Nishi FamilyCompare › Swarm Fabric vs Heterogeneous-Cluster Orchestrators

Nishi Compare · measured, not asserted

Swarm Fabric vs Heterogeneous-Cluster Orchestrators

Nishi vs the field — every Nishi cell is measured against real organ source at emit time; each gap names the watch contract that will close it.

A sovereign heterogeneous supercomputer -- fleet telemetry, load/energy-aware + max-utilization scheduling, durable jobs, cross-workstream fairness, real gen output, all callable over MCP -- vs K3s, HashiCorp Nomad, Ray, and KubeEdge. HONEST: Nishi is young on live multi-node scale; unique on sovereignty, MCP-native control, determinism, ocap dispatch, and zero-install germination.

Overview

The purpose, declared position and evidence coverage of this domain. Source presence and completed acceptance are different measures.

Where we are. Measured 2026-08-19. The fabric is young on live multi-node scale and unique on sovereignty, MCP-native control, determinism, ocap dispatch and zero-install germination; every row is present and gate-proven on one machine plus a LAN snapshot. The matrix carries no symbol gaps, so this plan admits six watch contracts on the rows where the orchestrators lead: live remote actuation, retries, re-placement, telemetry history, quota as data and a browser worker joining live. The ecosystem row (Helm, operators, CSI) stays a deliberate non-goal.

Where we need to go. Make multi-node real -- a job leased here runs there and survives the node dying -- then fairness and history as data, then germinate onto a phone through the browser, keeping every exceed (ocap, determinism, MCP-native) intact.

The unit. 1 u = one measured session-leg. Calibration from landed rungs: the mangagen panel compositor went from existing substrate to shipped and live-verified in ONE leg (2026-08-13); the citations rung went from 3 to 55 domains in one leg across seven seats (2026-08-18); a greenfield engine with a bite-proven gate has measured 2 to 4 legs. Estimates recalibrate as rungs land and PR7 actuals write back.
Cost to multi-node for real: 4.5 u. Through M0.
Cost to fairness and history: 6.5 u. Through M1.
Cost to germinate everywhere: 9 u. Everything below.
Dispatch audit 2026-09-10: FOUNDATION GAPS. Source reviewed: runtime/nx_swarm_job.nx and runtime/_hdl_build/nx_supervised_dispatch.nx. Harvest simulates execution; supervisor self-probe runs built-in payloads. These cannot establish provider execution, accepted deliverables or multi-node production reliability. Historical August estimates and GREEN labels are not fresh acceptance evidence.
Dispatch rung D0 - bytes and identity: FIRST PREREQUISITE. Versioned task and result envelopes; exact task, attempt, worker, account scope and artifact identity; full input validation. Missing, malformed, truncated and unavailable evidence must remain distinct from empty or successful results. Existing swarm journal owner under private investigation.
Dispatch rung D1 - authority and isolation: DEPENDS D0. Verified provider/account readiness and scoped capabilities; private content policy enforced before dispatch. Three personal Claude accounts authorized, only Aster connection observed; Gmail excluded from estate tasks. Credentials never enter prompts or public telemetry.
Dispatch rung D2 - durable task state: DEPENDS D0,D1. Submitted, admitted, leased, running, waiting, failed, unknown, completed, reviewed, accepted and delivered remain distinct. Exercise idempotency, stale-worker fencing, concurrent completion, crash replay and uncertain outcomes on isolated real storage before claims.
Dispatch rung D3 - real execution: DEPENDS D2. Existing dispatch owner invokes a real worker through MCP/API, records actual model/account and terminal outcome, retains outputs and supports bounded cancellation. Built-in payloads and simulated harvest do not pass. Close the verified Claude CLI exception through the existing adapter owner.
Dispatch rung D4 - qualified work: DEPENDS D3. Bounded Beach tasks with verified context, explicit deliverables and reproducible checks; code/outcome checks plus calibrated qualitative review. Worker completion is not acceptance. Root and delegate assumptions are both subject to contrary evidence.
Dispatch rung D5 - scheduling: DEPENDS D2,D3,D4. Choose serial, parallel, batched or fused execution from dependencies, measured resource capacity, locality, queue delay and transfer cost. Enforce configured admission and provider budgets; unknown quota is not zero or unlimited. Compare equivalent accepted outcomes.
Dispatch rung D6 - recoverable workflows: DEPENDS D5. One-call common workflows with checkpointing, bounded retry/backoff, cancellation, reconciliation and replay. Lost workers, NAS outage and rate limits retain task identity and cannot silently duplicate side effects.
Dispatch rung D7 - supervised teams: DEPENDS D4,D6. One-call advanced task decomposition and assignment with conflict-aware source ownership, independent review, artifact integration and alpha/beta/production receipts. Practice expands delegation only after demonstrated task-family reliability.
Dispatch rung D8 - measurable investment: DEPENDS D4,D7. Counts and percentages with named denominators for attempted, executed, reviewed, accepted and delivered work; model input/output/cache tokens, measured time, queue delay, retries, review effort and evidence age. Unavailable values are explicit. Quality and timeliness lead; savings cannot excuse regression.
Dispatch rung D9 - mastery and innovation: DEPENDS D8. Dated research baselines, representative held-out Beach tasks, repeated fault and quality evaluations, measured adoption experiments and regression retention. Mastery requires repeatability; innovation requires a demonstrated advance beyond a named baseline. Recalibrate as research changes.
Dispatch investment calibration: UNMEASURED. D0-D9 order is dependency rationale, not invented cost or SOTA percentage. Estimate effort and confidence from actual task receipts before numerical ranking. Existing R0-R10 remote execution, recovery, quota and telemetry owners are reused rather than duplicated.
Dispatch research 2026-09-10: PRIMARY SOURCES REVIEWED. Temporal activity-execution documentation distinguishes attempts, timeouts, retry and asynchronous completion (https://docs.temporal.io/activity-execution). Anthropic agent-evaluation guidance separates capability and regression suites and combines code, model and human graders (https://www.anthropic.com/engineering/demystifying-evals-for-ai-agents). OpenTelemetry agent convention URL moved; current destination and stability remain unresolved, not claimed implemented. These sources guide qualification and do not certify Nishi as SOTA.
Dispatch network worker requirement 2026-09-10: OPERATOR INVENTORY NOT YET VERIFIED. Operator reports multiple 5090 laptops and other local-network resources. Discover and enroll through existing authenticated node/beacon owners; qualify hardware and available VRAM from device observations, not model-name assumptions. D1 includes consent and node identity; D5 includes power, thermal state, user activity, reserved capacity, measured transfer cost, job-specific GPU/VRAM fit and fresh availability. Offline, stale or busy nodes must not receive new work; checkpoints and bounded reassignment preserve progress. Existing sp_score source covers freshness, battery, CPU-load and memory percentages with thermal derating, but that function has no job-specific GPU/VRAM demand, user activity or reservation inputs. Compose existing pack/admit/beat/place owners before adding fields; root has not verified any 5090 worker connected.
Dispatch queue practice 2026-09-10: PRIVATE QUALIFIED 6/6. Existing sk_pack selected assign<0, including its own -2 already-tried sentinel, so an unplaceable non-GPU demand could loop forever. Private nx_swarm_pack_queue_t68 changes selection to exactly -1; native gate1789058409 passes6/6 with oversized RAM, exhausted/empty pool, GPU VRAM shortfall and unchanged original8/8 fixture. No remote dispatch executed. Separate live-pool source defects remain: no freshness check and unknown GPU VRAM replaced with1000000MB sentinel. These invalidate live capacity trust and are not fixed by queue termination.
Dispatch queue adoption 2026-09-10: SOURCE AND SERVING ARTIFACT UPDATED. Guarded canonical edit job1789058443 applied only the reviewed queue-selection predicate. Build1789058450 deployed nx_swarm_pack.elf44760B SHA829ebd79dc17ae8088ad39877178af4cee45b1f47cb124c75874fbd322143d62 and original gate8/8. Direct MCP call capability-denied; existing management API used for the live planning check, not a shell. Discovery found existing nx_swarm_gpu owner with separate GPU total/free/timestamp rows; reuse it for real capacity integration rather than creating another GPU inventory.
Dispatch journal root review 2026-09-10: PRIVATE QUALIFICATION REVIEWED. Root read full exact8-edit integration and22/22 isolated NAS evidence gate8420 plus compatibility8/8 gate8442. Candidate ae803e7c156185cae2d35d9dccb6b9cbfffa6610c527a9328651dacec91ceea3 uses nx_readcap_lib to distinguish complete reads from missing, errors and over-cap input; rejects torn framing and malformed DONE identifiers before lease/completion decisions. Canonical adoption requested with base hash guard. This does not prove JOB authority, concurrent completion, fsync durability, real worker execution or delivered Beach output.
Dispatch journal adoption 2026-09-10: LIVE TOOL BUILT. Canonical candidate adopted job1789058587 after independent SHA256 recheck and writer-native content guard. Initial SHA256-as-writer-hash attempt8547 refused without mutation; build8569 consequently rebuilt original and is not correction evidence. Corrected build8602 deployed49424B SHA5402b841ddea1946b2c36b7cfaf0d6e956a04e4b799f9dc20bd2706b73b3f6d1 and passed8/8 compatibility. Retain distinction between writer content hash and artifact SHA256; exact source reconstruction reviewed. GPU measured-pool integration remains private ongoing; no5090 node enrollment or Beach browser acceptance established.
Polite device participation 2026-09-10: REQUIRED BEFORE EXECUTION. Operator requires no brute forcing occupied devices or interfering with updates. Native scheduling must consume explicit interactive-use and maintenance state, configurable reserves and participation windows, plus thermal/power and real CPU/RAM/VRAM observations. Unknown availability is not idle capacity. Admit before launch; yield/checkpoint/reassign when owner use or maintenance requires resources. Planning vectors alone do not authorize execution. Keep new orchestration/evidence logic in Nishi Lang existing owners; Playwright remains replaceable browser execution backend through MCP/API, not a new script-based estate control plane.
Measured GPU planning adoption 2026-09-10: DEPLOYED PLANNER - NOT EXECUTION ADMISSION. Root read full candidate delta, native 33/33 receipt and legacy 8/8 receipt before adopting pack-v2 into existing nx_swarm_pack owner. Canonical source 31239B; build/deploy job1789059416 produced serving ELF69352B SHA256918ab027e4be1963f7957a636f7475d2839609196ab2ed1cfe69c70e1f065b79 and compatibility8/8. Live management API job1789059432 called pack-v2 against retained synthetic snapshots with explicit diagnostic 10-second freshness windows and zero future skew: exit3, stale NODE/GPU, no assignments. These window values are test inputs, not production defaults. Exact NODE/GPU identity and measured VRAM replace the sentinel in versioned pack-v2 only; legacy pack remains pending migration. Unknown activity, maintenance and reserved budgets are printed; no worker execution or5090 qualification established. Beach and AI swarm remain priority; Browser/OS shared policy is a design constraint, not a separate workstream.
Pack-v2 adoption review correction 2026-09-10: KNOWN VALIDATION DEFECT - FIX IN PROGRESS. After adoption, audit and independent root read of nx_node_beacon lines260-299 confirmed NODE f4 is mem_used_pct. Deployed pack-v2 compares f4 with totalMB instead of100, and original synthetic fixtures incorrectly supplied4096 in the percent field. Earlier33/33 is insufficient for this boundary. Agent is preparing private correction and valid-percent/small-memory/101-percent controls; do not describe current pack-v2 as fully qualified. Planning-only, no worker dispatch from this path. Root missed the unit mismatch during full delta review; shared schema/units checks are an investment gap.
Pack-v2 memory unit correction delivered 2026-09-10: LIVE NEGATIVE CHECK VERIFIED. Root read full correction delta and both receipts: private desired37/37 plus baseline2/2 reproducing original defects. Adopted one-condition fix mem_used_pct<=100 preserving freeMB<=totalMB. Build/deploy1789059647 servingELF69304B SHA25630b7f90f538792a05b071e28161642b60d0ee078b307e7c4677de58c9009a6ae compatibility8/8. Live API1789059662 rejected actual retained NODE row with percent101 as pool_rc=-43, exit3, no assignments. This corrects the prior recorded defect; remains planning-only, no execution admission or hardware discovery proof.
Placement clock correction 2026-09-10: CANONICAL BUILT AND DEPLOYED; LIMITED SCOPE. Reviewed full candidate evidence buildroot/knowledge/gates/swarm-place-epoch-t71.json and source: placement compared epoch beacon timestamps with monotonic time. Replaced two clock calls (production and fixture) with sys_now_realtime_us in canonical nx_swarm_place. Private actual-beacon qualification9/9, baseline defect reproduction8/8, compatibility8/8. Canonical build/deploy job1789060378 exit0 and gate8/8, serving ELF41032B SHA256458fa054e5c2f334769737528eb07cc79fd99aaea5069af6bf69c3e8f7f4a832. Selection is not dispatch authorization or resource reservation; activity, maintenance, charging-policy and parser gaps remain. No remote workload started.
Cross-agent reproducibility review 2026-09-12: PARTIAL INDEPENDENT REVIEW - ROI UNMEASURED. Claude main session has2176 top-level tool-use blocks:1843 nativeMCP84.7pct;1198 file-read/text-scan/catalog55.1pct. These are call shares, not token/time/value shares, and exclude child workflows. Real admission promotion and46/46 refusal-shape evidence verified; design handoffs do not establish reproducible execution. Live catalogue returns DARK for ranker despite retained MCP calls and SOURCELESS for shipjoin despite implementation in nx_dora: repair alias lineage and observation coverage before trusting census. Current cronwatch21 watches9 stale includes gate roster and Compare; diagnose current attempts/refusals before blaming old capacity constants. Require owner+version+schema+recipe+fresh evidence+independent repeat+delivered outcome per capability, with bounded repair/escalation receipts. Review knowledge/gates/claude-review-20260912.json. Beach remains primary; source/monitoring repair and public Compare emission pending.
Estate evidence progression research 2026-09-12: DESIGN NOT IMPLEMENTATION. Primary-source research contract retained at buildroot/knowledge/gates/estate-evidence-progression-research-20260912.json (10112 bytes; write job1789236489 exit0; full readback verified). Defines unstructured-to-structured-to-meaningful-to-actionable-to-reproducible evidence, separate ownership/lineage/freshness/rework/rebuild/DORA/quality-preserving ROI measures with denominators and unknown coverage, no arbitrary composite. Physics and hardware limits remain separate from software maturity. Naming and alias owner linkage plus response/refusal reasons and adjudicated correctness required; no restriction evasion or acceptance-equals-legality inference. Existing owner/data mapping pending. No implementation, private qualification, publication or verified user outcome claimed.

