Component registration doctrine
The platform-wide rule for how components (providers, gateways, strategies, agents, tools, workflows) become reachable at runtime. Stated once here; each repo enforces it pragmatically (CI gates where they exist, review convention otherwise). Everything dynamic in research must become explicit before it is live.
The three tiers
| Tier | Where allowed | Rule |
|---|---|---|
| Entry-point / dynamic discovery | Research plane only | Discovery must produce an immutable registry value + fingerprint (content hash of the discovered set), never a mutable global. |
| YAML IoC / declarative config | Research plane only | Config-driven wiring must emit an immutable manifest (hash-locked, versioned) describing the resolved component graph. |
| Signed deployment manifests | The only live tier | Live/execution components come only from signed, schema-compatible deployment manifests; any drift between the manifest and the running graph fails fast. |
Invariants
- No import-time registry mutation anywhere. Registries are populated by
explicit calls from an application entry point, not by module import side
effects (extends the QAP
check_no_process_global_stategate platform-wide as a convention). - Promotion is the only crossing. A research-plane component becomes
live-eligible only through the typed promotion boundary
(
StrategyPromotionRequestand per-repo equivalents), carrying its manifest fingerprint. - Fingerprints are load-bearing. The fingerprint recorded at discovery/manifest-emission time is what the deployment manifest signs and what drift detection compares against.
Per-repo enforcement
alphaswarm_qap— mechanical CI gates (check_no_process_global_state, attestation checks).alphaswarm_agents— hash-lockedAgentSpecversions; derived (never hand-authored) roster manifests; duplicate-rejecting class registry.alphaswarm/alphaswarm_worker— explicitBUILTIN_*registries and guarded execution runtimes; no entry-point scanning on the live path.alphaswarm_platform— signed image provenance (SLSA/Cosign) and hash-locked terraform stack spec versions.