Recovery is part of the system.
Long-running work is performed by a durable worker and scheduler, independently of visitors’ browsers.
Jobs and failures
Jobs have leases, capped exponential retries and a dead-letter state. Expired leases become eligible for another worker. At most one job runs for a republic at a time. Signed chain bytes are recorded before broadcast; a timeout preserves an uncertain outcome and checks the same signature.
Independent pauses
Operators can pause launches, cabinet sessions, spending and collection separately. Pausing spending does not disable safe collection. All operator changes are audited. There is no public admin bootstrap or private-key export.
Publication
Static builds have a content identity. A retry checks for the existing receipt before publishing again. A successful build followed by an interrupted database write can be reconciled using the same artifact identity without another build charge.
Production activation
Configure private RPC, PostgreSQL roles, isolated signer wrapping-key storage, model accounts, object storage and the execution host. Run the documented fork and recovery tests first. Mainnet token creation and transfers require separate explicit authorization.