Latest recorded release

No valid dated release entry is recorded for this domain.

Release entries describe recorded changes; they do not establish that every capability passed evaluation.

18 of 31 capabilities measured|7 of them measured exceeds|13 open|coverage 580/1000|adoption 6 full / 12 partial

Evidence profile — what the gaps on this board actually are

Measured by nx_swcompare_evidence, read back by nx_evprofile_lib. Every figure is a count with its denominator — there is deliberately no score, no grade and no percentage anywhere in this band, because a stored scalar is a field a seat can edit and a counted partition is not.

evidence|grounded 18/18|unsupported 0|gates green 3/3|proven able to fail 2/3|never bitten 1|green at 0/0 0|open gaps 13|of them unnamed 1|of them proof withheld 0|flips ready 0

proven able to fail counts the gates that have a RECORDED RED — nx_gate_bite mutated the gate subject, rebuilt it, watched the gate go red, and that record is inside the shared TTL. never bitten is its complement over the same denominator: those gates ran and were green, and nothing has ever shown them able to detect anything, so their green is a statement about this run and not about the gate. green at 0/0 is a separate and much weaker observation — the gate printed GREEN on a zero denominator, so its own tooth counter says it examined nothing. A gate can be green, non-zero, and still never bitten; that is the common case and it is now visible instead of implied.

partition: grounded + unsupported = 18 vs present 18 · named + unnamed + withheld = 13 vs open 13 · both reconcile

liar-kill conj=GPQN · all four conjuncts held

graded document: BUILDROOT tree, 18039 bytes · gates map: PRIMARY · stamped 1d 7h ago · source ../knowledge/status/evstamp_swarm.verdict

Gap classWhat it is, and the work it names
UNNAMED-GAPA gap row carries a bare _ABSENT_ with no symbol after it, so it names no build contract and no seat can pick it up. Give it an _ABSENT_:<symbol> and it becomes work somebody can do.
This band reports the referee counts. The per-axis worklist rows — which axis is unsupported, which watch is ready to flip, which gap is unnamed — are printed by nx_swcompare_evidence swarm itself and are not carried on the stamp, so this page names the classes and the producer names the rows. That split is stated rather than hidden: a count without a worklist is not actionable, and this band is honest about which half of that it is.

Production map

Follow the dependencies, declared acceptance criteria and recorded priorities. Inspect source binding before treating a rank as executable work.

Ranking source binding: PLAN_MATRIX_BOUND_ONLY. Recorded priorities require current acceptance evidence and resource checks before execution.

Ranking matches the captured plan and matrix only. Latest execution outcome, research freshness, accepted delivery and investment return are unverified.

Recorded priority estimates

Order from nx_compare_rank (nx_dr_ocm: (deficit + cost-of-delay + option + enables) x sponsor x self-sufficiency x momentum / cost). FINISH rows are rungs whose symbol is present but whose organ is short of full adoption: listed before new work by this heuristic. Priority is not measured delivery cost or execution readiness. Stamp: # asof=1789541513 domain=swarm target_version=0.1 rungs=11 done=0 open=11 finish=0 ranker=nx_dr_ocm

#StageRungPriorityDerivation
#10.1Remote actuation (R0) sj_remote_dispatch4600v=23 m=1 c=5
#20.1Retry policy (R1) sj_retry_policy4500v=9 m=1 c=2
#30.1Re-placement on node failure (R2) sp_reschedule866v=13 m=1 c=15
#4laterHub outage leaves the spokes serving (R6) sj_hub_partition_proof5333v=16 m=1 c=3
#5laterTelemetry history (R3) sb_history1400v=7 m=1 c=5
#6laterTelemetry in the open standard (R9) sb_otlp_export1200v=6 m=1 c=5
#7laterConsistency proven by a Jepsen-class harness (R7) sj_partition_fixture1000v=5 m=1 c=5
#8laterQuota plane (R4) sa_quota_plane600v=6 m=1 c=10
#9laterFault injection as practice (R10) sh_fault_inject600v=9 m=1 c=15
#10laterNode conformance suite at join (R8) se_conformance_suite466v=7 m=1 c=15
#11laterBrowser worker joins live (R5) nxe_browser_worker_join120v=3 m=1 c=25

Declared roadmap — contract, acceptance, executor, effort

RungCloses withDefinition of done (pre-declared)ExecutorEst.
Remote actuation (R0)sj_remote_dispatchA job leased on the NAS executes on a remote node over the mesh transport and completes through the same journaled completion log; proven with the 3090 box and re-proven when it is offline (the lease is stolen back, never lost)Organ2 u
Retry policy (R1)
after R0
sj_retry_policyBounded retries with backoff and speculative re-execution of a slow attempt; the first completion wins idempotently; policy rows are dataOrgan1 u
Re-placement on node failure (R2)
after R0
sp_rescheduleA node that stops beating has its leased jobs re-placed by the placement scorer; a killed node in the fixture loses no jobOrgan1.5 u
Telemetry history (R3)sb_historyPer-node beats appended as a series with the liar-killed freshness semantics preserved; a forged or stale beat never enters the seriesOrgan1 u
Quota plane (R4)sa_quota_planePer-workstream budgets as plane rows read by the arbiter; a row change alters the grant in the next window without a rebuildOrgan1 u
Browser worker joins live (R5)
after R0
nxe_browser_worker_joinA phone joins through the browser WASM worker, receives a tile, returns a bit-identical render and is counted in the fleetOrgan2.5 u
Hub outage leaves the spokes serving (R6)
after R0
sj_hub_partition_proofA fixture kills the hub mid-job and proves the completion journal loses nothing when it returns; the spool-and-drain lane already carries a spoke's writes, so this rung closes the LEASE half. Done when the gate proves zero lost or doubled completions across a hub restart with a neg-control (a lease written without its journal row) going REDOrgan1.5 u
Consistency proven by a Jepsen-class harness (R7)
after R6
sj_partition_fixtureTwo lease holders driven through a simulated partition, pause and stale-steal window with the completion history checked against a declared consistency model; done when the harness names the model, passes on the shipped lease plane and goes RED on a deliberately broken idempotency keyOrgan2 u
Node conformance suite at join (R8)
after R0
se_conformance_suiteA candidate node runs a versioned suite at join time (bit-exact tile, lease hold, honest beat) whose receipt lands on the beat plane; done when a node that fails the suite is provably never placed and a passing node's receipt names host, toolchain and checksumOrgan1.5 u
Telemetry in the open standard (R9)
after R3
sb_otlp_exportThe beat plane emits its rows as OTLP metrics on request; done when an external collector reads our numbers byte-for-byte equal to the plane and a forged beat is refused before exportOrgan1 u
Fault injection as practice (R10)
after R2,R6
sh_fault_injectA heal-lane verb injects one declared fault (kill, delay, partition) against a fixture node and asserts steady state returns within a pre-declared bound; done when each fault class has a receipt and the bound is derived from measured recovery, never pickedOrgan1.5 u

Milestones

MilestoneRungsCumulative
M0 · Multi-node for realR0,R1,R24.5 u
M1 · Fairness and historyR3,R46.5 u
M2 · Germinate everywhereR59 u
M3 · Provable under failureR6,R7,R8,R9,R1016.5 u
Ladder verdict. NOT DECLARED. This board names no dated best-in-class or frontier target and no rung roles (sotatarget and rungrole rows on its plan); the ranker labels it NO-LADDER until it does, and until then its rungs climb toward a target nobody has written down. Bars: 0 (fresh 0, attested 0, stale 0, unattested 0), verdict NO-BAR against the current month 2026-09.

Inspect a rung and its prerequisites

Declared nodes 11. Rank input binding: PLAN_MATRIX_BOUND_ONLY. Dependency order is authored. Implementation, acceptance evidence, authority and resource readiness are unverified. No action is recommended or dispatched here.

