B8Grid Cloud

Local private beta control plane. generalAvailability: false.

B8Grid Local Private Beta

Control Cloud dashboard running on B8Grid Framework

Agent-native cloud control for humans and agents. Cloud Control remains the authority for projects, source, workspaces, builds, previews, secrets, database metadata, and audit evidence. The dashboard reads and mutates through @b8grid/framework plus @b8grid/data.

Statusready
Organizations0
Projects0
Source projects0
Workspaces0
Builds0
Secrets0
Audit events0
Framework routeready

Dashboard route, forms, queries, mutations, and region patches are served by B8Grid Framework.

Reactive data layerready

Dashboard events and invalidation contracts use B8Grid Data; durable control state remains Cloud Control.

Database boundarymetadata-only

Postgres details are metadata only; credentials stay in Cloud Trust secret grants.

Network posturelocal-only

Local beta keeps public exposure disabled and does not claim hosted promotion.

Database Control

Database resource registry, private network placement, migration status, backup/restore controls, and grants without raw credentials.

Database resource registryb8grid-cloud-control-database-control-v6no-raw-credentials-in-ui
Operator waveb8grid-cloud-control-operator-wave-v7shellCommandsInDashboard: false
Enginepostgres
Servicepostgres
Private hostpostgres:5432
Network zonedata_net
Publicly reachablefalse
Credential storagecloud-trust-secret-grants
Dashboard exposuremetadata-only
Source of truthcloud-control-service-store
Dashboard storeb8grid-data-ui-reactive-layer
resourceIdengineserviceNameprivateHostnamenetworkZonemigrationStatusbackupStatusrestoreStatuspublicReachable
postgres-local-private-betapostgrespostgrespostgres:5432data_netlocal-migration-gate-readylocal-restore-drill-readychecksum-manifest-and-restore-time-contractfalse
idlabelstatecommanddetail
migration-statusMigration statusreadycorepack pnpm --silent local:ops:migrations:status --jsonReads migration status from the local Cloud Control migration gate before deployment.
backup-restoreBackup/restorereadycorepack pnpm --silent local:ops:backup --jsonRuns backup/restore drill evidence without exposing database passwords.
connection-grantsConnection grantsreadycorepack pnpm --silent local:security-spine:v4 --jsonIssues database access through Cloud Trust grants instead of raw connection strings.
grantIdprincipalresourceIdactionsstatusrawCredentialExposed
grant:database:cloud-controlservice:cloud-controlpostgres-local-private-betaconnect,migrate,backupactive-contractfalse
grant:database:source-graph-cloudservice:source-graph-cloudpostgres-local-private-betaconnect,queryactive-contractfalse
idlabelstateexecutionModecommanddetail
database.migrationStatusMigration checkreadylocal-proof-commandcorepack pnpm --silent local:ops:migrations:status --jsonRecords that the local migration gate has been requested from the dashboard.
database.backupDrillBackup drillreadylocal-proof-commandcorepack pnpm --silent local:ops:backup --jsonRecords that the backup/restore drill should be run from the local operator workbench.
database.createGrantCreate DB grantservice-backedservice-backedcloud.dashboard.databaseCreateGrantCreates a Cloud Trust grant for Postgres access without returning a raw connection string.
database.revokeGrantRevoke DB grantservice-backedservice-backedcloud.dashboard.databaseRevokeGrantRevokes an existing Cloud Trust grant and records a grant.revoke audit event.

Auth Control

Auth is modeled for open beta with a removable private-beta admission gate, verified email, sessions, MFA, passkeys, reset flow status, and audit evidence.

