Nishi Family › Compare › Deployment and Live Hosting
Nishi Compare · measured, not asserted
Deployment and Live Hosting
Nishi vs the field — every Nishi cell is measured against real organ source at emit time; each gap names the watch contract that will close it.
The sovereign mgmt control plane (upload -> build-on-target -> health-gated promote -> auto-rollback, all simple API calls over own TLS) vs Vercel and Fly.io and Render and Kubernetes with Argo
Where we are. The sovereign control plane is live and self-hosting: health-gated promote with an auto-rollback watchdog (never-brick by default), instant rollback, build-on-target with the sovereign toolchain, one-command ship, sha-pinned atomic content publish, crash-loop-aware supervision, fleet inventory and SSE, the Sovereign Fleet UI, a fail-closed deploy-target registry, an OpenAPI spec, plus domain purchase with a spend wall, registrar DNS, ACME certs and purchase-to-live orchestration. Three exceeds: OPAQUE-PAKE control-plane auth, sovereign end-to-end TLS and routing, and a plane that deploys ITSELF through its own chain. Behind the platforms on: canary weighting, preview environments, blue-green warm slots, a GitOps reconciler, multi-node placement, autoscale, and rotation-managed secrets.
Where we need to go. The deployment ergonomics the platforms sell -- previews per change, weighted canaries, warm-slot cutover, declared-state reconciliation, secrets that rotate -- on owned hardware behind the same never-brick watchdog, and then placement across a second node without a cloud LB.
Research bar. Argo Rollouts is measured on weighted canary steps, blue-green, analysis-gated promotion. Theirs: the progressive-delivery reference. Ours: DL1 and DL2 measured on this page.
Research bar. Vercel is measured on preview deployment per change, instant rollback, edge network. Theirs: the DX bar. Ours: DL3; rollback already matched.
Research bar. Flux and Argo CD is measured on reconcile the cluster to declared repo state. Theirs: the GitOps bar. Ours: DL4.
11 of 25 capabilities measured|2 of them measured exceeds|14 open|coverage 440/1000|adoption 7 full / 4 partial
Do this next — computed by the ranker, never chosen by a seat
Order from nx_compare_rank (nx_dr_ocm: (deficit + cost-of-delay + option + enables) x sponsor x self-sufficiency x momentum / cost). FINISH rows are rungs whose symbol is present but whose organ is short of full adoption: the cheapest closures on this board, listed before any new work. Stamp: # asof=1787883400 domain=deploy target_version=0.1 rungs=10 done=3 open=7 finish=0 ranker=nx_dr_ocm
| # | Stage | Rung | Priority | Derivation |
|---|---|---|---|---|
| #1 | 0.1 | Preview per change (DL3) dp_preview_spawn | 2000 | v=10 m=2 c=10 |
| #2 | 0.1 | Blue-green warm slots (DL1) bg_slot_switch | 800 | v=6 m=2 c=15 |
| #3 | 0.1 | Weighted canary (DL2) dc_weight_shift | 400 | v=6 m=1 c=15 |
| #4 | later | Declared-state reconciler (DL4) go_reconcile_desired | 2400 | v=24 m=2 c=20 |
| #5 | later | Secrets rotation (DL5) ds_rotate_secret | 600 | v=6 m=1 c=10 |
| #6 | later | Scale to zero (DL7) as_scale_to_zero | 450 | v=9 m=1 c=20 |
| #7 | later | Second-node placement (DL6) rg_place_service | 300 | v=12 m=1 c=40 |
Critical path — contract, done-rule, executor, cost
| Rung | Closes with | Definition of done (pre-declared) | Executor | Est. |
|---|---|---|---|---|
| Never-brick deploy (DP0) | deploy_status | Stage, promote, async health watchdog, auto-rollback -- LANDED and self-applied | Organ | 0 u |
| Instant rollback (DP1) after DP0 | rollback | .prev restore via POST /api/rollback -- LANDED | Organ | 0 u |
| Fail-closed target registry (DP2) | md_upload_target_ok | Every deployable target allowlisted by name -- LANDED | Organ | 0 u |
