dokime-app
Responsibility: what the Dokime application is, and how a runtime runs it. It holds the folded state and the transactions that change it, assembles that declaration with Harmos, and implements the product’s operational capabilities.
Public Surface
Section titled “Public Surface”The root exports Runtime, RuntimeHandle, RuntimeConfig,
RuntimeCredentialConfig, Error, Result, and InstalledArtifact. It
re-exports the vocabulary modules from dokime and exposes its ownership
anchors:
app: Dokime’s HarmosApplicationidentity, its type aliases, itsLanesadmission catalog, and the entry verbs a shell stands it up with;state: the folded state Harmos replays and snapshots;transactions: the closed vocabulary that is the only way that state changes, with host-owned record admission and transaction-local drafting beside it;streams: the typed Harmos stream rows the application publishes;traceability: the projections that say why a measured value is what it is;config:Config,RuntimeConfig, and brand resolution;capabilities: artifacts, credentials, documents, evidence, execution, exports, parameters, plots, installed artifacts, prompts, reports, telemetry, and traceability;runtime: commands, queries, handles, work admission, state, and shutdown.
The root is closed to lib.rs, app.rs, and error.rs; everything else above
is a folder module. Nothing here is compiled by a plugin: the dependency runs
dokime → dokime-app → shells, and never back.
Runtime Shape
Section titled “Runtime Shape”Commands mutate through typed Harmos transactions. Reads use the closed
RuntimeViewQuery set. Work is separated into a serialized execution lane,
a report lane with concurrency 4, and an unbounded default lane. Storage
combines a JSONL journal, snapshot, selected series store, and artifact store.
This crate owns product behavior; interfaces should adapt it rather than reimplementing it.
Entry verbs
Section titled “Entry verbs”app.rs holds Dokime’s Harmos identity card and the only ways the application
is stood up. app::launch(config).await is the live entry: it takes a
config::Config a shell has already resolved — Config::local(output_root)
describes the normal local composition — and returns its owning Runtime. That
assembly includes trusted builtins, explicitly configured plugins, host
telemetry binding, and branding, and opens its local execution backend under
output_root/executions.
Under the opt-in sim feature, app::simulate(origin, seed) stands the same
declaration up on Harmos’s deterministic runtime: no storage, no clock, and no
environment.
Hosts can instead use Runtime::start(config, storage) with an explicitly
composed dokime_storage::Storage for a minimal composition. The runtime does
not bind a listener itself; attach dokime-server::grpc::Server to its
RuntimeHandle when a native endpoint is needed. Installing a tracing
subscriber is the shell’s job; this crate only emits.