Signup admissionb8grid-cloud-control-auth-control-v6allowlist -> open-signup
Default modeallowlist
Open modeopen-signup
Allowlist sourceB8GRID_AUTH_ALLOWLIST_EMAILS
Removable gatetrue
Verified emailtrue
External userstrue
Auth V9b8grid-local-auth-private-beta-v9
Token materialfalse
hostedGafalse
Provider credential preflightb8grid-auth-provider-credential-preflight-v1readyForHostedProviderDrill: false
Live provider credentialsfalse
Token materialfalse
Hosted provider drillb8grid-auth-hosted-provider-drill-manifest-v1readyForHostedProviderDrill: false
Public drill manifesthosted-auth-provider-drill-manifest-v1
OAuth callback routeb8grid-auth-oauth-callback-route-contract-v1
Callback path/.b8grid/auth/oauth/:provider/callback
Live drill contractb8grid-hosted-provider-live-drill-v16
Provider secretsfalse
External identity providersfalse
Hosted WebAuthn attestationfalse
Hosted TOTP KMS lifecyclefalse
Token materialfalse
hostedGafalse
idstateboundary
email-passwordreadyB8Grid-owned hash/session contract
passkeyadapter-readyB8Grid verifier/storage contract; hosted WebAuthn attestation still gated
email-code-magic-linkcontract-readyB8Grid email relay contract with local fake SMTP and optional SES/SMTP adapters
oidc-socialadapter-contractOIDC adapter contract for Google, GitHub, and Microsoft
idstatedetail
private-beta-v9readyRuns the V9 private-beta auth gate for allowlist/open admission, auth flows, local MFA, passkey adapter, abuse evidence, and token redaction.
session-device-viewreadyShows issued, refreshed, revoked, and project-bound Cloud Trust sessions without returning tokens.
mfa-passkey-statuslocal-readyTracks TOTP, backup-code, and passkey adapter readiness while keeping hosted WebAuthn claims explicit.
password-reset-flow-statuscontract-readyRecords password reset flow status as a local auth contract; email delivery remains adapter-driven.
suspicious-login-rate-limit-evidencereadyKeeps suspicious-login and rate-limit evidence queryable for private beta security review.
idkindstaterequiredRefsmissingRefsunsafeDirectValueRefs
office365-smtpemailmissing-managed-refB8GRID_EMAIL_RELAY_SMTP_URL_REF, B8GRID_EMAIL_RELAY_SMTP_FROM_REFB8GRID_EMAIL_RELAY_SMTP_URL_REF, B8GRID_EMAIL_RELAY_SMTP_FROM_REFnone
sesemailmissing-managed-refB8GRID_EMAIL_RELAY_SES_REGION_REF, B8GRID_EMAIL_RELAY_SES_IDENTITY_REFB8GRID_EMAIL_RELAY_SES_REGION_REF, B8GRID_EMAIL_RELAY_SES_IDENTITY_REFnone
github-oauthoauthmissing-managed-refB8GRID_AUTH_GITHUB_CLIENT_ID_REF, B8GRID_AUTH_GITHUB_CLIENT_SECRET_REFB8GRID_AUTH_GITHUB_CLIENT_ID_REF, B8GRID_AUTH_GITHUB_CLIENT_SECRET_REFnone
google-oidcoauthmissing-managed-refB8GRID_AUTH_GOOGLE_CLIENT_ID_REF, B8GRID_AUTH_GOOGLE_CLIENT_SECRET_REF, B8GRID_AUTH_GOOGLE_JWKS_REFB8GRID_AUTH_GOOGLE_CLIENT_ID_REF, B8GRID_AUTH_GOOGLE_CLIENT_SECRET_REF, B8GRID_AUTH_GOOGLE_JWKS_REFnone
microsoft-oidcoauthmissing-managed-refB8GRID_AUTH_MICROSOFT_CLIENT_ID_REF, B8GRID_AUTH_MICROSOFT_CLIENT_SECRET_REF, B8GRID_AUTH_MICROSOFT_JWKS_REFB8GRID_AUTH_MICROSOFT_CLIENT_ID_REF, B8GRID_AUTH_MICROSOFT_CLIENT_SECRET_REF, B8GRID_AUTH_MICROSOFT_JWKS_REFnone
providerpathurlrequiredRefsstate
github/.b8grid/auth/oauth/github/callbackhttps://beta.b8grid.xyz/.b8grid/auth/oauth/github/callbackB8GRID_AUTH_GITHUB_CLIENT_ID_REF, B8GRID_AUTH_GITHUB_CLIENT_SECRET_REFmanaged-provider-callback-required
google/.b8grid/auth/oauth/google/callbackhttps://beta.b8grid.xyz/.b8grid/auth/oauth/google/callbackB8GRID_AUTH_GOOGLE_CLIENT_ID_REF, B8GRID_AUTH_GOOGLE_CLIENT_SECRET_REF, B8GRID_AUTH_GOOGLE_JWKS_REFmanaged-provider-callback-required
