{"schemaVersion":"developer.reits.tech/runner-factory-controller-service-runtime-bootstrap/v1","status":"SERVICE_RUNTIME_BOOTSTRAP_IMPLEMENTED_NOT_INSTALLED","observedAt":"2026-07-21T00:00:00Z","scope":{"mode":"TEST_ONLY_SERVICE_HANDLER_NO_LISTENER","configurationInput":"VERIFIED_RESOLVED_BUNDLE_ONLY","readinessInput":"ELEVEN_SIGNED_GATE_ATTESTATIONS","output":"OPAQUE_IN_MEMORY_REQUEST_HANDLER","networkAuthority":"NONE","productionWebhookPolicy":"ALWAYS_BLOCKED","mutationPolicy":"NO_WRITE_NO_LISTENER_NO_LIFECYCLE_ADAPTER"},"truth":{"productionBootstraps":0,"productionServiceHandlers":0,"configuredReadinessGates":0,"runtimeBootstrapReceipts":0,"runtimeHandlerProjections":0,"controllerListeners":0,"productionWebhooksAccepted":0,"externalReadsExecuted":0,"externalWritesExecuted":0,"mutationsExecuted":0,"secretValuesRecorded":0,"paidResourcesCreated":false,"deploymentPermitted":false},"implementation":{"bootstrap":"ops/runner-factory/controller-service-runtime-bootstrap.mjs","configurationLoader":"ops/runner-factory/controller-runtime-configuration.mjs","componentComposer":"ops/runner-factory/controller-bootstrap-composition.mjs","runtimeAssembly":"ops/runner-factory/controller-runtime-assembly.mjs","serviceCore":"ops/runner-factory/controller-service-core.mjs","fixtureRegistry":"ops/runner-factory/controller-service-runtime-bootstrap-fixtures.json","verifier":"scripts/verify-runner-factory-controller-service-runtime-bootstrap.mjs","productionEntrypoint":"UNCHANGED_UNCONFIGURED"},"operations":[{"id":"prepare","guard":"resolved single-use bundle plus eleven positively verified Gate attestations","result":"opaque digest-bound service runtime capability"},{"id":"verify","guard":"exact upstream identities, zero-authority truth and receipt digest","result":"standalone runtime bootstrap receipt verdict"},{"id":"project","guard":"live unexpired capability may project once","result":"guarded in-memory request handler without a network listener"},{"id":"dispose","guard":"projection state is terminally revoked before component cleanup","result":"six bootstrap components disposed and future calls denied"}],"chain":[{"id":"configuration","input":"root-owned manifest + 11 ConfigRef + 1 KeyRef","proof":"CONFIGURATION_RESOLVED bundle digest"},{"id":"composition","input":"six closed TEST_ONLY factories","proof":"bootstrap receipt + opaque capability"},{"id":"assembly","input":"runtime identity + 11 signed Gate attestations","proof":"READY_VERIFIED packet + receipt-backed runtime"},{"id":"service","input":"safe config + frozen policy/template + verified runtime","proof":"ready in-memory handler; webhook remains blocked"},{"id":"network","input":"none","proof":"listener authorization absent and listener starts zero"}],"stateModel":[{"id":"UNPREPARED","meaning":"no configuration bundle or component capability has been consumed"},{"id":"COMPOSING","meaning":"the six-component TEST_ONLY closure is being built"},{"id":"ASSEMBLING","meaning":"identity and all Gate attestations are being verified"},{"id":"READY_HANDLER","meaning":"a receipt-backed service core exists only in memory"},{"id":"PROJECTED","meaning":"one guarded request function has been projected"},{"id":"DISPOSING","meaning":"future request calls are denied before reverse cleanup starts"},{"id":"DISPOSED","meaning":"all six components are closed and the handler is revoked"},{"id":"DENIED","meaning":"configuration, composition, assembly, service, receipt or cleanup failed closed"}],"invariants":["the orchestrator accepts only the exact TEST_ONLY bootstrap composer surface","service configuration remains EVIDENCE_ONLY on loopback port 8110","apply, public routing and external writes remain disabled","policy, worker template and service configuration are cloned and deeply frozen","a resolved configuration bundle is consumed only through the reviewed composer","exactly five read-only Readers and one verify-only attestation component remain underneath the capability","runtime assembly uses only the verifier projected by the live composition capability","runtime identity remains bound to the manifest controller, host and service identity","all eleven readiness Gate attestations are required before service construction","duplicate, stale, future, wrong-scope