Nishi Family › Compare › Swarm Fabric vs Heterogeneous-Cluster Orchestrators
Nishi Compare · measured, not asserted
Swarm Fabric vs Heterogeneous-Cluster Orchestrators
Nishi vs the field — every Nishi cell is measured against real organ source at emit time; each gap names the watch contract that will close it.
A sovereign heterogeneous supercomputer -- fleet telemetry, load/energy-aware + max-utilization scheduling, durable jobs, cross-workstream fairness, real gen output, all callable over MCP -- vs K3s, HashiCorp Nomad, Ray, and KubeEdge. HONEST: Nishi is young on live multi-node scale; unique on sovereignty, MCP-native control, determinism, ocap dispatch, and zero-install germination.
Overview
The purpose, declared position and evidence coverage of this domain. Source presence and completed acceptance are different measures.
Where we are. Measured 2026-08-19. The fabric is young on live multi-node scale and unique on sovereignty, MCP-native control, determinism, ocap dispatch and zero-install germination; every row is present and gate-proven on one machine plus a LAN snapshot. The matrix carries no symbol gaps, so this plan admits six watch contracts on the rows where the orchestrators lead: live remote actuation, retries, re-placement, telemetry history, quota as data and a browser worker joining live. The ecosystem row (Helm, operators, CSI) stays a deliberate non-goal.
Where we need to go. Make multi-node real -- a job leased here runs there and survives the node dying -- then fairness and history as data, then germinate onto a phone through the browser, keeping every exceed (ocap, determinism, MCP-native) intact.
Latest recorded release
No valid dated release entry is recorded for this domain.
Release entries describe recorded changes; they do not establish that every capability passed evaluation.
18 of 31 capabilities measured|7 of them measured exceeds|13 open|coverage 580/1000|adoption 6 full / 12 partial
Evidence profile — what the gaps on this board actually are
Measured by nx_swcompare_evidence, read back by nx_evprofile_lib. Every figure is a count with its denominator — there is deliberately no score, no grade and no percentage anywhere in this band, because a stored scalar is a field a seat can edit and a counted partition is not.
evidence|grounded 18/18|unsupported 0|gates green 3/3|proven able to fail 2/3|never bitten 1|green at 0/0 0|open gaps 13|of them unnamed 1|of them proof withheld 0|flips ready 0
proven able to fail counts the gates that have a RECORDED RED — nx_gate_bite mutated the gate subject, rebuilt it, watched the gate go red, and that record is inside the shared TTL. never bitten is its complement over the same denominator: those gates ran and were green, and nothing has ever shown them able to detect anything, so their green is a statement about this run and not about the gate. green at 0/0 is a separate and much weaker observation — the gate printed GREEN on a zero denominator, so its own tooth counter says it examined nothing. A gate can be green, non-zero, and still never bitten; that is the common case and it is now visible instead of implied.
partition: grounded + unsupported = 18 vs present 18 · named + unnamed + withheld = 13 vs open 13 · both reconcile
liar-kill conj=GPQN · all four conjuncts held
graded document: BUILDROOT tree, 18039 bytes · gates map: PRIMARY · stamped 1d 9h ago · source ../knowledge/status/evstamp_swarm.verdict
| Gap class | What it is, and the work it names |
|---|---|
| UNNAMED-GAP | A gap row carries a bare _ABSENT_ with no symbol after it, so it names no build contract and no seat can pick it up. Give it an _ABSENT_:<symbol> and it becomes work somebody can do. |
nx_swcompare_evidence swarm itself and are not carried on the stamp, so this page names the classes and the producer names the rows. That split is stated rather than hidden: a count without a worklist is not actionable, and this band is honest about which half of that it is.Production map
Follow the dependencies, declared acceptance criteria and recorded priorities. Inspect source binding before treating a rank as executable work.
Ranking source binding: PLAN_MATRIX_BOUND_ONLY. Recorded priorities require current acceptance evidence and resource checks before execution.
Ranking matches the captured plan and matrix only. Latest execution outcome, research freshness, accepted delivery and investment return are unverified.
Recorded priority estimates
Order from nx_compare_rank (nx_dr_ocm: (deficit + cost-of-delay + option + enables) x sponsor x self-sufficiency x momentum / cost). FINISH rows are rungs whose symbol is present but whose organ is short of full adoption: listed before new work by this heuristic. Priority is not measured delivery cost or execution readiness. Stamp: # asof=1789563137 domain=swarm target_version=0.1 rungs=11 done=0 open=11 finish=0 ranker=nx_dr_ocm
| # | Stage | Rung | Priority | Derivation |
|---|---|---|---|---|
| #1 | 0.1 | Remote actuation (R0) sj_remote_dispatch | 4600 | v=23 m=1 c=5 |
| #2 | 0.1 | Retry policy (R1) sj_retry_policy | 4500 | v=9 m=1 c=2 |
| #3 | 0.1 | Re-placement on node failure (R2) sp_reschedule | 866 | v=13 m=1 c=15 |
| #4 | later | Hub outage leaves the spokes serving (R6) sj_hub_partition_proof | 5333 | v=16 m=1 c=3 |
| #5 | later | Telemetry history (R3) sb_history | 1400 | v=7 m=1 c=5 |
| #6 | later | Telemetry in the open standard (R9) sb_otlp_export | 1200 | v=6 m=1 c=5 |
| #7 | later | Consistency proven by a Jepsen-class harness (R7) sj_partition_fixture | 1000 | v=5 m=1 c=5 |
| #8 | later | Quota plane (R4) sa_quota_plane | 600 | v=6 m=1 c=10 |
| #9 | later | Fault injection as practice (R10) sh_fault_inject | 600 | v=9 m=1 c=15 |
| #10 | later | Node conformance suite at join (R8) se_conformance_suite | 466 | v=7 m=1 c=15 |
| #11 | later | Browser worker joins live (R5) nxe_browser_worker_join | 120 | v=3 m=1 c=25 |
Declared roadmap — contract, acceptance, executor, effort
| Rung | Closes with | Definition of done (pre-declared) | Executor | Est. |
|---|---|---|---|---|
| Remote actuation (R0) | sj_remote_dispatch | A job leased on the NAS executes on a remote node over the mesh transport and completes through the same journaled completion log; proven with the 3090 box and re-proven when it is offline (the lease is stolen back, never lost) | Organ | 2 u |
| Retry policy (R1) after R0 | sj_retry_policy | Bounded retries with backoff and speculative re-execution of a slow attempt; the first completion wins idempotently; policy rows are data | Organ | 1 u |
| Re-placement on node failure (R2) after R0 | sp_reschedule | A node that stops beating has its leased jobs re-placed by the placement scorer; a killed node in the fixture loses no job | Organ | 1.5 u |
| Telemetry history (R3) | sb_history | Per-node beats appended as a series with the liar-killed freshness semantics preserved; a forged or stale beat never enters the series | Organ | 1 u |
| Quota plane (R4) | sa_quota_plane | Per-workstream budgets as plane rows read by the arbiter; a row change alters the grant in the next window without a rebuild | Organ | 1 u |
| Browser worker joins live (R5) after R0 | nxe_browser_worker_join | A phone joins through the browser WASM worker, receives a tile, returns a bit-identical render and is counted in the fleet | Organ | 2.5 u |
| Hub outage leaves the spokes serving (R6) after R0 | sj_hub_partition_proof | A fixture kills the hub mid-job and proves the completion journal loses nothing when it returns; the spool-and-drain lane already carries a spoke's writes, so this rung closes the LEASE half. Done when the gate proves zero lost or doubled completions across a hub restart with a neg-control (a lease written without its journal row) going RED | Organ | 1.5 u |
| Consistency proven by a Jepsen-class harness (R7) after R6 | sj_partition_fixture | Two lease holders driven through a simulated partition, pause and stale-steal window with the completion history checked against a declared consistency model; done when the harness names the model, passes on the shipped lease plane and goes RED on a deliberately broken idempotency key | Organ | 2 u |
| Node conformance suite at join (R8) after R0 | se_conformance_suite | A candidate node runs a versioned suite at join time (bit-exact tile, lease hold, honest beat) whose receipt lands on the beat plane; done when a node that fails the suite is provably never placed and a passing node's receipt names host, toolchain and checksum | Organ | 1.5 u |
| Telemetry in the open standard (R9) after R3 | sb_otlp_export | The beat plane emits its rows as OTLP metrics on request; done when an external collector reads our numbers byte-for-byte equal to the plane and a forged beat is refused before export | Organ | 1 u |
| Fault injection as practice (R10) after R2,R6 | sh_fault_inject | A heal-lane verb injects one declared fault (kill, delay, partition) against a fixture node and asserts steady state returns within a pre-declared bound; done when each fault class has a receipt and the bound is derived from measured recovery, never picked | Organ | 1.5 u |
Milestones
| Milestone | Rungs | Cumulative |
|---|---|---|
| M0 · Multi-node for real | R0,R1,R2 | 4.5 u |
| M1 · Fairness and history | R3,R4 | 6.5 u |
| M2 · Germinate everywhere | R5 | 9 u |
| M3 · Provable under failure | R6,R7,R8,R9,R10 | 16.5 u |
Inspect a rung and its prerequisites
Declared nodes 11. Rank input binding: PLAN_MATRIX_BOUND_ONLY. Dependency order is authored. Implementation, acceptance evidence, authority and resource readiness are unverified. No action is recommended or dispatched here.