Plan SHA-256 580f069eda6f55cf36f384d2216900ff479507a9eacf2f248f6fb6758bdbb731. Target rows 0; role rows 0. Existing risks and release worklog retain their own scope; no node completion is inferred.

Use Enter or Space on a rung to inspect its contract. Prerequisite links locate another rung in this list; open its summary to inspect it. Estimates are authored effort, not forecasts.

  1. R0 — Remote actuation

    Prerequisites: None declared; this does not establish execution eligibility.

    Contract: sj_remote_dispatch

    Acceptance: A job leased on the NAS executes on a remote node over the mesh transport and completes through the same journaled completion log; proven with the 3090 box and re-proven when it is offline (the lease is stolen back, never lost)

    Authored effort: 2. Executor kind: Organ. Responsible, accountable and verifier not established. Inspect retained worklog.

  2. R1 — Retry policy

    Prerequisites: R0 (acceptance unverified)

    Contract: sj_retry_policy

    Acceptance: Bounded retries with backoff and speculative re-execution of a slow attempt; the first completion wins idempotently; policy rows are data

    Authored effort: 1. Executor kind: Organ. Responsible, accountable and verifier not established. Inspect retained worklog.

  3. R2 — Re-placement on node failure

    Prerequisites: R0 (acceptance unverified)

    Contract: sp_reschedule

    Acceptance: A node that stops beating has its leased jobs re-placed by the placement scorer; a killed node in the fixture loses no job

    Authored effort: 1.5. Executor kind: Organ. Responsible, accountable and verifier not established. Inspect retained worklog.

  4. R3 — Telemetry history

    Prerequisites: None declared; this does not establish execution eligibility.

    Contract: sb_history

    Acceptance: Per-node beats appended as a series with the liar-killed freshness semantics preserved; a forged or stale beat never enters the series

    Authored effort: 1. Executor kind: Organ. Responsible, accountable and verifier not established. Inspect retained worklog.

  5. R4 — Quota plane

    Prerequisites: None declared; this does not establish execution eligibility.

    Contract: sa_quota_plane

    Acceptance: Per-workstream budgets as plane rows read by the arbiter; a row change alters the grant in the next window without a rebuild

    Authored effort: 1. Executor kind: Organ. Responsible, accountable and verifier not established. Inspect retained worklog.

  6. R5 — Browser worker joins live

    Prerequisites: R0 (acceptance unverified)

    Contract: nxe_browser_worker_join

    Acceptance: A phone joins through the browser WASM worker, receives a tile, returns a bit-identical render and is counted in the fleet

    Authored effort: 2.5. Executor kind: Organ. Responsible, accountable and verifier not established. Inspect retained worklog.

  7. R6 — Hub outage leaves the spokes serving

    Prerequisites: R0 (acceptance unverified)

    Contract: sj_hub_partition_proof

    Acceptance: A fixture kills the hub mid-job and proves the completion journal loses nothing when it returns; the spool-and-drain lane already carries a spoke's writes, so this rung closes the LEASE half. Done when the gate proves zero lost or doubled completions across a hub restart with a neg-control (a lease written without its journal row) going RED

    Authored effort: 1.5. Executor kind: Organ. Responsible, accountable and verifier not established. Inspect retained worklog.

  8. R7 — Consistency proven by a Jepsen-class harness

    Prerequisites: R6 (acceptance unverified)

    Contract: sj_partition_fixture

    Acceptance: Two lease holders driven through a simulated partition, pause and stale-steal window with the completion history checked against a declared consistency model; done when the harness names the model, passes on the shipped lease plane and goes RED on a deliberately broken idempotency key

    Authored effort: 2. Executor kind: Organ. Responsible, accountable and verifier not established. Inspect retained worklog.

  9. R8 — Node conformance suite at join

    Prerequisites: R0 (acceptance unverified)

    Contract: se_conformance_suite

    Acceptance: A candidate node runs a versioned suite at join time (bit-exact tile, lease hold, honest beat) whose receipt lands on the beat plane; done when a node that fails the suite is provably never placed and a passing node's receipt names host, toolchain and checksum

    Authored effort: 1.5. Executor kind: Organ. Responsible, accountable and verifier not established. Inspect retained worklog.

  10. R9 — Telemetry in the open standard

    Prerequisites: R3 (acceptance unverified)

    Contract: sb_otlp_export

    Acceptance: The beat plane emits its rows as OTLP metrics on request; done when an external collector reads our numbers byte-for-byte equal to the plane and a forged beat is refused before export

    Authored effort: 1. Executor kind: Organ. Responsible, accountable and verifier not established. Inspect retained worklog.

  11. R10 — Fault injection as practice

    Prerequisites: R2 (acceptance unverified), R6 (acceptance unverified)

    Contract: sh_fault_inject

    Acceptance: A heal-lane verb injects one declared fault (kill, delay, partition) against a fixture node and asserts steady state returns within a pre-declared bound; done when each fault class has a receipt and the bound is derived from measured recovery, never picked

    Authored effort: 1.5. Executor kind: Organ. Responsible, accountable and verifier not established. Inspect retained worklog.

Learning and practice paths

No structured learning path is declared for this plan. Existing research, roadmap and worklog remain available above.

Capability comparisons

Compare the field, search individual capabilities and open their source and adoption evidence. Documented presence does not establish comparative quality.

Position map — centrality and distinctiveness

The four-quadrant map the field uses for brand strategy (Dawar and Bagga, HBR June 2015), re-derived from this matrix on every publish. Centrality is the share of the category's feature mass a player covers, each feature weighted by how many hold it; distinctiveness is the average lead over each rival on the rows the player holds; breadth is the depth-weighted share of the whole matrix (the bubble); depth is how deeply the rows held are held; momentum is the day-over-day move off the spine (green rising, red falling, grey until day two); the dashed path runs first day → previous day → today. Dividers are the category means. Axes are fitted to the field of play, so read the tick numerals, not the frame. Rival marks are documented presence, so a rival's position reads the record, never its quality. The picture grades its own readability below; the table beside it is the same data for a screen reader or a second method.

Views. 2D cut: centrality, distinctiveness · 3D cube: centrality, distinctiveness, breadth · axes registered: centrality, distinctiveness, breadth, depth, momentum · a board picks its own in knowledge/compare/swarm.cdmap (cut|x|y, cube|x|y|z); absent = the HBR defaults
Position map, two-dimensional cutOne bubble per player. Bubble area is breadth, the ring colour is momentum, the dashed lines are the category means, and both axes are fitted to the field of play with their tick numerals shown. Every value is repeated in the table that follows. 500 600 700 800 900 1000 50 100 150 200 250 300 350 400 450 centrality (permil, fitted 500–1000) distinctiveness (permil, fitted 50–450) mean 823 mean 225 Unconventional Aspirational Peripheral Mainstream Nishi, centrality 607, distinctiveness 384, breadth 462, depth 796, momentum 0 K3s, centrality 925, distinctiveness 260, breadth 623, depth 805, momentum 0 Nomad, centrality 887, distinctiveness 155, breadth 526, depth 742, momentum 0 Ray, centrality 785, distinctiveness 127, breadth 430, depth 701, momentum 0 KubeEdge, centrality 915, distinctiveness 201, breadth 569, depth 736, momentum 0 Nishi K3s Nomad Ray KubeEdge

bubble area = breadth · ring = momentum (green rising, red falling, grey until day two) · dashed = category means · axes fitted to the field of play: centrality 500–1000, distinctiveness 50–450 of 0–1000 permil (the full range put every player in one corner)
readability of the 2D cut, self-graded by the layout ruler: label overlaps 0 · labels over marks 0 · off-canvas 0 · unresolved labels 0 · mark overlaps 0 (a fact of the data: two players that close are that close) · data spread 640 permil of the plot · quadrant words unseated 0
text contrast, measured with wcag2-ratio (floors from contrast.conf), light theme: labels 16.24 (floor 4.50) · notes 16.24 (floor 4.50) · quadrant words 5.89 (floor 4.50) · tick numerals 5.89 (floor 4.50) · axis titles 5.59 (floor 4.50) · dark theme: labels 13.78 (floor 4.50) · quadrant words 5.55 (floor 4.50) · axis titles 5.97 (floor 4.50) · dark classes under their floor 0 (one figure serves both themes: a dark shortfall is a token to fix, never a class to hide) · classes refused under their floor 0 (a refused class is not drawn; the scale classes are measured, never hidden) · export: SVG PNG (receipt, rendered by the estate's own rasteriser from this page)
Position map, three-dimensional cubeThe same players in an isometric cube. Each axis is fitted to its own field of play and carries numerals on the floor grid and the vertical axis; each bubble drops a dotted line to its floor shadow so height reads as height. Values are in the table that follows. 500 600 700 800 900 1000 50 100 150 200 250 300 350 400 450 400 450 500 550 600 650 centrality distinctiveness breadth Ray: centrality 785, distinctiveness 127, breadth 430 Nomad: centrality 887, distinctiveness 155, breadth 526 Nishi: centrality 607, distinctiveness 384, breadth 462 KubeEdge: centrality 915, distinctiveness 201, breadth 569 K3s: centrality 925, distinctiveness 260, breadth 623 Nishi K3s Nomad Ray KubeEdge
axes fitted: centrality 500–1000 · distinctiveness 50–450 · breadth 400–650 permil · farther bubbles are painted first, nearer ones over them · the floor shadow is each bubble's (x, y) at height 0
readability of the 3D cube, self-graded by the layout ruler: label overlaps 0 · labels over marks 0 · off-canvas 0 · unresolved labels 0 · mark overlaps 1 (a fact of the data: two players that close are that close) · data spread 403 permil of the plot
Position map, small multiplesEvery pair of registered axes as one small cut. Each panel fits both axes to the field of play, the dashed lines are the category means, bubble area is breadth and the ring colour is momentum; the legend below names the colours. 500 1000 50 450 distinctiveness vs centrality Nishi: centrality 607, distinctiveness 384 K3s: centrality 925, distinctiveness 260 Nomad: centrality 887, distinctiveness 155 Ray: centrality 785, distinctiveness 127 KubeEdge: centrality 915, distinctiveness 201 500 1000 400 650 breadth vs centrality Nishi: centrality 607, breadth 462 K3s: centrality 925, breadth 623 Nomad: centrality 887, breadth 526 Ray: centrality 785, breadth 430 KubeEdge: centrality 915, breadth 569 500 1000 675 825 depth vs centrality Nishi: centrality 607, depth 796 K3s: centrality 925, depth 805 Nomad: centrality 887, depth 742 Ray: centrality 785, depth 701 KubeEdge: centrality 915, depth 736 500 1000 480 520 momentum vs centrality Nishi: centrality 607, momentum 500 K3s: centrality 925, momentum 500 Nomad: centrality 887, momentum 500 Ray: centrality 785, momentum 500 KubeEdge: centrality 915, momentum 500 50 450 400 650 breadth vs distinctiveness Nishi: distinctiveness 384, breadth 462 K3s: distinctiveness 260, breadth 623 Nomad: distinctiveness 155, breadth 526 Ray: distinctiveness 127, breadth 430 KubeEdge: distinctiveness 201, breadth 569 50 450 675 825 depth vs distinctiveness Nishi: distinctiveness 384, depth 796 K3s: distinctiveness 260, depth 805 Nomad: distinctiveness 155, depth 742 Ray: distinctiveness 127, depth 701 KubeEdge: distinctiveness 201, depth 736 50 450 480 520 momentum vs distinctiveness Nishi: distinctiveness 384, momentum 500 K3s: distinctiveness 260, momentum 500 Nomad: distinctiveness 155, momentum 500 Ray: distinctiveness 127, momentum 500 KubeEdge: distinctiveness 201, momentum 500 400 650 675 825 depth vs breadth Nishi: breadth 462, depth 796 K3s: breadth 623, depth 805 Nomad: breadth 526, depth 742 Ray: breadth 430, depth 701 KubeEdge: breadth 569, depth 736 400 650 480 520 momentum vs breadth Nishi: breadth 462, momentum 500 K3s: breadth 623, momentum 500 Nomad: breadth 526, momentum 500 Ray: breadth 430, momentum 500 KubeEdge: breadth 569, momentum 500 675 825 480 520 momentum vs depth Nishi: depth 796, momentum 500 K3s: depth 805, momentum 500 Nomad: depth 742, momentum 500 Ray: depth 701, momentum 500 KubeEdge: depth 736, momentum 500
Nishi K3s Nomad Ray KubeEdge
10 panels over 5 registered axes, every pair once (the lower axis on x, the higher on y) · each panel fitted to its own field of play, first and last tick numerals shown · no labels in a small cut, the legend names the colours; the grade below reports the mark terms only (MM summed over the panels, spread averaged)
readability of the small multiples, self-graded by the layout ruler: label overlaps 0 · labels over marks 0 · off-canvas 0 · unresolved labels 0 · mark overlaps 2 (a fact of the data: two players that close are that close) · data spread 549 permil of the plot
PlayerQuadrantcentralitydistinctivenessbreadthdepthmomentumRows heldDays on spineFirst seen
NishiUnconventional6073844627960 since 2026-09-151822026-09-15
K3sAspirational9252606238050 since 2026-09-152422026-09-15
NomadMainstream8871555267420 since 2026-09-152222026-09-15
RayPeripheral7851274307010 since 2026-09-151922026-09-15
KubeEdgeMainstream9152015697360 since 2026-09-152422026-09-15
DayMatrix rows reviewedPlayers recorded
2026-09-15315
2026-09-16315

