LockerPhycer

Keep host execution authority out of ordinary application code.

LockerPhycer is Veklom's governed security, key and identity surface and the boundary around sensitive host execution. It exists so a normal app container cannot quietly become the machine's root authority.

Current classification
Mixed verification
MIXED

The repository contains the canonical 8092 service, dependency-health surfaces and governed execution-cell code. Runtime identity must still be proven from the deployed commit, listener and service response; source code is not promoted into a live claim automatically.

Architectural role
Security / key / identity and host-execution boundary
Owns
01Security and authentication utilities used at the host-sensitive boundary.
02Key and identity integration surfaces for governed execution.
03Execution-cell isolation and host-broker contracts where those paths are explicitly verified.
04Dependency health and protocol identity surfaces for the canonical LockerPhycer service.
Boundary

Power stays narrow on purpose.

cAPI owns canonical cross-service connection behavior.
CAPPO owns consequence authorization and fail-closed governance.
Gnomledger owns durable evidence/provenance and BYOS owns tenant/workspace runtime state.
Interfaces

The surface should tell you where the truth comes from.

Veklom does not promote a configured URL or a code path into a runtime claim. Interfaces are shown so operators can verify the actual boundary themselves.

Canonical local port
8092
Health
GET /health
Local API docs
http://127.0.0.1:8092/docs when the canonical service is running
Integrations
cAPI · CAPPO · Gnomledger/PGL · BYOS
Claim boundary

LockerPhycer should be judged by the exact deployed boundary: commit identity, listener, signed authority, replay behavior and the real consequence path. A configured URL or a passing unit test is not enough to claim the host boundary is live.