Redeon.SuperSiteEngineCore.Web.Eltheon.Core.Runtime
Core.Runtime provides the Eltheon runtime foundation for typed runtime configuration, runtime state, maintenance state, restart requirements, paths, diagnostics, events, policies, runtime metrics, and persistent boot tasks.
It is a foundation package, not a feature package. It intentionally does not contain Admin UI, RuntimeManagement UI, Watchdog proxy behavior, installer composition, EF migrations, or plugin management behavior.
Boundaries
- Runtime implementations live here.
- Stable neutral contracts live in Core.Abstractions.
- Existing
IConfigandConfigsFilepersistence remain owned by Core.ConfigFiles. - Runtime metrics are projections only; runtime state remains the source of truth.
- Boot tasks are stored atomically below
RuntimeRoot, execute serially in eitherPreCompositionorPreHostedServices, and expose only sanitized snapshots. Existing tasks default toPreHostedServices; configuration-changing migrations opt intoPreComposition. Blocking failures require an explicit retry or cancel. - Restart requirements carry a stable subsystem group and the runtime instance that created or refreshed them. A later ApplicationHost instance reconciles earlier-instance requirements even when the application was stopped and started without the Watchdog.
- Restart state uses atomic replacement and last-valid backups. Invalid primary and backup state fails closed instead of being replaced with an empty list.
- Watchdog intent and observation data provide additional supervised-restart evidence; an intent by itself never proves a restart.
Effective configuration snapshots
AddEltheonCoreRuntime() includes AddEltheonRuntimeConfigurationCaching().
The latter registers IRuntimeEffectiveConfigurationCache<TSnapshot> as an
open-generic singleton while its neutral contracts remain in
Core.Abstractions. A snapshot type binds to one canonical lowercase owner key
on first use. Loads are single-flight per snapshot type; cancelling one waiter
does not cancel the shared load, while host shutdown does.
The cache fences loads against concurrent invalidation generations, returns
only fresh and non-invalidated values from TryGet, and permits last-known-good
fallback only after a normal TTL refresh failure and only within the configured
maximum-stale interval. Security- and configuration-relevant invalidations
discard the prior value immediately. Metadata and metrics expose bounded state,
generation, age, outcome, and stable reason codes without configuration data.
Adviser Contributors
AddEltheonCoreRuntime() registers three scoped Adviser checks through the
neutral Core.Abstractions contributor contract:
eltheon.runtime.config-file-integrityeltheon.runtime.boot-task-recoveryeltheon.runtime.restart-requirements
The checks read existing runtime snapshots only. Evidence excludes paths, free-text errors, actors, payloads, and correlation data. Manual and recheck targeting accepts only validated runtime subject keys. Related restart requirements are grouped into one finding per stable subsystem key so a plugin operation does not produce duplicated Adviser cards.