and bad-signature attestations deny bootstrap","a BLOCKED_CONFIGURATION assembly packet never creates a service handler","the runtime projection is reconstructed only from the verified readiness receipt","service readiness must report 11 of 11 with a verified receipt","the service factory may expose only handle, readiness, response headers and mode","the projected capability exposes one guarded request function and no socket function","no listen, server or start operation is accepted from the service factory","production webhook handling remains 503 even inside a ready TEST_ONLY handler","health and readiness requests remain loopback-context only","one runtime capability may project a handler exactly once","forged and replayed handles are rejected","expired readiness evidence cannot be prepared or projected","disposal revokes the request guard before component cleanup begins","post-disposal handler calls are rejected","prepare failure disposes every successfully composed component","cleanup ambiguity fails closed and never emits a capability","bootstrap, assembly and readiness receipt digests remain linked in one receipt","runtime bootstrap identity is deterministic for composition, assembly packet and observed time","receipt verification rejects shape, truth, identity and digest drift","external reads, writes, mutations and listener starts remain zero during orchestration","the production Controller entrypoint remains unconfigured and port 8110 remains absent"],"verification":{"status":"PASS_FIXTURE_ONLY","fixtures":40,"acceptedOutcomes":7,"deniedOutcomes":33,"readyHandlerProjections":4,"blockedReadinessCases":2,"attestationDenials":10,"runtimeIdentityDenials":3,"configurationAndFactoryDenials":4,"serviceFactoryDenials":3,"constructorDenials":3,"capabilityDenials":3,"receiptDenials":2,"timeDenials":2,"cleanupDenials":1,"productionWebhooksAccepted":0,"externalReadsExecuted":0,"externalWritesExecuted":0,"mutationsExecuted":0,"listenerStarts":0},"failureClasses":[{"code":"RF_SERVICE_BOOTSTRAP_DEPENDENCIES|CONFIG|INPUT","effect":"deny incomplete, extended or authority-bearing orchestration inputs"},{"code":"RF_BOOTSTRAP_*","effect":"deny unverified configuration, factory drift, replay and component cleanup ambiguity"},{"code":"RF_ASSEMBLY_*","effect":"deny runtime identity, attestation, signature, time and packet drift"},{"code":"RF_SERVICE_BOOTSTRAP_READINESS|TIME","effect":"deny partial or expired readiness before a handler exists"},{"code":"RF_SERVICE_BOOTSTRAP_SERVICE","effect":"deny service factories that throw, stay unready or expose excess authority"},{"code":"RF_SERVICE_BOOTSTRAP_HANDLE|DISPOSED|CLEANUP","effect":"deny forged, replayed, revoked or ambiguously disposed capabilities"},{"code":"RF_SERVICE_BOOTSTRAP_RECEIPT|DIGEST","effect":"deny runtime bootstrap truth, identity and provenance drift"}],"productionPrerequisites":["install and verify the root-owned runtime manifest and all twelve typed references","replace all six TEST_ONLY factories with reviewed production read-only implementations","issue a dedicated host and non-login service identity receipt","produce fresh signed evidence for all eleven readiness Gates","prove the production service handler against real read adapters without granting write authority","add an independent owner-approved listener authorization receipt with expiry and rollback binding","install the hardened systemd unit only on the dedicated control-plane host","expose loopback through an authenticated reverse proxy only after security and runtime review","run live readiness, webhook denial, incident, rollback and cost-control acceptance before