Connect what already exists. Keep authority separate.
VLink is the portable connection primitive into Veklom: create a self-describing link, pair a workload, receive short-lived scoped access, execute through the link and leave verifiable activity without forcing an application rewrite.
Canonical VLink includes restart-safe single-node state, short-lived enrollment and workload access, cross-VLink replay denial, Ed25519-signed activity receipts and bounded retry-safe two-target failover. Each claim remains scoped to the exact behavior its tests cover.
Power stays narrow on purpose.
The surface should tell you where the truth comes from.
Veklom does not promote a configured URL or a code path into a runtime claim. Interfaces are shown so operators can verify the actual boundary themselves.
VLink's public promise should stay simple: link an existing system into Veklom with scoped temporary access and verifiable connection activity. It is not allowed to turn transport convenience into wider execution authority.
