Kaidera OS · the operational ontology

One appliance. Every object accountable to a table, an endpoint or a file.

Kaidera OS runs your AI workers as a Linux VM appliance: the console native on the host, the harness CLIs beside it, Cortex memory and its services in podman. This site is the platform's ontology: the objects, links, actions and security of the whole stack, grounded in the real schema.

Status: CANONICAL (supersedes the 2026-09-02 first draft) · Date: 2026-09-0211 domains101 objects
LINUX VM · ROCKY / ALMA 10 · RHEL FOR CUSTOMERS · UBUNTU BEHIND THE PREFLIGHTKOS consolenative service on the VMSPA · orchestrator · dispatchterminal PTY lane · settingssystemd unit · service userHarness lanes · local CLIsopenkaiprimary · first-party · pinned releaseompinstalled · supported until OpenKai is matureclaude-codeoptional · customer-installed · supportedcodexoptional · customer-installed · supportedspawns · PTYCortex and services · seven podman containersdb · pgvector 0.8.2 / Postgres 18migrate · schema ledgercortex-api · memory, handoffs, bootproject-bootstrap · roster seedgraph-workerembed-workerpdf-workerMANAGED BY kos · CONTRACT IN THE CONTROL VOLUME · NAMED VOLUMES · LIFECYCLE JOURNAL (CAS)build · up · down · doctor · backup · restore · upgrade · prunepublished on 127.0.0.1 only · reached by the console and the local CLIsloopback
Three promises the architecture is judged on

Reliability

Services restart on their own, lifecycle mutations cannot half-complete, data is liftable and restore is proven by exact counts, a completion is never a claim, and a green suite is not evidence until a fresh host says so.

How it holds →

Control

One contract configures the appliance, who may act is data not a guess, nothing dispatches by surprise, no one approves their own work, and spend is gated by edition, entitlement and reservation.

The gates →

Security

Four layers from hashed tokens to mTLS, row-level security underneath, a process boundary on the host, and secrets that never reach code or a browser. Open items are listed, not hidden.

The layers →
The domains · open one to see its objects, links and actions
DOMAIN 1

Subjects & Identity

The root subject of every action is an Actor, not an agent name.
6 objects4 links4 actions
DOMAIN 2

Memory — the semantic layer

Cortex memory is event-sourced where it matters and freshness-tracked throughout. It maps to a 6-type cognitive memory taxonomy (docs/design/10-work-p…
16 objects0 links6 actions
DOMAIN 3

Coordination — the kinetic layer

Handoffs are the dispatch trigger; everything durable runs on a lease.
11 objects0 links6 actions
DOMAIN 4

Capability — the extension layer

The domain imports nothing outward. Enforced by the import-linter fitness gate (the 5th gate). Ports are pure Protocols + DTOs; adapters are the only …
8 objects0 links4 actions
DOMAIN 5

Commerce — two systems, one law

The binding law (.agents/rules/licensing-separation.md, CTO decision 2026-07-15): there are two licensing systems. KOS signed grants carry entitlement…
16 objects0 links0 actions
DOMAIN 6

Manifold — the meter-once inference gateway

Same cust-portal backend, manifold schema + manifold_app_dml role (migrations 098–110). OpenAI-compatible edge mounted at app root /v1 (not /api/v1).
6 objects0 links0 actions
DOMAIN 7

Tenancy & Security — the substrate

Rebrand invariant: the user-facing product term is Kaidera / Kaidera OS. Legacy engen identifiers (schema, roles, key ids, manifest keys) are machine …
3 objects0 links0 actions
DOMAIN 8

Distribution & Ecosystem

Naming invariant: Cortex is the permanent component name; stable surfaces cortex-, CORTEX_, cortex-api, cortex-pg, local-cortex/. A redist without Cor…
24 objects15 links0 actions
DOMAIN 9

OpenKai — independent product, one projection seam

Split from KOS 2026-08-14 (ADR §8.1 D3/D4). MIT-licensed open agent harness + TUI.
6 objects0 links0 actions
DOMAIN 10

FDE-OS — the turnkey (pack on the platform)

A kaidera-os.project-pack installing a complete FDE practice (full detail: docs/design/18-fde-os-turnkey.md).
5 objects0 links0 actions
DOMAIN 11

Cross-domain links — the decision spine

Actor ─creates→ Handoff ─claimed by→ Actor ─runs via→ Harness ─uses→ Model ─routes→ Manifold
0 objects0 links0 actions
The decision spine · how a decision travels across domains
projectsregistryactorcreates / claimsreferencesreturnedaccept | reworkruns viausesroutesreservationusagecompletedprojectedsubscriptionentitlementsgates mintunlock / capacitygates providersextendgovernhostshostsOrgProjectActorAgentHandoffEpic / TaskCompletionHandbackHarnessSkill / Rule / PortModelManifoldWalletRelay → LedgerWorkProductL1–L6 memorySubscriptionGrantEditionRLS + L1–L4Appliance
Subjects & IdentityMemoryCoordinationCapabilityCommerceManifoldTenancy & SecurityDistribution & EcosystemOpenKaiFDE-OSCross-domain links