Nishi FamilyCompare › Deployment and Live Hosting

Nishi Compare · measured, not asserted

Deployment and Live Hosting

Nishi vs the field — every Nishi cell is measured against real organ source at emit time; each gap names the watch contract that will close it.

The sovereign mgmt control plane (upload -> build-on-target -> health-gated promote -> auto-rollback, all simple API calls over own TLS) vs Vercel and Fly.io and Render and Kubernetes with Argo

Layer 1 · Executive

Where we are. The sovereign control plane is live and self-hosting: health-gated promote with an auto-rollback watchdog (never-brick by default), instant rollback, build-on-target with the sovereign toolchain, one-command ship, sha-pinned atomic content publish, crash-loop-aware supervision, fleet inventory and SSE, the Sovereign Fleet UI, a fail-closed deploy-target registry, an OpenAPI spec, plus domain purchase with a spend wall, registrar DNS, ACME certs and purchase-to-live orchestration. Three exceeds: OPAQUE-PAKE control-plane auth, sovereign end-to-end TLS and routing, and a plane that deploys ITSELF through its own chain. Behind the platforms on: canary weighting, preview environments, blue-green warm slots, a GitOps reconciler, multi-node placement, autoscale, and rotation-managed secrets.

Where we need to go. The deployment ergonomics the platforms sell -- previews per change, weighted canaries, warm-slot cutover, declared-state reconciliation, secrets that rotate -- on owned hardware behind the same never-brick watchdog, and then placement across a second node without a cloud LB.

The unit. 1 u = one measured session-leg (estate calibration: graphics R21 in one leg 2026-08-15). Local evidence: the wiki restart route and the D-state admission witness each landed gated in one leg on 2026-08-17; estimates are relative to those.
Where we are: 7 open rungs. Control-plane fundamentals at or beyond the field; release ergonomics and multi-node behind. Counts measured at emit below this line.
Cost to safer releases: 4 u. DL1 blue-green warm slots, DL2 weighted canary on top of them, DL3 preview instances per staged change -- all ride the existing watchdog.
Cost to declared state: 3 u. DL4 the GitOps-class reconciler over the deploy-target registry, DL5 secrets rotation under it.
Cost to more than one box: 6 u. DL6 placement of a service on a second sovereign node, DL7 scale-to-zero for always-on daemons that idle.

Research bar. Argo Rollouts is measured on weighted canary steps, blue-green, analysis-gated promotion. Theirs: the progressive-delivery reference. Ours: DL1 and DL2 measured on this page.

Research bar. Vercel is measured on preview deployment per change, instant rollback, edge network. Theirs: the DX bar. Ours: DL3; rollback already matched.

Research bar. Flux and Argo CD is measured on reconcile the cluster to declared repo state. Theirs: the GitOps bar. Ours: DL4.

11 of 25 capabilities measured|2 of them measured exceeds|14 open|coverage 440/1000|adoption 7 full / 4 partial

Layer 2 · Roadmap

Do this next — computed by the ranker, never chosen by a seat

Order from nx_compare_rank (nx_dr_ocm: (deficit + cost-of-delay + option + enables) x sponsor x self-sufficiency x momentum / cost). FINISH rows are rungs whose symbol is present but whose organ is short of full adoption: the cheapest closures on this board, listed before any new work. Stamp: # asof=1787883400 domain=deploy target_version=0.1 rungs=10 done=3 open=7 finish=0 ranker=nx_dr_ocm

#StageRungPriorityDerivation
#10.1Preview per change (DL3) dp_preview_spawn2000v=10 m=2 c=10
#20.1Blue-green warm slots (DL1) bg_slot_switch800v=6 m=2 c=15
#30.1Weighted canary (DL2) dc_weight_shift400v=6 m=1 c=15
#4laterDeclared-state reconciler (DL4) go_reconcile_desired2400v=24 m=2 c=20
#5laterSecrets rotation (DL5) ds_rotate_secret600v=6 m=1 c=10
#6laterScale to zero (DL7) as_scale_to_zero450v=9 m=1 c=20
#7laterSecond-node placement (DL6) rg_place_service300v=12 m=1 c=40

