The Fabric Suite DSCForge · ConfigFabric · RepoFabric · Kamino · Kamino Imprint · Restraining Bolt · Holocron

Prove an application is safe to ship. Then ship it to the whole fleet, and keep it that way.

A three-stage pipeline takes any Windows installer and proves three things on real hardware: that it installs silently, that it is configured exactly as intended, and that it runs on the minimum rights it genuinely needs. What comes out is a package and a configuration you can defend. The Fabric then delivers it over your LAN, assigns it by Entra group, schedules it and enforces it — on infrastructure you own, with a private model that never leaves the building and never gets the last word.

What each product does

Three prove an application is safe to ship. Two author and govern. Two deliver and enforce — and contain no model at all.
Kamino Package · installs silently

Kamino Package — the prover

WinGet manifest set · Intune Win32

Determines and proves the fully silent install for any Windows application. Reverts a disposable Windows 11 VM, works down a ranked ladder of switch candidates, and asserts silence from inside the guest: no window appeared, no consent prompt fired, the product was actually detected afterwards.

Kamino Imprint · configured correctly

Kamino Imprint — the witness

DSC v3, both dialects · PSADT v4

Install the app, watch a human configure it, and emit the DSC v3 that reproduces it. Each field is seeded with a known value and hunted through the disk-and-registry delta across six encodings, so the mapping is evidence rather than a guess from a key's name.

Restraining Bolt · least privilege

Restraining Bolt — the auditor

Native Windows ACEs & user rights

Proves, with captured evidence, exactly which administrator rights the application genuinely uses — then removes the rest without breaking it. Every surviving denial resolves onto one of six axes, each with one precise minimal grant.

Authoring · model-assisted

DSCForge — the forge

Microsoft DSC v3 document schema

Turns natural language, GPO exports and live system scans into schema-validated DSC v3 YAML, and revises what the pipeline produced. The prompt is built at runtime from the resource schemas actually present on the target, so the model is told what exists rather than guessing.

Governance · model-assisted

Holocron — the spec generator

OpenSpec change sets · CommonMark

Generates OpenSpec specifications — proposal, design, tasks, measured environment facts and the delta against your living specs. It interviews you until every requirement is settled or parked with a named owner, then has two independent critics score the result.

Enforcement · no model

ConfigFabric — the enforcer

DSC v3 · Authenticode · NuGet v3 feed

Assigns proven configs — and Authenticode-signed PowerShell scripts — by transitive Entra device- or user-group membership. Scripts are approval-gated, then staged or run as SYSTEM or as the user, and the endpoint refuses any signer outside its pinned trust list. Bundles carry recurrence, time mode and jitter.

Delivery · no model

RepoFabric — the delivery fabric

Microsoft.Rest WinGet source API

A private winget source serving only vetted builds, advertising PeerDist hashes so BranchCache pulls installers from a LAN peer, not the WAN. Open-sourced under MIT; nothing phones home.

No lock-in

Open formats, end to end

nothing here is ours to read alone

Kamino silent-install proving Kamino Imprint configuration capture Restraining Bolt least-privilege proof DSCForge authoring · QA · registry host Holocron spec gate · critics propose a switch at a dead end when the ranked ladder is exhausted name the setting in this frame when the UI exposed no label to read propose the one minimal grant at a genuine dead end, never routinely write, explain or repair a config on generate, revise and retry interview, then critique on drafting, and again at convergence RingoLLM privately fine-tuned for Windows endpoint management · runs on hardware you own Serving load on demand, unload when idle Registry which model is good at what Routing ask for a role, not for a model the model proposes — it never decides, and it stops here ConfigFabric assign · schedule · enforce · measure RepoFabric catalogue · deliver · audit · retain Zero model call sites. Nothing that touches an endpoint asks a model anything. Between the two tiers stands a signed human approval, bound to the hash of the exact document being approved.
RingoLLM is the heartbeat of the authoring tier — and it is architecturally optional in every single caller. If the model is unreachable, each caller falls back to its deterministic behaviour rather than failing, and nothing it produces is ever applied automatically.

What that architecture buys a Windows estate

No prompt leavesYour configurations, your registry contents, your fleet's names. Inference runs on your own silicon.
Proof, not opinionSilence asserted from inside the guest. Configs verified by a test deliberately built to fail.
Fails closedA cleanup job cannot prune an installer that live enforced state still depends on.
Human-signedNo model-written configuration reaches an endpoint without an approval bound to its hash.

RingoLLM descends from Muse Glimmer 30B and is privately fine-tuned on the Windows endpoint-management domain — DSC v3, PowerShell 7 and Intune. It is deliberately narrow: it is trained to refuse work outside that domain rather than guess, which is why the estate routes by role and keeps other models on the same host for other jobs. On DSC v3 authoring it produces a valid document every time in our own published measurements, where general-purpose models routinely answer with the wrong generation of DSC entirely.

