You signed in with another tab or window. Reload to refresh your session.You signed out in another tab or window. Reload to refresh your session.You switched accounts on another tab or window. Reload to refresh your session.Dismiss alert
Copy file name to clipboardExpand all lines: README.md
+6-6Lines changed: 6 additions & 6 deletions
Display the source diff
Display the rich diff
Original file line number
Diff line number
Diff line change
@@ -139,7 +139,7 @@ Mac, Linux, and Windows use one synchronized desktop release version. A release
139
139
is held in full until the signed/notarized Mac DMG and updater ZIP, verified
140
140
Linux host archive, and Windows Setup/Squirrel feed have all passed native
141
141
install and update acceptance from the same source commit. Windows
142
-
Authenticode status is disclosed in every release; v0.0.30 is `NotSigned`.
142
+
Authenticode status is disclosed in every release; v0.0.31 is `NotSigned`.
143
143
144
144
### Connect from a phone or tablet
145
145
@@ -152,10 +152,10 @@ frontend; the password is never retained and the resulting session is stored
152
152
in the iOS Keychain or encrypted with a key held by Android Keystore.
153
153
154
154
- The native iOS and Android gateway source is included in this repository,
155
-
but neither mobile platform has a current v0.0.30 public build. The most
155
+
but neither mobile platform has a current v0.0.31 public build. The most
156
156
recent signed Android APK is the older v0.0.23 gateway, and 1Helm is not
157
157
currently listed in the public iOS App Store. Use the HTTPS browser interface
158
-
for the current v0.0.30 experience.
158
+
for the current v0.0.31 experience.
159
159
- The native clients require HTTPS, do not contain or initialize the 1Helm
160
160
server or a frozen copy of its product frontend, and do not retain host data
161
161
or provider credentials beyond the selected server address and secure
@@ -277,7 +277,7 @@ and an audit trail. A prompt saying “use this service” is not a connector.
277
277
service with health-check rollback.
278
278
- Signed, Apple-notarized, stapled Apple Silicon DMG releases.
279
279
- Browser access from phones and tablets to an already configured HTTPS 1Helm
280
-
host; native mobile gateway source is present but has no v0.0.30 public build.
280
+
host; native mobile gateway source is present but has no v0.0.31 public build.
281
281
282
282
### Platform truth
283
283
@@ -286,7 +286,7 @@ and an audit trail. A prompt saying “use this service” is not a connector.
286
286
|**Apple Silicon macOS 26**| Native desktop product and real isolated Linux computer per resident (Apple `container machine`, `home-mount=none`). |
287
287
|**Linux / CI**| Supported headless systemd host with one durable Podman OCI container per resident, runtime-owned storage, and exact ownership checks; CI may select an explicit test backend. |
288
288
|**Windows 11 x64**| Native desktop product with one installation-scoped WSL 2 OCI runtime and one durable container per resident; Windows-drive mounts and interop are disabled. |
289
-
|**iPhone, iPad, and Android**| Use the current HTTPS browser interface. Native gateway source exists, but v0.0.30 has no public mobile artifact and the iOS app is not publicly listed. |
289
+
|**iPhone, iPad, and Android**| Use the current HTTPS browser interface. Native gateway source exists, but v0.0.31 has no public mobile artifact and the iOS app is not publicly listed. |
290
290
291
291
Not yet shipped: current public mobile builds, a native Linux desktop shell, a
292
292
hosted control plane, rich Photon attachment fidelity, or blind execution of
@@ -313,7 +313,7 @@ A fresh data directory opens first-run setup. The source runtime defaults to
|`HELM_CHANNEL_COMPUTER_BACKEND`|`apple` on macOS, `oci` on Linux and Windows | Host isolation backend; `native` and `mock` are explicit development/test overrides. |
constsecurity=doc("/manual/security-model","Security model","How 1Helm isolates residents, brokers credentials, audits actions, validates skills, and defines the human boundary.",`<p class="intro">Autonomy without architecture is just ambient authority. 1Helm makes routine action cheap inside a narrow world and makes boundary crossings explicit, attributable, and recoverable.</p><h2>Resident isolation</h2><p>Each ordinary channel receives a separate persistent Linux world: an Apple container machine with no Mac home mount, or a durable OCI container. Linux runs OCI natively. Windows hosts containers inside one managed WSL 2 runtime whose Windows-drive mounts and interop are disabled. Exact labels, storage mounts, and owner markers gate lifecycle operations. Other residents and the host home are not exposed.</p><h2>Authoritative files</h2><p>OCI workspace storage belongs to the runtime and is authoritative. Files and Cowork receive narrow direct access to that channel's storage; command and terminal paths do not copy the whole workspace. Apple's backend retains its bounded, symlink-contained mirror.</p><h2>Skipper boundary</h2><p>Skipper owns native host operations, fleet lifecycle, credential brokering, and cross-channel work. A resident calls Skipper directly with the invoking thread; a Captain-authored request is required for host-authorized operations. Skipper returns the result to the resident automatically.