Use this catalog for Registryctl preflight, shared bundle verification, Relay activation, and
Notary activation codes. Each product owns its closed code definitions and static guidance.
The generated reference aggregates those definitions without copying runtime errors or values.
This page is generated from product-owned static definitions. It does not inspect a project, environment variables, secrets, runtime configuration, source responses, or country values.
rejected_binding
The bundle binding does not match the intended runtime target.
- Family
- bundle verification
- Product and owner
- registry platform ops; registry platform ops
- Phase
- bundle verification
- Rule
registry.platform.bundle_verification.binding_matches_target- Safe remediation
- Use a bundle issued for the intended runtime binding.
- Evidence scope
- signed bundle and configured runtime binding
- Evidence limitation
- The category does not disclose received or configured binding values.
- Value policy
- no runtime values
- Lifecycle
- unreleased, not released
rejected_rollback
The bundle or override does not satisfy local anti-rollback requirements.
- Family
- bundle verification
- Product and owner
- registry platform ops; registry platform ops
- Phase
- bundle activation
- Rule
registry.platform.bundle_verification.rollback_constraints_satisfied- Safe remediation
- Use a monotonic bundle or an authorized break-glass selection.
- Evidence scope
- local anti-rollback state and bundle or override metadata
- Evidence limitation
- The category does not disclose stored sequences, content digests, paths, or approval values.
- Value policy
- no runtime values
- Lifecycle
- unreleased, not released
rejected_signature
Bundle authenticity or declared content integrity verification failed.
- Family
- bundle verification
- Product and owner
- registry platform ops; registry platform ops
- Phase
- bundle verification
- Rule
registry.platform.bundle_verification.signature_and_integrity_accepted- Safe remediation
- Rebuild and sign the complete bundle with an accepted trust configuration.
- Evidence scope
- bundle trust metadata, signature envelope, file closure, and content digests
- Evidence limitation
- The category does not disclose signer identifiers, file names, or content digests.
- Value policy
- no runtime values
- Lifecycle
- unreleased, not released
rejected_validation
The bundle or acceptance metadata is missing, unreadable, malformed, or unsupported.
- Family
- bundle verification
- Product and owner
- registry platform ops; registry platform ops
- Phase
- bundle verification
- Rule
registry.platform.bundle_verification.input_is_valid- Safe remediation
- Regenerate the bundle and acceptance metadata using supported formats.
- Evidence scope
- bundle encoding, manifest, acceptance metadata, and required local inputs
- Evidence limitation
- The category does not disclose parser messages, local paths, or supplied values.
- Value policy
- no runtime values
- Lifecycle
- unreleased, not released
notary.cel.worker_unavailable
Registry Notary CEL worker is unavailable
- Family
- notary activation
- Product and owner
- registry notary; registry notary
- Phase
- runtime activation
- Rule
Every configured CEL worker must complete the bounded product protocol probe before listeners serve- Safe remediation
- verify that the adjacent CEL worker artifact is present and executable, confirm the supported platform and configured resource ceilings, then retry activation
- Evidence scope
- CEL worker packaging, protocol responsiveness, supported platform, and bounded startup capacity
- Evidence limitation
- The category confirms only the failed activation boundary; it does not disclose paths, URLs, hashes, credentials, identifiers, parser text, authored values, source responses, or country values.
- Value policy
- no runtime values
- Lifecycle
- unreleased, not released
notary.configuration.invalid
Registry Notary runtime configuration is invalid
- Family
- notary activation
- Product and owner
- registry notary; registry notary
- Phase
- configuration activation
- Rule
Runtime activation requires valid product configuration, supported features, and resolvable secret and provider bindings- Safe remediation
- run registry-notary doctor, correct the reviewed configuration or binding, and retry activation
- Evidence scope
- Notary configuration, provider bindings, and compiled feature support
- Evidence limitation
- The category confirms only the failed activation boundary; it does not disclose paths, URLs, hashes, credentials, identifiers, parser text, authored values, source responses, or country values.