Plan SHA-256 580f069eda6f55cf36f384d2216900ff479507a9eacf2f248f6fb6758bdbb731. Target rows 0; role rows 0. Existing risks and release worklog retain their own scope; no node completion is inferred.
Use Enter or Space on a rung to inspect its contract. Prerequisite links locate another rung in this list; open its summary to inspect it. Estimates are authored effort, not forecasts.
R0 — Remote actuation
Prerequisites: None declared; this does not establish execution eligibility.
Contract:
sj_remote_dispatchAcceptance: A job leased on the NAS executes on a remote node over the mesh transport and completes through the same journaled completion log; proven with the 3090 box and re-proven when it is offline (the lease is stolen back, never lost)
Authored effort: 2. Executor kind: Organ. Responsible, accountable and verifier not established. Inspect retained worklog.
R1 — Retry policy
Prerequisites: R0 (acceptance unverified)
Contract:
sj_retry_policyAcceptance: Bounded retries with backoff and speculative re-execution of a slow attempt; the first completion wins idempotently; policy rows are data
Authored effort: 1. Executor kind: Organ. Responsible, accountable and verifier not established. Inspect retained worklog.
R2 — Re-placement on node failure
Prerequisites: R0 (acceptance unverified)
Contract:
sp_rescheduleAcceptance: A node that stops beating has its leased jobs re-placed by the placement scorer; a killed node in the fixture loses no job
Authored effort: 1.5. Executor kind: Organ. Responsible, accountable and verifier not established. Inspect retained worklog.
R3 — Telemetry history
Prerequisites: None declared; this does not establish execution eligibility.
Contract:
sb_historyAcceptance: Per-node beats appended as a series with the liar-killed freshness semantics preserved; a forged or stale beat never enters the series
Authored effort: 1. Executor kind: Organ. Responsible, accountable and verifier not established. Inspect retained worklog.
R4 — Quota plane
Prerequisites: None declared; this does not establish execution eligibility.
Contract:
sa_quota_planeAcceptance: Per-workstream budgets as plane rows read by the arbiter; a row change alters the grant in the next window without a rebuild
Authored effort: 1. Executor kind: Organ. Responsible, accountable and verifier not established. Inspect retained worklog.
R5 — Browser worker joins live
Prerequisites: R0 (acceptance unverified)
Contract:
nxe_browser_worker_joinAcceptance: A phone joins through the browser WASM worker, receives a tile, returns a bit-identical render and is counted in the fleet
Authored effort: 2.5. Executor kind: Organ. Responsible, accountable and verifier not established. Inspect retained worklog.
R6 — Hub outage leaves the spokes serving
Prerequisites: R0 (acceptance unverified)
Contract:
sj_hub_partition_proofAcceptance: A fixture kills the hub mid-job and proves the completion journal loses nothing when it returns; the spool-and-drain lane already carries a spoke's writes, so this rung closes the LEASE half. Done when the gate proves zero lost or doubled completions across a hub restart with a neg-control (a lease written without its journal row) going RED
Authored effort: 1.5. Executor kind: Organ. Responsible, accountable and verifier not established. Inspect retained worklog.
R7 — Consistency proven by a Jepsen-class harness
Prerequisites: R6 (acceptance unverified)
Contract:
sj_partition_fixtureAcceptance: Two lease holders driven through a simulated partition, pause and stale-steal window with the completion history checked against a declared consistency model; done when the harness names the model, passes on the shipped lease plane and goes RED on a deliberately broken idempotency key
Authored effort: 2. Executor kind: Organ. Responsible, accountable and verifier not established. Inspect retained worklog.
R8 — Node conformance suite at join
Prerequisites: R0 (acceptance unverified)
Contract:
se_conformance_suiteAcceptance: A candidate node runs a versioned suite at join time (bit-exact tile, lease hold, honest beat) whose receipt lands on the beat plane; done when a node that fails the suite is provably never placed and a passing node's receipt names host, toolchain and checksum
Authored effort: 1.5. Executor kind: Organ. Responsible, accountable and verifier not established. Inspect retained worklog.
R9 — Telemetry in the open standard
Prerequisites: R3 (acceptance unverified)
Contract:
sb_otlp_exportAcceptance: The beat plane emits its rows as OTLP metrics on request; done when an external collector reads our numbers byte-for-byte equal to the plane and a forged beat is refused before export
Authored effort: 1. Executor kind: Organ. Responsible, accountable and verifier not established. Inspect retained worklog.
R10 — Fault injection as practice
Prerequisites: R2 (acceptance unverified), R6 (acceptance unverified)
Contract:
sh_fault_injectAcceptance: A heal-lane verb injects one declared fault (kill, delay, partition) against a fixture node and asserts steady state returns within a pre-declared bound; done when each fault class has a receipt and the bound is derived from measured recovery, never picked
Authored effort: 1.5. Executor kind: Organ. Responsible, accountable and verifier not established. Inspect retained worklog.
Learning and practice paths
No structured learning path is declared for this plan. Existing research, roadmap and worklog remain available above.
Capability comparisons
Compare the field, search individual capabilities and open their source and adoption evidence. Documented presence does not establish comparative quality.
Position map — centrality and distinctiveness
The four-quadrant map the field uses for brand strategy (Dawar and Bagga, HBR June 2015), re-derived from this matrix on every publish. Centrality is the share of the category's feature mass a player covers, each feature weighted by how many hold it; distinctiveness is the average lead over each rival on the rows the player holds; breadth is the depth-weighted share of the whole matrix (the bubble); depth is how deeply the rows held are held; momentum is the day-over-day move off the spine (green rising, red falling, grey until day two); the dashed path runs first day → previous day → today. Dividers are the category means. Axes are fitted to the field of play, so read the tick numerals, not the frame. Rival marks are documented presence, so a rival's position reads the record, never its quality. The picture grades its own readability below; the table beside it is the same data for a screen reader or a second method.