microsoft/.b8grid/auth/oauth/microsoft/callbackhttps://beta.b8grid.xyz/.b8grid/auth/oauth/microsoft/callbackB8GRID_AUTH_MICROSOFT_CLIENT_ID_REF, B8GRID_AUTH_MICROSOFT_CLIENT_SECRET_REF, B8GRID_AUTH_MICROSOFT_JWKS_REFmanaged-provider-callback-required
providertestrequiredRefsstate
office365-smtpsend password reset challenge through SMTP relay adapterB8GRID_EMAIL_RELAY_SMTP_URL_REF, B8GRID_EMAIL_RELAY_SMTP_FROM_REFmanaged-refs-missing
sessend password reset challenge through SES relay adapterB8GRID_EMAIL_RELAY_SES_REGION_REF, B8GRID_EMAIL_RELAY_SES_IDENTITY_REFmanaged-refs-missing
artifactstate
hosted-provider-callback-auditrequired-sanitized-evidence
hosted-provider-token-validation-fixturesrequired-sanitized-evidence
hosted-email-deliverability-bounce-complaint-outage-drillrequired-sanitized-evidence
hosted-webauthn-browser-attestationrequired-sanitized-evidence
hosted-encrypted-totp-secret-kms-lifecyclerequired-sanitized-evidence
blocker
missing managed ref: B8GRID_EMAIL_RELAY_SMTP_URL_REF
missing managed ref: B8GRID_EMAIL_RELAY_SMTP_FROM_REF
missing managed ref: B8GRID_EMAIL_RELAY_SES_REGION_REF
missing managed ref: B8GRID_EMAIL_RELAY_SES_IDENTITY_REF
missing managed ref: B8GRID_AUTH_GITHUB_CLIENT_ID_REF
missing managed ref: B8GRID_AUTH_GITHUB_CLIENT_SECRET_REF
missing managed ref: B8GRID_AUTH_GOOGLE_CLIENT_ID_REF
missing managed ref: B8GRID_AUTH_GOOGLE_CLIENT_SECRET_REF
missing managed ref: B8GRID_AUTH_GOOGLE_JWKS_REF
missing managed ref: B8GRID_AUTH_MICROSOFT_CLIENT_ID_REF
missing managed ref: B8GRID_AUTH_MICROSOFT_CLIENT_SECRET_REF
missing managed ref: B8GRID_AUTH_MICROSOFT_JWKS_REF
idsourceeventsredacted
auth-audit-streamcloud-trust-session-audit0true
suspicious-login-rate-limit-evidencelocal-auth-private-beta-v90true
idlabelstateexecutionModecommanddetail
auth.viewSessionsView sessionsreadyframework-data-backedcloud.dashboard.auth.sessionsShows session/device evidence as redacted metadata and never returns raw session tokens.
auth.switchAdmissionModeSwitch admissionreadyframework-data-backedcloud.dashboard.auth.admissionSwitches the removable signup admission gate between allowlist and open modes.
auth.runPrivateBetaV9Auth private beta V9readylocal-proof-commandcorepack pnpm --silent local:auth-private-beta:v9 --jsonRuns b8grid-local-auth-private-beta-v9 for the complete local private-beta auth readiness contract.
auth.runPrivateBetaV11Auth private beta V11readylocal-proof-commandcorepack pnpm --silent local:auth-private-beta:v11 --jsonRuns b8grid-local-auth-private-beta-v11 for email OTP, local auth hardening, abuse evidence, and token-free private-beta auth completion.
auth.runPrivateBetaV12Auth private beta V12readylocal-proof-commandcorepack pnpm --silent local:auth-private-beta:v12 --jsonRuns b8grid-local-auth-private-beta-v12 for password reset, MFA/passkey/session/device status, abuse limits, email relay, and leak-scan evidence.
auth.runHostedProviderLiveDrillV16Hosted provider live drill V16evidence-requiredowner-supplied-live-evidencecorepack pnpm --silent local:hosted-provider-live-drill:v16 -- --public-url https://<beta-domain> --evidence <sanitized-provider-evidence.json> --jsonTemplate: corepack pnpm --silent local:hosted-provider-live-drill:v16 -- --template --public-url https://<beta-domain> > sanitized-provider-evidence.json. Dr...
auth.runHardeningAuth hardeningreadylocal-proof-commandcorepack pnpm --silent local:auth-hardening:v4 --jsonRuns the private-beta auth hardening proof for MFA, reset, lockout, and abuse evidence.

