code wiki / mgmt
topic: mgmt
45 modules sharing the mgmt name family (derived from the tree's prefix discipline).
The 'mgmt' topic family in the Nishi sovereign ecosystem provides the control-plane infrastructure for managing and securing the system. It includes the nx_mgmt_api, which serves as the primary adapter for the API ring, and nx_mgmt_authz, which handles authorization to close privilege-escalation gaps. The nx_mgmt_client acts as a sovereign client for interacting with the live control-plane API, ensuring secure and measured management across the ecosystem.
auto-narrated by the local model from this topic's module headers; links verified against the wiki index.
narrated overview -- maintained by the narration lane, module links verified against this wiki.
| module | description | lines | funcs |
|---|---|---|---|
| nx_mgmt_api.nx | THE IO / TRANSPORT ring of the sovereign ecosystem control-plane API (the primary adapter). | 4044 | 128 |
| nx_mgmt_api.pre-toolchain-20260910.nx | THE IO / TRANSPORT ring of the sovereign ecosystem control-plane API (the primary adapter). | 4040 | 125 |
| nx_mgmt_api_gate.nx | SOVEREIGN in-process referee for the ecosystem control-plane API. NO socket, NO | 707 | 24 |
| nx_mgmt_api_search_candidate_t330.nx | THE IO / TRANSPORT ring of the sovereign ecosystem control-plane API (the primary adapter). | 4044 | 128 |
| nx_mgmt_api_toolchain_session_20260910.nx | THE IO / TRANSPORT ring of the sovereign ecosystem control-plane API (the primary adapter). | 4027 | 127 |
| nx_mgmt_authz.nx | the AUTHORIZATION tier of the management plane (closes the documented privilege-escalation: | 75 | 6 |
| nx_mgmt_authz_gate.nx | PURE isolation gate for the management AUTHORIZATION tier (nx_mgmt_authz). | 53 | 7 |
| nx_mgmt_call.nx | the mgmt-API driver forked as an MCP tool. Mints a FRESH admin session from the NAS key bundle | 161 | 5 |
| nx_mgmt_call_candidate_t189.nx | the mgmt-API driver forked as an MCP tool. Mints a FRESH admin session from the NAS key bundle | 156 | 5 |
| nx_mgmt_call_gate.nx | TEETH FOR THE CONTROL-PLANE DRIVER FAILURE PATH, PROVEN WITHOUT CAUSING A FAILURE. | 87 | 2 |
| nx_mgmt_cap_candidate_t186.nx | THE IO / TRANSPORT ring of the sovereign ecosystem control-plane API (the primary adapter). | 4042 | 127 |
| nx_mgmt_cap_data_candidate_t186.nx | the DATA / ADAPTER layer of the management plane (the OUTER ring; secondary adapters). | 2857 | 115 |
| nx_mgmt_cap_entry_gate_t187.nx | 22 | 1 | |
| nx_mgmt_cap_mint_gate.nx | prove POST /api/cap/mint is fail-closed least-authority. In-process referee | 140 | 10 |
| nx_mgmt_census.nx | the MEASURED, HONEST ecosystem-MANAGEMENT scorecard vs the June-2026 SOTA (operator: | 104 | 9 |
| nx_mgmt_client.nx | SOVEREIGN CLIENT for the live control-plane mgmt API (nx_mgmt_api.nx, https://<host>/api). | 689 | 23 |
| nx_mgmt_client_gate.nx | in-process referee for the sovereign mgmt-API client codec. NO socket / NO creds: | 142 | 7 |
| nx_mgmt_core.nx | the LOGIC / DOMAIN layer of the management plane (the hexagonal CORE). | 37 | 5 |
| nx_mgmt_core_gate.nx | PURE unit gate for the management LOGIC layer. The whole point of the layering: the | 54 | 4 |
| nx_mgmt_data.nx | the DATA / ADAPTER layer of the management plane (the OUTER ring; secondary adapters). | 2860 | 115 |
| nx_mgmt_data.pre-toolchain-20260910.nx | the DATA / ADAPTER layer of the management plane (the OUTER ring; secondary adapters). | 2785 | 111 |
| nx_mgmt_data_toolchain_session_20260910.nx | the DATA / ADAPTER layer of the management plane (the OUTER ring; secondary adapters). | 2851 | 114 |
| nx_mgmt_deploy_candidate_t185.nx | THE IO / TRANSPORT ring of the sovereign ecosystem control-plane API (the primary adapter). | 4046 | 127 |
| nx_mgmt_deploy_data_candidate_t185.nx | the DATA / ADAPTER layer of the management plane (the OUTER ring; secondary adapters). | 2852 | 115 |
| nx_mgmt_gaterun_gate.nx | GATE for the control plane's two lane-J fixes (2026-08-23): | 304 | 8 |
| nx_mgmt_organ_capacity_gate_t180.nx | Actual management handler gate. Fixture registry is isolated in a unique temporary directory; | 87 | 6 |
| nx_mgmt_private_canonical_gate_t189.nx | 44 | 3 | |
| nx_mgmt_private_connected_gate_t189.nx | 44 | 3 | |
| nx_mgmt_private_discovery_gate_t189.nx | 53 | 3 | |
| nx_mgmt_private_response.nx | Private response handoff used by nx_mgmt_call; never emits upstream body bytes. | 137 | 14 |
| nx_mgmt_private_response_candidate_t189.nx | Private response handoff used by nx_mgmt_call; never emits upstream body bytes. | 137 | 14 |
| nx_mgmt_private_response_gate_t189.nx | 51 | 2 | |
| nx_mgmt_proc_read_gate.nx | Regression for the management API's real bounded proc reader. | 35 | 1 |
| nx_mgmt_promote_gate.nx | referee for POST /api/promote: fail-closed, never-brick, AND lease-clean. | 455 | 14 |
| nx_mgmt_publish_bin.nx | submit the ecosystem CONTROL-PLANE binary (nx_mgmt_api) to the publisher | 48 | 4 |
| nx_mgmt_research.nx | THIN structured ECOSYSTEM-MANAGEMENT / CONTROL-PLANE research source organ. | 46 | 1 |
| nx_mgmt_session_mint.nx | CLI over nx_session_mint_lib: mint an M5 no-cookie session token (the X-Nishi-Session | 21 | 1 |
| nx_mgmt_session_mint_gate.nx | proves the session minter: a token minted by msm_mint_raw (loading ed_priv from a | 90 | 3 |
| nx_mgmt_snapshot.nx | R1b: the LIVE health-snapshot PRODUCER for the sovereign management plane. | 181 | 9 |
| nx_mgmt_snapshot_gate.nx | PURE isolation gate for the R1b health-snapshot PRODUCER (nx_mgmt_snapshot). | 102 | 7 |
| nx_mgmt_snapshot_run.nx | the COMPLETE, self-contained health-snapshot PRODUCER binary (R1b, live path). | 274 | 9 |
| nx_mgmt_snapshot_run_gate.nx | PURE isolation gate for the producer's INSTANCE-vs-fork-child rule | 61 | 4 |
| nx_mgmt_tools_register_gate.nx | prove POST /api/tools/register is fail-closed + idempotent. In-process | 221 | 10 |
| nx_mgmt_upload.nx | CAP-API-UPLOAD: the #1 census gap = binary UPLOAD over /api, the "not-on-LAN deploy" | 53 | 3 |
| nx_mgmt_upload_gate.nx | SOVEREIGN in-process referee for the /api/upload keystone (chunked artifact publish). | 327 | 12 |