</p><h2>Credentials and connections</h2><p>Provider, Gmail, and Photon credentials stay in host-owned storage. Residents receive task-scoped tools and permission records, not raw access tokens or the native Messages database. Photon accepts only the configured Captain phone and keeps that direct Skipper conversation in the Captain's private <code>#main</code>.</p><h2>Skill supply chain</h2><p>The external catalog is discovery metadata, not executable trust. 1Helm shows the open registry's results without applying its own browse-time allowlist. A selected GitHub source is resolved to an immutable commit, bounded to 256 KiB, scanned for instruction override, exfiltration, remote-pipe execution, broad destructive commands, security disabling, private-host access, and prompt extraction, then hashed and wrapped beneath runtime authority.</p><h2>Audit and limits</h2><p>New activity, tool starts/results, and skill installation decisions enter an append-only SHA-256 chain. The chain is tamper-evident, not a remote transparency log: an administrator with database access can still delete or replace the entire database. Historical rows predating the chain are not backfilled.</p><h2>Known dependency debt</h2><p>The pinned Photon SDK currently carries moderate OpenTelemetry advisories upstream. It runs in a supervised loopback-only child process with telemetry disabled. 1Helm tracks the exact pin and will upgrade when the required Photon API remains compatible; this is not represented as a clean dependency audit.</p><h2>Report a vulnerability</h2><p>Use GitHub's private vulnerability reporting for the 1Helm repository. Do not open a public issue containing credentials, tokens, or an unpatched exploit.</p>`);
15
15
16
-
constgettingStarted=doc("/manual/getting-started","Getting started","Install 1Helm, connect providers, create the workspace, and give the first resident a real outcome.",`<p class="intro">The normal setup is three product decisions. 1Helm handles the infrastructure around them.</p><h2>1. Install or connect</h2><p>On Apple Silicon, download the signed, notarized, and stapled DMG. On Windows 11 x64, download the Setup executable; its Authenticode status is disclosed in the release notes and v0.0.30 is <code>NotSigned</code>. Ubuntu/Debian hosts use the digest-verified Linux systemd installer. A new desktop installation can host its own workspace or connect to an existing HTTPS 1Helm host. Native mobile apps connect only to an existing configured host. Starting a new host may request one administrator approval for its isolated Linux runtime.</p><h2>2. Captain</h2><p>Create the first account. This is the Captain: owner, final authority, and administrator. Public registration closes after the Captain exists.</p><h2>3. Providers</h2><p>Connect one or more subscription accounts or API keys. You can add more later, pool accounts, select exact models, and build fallback or round-robin routes. There is no required single “AI brain.”</p><h2>4. Workspace</h2><p>Name the workspace. Terminals default on. 1Helm creates <code>#main</code> with the one Skipper, then you create ordinary channels with plain-language purposes. Every ordinary channel gets a private Linux computer.</p><h2>5. Give an outcome</h2><p>Try: <em>“Audit this launch folder, turn the notes into a decision brief, resolve obvious gaps yourself, and give me the finished PDF with evidence.”</em> The resident should inspect, execute, create the artifact, and call Skipper itself if it crosses the channel boundary.</p>`);
16
+
constgettingStarted=doc("/manual/getting-started","Getting started","Install 1Helm, connect providers, create the workspace, and give the first resident a real outcome.",`<p class="intro">The normal setup is three product decisions. 1Helm handles the infrastructure around them.</p><h2>1. Install or connect</h2><p>On Apple Silicon, download the signed, notarized, and stapled DMG. On Windows 11 x64, download the Setup executable; its Authenticode status is disclosed in the release notes and v0.0.31 is <code>NotSigned</code>. Ubuntu/Debian hosts use the digest-verified Linux systemd installer. A new desktop installation can host its own workspace or connect to an existing HTTPS 1Helm host. Native mobile apps connect only to an existing configured host. Starting a new host may request one administrator approval for its isolated Linux runtime.</p><h2>2. Captain</h2><p>Create the first account. This is the Captain: owner, final authority, and administrator. Public registration closes after the Captain exists.</p><h2>3. Providers</h2><p>Connect one or more subscription accounts or API keys. You can add more later, pool accounts, select exact models, and build fallback or round-robin routes. There is no required single “AI brain.”</p><h2>4. Workspace</h2><p>Name the workspace. Terminals default on. 1Helm creates <code>#main</code> with the one Skipper, then you create ordinary channels with plain-language purposes. Every ordinary channel gets a private Linux computer.</p><h2>5. Give an outcome</h2><p>Try: <em>“Audit this launch folder, turn the notes into a decision brief, resolve obvious gaps yourself, and give me the finished PDF with evidence.”</em> The resident should inspect, execute, create the artifact, and call Skipper itself if it crosses the channel boundary.</p>`);
17
17
constarchitecture=doc("/manual/architecture","Architecture","The 1Helm control plane, resident computers, Skipper, model fabric, memory, obligations, connections, and audit chain.",`<p class="intro">1Helm is a compact local control plane around many persistent employee worlds.</p><pre class="diagram">Captain
0 commit comments