players 5|matrix rows 31|feature mass 107|centrality mean 823|distinctiveness mean 225|axes 5|spine days 2 (shown 2)|rows written today 0|readability defects 2D 0 cube 0|spine knowledge/status/cdmap/swarm.spine

How this is scored. Every Nishi mark is measured: the generator reads the real organ source on disk and requires the implementing symbol to exist (no self-grading). A watching tag names the organ and symbol contracted to close a gap — the mark flips itself on the next compare beat when that workstream ships, and the comparewatch- plane row flips with it. A dark tag means the organ file EXISTS but does not declare the contracted symbol: something shipped there under another name, and until the contract is repointed to the real entry point (the plan rung and this row) or the function is renamed, that capability is invisible to this board — a build lost to darkness, named so it is not. The flip is necessary, not sufficient: it proves the symbol exists, never that the capability is good. The bar is the rung's pre-declared done-rule, proven by its gate — a symbol shipped without the behaviour behind it is a defect, and the flip is exactly what makes that defect visible instead of quiet. Competitor marks record documented capability presence — presence, not depth or scale. Adoption is measured too: every measured row carries where its organ stands on the estate's ladder (source → built → promoted → registered → invoked; libraries by importer reach minus validation importers; gates by the execution surfaces that run them). A row is fully adopted only at the top of its ladder; anything short is tagged partial with the exact remedy, so a build nobody promoted can no longer read as shipped. Census stamps: importers asof 1789497476, gate census asof 1789498715 (unix seconds; -1 = census absent).

Capability matrix — measured against source

leads / measured exceed present partial absent · click any capability for its evidence