Security Workbench

Local-first checks for dependency/security scanning, auth abuse, access-control abuse, Docker isolation, and secret leakage.

Local security gateb8grid-cloud-control-security-workbench-v6publicInternet: false
Local onlytrue
hostedGafalse
External pentestfalse
Destructive pentestfalse
Raw credentials outputfalse
idstatereadycommanddetail
dependency-security-scanreadytruecorepack pnpm --silent local:supply-sandbox:v4 --jsonLocal SBOM, dependency, license, lifecycle-script, image provenance, and runtime sandbox evidence.
auth-abuse-testsreadytruecorepack pnpm --silent local:auth-hardening:v4 --jsonLocal auth abuse evidence for MFA, backup codes, revocation, lockout, and suspicious login audit.
wrong-user-wrong-org-wrong-project-testsreadytruecorepack pnpm --filter @b8grid/cloud-control testWrong actor, wrong project, wrong org, signed session, and Cloud Trust boundary tests.
docker-network-isolation-proofsreadytruecorepack pnpm --silent local:service-images:v3:live --jsonDocker network isolation proof that only ingress publishes a host port and data_net stays private.
secrets-in-logs-image-checksreadytruecorepack pnpm --silent local:secrets --jsonScans compose, env, image metadata, and proof outputs for secret-shaped material.
idlabelstateexecutionModecommanddetail
network.runIsolationProofNetwork proofreadylocal-proof-commandcorepack pnpm --silent local:cluster:v2 --jsonRuns public/control/source/data/ops network isolation proof with Postgres private.
trust.runSecuritySpineTrust spinereadylocal-proof-commandcorepack pnpm --silent local:security-spine:v4 --jsonRuns local CA, service cert, mTLS, KMS envelope, grant, and redaction proof.
ops.runObservabilityOps proofreadylocal-proof-commandcorepack pnpm --silent local:ops-observability:v4 -- --mode offline --jsonRuns logs, metrics, traces, audit search, health timeline, incident, and restore evidence.
ops.runObservabilityV5Ops observability V5readylocal-proof-commandcorepack pnpm --silent local:ops-observability:v5 -- --mode offline --jsonRuns b8grid-local-ops-observability-v5 for audit search, health timeline, alert rules, incident snapshots, and sanitized artifact scans.
ops.runRecoveryV5Ops recovery V5readylocal-proof-commandcorepack pnpm --silent local:ops-recovery:v5 -- --mode offline --jsonRuns b8grid-local-ops-recovery-v5 for restore history, recovery runbook, upgrade/rollback evidence, and sanitized artifact scans.
security.runWorkbenchSecurity workbenchreadylocal-proof-commandcorepack pnpm --silent local:security-workbench:v6 --jsonRuns the local security workbench gate for dependencies, auth abuse, isolation, and secret leaks.
security.runWorkbenchV7Security workbench V7readylocal-proof-commandcorepack pnpm --silent local:security-workbench:v7 --jsonRuns b8grid-local-security-workbench-v7 with Auth V12 attack-path mapping and proof-output leak scanning.

Organizations

Bootstrap local projects through the framework mutation path. The signed actor must match the owner field.

projectIdorganizationIdname
No projects yet.

Secrets

Secret mutations write through Cloud Trust and return redacted metadata only.

projectIdenvironmentIdnameversionactiveclass
No secrets yet.

Source Graph

Source Graph remains the first product surface. Cloud Control mediates project, workspace, and source authorization.

projectIdnameremoteIdproductionReadiness
No Source Graph projects yet.
workspaceIdprojectIdnameproductionReadiness
No workspaces yet.
idlabelstateexecutionModecommanddetail
sourceGraph.runPrivateBetaV10Source Graph V10readylocal-proof-commandcorepack pnpm --silent local:source-graph-private-beta:v10 --jsonEmits b8grid-local-source-graph-private-beta-v10 by proving auth-session exchange, real /source app rendering, metadata-safe query output, and customizable U...
sourceGraph.runPrivateBetaV12Source Graph V12readylocal-proof-commandcorepack pnpm --silent local:source-graph-private-beta:v12 --jsonEmits b8grid-local-source-graph-private-beta-v12 for project/repository/workspace/review/readiness UX, metadata-safe APIs, and future-customizable UI slots.
sourceGraph.runPrivateBetaV27Source Graph first-friend V27readylocal-proof-commandcorepack pnpm --silent local:source-graph-private-beta:v27 --jsonEmits b8grid-local-source-graph-private-beta-v27 for allowlist, signup/login, signed CLI installer, CLI session exchange, project bootstrap, commit/push, UI ...
sourceGraph.runAuthUxV28Source Graph auth UX V28readylocal-proof-commandcorepack pnpm --silent local:source-graph-auth-ux:v28 --jsonEmits b8grid-local-source-graph-auth-ux-v28 for password credential setup, password login, password reset consume, passkey registration/authentication, devic...
sourceGraph.runCliBrowserLoginV29Source Graph CLI browser login V29readylocal-proof-commandcorepack pnpm --silent local:source-graph-cli-browser-login:v29 --jsonEmits source-graph-cli-browser-login-v29 for challenge start, browser sign-in approval, shared signed Auth Control cookie, CLI polling, and one-time scoped C...
sourceGraph.runFriendInstall003Source Graph friend install v0.0.3readylocal-proof-commandcorepack pnpm --silent local:source-graph-friend-install:v0.0.3 --jsonEmits source-graph-friend-install-smoke-v0.0.3 by proving the public manifest, PowerShell installer, shell installer, and detached signature download without...
sourceGraph.runFriendInstallExecution003Source Graph install execution v0.0.3readylocal-proof-commandcorepack pnpm --silent local:source-graph-friend-install-execution:v0.0.3 --jsonEmits source-graph-friend-install-execution-v0.0.3 by executing the public PowerShell installer into an isolated temporary directory, verifying the installed...

