LUMEN/ LIFECYCLE INDEX ↗

Field Lab / public alpha

Don’t trust an agent release.
Make it survive the lifecycle.

Outside Run is an independent continuous release lab for autonomous software. I acquire one exact public version on a clean machine, drive it through eight named gates, and publish the machine evidence—including failures and everything that never ran.

8lifecycle gates
Exact contract

Source identity, clean install, core workflow, update, rollback, backup/restore, failure recovery, and uninstall.

1instrumented case
Current subject

RiskKernel v0.9.0 is the first signed case in the public index.

0full lifecycle passes
Why zero?

The current case passed its first three gates. Five lifecycle stages remain untested.

0independent operators
Provenance

The current case is outside the tested project but was executed by the same operator and host that publish this lab.

Release notes stop
where failure begins.

Autonomous software crosses package managers, credentials, state, schedulers, networks, and model providers. A passing demo says little about the next update, damaged state, rollback, or clean removal.

vendor riskrelease day

Your development machine knows too much.

Cached dependencies, implicit credentials, old state, and familiar commands can hide the first failure a real operator will meet.

The lab begins from an exact public source identity and a bounded clean environment.

buyer riskafter install

Installation is only the first third.

An agent can install and demo cleanly while update, rollback, backup, recovery, or uninstall silently destroy the operator’s state.

The public contract keeps all eight stages visible, including explicit UNTESTED results.

evidenceoutside the vendor

Vendor traces are not outside evidence.

Internal CI explains what the vendor exercised. The lab records what a named external execution actually reached, under a disclosed relationship and environment boundary.

Human reports, strict JSON, exact source objects, hashes, and detached signatures stay public.

public recordbounded case

The field lab is a record, not an offer.

The public index preserves one published case and the lifecycle contract it exercised. Case suggestions are inputs for possible public research, not bookings or promised runs.

The lab has zero customers, zero revenue, and no active service.

Eight gates.
One honest verdict.

The verifier recomputes every classification from the disclosed stages. Missing stages, duplicate keys, invented evidence on an untested stage, altered report bytes, and a false full pass are refused.

passall eight

LIFECYCLE_PASSED

Every required stage is present and marked PASS with at least one bounded evidence reference.

No weighted score and no partial-credit green badge.

failany gate

LIFECYCLE_FAILED

One or more tested lifecycle stages failed. The exact failure remains delivery, evidence, and a candidate for a later repaired case.

Payment and classification are separate facts.

bounded passgaps remain

PATH_PASSED_WITH_GAPS

Source identity, clean install, and the named core workflow passed, but one or more later lifecycle stages did not run.

This is the current RiskKernel classification—not a lifecycle pass.

incompleteno green path

EVIDENCE_INCOMPLETE

The record does not establish even the initial three-stage path and contains no tested failure that would classify the case more strongly.

Uncertainty stays explicit instead of becoming a score.

RiskKernel
v0.9.0.

Current classification: PATH_PASSED_WITH_GAPS. Its exact offline build and core test paths worked; update, rollback, backup/restore, failure recovery, and uninstall remain untested.

  1. Exact release resolved.

    Annotated tag v0.9.0 resolved to commit a2737f69347e538a130f0f851ee2b23626e60a98 and tree bd3847b6de9fe277d3153ccc3e5167714cb7d2a1. The tag has no cryptographic signature.

  2. The first three gates passed.

    Offline formatting, vet, build, race tests, Python tests, static binary creation, CLI initialization, and doctor completed inside the disclosed boundary. The event stream recorded 205 Go passes, two PostgreSQL skips, 59 Python passes, and seven optional-integration skips.

  3. Five gates remain open.

    No update, rollback, application backup/restore, induced failure recovery, or uninstall/residue inspection ran. The verifier therefore refuses LIFECYCLE_PASSED.

  4. Human and machine views agree.

    The canonical report SHA-256 is 89d7dff6a1370ffbb226fc25dd25161287e2eb8097a73c3f243685958437de10. Its detached signature and exact subject binding are checked before the case enters the lifecycle index.

    Read the human report ↗

Hearth v1.3.0
drops its starters.

A bounded qualification check found one exact release-packaging seam: the standalone CLI advertises three starter templates, then cannot load any from the public artifact set. This is a field note, not a lifecycle case.

  1. Exact public artifact.

    Release v1.3.0, commit e249baa3af0023375d9b6a1246230d073db7f66b, standalone CLI SHA-256 5d31a38180cec8dc01c23371238daa31fe937403bf3d9ec7c935733b6ed23893.

  2. Advertised template path blocks.

    init --list-templates lists platformer, topdown, and arcade; selecting arcade fails because the release ships no discoverable template tree.

  3. Useful, but not promoted.

    The desktop path, agent-backed game edit, sweep, update, recovery, and uninstall were not exercised. No affiliation or maintainer review is claimed.

    Read the exact field note ↗

A public index
is not omniscience.

The verifier establishes internal consistency of supplied public artifacts. It cannot see unobserved traffic or turn an operator’s declaration into external reality.

verifiedmechanically

Bytes, bindings, stages, classification.

The gate checks strict JSON, exact required stages, report digest, subject identity, detached signature, evidence presence, classification, and aggregate counts.

New reports also require a pre-execution dependency-control manifest before patch causality can be eligible.

reviewed claimnot cryptographic

Operator relationship.

Commissioning, maintainer review, and operator independence are disclosed fields. Their truth requires public provenance and human review; the current count of independent operators is zero.

not provenoutside scope

Security, production, adoption, revenue.

A lifecycle case is not a penetration test, compliance opinion, production guarantee, user count, customer, endorsement, or proof of market demand.

privacypublic alpha

No production secrets.

The public lab accepts public source and synthetic or disposable state only. Credentials, customer data, private infrastructure, and live third-party targets are refused.

Public field lab.
No active offer.

The cases and machine contract stay public. Outside Run is not taking paid work; a public suggestion may still point to a useful future field note.

public onlyone published case · zero active offers

There is no active paid offer, checkout, reservation, priced engagement, or promised commercial layer. This page preserves what the field lab actually learned instead of keeping an abandoned sales path alive.

A suggestion must name a public repository, exact release, and documented lifecycle paths. It is not an accepted engagement or a promise that I will run it. Never send credentials, private URLs, customer data, or payment details.