Start with what is available now
Start with the 0.1.0-alpha.6 reviewed-action walkthrough. It documents one actual governed effect and a separate credential-free newcomer check from anonymous public clones. Earlier releases remain available for their narrower consultation, saved-check, objective-read, connected-cache and installed-cadence profiles.
Guides
- Integration — choose the smallest evidence-backed composition for consultation, attention or one governed action.
- Recipes — runnable public recipes with exact prerequisites, substitutions, recovery behavior and limits.
- Operations — lifecycle, retention, backup, recovery and upgrade limits for released profiles.
- Troubleshooting — inspect, preserve and report problems without blindly repeating uncertain work.
- Notifications, release policy and the over-the-wire roadmap.
- Earlier prototypes and historical exhibits are in the archive.
Public source
Use the component map for current source links and scope. A public repository is source availability, not an installed service or a hosted offering.
- Constellation AG — authorization and the read-only Phosphor inspector: public source. Alpha.6 pins authorization runtime
4dafc1a774178a9e09e75afc6e22c71052fd3dceand evidence readere0f30de668234935cdbc4b0bd04f5dc13838411d. - Constellation Docket — custody and settlement for bounded attempts: public source.
- Constellation Nightshift — currentness and attention over time: public source.
- Constellation NQ — bounded diagnostic evaluation, saved SQLite checks, maintenance projection and local notification custody. The released saved-check profile pins public NQ source
e259852ed58b8c0bf65a629b3c494afba28d9ce9. The repository's public release guide documents other component-qualified cuts. Apart from the NQ 0.2.0 package, these are source-only, and component cuts are not interchangeable by version string. - Constellation Linear Accountant — deterministic bounded arithmetic/reference decisions, with a separately scoped Lean model: public source. It does not authorize action.
- Maude — plan authoring and checking: use the released versioned
maude-plan-consultation/v1guide for the qualified Maude-only consultation path (public source7d196e2ab0e78cca46bd34af1ce6e9cbc9bf7fa6; kit013b05d0c5258ee1bc898a51b271e47d49c4f865), or read the local authoring walkthrough.
Do not install unpingable/nq for this path: it is the deprecated classic predecessor. The supported successor source is explicitly unpingable/constellation-nq; the repositories are not drop-in compatible.
Build the App Server source prerequisite
The alpha.6 review path used a public source-build prerequisite. This is not a binary download, provider setup, or authority to repeat the qualified action. Start from the public Codex source repository and detach the exact commit 97b0acd5ce2ccb3c87a763606696c35a450947f6; the branch name is only a locator.
git clone https://github.com/unpingable/codex.git codex-public
cd codex-public
git checkout --detach 97b0acd5ce2ccb3c87a763606696c35a450947f6
cd codex-rs
rustup toolchain install 1.95.0
CARGO_PROFILE_DEV_DEBUG=0 CARGO_INCREMENTAL=0 CARGO_BUILD_JOBS=2 \
cargo +1.95.0 build --locked -p codex-app-server --bin codex-app-server
./target/debug/codex-app-server --version
./target/debug/codex-app-server --help
The source selects Rust 1.95.0 in codex-rs/rust-toolchain.toml; the package and binary are declared in codex-rs/app-server/Cargo.toml, and --locked uses the checked-in workspace lockfile. A fresh environment needs its normal public Cargo registry and Git dependency access. No offline cache, prebuilt binary, credential, or local campaign artifact is an installation prerequisite.
For a local process-only check, use an empty working directory and empty HOME/CODEX_HOME, then exchange only a JSON-lines initialize request, the initialized acknowledgement, and EOF over stdio. This verifies startup and protocol initialization only. Do not send a turn or thread request, configure a provider, or treat this check as review, authorization, execution, or tutorial completion.
What you can do safely today
- Read each repository's current README and public guide. Check the stated maturity, supported surface, and deployment assumptions for the component you need.