Hosted Beta Handoff

Provider-independent remote-host handoff for moving from laptop Docker plus relay to a real private-beta host without bundling local secret values.

Remote host handoffb8grid-cloud-control-hosted-beta-handoff-v1remoteLiveReady: false
Remote deploy contractb8grid-remote-private-beta-host-handoff-v1liveRemoteHostReady: false
Remote bundle contractb8grid-remote-private-beta-handoff-bundle-v14requiredForInstallerEndpoints: true
Production gateb8grid-local-production-hosting-v13
Bundle root/opt/b8grid/private-beta
CLI release envB8GRID_SOURCE_GRAPH_CLI_RELEASE_ROOT
CLI release default sourceartifacts/source-graph-cli/windows-x64/release/source-graph
CLI release remote path/opt/b8grid/private-beta/artifacts/source-graph-cli/windows-x64/release/source-graph
CLI compose mount/app/artifacts/source-graph-cli/windows-x64/release/source-graph:ro
Target stageremote-private-beta
Target regionap-south-1
Target profilepublic-private-beta
Remote env path/opt/b8grid/private-beta/.env
Env templateinfra/local/.env.example
Remote health markersremoteHealthMarkers: true
Remote env template proofremoteEnvTemplate: true
CLI release proofreleaseArtifacts: true
Promotion live gatecorepack pnpm --silent local:public-private-beta:live --json --promotion-evidence-packet sanitized-promotion-evidence.json
Local secret bundleincludeLocalSecretsInBundle: false
Secret materialsecretMaterialIncluded: false
hostedGafalse
publicInternetfalse
idpath
compose-1infra/local/docker-compose.yml
compose-2infra/local/docker-compose.production-like-v1.yml
compose-3infra/local/docker-compose.public-private-beta.yml
namestate
B8GRID_LOCAL_POSTGRES_DBrequired-on-remote-host
B8GRID_LOCAL_POSTGRES_USERrequired-on-remote-host
B8GRID_LOCAL_POSTGRES_PASSWORDrequired-on-remote-host
B8GRID_SOURCE_GRAPH_CLOUD_POSTGRES_URLrequired-on-remote-host
B8GRID_LOCAL_SOURCE_GRAPH_TENANTrequired-on-remote-host
B8GRID_LOCAL_SOURCE_GRAPH_PROJECTrequired-on-remote-host
B8GRID_LOCAL_SOURCE_GRAPH_TOKEN_SECRETrequired-on-remote-host
B8X_CLOUD_SESSION_SECRETrequired-on-remote-host
B8GRID_PUBLIC_PRIVATE_BETA_URLrequired-on-remote-host
B8GRID_PUBLIC_PRIVATE_BETA_PUBLIC_REACHABILITYrequired-on-remote-host
B8GRID_REMOTE_PRIVATE_BETA_HOST_MODErequired-on-remote-host
pathstate
cli/manifest.jsonrequired-for-public-installer-endpoints
cli/latest/windows-x64/sha256.txtrequired-for-public-installer-endpoints
cli/signing/b8grid-release-signing-public.xmlrequired-for-public-installer-endpoints
install.ps1required-for-public-installer-endpoints
install.shrequired-for-public-installer-endpoints
idstate
aws-ec2-ap-south-1recommended-beta-default
aws-ec2-ap-south-2supported-handoff-target
oci-bare-metal-indiasupported-handoff-target
gcp-sole-tenant-indiasupported-handoff-target
operator-owned-serversupported-handoff-target
idrequirement
host-requirement-1Ubuntu 24.04 LTS or compatible Linux host
host-requirement-2Docker Engine with Compose plugin
host-requirement-3SSH access for the deploy operator
host-requirement-4public DNS/TLS endpoint owned by the operator
host-requirement-5persistent volume path for Postgres and release evidence
host-requirement-6firewall exposing only HTTP/HTTPS ingress
idcommandstate
preparessh <remote-host> 'sudo mkdir -p /opt/b8grid/private-beta /opt/b8grid/private-beta/artifacts/source-graph-cli/windows-x64/release/source-graph && sudo chown ...operator-run-on-remote-host
upload-compose-bundlersync -av --relative package.json pnpm-lock.yaml infra/local/docker-compose.yml infra/local/docker-compose.production-like-v1.yml infra/local/docker-compose....no-local-secret-values
upload-runtime-bundlersync -av --relative packages scripts docs <remote-host>:/opt/b8grid/private-beta/no-local-secret-values
upload-cli-release-artifactsrsync -av "${B8GRID_SOURCE_GRAPH_CLI_RELEASE_ROOT:-artifacts/source-graph-cli/windows-x64/release/source-graph/}" <remote-host>:/opt/b8grid/private-beta/arti...required-for-installer-endpoints
preflight-remote-host-v19corepack pnpm --silent local:remote-private-beta-host-preflight:v19 -- --bundle-root . --artifact-root ${B8GRID_SOURCE_GRAPH_CLI_RELEASE_ROOT:-artifacts/sour...b8grid-remote-private-beta-host-preflight-v19
startssh <remote-host> 'cd /opt/b8grid/private-beta && docker compose --env-file /opt/b8grid/private-beta/.env -f infra/local/docker-compose.yml -f infra/local/do...build-and-start-on-remote-host
verifycorepack pnpm --silent local:production-hosting:v13 --json --dashboard-base-url https://<remote-host-or-domain> --allow-public-dashboardowner-authorized-public-dashboard-probe