| Blue-green warm slots (DL1) after DP0 | bg_slot_switch | Two installed slots per daemon, the idle one warmed by the health probe before the SNI route flips; gate proves a flip under a synthetic request stream drops zero requests and a failed warm-up never flips | Organ | 1.5 u |
| Weighted canary (DL2) after DL1 | dc_weight_shift | Route a declared permil of new connections to the warm slot and advance the weight only while the watchdog stays GREEN; gate proves a RED at 100 permil rolls the weight back to zero and records it | Organ | 1.5 u |
| Preview per change (DL3) after DP0 | dp_preview_spawn | A staged .new binary runs on an ephemeral port behind the operator login with its own route, torn down on promote or expiry; gate proves the preview serves the staged bytes while live serves the promoted bytes, byte-verified both | Organ | 1 u |
| Declared-state reconciler (DL4) after DP2 | go_reconcile_desired | A signed desired-state file (targets, versions by sha, routes) reconciled against the live plane on a beat through the existing promote and deploy doors; drift is REPORTED with the diff and applied only when the file says apply; gate proves a declared sha converges and a tampered file is refused by signature | Organ | 2 u |
| Secrets rotation (DL5) after DL4 | ds_rotate_secret | Secrets referenced by name from the desired state, rotated on a declared schedule with the old value kept readable for the grace window and the rotation recorded; gate proves a daemon keeps serving through a rotation and a revoked secret is refused after the window | Organ | 1 u |
| Second-node placement (DL6) after DL4 | rg_place_service | Place a service on a second sovereign host from the same desired state, with the SNI router fronting both; gate proves a request reaches the second node and a node loss routes back within the watchdog window | Organ | 4 u |
| Scale to zero (DL7) after DL1 | as_scale_to_zero | An always-on daemon declared idle-capable is stopped after a declared idle window and respawned on first connection by the router; gate proves zero process while idle and a first request served within the declared cold-start bound | Organ | 2 u |
Milestones
| Milestone | Rungs | Cumulative |
|---|---|---|
| M1 · Safer releases | DL1,DL2,DL3 | 4 u |
| M2 · Declared state | DL4,DL5 | 7 u |
| M3 · More than one box | DL6,DL7 | 13 u |
comparewatch- plane row flips with it. The flip is necessary, not sufficient: it proves the symbol exists, never that the capability is good. The bar is the rung's pre-declared done-rule, proven by its gate — a symbol shipped without the behaviour behind it is a defect, and the flip is exactly what makes that defect visible instead of quiet. Competitor marks record documented capability presence — presence, not depth or scale. Adoption is measured too: every measured row carries where its organ stands on the estate's ladder (source → built → promoted → registered → invoked; libraries by importer reach minus validation importers; gates by the execution surfaces that run them). A row is fully adopted only at the top of its ladder; anything short is tagged partial with the exact remedy, so a build nobody promoted can no longer read as shipped. Census stamps: importers asof 1787849099, gate census asof 1787855507 (unix seconds; -1 = census absent).Capability matrix — measured against source
◉ leads / measured exceed● present◐ partial○ absent · click any capability for its evidence
| Capability | Nishi | Vercel | Fly.io | Render | Kubernetes+Argo |
|---|---|---|---|---|---|
Health-gated promote with auto-rollback watchdogOpen — no implementing organ is measured for this axis yet. Argo Rollouts is the reference [argo-rollouts]; Fly and Render health-check releases [render-deploys]; Nishi /api/deploy stages .new then promotes then an async watchdog verifies health and ROLLS BACK by construction -- never-brick is the default not an option | ○ | ● | ● | ● | ◉ |
