Keep host execution authority out of ordinary application code.
LockerPhycer is Veklom's governed security, key and identity surface and the boundary around sensitive host execution. It exists so a normal app container cannot quietly become the machine's root authority.
The repository contains the canonical 8092 service, dependency-health surfaces and governed execution-cell code. Runtime identity must still be proven from the deployed commit, listener and service response; source code is not promoted into a live claim automatically.
Power stays narrow on purpose.
The surface should tell you where the truth comes from.
Veklom does not promote a configured URL or a code path into a runtime claim. Interfaces are shown so operators can verify the actual boundary themselves.
LockerPhycer should be judged by the exact deployed boundary: commit identity, listener, signed authority, replay behavior and the real consequence path. A configured URL or a passing unit test is not enough to claim the host boundary is live.