- Value policy
- no runtime values
- Lifecycle
- unreleased, not released
notary.deployment.gate_failed
Registry Notary deployment gates refused startup
- Family
- notary activation
- Product and owner
- registry notary; registry notary
- Phase
- deployment activation
- Rule
Every startup-failing deployment gate must pass before activation- Safe remediation
- run registry-notary doctor for the selected deployment profile and resolve its startup-failing findings
- Evidence scope
- selected deployment profile and startup-failing gate results
- Evidence limitation
- The category confirms only the failed activation boundary; it does not disclose paths, URLs, hashes, credentials, identifiers, parser text, authored values, source responses, or country values.
- Value policy
- no runtime values
- Lifecycle
- unreleased, not released
notary.relay.activation_failed
Relay consultation activation failed
- Family
- notary activation
- Product and owner
- registry notary; registry notary
- Phase
- relay activation
- Rule
Registry-backed claims require the reviewed Relay consultation client to activate before Notary serves- Safe remediation
- check the Notary configuration and startup environment
- Evidence scope
- Notary Relay consultation client activation lifecycle
- Evidence limitation
- The category confirms only the failed activation boundary; it does not disclose paths, URLs, hashes, credentials, identifiers, parser text, authored values, source responses, or country values.
- Value policy
- no runtime values
- Lifecycle
- unreleased, not released
notary.relay.configuration_invalid
Relay consultation configuration is invalid
- Family
- notary activation
- Product and owner
- registry notary; registry notary
- Phase
- relay activation
- Rule
The Relay destination, activation plan, and activation lifecycle must form one valid reviewed configuration- Safe remediation
- check the evidence.relay connection and Registry-backed consultation configuration
- Evidence scope
- Relay destination, activation plan, and consultation configuration
- Evidence limitation
- The category confirms only the failed activation boundary; it does not disclose paths, URLs, hashes, credentials, identifiers, parser text, authored values, source responses, or country values.
- Value policy
- no runtime values
- Lifecycle
- unreleased, not released
notary.relay.credential_unavailable
Relay workload credential is unavailable
- Family
- notary activation
- Product and owner
- registry notary; registry notary
- Phase
- relay activation
- Rule
A current non-empty workload credential must be available before a live Relay consultation- Safe remediation
- mount a current readable workload JWT at evidence.relay.token_file
- Evidence scope
- configured Relay workload credential availability
- Evidence limitation
- The category confirms only the failed activation boundary; it does not disclose paths, URLs, hashes, credentials, identifiers, parser text, authored values, source responses, or country values.
- Value policy
- no runtime values
- Lifecycle
- unreleased, not released
notary.relay.credentials_rejected
Relay rejected the configured workload credential
- Family
- notary activation
- Product and owner
- registry notary; registry notary
- Phase
- relay activation
- Rule
Relay must accept the configured Notary workload binding, scope, and validity window- Safe remediation
- rotate the workload JWT and verify that Relay recognizes its workload binding, required scope, and validity window
- Evidence scope
- Relay workload binding, scope, and validity acceptance
- Evidence limitation
- The category confirms only the failed activation boundary; it does not disclose paths, URLs, hashes, credentials, identifiers, parser text, authored values, source responses, or country values.
- Value policy
- no runtime values
- Lifecycle
- unreleased, not released
notary.relay.profile_mismatch
Relay consultation profile does not match the configured contract pin
- Family
- notary activation
- Product and owner
- registry notary; registry notary
- Phase
- relay activation
- Rule
The active Relay profile must match the reviewed Notary consultation contract pin- Safe remediation
- reconcile the Notary profile id and contract hash with the reviewed Relay consultation contract
- Evidence scope
- reviewed Notary profile pin and active Relay consultation contract
- Evidence limitation
- The category confirms only the failed activation boundary; it does not disclose paths, URLs, hashes, credentials, identifiers, parser text, authored values, source responses, or country values.
- Value policy
- no runtime values
- Lifecycle
- unreleased, not released
notary.relay.profile_not_found
Relay consultation profile was not found
- Family
- notary activation
- Product and owner
- registry notary; registry notary
- Phase
- relay activation
- Rule
Every Registry-backed Notary consultation must resolve to an active Relay profile- Safe remediation
- deploy the configured Relay profile id, then retry the live check
- Evidence scope
- configured consultation profile resolution in Relay
- Evidence limitation
- The category confirms only the failed activation boundary; it does not disclose paths, URLs, hashes, credentials, identifiers, parser text, authored values, source responses, or country values.