Instant manual rollbackOpen — no implementing organ is measured for this axis yet. Vercel instant alias flip to any prior immutable deployment is Best [vercel-instant-rollback]; Nishi POST /api/rollback restores the .prev binary | ○ | ◉ | ● | ● | ● |
Build on the target from sourceOpen — no implementing organ is measured for this axis yet. Vercel build pipeline is Best-in-class; K8s delegates builds to CI; Nishi POST /api/build compiles with the sovereign toolchain ON the NAS -- no external CI | ○ | ◉ | ● | ● | ◐ |
One-command source to liveMeasured:SHIPPED exists in runtime/nx_ship.nx, verified at emit. vercel deploy set the DX bar; Nishi nx_ship packs the tree then uploads over sovereign TLS then builds on target in ONE command Adoption: RUN-BY:fork:nx_ws_hygiene_gate — fully adopted (top of its ladder). | ● | ◉ | ● | ● | ◐ |
Staged content publish (sha-pinned, atomic)Open — no implementing organ is measured for this axis yet. Everyone stages then swaps; Nishi /api/promote_content and /api/compare/publish re-hash the stage and install atomically with .prev backing | ○ | ● | ● | ● | ● |
Service supervision with crash-loop backoffMeasured:crash-loop exists in runtime/_hdl_build/nx_hostctl.nx, verified at emit. K8s liveness probes are Best; Nishi hostctl supervise runs live (PID + SERVING probe, HUNG-aware, backoff) and respawns from the promoted binary Adoption: LIVE-DAEMON — fully adopted (top of its ladder). | ● | ● | ● | ● | ◉ |
Live fleet inventory APIMeasured:/api/services exists in runtime/_hdl_build/nx_mgmt_api.nx, verified at emit. kubectl get is the reference [k8s-deployment]; Nishi GET /api/services serves the multi-service inventory Adoption: LIVE-DAEMON — fully adopted (top of its ladder). | ● | ● | ● | ● | ◉ |
Deploy and ops event streamMeasured:event-stream exists in runtime/_hdl_build/nx_mgmt_api.nx, verified at emit. K8s watch API Best; Nishi GET /api/events serves SSE to EventSource clients Adoption: LIVE-DAEMON — fully adopted (top of its ladder). | ● | ● | ● | ● | ◉ |
Ops dashboard UIOpen — no implementing organ is measured for this axis yet. Vercel dashboard is Best; Nishi Sovereign Fleet at /health is LIVE behind the operator login with per-service cards and allowlisted actions | ○ | ◉ | ● | ● | ◐ |
Fail-closed deploy-target registryMeasured:md_upload_target_ok exists in runtime/_hdl_build/nx_mgmt_data.nx, verified at emit. K8s RBAC-scoped resources are the reference; Nishi allowlists every uploadable and deployable target BY NAME -- unknown targets are refused Adoption: LIB-WIRED importers=4 nonval=1 — fully adopted (top of its ladder). | ● | ● | ● | ● | ◉ |
Machine-readable control-plane specOpen — no implementing organ is measured for this axis yet. K8s OpenAPI is the reference; Nishi GET /api/openapi.json describes the whole plane for auto-driving agents | ○ | ● | ● | ● | ◉ |
EXCEED control-plane auth is OPAQUE PAKEMeasured exceed:OPAQUE in runtime/nx_opaque_login.nx, verified at emit. Incumbents authenticate deploys with bearer tokens and OIDC; the Nishi plane authenticates with OPAQUE-3DH -- the password never crosses the wire and the server stores no password-equivalent [rfc9807-opaque]; sessions are Ed25519-minted and TTL-bound Adoption: RUN-BY:daemon — fully adopted (top of its ladder). | ◉ | ○ | ○ | ○ | ○ |
EXCEED sovereign end-to-end hostingMeasured exceed:WITHOUT terminating in runtime/nx_sni_route.nx, verified at emit. The live site terminates its own TLS 1.3 [rfc8446-tls13] and routes SNI without a third-party terminator -- no nginx no cloud LB no CDN vendor; every byte from ClientHello to response is auditable sovereign source on owned hardware Adoption: LIB-WIRED importers=3 nonval=1 — fully adopted (top of its ladder). | ◉ | ○ | ○ | ○ | ○ |
EXCEED the control plane deploys ITSELFOpen — no implementing organ is measured for this axis yet. Proven live: the mgmt API was upgraded THROUGH its own upload-deploy-watchdog chain (DEPLOYED-GREEN) -- self-hosting deployment with never-brick protection; platform vendors upgrade their planes outside your view | ○ | ○ | ○ | ○ | ○ |