Critical path — contract, done-rule, executor, cost

RungCloses withDefinition of done (pre-declared)ExecutorEst.
Never-brick deploy (DP0)deploy_statusStage, promote, async health watchdog, auto-rollback -- LANDED and self-appliedOrgan0 u
Instant rollback (DP1)
after DP0
rollback.prev restore via POST /api/rollback -- LANDEDOrgan0 u
Fail-closed target registry (DP2)md_upload_target_okEvery deployable target allowlisted by name -- LANDEDOrgan0 u
Blue-green warm slots (DL1)
after DP0
bg_slot_switchTwo installed slots per daemon, the idle one warmed by the health probe before the SNI route flips; gate proves a flip under a synthetic request stream drops zero requests and a failed warm-up never flipsOrgan1.5 u
Weighted canary (DL2)
after DL1
dc_weight_shiftRoute a declared permil of new connections to the warm slot and advance the weight only while the watchdog stays GREEN; gate proves a RED at 100 permil rolls the weight back to zero and records itOrgan1.5 u
Preview per change (DL3)
after DP0
dp_preview_spawnA staged .new binary runs on an ephemeral port behind the operator login with its own route, torn down on promote or expiry; gate proves the preview serves the staged bytes while live serves the promoted bytes, byte-verified bothOrgan1 u
Declared-state reconciler (DL4)
after DP2
go_reconcile_desiredA signed desired-state file (targets, versions by sha, routes) reconciled against the live plane on a beat through the existing promote and deploy doors; drift is REPORTED with the diff and applied only when the file says apply; gate proves a declared sha converges and a tampered file is refused by signatureOrgan2 u
Secrets rotation (DL5)
after DL4
ds_rotate_secretSecrets referenced by name from the desired state, rotated on a declared schedule with the old value kept readable for the grace window and the rotation recorded; gate proves a daemon keeps serving through a rotation and a revoked secret is refused after the windowOrgan1 u
Second-node placement (DL6)
after DL4
rg_place_servicePlace a service on a second sovereign host from the same desired state, with the SNI router fronting both; gate proves a request reaches the second node and a node loss routes back within the watchdog windowOrgan4 u
Scale to zero (DL7)
after DL1
as_scale_to_zeroAn always-on daemon declared idle-capable is stopped after a declared idle window and respawned on first connection by the router; gate proves zero process while idle and a first request served within the declared cold-start boundOrgan2 u

Milestones

MilestoneRungsCumulative
M1 · Safer releasesDL1,DL2,DL34 u
M2 · Declared stateDL4,DL57 u
M3 · More than one boxDL6,DL713 u
Layer 3 · Engineering
How this is scored. Every Nishi mark is measured: the generator reads the real organ source on disk and requires the implementing symbol to exist (no self-grading). A watching tag names the organ and symbol contracted to close a gap — the mark flips itself on the next compare beat when that workstream ships, and the comparewatch- plane row flips with it. The flip is necessary, not sufficient: it proves the symbol exists, never that the capability is good. The bar is the rung's pre-declared done-rule, proven by its gate — a symbol shipped without the behaviour behind it is a defect, and the flip is exactly what makes that defect visible instead of quiet. Competitor marks record documented capability presence — presence, not depth or scale. Adoption is measured too: every measured row carries where its organ stands on the estate's ladder (source → built → promoted → registered → invoked; libraries by importer reach minus validation importers; gates by the execution surfaces that run them). A row is fully adopted only at the top of its ladder; anything short is tagged partial with the exact remedy, so a build nobody promoted can no longer read as shipped. Census stamps: importers asof 1787849099, gate census asof 1787855507 (unix seconds; -1 = census absent).

Capability matrix — measured against source

leads / measured exceed present partial absent · click any capability for its evidence