verify-remote-host-v15corepack pnpm --silent local:remote-private-beta-host:v15 -- --public-url https://<remote-host-or-domain> --jsonb8grid-remote-private-beta-host-v15
capture-remote-host-evidence-kit-v20corepack pnpm --silent local:private-beta-evidence-kit:v20 -- --public-url https://<beta-domain> --remote-host-url https://<remote-host-or-domain> --capture-...writes-sanitized-remote-host-verification
template-external-pentest-report-v17corepack pnpm --silent local:external-pentest-report:v17 -- --template --public-url https://<beta-domain> > sanitized-external-pentest-report.jsonb8grid-external-pentest-report-v1
write-evidence-handoff-kit-v20corepack pnpm --silent local:private-beta-evidence-kit:v20 -- --public-url https://<beta-domain> --remote-host-url https://<remote-host-or-domain> --write-di...b8grid-private-beta-evidence-handoff-kit-v20
write-partial-evidence-handoff-kit-v20corepack pnpm --silent local:private-beta-evidence-kit:v20 -- --public-url https://<beta-domain> --write-dir ./.b8x/private-beta-evidence-kit --jsonprovider-and-pentest-evidence-before-remote-host
draft-provider-evidence-kit-v20corepack pnpm --silent local:private-beta-evidence-kit:v20 -- --public-url https://<beta-domain> --draft-provider-evidence ./.b8x/private-beta-evidence-kit -...writes-sanitized-provider-draft-from-public-readiness
validate-evidence-handoff-kit-v20corepack pnpm --silent local:private-beta-evidence-kit:v20 -- --public-url https://<beta-domain> --validate-dir ./.b8x/private-beta-evidence-kit --jsonchecks-provider-and-pentest-evidence-before-promotion
status-evidence-kit-v20corepack pnpm --silent local:private-beta-evidence-kit:v20 -- --public-url https://<beta-domain> --remote-host-url https://<remote-host-or-domain> --status-d...reports-valid-missing-and-assembly-ready-evidence
capture-remote-host-preflight-evidence-kit-v20corepack pnpm --silent local:private-beta-evidence-kit:v20 -- --capture-remote-host-preflight ./.b8x/private-beta-evidence-kit --public-url https://<beta-dom...writes-sanitized-remote-host-preflight
capture-provider-evidence-kit-v20corepack pnpm --silent local:private-beta-evidence-kit:v20 -- --public-url https://<beta-domain> --provider-evidence sanitized-provider-evidence.json --captu...writes-verified-sanitized-provider-evidence
capture-external-pentest-evidence-kit-v20corepack pnpm --silent local:private-beta-evidence-kit:v20 -- --public-url https://<beta-domain> --external-pentest-report sanitized-external-pentest-report....writes-verified-sanitized-pentest-evidence
assemble-promotion-evidence-kit-v20corepack pnpm --silent local:private-beta-evidence-kit:v20 -- --public-url https://<beta-domain> --remote-host-url https://<remote-host-or-domain> --assemble...writes-sanitized-promotion-evidence-packet
verify-external-pentest-report-v17corepack pnpm --silent local:external-pentest-report:v17 -- --public-url https://<beta-domain> --report sanitized-external-pentest-report.json --jsonrequires-sanitized-attacker-box-report
template-promotion-evidence-v18corepack pnpm --silent local:private-beta-promotion-evidence:v18 -- --template --public-url https://<beta-domain> --remote-host-url https://<remote-host-or-d...b8grid-private-beta-promotion-evidence-packet-v1
verify-promotion-evidence-v18corepack pnpm --silent local:private-beta-promotion-evidence:v18 -- --public-url https://<beta-domain> --packet sanitized-promotion-evidence.json --jsonrequires-remote-host-provider-and-pentest-evidence
clear-promotion-blockerscorepack pnpm --silent local:public-private-beta:live --json --promotion-evidence-packet sanitized-promotion-evidence.jsonrequires-verified-promotion-evidence-packet
clear-promotion-blockers-individualcorepack pnpm --silent local:public-private-beta:live --json --remote-host-url https://<remote-host-or-domain> --provider-evidence sanitized-provider-evidenc...legacy-individual-evidence-path
idstep
build-signed-imagesbuild signed images
generate-remote-envgenerate remote private-beta env on the host
copy-compose-bundlecopy compose bundle to host without local secret values
provision-networkprovision private network
restore-postgresrestore or initialize Postgres volume
enable-httpsenable HTTPS ingress
verify-remote-dashboardrun local:production-hosting:v13 against the remote dashboard URL after owner authorization

Operations

Framework mutations emit B8Grid Data invalidations and patch this region without returning a full document.