Canary and progressive traffic shiftingOpen — watchingruntime/nx_deploy_canary.nx : dc_weight_shift, re-measured on every compare beat. Ship that symbol and this mark flips itself; the comparewatch- plane row flips with it. Argo Rollouts weighted steps are the reference [argo-rollouts]; Nishi promotes whole-service -- percentage shifting is a named gap | ○ | ● | ● | ● | ◉ |
Preview environments per changeOpen — watchingruntime/nx_deploy_preview.nx : dp_preview_spawn, re-measured on every compare beat. Ship that symbol and this mark flips itself; the comparewatch- plane row flips with it. Vercel preview-per-PR defined the category; Nishi has no ephemeral preview instances yet | ○ | ◉ | ● | ● | ◐ |
Blue-green dual-slot instant switchOpen — watchingruntime/nx_deploy_bluegreen.nx : bg_slot_switch, re-measured on every compare beat. Ship that symbol and this mark flips itself; the comparewatch- plane row flips with it. Nishi has .prev restore but not two warm slots with instant cutover | ○ | ● | ● | ● | ● |
GitOps declared-state reconcilerOpen — watchingruntime/nx_deploy_gitops.nx : go_reconcile_desired, re-measured on every compare beat. Ship that symbol and this mark flips itself; the comparewatch- plane row flips with it. Argo/Flux reconcile the cluster to a declared repo state; the Nishi registry is imperative API calls today | ○ | ◐ | ◐ | ◐ | ◉ |
Multi-node and multi-region placementOpen — watchingruntime/nx_deploy_region.nx : rg_place_service, re-measured on every compare beat. Ship that symbol and this mark flips itself; the comparewatch- plane row flips with it. Fly regions and Vercel edge network lead [flyio-config]; Nishi runs one sovereign host plus workstation | ○ | ◉ | ◉ | ● | ◉ |
Autoscale including scale-to-zeroOpen — watchingruntime/nx_deploy_scale.nx : as_scale_to_zero, re-measured on every compare beat. Ship that symbol and this mark flips itself; the comparewatch- plane row flips with it. Serverless platforms scale to zero; Nishi services are always-on supervised processes | ○ | ◉ | ◉ | ● | ● |
Secrets manager with rotationOpen — watchingruntime/nx_deploy_secrets.nx : ds_rotate_secret, re-measured on every compare beat. Ship that symbol and this mark flips itself; the comparewatch- plane row flips with it. K8s secrets plus external-secrets is the reference; Nishi has key files and a vault doctrine but no rotation-managed deploy secrets plane | ○ | ● | ● | ● | ◉ |
Domain purchase API with spend wall + dry-run-firstMeasured:pbd_register_wall exists in runtime/nx_porkbun_domain.nx, verified at emit. LIVE-PROVEN to the server pre-flight (Porkbun dryRun, 0 charge) [porkbun-api]: refusal ladder = spec-verified endpoint, creds, literal confirm-spend, quote<=cap; Vercel sells domains via API too -- ours adds the client-side spend wall (their docs not banked, so no exceed claimed) Adoption: BUILT-UNPROMOTED — PARTIAL: compiled, never promoted to the serving root: /api/promote it. | ● | ● | ○ | ○ | ○ |
DNS records API on the live registrar (A/TXT)Measured:nx_porkbun_set_a exists in runtime/nx_acme_porkbun.nx, verified at emit. Live-KAT proven against andelinwest.com over sovereign TLS; platforms manage DNS on their own edges; K8s external-dns is Part Adoption: SOURCE-ONLY — PARTIAL: source exists, never compiled: /api/build it. | ● | ● | ● | ◐ | ◐ |
TLS certificate acquisition (bundle retrieve + ACME DNS-01)Measured:acme_account_key exists in runtime/nx_acme_issue.nx, verified at emit. LIVE: 10509-byte LE bundle retrieved (0600, key never printed) for andelinwest.com; platforms auto-provision on their edge -- ours lands certs on the sovereign edge [rfc8555-acme] Adoption: SOURCE-ONLY — PARTIAL: source exists, never compiled: /api/build it. | ● | ● | ● | ● | ◐ |