CapabilityNishiVercelFly.ioRenderKubernetes+Argo
Health-gated promote with auto-rollback watchdogOpen — no implementing organ is measured for this axis yet. Argo Rollouts is the reference [argo-rollouts]; Fly and Render health-check releases [render-deploys]; Nishi /api/deploy stages .new then promotes then an async watchdog verifies health and ROLLS BACK by construction -- never-brick is the default not an option
Instant manual rollbackOpen — no implementing organ is measured for this axis yet. Vercel instant alias flip to any prior immutable deployment is Best [vercel-instant-rollback]; Nishi POST /api/rollback restores the .prev binary
Build on the target from sourceOpen — no implementing organ is measured for this axis yet. Vercel build pipeline is Best-in-class; K8s delegates builds to CI; Nishi POST /api/build compiles with the sovereign toolchain ON the NAS -- no external CI
One-command source to liveMeasured: SHIPPED exists in runtime/nx_ship.nx, verified at emit. vercel deploy set the DX bar; Nishi nx_ship packs the tree then uploads over sovereign TLS then builds on target in ONE command Adoption: RUN-BY:fork:nx_ws_hygiene_gate — fully adopted (top of its ladder).
Staged content publish (sha-pinned, atomic)Open — no implementing organ is measured for this axis yet. Everyone stages then swaps; Nishi /api/promote_content and /api/compare/publish re-hash the stage and install atomically with .prev backing
Service supervision with crash-loop backoffMeasured: crash-loop exists in runtime/_hdl_build/nx_hostctl.nx, verified at emit. K8s liveness probes are Best; Nishi hostctl supervise runs live (PID + SERVING probe, HUNG-aware, backoff) and respawns from the promoted binary Adoption: LIVE-DAEMON — fully adopted (top of its ladder).
Live fleet inventory APIMeasured: /api/services exists in runtime/_hdl_build/nx_mgmt_api.nx, verified at emit. kubectl get is the reference [k8s-deployment]; Nishi GET /api/services serves the multi-service inventory Adoption: LIVE-DAEMON — fully adopted (top of its ladder).
Deploy and ops event streamMeasured: event-stream exists in runtime/_hdl_build/nx_mgmt_api.nx, verified at emit. K8s watch API Best; Nishi GET /api/events serves SSE to EventSource clients Adoption: LIVE-DAEMON — fully adopted (top of its ladder).
Ops dashboard UIOpen — no implementing organ is measured for this axis yet. Vercel dashboard is Best; Nishi Sovereign Fleet at /health is LIVE behind the operator login with per-service cards and allowlisted actions
Fail-closed deploy-target registryMeasured: md_upload_target_ok exists in runtime/_hdl_build/nx_mgmt_data.nx, verified at emit. K8s RBAC-scoped resources are the reference; Nishi allowlists every uploadable and deployable target BY NAME -- unknown targets are refused Adoption: LIB-WIRED importers=4 nonval=1 — fully adopted (top of its ladder).
Machine-readable control-plane specOpen — no implementing organ is measured for this axis yet. K8s OpenAPI is the reference; Nishi GET /api/openapi.json describes the whole plane for auto-driving agents
EXCEED control-plane auth is OPAQUE PAKEMeasured exceed: OPAQUE in runtime/nx_opaque_login.nx, verified at emit. Incumbents authenticate deploys with bearer tokens and OIDC; the Nishi plane authenticates with OPAQUE-3DH -- the password never crosses the wire and the server stores no password-equivalent [rfc9807-opaque]; sessions are Ed25519-minted and TTL-bound Adoption: RUN-BY:daemon — fully adopted (top of its ladder).
EXCEED sovereign end-to-end hostingMeasured exceed: WITHOUT terminating in runtime/nx_sni_route.nx, verified at emit. The live site terminates its own TLS 1.3 [rfc8446-tls13] and routes SNI without a third-party terminator -- no nginx no cloud LB no CDN vendor; every byte from ClientHello to response is auditable sovereign source on owned hardware Adoption: LIB-WIRED importers=3 nonval=1 — fully adopted (top of its ladder).
EXCEED the control plane deploys ITSELFOpen — no implementing organ is measured for this axis yet. Proven live: the mgmt API was upgraded THROUGH its own upload-deploy-watchdog chain (DEPLOYED-GREEN) -- self-hosting deployment with never-brick protection; platform vendors upgrade their planes outside your view
