Architecture

Keep Shipping is a harness in the style of Factory Zero's Cratefield harness: a small Rust core, ports (traits), and adapters (the only vendor-aware code), composed at compile time.

ship.ks ──► ks-lang (parse, format) ──► ks-core (types, check, diagnostics)
                                              │
keepshipping (ks-cli): check · run · fmt · graph · approve · log verify · blocks · import
ks-lsp: the same ks-core, for editors
                                              ▼
                  ks-engine (DAG, run state, policy gates, approvals, run log)
                                              │ only sees ports
ports: RunContext · Secrets · ImageBuilder · Registry · Signer · IacTool · Cluster
       RemoteShell · FunctionHost · ScriptHost · ApprovalChannel · Directory
       DecisionModel · RunLog · StateStore · BlockSource · BlocksIndex · PolicyStore
       HttpClient · Clock · IdGen
                                              │
adapters/*: buildkit, oci-distribution, sigstore, tofu-cli, kube, ssh, deno script host,
            tty / GitHub approvals, jev, local run log, github-actions, …

The rules that follow from the picture:

Crates

PathCrateRole
crates/langks-langLexer, parser, lossless syntax tree with spans, formatter. No I/O, wasm-safe
crates/coreks-coreType system, checker, diagnostics registry, the StepKind trait, port traits, the Harness builder
crates/engineks-engineDAG planner and executor, run state (park and resume), policy enforcement, run log
crates/cliks-cliThe keepshipping binary
crates/lspks-lspLanguage server (keepshipping lsp)
crates/testingks-testingFakes for every port, plus the conformance kits steps and adapters must pass, and the ADR guard test
steps/*—Built-in step families (later epic)
adapters/*—One crate per vendor integration (later epic)
sdk/ts@keepshipping/sdk@keepshipping/sdk for TypeScript escape-hatch steps, and @keepshipping/sdk/testing to unit-test one in your own test runner
ventures/keepshipping—The optional hosted parts (waitlist, web approvals, run-log viewer, blocks index) as a Cratefield venture (later epic)

Changes to this layout go through a new ADR — see the ADR index.