dokime-server
Responsibility: adapt typed native gRPC services to dokime-app.
Public Surface
Section titled “Public Surface”The crate exposes grpc::Server, grpc::Config, grpc::TlsIdentity, and
grpc::Error. The generated service adapters are grouped internally by
capability and implement the services declared in proto/dokime/v1/.
The adapters handle runtime queries and commands, installed artifact configuration flows, suite and cycle workflows, telemetry/plot streaming, reports, documents, artifacts, diagnostics, and branded assets.
Boundary
Section titled “Boundary”The server does not own hot state, scheduling, or durability policy. Those
remain in dokime-app.
Attached server lifecycle
Section titled “Attached server lifecycle”Server::start(runtime.handle(), config).await binds a native gRPC listener and
serves the existing runtime. address() returns the bound socket address and
local_endpoint() returns its native endpoint URI. shutdown().await stops
accepting calls and drains gRPC connections; after the graceful drain window it
cancels only listener-owned connection I/O. It does not stop the runtime. The
owning host shuts the runtime down after releasing all other handles.
The typed services are documented in the gRPC reference. There is no HTTP route, WebSocket protocol, OpenAPI layer, or separate asset server in this crate.
Native appearance
Section titled “Native appearance”grpc::Server registers the generated Appearance.GetAppearance and
Content.DownloadAppearanceAsset methods under Read authorization. Appearance
returns the complete resolved theme and branding data, with portable digest-bound
logo references. Downloads capture a registered image of at most 8 MiB before
streaming metadata, bounded chunks, and a digest completion marker. They accept
no caller filesystem paths. Refresh appearance after a missing or changed asset;
clients verify both the digest and the final successful gRPC status.
The runtime remains the authority for brand precedence. Source strings and container entries are bounded before cloning, and encoded responses obey the configured message limit. These native methods require no backend UI.