Canary and progressive traffic shiftingOpen — watching runtime/nx_deploy_canary.nx : dc_weight_shift, re-measured on every compare beat. Ship that symbol and this mark flips itself; the comparewatch- plane row flips with it. Argo Rollouts weighted steps are the reference [argo-rollouts]; Nishi promotes whole-service -- percentage shifting is a named gap
watching dc_weight_shift
Preview environments per changeOpen — watching runtime/nx_deploy_preview.nx : dp_preview_spawn, re-measured on every compare beat. Ship that symbol and this mark flips itself; the comparewatch- plane row flips with it. Vercel preview-per-PR defined the category; Nishi has no ephemeral preview instances yet
watching dp_preview_spawn
Blue-green dual-slot instant switchOpen — watching runtime/nx_deploy_bluegreen.nx : bg_slot_switch, re-measured on every compare beat. Ship that symbol and this mark flips itself; the comparewatch- plane row flips with it. Nishi has .prev restore but not two warm slots with instant cutover
watching bg_slot_switch
GitOps declared-state reconcilerOpen — watching runtime/nx_deploy_gitops.nx : go_reconcile_desired, re-measured on every compare beat. Ship that symbol and this mark flips itself; the comparewatch- plane row flips with it. Argo/Flux reconcile the cluster to a declared repo state; the Nishi registry is imperative API calls today
watching go_reconcile_desired
Multi-node and multi-region placementOpen — watching runtime/nx_deploy_region.nx : rg_place_service, re-measured on every compare beat. Ship that symbol and this mark flips itself; the comparewatch- plane row flips with it. Fly regions and Vercel edge network lead [flyio-config]; Nishi runs one sovereign host plus workstation
watching rg_place_service
Autoscale including scale-to-zeroOpen — watching runtime/nx_deploy_scale.nx : as_scale_to_zero, re-measured on every compare beat. Ship that symbol and this mark flips itself; the comparewatch- plane row flips with it. Serverless platforms scale to zero; Nishi services are always-on supervised processes
watching as_scale_to_zero
Secrets manager with rotationOpen — watching runtime/nx_deploy_secrets.nx : ds_rotate_secret, re-measured on every compare beat. Ship that symbol and this mark flips itself; the comparewatch- plane row flips with it. K8s secrets plus external-secrets is the reference; Nishi has key files and a vault doctrine but no rotation-managed deploy secrets plane
watching ds_rotate_secret
Domain purchase API with spend wall + dry-run-firstMeasured: pbd_register_wall exists in runtime/nx_porkbun_domain.nx, verified at emit. LIVE-PROVEN to the server pre-flight (Porkbun dryRun, 0 charge) [porkbun-api]: refusal ladder = spec-verified endpoint, creds, literal confirm-spend, quote<=cap; Vercel sells domains via API too -- ours adds the client-side spend wall (their docs not banked, so no exceed claimed) Adoption: BUILT-UNPROMOTED — PARTIAL: compiled, never promoted to the serving root: /api/promote it.
adoption BUILT-UNPROMOTED
DNS records API on the live registrar (A/TXT)Measured: nx_porkbun_set_a exists in runtime/nx_acme_porkbun.nx, verified at emit. Live-KAT proven against andelinwest.com over sovereign TLS; platforms manage DNS on their own edges; K8s external-dns is Part Adoption: SOURCE-ONLY — PARTIAL: source exists, never compiled: /api/build it.
adoption SOURCE-ONLY
TLS certificate acquisition (bundle retrieve + ACME DNS-01)Measured: acme_account_key exists in runtime/nx_acme_issue.nx, verified at emit. LIVE: 10509-byte LE bundle retrieved (0600, key never printed) for andelinwest.com; platforms auto-provision on their edge -- ours lands certs on the sovereign edge [rfc8555-acme] Adoption: SOURCE-ONLY — PARTIAL: source exists, never compiled: /api/build it.
adoption SOURCE-ONLY
Purchase-to-live orchestration (ordered, once-only spend)Measured: gl_advance exists in runtime/_hdl_build/nx_domain_golive.nx, verified at emit. Gated 8/8: dryrun-then-confirm spend, double-purchase impossible by construction, operator-gated edge step; Vercel buy+auto-cert is the incumbent flow without explicit spend caps Adoption: SOURCE-ONLY — PARTIAL: source exists, never compiled: /api/build it.
adoption SOURCE-ONLY

