← Frontier InfraCONTENT HISTORYWHAT CHANGED · RULE-BASED ANALYSIS
Update to Frontier Infra
Snapshot Sep 30, 2026 · 23:14 UTC · version 0.3.2
Collection source: not recorded for this historical snapshot.
First saved snapshot
No earlier snapshot is available to establish a change.
Compare saved observations
Download comparison JSONFull technical diff · 0 changed fields
Full snapshot data
{
"description": "Implement, adapt, or harden a Frontier Infra Machine-shaped AI harness with a deterministic driver, durable state, fresh workers, independent verification, governance gates, budgets, quarantine, receipts, and runtime health.",
"included_files": [
{
"relative_path": "agents/openai.yaml",
"size_in_bytes": 217
}
],
"name": "machine-deployment",
"skill_md_contents": "---\nname: machine-deployment\ndescription: Implement, adapt, or harden a Frontier Infra Machine-shaped AI harness with a deterministic driver, durable state, fresh workers, independent verification, governance gates, budgets, quarantine, receipts, and runtime health.\n---\n\n# Deploy The Machine\n\nRead `../../references/philosophy.md`, `../../references/system-architecture.md`, `../../references/pattern-catalog.md`, and `../../references/threat-model.md`. If the control loop asks a model to choose the next transition, stop and use `conductor-pipeline` or explicitly redesign it as an orchestrator shape.\n\nYou are implementing the target Machine, not participating in it as a worker.\n\n## Target runtime contract\n\nImplement or adapt a ratifiable work-contract capability in the target runtime with:\n\n- one outcome-oriented definition of done;\n- runnable acceptance checks and immutable constraints;\n- an independently ratified contract (`ratified_by` differs from `proposed_by`) before the target runtime performs commit-capable work;\n- worker-run and wall-time budgets;\n- a conservative initial autonomy ceiling (`0` / propose-only).\n\nDo not use `goal-contract` to gate the current coding task unless the user\nexplicitly asks to govern the development workflow or a real ADL/Proctor-style\nintegration already enforces it.\n\n## Required deployment shape\n\n1. Fill `../../assets/harness-design-dossier.md`; inventory every durable mutation path.\n2. Define typed durable states, legal transitions, terminal quarantine, and write ordering.\n3. Implement queue, worker, verifier, store, gate, receipt, alert, and ground-truth ports behind narrow adapters.\n4. Persist before dispatch and before effects; enforce stable idempotency at the mutation store.\n5. Start a new bounded worker for every attempt from contract plus current state, not transcript history.\n6. Run contract checks in a distinct verifier and hard-deny success or mutation when it is absent, stale, or failed.\n7. Evaluate operator dial, contract ceiling, scoped verifier trust, and verified reversibility at the single mutation gate.\n8. Enforce attempt/resource budgets, acknowledgement escalation, terminal quarantine, and out-of-band override.\n9. Emit receipts for transitions and gate decisions; publish health for every critical organ and the monitor itself.\n10. Implement runtime health as four independent layers: process heartbeat, scheduler work-claim path, representative execution path, and governance gate path. Aggregate status must fail closed unless every layer passes a fresh check.\n\n## Reference implementations\n\nStart from the working deployments instead of a blank page: `machine-driver`\n(github.com/frontier-infra/machine-driver) is the deterministic Box-2 driver\nfor code work with Machine-L2 evidence; `conductor-public` is the\norchestrator-shaped ops template. Adapt; do not reinvent.\n\n## Target deployment verification\n\nRun kill/resume, duplicate replay, lying-worker, missing/stale-verifier, forged-rollback, cap/quarantine, override, bypass, and dead-workforce health fixtures against the target deployment before claiming enforcement.\n\nValidate runtime health with the published reducer — add `@frontier-infra/protocol`\nto the deployment and evaluate records with `evaluateRuntimeHealth` /\n`runtimeHealthExitCode`. When the user requests a conformance claim or the\ntarget's release criteria require it, score the target deployment repository\nwith the published CLI, which bundles The Machine's static kit:\n\n```sh\nnpx -y @frontier-infra/audit run <path-to-deployment-repo> --out <dir-outside-that-repo>\n```\n\nTreat the generated evidence packet as the source for conformance claims. Static implementation review establishes only a `structural candidate`; a README claim or a passing happy path does not establish a Machine level.\n\n## Boundaries\n\n- Start in propose-only mode; do not change to commit mode without a verified contract and operator authority.\n- Requeue failed work only within a fixed budget; quarantine and surface repeated failures.\n- Do not treat driver hash-chain logs as canonical AARs unless they are actually shaped, signed, and independently verified as AARs.\n"
}SHA-256 of public snapshot: fe1000d6e04e81b28e81ba78c478b6aedb819a8789e92620a4b1c40096d9e013