about / v0.1.0

About systemd-sentry.

Design principles, architectural invariants, Unix philosophy, and systemd integration.

01The Genesis: Moving Beyond Blind Restarts

System supervision in Linux has historically been trapped between two extremes: either a crude Restart=always directive in a systemd unit file that blindly restarts a crashing service until system resources are exhausted, or an over-engineered observability stack requiring hundreds of megabytes of RAM, external agents, and complex network telemetry pipelines.

systemd-sentry was designed from first principles to bridge this gap: an autonomous, zero-trust host supervisor that detects failures in real time, extracts rich kernel and journal telemetry, synthesizes root cause diagnostics, and applies deterministic circuit breaking to permanently stop flapping failure storms.

02Unix Philosophy: Mechanism vs. Policy

Following classical Unix design principles codified by McIlroy, Thompson, and Ritchie:

03Linus Torvalds Pragmatism

Engineered for real-world production Linux servers with zero patience for bloat:

04systemd Design Alignment

systemd-sentry integrates as a native, first-class citizen of modern systemd environments:

05Codebase Architecture

The workspace is partitioned into specialized, single-responsibility crates with strict file length constraints (≤256 LOC per file):

systemd-sentry/
├── crates/
│   ├── sentry-core/        Domain models, cgroups v2, PSI, coredumps, error types
│   ├── sentry-driver/      Pure Rust socket activation, sd_notify, journal, D-Bus
│   ├── sentry-diagnostic/  LLM clients (routerd, llama.cpp, OpenAI) & fallback triage
│   ├── sentry-mcp/         Model Context Protocol stdio server for AI agents
│   └── sentry-safety/      Sliding-window circuit breaker & drop-in policy gatekeeper
├── qa/
│   ├── unit/               1:1 Unit QA test suite (200 tests)
│   ├── e2e/                4-tier E2E feature verification suite (87 tests)
│   ├── fixtures/           Crashing mock binaries (segfault, OOM, flapper)
│   └── fuzz/               cargo-fuzz targets (journal, D-Bus, PSI, triage)
├── systemd/                Unit files (.service, .socket, sysusers.d, tmpfiles.d, dbus-1)
└── site/                   Static documentation & GitHub Pages website