076,1077],{},"latest"," flag, and\ntimestamps are outside that content identity. An exact pipeline revision is\ntherefore identified by ",[400,1080,1081],{},"spec_name + spec_hash",", and an exact compiled\ntransform by its artifact hash.",[410,1084,1085,1088,1089,690,1092,690,1095,1098],{},[400,1086,1087],{},"AppRelease.content_hash"," covers the canonical package graph and exact\nreferenced hashes with ",[400,1090,1091],{},"content_hash",[400,1093,1094],{},"author_hash",[400,1096,1097],{},"author_signature",", and\nthe provenance publisher fields cleared. It is therefore independent of\npublisher identity. A separate publisher attestation binds signer identity to\nthat digest. Canonical hashing is implemented for local release candidates;\nlocal inspection distinguishes an unsigned draft from registry verification.",[410,1100,1101,1102,1105],{},"Managed publication strictly decodes the wire bytes, rejects unknown fields and\ntags, binds the authored source to the normalized manifest and release digest,\nverifies the publisher attestation and referenced evidence, and issues the\nopaque receipt used by installation and remote loading. A signed pipeline alone\ndoes not authenticate a page layout, asset, dependency, capability request, or\nmigration.\nRead ",[477,1103,1104],{"href":284},"release and security lifecycle","\nfor the full boundary.",[405,1107,1109],{"id":1108},"continue","Continue",[748,1111,1112,1117,1122,1127],{},[751,1113,1114,1116],{},[477,1115,279],{"href":280},"\nshows how the complete target fits together.",[751,1118,1119,1121],{},[477,1120,283],{"href":284},"\ncovers signatures, permissions, installation, upgrades, sharing, and forks.",[751,1123,1124,1126],{},[477,1125,291],{"href":292}," defines the\ncurrent customer-reviewed backend contract.",[751,1128,1129,1131],{},[477,1130,287],{"href":288}," covers the current repository\nimplementation path in detail.",[1133,1134,1135],"style",{},"html pre.shiki code .sTEyZ, html code.shiki .sTEyZ{--shiki-light:#90A4AE;--shiki-default:#EEFFFF;--shiki-dark:#BABED8}html .light .shiki span {color: var(--shiki-light);background: var(--shiki-light-bg);font-style: var(--shiki-light-font-style);font-weight: var(--shiki-light-font-weight);text-decoration: var(--shiki-light-text-decoration);}html.light .shiki span {color: var(--shiki-light);background: var(--shiki-light-bg);font-style: var(--shiki-light-font-style);font-weight: var(--shiki-light-font-weight);text-decoration: var(--shiki-light-text-decoration);}html .default .shiki span {color: var(--shiki-default);background: var(--shiki-default-bg);font-style: var(--shiki-default-font-style);font-weight: var(--shiki-default-font-weight);text-decoration: var(--shiki-default-text-decoration);}html .shiki span {color: var(--shiki-default);background: var(--shiki-default-bg);font-style: var(--shiki-default-font-style);font-weight: var(--shiki-default-font-weight);text-decoration: var(--shiki-default-text-decoration);}html .dark .shiki span {color: var(--shiki-dark);background: var(--shiki-dark-bg);font-style: var(--shiki-dark-font-style);font-weight: var(--shiki-dark-font-weight);text-decoration: var(--shiki-dark-text-decoration);}html.dark .shiki span {color: var(--shiki-dark);background: var(--shiki-dark-bg);font-style: var(--shiki-dark-font-style);font-weight: var(--shiki-dark-font-weight);text-decoration: var(--shiki-dark-text-decoration);}html pre.shiki code .sMK4o, html code.shiki .sMK4o{--shiki-light:#39ADB5;--shiki-default:#89DDFF;--shiki-dark:#89DDFF}html pre.shiki code .sBMFI, html code.shiki .sBMFI{--shiki-light:#E2931D;--shiki-default:#FFCB6B;--shiki-dark:#FFCB6B}html pre.shiki code .sfazB, html code.shiki .sfazB{--shiki-light:#91B859;--shiki-default:#C3E88D;--shiki-dark:#C3E88D}",{"title":497,"searchDepth":511,"depth":511,"links":1137},[1138,1139,1140,1141,1148,1149,1150,1151],{"id":407,"depth":511,"text":408},{"id":489,"depth":511,"text":490},{"id":568,"depth":511,"text":569},{"id":621,"depth":511,"text":622,"children":1142},[1143,1144,1145,1146,1147],{"id":626,"depth":517,"text":627},{"id":643,"depth":517,"text":644},{"id":668,"depth":517,"text":669},{"id":678,"depth":517,"text":679},{"id":919,"depth":517,"text":920},{"id":959,"depth":511,"text":960},{"id":976,"depth":511,"text":977},{"id":1063,"depth":511,"text":1064},{"id":1108,"depth":511,"text":1109},"Portable application contracts, strict TOML compilation, and a shared declarative host built on the pipeline backend.","md","2026-08-14",null,"preview",{"toc":1158,"visibility":251},true,{"title":276,"description":1152},"FHyl3-eH16jauXKuhjq7pKtkq8YEg3Zq6NufNYDgqAc",[1162,1164],{"title":267,"path":268,"stem":269,"description":1163,"children":-1},"Scaffold, check, publish, and pin a trusted Rust transform that processes Arrow IPC batches in the dataflow engine.",{"title":279,"path":280,"stem":281,"description":1165,"children":-1},"A developer-preview portable pipeline app spanning release distribution, rendering, durable replay, and causal entity merge.",1789873213247]