ReferenceReferenceOverview

Reference

Everything documented here belongs to memnox-runtime, the open-source gate that runs on your own machines. It is Apache-2.0, so every flag and command below sits in a repository you can read.

What is not here

The runtime has no HTTP API. It is a CLI, a Unix socket at ~/.memnox/memnox.sock, and files under ~/.memnox/. There is no port to call, no agent token to issue and no SDK to install, and that is a decision rather than a gap: a governance daemon reachable over the network is a governance daemon somebody else can reach. What something talks to instead is on Runtime seams.

The hosted control plane's HTTP API is not published. The console is its interface, and the console is how you drive it, and The console is the tour. Where a page needs you to do something there, it names the screen rather than a route.

It is a private, versioned surface that moves with the product. Publishing it invites integrations against endpoints that will change, and then breaking them. If you need programmatic access, talk to us about it rather than reverse-engineering the console. An integration we know about is one we can avoid breaking.

Versioning and stability

  • The policy file carries version = 1 at the top.
  • A rule set is identified by a content hash, recorded on every event and printed by memnox doctor --wiring, so two machines are compared without diffing files.
  • The event schema is frozen at version 1 and carries its version in every row, which is what lets an export written today be read later.
  • --json output is the contract. The human wording of a command may change; the JSON shape does not without a version.

Conventions used throughout

Placeholder

<name>

A value you supply on the command line

[value]

An optional command argument

-- <command>

Everything after -- is passed through untouched