A modular zero-trust cryptographic platform — Sentinel · Bolt · Palette.
Status: Active / Autonomous Architecture Node Core Engine: Cryptographic Pipeline & Session State Manager Primary Datastore: Redis Service Layer: Express.js / Node.js (>=20) Encryption Protocol: Cipher Tube Assembly Protocol (CTAP)
CypherTube is a zero-trust session and cryptographic pipeline built on Express 5 and Redis 5. It provides blinded session token management, cryptographically guarded gateway routing, real-time telemetry, and a modular workspace architecture spanning six core packages.
| Package | Role |
|---|---|
sentinel |
Security boundary enforcement, middleware guards, rate limiting |
bolt |
Performance optimization layer — pre-rendering, cache pooling, hot-path tuning |
palette |
Design system and Storybook component library |
tube |
Core cryptographic pipeline — cipher assembly, encryption/decryption |
ui |
Cosmology map and client-facing interface rendering |
wizard |
CLI tooling (ctube) and world management |
session_rotator.ts— Blinded SHA-256 token hashing, session creation, rotation with 5-second grace periodgatewayServer.ts— Express gateway with telemetry endpoint, ZK validation middleware, graceful SIGTERM shutdownserver.ts— Primary application server with Helmet, rate limiting, LRU cache, myth/ritual engine integrationcta.ts— Cipher Tube Assembly —buildCipherTube/decryptCipherTube/fastHashcrypto/verifier.ts— Cryptographic proof verificationgateway/sessionMiddleware.ts—cipherTubeGatewaymiddleware for ZK validation boundariescache/redisPool.ts— Redis connection pooling
core/— Python telemetry and indexing nodes (indexer.py,nodes.py,telemetry.py)cyphertube-core/— Packaged core library with its ownpackage.jsongovernance/— OPA policy definitionssecurity/— Security audit artifacts and secret scanning baselinedocs/— API reference, philosophy, architecture documentation
- Node.js >= 20.0.0
- npm >= 10.0.0
- Redis running locally or reachable via
REDIS_URL
npm install
npm startCopy .env.example to .env and configure:
REDIS_URL— Redis connection stringGATEWAY_PORT— Gateway server port (default: 8080)NODE_ENV—production/development/test
# Run all workspace tests
npm test
# Run sovereign OS core tests
npx vitest tests/unit/sovereign-os.test.ts
# Integration tests
npm run test:integration
# Security scan
npm run security:scan- ✅ Autonomous repository synchronization
- ✅ State and session recovery with blinded token storage
- ✅ Real-time gateway telemetry and diagnostics
- ✅ Rate limiting and Helmet security headers
- ✅ Graceful shutdown with Redis connection cleanup
- ✅ Session rotation with 5-second grace period (race-condition tolerant)
- ✅ LRU in-process cache for hot-path optimization
- ✅ Pre-rendered static UI components (Bolt optimization)
- ✅ OPA governance policy testing
For the full detailed assessment, see ASSESSMENT.md.
- Session Payload Serialization — Migrate from raw
userIdstring to a versioned, typedSessionPayloadwith metadata, scopes, issued-at, and rotation lineage tracking. - Redis Memory & Eviction Policy — Explicit
maxmemory-policyconfiguration,INFO-based memory monitoring, and cache warmup/teardown strategy. - Zero-Downtime Key Rotation — Transactional rotation (create new → verify → expire old) with challenge-response handshake validation.
- High-Throughput Metrics Pipeline — Redis
INCR/HINCRBYcounters for request/rotation/failure metrics with periodic flush to an aggregator.
- ❌ Unencrypted transient storage layers (LRU cache entries with sensitive data must be encrypted)
- ❌ Monolithic state coupling outside the Express/Redis pipeline (Python
core/modules should be isolated as a sidecar or migrated to TypeScript) - ❌ Vendor lock-in proprietary dependencies lacking data rights compliance
MIT — © 2026 Sovereign Cypher-Tube.
The consolidated project roadmap lives in ROADMAP.md — the four build priorities (#463–#465) and the multi-platform distribution phases from PLATFORM_SHIP_PLAN.md. Current tag: v1.6.0-alpha.1.