Risk register

RiskLikelihood x impactMitigation
Two warm slots double the memory footprint on a box that is already swappinglikely x mediumDL1 warms on demand and the admission gate refuses a warm-up under the memory floor.
A reconciler with apply authority is the most dangerous daemon on the boxpossible x highDL4 applies only through the never-brick doors it already has, never by file copy; report-only is the default mode.
On these two registers. Rows are declared in the domain's plan file and carry the debt id, which is the join key back to the sovereign debt plane — that plane, not this page, is the authority on state. Reconciling them automatically (the regen reading the plane and refreshing these rows) is a named, owed rung; until it lands, treat an id here as a pointer to look up, not a status to trust.
Honest verdict. The coverage above is capability presence measured against source — not depth, scale, or polish, where mature rivals may lead. Exceeds are claimed only where a mechanism backs them. Every open gap is a watch contract: it names the organ and symbol that closes it, and this page flips the cell itself when that workstream ships.

Person · product · place — not yet measured for this domain

Every compare carries this layer. Declare knowledge/compare/deploy.ppp (rows surface|nishi or c1..c4|label|url|connect naming OUR live surface and each rival's front door), run nx_ppp_probe domain deploy, and this section fills itself on the next beat: the same ruler on both sides — privacy and CX (third-party hosts, tracker classes, cookies, security headers), design and longevity (design hygiene, computed WCAG contrast, render-blocking resources, unsized media, script weight, theme and motion queries), findability (landmarks, skip link, on-site search, breadcrumb, headings, internal links).

