Evidence-first cybersecurity operations platform built on a Bun + Turborepo monorepo.
- Blade — trusted execution plane: reproducible lab environments, policy, signed evidence, cleanup. Standalone product; works from the CLI with no RedCore required.
- RedCore — operator and orchestration layer (web, API, mobile) built around Blade. Planned; not the current milestone.
This repo is contract-first. Blade ships as a read-only CLI today; RedCore apps reuse the Starter kit layout for future operator UI and API work.
Workspace UI packages still use the
@school-os/*npm scope (shared starter imports). RedCore domain packages use@redcore/*(e.g.@redcore/contracts).
Prerequisites
git clone https://github.com/shabirkhan-dev/redcore.git
cd redcore
bun install
bun run preparecargo generate-lockfile # first time only
bun run test:contracts
bun run test:blade
bun run blade -- version
bun run blade -- doctor
bun run blade -- build validate examples/operator/Bladefile.json
bun run blade -- lab validate examples/labs/web-pentest.lab.jsonValidation commands accept --output text or --output json. Exit codes: 0 ok, 1 contract/prereq fail, 2 usage, 3 input/read error, 4 engine error.
Lock resolution, artifact downloads, image builds, runtime provisioning, networking, and evidence capture are not implemented yet. See docs/architecture/phase-gap.md and plan.md.
bun run dev| App | URL (dev) |
|---|---|
| Web | http://localhost:3000 |
| Nest API | http://localhost:4000 |
| Docs | http://localhost:3002/docs |
| Area | Purpose |
|---|---|
crates/ |
Blade Rust workspace (blade-cli, blade-core) |
packages/contracts |
@redcore/contracts — Bladefile, LabSpec, EvidenceEvent, SignedOperationRequest v1 |
packages/ui, logger, typescript-config |
Shared Starter kit packages (@school-os/*) |
apps/web, mobile, nest-api, docs, ai-api, rust |
Future RedCore operator surfaces (Starter scaffold today) |
docs/adr, docs/architecture |
Blade/RedCore architecture decisions and gap report |
examples/ |
Operator Bladefile and lab spec fixtures |
plan.md |
Living product and roadmap document |
docker/, .github/workflows/ |
Compose fragments, CI/CD, security |
| Command | Purpose |
|---|---|
bun run blade -- <args> |
Run the Blade CLI (cargo run -p blade-cli) |
bun run test:contracts |
Test @redcore/contracts |
bun run test:blade |
cargo test for Blade crates |
bun run check:contracts |
Typecheck contracts package |
bun run check:blade |
cargo check for Blade workspace |
bun run dev |
Start Starter app dev servers (Turbo) |
bun run build |
Build all apps |
bun run lint / lint:fix |
Biome + script linters |
bun run format |
Format TS/JS, shell, Python, Rust |
bun run typecheck |
TypeScript across workspaces |
bun run test / test:coverage |
Workspace tests + coverage |
bun run test:e2e:web |
Playwright e2e for web |
bun run architecture:check |
Import boundary rules |
bun run preflight |
Lint + typecheck + test |
- Rust — Blade CLI, daemon (planned), policy, runtimes, networking, evidence, TTL, reconciliation.
- Bun + TypeScript — contracts, workspace tooling; later RedCore API and web app.
- Python — isolated tool adapters and automation at package boundaries only.
Blade runs on Windows, macOS, and Linux. Container side effects run on a Linux execution plane (native Linux, WSL2, VM, or cloud). Clients control Blade over an authenticated API; they do not run Podman directly. See docs/adr/0006-portable-clients-use-a-linux-blade-execution-plane.md.
cp env.docker.example .env
docker compose up -d --buildWeb :3000 · Nest :4000 · Postgres host :5433. Details: docker/README.md and the docs app route /docs/docker.
| Doc | Purpose |
|---|---|
| plan.md | Vision, phases, and immediate next steps |
| docs/adr/ | Architecture decision records |
| docs/architecture/phase-gap.md | Phase 0/1 gap report |
| PROJECT.md | Monorepo layout and conventions |
| AGENTS.md | Instructions for AI agents |
| DESIGN.md | UI design brief (operator surfaces) |
apps/docs |
Fumadocs site (bun --cwd apps/docs run dev) |
Dual-licensed under MIT or Apache-2.0 at your option: LICENSE-MIT, LICENSE-Apache-2.0.