Operator readinessb8grid-cloud-control-operator-wave-v7rawCredentialsInOutput: false
Shell in dashboardfalse
Destructive opsfalse
Local onlytrue
Public internetfalse
idlabelstateexecutionModecommanddetail
database.migrationStatusMigration checkreadylocal-proof-commandcorepack pnpm --silent local:ops:migrations:status --jsonRecords that the local migration gate has been requested from the dashboard.
database.backupDrillBackup drillreadylocal-proof-commandcorepack pnpm --silent local:ops:backup --jsonRecords that the backup/restore drill should be run from the local operator workbench.
database.createGrantCreate DB grantservice-backedservice-backedcloud.dashboard.databaseCreateGrantCreates a Cloud Trust grant for Postgres access without returning a raw connection string.
database.revokeGrantRevoke DB grantservice-backedservice-backedcloud.dashboard.databaseRevokeGrantRevokes an existing Cloud Trust grant and records a grant.revoke audit event.
auth.viewSessionsView sessionsreadyframework-data-backedcloud.dashboard.auth.sessionsShows session/device evidence as redacted metadata and never returns raw session tokens.
auth.switchAdmissionModeSwitch admissionreadyframework-data-backedcloud.dashboard.auth.admissionSwitches the removable signup admission gate between allowlist and open modes.
auth.runPrivateBetaV9Auth private beta V9readylocal-proof-commandcorepack pnpm --silent local:auth-private-beta:v9 --jsonRuns b8grid-local-auth-private-beta-v9 for the complete local private-beta auth readiness contract.
auth.runPrivateBetaV11Auth private beta V11readylocal-proof-commandcorepack pnpm --silent local:auth-private-beta:v11 --jsonRuns b8grid-local-auth-private-beta-v11 for email OTP, local auth hardening, abuse evidence, and token-free private-beta auth completion.
auth.runPrivateBetaV12Auth private beta V12readylocal-proof-commandcorepack pnpm --silent local:auth-private-beta:v12 --jsonRuns b8grid-local-auth-private-beta-v12 for password reset, MFA/passkey/session/device status, abuse limits, email relay, and leak-scan evidence.
auth.runHostedProviderLiveDrillV16Hosted provider live drill V16evidence-requiredowner-supplied-live-evidencecorepack pnpm --silent local:hosted-provider-live-drill:v16 -- --public-url https://<beta-domain> --evidence <sanitized-provider-evidence.json> --jsonTemplate: corepack pnpm --silent local:hosted-provider-live-drill:v16 -- --template --public-url https://<beta-domain> > sanitized-provider-evidence.json. Dr...
auth.runHardeningAuth hardeningreadylocal-proof-commandcorepack pnpm --silent local:auth-hardening:v4 --jsonRuns the private-beta auth hardening proof for MFA, reset, lockout, and abuse evidence.
runtime.runCompletionV11Runtime V11 completionreadylocal-proof-commandcorepack pnpm --silent local:runtime:v11 --jsonRuns b8grid-local-docker-private-beta-runtime-v11 for the local Docker private-beta runtime completion contract.
provider.runIndependenceV11Provider independence V11readylocal-proof-commandcorepack pnpm --silent local:provider-independence:v11 --jsonRuns b8grid-local-provider-independence-v11 for provider-independent local production posture, including network, trust, observability, and security contracts.
network.runIsolationProofNetwork proofreadylocal-proof-commandcorepack pnpm --silent local:cluster:v2 --jsonRuns public/control/source/data/ops network isolation proof with Postgres private.
trust.runSecuritySpineTrust spinereadylocal-proof-commandcorepack pnpm --silent local:security-spine:v4 --jsonRuns local CA, service cert, mTLS, KMS envelope, grant, and redaction proof.
ops.runObservabilityOps proofreadylocal-proof-commandcorepack pnpm --silent local:ops-observability:v4 -- --mode offline --jsonRuns logs, metrics, traces, audit search, health timeline, incident, and restore evidence.
ops.runObservabilityV5Ops observability V5readylocal-proof-commandcorepack pnpm --silent local:ops-observability:v5 -- --mode offline --jsonRuns b8grid-local-ops-observability-v5 for audit search, health timeline, alert rules, incident snapshots, and sanitized artifact scans.
ops.runRecoveryV5Ops recovery V5readylocal-proof-commandcorepack pnpm --silent local:ops-recovery:v5 -- --mode offline --jsonRuns b8grid-local-ops-recovery-v5 for restore history, recovery runbook, upgrade/rollback evidence, and sanitized artifact scans.