knowledge/compare/swarm.cdmap (cut|x|y, cube|x|y|z); absent = the HBR defaultsbubble area = breadth · ring = momentum (green rising, red falling, grey until day two) · dashed = category means · axes fitted to the field of play: centrality 500–1000, distinctiveness 50–450 of 0–1000 permil (the full range put every player in one corner)
readability of the 2D cut, self-graded by the layout ruler: label overlaps 0 · labels over marks 0 · off-canvas 0 · unresolved labels 0 · mark overlaps 0 (a fact of the data: two players that close are that close) · data spread 640 permil of the plot · quadrant words unseated 0
text contrast, measured with wcag2-ratio (floors from contrast.conf), light theme: labels 16.24 (floor 4.50) · notes 16.24 (floor 4.50) · quadrant words 5.89 (floor 4.50) · tick numerals 5.89 (floor 4.50) · axis titles 5.59 (floor 4.50) · dark theme: labels 13.78 (floor 4.50) · quadrant words 5.55 (floor 4.50) · axis titles 5.97 (floor 4.50) · dark classes under their floor 0 (one figure serves both themes: a dark shortfall is a token to fix, never a class to hide) · classes refused under their floor 0 (a refused class is not drawn; the scale classes are measured, never hidden) · export: SVG PNG (receipt, rendered by the estate's own rasteriser from this page)
readability of the 3D cube, self-graded by the layout ruler: label overlaps 0 · labels over marks 0 · off-canvas 0 · unresolved labels 0 · mark overlaps 1 (a fact of the data: two players that close are that close) · data spread 403 permil of the plot
10 panels over 5 registered axes, every pair once (the lower axis on x, the higher on y) · each panel fitted to its own field of play, first and last tick numerals shown · no labels in a small cut, the legend names the colours; the grade below reports the mark terms only (MM summed over the panels, spread averaged)
readability of the small multiples, self-graded by the layout ruler: label overlaps 0 · labels over marks 0 · off-canvas 0 · unresolved labels 0 · mark overlaps 2 (a fact of the data: two players that close are that close) · data spread 549 permil of the plot
| Player | Quadrant | centrality | distinctiveness | breadth | depth | momentum | Rows held | Days on spine | First seen |
|---|---|---|---|---|---|---|---|---|---|
| Nishi | Unconventional | 607 | 384 | 462 | 796 | 0 since 2026-09-15 | 18 | 2 | 2026-09-15 |
| K3s | Aspirational | 925 | 260 | 623 | 805 | 0 since 2026-09-15 | 24 | 2 | 2026-09-15 |
| Nomad | Mainstream | 887 | 155 | 526 | 742 | 0 since 2026-09-15 | 22 | 2 | 2026-09-15 |
| Ray | Peripheral | 785 | 127 | 430 | 701 | 0 since 2026-09-15 | 19 | 2 | 2026-09-15 |
| KubeEdge | Mainstream | 915 | 201 | 569 | 736 | 0 since 2026-09-15 | 24 | 2 | 2026-09-15 |
| Day | Matrix rows reviewed | Players recorded |
|---|---|---|
| 2026-09-15 | 31 | 5 |
| 2026-09-16 | 31 | 5 |
players 5|matrix rows 31|feature mass 107|centrality mean 823|distinctiveness mean 225|axes 5|spine days 2 (shown 2)|rows written today 0|readability defects 2D 0 cube 0|spine knowledge/status/cdmap/swarm.spine
comparewatch- plane row flips with it. A dark tag means the organ file EXISTS but does not declare the contracted symbol: something shipped there under another name, and until the contract is repointed to the real entry point (the plan rung and this row) or the function is renamed, that capability is invisible to this board — a build lost to darkness, named so it is not. The flip is necessary, not sufficient: it proves the symbol exists, never that the capability is good. The bar is the rung's pre-declared done-rule, proven by its gate — a symbol shipped without the behaviour behind it is a defect, and the flip is exactly what makes that defect visible instead of quiet. Competitor marks record documented capability presence — presence, not depth or scale. Adoption is measured too: every measured row carries where its organ stands on the estate's ladder (source → built → promoted → registered → invoked; libraries by importer reach minus validation importers; gates by the execution surfaces that run them). A row is fully adopted only at the top of its ladder; anything short is tagged partial with the exact remedy, so a build nobody promoted can no longer read as shipped. Census stamps: importers asof 1789497476, gate census asof 1789498715 (unix seconds; -1 = census absent).Capability matrix — measured against source
◉ leads / measured exceed● present◐ partial○ absent · click any capability for its evidence
| Capability | Nishi | K3s | Nomad | Ray | KubeEdge |
|---|---|---|---|---|---|
Fleet node telemetryMeasured:SWARMBEATGATE exists in runtime/nx_swarm_beat.nx, verified at emit. All expose node metrics; K3s (metrics-server) is Best [k3s-docs]. Nishi has a liar-killed freshness store (stale/forged->never FRESH) but no historical TSDB Adoption: REGISTERED-DARK — PARTIAL: callable, authorised, completed MCP invocation not established by supplied journal window; lifetime history unknown (direct execution may be recorded elsewhere; this scan does not establish lifetime use); no execution surface runs it either (clock, cron, daemon, roster, actlog and surfaced forks checked).Pros Nishi has it, measured on diskCons behind K3s (leads); not adopted yet: callable, authorised, completed MCP invocation not established by supplied journal window; lifetime history unknown (direct execution may be recorded elsewhere; this scan does not establish lifetime use); no execution surface runs it either (clock, cron, daemon, roster, actlog and surfaced forks checked) | ● | ◉ | ● | ● | ● |
Load + energy-aware placementMeasured:SWARMPLACEGATE exists in runtime/nx_swarm_place.nx, verified at emit. K8s/Nomad bin-pack by cpu/mem [nomad-scheduling]; Ray by resources [ray-scheduling]; Nishi scores load AND thermal/battery (never cook a phone) with data-driven weights -- comparable, energy-axis slightly ahead Adoption: REGISTERED-DARK — PARTIAL: callable, authorised, completed MCP invocation not established by supplied journal window; lifetime history unknown (direct execution may be recorded elsewhere; this scan does not establish lifetime use); no execution surface runs it either (clock, cron, daemon, roster, actlog and surfaced forks checked).Pros Nishi has it, measured on diskCons not adopted yet: callable, authorised, completed MCP invocation not established by supplied journal window; lifetime history unknown (direct execution may be recorded elsewhere; this scan does not establish lifetime use); no execution surface runs it either (clock, cron, daemon, roster, actlog and surfaced forks checked) | ● | ● | ● | ● | ● |
Heterogeneous max-utilization schedulerMeasured:SWARMPACKGATE exists in runtime/nx_swarm_pack.nx, verified at emit. Ray is Best at packing mixed CPU/GPU tasks; Nishi packs a resource-vector (cpu-milli/ram/gpu/vram) so ONE node runs GPU-gen+CPU-tile+RAM-index at once, measured 7 vs naive 5 -- parity in kind, young in scale rival marks uncited — the Yes, Best or Part codes on this row are an observation read with no reference mark behind them Adoption: REGISTERED-DARK — PARTIAL: callable, authorised, completed MCP invocation not established by supplied journal window; lifetime history unknown (direct execution may be recorded elsewhere; this scan does not establish lifetime use); no execution surface runs it either (clock, cron, daemon, roster, actlog and surfaced forks checked).Pros Nishi has it, measured on diskCons behind Ray (leads); not adopted yet: callable, authorised, completed MCP invocation not established by supplied journal window; lifetime history unknown (direct execution may be recorded elsewhere; this scan does not establish lifetime use); no execution surface runs it either (clock, cron, daemon, roster, actlog and surfaced forks checked) | ● | ● | ● | ◉ | ● |
Cross-workstream resource fairnessMeasured:SWARMARBITRATEGATE exists in runtime/nx_swarm_arbitrate.nx, verified at emit. K8s ResourceQuota+PriorityClass+preemption is Best/mature [k8s-priority] [ghodsi2011] [verma2015]; Nishi has max-share caps (no-monopoly) + priority preemption + partial grants (no-starvation), gate-proven -- same model, less mature Adoption: SOURCE-ONLY — PARTIAL: source exists, never compiled: /api/build it.Pros Nishi has it, measured on diskCons behind K3s (leads); not adopted yet: source exists, never compiled: /api/build it | ● | ◉ | ● | ● | ● |
Capability-scoped (ocap) job dispatchMeasured exceed:WORKERDISPATCHGATE in runtime/nx_worker_dispatch.nx, verified at emit. K8s RBAC/Nomad ACLs are coarse cluster roles; NONE grant a JOB an attenuated capability to exactly the worker+storage it needs, deny-by-default -- Nishi's ocap-per-job is unique [miller2006]. FIELD CHECK 2026-09-02: SPIFFE is the industry's workload-identity standard -- an SVID names WHO a workload is, never WHAT it may touch -- so ocap dispatch stays the exceed and a SPIFFE-shaped identity document is the interop this row does not yet speak [spiffe-overview]; and the gauge's own weakest link stands beside it: the worker API is unauthenticated on the wire today (nx_swarm_maturity Security L0), so the authority model is ahead of the transport that carries it -- see the worker-authentication row below Adoption: RUN-BY:fork:nx_mesh_run — fully adopted (top of its ladder).Pros Nishi leads, a measured exceed; ahead of K3s, Nomad, Ray, KubeEdge; fully adopted on the estate ladderCons none on the measured axes (rival marks are documented presence, not depth) | ◉ | ○ | ○ | ○ | ○ |
