Hercules
Hercules is the SauceApproved canonical software platform repository.
Canonical source: Sauceapproved7/expert-doodle.
Runtime surfaces
hercules-forge/— builder, control plane, identity, audit, preview, release and runtime-data services.hercules-chat/— authenticated chat, RLS, semantic memory, usage metering and AI-router gateway.hercules-base/— backend operating system: Blueprint Engine, Guardian policy compiler, portability manifests and self-hosted control API.hercules-models/— model plane and embedded native runtimes.hercules-training/— training, evaluation, checkpoint and activation pipeline.hercules-video/— video planning, rendering, quality and execution coordination.sauceapproved-studio/— owned Studio product modules, including governed content multiplication, grounded sales intelligence, brand governance and brand-aware workflows.hercules-cleaner/— local-first computer cleanup agent with policy-scoped automation, Session Clean and reversible Recovery Capsules.hercules-hurc/— HURC token, Base Sepolia browser/RPC/signing components.hercules-bank/— sandbox financial core: double-entry ledger, customer accounts, internal transfers and statements; external money rails remain disabled.staging-plane/— isolated synthetic PostgreSQL/PostgREST/Forge staging.observability/— sampled SLO policy.scripts/— validation, benchmarking, security and operator tooling.
The exact owner-code and external-infrastructure boundaries are defined in
governance/owner-code-policy.json.
VS Code development container
The checked-in .devcontainer/devcontainer.json uses a digest-pinned Node.js development image and a non-root user. It provides a consistent Node.js editor environment; it does not contain cluster credentials or deploy workloads. Build, policy, and deployment checks remain in repository scripts and CI.
On a host with Podman 5 or later, configure VS Code's user setting so Dev Containers uses Podman:
{
"dev.containers.dockerPath": "podman"
}
Keep this in local VS Code user settings rather than workspace settings so contributors who use another compatible engine can choose it. Then open the repository in VS Code and run Dev Containers: Reopen in Container. The container installs the pinned oc, kubectl, Helm, and Ansible Core CLI toolchain listed in .devcontainer/toolchain-versions.json. The cluster client targets OpenShift 4.20; update that pin when a target cluster requires another supported client version. The tools do not include cluster credentials or grant deployment authority.
Verify the repository
Core checks:
node scripts/verify-owner-code-only.mjs
node scripts/security-baseline.mjs
node --test tests/hercules-forge*.test.mjs
node --test tests/hercules-hurc-*.test.mjs
node --test tests/hercules-chat*.test.mjs
node --test tests/hercules-base*.test.mjs
node --test tests/hercules-bank-*.test.mjs
Docker-capable staging:
node scripts/staging-plane.mjs all
The performance harness is intentionally loopback/fixture-only. Passing staging benchmarks are not represented as production-scale or multi-region operating history.
Security
Read:
SECURITY.mddocs/HERCULES-THREAT-MODEL.mddocs/HERCULES-FORGE-AUDIT-SECURITY-V1.4.md
HURC signing code is testnet-only unless a separate security review and explicit production authorization state otherwise.
Provenance
IP_PROVENANCE.md records canonical-source, rights, provenance and merge rules.
The owner-code gate rejects undeclared runtime dependencies and unapproved CI
actions. Release evidence can generate a runtime manifest, SPDX SBOM and signed
GitHub artifact attestation.
Reliability
observability/slo-baseline.json defines the sampled staging objectives and
history gate. Hercules explicitly distinguishes sampled staging evidence from
continuous production SLO attainment.
Current engineering rule
Do not let maturity claims advance faster than machine-verifiable evidence.