security.runWorkbenchSecurity workbenchreadylocal-proof-commandcorepack pnpm --silent local:security-workbench:v6 --jsonRuns the local security workbench gate for dependencies, auth abuse, isolation, and secret leaks.
security.runWorkbenchV7Security workbench V7readylocal-proof-commandcorepack pnpm --silent local:security-workbench:v7 --jsonRuns b8grid-local-security-workbench-v7 with Auth V12 attack-path mapping and proof-output leak scanning.
sourceGraph.runPrivateBetaV10Source Graph V10readylocal-proof-commandcorepack pnpm --silent local:source-graph-private-beta:v10 --jsonEmits b8grid-local-source-graph-private-beta-v10 by proving auth-session exchange, real /source app rendering, metadata-safe query output, and customizable U...
sourceGraph.runPrivateBetaV12Source Graph V12readylocal-proof-commandcorepack pnpm --silent local:source-graph-private-beta:v12 --jsonEmits b8grid-local-source-graph-private-beta-v12 for project/repository/workspace/review/readiness UX, metadata-safe APIs, and future-customizable UI slots.
sourceGraph.runPrivateBetaV27Source Graph first-friend V27readylocal-proof-commandcorepack pnpm --silent local:source-graph-private-beta:v27 --jsonEmits b8grid-local-source-graph-private-beta-v27 for allowlist, signup/login, signed CLI installer, CLI session exchange, project bootstrap, commit/push, UI ...
sourceGraph.runAuthUxV28Source Graph auth UX V28readylocal-proof-commandcorepack pnpm --silent local:source-graph-auth-ux:v28 --jsonEmits b8grid-local-source-graph-auth-ux-v28 for password credential setup, password login, password reset consume, passkey registration/authentication, devic...
sourceGraph.runCliBrowserLoginV29Source Graph CLI browser login V29readylocal-proof-commandcorepack pnpm --silent local:source-graph-cli-browser-login:v29 --jsonEmits source-graph-cli-browser-login-v29 for challenge start, browser sign-in approval, shared signed Auth Control cookie, CLI polling, and one-time scoped C...
sourceGraph.runFriendInstall003Source Graph friend install v0.0.3readylocal-proof-commandcorepack pnpm --silent local:source-graph-friend-install:v0.0.3 --jsonEmits source-graph-friend-install-smoke-v0.0.3 by proving the public manifest, PowerShell installer, shell installer, and detached signature download without...
sourceGraph.runFriendInstallExecution003Source Graph install execution v0.0.3readylocal-proof-commandcorepack pnpm --silent local:source-graph-friend-install-execution:v0.0.3 --jsonEmits source-graph-friend-install-execution-v0.0.3 by executing the public PowerShell installer into an isolated temporary directory, verifying the installed...
platform.completionV9Platform V9 completionreadylocal-proof-commandcorepack pnpm --silent local:platform:v9 --jsonEmits b8grid-local-platform-completion-v9 by aggregating local runtime, dashboard, auth, provider-independence, and backup/restore evidence without claiming ...
platform.completionV10Platform V10 completionreadylocal-proof-commandcorepack pnpm --silent local:platform:v10 --jsonEmits b8grid-local-platform-completion-v10 by adding the real Source Graph private-beta app/auth/UI contract to the V9 local platform proof.
platform.completionV11Platform V11 completionreadylocal-proof-commandcorepack pnpm --silent local:platform:v11 --jsonEmits b8grid-local-platform-completion-v11 by aggregating V11 runtime, auth, provider-independence, Source Graph, and dashboard operator evidence while prese...
platform.runProductionPrivateBetaV12Production private beta V12readylocal-proof-commandcorepack pnpm --silent local:production-private-beta:v12 --jsonEmits b8grid-local-production-private-beta-v12 by aggregating runtime, Auth V12, Security V7, provider independence, Ops V5, Source Graph V12, and dashboard ...
platform.runProductionHostingV13Production hosting V13readylocal-proof-commandcorepack pnpm --silent local:production-hosting:v13 --jsonEmits b8grid-local-production-hosting-v13 for provider-independent hosting readiness, including remote host handoff, provider credential preflight, egress de...
createdAtactionstatusreadyactorIdprojectIdcommandsummary
No operator runs yet.
createdAtactionactorIdprojectIdsummary
No dashboard actions yet.
createdAtoperationactorIdprojectIdsecretName
No audit events yet.