Skip to content

sauceapproved7/hercules-community

v0.1.0Apache-2.0

Use five bounded read-only Hercules tools from ChatGPT and Codex with explicit security boundaries.

Hercules

Hercules is the SauceApproved canonical software platform repository.

Canonical source: Sauceapproved7/expert-doodle.

Runtime surfaces

  • hercules-forge/ — builder, control plane, identity, audit, preview, release and runtime-data services.
  • hercules-chat/ — authenticated chat, RLS, semantic memory, usage metering and AI-router gateway.
  • hercules-base/ — backend operating system: Blueprint Engine, Guardian policy compiler, portability manifests and self-hosted control API.
  • hercules-models/ — model plane and embedded native runtimes.
  • hercules-training/ — training, evaluation, checkpoint and activation pipeline.
  • hercules-video/ — video planning, rendering, quality and execution coordination.
  • sauceapproved-studio/ — owned Studio product modules, including governed content multiplication, grounded sales intelligence, brand governance and brand-aware workflows.
  • hercules-cleaner/ — local-first computer cleanup agent with policy-scoped automation, Session Clean and reversible Recovery Capsules.
  • hercules-hurc/ — HURC token, Base Sepolia browser/RPC/signing components.
  • hercules-bank/ — sandbox financial core: double-entry ledger, customer accounts, internal transfers and statements; external money rails remain disabled.
  • staging-plane/ — isolated synthetic PostgreSQL/PostgREST/Forge staging.
  • observability/ — sampled SLO policy.
  • scripts/ — validation, benchmarking, security and operator tooling.

The exact owner-code and external-infrastructure boundaries are defined in governance/owner-code-policy.json.

VS Code development container

The checked-in .devcontainer/devcontainer.json uses a digest-pinned Node.js development image and a non-root user. It provides a consistent Node.js editor environment; it does not contain cluster credentials or deploy workloads. Build, policy, and deployment checks remain in repository scripts and CI.

On a host with Podman 5 or later, configure VS Code's user setting so Dev Containers uses Podman:

{
  "dev.containers.dockerPath": "podman"
}

Keep this in local VS Code user settings rather than workspace settings so contributors who use another compatible engine can choose it. Then open the repository in VS Code and run Dev Containers: Reopen in Container. The container installs the pinned oc, kubectl, Helm, and Ansible Core CLI toolchain listed in .devcontainer/toolchain-versions.json. The cluster client targets OpenShift 4.20; update that pin when a target cluster requires another supported client version. The tools do not include cluster credentials or grant deployment authority.

Verify the repository

Core checks:

node scripts/verify-owner-code-only.mjs
node scripts/security-baseline.mjs
node --test tests/hercules-forge*.test.mjs
node --test tests/hercules-hurc-*.test.mjs
node --test tests/hercules-chat*.test.mjs
node --test tests/hercules-base*.test.mjs
node --test tests/hercules-bank-*.test.mjs

Docker-capable staging:

node scripts/staging-plane.mjs all

The performance harness is intentionally loopback/fixture-only. Passing staging benchmarks are not represented as production-scale or multi-region operating history.

Security

Read:

  • SECURITY.md
  • docs/HERCULES-THREAT-MODEL.md
  • docs/HERCULES-FORGE-AUDIT-SECURITY-V1.4.md

HURC signing code is testnet-only unless a separate security review and explicit production authorization state otherwise.

Provenance

IP_PROVENANCE.md records canonical-source, rights, provenance and merge rules. The owner-code gate rejects undeclared runtime dependencies and unapproved CI actions. Release evidence can generate a runtime manifest, SPDX SBOM and signed GitHub artifact attestation.

Reliability

observability/slo-baseline.json defines the sampled staging objectives and history gate. Hercules explicitly distinguishes sampled staging evidence from continuous production SLO attainment.

Current engineering rule

Do not let maturity claims advance faster than machine-verifiable evidence.