code wiki / mgmt

topic: mgmt

45 modules sharing the mgmt name family (derived from the tree's prefix discipline).

The 'mgmt' topic family in the Nishi sovereign ecosystem provides the control-plane infrastructure for managing and securing the system. It includes the nx_mgmt_api, which serves as the primary adapter for the API ring, and nx_mgmt_authz, which handles authorization to close privilege-escalation gaps. The nx_mgmt_client acts as a sovereign client for interacting with the live control-plane API, ensuring secure and measured management across the ecosystem.

auto-narrated by the local model from this topic's module headers; links verified against the wiki index.

narrated overview -- maintained by the narration lane, module links verified against this wiki.

moduledescriptionlinesfuncs
nx_mgmt_api.nxTHE IO / TRANSPORT ring of the sovereign ecosystem control-plane API (the primary adapter).4044128
nx_mgmt_api.pre-toolchain-20260910.nxTHE IO / TRANSPORT ring of the sovereign ecosystem control-plane API (the primary adapter).4040125
nx_mgmt_api_gate.nxSOVEREIGN in-process referee for the ecosystem control-plane API. NO socket, NO70724
nx_mgmt_api_search_candidate_t330.nxTHE IO / TRANSPORT ring of the sovereign ecosystem control-plane API (the primary adapter).4044128
nx_mgmt_api_toolchain_session_20260910.nxTHE IO / TRANSPORT ring of the sovereign ecosystem control-plane API (the primary adapter).4027127
nx_mgmt_authz.nxthe AUTHORIZATION tier of the management plane (closes the documented privilege-escalation:756
nx_mgmt_authz_gate.nxPURE isolation gate for the management AUTHORIZATION tier (nx_mgmt_authz).537
nx_mgmt_call.nxthe mgmt-API driver forked as an MCP tool. Mints a FRESH admin session from the NAS key bundle1615
nx_mgmt_call_candidate_t189.nxthe mgmt-API driver forked as an MCP tool. Mints a FRESH admin session from the NAS key bundle1565
nx_mgmt_call_gate.nxTEETH FOR THE CONTROL-PLANE DRIVER FAILURE PATH, PROVEN WITHOUT CAUSING A FAILURE.872
nx_mgmt_cap_candidate_t186.nxTHE IO / TRANSPORT ring of the sovereign ecosystem control-plane API (the primary adapter).4042127
nx_mgmt_cap_data_candidate_t186.nxthe DATA / ADAPTER layer of the management plane (the OUTER ring; secondary adapters).2857115
nx_mgmt_cap_entry_gate_t187.nx221
nx_mgmt_cap_mint_gate.nxprove POST /api/cap/mint is fail-closed least-authority. In-process referee14010
nx_mgmt_census.nxthe MEASURED, HONEST ecosystem-MANAGEMENT scorecard vs the June-2026 SOTA (operator:1049
nx_mgmt_client.nxSOVEREIGN CLIENT for the live control-plane mgmt API (nx_mgmt_api.nx, https://<host>/api).68923
nx_mgmt_client_gate.nxin-process referee for the sovereign mgmt-API client codec. NO socket / NO creds:1427
nx_mgmt_core.nxthe LOGIC / DOMAIN layer of the management plane (the hexagonal CORE).375
nx_mgmt_core_gate.nxPURE unit gate for the management LOGIC layer. The whole point of the layering: the544
nx_mgmt_data.nxthe DATA / ADAPTER layer of the management plane (the OUTER ring; secondary adapters).2860115
nx_mgmt_data.pre-toolchain-20260910.nxthe DATA / ADAPTER layer of the management plane (the OUTER ring; secondary adapters).2785111
nx_mgmt_data_toolchain_session_20260910.nxthe DATA / ADAPTER layer of the management plane (the OUTER ring; secondary adapters).2851114
nx_mgmt_deploy_candidate_t185.nxTHE IO / TRANSPORT ring of the sovereign ecosystem control-plane API (the primary adapter).4046127
nx_mgmt_deploy_data_candidate_t185.nxthe DATA / ADAPTER layer of the management plane (the OUTER ring; secondary adapters).2852115
nx_mgmt_gaterun_gate.nxGATE for the control plane's two lane-J fixes (2026-08-23):3048
nx_mgmt_organ_capacity_gate_t180.nxActual management handler gate. Fixture registry is isolated in a unique temporary directory;876
nx_mgmt_private_canonical_gate_t189.nx443
nx_mgmt_private_connected_gate_t189.nx443
nx_mgmt_private_discovery_gate_t189.nx533
nx_mgmt_private_response.nxPrivate response handoff used by nx_mgmt_call; never emits upstream body bytes.13714
nx_mgmt_private_response_candidate_t189.nxPrivate response handoff used by nx_mgmt_call; never emits upstream body bytes.13714
nx_mgmt_private_response_gate_t189.nx512
nx_mgmt_proc_read_gate.nxRegression for the management API's real bounded proc reader.351
nx_mgmt_promote_gate.nxreferee for POST /api/promote: fail-closed, never-brick, AND lease-clean.45514
nx_mgmt_publish_bin.nxsubmit the ecosystem CONTROL-PLANE binary (nx_mgmt_api) to the publisher484
nx_mgmt_research.nxTHIN structured ECOSYSTEM-MANAGEMENT / CONTROL-PLANE research source organ.461
nx_mgmt_session_mint.nxCLI over nx_session_mint_lib: mint an M5 no-cookie session token (the X-Nishi-Session211
nx_mgmt_session_mint_gate.nxproves the session minter: a token minted by msm_mint_raw (loading ed_priv from a903
nx_mgmt_snapshot.nxR1b: the LIVE health-snapshot PRODUCER for the sovereign management plane.1819
nx_mgmt_snapshot_gate.nxPURE isolation gate for the R1b health-snapshot PRODUCER (nx_mgmt_snapshot).1027
nx_mgmt_snapshot_run.nxthe COMPLETE, self-contained health-snapshot PRODUCER binary (R1b, live path).2749
nx_mgmt_snapshot_run_gate.nxPURE isolation gate for the producer's INSTANCE-vs-fork-child rule614
nx_mgmt_tools_register_gate.nxprove POST /api/tools/register is fail-closed + idempotent. In-process22110
nx_mgmt_upload.nxCAP-API-UPLOAD: the #1 census gap = binary UPLOAD over /api, the "not-on-LAN deploy"533
nx_mgmt_upload_gate.nxSOVEREIGN in-process referee for the /api/upload keystone (chunked artifact publish).32712