# Armature A self-hosted extension platform. Identity, teams, permissions, workflows, and a package system. Everything else ships as installable extensions. ## What This Is Armature is the kernel. It provides the primitives that extensions build on: users, teams, groups, scoped credentials, a Starlark sandbox, workflow orchestration, notifications, and a package installer. It does not include AI chat, providers, personas, or any domain-specific features — those are all extension packages. ## Stack - **Backend**: Go / Gin - **Frontend**: Preact + htm (no build step) - **Database**: PostgreSQL (production) + SQLite (dev/test/edge) - **Sandbox**: Starlark with capability-gated modules - **Deployment**: Single Docker image, Kubernetes ## Quick Start ```bash # Docker (recommended) docker compose up --build # → http://localhost:3000 (admin/admin) # Or from source git clone && cd armature cp server/.env.example server/.env # edit DB credentials cd server && go run . # → http://localhost:8080 ``` Bundled packages (workflows, surfaces, task manager) are auto-installed on first boot. See [Distribution Guide](docs/DISTRIBUTION.md) for production deployment and customization. ## Kernel Features - **Auth**: Builtin password, mTLS (client cert), OIDC (Keycloak et al.) - **Teams & Groups**: Horizontal isolation + vertical permissions - **Packages**: Unified registry for surfaces, extensions, libraries, workflows - **Starlark Sandbox**: Capability-gated server-side scripting for extensions - **Workflows**: Staged processes with forms, review, and webhooks - **Connections**: Scoped credential storage (global/team/personal), AES-256-GCM encrypted - **Notifications**: In-app with per-type preferences - **Audit Log**: All admin operations logged - **Object Storage**: PVC or S3-compatible - **Multi-Replica HA**: PG-backed WS tickets and rate limit counters ## Documentation - [Distribution Guide](docs/DISTRIBUTION.md) — Docker, bundled packages, builder image, production deployment - [Architecture](docs/ARCHITECTURE.md) — kernel components and design reasoning - [Roadmap](ROADMAP.md) — current status and planned milestones - [Changelog](CHANGELOG.md) — version history ## Project Status **v0.5.0** — Realtime pub/sub primitive, dialog audit, and admin permissions UI. Extensions can now publish events to WebSocket channels via Starlark; clients subscribe with `sw.realtime.subscribe()`. Admin Packages page gains per-permission grant/revoke controls and status badges. See [ROADMAP.md](ROADMAP.md) for the full journey from v0.1.0 kernel extraction through v0.3.x workflows, v0.4.x Notes surface, to v0.5.x realtime and chat. ## License Proprietary. All rights reserved.