Skip to content

Architecture

optiflow converts immutable filesystem observations into evidence-backed reports and review-only plans. Detection never implies deletion authority.

The generated architecture portal provides the interactive system boundary, structural layer, and canonical document graph. This page focuses on the runtime flow and verification model.

Runtime flow

CLI / environment / TOML
          |
          v
  effective policy
          |
          v
      discovery
          |
          v
 content + media inventory
          |
          v
 persistent observations
          +----> media-profile evidence
          |
          +----> exact relationship evidence
          |
          v
 immutable report + plan
          |
          v
 typed command outcome

The v0.1.x authority boundary ends at plan generation. Mutation, transactional replacement, validation, quarantine, and recovery require a separate specification and execution architecture.

Ownership boundaries

optiflow owns discovery policy, observations, content evidence, exact relationship derivation, immutable artifacts, local state, and its versioned CLI contracts.

Current scan outputs are published as a sealed directory set; plan outputs use a recoverable plan-and-marker handshake. The artifact-set protocol defines the visibility, durability, inspection, and recovery boundaries.

Specialized tools remain behind typed adapters. The current media probe invokes one canonical, digest-bound ffprobe executable without a shell and accepts only bounded, semantically valid output. The built-in lossless-PNG profile then derives review evidence from current observations without producing an output or estimating savings. Future encoders, optimizers, quality metrics, and fingerprinters must follow the same explicit capability boundary.

The safe extension SDK adds a second, explicit boundary for provider contributions. A manifest declares; an operator lock pins and grants; the host resolves and revalidates. Embedded roles are registered by type, while process providers use bounded JSON stdio with an absolute byte-pinned executable. Neither path can execute plans, publish artifacts, or receive source-media mutation authority.

Verification loop

specification
  -> schemas and examples
  -> executable tests
  -> implementation
  -> observed evidence
  -> specification refinement

The development model defines the required traceability between behavior, safety invariants, machine contracts, tests, and emitted evidence. The performance budget exercises the same public CLI while keeping its synthetic measurement artifact outside the product contract.

The repository-level architecture reference contains the complete component and data-model inventory.

The root meta-architecture inventory connects the complete purpose, principles, knowledge, domain, system, design, decision, and roadmap document set. Cloud-native placement explains how OptiFlow remains a portable product workload while Realm, Relay, Flow, and infrastructure provide replaceable platform capabilities.