References

Beyond a link list. Every reference below resolves twice — the publisher's copy and, where banked, the estate's own non-rottable library mirror with a content pin — and carries its evidence class plus the exact claim on this page it grounds. Keyed marks like [key] in the matrix notes jump here. A dash means honestly absent, never assumed.
  1. [vercel-instant-rollback] Vercel Inc. Performing an Instant Rollback on a Deployment (vercel.com/docs/instant-rollback): point production domains back at any previously aliased immutable deployment, instantly, from dashboard or CLI. publisher · read in our library knowledge/fetched/cmp_deploy_vercel-rollback.html · pin h9f831075f1290e10a25f584d26d0cb540d2918a90407bf5db0a0c2e71bf2d8c4 · accessed 2026-08-18 · vendor-docGrounds: The Instant manual rollback row where Vercel is Best (instant alias flip to any prior immutable deployment) -- the bar POST /api/rollback restoring the .prev binary is graded against -- and the Vercel column on Preview environments per change and Ops dashboard UI.
  2. [flyio-config] Fly.io. App Configuration (fly.toml) reference (fly.io/docs/reference/configuration): services, http_checks and tcp checks, deploy strategy (rolling, immediate, canary, bluegreen) and regions. publisher · read in our library knowledge/fetched/cmp_deploy_flyio-config.html · pin he572699e7dd7d2995498953f7e53220694379da131a2a131f3317be1d77b674a · accessed 2026-08-18 · vendor-docGrounds: The Fly.io column: Health-gated promote with auto-rollback watchdog (Fly health-checks releases), Canary and progressive traffic shifting, Blue-green dual-slot instant switch and Multi-node and multi-region placement (Fly regions lead) -- the fly.toml checks and deploy-strategy keys are the documented mechanism behind those cells.
  3. [render-deploys] Render. Deploys (render.com/docs/deploys): git-triggered builds, zero-downtime deploys gated on the service's health check path, deploy hooks and manual rollback to a previous deploy. publisher · read in our library knowledge/fetched/cmp_deploy_render-deploys.html · pin heef78665ed2695dc39603c2c2b784ad4b965b5bea20e5fcda2df37fcbd63ef9e · accessed 2026-08-18 · vendor-docGrounds: The Render column: Health-gated promote with auto-rollback watchdog (Render health-checks releases), Instant manual rollback and Build on the target from source -- the documented deploy lifecycle the Nishi upload-build-promote-watchdog chain is compared with.
  4. [argo-rollouts] Argo Project. Argo Rollouts -- Kubernetes progressive delivery controller (argo-rollouts.readthedocs.io): blue-green and canary strategies, weighted traffic steps, analysis-driven automated rollback. publisher · read in our library knowledge/fetched/cmp_deploy_argo-rollouts.html · pin ha13ade59af2152720464f62827c8a867ef7f009201eda8216fc78be275407617 · accessed 2026-08-18 · vendor-docGrounds: The Kubernetes+Argo column: Health-gated promote with auto-rollback watchdog (Argo Rollouts is the reference), Canary and progressive traffic shifting (weighted steps are the reference for the _ABSENT_ nx_deploy_canary gap) and Blue-green dual-slot instant switch.
  5. [k8s-deployment] The Kubernetes Authors. Deployments (kubernetes.io/docs/concepts/workloads/controllers/deployment): declarative rolling updates, revision history and kubectl rollout undo. publisher · read in our library knowledge/fetched/cmp_deploy_k8s-deployment.html · pin h2fc7e20d2384f405f3f6c9a651f4ba8f0542b0ed8925e7f47e47bcb9f92f9775 · accessed 2026-08-18 · vendor-docGrounds: The Kubernetes half of the Kubernetes+Argo column: Instant manual rollback (rollout undo), Staged content publish, Live fleet inventory API (kubectl get is the reference) and the GitOps declared-state reconciler row's declared-state model that Argo/Flux reconcile toward.
  6. [rfc9807-opaque] Bourdrez, Krawczyk, Lewi, Wood. RFC 9807: The OPAQUE Augmented Password-Authenticated Key Exchange (aPAKE) Protocol. IETF, July 2025. publisher · read in our library knowledge/fetched/cmp_deploy_rfc9807.html · pin h0e1ee56460c024fff7057d3743eb73aa4382a4fc274eb484597d6d43b41274cb · accessed 2026-08-18 · published-standardGrounds: The EXCEED control-plane auth is OPAQUE PAKE row: the password never crosses the wire and the server stores no password-equivalent are properties of this protocol (OPAQUE-3DH), which nx_opaque_login implements -- versus bearer tokens and OIDC on the incumbents.
  7. [rfc8446-tls13] Rescorla, E. RFC 8446: The Transport Layer Security (TLS) Protocol Version 1.3. IETF, August 2018. publisher · read in our library knowledge/fetched/cmp_deploy_rfc8446.html · pin h370ed8c0e6da22c8b8f4ad0230b6c12e6ec8ae807eca034220070828f25684fb · accessed 2026-08-18 · published-standardGrounds: The EXCEED sovereign end-to-end hosting row: the live site terminates its own TLS 1.3 (nx_sni_route, no nginx, no cloud LB, no CDN) -- the protocol it implements is this RFC, so every byte from ClientHello to response is checkable against a public standard, and the One-command source to live row's upload over sovereign TLS rides the same stack.
  8. [rfc8555-acme] Barnes, Hoffman-Andrews, McCarney, Kasten. RFC 8555: Automatic Certificate Management Environment (ACME). IETF, March 2019. publisher · read in our library knowledge/fetched/cmp_deploy_rfc8555.html · pin he6ca1ca3e44cbb54cf6dc126f23d9f2abc5837119800af49bfa5e2c546d79393 · accessed 2026-08-18 · published-standardGrounds: The TLS certificate acquisition (bundle retrieve + ACME DNS-01) row: the DNS-01 challenge nx_acme_issue completes for andelinwest.com (10509-byte Let's Encrypt bundle) is defined here -- platforms auto-provision on their edge, ours lands certs on the sovereign edge through the same protocol.
  9. [porkbun-api] Porkbun LLC. Porkbun API v3 documentation (porkbun.com/api/json/v3/documentation): REST/JSON API to register and manage domains, DNS records, DNSSEC and SSL bundle retrieval, with an OpenAPI spec and sandbox. publisher · read in our library knowledge/fetched/cmp_deploy_porkbun-api.html · pin h8dae6acbd654dbc32e631c23715266204354a526c7092df91f68b2f3b1cd7122 · accessed 2026-08-18 · vendor-docGrounds: The Domain purchase API with spend wall + dry-run-first, DNS records API on the live registrar (A/TXT) and Purchase-to-live orchestration rows: the registrar endpoints (dryRun pre-flight, DNS record edit, SSL bundle retrieve) that nx_porkbun_domain, nx_acme_porkbun and nx_domain_golive drive live over sovereign TLS.

generated by nx_swcompare_matrix (sovereign NishiLang organ) from knowledge/compare/deploy.matrix · every Nishi cell verified against organ source at emit time · watch cells re-measured on every compare beat · zero JS, zero trackers