Recovery is still a consequence. Give it a leash.
Guardian is the thin recovery plane around the local Veklom stack. It observes declared service state, diagnoses the failure domain, performs only pre-authorized recovery actions and preserves recovery evidence instead of becoming an unrestricted host administrator.
Canonical Guardian source now includes signed manifest authority, application-level health checks, dependency gating, immutable LKG rollback and restart-budget state that survives Guardian restart. Native Windows SCM supervisor code is merged, but the live elevated install/kill/resurrection falsifier remains unsealed on the current laptop.
Power stays narrow on purpose.
The surface should tell you where the truth comes from.
Veklom does not promote a configured URL or a code path into a runtime claim. Interfaces are shown so operators can verify the actual boundary themselves.
Guardian is not advertised as zero downtime. Its claim is the exact set of failure modes it has actually recovered under bounded authority on the tested Windows/Docker profile; the Windows SCM resurrection row stays unsealed until the elevated live falsifier runs.
