Veklom Guardian

Recovery is still a consequence. Give it a leash.

Guardian is the thin recovery plane around the local Veklom stack. It observes declared service state, diagnoses the failure domain, performs only pre-authorized recovery actions and preserves recovery evidence instead of becoming an unrestricted host administrator.

Current classification
Mixed verification
MIXED

Canonical Guardian source now includes signed manifest authority, application-level health checks, dependency gating, immutable LKG rollback and restart-budget state that survives Guardian restart. Native Windows SCM supervisor code is merged, but the live elevated install/kill/resurrection falsifier remains unsealed on the current laptop.

Architectural role
Policy-bounded software / service recovery
Owns
01Health and desired-state reconciliation for explicitly enrolled Veklom services.
02Bounded restart / rollback actions defined by the signed recovery manifest.
03Dependency-aware recovery so one failure does not trigger a full-stack restart storm.
04Persistent recovery-exhaustion state and structured/cryptographic recovery evidence where verified.
Boundary

Power stays narrow on purpose.

Guardian cannot widen its manifest authority into arbitrary Docker or shell administration.
It does not provide physical host, power, disk, router, ISP or multi-host high availability.
Database/data rollback and destructive state repair remain outside automatic recovery.
Interfaces

The surface should tell you where the truth comes from.

Veklom does not promote a configured URL or a code path into a runtime claim. Interfaces are shown so operators can verify the actual boundary themselves.

Canonical source
Veklom-Sovereign-Runtime-Infrastructure / guardian
Recovery policy
Signed manifest.yaml + pinned trust root
LKG
Immutable sha256 image identity
Remaining live gate
Windows SCM install + destructive wrapper restart proof
Claim boundary

Guardian is not advertised as zero downtime. Its claim is the exact set of failure modes it has actually recovered under bounded authority on the tested Windows/Docker profile; the Windows SCM resurrection row stays unsealed until the elevated live falsifier runs.