MCP-native control planeMeasured exceed:ma_emit_nodes in runtime/_hdl_build/nx_mgmt_api.nx, verified at emit. Every organ callable over MCP tools/call (proven live); none of the orchestrators are MCP-native -- an agent drives the whole fabric with a scoped cap Adoption: LIVE-DAEMON — fully adopted (top of its ladder).Pros Nishi leads, a measured exceed; ahead of K3s, Nomad, Ray, KubeEdge; fully adopted on the estate ladderCons none on the measured axes (rival marks are documented presence, not depth) | ◉ | ○ | ○ | ○ | ○ |
Deterministic int-exact computeMeasured exceed:SWARMTILEGATE in runtime/nx_swarm_tile.nx, verified at emit. Nishi's tiled render is 100% integer -> bit-identical across ANY device (proven byte-exact re-render); float compute on the others varies by hardware -- reproducibility is a sovereign axis Adoption: REGISTERED-DARK — PARTIAL: callable, authorised, completed MCP invocation not established by supplied journal window; lifetime history unknown (direct execution may be recorded elsewhere; this scan does not establish lifetime use); no execution surface runs it either (clock, cron, daemon, roster, actlog and surfaced forks checked).Pros Nishi leads, a measured exceed; ahead of K3s, Nomad, Ray, KubeEdgeCons not adopted yet: callable, authorised, completed MCP invocation not established by supplied journal window; lifetime history unknown (direct execution may be recorded elsewhere; this scan does not establish lifetime use); no execution surface runs it either (clock, cron, daemon, roster, actlog and surfaced forks checked) | ◉ | ○ | ○ | ○ | ○ |
Durable jobs + speculative harvestMeasured:SWARMJOBGATE exists in runtime/nx_swarm_job.nx, verified at emit. Nomad/K8s Jobs + Ray retries are Best/mature; Nishi has a journaled completion log + O_EXCL leases with stale-steal + idempotent complete (crash-replay proven) -- correct, young rival marks uncited — the Yes, Best or Part codes on this row are an observation read with no reference mark behind them Adoption: REGISTERED-DARK — PARTIAL: callable, authorised, completed MCP invocation not established by supplied journal window; lifetime history unknown (direct execution may be recorded elsewhere; this scan does not establish lifetime use); no execution surface runs it either (clock, cron, daemon, roster, actlog and surfaced forks checked).Pros Nishi has it, measured on diskCons behind K3s (leads), Nomad (leads); not adopted yet: callable, authorised, completed MCP invocation not established by supplied journal window; lifetime history unknown (direct execution may be recorded elsewhere; this scan does not establish lifetime use); no execution surface runs it either (clock, cron, daemon, roster, actlog and surfaced forks checked) | ● | ◉ | ◉ | ● | ● |
Autoscale to zeroMeasured:MESHAUTOSCALEGATE exists in runtime/nx_mesh_autoscale.nx, verified at emit. KubeEdge/Knative-class scale-to-zero is Best; Nishi has a proven policy + host-agent, true 0MB/0proc idle -- parity in kind rival marks uncited — the Yes, Best or Part codes on this row are an observation read with no reference mark behind them Adoption: REGISTERED-UNAUTHORISED — PARTIAL: registered, no cap ever minted; no execution surface runs it either (clock, cron, daemon, roster, actlog and surfaced forks checked).Pros Nishi has it, measured on diskCons behind KubeEdge (leads); not adopted yet: registered, no cap ever minted; no execution surface runs it either (clock, cron, daemon, roster, actlog and surfaced forks checked) | ● | ● | ● | ● | ◉ |
Native container governance daemonlessMeasured exceed:nx_pe_emit_container in runtime/nx_pe_container_win.nx, verified at emit. K3s needs containerd, Nomad a driver, Ray a runtime, KubeEdge a kubelet; Nishi governs a worker natively (Job Object) with no daemon/VM. SYMBOL REPOINTED 2026-09-01: the row cited CreateJobObjectW, which is a WINDOWS API NAME and not a sovereign function, so the one-symbol ruler correctly refused it and the OLD substring ruler had been grounding the row against a COMMENT. THE SAME ROW APPEARS IN THREE BOARDS (containers, swarm, workermesh) AND WAS THE ENTIRE RED FOR ALL THREE -- one cause, three domains, which is why collapsing to causes before sizing a campaign matters. The defining sovereign function in that organ is nx_pe_emit_container. A ROW THAT CITES A FOREIGN OS API HAS NO SOVEREIGN DEFINITION TO GROUND AGAINST -- name the wrapper, never the syscall it wraps rival marks uncited — the Yes, Best or Part codes on this row are an observation read with no reference mark behind them Adoption: SOURCE-ONLY — PARTIAL: source exists, never compiled: /api/build it.Pros Nishi leads, a measured exceed; ahead of K3s, Nomad, Ray, KubeEdgeCons not adopted yet: source exists, never compiled: /api/build it | ◉ | ◐ | ◐ | ◐ | ◐ |
Compile-on-target ISA-exact distributionMeasured exceed:cmd_buildrun in runtime/_hdl_build/nx_hostctl.nx, verified at emit. All ship generic container images (-march=native is manual/Buildx-matrix); Nishi ships SOURCE and compiles per-node so the binary is ISA-exact by construction Adoption: LIVE-DAEMON — fully adopted (top of its ladder).Pros Nishi leads, a measured exceed; ahead of K3s, Nomad, Ray, KubeEdge; fully adopted on the estate ladderCons none on the measured axes (rival marks are documented presence, not depth) | ◉ | ○ | ○ | ○ | ○ |
Zero-install germination (bare-metal + browser)Measured exceed:nxe_load_exec in runtime/nx_nxe_lib.nx, verified at emit. KubeEdge does edge nodes but needs a kubelet install; Nishi germinates from POST via SHA-verified NXE (never-brick) and can join phones via a browser WASM worker -- no agent install rival marks uncited — the Yes, Best or Part codes on this row are an observation read with no reference mark behind them Adoption: LIB-WIRED importers=4 nonval=4 — fully adopted (top of its ladder).Pros Nishi leads, a measured exceed; ahead of K3s, Nomad, Ray, KubeEdge; fully adopted on the estate ladderCons none on the measured axes (rival marks are documented presence, not depth) | ◉ | ○ | ○ | ○ | ◐ |
P2P artifact distributionMeasured:BitTorrent SEEDER exists in runtime/nx_torrent_seed.nx, verified at emit. Registries + OCI distribution are standard; Nishi content-addresses artifacts + announces to a live DHT [bep5-dht] -- LAN distribution without a hub registry Adoption: LIVE-DAEMON — fully adopted (top of its ladder).Pros Nishi has it, measured on disk; ahead of Ray; fully adopted on the estate ladderCons none on the measured axes (rival marks are documented presence, not depth) | ● | ● | ● | ○ | ● |
Content-addressed integrity registryMeasured:CONTAINERREGISTRYGATE exists in runtime/nx_container_registry.nx, verified at emit. OCI registries are the reference; Nishi's SHA-256 CAS refuses a tampered/bit-rot pull at get-time by construction -- parity rival marks uncited — the Yes, Best or Part codes on this row are an observation read with no reference mark behind them Adoption: BUILT-UNPROMOTED — PARTIAL: compiled, never promoted to the serving root: /api/promote it.Pros Nishi has it, measured on diskCons not adopted yet: compiled, never promoted to the serving root: /api/promote it | ● | ● | ● | ● | ● |
Fleet supervision + crash respawnMeasured:cmd_supervise exists in runtime/_hdl_build/nx_hostctl.nx, verified at emit. K8s/Nomad/KubeEdge self-healing is Best/mature; Nishi supervises via connect-probe + guard respawn -- works, less featureful. FIELD CHECK 2026-09-02: the supervision-tree archetype is OTP's -- restart strategies and a restart intensity bound (maximum restarts within a period) past which a supervisor stops and escalates instead of crash-looping [otp-supervision]; our guard has no such bound, which is the hc_restart_intensity contract on the supervisor board, and the estate measured the cost on 2026-08-16 when an unbounded revive loop amplified a lock-blocked daemon into an eight-minute blackout Adoption: LIVE-DAEMON — fully adopted (top of its ladder).Pros Nishi has it, measured on disk; fully adopted on the estate ladderCons behind K3s (leads), Nomad (leads), KubeEdge (leads) | ● | ◉ | ◉ | ● | ◉ |
Offline store-and-forward (intermittent)Measured:sp_streq exists in runtime/nx_state_spool.nx, verified at emit. KubeEdge is Best at disconnected edge autonomy [kubeedge-docs]; Nishi spools locally offline + drains on reconnect, head-of-line-safe -- parity with KubeEdge's niche. FIELD CHECK 2026-09-02: NATS leaf nodes are the field's documented hub-and-spoke messaging shape -- a local NATS system bridged to a remote hub over one leaf connection with subject bridging and per-link credentials -- so the spool lane is graded against a named topology rather than a generic queue [nats-leafnodes] Adoption: BUILT-UNPROMOTED — PARTIAL: compiled, never promoted to the serving root: /api/promote it.Pros Nishi has it, measured on disk; ahead of RayCons behind KubeEdge (leads); not adopted yet: compiled, never promoted to the serving root: /api/promote it | ● | ● | ● | ○ | ◉ |
