Starfly Fabrics ecosystem
Starfly alone is enough. Everything on this page is optional — companions that extend the fabric when you are ready. None of them sit on the exchange or revocation hot paths.
The map
Section titled “The map” [ Reflector · SSF Relay · Reasoner · CALM Forge ] async · sense · relay · judge │ [ Graph · Dashboard · LPA Crypto Heart ] memory · watch · signed policy │ ┌───────────────┐ │ Starfly │ ← deploy this first │ identity PEP │ └───────────────┘ ▲ [ Credential patterns · SPIFFE · K8s · Vault · cloud ] upstream issuers (public) → private PEP (WIMSE)Companion picker
Section titled “Companion picker”| Companion | Why it exists | Status |
|---|---|---|
| Starfly | Exchange, revoke, MCP verify — the fabric core | Shipped — this repo |
| Credential patterns | SPIFFE, K8s, Vault, cloud WI feed exchange | Shipped |
| CALM Forge | Design-time graph — what workloads should do | Satellite — project-calm-forge |
| Starfly Graph | Runtime memory — lineage, blast radius | Preview |
| Dashboard | Human NOC — metrics, SSE, federation watch | Preview |
| Reflector | eBPF senses — observe MCP/tool traffic on the platform | Preview — workload-ebpf-reflector |
| SSF Relay | Motor layer — fan CAEP/SET to enterprise sinks | Preview |
| Reasoner | Coherence — design vs runtime drift, shadow agents | Preview |
| LPA Crypto Heart | Signed policy bundles and provenance heartbeats | Preview |
Layers (how to think about it)
Section titled “Layers (how to think about it)”| Layer | Question it answers | Members |
|---|---|---|
| Upstream | Who attested this workload? | SPIFFE/SPIRE, K8s, Vault OIDC, cloud WI → credential patterns |
| Core | What token may leave the fabric? | Starfly PEP |
| Memory & ops | What happened? What should have? | Graph, Dashboard, CALM Forge |
| Sense & motion | What does the platform see? Where do signals go? | Reflector, SSF Relay |
| Judgment | Does runtime match intent? | Reasoner |
| Provenance | Is policy tamper-evident? | LPA Crypto Heart |
Start here
Section titled “Start here”- Getting started — first WIMSE JWT in 15 minutes
- How the fabric thinks — determinism, graphs, autonomic loop
- Integrators — wire agents and tools
- Pick one companion when you have a concrete need — not all at once