CapabilityNishiK3sNomadRayKubeEdge
Fleet node telemetryMeasured: SWARMBEATGATE exists in runtime/nx_swarm_beat.nx, verified at emit. All expose node metrics; K3s (metrics-server) is Best [k3s-docs]. Nishi has a liar-killed freshness store (stale/forged->never FRESH) but no historical TSDB Adoption: REGISTERED-DARK — PARTIAL: callable, authorised, completed MCP invocation not established by supplied journal window; lifetime history unknown (direct execution may be recorded elsewhere; this scan does not establish lifetime use); no execution surface runs it either (clock, cron, daemon, roster, actlog and surfaced forks checked).
not adopted: callable, authorised, completed MCP invocation not established by supplied journal window; lifetime history unknown (direct execution may be recorded elsewhere; this scan does not establish lifetime use); no execution surface runs it either (clock, cron, daemon, roster, actlog and surfaced forks checked)
Pros Nishi has it, measured on diskCons behind K3s (leads); not adopted yet: callable, authorised, completed MCP invocation not established by supplied journal window; lifetime history unknown (direct execution may be recorded elsewhere; this scan does not establish lifetime use); no execution surface runs it either (clock, cron, daemon, roster, actlog and surfaced forks checked)
Load + energy-aware placementMeasured: SWARMPLACEGATE exists in runtime/nx_swarm_place.nx, verified at emit. K8s/Nomad bin-pack by cpu/mem [nomad-scheduling]; Ray by resources [ray-scheduling]; Nishi scores load AND thermal/battery (never cook a phone) with data-driven weights -- comparable, energy-axis slightly ahead Adoption: REGISTERED-DARK — PARTIAL: callable, authorised, completed MCP invocation not established by supplied journal window; lifetime history unknown (direct execution may be recorded elsewhere; this scan does not establish lifetime use); no execution surface runs it either (clock, cron, daemon, roster, actlog and surfaced forks checked).
not adopted: callable, authorised, completed MCP invocation not established by supplied journal window; lifetime history unknown (direct execution may be recorded elsewhere; this scan does not establish lifetime use); no execution surface runs it either (clock, cron, daemon, roster, actlog and surfaced forks checked)
Pros Nishi has it, measured on diskCons not adopted yet: callable, authorised, completed MCP invocation not established by supplied journal window; lifetime history unknown (direct execution may be recorded elsewhere; this scan does not establish lifetime use); no execution surface runs it either (clock, cron, daemon, roster, actlog and surfaced forks checked)
Heterogeneous max-utilization schedulerMeasured: SWARMPACKGATE exists in runtime/nx_swarm_pack.nx, verified at emit. Ray is Best at packing mixed CPU/GPU tasks; Nishi packs a resource-vector (cpu-milli/ram/gpu/vram) so ONE node runs GPU-gen+CPU-tile+RAM-index at once, measured 7 vs naive 5 -- parity in kind, young in scale rival marks uncited — the Yes, Best or Part codes on this row are an observation read with no reference mark behind them Adoption: REGISTERED-DARK — PARTIAL: callable, authorised, completed MCP invocation not established by supplied journal window; lifetime history unknown (direct execution may be recorded elsewhere; this scan does not establish lifetime use); no execution surface runs it either (clock, cron, daemon, roster, actlog and surfaced forks checked).
not adopted: callable, authorised, completed MCP invocation not established by supplied journal window; lifetime history unknown (direct execution may be recorded elsewhere; this scan does not establish lifetime use); no execution surface runs it either (clock, cron, daemon, roster, actlog and surfaced forks checked)
Pros Nishi has it, measured on diskCons behind Ray (leads); not adopted yet: callable, authorised, completed MCP invocation not established by supplied journal window; lifetime history unknown (direct execution may be recorded elsewhere; this scan does not establish lifetime use); no execution surface runs it either (clock, cron, daemon, roster, actlog and surfaced forks checked)
Cross-workstream resource fairnessMeasured: SWARMARBITRATEGATE exists in runtime/nx_swarm_arbitrate.nx, verified at emit. K8s ResourceQuota+PriorityClass+preemption is Best/mature [k8s-priority] [ghodsi2011] [verma2015]; Nishi has max-share caps (no-monopoly) + priority preemption + partial grants (no-starvation), gate-proven -- same model, less mature Adoption: SOURCE-ONLY — PARTIAL: source exists, never compiled: /api/build it.
not adopted: source exists, never compiled: /api/build it
Pros Nishi has it, measured on diskCons behind K3s (leads); not adopted yet: source exists, never compiled: /api/build it
Capability-scoped (ocap) job dispatchMeasured exceed: WORKERDISPATCHGATE in runtime/nx_worker_dispatch.nx, verified at emit. K8s RBAC/Nomad ACLs are coarse cluster roles; NONE grant a JOB an attenuated capability to exactly the worker+storage it needs, deny-by-default -- Nishi's ocap-per-job is unique [miller2006]. FIELD CHECK 2026-09-02: SPIFFE is the industry's workload-identity standard -- an SVID names WHO a workload is, never WHAT it may touch -- so ocap dispatch stays the exceed and a SPIFFE-shaped identity document is the interop this row does not yet speak [spiffe-overview]; and the gauge's own weakest link stands beside it: the worker API is unauthenticated on the wire today (nx_swarm_maturity Security L0), so the authority model is ahead of the transport that carries it -- see the worker-authentication row below Adoption: RUN-BY:fork:nx_mesh_run — fully adopted (top of its ladder).
Pros Nishi leads, a measured exceed; ahead of K3s, Nomad, Ray, KubeEdge; fully adopted on the estate ladderCons none on the measured axes (rival marks are documented presence, not depth)
MCP-native control planeMeasured exceed: ma_emit_nodes in runtime/_hdl_build/nx_mgmt_api.nx, verified at emit. Every organ callable over MCP tools/call (proven live); none of the orchestrators are MCP-native -- an agent drives the whole fabric with a scoped cap Adoption: LIVE-DAEMON — fully adopted (top of its ladder).
Pros Nishi leads, a measured exceed; ahead of K3s, Nomad, Ray, KubeEdge; fully adopted on the estate ladderCons none on the measured axes (rival marks are documented presence, not depth)
Deterministic int-exact computeMeasured exceed: SWARMTILEGATE in runtime/nx_swarm_tile.nx, verified at emit. Nishi's tiled render is 100% integer -> bit-identical across ANY device (proven byte-exact re-render); float compute on the others varies by hardware -- reproducibility is a sovereign axis Adoption: REGISTERED-DARK — PARTIAL: callable, authorised, completed MCP invocation not established by supplied journal window; lifetime history unknown (direct execution may be recorded elsewhere; this scan does not establish lifetime use); no execution surface runs it either (clock, cron, daemon, roster, actlog and surfaced forks checked).
not adopted: callable, authorised, completed MCP invocation not established by supplied journal window; lifetime history unknown (direct execution may be recorded elsewhere; this scan does not establish lifetime use); no execution surface runs it either (clock, cron, daemon, roster, actlog and surfaced forks checked)
Pros Nishi leads, a measured exceed; ahead of K3s, Nomad, Ray, KubeEdgeCons not adopted yet: callable, authorised, completed MCP invocation not established by supplied journal window; lifetime history unknown (direct execution may be recorded elsewhere; this scan does not establish lifetime use); no execution surface runs it either (clock, cron, daemon, roster, actlog and surfaced forks checked)
Durable jobs + speculative harvestMeasured: SWARMJOBGATE exists in runtime/nx_swarm_job.nx, verified at emit. Nomad/K8s Jobs + Ray retries are Best/mature; Nishi has a journaled completion log + O_EXCL leases with stale-steal + idempotent complete (crash-replay proven) -- correct, young rival marks uncited — the Yes, Best or Part codes on this row are an observation read with no reference mark behind them Adoption: REGISTERED-DARK — PARTIAL: callable, authorised, completed MCP invocation not established by supplied journal window; lifetime history unknown (direct execution may be recorded elsewhere; this scan does not establish lifetime use); no execution surface runs it either (clock, cron, daemon, roster, actlog and surfaced forks checked).
not adopted: callable, authorised, completed MCP invocation not established by supplied journal window; lifetime history unknown (direct execution may be recorded elsewhere; this scan does not establish lifetime use); no execution surface runs it either (clock, cron, daemon, roster, actlog and surfaced forks checked)
Pros Nishi has it, measured on diskCons behind K3s (leads), Nomad (leads); not adopted yet: callable, authorised, completed MCP invocation not established by supplied journal window; lifetime history unknown (direct execution may be recorded elsewhere; this scan does not establish lifetime use); no execution surface runs it either (clock, cron, daemon, roster, actlog and surfaced forks checked)
Autoscale to zeroMeasured: MESHAUTOSCALEGATE exists in runtime/nx_mesh_autoscale.nx, verified at emit. KubeEdge/Knative-class scale-to-zero is Best; Nishi has a proven policy + host-agent, true 0MB/0proc idle -- parity in kind rival marks uncited — the Yes, Best or Part codes on this row are an observation read with no reference mark behind them Adoption: REGISTERED-UNAUTHORISED — PARTIAL: registered, no cap ever minted; no execution surface runs it either (clock, cron, daemon, roster, actlog and surfaced forks checked).
not adopted: registered, no cap ever minted; no execution surface runs it either (clock, cron, daemon, roster, actlog and surfaced forks checked)
Pros Nishi has it, measured on diskCons behind KubeEdge (leads); not adopted yet: registered, no cap ever minted; no execution surface runs it either (clock, cron, daemon, roster, actlog and surfaced forks checked)
Native container governance daemonlessMeasured exceed: nx_pe_emit_container in runtime/nx_pe_container_win.nx, verified at emit. K3s needs containerd, Nomad a driver, Ray a runtime, KubeEdge a kubelet; Nishi governs a worker natively (Job Object) with no daemon/VM. SYMBOL REPOINTED 2026-09-01: the row cited CreateJobObjectW, which is a WINDOWS API NAME and not a sovereign function, so the one-symbol ruler correctly refused it and the OLD substring ruler had been grounding the row against a COMMENT. THE SAME ROW APPEARS IN THREE BOARDS (containers, swarm, workermesh) AND WAS THE ENTIRE RED FOR ALL THREE -- one cause, three domains, which is why collapsing to causes before sizing a campaign matters. The defining sovereign function in that organ is nx_pe_emit_container. A ROW THAT CITES A FOREIGN OS API HAS NO SOVEREIGN DEFINITION TO GROUND AGAINST -- name the wrapper, never the syscall it wraps rival marks uncited — the Yes, Best or Part codes on this row are an observation read with no reference mark behind them Adoption: SOURCE-ONLY — PARTIAL: source exists, never compiled: /api/build it.
not adopted: source exists, never compiled: /api/build it
Pros Nishi leads, a measured exceed; ahead of K3s, Nomad, Ray, KubeEdgeCons not adopted yet: source exists, never compiled: /api/build it
Compile-on-target ISA-exact distributionMeasured exceed: cmd_buildrun in runtime/_hdl_build/nx_hostctl.nx, verified at emit. All ship generic container images (-march=native is manual/Buildx-matrix); Nishi ships SOURCE and compiles per-node so the binary is ISA-exact by construction Adoption: LIVE-DAEMON — fully adopted (top of its ladder).
Pros Nishi leads, a measured exceed; ahead of K3s, Nomad, Ray, KubeEdge; fully adopted on the estate ladderCons none on the measured axes (rival marks are documented presence, not depth)
Zero-install germination (bare-metal + browser)Measured exceed: nxe_load_exec in runtime/nx_nxe_lib.nx, verified at emit. KubeEdge does edge nodes but needs a kubelet install; Nishi germinates from POST via SHA-verified NXE (never-brick) and can join phones via a browser WASM worker -- no agent install rival marks uncited — the Yes, Best or Part codes on this row are an observation read with no reference mark behind them Adoption: LIB-WIRED importers=4 nonval=4 — fully adopted (top of its ladder).
Pros Nishi leads, a measured exceed; ahead of K3s, Nomad, Ray, KubeEdge; fully adopted on the estate ladderCons none on the measured axes (rival marks are documented presence, not depth)
P2P artifact distributionMeasured: BitTorrent SEEDER exists in runtime/nx_torrent_seed.nx, verified at emit. Registries + OCI distribution are standard; Nishi content-addresses artifacts + announces to a live DHT [bep5-dht] -- LAN distribution without a hub registry Adoption: LIVE-DAEMON — fully adopted (top of its ladder).
Pros Nishi has it, measured on disk; ahead of Ray; fully adopted on the estate ladderCons none on the measured axes (rival marks are documented presence, not depth)
Content-addressed integrity registryMeasured: CONTAINERREGISTRYGATE exists in runtime/nx_container_registry.nx, verified at emit. OCI registries are the reference; Nishi's SHA-256 CAS refuses a tampered/bit-rot pull at get-time by construction -- parity rival marks uncited — the Yes, Best or Part codes on this row are an observation read with no reference mark behind them Adoption: BUILT-UNPROMOTED — PARTIAL: compiled, never promoted to the serving root: /api/promote it.
not adopted: compiled, never promoted to the serving root: /api/promote it
Pros Nishi has it, measured on diskCons not adopted yet: compiled, never promoted to the serving root: /api/promote it
Fleet supervision + crash respawnMeasured: cmd_supervise exists in runtime/_hdl_build/nx_hostctl.nx, verified at emit. K8s/Nomad/KubeEdge self-healing is Best/mature; Nishi supervises via connect-probe + guard respawn -- works, less featureful. FIELD CHECK 2026-09-02: the supervision-tree archetype is OTP's -- restart strategies and a restart intensity bound (maximum restarts within a period) past which a supervisor stops and escalates instead of crash-looping [otp-supervision]; our guard has no such bound, which is the hc_restart_intensity contract on the supervisor board, and the estate measured the cost on 2026-08-16 when an unbounded revive loop amplified a lock-blocked daemon into an eight-minute blackout Adoption: LIVE-DAEMON — fully adopted (top of its ladder).
Pros Nishi has it, measured on disk; fully adopted on the estate ladderCons behind K3s (leads), Nomad (leads), KubeEdge (leads)
Offline store-and-forward (intermittent)Measured: sp_streq exists in runtime/nx_state_spool.nx, verified at emit. KubeEdge is Best at disconnected edge autonomy [kubeedge-docs]; Nishi spools locally offline + drains on reconnect, head-of-line-safe -- parity with KubeEdge's niche. FIELD CHECK 2026-09-02: NATS leaf nodes are the field's documented hub-and-spoke messaging shape -- a local NATS system bridged to a remote hub over one leaf connection with subject bridging and per-link credentials -- so the spool lane is graded against a named topology rather than a generic queue [nats-leafnodes] Adoption: BUILT-UNPROMOTED — PARTIAL: compiled, never promoted to the serving root: /api/promote it.
not adopted: compiled, never promoted to the serving root: /api/promote it
Pros Nishi has it, measured on disk; ahead of RayCons behind KubeEdge (leads); not adopted yet: compiled, never promoted to the serving root: /api/promote it
Multi-node live distribution at scaleMeasured: SWARMJOBGATE exists in runtime/nx_swarm_job.nx, verified at emit. THE honest gap: K3s/Nomad/Ray/KubeEdge run real multi-thousand-node clusters in production; Nishi is PROVEN single-machine + LAN-snapshot, live remote actuation (mesh_gen) not yet wired -- young rival marks uncited — the Yes, Best or Part codes on this row are an observation read with no reference mark behind them Adoption: REGISTERED-DARK — PARTIAL: callable, authorised, completed MCP invocation not established by supplied journal window; lifetime history unknown (direct execution may be recorded elsewhere; this scan does not establish lifetime use); no execution surface runs it either (clock, cron, daemon, roster, actlog and surfaced forks checked).
not adopted: callable, authorised, completed MCP invocation not established by supplied journal window; lifetime history unknown (direct execution may be recorded elsewhere; this scan does not establish lifetime use); no execution surface runs it either (clock, cron, daemon, roster, actlog and surfaced forks checked)
Pros Nishi has it, measured on diskCons behind K3s (leads), Nomad (leads), Ray (leads), KubeEdge (leads); not adopted yet: callable, authorised, completed MCP invocation not established by supplied journal window; lifetime history unknown (direct execution may be recorded elsewhere; this scan does not establish lifetime use); no execution surface runs it either (clock, cron, daemon, roster, actlog and surfaced forks checked)