Multi-node live distribution at scaleMeasured:SWARMJOBGATE exists in runtime/nx_swarm_job.nx, verified at emit. THE honest gap: K3s/Nomad/Ray/KubeEdge run real multi-thousand-node clusters in production; Nishi is PROVEN single-machine + LAN-snapshot, live remote actuation (mesh_gen) not yet wired -- young rival marks uncited — the Yes, Best or Part codes on this row are an observation read with no reference mark behind them Adoption: REGISTERED-DARK — PARTIAL: callable, authorised, completed MCP invocation not established by supplied journal window; lifetime history unknown (direct execution may be recorded elsewhere; this scan does not establish lifetime use); no execution surface runs it either (clock, cron, daemon, roster, actlog and surfaced forks checked).Pros Nishi has it, measured on diskCons behind K3s (leads), Nomad (leads), Ray (leads), KubeEdge (leads); not adopted yet: callable, authorised, completed MCP invocation not established by supplied journal window; lifetime history unknown (direct execution may be recorded elsewhere; this scan does not establish lifetime use); no execution surface runs it either (clock, cron, daemon, roster, actlog and surfaced forks checked) | ● | ◉ | ◉ | ◉ | ◉ |
Ecosystem / operators / helm / CSI storageOpen — no implementing organ is measured for this axis yet. Mature ecosystems (Helm, operators, CSI, CNI, service mesh) are the orchestrators' moat; Nishi has none of that surface -- a deliberate non-goal for a sovereign single-operator fabric, but an honest absence rival marks uncited — the Yes, Best or Part codes on this row are an observation read with no reference mark behind themPros none measured yetCons behind K3s (leads), Nomad (leads), Ray (leads), KubeEdge (leads); no implementing organ measured | ○ | ◉ | ◉ | ◉ | ◉ |
Worker API authenticated on the wireDARK —runtime/nx_worker_dispatch.nx EXISTS but does not declare wd_worker_auth: something shipped at this path under another name, and this mark would read open forever. Repoint the contract to the real entry point (the plan rung AND this row) or rename the function; the flip follows on the next beat, and the comparewatch- plane row reads DARK until then. NEW WATCH 2026-09-02 (hub-and-spoke failure class 0 -- the one the estate's own gauge names its weakest link: nx_swarm_maturity Security L0, worker API 0.0.0.0 unauthenticated today, so ocap decides WHAT a job may do while any LAN peer may speak to the worker at all). K3s, Nomad and KubeEdge run mutual TLS between the control plane and each node agent with a per-node identity (Best); Ray's inter-node TLS is optional configuration (Part). SPIFFE is the identity standard the field converges on -- an SVID names the workload and the Workload API hands it out [spiffe-overview]. Contract: every worker request carries a capability bound to a per-node identity the hub issued, an unauthenticated request is REFUSED before dispatch, and the gate proves both the refusal and the positive control (a valid cap is served); the gauge's Security dimension leaves L0 the day this lands.Pros none measured yetCons behind K3s (leads), Nomad (leads), Ray, KubeEdge (leads); open contract, nothing on disk yet | ○ | ◉ | ◉ | ◐ | ◉ |
Hub outage leaves the spokes serving (static stability)DARK —runtime/nx_swarm_job.nx EXISTS but does not declare sj_hub_partition_proof: something shipped at this path under another name, and this mark would read open forever. Repoint the contract to the real entry point (the plan rung AND this row) or rename the function; the flip follows on the next beat, and the comparewatch- plane row reads DARK until then. NEW WATCH 2026-09-02 (failure class 1 of 5: the hub as a single point of failure). Tailscale is the field's cleanest statement of the remedy -- a coordination server that only exchanges keys and metadata while the WireGuard data plane runs node-to-node, so a coordination-server outage cannot stop traffic that already flows (Best) [tailscale-how]; KubeEdge's edge autonomy keeps pods running through a cloud disconnect (Best) [kubeedge-docs]; K3s and Nomad are graded Part from their architecture reads -- a kubelet or a Nomad client keeps its allocations running while the server is unreachable but takes no new work -- and that grade is an architecture read, not a mirrored sentence; Ray's head node is a hard dependency (No) [ray-scheduling]. Ours: the spool-and-drain lane already carries a spoke's writes through a hub outage (row above), but a LEASED JOB is hub-only state, so the contract is a fixture that kills the hub mid-job and proves the completion journal loses nothing when it returns.Pros none measured yetCons behind K3s, Nomad, KubeEdge (leads); open contract, nothing on disk yet | ○ | ◐ | ◐ | ○ | ◉ |
Consistency proven by an adversarial Jepsen-class harnessDARK —runtime/nx_swarm_job.nx EXISTS but does not declare sj_partition_fixture: something shipped at this path under another name, and this mark would read open forever. Repoint the contract to the real entry point (the plan rung AND this row) or rename the function; the flip follows on the next beat, and the comparewatch- plane row reads DARK until then. NEW WATCH 2026-09-02 (failure class 2: split brain and double completion under a partition). Our lease plane claims exactly-once completion by O_EXCL leases with stale-steal and an idempotent complete, crash-replay proven on ONE node -- Jepsen's consistency reference defines the models such a claim must name, which histories the journal admits and which phenomena it forbids, and the field's bar is an analysis that partitions, pauses and clock-skews the system while checking the history [jepsen-consistency]. K3s inherits etcd, whose Jepsen analysis is published (Yes) [jepsen-etcd]; Nomad's Raft store has no published Jepsen analysis (Part); Ray and KubeEdge none (No). Contract: a fixture that runs two lease holders through a simulated partition and stale-steal window and checks the completion history against a declared model, with a neg-control (a deliberately broken idempotency key) going RED.Pros none measured yetCons behind K3s, Nomad; open contract, nothing on disk yet | ○ | ● | ◐ | ○ | ○ |
A fabric conformance suite any node must pass to joinDARK —runtime/nx_swarm_endpoint.nx EXISTS but does not declare se_conformance_suite: something shipped at this path under another name, and this mark would read open forever. Repoint the contract to the real entry point (the plan rung AND this row) or rename the function; the flip follows on the next beat, and the comparewatch- plane row reads DARK until then. NEW WATCH 2026-09-02 (failure class 3: config drift between the hub and its spokes, the silent failure a heterogeneous fleet manufactures by construction). The field's industry test is the CNCF Kubernetes conformance program -- a published, versioned suite a distribution must pass to carry the mark, with results submitted as reproducible logs (Best) [cncf-conformance]; KubeEdge conforms at its cloud edge (Part); Nomad and Ray publish no conformance program (No). Ours: gates prove organs, not nodes -- a laptop, the 3090 box or a phone joining the fleet is never asked to prove it can take a tile bit-exactly, hold a lease and beat honestly before it is placed. Contract: a suite a candidate node runs at join time whose receipt (host, toolchain, checksum, result) lands on the beat plane and whose failure keeps the node out of placement.Pros none measured yetCons behind K3s (leads), KubeEdge; open contract, nothing on disk yet | ○ | ◉ | ○ | ○ | ◐ |
Telemetry exported in the open standard (OTLP)DARK —runtime/nx_swarm_beat.nx EXISTS but does not declare sb_otlp_export: something shipped at this path under another name, and this mark would read open forever. Repoint the contract to the real entry point (the plan rung AND this row) or rename the function; the flip follows on the next beat, and the comparewatch- plane row reads DARK until then. NEW WATCH 2026-09-02 (failure class 4: observability only its own author can read). Our beats are liar-killed and sovereign, and no outside instrument can consume them -- an audit or an award reads OpenTelemetry, whose specification defines the metrics, traces and logs signals and the OTLP wire every collector accepts [otel-spec]. Ray exports Prometheus and OpenTelemetry metrics natively (Best); K3s, Nomad and KubeEdge expose Prometheus endpoints an OTel collector scrapes (Yes). Contract: the beat plane emits its rows as OTLP metrics on request, so an external collector can check our numbers without trusting our page -- sovereignty is the SOURCE of the data, not a refusal to speak the open format.Pros none measured yetCons behind K3s, Nomad, Ray (leads), KubeEdge; open contract, nothing on disk yet | ○ | ● | ● | ◉ | ● |
Fault injection as a standing practice (chaos)DARK —runtime/nx_swarm_heal.nx EXISTS but does not declare sh_fault_inject: something shipped at this path under another name, and this mark would read open forever. Repoint the contract to the real entry point (the plan rung AND this row) or rename the function; the flip follows on the next beat, and the comparewatch- plane row reads DARK until then. NEW WATCH 2026-09-02 (failure class 5: a healer that has only ever seen healthy nodes). nx_swarm_heal heals what the beat reports and the gate fleet bites organs with mutants, but no organ ever KILLS a healthy spoke, delays its beats or partitions it on purpose to see whether placement, leases and healing recover -- the discipline the Principles of Chaos Engineering define as experiments on a steady-state hypothesis with a minimised blast radius [chaos-principles]. K3s and Ray carry chaos tooling in their ecosystems (Part); Nomad and KubeEdge ship none (No). Contract: a heal-lane verb that injects one declared fault (kill, delay, partition) against a fixture node and asserts the fleet's steady state returns within a pre-declared bound, the fault class named in the receipt.Pros none measured yetCons behind K3s, Ray; open contract, nothing on disk yet | ○ | ◐ | ○ | ◐ | ○ |