Purchase-to-live orchestration (ordered, once-only spend)Measured:gl_advance exists in runtime/_hdl_build/nx_domain_golive.nx, verified at emit. Gated 8/8: dryrun-then-confirm spend, double-purchase impossible by construction, operator-gated edge step; Vercel buy+auto-cert is the incumbent flow without explicit spend caps Adoption: SOURCE-ONLY — PARTIAL: source exists, never compiled: /api/build it. | ● | ● | ○ | ○ | ○ |
Risk register
| Risk | Likelihood x impact | Mitigation |
|---|---|---|
| Two warm slots double the memory footprint on a box that is already swapping | likely x medium | DL1 warms on demand and the admission gate refuses a warm-up under the memory floor. |
| A reconciler with apply authority is the most dangerous daemon on the box | possible x high | DL4 applies only through the never-brick doors it already has, never by file copy; report-only is the default mode. |
Person · product · place — not yet measured for this domain
knowledge/compare/deploy.ppp (rows surface|nishi or c1..c4|label|url|connect naming OUR live surface and each rival's front door), run nx_ppp_probe domain deploy, and this section fills itself on the next beat: the same ruler on both sides — privacy and CX (third-party hosts, tracker classes, cookies, security headers), design and longevity (design hygiene, computed WCAG contrast, render-blocking resources, unsized media, script weight, theme and motion queries), findability (landmarks, skip link, on-site search, breadcrumb, headings, internal links).References
- [vercel-instant-rollback] Vercel Inc. Performing an Instant Rollback on a Deployment (vercel.com/docs/instant-rollback): point production domains back at any previously aliased immutable deployment, instantly, from dashboard or CLI. publisher · read in our library
knowledge/fetched/cmp_deploy_vercel-rollback.html· pinh9f831075f1290e10a25f584d26d0cb540d2918a90407bf5db0a0c2e71bf2d8c4· accessed 2026-08-18 · vendor-docGrounds: The Instant manual rollback row where Vercel is Best (instant alias flip to any prior immutable deployment) -- the bar POST /api/rollback restoring the .prev binary is graded against -- and the Vercel column on Preview environments per change and Ops dashboard UI. - [flyio-config] Fly.io. App Configuration (fly.toml) reference (fly.io/docs/reference/configuration): services, http_checks and tcp checks, deploy strategy (rolling, immediate, canary, bluegreen) and regions. publisher · read in our library
knowledge/fetched/cmp_deploy_flyio-config.html· pinhe572699e7dd7d2995498953f7e53220694379da131a2a131f3317be1d77b674a· accessed 2026-08-18 · vendor-docGrounds: The Fly.io column: Health-gated promote with auto-rollback watchdog (Fly health-checks releases), Canary and progressive traffic shifting, Blue-green dual-slot instant switch and Multi-node and multi-region placement (Fly regions lead) -- the fly.toml checks and deploy-strategy keys are the documented mechanism behind those cells. - [render-deploys] Render. Deploys (render.com/docs/deploys): git-triggered builds, zero-downtime deploys gated on the service's health check path, deploy hooks and manual rollback to a previous deploy. publisher · read in our library
knowledge/fetched/cmp_deploy_render-deploys.html· pinheef78665ed2695dc39603c2c2b784ad4b965b5bea20e5fcda2df37fcbd63ef9e· accessed 2026-08-18 · vendor-docGrounds: The Render column: Health-gated promote with auto-rollback watchdog (Render health-checks releases), Instant manual rollback and Build on the target from source -- the documented deploy lifecycle the Nishi upload-build-promote-watchdog chain is compared with. - [argo-rollouts] Argo Project. Argo Rollouts -- Kubernetes progressive delivery controller (argo-rollouts.readthedocs.io): blue-green and canary strategies, weighted traffic steps, analysis-driven automated rollback. publisher · read in our library