Ecosystem / operators / helm / CSI storageOpen — no implementing organ is measured for this axis yet. Mature ecosystems (Helm, operators, CSI, CNI, service mesh) are the orchestrators' moat; Nishi has none of that surface -- a deliberate non-goal for a sovereign single-operator fabric, but an honest absence rival marks uncited — the Yes, Best or Part codes on this row are an observation read with no reference mark behind them
Pros none measured yetCons behind K3s (leads), Nomad (leads), Ray (leads), KubeEdge (leads); no implementing organ measured
Worker API authenticated on the wireDARK — runtime/nx_worker_dispatch.nx EXISTS but does not declare wd_worker_auth: something shipped at this path under another name, and this mark would read open forever. Repoint the contract to the real entry point (the plan rung AND this row) or rename the function; the flip follows on the next beat, and the comparewatch- plane row reads DARK until then. NEW WATCH 2026-09-02 (hub-and-spoke failure class 0 -- the one the estate's own gauge names its weakest link: nx_swarm_maturity Security L0, worker API 0.0.0.0 unauthenticated today, so ocap decides WHAT a job may do while any LAN peer may speak to the worker at all). K3s, Nomad and KubeEdge run mutual TLS between the control plane and each node agent with a per-node identity (Best); Ray's inter-node TLS is optional configuration (Part). SPIFFE is the identity standard the field converges on -- an SVID names the workload and the Workload API hands it out [spiffe-overview]. Contract: every worker request carries a capability bound to a per-node identity the hub issued, an unauthenticated request is REFUSED before dispatch, and the gate proves both the refusal and the positive control (a valid cap is served); the gauge's Security dimension leaves L0 the day this lands.
watching wd_worker_auth
Pros none measured yetCons behind K3s (leads), Nomad (leads), Ray, KubeEdge (leads); open contract, nothing on disk yet
Hub outage leaves the spokes serving (static stability)DARK — runtime/nx_swarm_job.nx EXISTS but does not declare sj_hub_partition_proof: something shipped at this path under another name, and this mark would read open forever. Repoint the contract to the real entry point (the plan rung AND this row) or rename the function; the flip follows on the next beat, and the comparewatch- plane row reads DARK until then. NEW WATCH 2026-09-02 (failure class 1 of 5: the hub as a single point of failure). Tailscale is the field's cleanest statement of the remedy -- a coordination server that only exchanges keys and metadata while the WireGuard data plane runs node-to-node, so a coordination-server outage cannot stop traffic that already flows (Best) [tailscale-how]; KubeEdge's edge autonomy keeps pods running through a cloud disconnect (Best) [kubeedge-docs]; K3s and Nomad are graded Part from their architecture reads -- a kubelet or a Nomad client keeps its allocations running while the server is unreachable but takes no new work -- and that grade is an architecture read, not a mirrored sentence; Ray's head node is a hard dependency (No) [ray-scheduling]. Ours: the spool-and-drain lane already carries a spoke's writes through a hub outage (row above), but a LEASED JOB is hub-only state, so the contract is a fixture that kills the hub mid-job and proves the completion journal loses nothing when it returns.
watching sj_hub_partition_proof
Pros none measured yetCons behind K3s, Nomad, KubeEdge (leads); open contract, nothing on disk yet
Consistency proven by an adversarial Jepsen-class harnessDARK — runtime/nx_swarm_job.nx EXISTS but does not declare sj_partition_fixture: something shipped at this path under another name, and this mark would read open forever. Repoint the contract to the real entry point (the plan rung AND this row) or rename the function; the flip follows on the next beat, and the comparewatch- plane row reads DARK until then. NEW WATCH 2026-09-02 (failure class 2: split brain and double completion under a partition). Our lease plane claims exactly-once completion by O_EXCL leases with stale-steal and an idempotent complete, crash-replay proven on ONE node -- Jepsen's consistency reference defines the models such a claim must name, which histories the journal admits and which phenomena it forbids, and the field's bar is an analysis that partitions, pauses and clock-skews the system while checking the history [jepsen-consistency]. K3s inherits etcd, whose Jepsen analysis is published (Yes) [jepsen-etcd]; Nomad's Raft store has no published Jepsen analysis (Part); Ray and KubeEdge none (No). Contract: a fixture that runs two lease holders through a simulated partition and stale-steal window and checks the completion history against a declared model, with a neg-control (a deliberately broken idempotency key) going RED.
watching sj_partition_fixture
Pros none measured yetCons behind K3s, Nomad; open contract, nothing on disk yet
A fabric conformance suite any node must pass to joinDARK — runtime/nx_swarm_endpoint.nx EXISTS but does not declare se_conformance_suite: something shipped at this path under another name, and this mark would read open forever. Repoint the contract to the real entry point (the plan rung AND this row) or rename the function; the flip follows on the next beat, and the comparewatch- plane row reads DARK until then. NEW WATCH 2026-09-02 (failure class 3: config drift between the hub and its spokes, the silent failure a heterogeneous fleet manufactures by construction). The field's industry test is the CNCF Kubernetes conformance program -- a published, versioned suite a distribution must pass to carry the mark, with results submitted as reproducible logs (Best) [cncf-conformance]; KubeEdge conforms at its cloud edge (Part); Nomad and Ray publish no conformance program (No). Ours: gates prove organs, not nodes -- a laptop, the 3090 box or a phone joining the fleet is never asked to prove it can take a tile bit-exactly, hold a lease and beat honestly before it is placed. Contract: a suite a candidate node runs at join time whose receipt (host, toolchain, checksum, result) lands on the beat plane and whose failure keeps the node out of placement.
watching se_conformance_suite
Pros none measured yetCons behind K3s (leads), KubeEdge; open contract, nothing on disk yet
Telemetry exported in the open standard (OTLP)DARK — runtime/nx_swarm_beat.nx EXISTS but does not declare sb_otlp_export: something shipped at this path under another name, and this mark would read open forever. Repoint the contract to the real entry point (the plan rung AND this row) or rename the function; the flip follows on the next beat, and the comparewatch- plane row reads DARK until then. NEW WATCH 2026-09-02 (failure class 4: observability only its own author can read). Our beats are liar-killed and sovereign, and no outside instrument can consume them -- an audit or an award reads OpenTelemetry, whose specification defines the metrics, traces and logs signals and the OTLP wire every collector accepts [otel-spec]. Ray exports Prometheus and OpenTelemetry metrics natively (Best); K3s, Nomad and KubeEdge expose Prometheus endpoints an OTel collector scrapes (Yes). Contract: the beat plane emits its rows as OTLP metrics on request, so an external collector can check our numbers without trusting our page -- sovereignty is the SOURCE of the data, not a refusal to speak the open format.
watching sb_otlp_export
Pros none measured yetCons behind K3s, Nomad, Ray (leads), KubeEdge; open contract, nothing on disk yet
Fault injection as a standing practice (chaos)DARK — runtime/nx_swarm_heal.nx EXISTS but does not declare sh_fault_inject: something shipped at this path under another name, and this mark would read open forever. Repoint the contract to the real entry point (the plan rung AND this row) or rename the function; the flip follows on the next beat, and the comparewatch- plane row reads DARK until then. NEW WATCH 2026-09-02 (failure class 5: a healer that has only ever seen healthy nodes). nx_swarm_heal heals what the beat reports and the gate fleet bites organs with mutants, but no organ ever KILLS a healthy spoke, delays its beats or partitions it on purpose to see whether placement, leases and healing recover -- the discipline the Principles of Chaos Engineering define as experiments on a steady-state hypothesis with a minimised blast radius [chaos-principles]. K3s and Ray carry chaos tooling in their ecosystems (Part); Nomad and KubeEdge ship none (No). Contract: a heal-lane verb that injects one declared fault (kill, delay, partition) against a fixture node and asserts the fleet's steady state returns within a pre-declared bound, the fault class named in the receipt.
watching sh_fault_inject
Pros none measured yetCons behind K3s, Ray; open contract, nothing on disk yet
Delivery performance measured in the industry's own keys (DORA)Measured exceed: d_band_deploy in runtime/_hdl_build/nx_dora.nx, verified at emit. LANDED, cited 2026-09-02: the hub-and-spoke DEVELOPMENT loop (seat, build, promote, deploy) grades itself in DORA's four keys derived from the estate's own event planes -- deploy frequency and lead time measured from the ws_sync and organ_ship journals, change-fail and recovery time declared as proxies rather than faked, banded ELITE, HIGH, MEDIUM, LOW against the published thresholds [dora-fourkeys]. None of the four orchestrators measure the delivery loop that feeds them (they are its subject, not its instrument), so the exceed is claimed narrowly: the fabric's own dev loop reports the metric the industry's DORA report uses, and it refuses to count a guard refusal as a production failure. Adoption axis stated: nx_dora is REGISTERED-DARK on the MCP surface today (nx_catalog 2026-09-02), so the capability is present and the beat that publishes it is the open work. Adoption: REGISTERED-DARK — PARTIAL: callable, authorised, completed MCP invocation not established by supplied journal window; lifetime history unknown (direct execution may be recorded elsewhere; this scan does not establish lifetime use); no execution surface runs it either (clock, cron, daemon, roster, actlog and surfaced forks checked); only referenced by nx_shipjoin_gate -- a mention, not a run.
not adopted: callable, authorised, completed MCP invocation not established by supplied journal window; lifetime history unknown (direct execution may be recorded elsewhere; this scan does not establish lifetime use); no execution surface runs it either (clock, cron, daemon, roster, actlog and surfaced forks checked); only referenced by nx_shipjoin_gate -- a mention, not a run
Pros Nishi leads, a measured exceed; ahead of K3s, Nomad, Ray, KubeEdgeCons not adopted yet: callable, authorised, completed MCP invocation not established by supplied journal window; lifetime history unknown (direct execution may be recorded elsewhere; this scan does not establish lifetime use); no execution surface runs it either (clock, cron, daemon, roster, actlog and surfaced forks checked); only referenced by nx_shipjoin_gate -- a mention, not a run
Live multi-node remote actuationDARK — runtime/nx_swarm_job.nx EXISTS but does not declare sj_remote_dispatch: something shipped at this path under another name, and this mark would read open forever. Repoint the contract to the real entry point (the plan rung AND this row) or rename the function; the flip follows on the next beat, and the comparewatch- plane row reads DARK until then. The honest gap named on the distribution row: a job leased on the NAS executes on a remote node (the 3090 box, a phone) and completes through the same journal rival marks uncited — the Yes, Best or Part codes on this row are an observation read with no reference mark behind them
watching sj_remote_dispatch
Pros none measured yetCons behind K3s (leads), Nomad (leads), Ray (leads), KubeEdge (leads); open contract, nothing on disk yet
Retry policy with backoff and speculative re-executionDARK — runtime/nx_swarm_job.nx EXISTS but does not declare sj_retry_policy: something shipped at this path under another name, and this mark would read open forever. Repoint the contract to the real entry point (the plan rung AND this row) or rename the function; the flip follows on the next beat, and the comparewatch- plane row reads DARK until then. Nomad and Ray retries are mature; ours is stale-steal only. RE-GRADED 2026-09-02 against the September-2026 field: the bar is capped exponential backoff with full jitter so a hub reconnect never synchronises a herd of spokes into one retry storm [aws-backoff-jitter], durable execution that retries an activity idempotently against a journaled history instead of re-running it blind [temporal-workflows], and a per-client retry budget so retries cannot turn one slow hub into a cascading failure [sre-cascading] -- the estate measured the herd case on its own promote lease (a bare Retry-After scalar synchronised every caller), which is why LV6 on the loadgov board answers overload as its own error class
watching sj_retry_policy
Pros none measured yetCons behind K3s (leads), Nomad (leads), Ray, KubeEdge; open contract, nothing on disk yet
Re-placement on node failureDARK — runtime/nx_swarm_place.nx EXISTS but does not declare sp_reschedule: something shipped at this path under another name, and this mark would read open forever. Repoint the contract to the real entry point (the plan rung AND this row) or rename the function; the flip follows on the next beat, and the comparewatch- plane row reads DARK until then. Self-healing placement: a node that stops beating has its jobs re-placed, never stranded rival marks uncited — the Yes, Best or Part codes on this row are an observation read with no reference mark behind them
watching sp_reschedule
Pros none measured yetCons behind K3s (leads), Nomad (leads), Ray, KubeEdge (leads); open contract, nothing on disk yet
Node telemetry historyDARK — runtime/nx_swarm_beat.nx EXISTS but does not declare sb_history: something shipped at this path under another name, and this mark would read open forever. Repoint the contract to the real entry point (the plan rung AND this row) or rename the function; the flip follows on the next beat, and the comparewatch- plane row reads DARK until then. The freshness store is liar-killed but has no history; a series per node over time rival marks uncited — the Yes, Best or Part codes on this row are an observation read with no reference mark behind them
watching sb_history
Pros none measured yetCons behind K3s (leads), Nomad, Ray, KubeEdge; open contract, nothing on disk yet
Per-workstream quota as a planeDARK — runtime/nx_swarm_arbitrate.nx EXISTS but does not declare sa_quota_plane: something shipped at this path under another name, and this mark would read open forever. Repoint the contract to the real entry point (the plan rung AND this row) or rename the function; the flip follows on the next beat, and the comparewatch- plane row reads DARK until then. Max-share caps and preemption exist; budgets declared as plane rows per workstream, never constants rival marks uncited — the Yes, Best or Part codes on this row are an observation read with no reference mark behind them
watching sa_quota_plane
Pros none measured yetCons behind K3s (leads), Nomad, Ray, KubeEdge; open contract, nothing on disk yet
Browser WASM worker joins the fabric liveDARK — runtime/nx_nxe_lib.nx EXISTS but does not declare nxe_browser_worker_join: something shipped at this path under another name, and this mark would read open forever. Repoint the contract to the real entry point (the plan rung AND this row) or rename the function; the flip follows on the next beat, and the comparewatch- plane row reads DARK until then. Germination exists; a phone joining through a browser worker and taking a tile is the proof. FIELD CHECK 2026-09-02: the transports a spoke that is a PAGE would ride are standardised -- W3C WebTransport gives a browser client-server QUIC streams and datagrams [w3c-webtransport], and libp2p's specs cover the browser transports (WebRTC, WebTransport), NAT traversal and peer identity a third-party browser needs to reach a hub behind a home router [libp2p-specs]; the estate already holds a QUIC substrate (fourteen nx_quic_* organs, see the edge board), so the browser spoke is a WIRING rung on both ends, not a protocol build
watching nxe_browser_worker_join
Pros none measured yetCons behind KubeEdge; open contract, nothing on disk yet
Rival-claim provenance. Every Yes, Best or Part mark in a rival column is a claim about someone else's product. rows with rival marks 26 · cited 14 · uncited 12. A cited row carries a reference mark that resolves to a pinned mirror (the refs gate measures that); an uncited row is an observation read and is badged in its evidence until a reference lands. The badge is the receipt, never the proof: a mark proves a mirror exists, not that the mirror supports the code.

