sw.testing SDK module — structured test framework for surface runners: - suite/test registration, lifecycle hooks (beforeAll/afterAll/beforeEach/afterEach) - Assertion library (ok/eq/neq/gt/match/throws/status/shape/arrayOf) - Auto-cleanup via track(type, id) with LIFO deletion - Three result statuses: passed/failed/warned - Structured JSON results with timing, warnings, cleanup stats test-runner manifest type: - ValidateManifest accepts "test-runner" packages - Excluded from sidebar nav (extensionNavItems filters surface/full only) - DB migrations: SQLite 013, Postgres 014 (CHECK constraint) ICD runner migration (kernel-only): - Migrated from T.test()/T.assert() to sw.testing.suite() - Stripped extension-dependent tests (channels, notes, personas, etc.) - Kernel suites: smoke, crud, authz, security, providers, packaging, sdk - Deleted ui.js + css (rendering delegated to registry surface) SDK runner migration (kernel-only): - Migrated from T.dualTest()/T.domains to sw.testing.suite() - Stripped extension domains (belong in v0.7.2 package runners) - Kernel suites: misc, workflows, admin, packages, connections, deps, composition Runner registry surface (/s/test-runners): - Admin-only dashboard discovering test-runner packages - Run All / per-runner Run buttons, real-time results - Export Failures / Export Full Results (JSON download) - Dark mode styling using kernel CSS variables - Suite count polling for async runner script loading 141 passed, 0 failed on fresh minimal install. Co-Authored-By: Claude Opus 4.6 (1M context) <noreply@anthropic.com>
Armature
A self-hosted extension platform. Identity, teams, permissions, workflows, and a package system. Everything else ships as installable extensions.
What This Is
Armature is the kernel. It provides the primitives that extensions build on: users, teams, groups, scoped credentials, a Starlark sandbox, workflow orchestration, notifications, and a package installer. It does not include AI chat, providers, personas, or any domain-specific features — those are all extension packages.
Stack
- Backend: Go / Gin
- Frontend: Preact + htm (no build step)
- Database: PostgreSQL (production) + SQLite (dev/test/edge)
- Sandbox: Starlark with capability-gated modules
- Deployment: Single Docker image, Kubernetes
Quick Start
# Docker (recommended)
docker compose up --build
# → http://localhost:3000 (admin/admin)
# Or from source
git clone <repo-url> && cd armature
cp server/.env.example server/.env # edit DB credentials
cd server && go run .
# → http://localhost:8080
Bundled packages (workflows, surfaces, task manager) are auto-installed on first boot. See Distribution Guide for production deployment and customization.
Kernel Features
- Auth: Builtin password, mTLS (client cert), OIDC (Keycloak et al.)
- Teams & Groups: Horizontal isolation + vertical permissions
- Packages: Unified registry for surfaces, extensions, libraries, workflows
- Starlark Sandbox: Capability-gated server-side scripting for extensions
- Workflows: Staged processes with forms, review, and webhooks
- Connections: Scoped credential storage (global/team/personal), AES-256-GCM encrypted
- Notifications: In-app with per-type preferences
- Audit Log: All admin operations logged
- Object Storage: PVC or S3-compatible
- Multi-Replica HA: PG-backed WS tickets and rate limit counters
Documentation
- Distribution Guide — Docker, bundled packages, builder image, production deployment
- Architecture — kernel components and design reasoning
- Roadmap — current status and planned milestones
- Changelog — version history
Project Status
v0.5.0 — Realtime pub/sub primitive, dialog audit, and admin permissions
UI. Extensions can now publish events to WebSocket channels via Starlark;
clients subscribe with sw.realtime.subscribe(). Admin Packages page gains
per-permission grant/revoke controls and status badges. See
ROADMAP.md for the full journey from v0.1.0 kernel extraction
through v0.3.x workflows, v0.4.x Notes surface, to v0.5.x realtime and chat.
License
Proprietary. All rights reserved.