Delivery performance measured in the industry's own keys (DORA)Measured exceed:d_band_deploy in runtime/_hdl_build/nx_dora.nx, verified at emit. LANDED, cited 2026-09-02: the hub-and-spoke DEVELOPMENT loop (seat, build, promote, deploy) grades itself in DORA's four keys derived from the estate's own event planes -- deploy frequency and lead time measured from the ws_sync and organ_ship journals, change-fail and recovery time declared as proxies rather than faked, banded ELITE, HIGH, MEDIUM, LOW against the published thresholds [dora-fourkeys]. None of the four orchestrators measure the delivery loop that feeds them (they are its subject, not its instrument), so the exceed is claimed narrowly: the fabric's own dev loop reports the metric the industry's DORA report uses, and it refuses to count a guard refusal as a production failure. Adoption axis stated: nx_dora is REGISTERED-DARK on the MCP surface today (nx_catalog 2026-09-02), so the capability is present and the beat that publishes it is the open work. Adoption: REGISTERED-DARK — PARTIAL: callable, authorised, completed MCP invocation not established by supplied journal window; lifetime history unknown (direct execution may be recorded elsewhere; this scan does not establish lifetime use); no execution surface runs it either (clock, cron, daemon, roster, actlog and surfaced forks checked); only referenced by nx_shipjoin_gate -- a mention, not a run.Pros Nishi leads, a measured exceed; ahead of K3s, Nomad, Ray, KubeEdgeCons not adopted yet: callable, authorised, completed MCP invocation not established by supplied journal window; lifetime history unknown (direct execution may be recorded elsewhere; this scan does not establish lifetime use); no execution surface runs it either (clock, cron, daemon, roster, actlog and surfaced forks checked); only referenced by nx_shipjoin_gate -- a mention, not a run | ◉ | ○ | ○ | ○ | ○ |
Live multi-node remote actuationDARK —runtime/nx_swarm_job.nx EXISTS but does not declare sj_remote_dispatch: something shipped at this path under another name, and this mark would read open forever. Repoint the contract to the real entry point (the plan rung AND this row) or rename the function; the flip follows on the next beat, and the comparewatch- plane row reads DARK until then. The honest gap named on the distribution row: a job leased on the NAS executes on a remote node (the 3090 box, a phone) and completes through the same journal rival marks uncited — the Yes, Best or Part codes on this row are an observation read with no reference mark behind themPros none measured yetCons behind K3s (leads), Nomad (leads), Ray (leads), KubeEdge (leads); open contract, nothing on disk yet | ○ | ◉ | ◉ | ◉ | ◉ |
Retry policy with backoff and speculative re-executionDARK —runtime/nx_swarm_job.nx EXISTS but does not declare sj_retry_policy: something shipped at this path under another name, and this mark would read open forever. Repoint the contract to the real entry point (the plan rung AND this row) or rename the function; the flip follows on the next beat, and the comparewatch- plane row reads DARK until then. Nomad and Ray retries are mature; ours is stale-steal only. RE-GRADED 2026-09-02 against the September-2026 field: the bar is capped exponential backoff with full jitter so a hub reconnect never synchronises a herd of spokes into one retry storm [aws-backoff-jitter], durable execution that retries an activity idempotently against a journaled history instead of re-running it blind [temporal-workflows], and a per-client retry budget so retries cannot turn one slow hub into a cascading failure [sre-cascading] -- the estate measured the herd case on its own promote lease (a bare Retry-After scalar synchronised every caller), which is why LV6 on the loadgov board answers overload as its own error classPros none measured yetCons behind K3s (leads), Nomad (leads), Ray, KubeEdge; open contract, nothing on disk yet | ○ | ◉ | ◉ | ● | ● |
Re-placement on node failureDARK —runtime/nx_swarm_place.nx EXISTS but does not declare sp_reschedule: something shipped at this path under another name, and this mark would read open forever. Repoint the contract to the real entry point (the plan rung AND this row) or rename the function; the flip follows on the next beat, and the comparewatch- plane row reads DARK until then. Self-healing placement: a node that stops beating has its jobs re-placed, never stranded rival marks uncited — the Yes, Best or Part codes on this row are an observation read with no reference mark behind themPros none measured yetCons behind K3s (leads), Nomad (leads), Ray, KubeEdge (leads); open contract, nothing on disk yet | ○ | ◉ | ◉ | ● | ◉ |
Node telemetry historyDARK —runtime/nx_swarm_beat.nx EXISTS but does not declare sb_history: something shipped at this path under another name, and this mark would read open forever. Repoint the contract to the real entry point (the plan rung AND this row) or rename the function; the flip follows on the next beat, and the comparewatch- plane row reads DARK until then. The freshness store is liar-killed but has no history; a series per node over time rival marks uncited — the Yes, Best or Part codes on this row are an observation read with no reference mark behind themPros none measured yetCons behind K3s (leads), Nomad, Ray, KubeEdge; open contract, nothing on disk yet | ○ | ◉ | ● | ● | ● |
Per-workstream quota as a planeDARK —runtime/nx_swarm_arbitrate.nx EXISTS but does not declare sa_quota_plane: something shipped at this path under another name, and this mark would read open forever. Repoint the contract to the real entry point (the plan rung AND this row) or rename the function; the flip follows on the next beat, and the comparewatch- plane row reads DARK until then. Max-share caps and preemption exist; budgets declared as plane rows per workstream, never constants rival marks uncited — the Yes, Best or Part codes on this row are an observation read with no reference mark behind themPros none measured yetCons behind K3s (leads), Nomad, Ray, KubeEdge; open contract, nothing on disk yet | ○ | ◉ | ● | ● | ● |
Browser WASM worker joins the fabric liveDARK —runtime/nx_nxe_lib.nx EXISTS but does not declare nxe_browser_worker_join: something shipped at this path under another name, and this mark would read open forever. Repoint the contract to the real entry point (the plan rung AND this row) or rename the function; the flip follows on the next beat, and the comparewatch- plane row reads DARK until then. Germination exists; a phone joining through a browser worker and taking a tile is the proof. FIELD CHECK 2026-09-02: the transports a spoke that is a PAGE would ride are standardised -- W3C WebTransport gives a browser client-server QUIC streams and datagrams [w3c-webtransport], and libp2p's specs cover the browser transports (WebRTC, WebTransport), NAT traversal and peer identity a third-party browser needs to reach a hub behind a home router [libp2p-specs]; the estate already holds a QUIC substrate (fourteen nx_quic_* organs, see the edge board), so the browser spoke is a WIRING rung on both ends, not a protocol buildPros none measured yetCons behind KubeEdge; open contract, nothing on disk yet | ○ | ○ | ○ | ○ | ◐ |
Delivery and evidence
Inspect risks, technical debt, rendered observations, experiments and references. Read scope and limitations alongside every result.
Release history and work log
| When | Rung | Kind | Entry |
|---|---|---|---|
| 2026-09-11 | - | queue | AI-collaboration protocol DESIGN ONLY (lane swarm-design, 2026-09-11): knowledge/status/swarm_ai_handoff_design_20260911.md 65021 B sha256 5ad97fc2726a25e7c43a45315650a3f257be8e608edf18de9da462fe384e0053. Zone ledger GREEN AMBER RED per subject and action as data, handoff packet and cross-family review queue, regression fence composing the nx_fence guard that /api/promote already forks, durable checkpoint and resume per run lane step with a writer nonce, collab_pass in the emitter. Proposed M4 rungs AC1-AC9 with sotabar, barscan, sotatarget and rungrole rows are AMBER and must land as ONE block only after two distinct-family reviews (first reviewer Codex on or after 2026-09-16), because a sotatarget without every rungrole refuses the whole board |
Person · product · place — not yet measured for this domain
knowledge/compare/swarm.ppp (rows surface|nishi or c1..c4|label|url|connect naming OUR live surface and each rival's front door), run nx_ppp_probe domain swarm, and this section fills itself on the next beat: the same ruler on both sides — privacy and CX (third-party hosts, tracker classes, cookies, security headers), design and longevity (design hygiene, computed WCAG contrast, render-blocking resources, unsized media, script weight, theme and motion queries), findability (landmarks, skip link, on-site search, breadcrumb, headings, internal links).The field — discovered, not chosen
Rows written by nx_field_discover from swarm.seeds: the industry's own lists (Wikipedia wikitext, GitHub topics, awesome lists) read mechanically, every candidate counted across seeds. The matrix columns above are a SEAT'S pick; this band is the population they were picked from, and the stats line measures one against the other. A rival here is a lead, never a verdict — it earns a column when its capabilities are read and pinned.