Delivery and evidence

Inspect risks, technical debt, rendered observations, experiments and references. Read scope and limitations alongside every result.

Release history and work log

The worked plan, on the board. Every leg appends what it measured, landed, retracted, learned and left queued, per rung, so a crash leaves the next seat a ledger here rather than a transcript to mine. Kinds: measure, land, retract, lesson, queue. Newest last.
WhenRungKindEntry
2026-09-11-queueAI-collaboration protocol DESIGN ONLY (lane swarm-design, 2026-09-11): knowledge/status/swarm_ai_handoff_design_20260911.md 65021 B sha256 5ad97fc2726a25e7c43a45315650a3f257be8e608edf18de9da462fe384e0053. Zone ledger GREEN AMBER RED per subject and action as data, handoff packet and cross-family review queue, regression fence composing the nx_fence guard that /api/promote already forks, durable checkpoint and resume per run lane step with a writer nonce, collab_pass in the emitter. Proposed M4 rungs AC1-AC9 with sotabar, barscan, sotatarget and rungrole rows are AMBER and must land as ONE block only after two distinct-family reviews (first reviewer Codex on or after 2026-09-16), because a sotatarget without every rungrole refuses the whole board
On these two registers. Rows are declared in the domain's plan file and carry the debt id, which is the join key back to the sovereign debt plane — that plane, not this page, is the authority on state. Reconciling them automatically (the regen reading the plane and refreshing these rows) is a named, owed rung; until it lands, treat an id here as a pointer to look up, not a status to trust.
Honest verdict. The coverage above is capability presence measured against source — not depth, scale, or polish, where mature rivals may lead. Exceeds are claimed only where a mechanism backs them. Every open gap is a watch contract: it names the organ and symbol that closes it, and this page flips the cell itself when that workstream ships.

Person · product · place — not yet measured for this domain

Every compare carries this layer. Declare knowledge/compare/swarm.ppp (rows surface|nishi or c1..c4|label|url|connect naming OUR live surface and each rival's front door), run nx_ppp_probe domain swarm, and this section fills itself on the next beat: the same ruler on both sides — privacy and CX (third-party hosts, tracker classes, cookies, security headers), design and longevity (design hygiene, computed WCAG contrast, render-blocking resources, unsized media, script weight, theme and motion queries), findability (landmarks, skip link, on-site search, breadcrumb, headings, internal links).

The field — discovered, not chosen

Rows written by nx_field_discover from swarm.seeds: the industry's own lists (Wikipedia wikitext, GitHub topics, awesome lists) read mechanically, every candidate counted across seeds. The matrix columns above are a SEAT'S pick; this band is the population they were picked from, and the stats line measures one against the other. A rival here is a lead, never a verdict — it earns a column when its capabilities are read and pinned.

field|seeds=4|scanned=4|fetched=4|reused=0|failed=0|named=4|candidates=4|mentions=4|capped=0 rival|K3s|1|1|col0-k3s|https://docs.k3s.io/|named rival|Nomad|1|1|col1-nomad|https://developer.hashicorp.com/nomad/docs/concepts/scheduling/how-scheduling-works|named rival|Ray|1|1|col2-ray|https://docs.ray.io/en/latest/ray-core/scheduling/index.html|named rival|KubeEdge|1|1|col3-kubeedge|https://kubeedge.io/docs/|named
RankRivalSeedsMentionsFirst seedKindLink
1K3s11col0-k3snamedhttps://docs.k3s.io/
2Nomad11col1-nomadnamedhttps://developer.hashicorp.com/nomad/docs/concepts/scheduling/how-scheduling-works
3Ray11col2-raynamedhttps://docs.ray.io/en/latest/ray-core/scheduling/index.html
4KubeEdge11col3-kubeedgenamedhttps://kubeedge.io/docs/

field candidates 4|shown 4 of 4|matrix columns in the field 4 of 4|discovered rivals with no column 0|malformed rows 0 (counted, never rendered)|read-capped 0

Gaps from the record — what the estate does that no board carries

The record census (nx_goalmap record) reads the invoked-tool population and every plan queue row and files each organ or directive that NO matrix, plan or gates row names. A row here is a callout the boards missed: adjudicate it onto a board or declare it infrastructure. Census state BLIND (age 74333 s), sources read 4 of 7 declared — a BLIND census is a FLOOR: unread sources can only add rows.

kindnameboardsourceevidence
directivenx_fenceswarmplan-queuerung=-

rows shown 1|this board's directives 1|estate-wide un-boarded organs 492 (listed in full on /compare/ecosystem)|census rows 611|malformed 0 (counted, never rendered)

