Browse documentation
Docs/Operate

Operate Research Workspace services

Select, authorize, back up, recover, and diagnose the Pro research capability without weakening its artifact and executor boundaries.

Operate Research Workspace services

Research Workspace is a Pro build-selected capability over Grid's existing model, artifact, governance, and Backbone boundaries. It does not add another evaluator, an HPC scheduler, a DOI authority, or an institutional repository.

The 0.65.0 contract documented here is still a release candidate. Do not enable a production deployment from documentation alone; confirm the exact product artifact, edition, capability catalog, Domain Pack, and external authorities.

Select the product once

  • Build Server or Desktop with the Pro edition when research services are required.
  • Keep Lite for products that do not offer them. Lite omits the optional research contract crates and workspace.
  • Never advertise a Pro deployment plan with Lite bytes. Startup rejects this mismatch.

Route registration follows the startup-frozen deployment plan. The presence of research code does not start a worker, queue, timer, socket, or network discovery operation.

Preserve identity and access boundaries

The public facade applies the existing model-resource authorization before a research operation. Reads require model read access. Mutations require model write access and an authenticated principal. Runtime Host derives actor, revision, branch, producer, clock, and content identities; a client cannot supply them as authority.

Research-use policies govern exact artifact operations. They do not replace caller authentication, tenant authorization, executor trust, or signed workflow authority. Generic raw artifact content is intentionally denied for governed research and scholarly identities; use a supported purpose-specific export route when one exists.

Install workflow and signing authority deliberately

Install a complete verified Domain Pack catalog and configure GRID_DOMAIN_PACK_CATALOG_PATH before admitting executable research workflows. A missing, ambiguous, or digest-mismatched pack fails closed.

Signed approvals and scholarly releases also need deployment-owned approval and release signing keys plus an explicit release trust policy. Supply these through the deployment secret manager. Do not place private keys or production catalog paths in source, fixtures, release notes, or an operations ledger.

Treat specialist execution as an external trust boundary

Grid publishes and validates a candidate; it does not ship a GROMACS worker. A configured specialist worker consumes the exact artifact contract selected by the verified Domain Pack and returns contract-bound output, receipt, and optional verification artifacts under durable Backbone job coordinates.

Do not add a generic process launcher, shell command, arbitrary-code route, or silent in-process fallback. A mismatch in tool, environment, request, attempt, fence, output, or receipt identity must fail closed.

Back up the complete durable state

Include the model home, artifact blobs, policy and status heads, workflow state, and scholarly activations in normal backup policy. An exported RO-Crate that links local artifacts is not a complete backup by itself.

After restart:

  1. Reopen the model and artifact stores before research traffic.
  2. Reverify the Domain Pack catalog and signing/trust configuration.
  3. Read the current policy or activation head instead of replaying a remembered browser response.
  4. Reconcile interrupted jobs through the governed-workflow operation.
  5. Verify retained artifacts and signed releases before export.

Temporary publication roots preserve interrupted multi-artifact commits for explicit recovery. Do not delete one merely because its HTTP connection ended.

Diagnose from durable records

Use immutable artifact, policy, workflow, execution receipt, validation, and activation records together with authenticated RPC logs.

Status Operational meaning
409 A revision, policy head, or compare-and-swap fence changed. Reload and prepare a new operation.
403 Caller authority or the bound purpose/recipient policy refuses the operation.
422 Artifact, evidence, or typed workflow contract is invalid for this operation.

Do not repair these failures by modifying immutable evidence or signed status. Create a corrected or superseding artifact when the contract permits it.

For the five end-user workflows and their claim limits, read Research Workspace. For deployments that select distributed execution, also read Choose a Backbone topology.