field|seeds=4|scanned=4|fetched=4|reused=0|failed=0|named=4|candidates=4|mentions=4|capped=0
rival|K3s|1|1|col0-k3s|https://docs.k3s.io/|named
rival|Nomad|1|1|col1-nomad|https://developer.hashicorp.com/nomad/docs/concepts/scheduling/how-scheduling-works|named
rival|Ray|1|1|col2-ray|https://docs.ray.io/en/latest/ray-core/scheduling/index.html|named
rival|KubeEdge|1|1|col3-kubeedge|https://kubeedge.io/docs/|named
| Rank | Rival | Seeds | Mentions | First seed | Kind | Link |
|---|---|---|---|---|---|---|
| 1 | K3s | 1 | 1 | col0-k3s | named | https://docs.k3s.io/ |
| 2 | Nomad | 1 | 1 | col1-nomad | named | https://developer.hashicorp.com/nomad/docs/concepts/scheduling/how-scheduling-works |
| 3 | Ray | 1 | 1 | col2-ray | named | https://docs.ray.io/en/latest/ray-core/scheduling/index.html |
| 4 | KubeEdge | 1 | 1 | col3-kubeedge | named | https://kubeedge.io/docs/ |
field candidates 4|shown 4 of 4|matrix columns in the field 4 of 4|discovered rivals with no column 0|malformed rows 0 (counted, never rendered)|read-capped 0
Gaps from the record — what the estate does that no board carries
The record census (nx_goalmap record) reads the invoked-tool population and every plan queue row and files each organ or directive that NO matrix, plan or gates row names. A row here is a callout the boards missed: adjudicate it onto a board or declare it infrastructure. Census state BLIND (age 81618 s), sources read 4 of 7 declared — a BLIND census is a FLOOR: unread sources can only add rows.
| kind | name | board | source | evidence |
|---|---|---|---|---|
| directive | nx_fence | swarm | plan-queue | rung=- |
rows shown 1|this board's directives 1|estate-wide un-boarded organs 492 (listed in full on /compare/ecosystem)|census rows 611|malformed 0 (counted, never rendered)
References
- [k3s-docs] K3s project (SUSE / CNCF). K3s -- Lightweight Kubernetes documentation (docs.k3s.io): single-binary distribution with embedded containerd, metrics-server, local storage and Helm controller. publisher · read in our library
knowledge/fetched/cmp_swarm_k3s.html· pinhb226a6c8ced451de2ab0bc90a1cf10493320bebe70a75efa4f0f7706c8eec09d· accessed 2026-08-18 · vendor-docGrounds: The K3s column: Fleet node telemetry (metrics-server is Best), Fleet supervision + crash respawn (K8s self-healing), Native container governance daemonless (K3s needs containerd, Part) and Ecosystem / operators / helm / CSI storage (the orchestrators' moat). - [nomad-scheduling] HashiCorp. How Nomad job scheduling works (developer.hashicorp.com/nomad/docs/concepts/scheduling): evaluations, allocations, feasibility checking and ranking with bin packing, and the service/batch/system schedulers. publisher · read in our library
knowledge/fetched/cmp_swarm_nomad-scheduling.html· pinh0883ef9786ba712aa47c5c12b48440739461a1f8a8838ea84f015dde27976296· accessed 2026-08-18 · vendor-docGrounds: The Nomad column: Load + energy-aware placement (Nomad bin-packs by cpu/mem), Durable jobs + speculative harvest (Nomad Jobs are Best/mature) and Cross-workstream resource fairness -- the evaluation-and-allocation model our nx_swarm_place / nx_swarm_pack scorers are graded against. - [ray-scheduling] Anyscale / Ray project. Ray Core -- Scheduling (docs.ray.io/en/latest/ray-core/scheduling): resource-based task and actor scheduling, placement groups, locality-aware and spread strategies across a heterogeneous cluster. publisher · read in our library
knowledge/fetched/cmp_swarm_ray-scheduling.html· pinh6ea883313eae4e28596f4555624e2069d2306325a76db7ca734fa7a64ef8500e· accessed 2026-08-18 · vendor-docGrounds: The Ray column: Heterogeneous max-utilization scheduler (Ray is Best at packing mixed CPU/GPU tasks -- the bar nx_swarm_pack's resource-vector packing, measured 7 vs naive 5, is compared with), Load + energy-aware placement (Ray by resources) and Durable jobs (Ray retries). - [kubeedge-docs] KubeEdge project (CNCF). KubeEdge documentation (kubeedge.io/docs): cloud-edge architecture with CloudCore and EdgeCore, edge autonomy under disconnection, and device management. publisher · read in our library
knowledge/fetched/cmp_swarm_kubeedge.html· pinh90317819fcc198f18dff4455312c97bda1ec980b29bdbb05dd5f2fdb255124b3· accessed 2026-08-18 · vendor-docGrounds: The KubeEdge column: Offline store-and-forward (KubeEdge is Best at disconnected edge autonomy -- parity claimed for the spool-and-drain lane), Zero-install germination (KubeEdge does edge nodes but needs a kubelet install, Part) and Autoscale to zero (KubeEdge/Knative-class is Best). - [verma2015] Verma, Pedrosa, Korupolu, Oppenheimer, Tune, Wilkes. Large-scale cluster management at Google with Borg. EuroSys 2015. publisher · read in our library
knowledge/fetched/cmp_swarm_verma2015.pdf· pinh2fdacd3b69f8af91477412fc91d1d858a43e764929a4edb646bd517ededdad94· accessed 2026-08-18 · published-paperGrounds: The published ancestor of the K3s column's scheduling model: admission control, priority and quota, preemption, bin-packing and machine sharing with performance isolation -- the mature form of the Cross-workstream resource fairness (max-share caps + priority preemption + partial grants) and Heterogeneous max-utilization scheduler rows, and why Multi-node live distribution at scale is THE honest gap. - [ghodsi2011] Ghodsi, Zaharia, Hindman, Konwinski, Shenker, Stoica. Dominant Resource Fairness: Fair Allocation of Multiple Resource Types. USENIX NSDI 2011. publisher · read in our library
knowledge/fetched/cmp_swarm_ghodsi2011.html· pinh97dfb22b355d36a71ff1f6a25b6695f51a928809a3796efec561304a8c7c1110· accessed 2026-08-18 · published-paperGrounds: The Cross-workstream resource fairness row: fair allocation over a multi-resource vector (cpu-milli / ram / gpu / vram) with the no-monopoly and no-starvation properties nx_swarm_arbitrate gate-proves is the DRF problem statement -- the published fairness bar behind the K8s ResourceQuota + PriorityClass Best cell. - [bep5-dht] Loewenstern, Norberg. BEP 5: DHT Protocol (bittorrent.org/beps/bep_0005): the Kademlia-based distributed hash table for trackerless torrents -- ping, find_node, get_peers, announce_peer. publisher · read in our library
knowledge/fetched/cmp_swarm_bep5.html· pinh103f7501c56d8e17a87066af30419bd5199a904ae84f3962fecfc37b7bfc45ca· accessed 2026-08-18 · published-standardGrounds: The P2P artifact distribution row: nx_torrent_seed content-addresses artifacts and announces to a live DHT -- LAN distribution without a hub registry -- and the DHT it announces to is this protocol; registries plus OCI distribution are the standard the row contrasts with. - [k8s-priority] The Kubernetes Authors. Pod Priority and Preemption (kubernetes.io/docs/concepts/scheduling-eviction/pod-priority-preemption): PriorityClass, preemption of lower-priority pods, and interaction with ResourceQuota. publisher · read in our library
knowledge/fetched/cmp_swarm_k8s-priority.html· pinh87bd7a066d9b46c35fefacc28ad756036d6466fdb8be31a9eef9649024dc1c78· accessed 2026-08-18 · vendor-docGrounds: The Cross-workstream resource fairness row's K3s Best cell (K8s ResourceQuota + PriorityClass + preemption is Best/mature) and the Capability-scoped (ocap) job dispatch note that K8s RBAC/Nomad ACLs are coarse cluster roles -- the mature model our max-share caps + priority preemption + partial grants are the young twin of. - [miller2006] Miller, M. S. Robust Composition: Towards a Unified Approach to Access Control and Concurrency Control. PhD dissertation, Johns Hopkins University, 2006 (JScholarship record; author copy at erights.org). publisher · read in our library
knowledge/fetched/cmp_swarm_miller2006-jhu.html· pinhaf29e138b8ca91abf97435a07a9c055452c1432a128cab0e47c223ed4f048a0f· accessed 2026-08-18 · published-paperGrounds: The Capability-scoped (ocap) job dispatch row (EXCEED, unique): a JOB granted an attenuated capability to exactly the worker + storage it needs, deny-by-default, is the object-capability discipline this dissertation formalises -- none of K3s, Nomad, Ray or KubeEdge grant per-job attenuated capabilities. - [otp-supervision] Ericsson AB. Erlang/OTP System Documentation, OTP Design Principles: Supervisor Behaviour -- supervision trees, restart strategies (one_for_one, one_for_all, rest_for_one) and the restart intensity bound (maximum restarts within a period) past which a supervisor stops its children and itself instead of crash-looping. publisher · read in our library
