Installed components
Installed components displays real server state with a next action, not placeholder statistics.
Served by the core studio
Software records (sources, programs, runs, releases, components, environments, media, verification and exports) live in the core engine and are edited in its studio. When a connected engine answers through this workspace, the panels above render its own records as returned; without a connection the shell states that and shows nothing rather than an invented row. The surface contract below names each action and the setup it needs.
Surface contract
Primary object: installed components: the exact digest, the permissions each component declares, and whether an upgrade is available.
Actions
- BrowseOpens the public catalogue, where each component states its licence, digest and declared permissions before installation; free first-party components are marked.
- ConfigureCore studioConfiguration is stored with the installed digest in the core studio and is re-validated on upgrade; the hosted shell has no installed row.
- UpgradeCore studioAn upgrade shows the digest change and re-asks for any newly declared permissions before the engine applies it; nothing upgrades silently here.
- RemoveCore studioRemoval deletes the installed record in the core studio; other components that depend on it are listed by the engine before removal, never guessed here.
Required states and how this surface reaches them
- loading
- the session probe and each list show Loading… until the control plane answers.
- ready
- the server’s own records render as returned; the primary object is named before its details.
- empty
- no component is installed for this software yet; the direct action is the public component catalogue.
- error
- the control plane’s status and detail are shown; no placeholder row replaces them.
- offline
- no control plane is reachable; nothing is rendered rather than invented.
- permission_denied
- a 401 returns to sign-in with this path; a 403 states that the role cannot read this surface.
- not_configured
- a 503 names the missing provider or secret; setup is shown, never fake results.
- budget_paused
- a 402 (quota_exceeded / upgrade_required) pauses spending; the budget row shows the cap and consumption that caused it.
- requires_approval
- mutations the server reserves for an explicit human owner/admin are refused with its own detail and never auto-approved here.
Scope: workspace membership. Engine records are read and written through the core engine’s own routes (proxied by the control plane); the hosted shell binds only to named contracts, shows a record only when the server returned it, and never calculates permissions in the browser.