Skip to main content

Component registration doctrine

The platform-wide rule for how components (providers, gateways, strategies, agents, tools, workflows) become reachable at runtime. Stated once here; each repo enforces it pragmatically (CI gates where they exist, review convention otherwise). Everything dynamic in research must become explicit before it is live.

The three tiers​

TierWhere allowedRule
Entry-point / dynamic discoveryResearch plane onlyDiscovery must produce an immutable registry value + fingerprint (content hash of the discovered set), never a mutable global.
YAML IoC / declarative configResearch plane onlyConfig-driven wiring must emit an immutable manifest (hash-locked, versioned) describing the resolved component graph.
Signed deployment manifestsThe only live tierLive/execution components come only from signed, schema-compatible deployment manifests; any drift between the manifest and the running graph fails fast.

Invariants​

  • No import-time registry mutation anywhere. Registries are populated by explicit calls from an application entry point, not by module import side effects (extends the QAP check_no_process_global_state gate platform-wide as a convention).
  • Promotion is the only crossing. A research-plane component becomes live-eligible only through the typed promotion boundary (StrategyPromotionRequest and per-repo equivalents), carrying its manifest fingerprint.
  • Fingerprints are load-bearing. The fingerprint recorded at discovery/manifest-emission time is what the deployment manifest signs and what drift detection compares against.

Per-repo enforcement​

  • alphaswarm_qap — mechanical CI gates (check_no_process_global_state, attestation checks).
  • alphaswarm_agents — hash-locked AgentSpec versions; derived (never hand-authored) roster manifests; duplicate-rejecting class registry.
  • alphaswarm / alphaswarm_worker — explicit BUILTIN_* registries and guarded execution runtimes; no entry-point scanning on the live path.
  • alphaswarm_platform — signed image provenance (SLSA/Cosign) and hash-locked terraform stack spec versions.