@arqen/kernel (2.0.0)
Installation
@arqen:registry=https://git.arqen.io/api/packages/Eugenio/npm/npm install @arqen/kernel@2.0.0"@arqen/kernel": "2.0.0"About this package
Arqen Kernel Engine v2.0.0
Headless Integrity Engine for Industrial OT, Civic Entities, and Educational Institutions.
Arqen è un middleware Headless (Pure-Engine) ad alte prestazioni progettato per la validazione deterministica, la transizione di stato atomicamente garantita e l'audit crittografico (SHA-256 Ledger) di eventi di processo industriali e civici.
Non include interfaccia utente: opera come Infrastruttura d'Integrità On-Premise / Cloud Privato comunicando unicamente tramite API REST tipate e SDK client.
Quick Start On-Premise (One-Shot Deployment)
L'Engine viene distribuito come stack containerizzato OCI isolato (Engine + PostgreSQL 16 con RLS).
# 1. Clona la repository On-Premise
git clone https://github.com/arqen/kernel-engine.git
cd kernel-engine
# 2. Esegui lo script di inizializzazione automatica
./scripts/init-onpremise.sh
Lo script init-onpremise.sh:
- Genera automaticamente credenziali sicure e secrets in
.env. - Avvia i container
arqen-postgres-dbearqen-engine. - Esegue le migrazioni del database (
npm run db:migrate:prod) e il seed demo. - Espone l'endpoint di Healthcheck su
http://localhost:3000/api/v1/health.
Architettura & Garanzie Invarianti
[ Application / Sensore ] --( SDK 2 Righe )--> [ Arqen Engine API ]
|
┌───────────┴───────────┐
│ Fail-Closed Validation
│ • Schema/JSON Check
│ • FSM Transition
│ • RBAC
└───────────┬───────────┘
│
▼
[ PostgreSQL + Ledger SHA-256 ]
- Fail-Closed Server-Side: Nessun payload errato, parziale o non conforme allo schema può toccare il database reale. L'Engine blocca la transazione all'origine restituendo codici tipati (
VALIDATION,INVALID_TRANSITION,RBAC_DENIED). - Audit Ledger SHA-256: Ogni commit valido genera un hash crittografico concatenato che certifica l'immutabilità della catena degli eventi.
- Isolamento Multi-Tenant via RLS: Sicurezza nativa a livello di database tramite Row Level Security di PostgreSQL 16.
- Zero Lock-In: Schema SQL standard su PostgreSQL aperto. Nessun formato proprietario.
Variabili d'Ambiente (.env)
| Variabile | Descrizione | Esempio |
|---|---|---|
PORT |
Porta HTTP dell'Engine | 3000 |
NODE_ENV |
Ambiente di esecuzione | production |
DB_HOST |
Host PostgreSQL | arqen-db |
DB_PORT |
Porta PostgreSQL | 5432 |
DB_NAME |
Nome database | arqen_core_db |
DB_USER |
Ruolo applicazione | app_user |
DB_PASSWORD |
Password applicazione | ... |
DB_ADMIN_USER |
Ruolo admin per migrazioni | postgres |
DB_ADMIN_PASSWORD |
Password admin | ... |
MANIFEST_SECRET |
Secret per firma manifest | ... |
PLUGIN_SECRET_KEY |
Chiave verifica plugin | ... |
ARQEN_ALLOW_INSECURE_CLOUD_URL |
Permette URL cloud HTTP in rete privata | 1 |
Collaudo e Invarianti Fail-Closed
L'Engine include una suite di Fuzzing Test per verificare la tenuta contro payload malformati, transizioni illegali e tentativi di injection:
npx jest src/kernel/__tests__/failClosed.test.ts --runInBand
Distribuzione Economica
Arqen è strutturato per un'accessibilità democratica:
- Civic & Edu: 1.000 € / anno (Istituti, ITS, Comuni).
- B2B Industrial Starter: 1.500 € Setup + 2.400 € / anno (200 €/mese per PMI).
- B2B Industrial Professional: 4.500 € Setup + 6.000 € / anno (500 €/mese).
- B2B Industrial Enterprise: 10.000 € Setup + 15.000 € / anno (SLA 24/7, Source Code Escrow).
Per la documentazione completa di architettura, DSL e ADR vedi docs/.
Dependencies
Dependencies
| ID | Version |
|---|---|
| ajv | ^8.17.1 |
| ajv-formats | ^2.1.1 |
| axios | ^1.7.9 |
| bcryptjs | ^3.0.2 |
| dotenv | ^16.4.7 |
| express | ^4.21.2 |
| pg | ^8.13.1 |
Development Dependencies
| ID | Version |
|---|---|
| @eslint/js | 10.0.1 |
| @types/express | ^4.17.21 |
| @types/jest | ^29.5.14 |
| @types/node | ^20.11.24 |
| @types/pg | ^8.11.10 |
| eslint | 10.10.0 |
| globals | ^17.12.0 |
| jest | ^29.7.0 |
| ts-jest | ^29.2.5 |
| tsx | ^4.19.2 |
| typescript | ^5.6.3 |
| typescript-eslint | 8.70.0 |