- For qualified Maude-only consultation, follow the versioned guide above. It uses one selected local
plans.sqlite, no service or credential, and requires quiescent writers for a consistent aggregate. Drafting, checking, comparing, and locking a plan do not perform the planned work. - For a finite saved SQLite check, maintenance annotation, retained attention decision and one local-inbox file, follow the released
saved-check-attention/v1guide. Its exact public Monitor, NQ and Nightshift revisions are fixed by the release manifest. It is attended and create-only, not an installed recurring monitor. - For the direct local example of an installed-cadence tick, use the pinned
installed-saved-check/v1alpha.5 guide. Clean public-only anonymous-clone reproduction and retained-state inspection passed. The single-user fixture uses NQ's explicit debug-only same-UID helper exception; it does not establish systemd activation, post-acceptance response-loss behavior, remote notification delivery or human acknowledgment. - For one independently reviewed, explicitly accepted governed action, use the pinned
reviewed-local-copy/v1alpha.6 guide. Its public newcomer path verifies immutable evidence and refusal behavior without credentials, another provider request, or another effect. - For inspection, follow Constellation AG's Phosphor guide. Run
scripts/run-operator-ui-demo.sh, then openhttp://127.0.0.1:8417/phosphor-ng. The page identifies its deterministic demo corpus. Phosphor can show joined records but cannot accept a plan, grant authority, rerun work, or settle an occurrence. - Build or test only the component whose documented prerequisites you have. Do not infer compatibility between repository heads or between classic and successor components.
Credential-free and model-assisted routes
Deterministic, credential-free route: the alpha.6 public evidence check, Maude's local fixture path and Phosphor's deterministic demo require no model-provider credential. The alpha.6 check verifies a retained governed occurrence; it does not repeat the paid review or effect. The other two routes author/check sample material or render read-only fixture state.
Optional provider-assisted authoring route: the OpenRouter authoring guide pins the verified Maude runtime and Switchyard Runtime source. One live scope-bound proposal and diff has been verified. This optional route needs caller-owned provider enrollment, credential and budget; it does not accept a draft or authorize downstream work, and is not part of the credential-free path.
Synthetic-cache runtime status
The disposable four-container HTTP/cache workload has completed a local qualification and a separately governed teardown. That run used real NQ diagnostics, Pulse support, Maude compilation and handoff, Nightshift proposal handling, AG authorization, Docket execution, and a fresh NQ check of the recorded result. Teardown ended with no containers or network remaining for that run's exact Compose project.
What remains incomplete around the connected cache profile: an installed continuous service and a Nightshift successor using authenticated application evidence. Alpha.4's public-only newcomer reproduction passed, but it used an explicitly synthetic Standing input and did not qualify a deployment standing service. Alpha.6 qualifies a different reviewed local-copy composition; it does not upgrade the cache profile. A retained-result check establishes what happened in its attempt, not the cache's condition now.
Constellation Monitor is the canonical public source for Monitor and its hosted Pulse subsystem. This released tutorial still uses its exact pinned Pulse compatibility export. Reproduction requires those exact compatible source commits and built executables, an explicitly selected local Docker daemon and Compose, and a fresh disposable workspace. The tutorial image is selected by registry manifest digest sha256:46ee549c88617e9bc8acb843a326f1a5c0fa5608d7f9703509efe6d53b55f318, not merely by a mutable tag.
Design-flow work
Operational ECAD is a pre-alpha consumer and proving ground for the design-flow goal. It is not a family member, an automatic dependency, or a public installation route.
Before any effectful run
Use the repository's read-only preflight first. Confirm exact revisions, executable identities, local runtime access, storage availability, and an exclusive disposable workspace. Access to a Docker daemon commonly permits broad host-level container, filesystem, and network changes; treat that daemon and its socket as a deployment trust boundary, use a deliberately selected local daemon, and do not expose it to unreviewed work. Review what the run may change and who may authorize it. Afterward, inspect the attempt outcome, current observations, attention items, and settlement separately. If the outcome is uncertain, reconcile the existing attempt before considering any new action.