How an application reaches the fleet

The pipeline proves it, the Fabric ships and enforces it, and a gate closes behind it. Teal dots mark the only points where a model is consulted.
1 · PROVE IT 2 · AUTHOR & TEST 3 · ASSIGN & ENFORCE 4 · DELIVER the secure package pipeline Kamino it installs silently — proven in a VM Kamino Imprint it is configured as intended Restraining Bolt it runs on minimum rights One proven, secure app installer + manifest, and a config carrying its settings and its grants DSCForge author from scratch, or revise what the pipeline produced Imprint round-trip, same bench 1 validate   2 expect OUT of state 3 apply      4 expect IN state 5 apply again → expect a no-op 6 break one value on purpose     and require the test to FAIL a test that cannot fail is not a test ConfigFabric configs + signed scripts, by Entra group Enforce or Audit-only, per group Scheduled bundle recurrence · local-or-UTC · jitter phase-ranked, dependency-sorted Endpoint Intune remediation, task, or SYSTEM no Windows service installed — and it pulls the installer from a LAN peer RepoFabric private winget source, vetted builds PeerDist → one download per subnet Lock gate — fails closed Before pruning any build, RepoFabric asks whether live enforced state still needs it. No answer means no. There is no override. proven verdict the proven installer and manifest, published on explicit operator confirmation and cryptographically signed asks first Restraining Bolt's grants and Imprint's captured settings are ordinary DSC v3 resources — ConfigFabric enforces them exactly like any other configuration.
a model is consulted here — advisory only carrying traffic today returned by polling — no inbound listener fail-closed gate

The integration points, precisely

Every row is a real endpoint or contract, and all of them work today. LIVE is machine-to-machine; OPERATOR means a person deliberately carries the handoff.
From → To What moves When it fires If it fails
DSCForge → Kamino LIVE An authored DSC v3 document, versioned and never overwritten, posted to an Imprint session. When an author sends a draft to be proved on real hardware. The version records with its proof state left explicitly unknown — never assumed good.
Kamino → DSCForge LIVE The six-stage verdict and a three-state proof flag: never proved, proved and failed, or proven. The author polls a shared mailbox. Kamino never calls out — both sides append to one table. Neither side needs an inbound listener, a webhook secret or a reachable address.
Kamino → DSCForge LIVE MODEL Measured model capability — which model actually did which job, how fast, and how well. On publish to the shared registry DSCForge hosts for the whole estate. Recorded, never auto-adopted. A peer publishing an endpoint can never redirect your prompts.
Kamino → RepoFabric LIVE The proven manifest set and installer binary, hash-bound to a cryptographically signed request. Only on explicit operator confirmation. Nothing fires automatically. A hash mismatch commits nothing. The publishing client is two-factor and revocable in one update.
DSCForge → RepoFabric LIVE A catalogue question: is this app present, at what promotion stage, coherent in this repo? At author time, per app, while the config is still being written. Degrades open. An unreachable catalogue warns and never blocks authoring.
RepoFabric → ConfigFabric LIVE A list of build versions proposed for deletion, and a per-version verdict on each. Before every prune: retention sweeps, reverts, manual removals. Fails closed. Timeout, 401, 404 or an unreadable ledger all deny every candidate.
ConfigFabric → RepoFabric LIVE Publish, promote, revert and drift events into one shared append-only ledger, stamped by source. On every local ledger insert, attributed to a signed-in user or to the scheduled job. Fail-soft and de-duplicated. A forwarding failure never breaks the local publish.
ConfigFabric → fleet LIVE A per-device manifest: ordered config entries and approved signed scripts, with content hashes. At check-in and at each scheduled bundle window. A degraded manifest never overwrites the device's last-known-good copy.
Restraining Bolt → the config OPERATOR The proven minimal grants — scoped ACEs, user-rights assignments, service logon rights — each cited to the evidence that justified it. Once the app's rights are proved, alongside Imprint's captured settings. An operator reviews the grants and carries them across. Grants are ordinary DSC v3 resources, so ConfigFabric enforces them with no new machinery.
Holocron → the model plane LIVE MODEL No product-to-product traffic by design. It joins the estate at the shared model host and its role registry. Whenever it needs judgement — an interview turn, a critique at convergence. Fully standalone. Nothing in it depends on a Fabric product being deployed.
DSCForge → ConfigFabric OPERATOR The published config plus the exact app builds it declares a dependency on. On publish. An operator moves the authored document into ConfigFabric, which validates and publishes it. Format and dependency-lock grammar are frozen on both sides. A registered automated pull is the remaining automation step.

Who owns which record

One writer per fact. Everything else reads.

Config document DSCForge

Proof record Kamino

Imprint session Imprint

Privilege finding Restraining Bolt

Signed script ConfigFabric

Version lock ConfigFabric

Publish ledger RepoFabric

Spec change set Holocron

The pipeline is one platform, not three tools. Kamino grew out of the Restraining Bolt platform and still runs on it — the same bench, the same append-only ledger, the same safety pin that refuses to touch a VM whose reported identity does not match the one it was told to use. So the three proving stages share evidence, storage and discipline rather than exchanging files across a gap. What leaves the pipeline is a single defensible claim about one application: it installs without a prompt, it is configured the way you meant, and it holds only the rights you can show it uses.

Deploy it whole, or one piece at a time. Every product stands alone and is useful on its own — the integrations are additive and read-mostly, so a product with no peer configured behaves exactly as a standalone install. Communication between products is cryptographically signed with per-leg, least-privilege credentials: a catalogue token reaches only the catalogue, and deletion authority is withheld from the authoring tier entirely, by design rather than by configuration.

By RingoSystems Heavy Industries. Every capability above is drawn from current shipping code. Cross-product message signing is deployed in observing mode and moves to enforcing at a scheduled cut-over. Kamino is phase-gated rather than versioned: five of six phases complete, confirm-gated publishing to RepoFabric proven end to end, with the Intune upload remaining an operator step.