knowledge/fetched/cmp_deploy_argo-rollouts.html· pinha13ade59af2152720464f62827c8a867ef7f009201eda8216fc78be275407617· accessed 2026-08-18 · vendor-docGrounds: The Kubernetes+Argo column: Health-gated promote with auto-rollback watchdog (Argo Rollouts is the reference), Canary and progressive traffic shifting (weighted steps are the reference for the _ABSENT_ nx_deploy_canary gap) and Blue-green dual-slot instant switch. - [k8s-deployment] The Kubernetes Authors. Deployments (kubernetes.io/docs/concepts/workloads/controllers/deployment): declarative rolling updates, revision history and kubectl rollout undo. publisher · read in our library
knowledge/fetched/cmp_deploy_k8s-deployment.html· pinh2fc7e20d2384f405f3f6c9a651f4ba8f0542b0ed8925e7f47e47bcb9f92f9775· accessed 2026-08-18 · vendor-docGrounds: The Kubernetes half of the Kubernetes+Argo column: Instant manual rollback (rollout undo), Staged content publish, Live fleet inventory API (kubectl get is the reference) and the GitOps declared-state reconciler row's declared-state model that Argo/Flux reconcile toward. - [rfc9807-opaque] Bourdrez, Krawczyk, Lewi, Wood. RFC 9807: The OPAQUE Augmented Password-Authenticated Key Exchange (aPAKE) Protocol. IETF, July 2025. publisher · read in our library
knowledge/fetched/cmp_deploy_rfc9807.html· pinh0e1ee56460c024fff7057d3743eb73aa4382a4fc274eb484597d6d43b41274cb· accessed 2026-08-18 · published-standardGrounds: The EXCEED control-plane auth is OPAQUE PAKE row: the password never crosses the wire and the server stores no password-equivalent are properties of this protocol (OPAQUE-3DH), which nx_opaque_login implements -- versus bearer tokens and OIDC on the incumbents. - [rfc8446-tls13] Rescorla, E. RFC 8446: The Transport Layer Security (TLS) Protocol Version 1.3. IETF, August 2018. publisher · read in our library
knowledge/fetched/cmp_deploy_rfc8446.html· pinh370ed8c0e6da22c8b8f4ad0230b6c12e6ec8ae807eca034220070828f25684fb· accessed 2026-08-18 · published-standardGrounds: The EXCEED sovereign end-to-end hosting row: the live site terminates its own TLS 1.3 (nx_sni_route, no nginx, no cloud LB, no CDN) -- the protocol it implements is this RFC, so every byte from ClientHello to response is checkable against a public standard, and the One-command source to live row's upload over sovereign TLS rides the same stack. - [rfc8555-acme] Barnes, Hoffman-Andrews, McCarney, Kasten. RFC 8555: Automatic Certificate Management Environment (ACME). IETF, March 2019. publisher · read in our library
knowledge/fetched/cmp_deploy_rfc8555.html· pinhe6ca1ca3e44cbb54cf6dc126f23d9f2abc5837119800af49bfa5e2c546d79393· accessed 2026-08-18 · published-standardGrounds: The TLS certificate acquisition (bundle retrieve + ACME DNS-01) row: the DNS-01 challenge nx_acme_issue completes for andelinwest.com (10509-byte Let's Encrypt bundle) is defined here -- platforms auto-provision on their edge, ours lands certs on the sovereign edge through the same protocol. - [porkbun-api] Porkbun LLC. Porkbun API v3 documentation (porkbun.com/api/json/v3/documentation): REST/JSON API to register and manage domains, DNS records, DNSSEC and SSL bundle retrieval, with an OpenAPI spec and sandbox. publisher · read in our library
knowledge/fetched/cmp_deploy_porkbun-api.html· pinh8dae6acbd654dbc32e631c23715266204354a526c7092df91f68b2f3b1cd7122· accessed 2026-08-18 · vendor-docGrounds: The Domain purchase API with spend wall + dry-run-first, DNS records API on the live registrar (A/TXT) and Purchase-to-live orchestration rows: the registrar endpoints (dryRun pre-flight, DNS record edit, SSL bundle retrieve) that nx_porkbun_domain, nx_acme_porkbun and nx_domain_golive drive live over sovereign TLS.
generated by nx_swcompare_matrix (sovereign NishiLang organ) from knowledge/compare/deploy.matrix · every Nishi cell verified against organ source at emit time · watch cells re-measured on every compare beat · zero JS, zero trackers