Start with what is available now

Start with the 0.1.0-alpha.6 reviewed-action walkthrough. It documents one actual governed effect and a separate credential-free newcomer check from anonymous public clones. Earlier releases remain available for their narrower consultation, saved-check, objective-read, connected-cache and installed-cadence profiles.

Guides

Public source

Use the component map for current source links and scope. A public repository is source availability, not an installed service or a hosted offering.

Do not install unpingable/nq for this path: it is the deprecated classic predecessor. The supported successor source is explicitly unpingable/constellation-nq; the repositories are not drop-in compatible.

Build the App Server source prerequisite

The alpha.6 review path used a public source-build prerequisite. This is not a binary download, provider setup, or authority to repeat the qualified action. Start from the public Codex source repository and detach the exact commit 97b0acd5ce2ccb3c87a763606696c35a450947f6; the branch name is only a locator.

git clone https://github.com/unpingable/codex.git codex-public
cd codex-public
git checkout --detach 97b0acd5ce2ccb3c87a763606696c35a450947f6
cd codex-rs
rustup toolchain install 1.95.0
CARGO_PROFILE_DEV_DEBUG=0 CARGO_INCREMENTAL=0 CARGO_BUILD_JOBS=2 \
  cargo +1.95.0 build --locked -p codex-app-server --bin codex-app-server
./target/debug/codex-app-server --version
./target/debug/codex-app-server --help

The source selects Rust 1.95.0 in codex-rs/rust-toolchain.toml; the package and binary are declared in codex-rs/app-server/Cargo.toml, and --locked uses the checked-in workspace lockfile. A fresh environment needs its normal public Cargo registry and Git dependency access. No offline cache, prebuilt binary, credential, or local campaign artifact is an installation prerequisite.

For a local process-only check, use an empty working directory and empty HOME/CODEX_HOME, then exchange only a JSON-lines initialize request, the initialized acknowledgement, and EOF over stdio. This verifies startup and protocol initialization only. Do not send a turn or thread request, configure a provider, or treat this check as review, authorization, execution, or tutorial completion.

What you can do safely today

  1. Read each repository's current README and public guide. Check the stated maturity, supported surface, and deployment assumptions for the component you need.
  2. For qualified Maude-only consultation, follow the versioned guide above. It uses one selected local plans.sqlite, no service or credential, and requires quiescent writers for a consistent aggregate. Drafting, checking, comparing, and locking a plan do not perform the planned work.
  3. For a finite saved SQLite check, maintenance annotation, retained attention decision and one local-inbox file, follow the released saved-check-attention/v1 guide. Its exact public Monitor, NQ and Nightshift revisions are fixed by the release manifest. It is attended and create-only, not an installed recurring monitor.
  4. For the direct local example of an installed-cadence tick, use the pinned installed-saved-check/v1 alpha.5 guide. Clean public-only anonymous-clone reproduction and retained-state inspection passed. The single-user fixture uses NQ's explicit debug-only same-UID helper exception; it does not establish systemd activation, post-acceptance response-loss behavior, remote notification delivery or human acknowledgment.
  5. For one independently reviewed, explicitly accepted governed action, use the pinned reviewed-local-copy/v1 alpha.6 guide. Its public newcomer path verifies immutable evidence and refusal behavior without credentials, another provider request, or another effect.
  6. For inspection, follow Constellation AG's Phosphor guide. Run scripts/run-operator-ui-demo.sh, then open http://127.0.0.1:8417/phosphor-ng. The page identifies its deterministic demo corpus. Phosphor can show joined records but cannot accept a plan, grant authority, rerun work, or settle an occurrence.
  7. Build or test only the component whose documented prerequisites you have. Do not infer compatibility between repository heads or between classic and successor components.

Credential-free and model-assisted routes

Deterministic, credential-free route: the alpha.6 public evidence check, Maude's local fixture path and Phosphor's deterministic demo require no model-provider credential. The alpha.6 check verifies a retained governed occurrence; it does not repeat the paid review or effect. The other two routes author/check sample material or render read-only fixture state.

Optional provider-assisted authoring route: the OpenRouter authoring guide pins the verified Maude runtime and Switchyard Runtime source. One live scope-bound proposal and diff has been verified. This optional route needs caller-owned provider enrollment, credential and budget; it does not accept a draft or authorize downstream work, and is not part of the credential-free path.

Synthetic-cache runtime status

The disposable four-container HTTP/cache workload has completed a local qualification and a separately governed teardown. That run used real NQ diagnostics, Pulse support, Maude compilation and handoff, Nightshift proposal handling, AG authorization, Docket execution, and a fresh NQ check of the recorded result. Teardown ended with no containers or network remaining for that run's exact Compose project.

What remains incomplete around the connected cache profile: an installed continuous service and a Nightshift successor using authenticated application evidence. Alpha.4's public-only newcomer reproduction passed, but it used an explicitly synthetic Standing input and did not qualify a deployment standing service. Alpha.6 qualifies a different reviewed local-copy composition; it does not upgrade the cache profile. A retained-result check establishes what happened in its attempt, not the cache's condition now.

Constellation Monitor is the canonical public source for Monitor and its hosted Pulse subsystem. This released tutorial still uses its exact pinned Pulse compatibility export. Reproduction requires those exact compatible source commits and built executables, an explicitly selected local Docker daemon and Compose, and a fresh disposable workspace. The tutorial image is selected by registry manifest digest sha256:46ee549c88617e9bc8acb843a326f1a5c0fa5608d7f9703509efe6d53b55f318, not merely by a mutable tag.

Design-flow work

Operational ECAD is a pre-alpha consumer and proving ground for the design-flow goal. It is not a family member, an automatic dependency, or a public installation route.

Before any effectful run

Use the repository's read-only preflight first. Confirm exact revisions, executable identities, local runtime access, storage availability, and an exclusive disposable workspace. Access to a Docker daemon commonly permits broad host-level container, filesystem, and network changes; treat that daemon and its socket as a deployment trust boundary, use a deliberately selected local daemon, and do not expose it to unreviewed work. Review what the run may change and who may authorize it. Afterward, inspect the attempt outcome, current observations, attention items, and settlement separately. If the outcome is uncertain, reconcile the existing attempt before considering any new action.

Read the responsibility and trust-boundary overview.