References

Beyond a link list. Every reference below resolves twice — the publisher's copy and, where banked, the estate's own non-rottable library mirror with a content pin — and carries its evidence class plus the exact claim on this page it grounds. Keyed marks like [key] in the matrix notes jump here. A dash means honestly absent, never assumed.
  1. [k3s-docs] K3s project (SUSE / CNCF). K3s -- Lightweight Kubernetes documentation (docs.k3s.io): single-binary distribution with embedded containerd, metrics-server, local storage and Helm controller. publisher · read in our library knowledge/fetched/cmp_swarm_k3s.html · pin hb226a6c8ced451de2ab0bc90a1cf10493320bebe70a75efa4f0f7706c8eec09d · accessed 2026-08-18 · vendor-docGrounds: The K3s column: Fleet node telemetry (metrics-server is Best), Fleet supervision + crash respawn (K8s self-healing), Native container governance daemonless (K3s needs containerd, Part) and Ecosystem / operators / helm / CSI storage (the orchestrators' moat).
  2. [nomad-scheduling] HashiCorp. How Nomad job scheduling works (developer.hashicorp.com/nomad/docs/concepts/scheduling): evaluations, allocations, feasibility checking and ranking with bin packing, and the service/batch/system schedulers. publisher · read in our library knowledge/fetched/cmp_swarm_nomad-scheduling.html · pin h0883ef9786ba712aa47c5c12b48440739461a1f8a8838ea84f015dde27976296 · accessed 2026-08-18 · vendor-docGrounds: The Nomad column: Load + energy-aware placement (Nomad bin-packs by cpu/mem), Durable jobs + speculative harvest (Nomad Jobs are Best/mature) and Cross-workstream resource fairness -- the evaluation-and-allocation model our nx_swarm_place / nx_swarm_pack scorers are graded against.
  3. [ray-scheduling] Anyscale / Ray project. Ray Core -- Scheduling (docs.ray.io/en/latest/ray-core/scheduling): resource-based task and actor scheduling, placement groups, locality-aware and spread strategies across a heterogeneous cluster. publisher · read in our library knowledge/fetched/cmp_swarm_ray-scheduling.html · pin h6ea883313eae4e28596f4555624e2069d2306325a76db7ca734fa7a64ef8500e · accessed 2026-08-18 · vendor-docGrounds: The Ray column: Heterogeneous max-utilization scheduler (Ray is Best at packing mixed CPU/GPU tasks -- the bar nx_swarm_pack's resource-vector packing, measured 7 vs naive 5, is compared with), Load + energy-aware placement (Ray by resources) and Durable jobs (Ray retries).
  4. [kubeedge-docs] KubeEdge project (CNCF). KubeEdge documentation (kubeedge.io/docs): cloud-edge architecture with CloudCore and EdgeCore, edge autonomy under disconnection, and device management. publisher · read in our library knowledge/fetched/cmp_swarm_kubeedge.html · pin h90317819fcc198f18dff4455312c97bda1ec980b29bdbb05dd5f2fdb255124b3 · accessed 2026-08-18 · vendor-docGrounds: The KubeEdge column: Offline store-and-forward (KubeEdge is Best at disconnected edge autonomy -- parity claimed for the spool-and-drain lane), Zero-install germination (KubeEdge does edge nodes but needs a kubelet install, Part) and Autoscale to zero (KubeEdge/Knative-class is Best).
  5. [verma2015] Verma, Pedrosa, Korupolu, Oppenheimer, Tune, Wilkes. Large-scale cluster management at Google with Borg. EuroSys 2015. publisher · read in our library knowledge/fetched/cmp_swarm_verma2015.pdf · pin h2fdacd3b69f8af91477412fc91d1d858a43e764929a4edb646bd517ededdad94 · accessed 2026-08-18 · published-paperGrounds: The published ancestor of the K3s column's scheduling model: admission control, priority and quota, preemption, bin-packing and machine sharing with performance isolation -- the mature form of the Cross-workstream resource fairness (max-share caps + priority preemption + partial grants) and Heterogeneous max-utilization scheduler rows, and why Multi-node live distribution at scale is THE honest gap.
  6. [ghodsi2011] Ghodsi, Zaharia, Hindman, Konwinski, Shenker, Stoica. Dominant Resource Fairness: Fair Allocation of Multiple Resource Types. USENIX NSDI 2011. publisher · read in our library knowledge/fetched/cmp_swarm_ghodsi2011.html · pin h97dfb22b355d36a71ff1f6a25b6695f51a928809a3796efec561304a8c7c1110 · accessed 2026-08-18 · published-paperGrounds: The Cross-workstream resource fairness row: fair allocation over a multi-resource vector (cpu-milli / ram / gpu / vram) with the no-monopoly and no-starvation properties nx_swarm_arbitrate gate-proves is the DRF problem statement -- the published fairness bar behind the K8s ResourceQuota + PriorityClass Best cell.
  7. [bep5-dht] Loewenstern, Norberg. BEP 5: DHT Protocol (bittorrent.org/beps/bep_0005): the Kademlia-based distributed hash table for trackerless torrents -- ping, find_node, get_peers, announce_peer. publisher · read in our library knowledge/fetched/cmp_swarm_bep5.html · pin h103f7501c56d8e17a87066af30419bd5199a904ae84f3962fecfc37b7bfc45ca · accessed 2026-08-18 · published-standardGrounds: The P2P artifact distribution row: nx_torrent_seed content-addresses artifacts and announces to a live DHT -- LAN distribution without a hub registry -- and the DHT it announces to is this protocol; registries plus OCI distribution are the standard the row contrasts with.
  8. [k8s-priority] The Kubernetes Authors. Pod Priority and Preemption (kubernetes.io/docs/concepts/scheduling-eviction/pod-priority-preemption): PriorityClass, preemption of lower-priority pods, and interaction with ResourceQuota. publisher · read in our library knowledge/fetched/cmp_swarm_k8s-priority.html · pin h87bd7a066d9b46c35fefacc28ad756036d6466fdb8be31a9eef9649024dc1c78 · accessed 2026-08-18 · vendor-docGrounds: The Cross-workstream resource fairness row's K3s Best cell (K8s ResourceQuota + PriorityClass + preemption is Best/mature) and the Capability-scoped (ocap) job dispatch note that K8s RBAC/Nomad ACLs are coarse cluster roles -- the mature model our max-share caps + priority preemption + partial grants are the young twin of.
  9. [miller2006] Miller, M. S. Robust Composition: Towards a Unified Approach to Access Control and Concurrency Control. PhD dissertation, Johns Hopkins University, 2006 (JScholarship record; author copy at erights.org). publisher · read in our library knowledge/fetched/cmp_swarm_miller2006-jhu.html · pin haf29e138b8ca91abf97435a07a9c055452c1432a128cab0e47c223ed4f048a0f · accessed 2026-08-18 · published-paperGrounds: The Capability-scoped (ocap) job dispatch row (EXCEED, unique): a JOB granted an attenuated capability to exactly the worker + storage it needs, deny-by-default, is the object-capability discipline this dissertation formalises -- none of K3s, Nomad, Ray or KubeEdge grant per-job attenuated capabilities.
  10. [otp-supervision] Ericsson AB. Erlang/OTP System Documentation, OTP Design Principles: Supervisor Behaviour -- supervision trees, restart strategies (one_for_one, one_for_all, rest_for_one) and the restart intensity bound (maximum restarts within a period) past which a supervisor stops its children and itself instead of crash-looping. publisher · read in our library knowledge/fetched/cmp_swarm_otp-supervision.html · pin h3d990d5bf67a0e4fbb5e2af86b7e74f6b1ae5db8a27d8f49a3a8648e980be8df · accessed 2026-09-02 · vendor-docGrounds: Fleet supervision + crash respawn -- the supervision-tree archetype our hostctl guard is the young twin of, and the restart-intensity bound it lacks.
  11. [nats-leafnodes] Synadia and the NATS project. NATS Server documentation: Leaf Nodes -- a local NATS system bridged to a remote hub over one leaf connection, the documented hub-and-spoke topology for edge and disconnected sites, with subject bridging and credentials per link. publisher · read in our library knowledge/fetched/cmp_swarm_nats-leafnodes.html · pin h351bbd9e2fcb14cf045f01516d9d4ccea378e5342e057c566c95f377593b63e2 · accessed 2026-09-05 · vendor-docGrounds: Offline store-and-forward (intermittent) -- the field's messaging shape for a spoke behind an intermittent hub link.
  12. [tailscale-how] Pennarun, A. (Tailscale Inc). How Tailscale works: a coordination server exchanges public keys and metadata while every packet runs peer-to-peer over WireGuard -- the control plane and the data plane are separated by design so that traffic already flowing does not depend on the coordination server. publisher · read in our library knowledge/fetched/cmp_swarm_tailscale-how.html · pin h8cf2c779da9c24bffecd0747cf836f8d79faecf2ceeff97cb90f1d4cf30b076e · accessed 2026-09-02 · vendor-docGrounds: Hub outage leaves the spokes serving (static stability) -- the cleanest published statement of a hub that cannot take the data plane down with it.
  13. [jepsen-consistency] Kingsbury, K. (Jepsen LLC). Consistency -- the reference guide defining consistency models as sets of admissible histories, the phenomena each forbids, and the dependency graphs the models are built from. publisher · read in our library knowledge/fetched/cmp_swarm_jepsen-consistency.html · pin h3973e30505147b7e79d7e6f8d1bbd36c51ed0568a59aff949635e101c6234c96 · accessed 2026-09-02 · published-courseGrounds: Consistency proven by an adversarial Jepsen-class harness -- the vocabulary a lease-plane exactly-once claim must be stated in before it can be tested.
  14. [cncf-conformance] Cloud Native Computing Foundation. Kubernetes Conformance (cncf/k8s-conformance): the versioned conformance test suite and the submission process by which a distribution earns the Certified Kubernetes mark, with results filed as reproducible logs. publisher · read in our library knowledge/fetched/cmp_swarm_cncf-conformance.html · pin hdde74a9e4c2704cd918bb7f851372dda96bac3a6d09542da4c44ece4e9e3ab22 · accessed 2026-09-02 · published-standardGrounds: A fabric conformance suite any node must pass to join -- the industry test the row names as its bar.
  15. [temporal-workflows] Temporal Technologies. Temporal documentation: Workflows -- durable execution over an event history, deterministic replay, and the retry and timeout policies attached to activities. publisher · read in our library knowledge/fetched/cmp_swarm_temporal-workflows.html · pin h49a387252e1c9fe2184d0a878ea828ce254560ffd363d72b0c566043a56bc3e7 · accessed 2026-09-02 · vendor-docGrounds: Retry policy with backoff and speculative re-execution -- the durable-execution bar for a retry that replays against a journal instead of re-running blind.
  16. [libp2p-specs] Protocol Labs and the libp2p project. libp2p specifications: transports including WebRTC and WebTransport for browsers, NAT traversal (hole punching, relays), peer identity and discovery. publisher · read in our library knowledge/fetched/cmp_swarm_libp2p-specs.html · pin he55222395a1475c9f4dc1543f87718bdedc519c74d3b58159db69a0bf06636f9 · accessed 2026-09-02 · published-standardGrounds: Browser WASM worker joins the fabric live -- the browser-spoke transport and NAT-traversal specs a phone joining from a third-party browser would ride.
  17. [w3c-webtransport] W3C WebTransport Working Group. WebTransport (editor's draft): the browser API for client-server QUIC streams and unreliable datagrams. publisher · read in our library knowledge/fetched/cmp_swarm_w3c-webtransport.html · pin h78c38f488a6cf3715da8c0db013f6c40be09761a1826ff5e542fdfe7f3aef04f · accessed 2026-09-02 · published-standardGrounds: Browser WASM worker joins the fabric live -- the standard browser transport for a spoke that is a page.
  18. [sre-cascading] Beyer, Jones, Petoff, Murphy (eds.). Site Reliability Engineering, chapter 22 Addressing Cascading Failures (Ulrich): load shedding, retry budgets and the ways client retries amplify a server overload into a cascade. publisher · read in our library knowledge/fetched/cmp_swarm_sre-cascading.html · pin hf16f9a582bab016af83c9393e56d7571ba91b49e371bd6b55e7a482c041dddb3 · accessed 2026-09-02 · published-courseGrounds: Retry policy with backoff and speculative re-execution -- the retry-budget discipline that keeps a slow hub from becoming a cascading failure.
  19. [otel-spec] OpenTelemetry Authors (CNCF). OpenTelemetry Specification: the traces, metrics and logs signals, the API and SDK contracts, and the OTLP wire protocol. publisher · read in our library knowledge/fetched/cmp_swarm_otel-spec.html · pin h03bc4b814fe070b0f3ce0c531ce7514081e7bd75da6fa8a48e08f11dbb884082 · accessed 2026-09-02 · published-standardGrounds: Telemetry exported in the open standard (OTLP) -- the format an outside collector, audit or award reads.
  20. [dora-fourkeys] DORA (Google Cloud). DORA metrics: the four keys -- deployment frequency, lead time for changes, change failure rate and failed deployment recovery time -- and the performance bands used to grade them. publisher · read in our library knowledge/fetched/cmp_swarm_dora-fourkeys.html · pin h00f7a12f296db54df7006f19badcfe668819c30fc50d386c471fe55531bcdff1 · accessed 2026-09-05 · published-courseGrounds: Delivery performance measured in the industry's own keys (DORA) -- the published definitions and bands nx_dora derives its keys against.
  21. [spiffe-overview] SPIFFE project (CNCF). SPIFFE overview: the workload identity framework -- SPIFFE IDs, SVIDs and the Workload API that hands a workload its identity document. publisher · read in our library knowledge/fetched/cmp_swarm_spiffe-overview.html · pin heaf3585622e98a3f2bd90329ea8b3192a2ea10b76979ae7c3b0fc7e45945b1bd · accessed 2026-09-02 · published-standardGrounds: Capability-scoped (ocap) job dispatch -- the field's identity standard, which names WHO a workload is and not WHAT it may touch.
  22. [chaos-principles] Basiri, Behnam, de Rooij, Hochstein, Kosewski, Reynolds, Rosenthal (Netflix). Principles of Chaos Engineering: a steady-state hypothesis, varying real-world events, experiments in production, automation, and a minimised blast radius. publisher · read in our library knowledge/fetched/cmp_swarm_chaos-principles.html · pin h06bb2df5d5da7442473850d74d911458dba77e0a289b4ebac73c55c4ded1229b · accessed 2026-09-02 · published-courseGrounds: Fault injection as a standing practice (chaos) -- the discipline the row names as its bar.
  23. [jepsen-etcd] Kingsbury, K. (Jepsen LLC). Jepsen: etcd 3.4.3 (2020) -- the published adversarial analysis of the consensus store Kubernetes distributions inherit: partitions, process pauses and clock skew driven against the store while the operation history is checked for the anomalies its consistency claims forbid. publisher · read in our library knowledge/fetched/cmp_swarm_jepsen-etcd.html · pin h3caa046e71eaa23e99bd2a28c5b7b5c4039625c1354a7c3a3dc4871978168bab · accessed 2026-09-02 · published-paperGrounds: Consistency proven by an adversarial Jepsen-class harness -- the K3s column's Yes: the store it inherits has a published Jepsen analysis, which none of the other three columns and none of our lease plane has yet.
  24. [aws-backoff-jitter] Brooker, M. Timeouts, retries, and backoff with jitter. Amazon Builders' Library. Archive snapshot read 2026-09-02 because the canonical URL now redirects to the AWS Builder Center shell page (a 3,101-byte stub, not the article). publisher · read in our library knowledge/fetched/cmp_swarm_aws-backoff-jitter-archive.html · pin hf98d8e20f9cad348f3102524d05110bb2240d4a92385ec7ed31d036c8c3cf1ed · accessed 2026-09-05 · vendor-docGrounds: Retry policy with backoff and speculative re-execution -- capped exponential backoff with full jitter so a hub reconnect never synchronises a herd of spokes into one retry storm.

generated by nx_swcompare_matrix (sovereign NishiLang organ) from knowledge/compare/swarm.matrix · source checks show implementation presence; runtime and user-outcome evidence are reported separately · JavaScript supports page controls