Architecture

Architecture

Small, separate layers underneath; one coherent experience on top. Dependencies only ever point down, and a layer you do not use is not in your binary.

Layers

LayerContainsToday
L3 · ExperienceThe rustclamp facade, and later a CLI, macros, recipes and templates.Facade works the rest Planned
L2 · ModulesIntegrations: HTTP, CLI, worker, databases, messaging.Planned — only example targets exist
L1 · CoordinationKernel and Runtime; later configuration, observability, testing.Kernel Prototype Runtime Planned
L0 · FoundationsCore contracts and small primitives: Clock, module and capability identities.Prototype

Crates

PackageRoleDepends on
rustclampFacade: Clamp::run and the preludenothing
rustclamp-coreDomain-neutral contracts: modules, capabilities, contributionsnothing
rustclamp-kernelResolution, cycle detection, projection, freezeCore
rustclamp-runtimeExecution-environment contracts (scaffold)nothing yet

Four repositories, one package each. A generated local workspace ties them together for development; Git ownership stays separate (ADR 0001). A crate boundary has to earn its existence through dependency isolation, portability or ownership — not aesthetics.

The composition path

Independent Rust components
          │
          ▼
       Modules
          │
          ▼
Capabilities + Contributions
          │
          ▼
  Process projection
          │
          ▼
    Minimal Kernel
          │
          ▼
 Running application

This is the design direction. Projection, resolution and freeze exist as prototypes; a single end-to-end pipeline from blueprint to a running production process does not exist yet.

Non-negotiables

RuleWhyEnforced
No unsafeThe framework should not ask for more trust than Rust itself.unsafe_code = "forbid" in every crate
Documented public APIContracts are the product; undocumented ones are accidents.missing_docs = "deny"
Zero third-party dependenciesUnused architecture must cost nothing, and your supply chain stays yours.Boundary tests
No globals, no service locatorHidden coupling and untyped lookup are what the framework exists to remove.By construction: no registry, TypeId or Any map
Ambiguity is an error“Last registration wins” hides real bugs.Resolver tests
Immutable after freezeRuntime behaviour stays predictable and inspectable.Compile-fail doc test
Measured, not assertedCost claims need a control and raw samples.Evidence with caveats

What Clamp is not

Not a web framework, an async runtime, an ORM, a dependency-injection container, a virtual machine or an AI framework. Not a replacement for Tokio, Axum, SQLx or Serde. Clamp coordinates the libraries that already do those jobs well — integrate before reinventing.