activation"],"fixtureRegistry":{"schemaVersion":"developer.reits.tech/runner-factory-controller-service-runtime-bootstrap-fixtures/v1","fixedTime":"2026-07-21T00:00:00.000Z","cases":[{"id":"RFSB-01","profile":"ready-project","expected":"ACCEPT","outcome":"SERVICE_HANDLER_PROJECTED_TEST_ONLY"},{"id":"RFSB-02","profile":"ready-health","expected":"ACCEPT","outcome":"ALIVE_READY"},{"id":"RFSB-03","profile":"ready-readiness","expected":"ACCEPT","outcome":"READY_11_OF_11"},{"id":"RFSB-04","profile":"ready-webhook-blocked","expected":"ACCEPT","outcome":"PRODUCTION_WEBHOOK_503"},{"id":"RFSB-05","profile":"dispose-before-project","expected":"ACCEPT","outcome":"DISPOSED"},{"id":"RFSB-06","profile":"dispose-after-project","expected":"ACCEPT","outcome":"DISPOSED"},{"id":"RFSB-07","profile":"dispose-replay","expected":"ACCEPT","outcome":"DISPOSED_REPLAY"},{"id":"RFSB-08","profile":"zero-attestations","expected":"DENY","errorCode":"RF_SERVICE_BOOTSTRAP_READINESS"},{"id":"RFSB-09","profile":"one-missing-attestation","expected":"DENY","errorCode":"RF_SERVICE_BOOTSTRAP_READINESS"},{"id":"RFSB-10","profile":"duplicate-attestation","expected":"DENY","errorCode":"RF_ASSEMBLY_ATTESTATION_SET"},{"id":"RFSB-11","profile":"invalid-signature","expected":"DENY","errorCode":"RF_ASSEMBLY_SIGNATURE"},{"id":"RFSB-12","profile":"verifier-false","expected":"DENY","errorCode":"RF_ASSEMBLY_SIGNATURE"},{"id":"RFSB-13","profile":"expired-attestation","expected":"DENY","errorCode":"RF_ASSEMBLY_ATTESTATION_TIME"},{"id":"RFSB-14","profile":"future-attestation","expected":"DENY","errorCode":"RF_ASSEMBLY_ATTESTATION_TIME"},{"id":"RFSB-15","profile":"wrong-subject","expected":"DENY","errorCode":"RF_ASSEMBLY_ATTESTATION"},{"id":"RFSB-16","profile":"wrong-manifest-digest","expected":"DENY","errorCode":"RF_ASSEMBLY_ATTESTATION"},{"id":"RFSB-17","profile":"wrong-identity-digest","expected":"DENY","errorCode":"RF_ASSEMBLY_ATTESTATION"},{"id":"RFSB-18","profile":"wrong-issuer-key","expected":"DENY","errorCode":"RF_ASSEMBLY_ATTESTATION"},{"id":"RFSB-19","profile":"unknown-gate","expected":"DENY","errorCode":"RF_ASSEMBLY_ATTESTATION"},{"id":"RFSB-20","profile":"identity-stale","expected":"DENY","errorCode":"RF_ASSEMBLY_IDENTITY_TIME"},{"id":"RFSB-21","profile":"identity-shared-host","expected":"DENY","errorCode":"RF_ASSEMBLY_IDENTITY"},{"id":"RFSB-22","profile":"identity-wrong-user","expected":"DENY","errorCode":"RF_ASSEMBLY_IDENTITY"},{"id":"RFSB-23","profile":"blocked-bundle","expected":"DENY","errorCode":"RF_BOOTSTRAP_CONFIGURATION_BLOCKED"},{"id":"RFSB-24","profile":"tampered-bundle","expected":"DENY","errorCode":"RF_BOOTSTRAP_CONFIGURATION_VERIFY"},{"id":"RFSB-25","profile":"expired-bundle","expected":"DENY","errorCode":"RF_BOOTSTRAP_CONFIGURATION_TIME"},{"id":"RFSB-26","profile":"factory-failure","expected":"DENY","errorCode":"RF_BOOTSTRAP_FACTORY"},{"id":"RFSB-27","profile":"unsafe-service-extra-key","expected":"DENY","errorCode":"RF_SERVICE_BOOTSTRAP_SERVICE"},{"id":"RFSB-28","profile":"unsafe-service-unready","expected":"DENY","errorCode":"RF_SERVICE_BOOTSTRAP_SERVICE"},{"id":"RFSB-29","profile":"service-factory-throws","expected":"DENY","errorCode":"RF_SERVICE_BOOTSTRAP_SERVICE"},{"id":"RFSB-30","profile":"invalid-config-mode","expected":"DENY","errorCode":"RF_SERVICE_BOOTSTRAP_CONFIG"},{"id":"RFSB-31","profile":"invalid-config-port","expected":"DENY","errorCode":"RF_SERVICE_BOOTSTRAP_CONFIG"},{"id":"RFSB-32","profile":"forged-handle","expected":"DENY","errorCode":"RF_SERVICE_BOOTSTRAP_HANDLE"},{"id":"RFSB-33","profile":"project-replay","expected":"DENY","errorCode":"RF_SERVICE_BOOTSTRAP_HANDLE"},{"id":"RFSB-34","profile":"use-after-dispose","expected":"DENY","errorCode":"RF_SERVICE_BOOTSTRAP_DISPOSED"},{"id":"RFSB-35","profile":"receipt-status-tamper","expected":"DENY","errorCode":"RF_SERVICE_BOOTSTRAP_RECEIPT"},{"id":"RFSB-36","profile":"receipt-digest-tamper","expected":"DENY","errorCode":"RF_SERVICE_BOOTSTRAP_DIGEST"},{"id":"RFSB-37","profile":"invalid-clock","expected":"DENY","errorCode":"RF_BOOTSTRAP_CLOCK"},{"id":"RFSB-38","profile":"expired-before-project","expected":"DENY","errorCode":"RF_SERVICE_BOOTSTRAP_TIME"},{"id":"RFSB-39","profile":"cleanup-failure","expected":"DENY","errorCode":"RF_SERVICE_BOOTSTRAP_CLEANUP"},{"id":"RFSB-40","profile":"unsafe-composer-surface","expected":"DENY","errorCode":"RF_SERVICE_BOOTSTRAP_DEPENDENCIES"}]},"discovery":{"controller":"/api/runner-factory/controller","configuration":"/api/runner-factory/controller/runtime-configuration","composition":"/api/runner-factory/controller/bootstrap-composition","assembly":"/api/runner-factory/controller/runtime-assembly","servicePackage":"/api/runner-factory/controller","workbench":"/release-foundation#service-runtime-bootstrap","schema":"/schemas/runner-factory-controller-service-runtime-bootstrap.v1.schema.json"}}