knowledge/fetched/cmp_swarm_otp-supervision.html· pinh3d990d5bf67a0e4fbb5e2af86b7e74f6b1ae5db8a27d8f49a3a8648e980be8df· accessed 2026-09-02 · vendor-docGrounds: Fleet supervision + crash respawn -- the supervision-tree archetype our hostctl guard is the young twin of, and the restart-intensity bound it lacks. - [nats-leafnodes] Synadia and the NATS project. NATS Server documentation: Leaf Nodes -- a local NATS system bridged to a remote hub over one leaf connection, the documented hub-and-spoke topology for edge and disconnected sites, with subject bridging and credentials per link. publisher · read in our library
knowledge/fetched/cmp_swarm_nats-leafnodes.html· pinh351bbd9e2fcb14cf045f01516d9d4ccea378e5342e057c566c95f377593b63e2· accessed 2026-09-05 · vendor-docGrounds: Offline store-and-forward (intermittent) -- the field's messaging shape for a spoke behind an intermittent hub link. - [tailscale-how] Pennarun, A. (Tailscale Inc). How Tailscale works: a coordination server exchanges public keys and metadata while every packet runs peer-to-peer over WireGuard -- the control plane and the data plane are separated by design so that traffic already flowing does not depend on the coordination server. publisher · read in our library
knowledge/fetched/cmp_swarm_tailscale-how.html· pinh8cf2c779da9c24bffecd0747cf836f8d79faecf2ceeff97cb90f1d4cf30b076e· accessed 2026-09-02 · vendor-docGrounds: Hub outage leaves the spokes serving (static stability) -- the cleanest published statement of a hub that cannot take the data plane down with it. - [jepsen-consistency] Kingsbury, K. (Jepsen LLC). Consistency -- the reference guide defining consistency models as sets of admissible histories, the phenomena each forbids, and the dependency graphs the models are built from. publisher · read in our library
knowledge/fetched/cmp_swarm_jepsen-consistency.html· pinh3973e30505147b7e79d7e6f8d1bbd36c51ed0568a59aff949635e101c6234c96· accessed 2026-09-02 · published-courseGrounds: Consistency proven by an adversarial Jepsen-class harness -- the vocabulary a lease-plane exactly-once claim must be stated in before it can be tested. - [cncf-conformance] Cloud Native Computing Foundation. Kubernetes Conformance (cncf/k8s-conformance): the versioned conformance test suite and the submission process by which a distribution earns the Certified Kubernetes mark, with results filed as reproducible logs. publisher · read in our library
knowledge/fetched/cmp_swarm_cncf-conformance.html· pinhdde74a9e4c2704cd918bb7f851372dda96bac3a6d09542da4c44ece4e9e3ab22· accessed 2026-09-02 · published-standardGrounds: A fabric conformance suite any node must pass to join -- the industry test the row names as its bar. - [temporal-workflows] Temporal Technologies. Temporal documentation: Workflows -- durable execution over an event history, deterministic replay, and the retry and timeout policies attached to activities. publisher · read in our library
knowledge/fetched/cmp_swarm_temporal-workflows.html· pinh49a387252e1c9fe2184d0a878ea828ce254560ffd363d72b0c566043a56bc3e7· accessed 2026-09-02 · vendor-docGrounds: Retry policy with backoff and speculative re-execution -- the durable-execution bar for a retry that replays against a journal instead of re-running blind. - [libp2p-specs] Protocol Labs and the libp2p project. libp2p specifications: transports including WebRTC and WebTransport for browsers, NAT traversal (hole punching, relays), peer identity and discovery. publisher · read in our library
knowledge/fetched/cmp_swarm_libp2p-specs.html· pinhe55222395a1475c9f4dc1543f87718bdedc519c74d3b58159db69a0bf06636f9· accessed 2026-09-02 · published-standardGrounds: Browser WASM worker joins the fabric live -- the browser-spoke transport and NAT-traversal specs a phone joining from a third-party browser would ride. - [w3c-webtransport] W3C WebTransport Working Group. WebTransport (editor's draft): the browser API for client-server QUIC streams and unreliable datagrams. publisher · read in our library
knowledge/fetched/cmp_swarm_w3c-webtransport.html· pinh78c38f488a6cf3715da8c0db013f6c40be09761a1826ff5e542fdfe7f3aef04f· accessed 2026-09-02 · published-standardGrounds: Browser WASM worker joins the fabric live -- the standard browser transport for a spoke that is a page. - [sre-cascading] Beyer, Jones, Petoff, Murphy (eds.). Site Reliability Engineering, chapter 22 Addressing Cascading Failures (Ulrich): load shedding, retry budgets and the ways client retries amplify a server overload into a cascade. publisher · read in our library
knowledge/fetched/cmp_swarm_sre-cascading.html· pinhf16f9a582bab016af83c9393e56d7571ba91b49e371bd6b55e7a482c041dddb3· accessed 2026-09-02 · published-courseGrounds: Retry policy with backoff and speculative re-execution -- the retry-budget discipline that keeps a slow hub from becoming a cascading failure. - [otel-spec] OpenTelemetry Authors (CNCF). OpenTelemetry Specification: the traces, metrics and logs signals, the API and SDK contracts, and the OTLP wire protocol. publisher · read in our library
knowledge/fetched/cmp_swarm_otel-spec.html· pinh03bc4b814fe070b0f3ce0c531ce7514081e7bd75da6fa8a48e08f11dbb884082· accessed 2026-09-02 · published-standardGrounds: Telemetry exported in the open standard (OTLP) -- the format an outside collector, audit or award reads. - [dora-fourkeys] DORA (Google Cloud). DORA metrics: the four keys -- deployment frequency, lead time for changes, change failure rate and failed deployment recovery time -- and the performance bands used to grade them. publisher · read in our library
knowledge/fetched/cmp_swarm_dora-fourkeys.html· pinh00f7a12f296db54df7006f19badcfe668819c30fc50d386c471fe55531bcdff1· accessed 2026-09-05 · published-courseGrounds: Delivery performance measured in the industry's own keys (DORA) -- the published definitions and bands nx_dora derives its keys against. - [spiffe-overview] SPIFFE project (CNCF). SPIFFE overview: the workload identity framework -- SPIFFE IDs, SVIDs and the Workload API that hands a workload its identity document. publisher · read in our library
knowledge/fetched/cmp_swarm_spiffe-overview.html· pinheaf3585622e98a3f2bd90329ea8b3192a2ea10b76979ae7c3b0fc7e45945b1bd· accessed 2026-09-02 · published-standardGrounds: Capability-scoped (ocap) job dispatch -- the field's identity standard, which names WHO a workload is and not WHAT it may touch. - [chaos-principles] Basiri, Behnam, de Rooij, Hochstein, Kosewski, Reynolds, Rosenthal (Netflix). Principles of Chaos Engineering: a steady-state hypothesis, varying real-world events, experiments in production, automation, and a minimised blast radius. publisher · read in our library
knowledge/fetched/cmp_swarm_chaos-principles.html· pinh06bb2df5d5da7442473850d74d911458dba77e0a289b4ebac73c55c4ded1229b· accessed 2026-09-02 · published-courseGrounds: Fault injection as a standing practice (chaos) -- the discipline the row names as its bar. - [jepsen-etcd] Kingsbury, K. (Jepsen LLC). Jepsen: etcd 3.4.3 (2020) -- the published adversarial analysis of the consensus store Kubernetes distributions inherit: partitions, process pauses and clock skew driven against the store while the operation history is checked for the anomalies its consistency claims forbid. publisher · read in our library
knowledge/fetched/cmp_swarm_jepsen-etcd.html· pinh3caa046e71eaa23e99bd2a28c5b7b5c4039625c1354a7c3a3dc4871978168bab· accessed 2026-09-02 · published-paperGrounds: Consistency proven by an adversarial Jepsen-class harness -- the K3s column's Yes: the store it inherits has a published Jepsen analysis, which none of the other three columns and none of our lease plane has yet. - [aws-backoff-jitter] Brooker, M. Timeouts, retries, and backoff with jitter. Amazon Builders' Library. Archive snapshot read 2026-09-02 because the canonical URL now redirects to the AWS Builder Center shell page (a 3,101-byte stub, not the article). publisher · read in our library
knowledge/fetched/cmp_swarm_aws-backoff-jitter-archive.html· pinhf98d8e20f9cad348f3102524d05110bb2240d4a92385ec7ed31d036c8c3cf1ed· accessed 2026-09-05 · vendor-docGrounds: Retry policy with backoff and speculative re-execution -- capped exponential backoff with full jitter so a hub reconnect never synchronises a herd of spokes into one retry storm.
generated by nx_swcompare_matrix (sovereign NishiLang organ) from knowledge/compare/swarm.matrix · source checks show implementation presence; runtime and user-outcome evidence are reported separately · JavaScript supports page controls