๐What it means
The build machinery's locked files -- the pipeline, its budgets and spending gate, the model adapters, the status router, the agents that run the build, and the test sandbox. The operators and Orion edit it, through the carol-operators group that follows the active operators in the authority store; Radagast changes it only through his core-install door with an operator's approval for that change; no other agent may, and no agent holds standing write access. It is not part of the core: the core is what is protected from the operators, and the pipeline core is protected only from the agents. An agent refused a write to it files a core-change request for Orion.
๐Easily confused with
[{"term": "Core", "distinction": "The core is protected from the operators; the pipeline core is protected only from the agents, and the operators edit it."}, {"term": "Core-change request", "distinction": "The pipeline core is the locked thing; a core-change request is what an agent files when it is refused a write to it."}]
๐Nuance
Called 'protected core' until 2026-09-24, when it meant 'the core' as a whole and was reached only through Radagast's core-install lane. Ninad then ruled that the operators and Orion edit it and no other agent does. Shown that this retired Radagast's core-install door while kept it, Ninad kept the door (CLI-544, Rulings Repo security #122 superseding #114): it is the one way an agent changes the pipeline core, per change and with an operator's approval.
๐Also called
- protected core
- locked core
- build machinery
๐Filed under
Category: work.
Service: Build Initiatives.
Source: Data Dictionary ยท Public information reflected here.