- Value policy
- no runtime values
- Lifecycle
- unreleased, not released
notary.relay.unavailable
Relay consultation service is unavailable
- Family
- notary activation
- Product and owner
- registry notary; registry notary
- Phase
- relay activation
- Rule
The reviewed Relay destination must be reachable through the configured transport policy- Safe remediation
- check Relay reachability, TLS, destination policy, and service health
- Evidence scope
- reviewed Relay destination, transport policy, and service availability
- Evidence limitation
- The category confirms only the failed activation boundary; it does not disclose paths, URLs, hashes, credentials, identifiers, parser text, authored values, source responses, or country values.
- Value policy
- no runtime values
- Lifecycle
- unreleased, not released
notary.runtime.activation_failed
Registry Notary runtime activation failed
- Family
- notary activation
- Product and owner
- registry notary; registry notary
- Phase
- runtime activation
- Rule
Audit, state, sensitive-state, and other runtime dependencies must activate successfully before listeners serve- Safe remediation
- restore the governed runtime dependency or integrity condition, then retry activation
- Evidence scope
- governed audit, state, sensitive-state, and runtime dependencies
- Evidence limitation
- The category confirms only the failed activation boundary; it does not disclose paths, URLs, hashes, credentials, identifiers, parser text, authored values, source responses, or country values.
- Value policy
- no runtime values
- Lifecycle
- unreleased, not released
notary.runtime.activation_required
Registry Notary runtime activation is required before serving
- Family
- notary activation
- Product and owner
- registry notary; registry notary
- Phase
- runtime activation
- Rule
Routers may be built only after the governed audit and state activation lifecycle completes- Safe remediation
- run the compiled Registry Notary runtime activation step before building or serving routers
- Evidence scope
- router assembly and governed audit and state activation lifecycle
- Evidence limitation
- The category confirms only the failed activation boundary; it does not disclose paths, URLs, hashes, credentials, identifiers, parser text, authored values, source responses, or country values.
- Value policy
- no runtime values
- Lifecycle
- unreleased, not released
notary.state.postgresql.database_read_only
Registry Notary PostgreSQL state database is read-only or recovering
- Family
- notary activation
- Product and owner
- registry notary; registry notary
- Phase
- runtime activation
- Rule
Serving requires a writable PostgreSQL primary for correctness-state transactions- Safe remediation
- restore a writable PostgreSQL primary, run registry-notary state doctor, and retry activation
- Evidence scope
- PostgreSQL writeability and recovery posture
- Evidence limitation
- The category confirms only the failed activation boundary; it does not disclose paths, URLs, hashes, credentials, identifiers, parser text, authored values, source responses, or country values.
- Value policy
- no runtime values
- Lifecycle
- unreleased, not released
notary.state.postgresql.database_unavailable
Registry Notary PostgreSQL state database is unavailable
- Family
- notary activation
- Product and owner
- registry notary; registry notary
- Phase
- runtime activation
- Rule
Serving requires a reachable PostgreSQL service with an accepted TLS trust chain- Safe remediation
- check PostgreSQL reachability, TLS trust, and service health, then run registry-notary state doctor
- Evidence scope
- PostgreSQL transport, TLS trust, and service availability
- Evidence limitation
- The category confirms only the failed activation boundary; it does not disclose paths, URLs, hashes, credentials, identifiers, parser text, authored values, source responses, or country values.
- Value policy
- no runtime values
- Lifecycle
- unreleased, not released
notary.state.postgresql.database_unsupported
Registry Notary PostgreSQL server major is unsupported
- Family
- notary activation
- Product and owner
- registry notary; registry notary
- Phase
- runtime activation
- Rule
Serving requires a PostgreSQL major covered by the Registry Notary compatibility contract- Safe remediation
- move the state database to a supported PostgreSQL major, run registry-notary state doctor, and retry activation
- Evidence scope
- PostgreSQL server-major compatibility
- Evidence limitation
- The category confirms only the failed activation boundary; it does not disclose paths, URLs, hashes, credentials, identifiers, parser text, authored values, source responses, or country values.
- Value policy
- no runtime values
- Lifecycle
- unreleased, not released
notary.state.postgresql.durability_unsafe
Registry Notary PostgreSQL durability settings are unsafe
- Family
- notary activation
- Product and owner
- registry notary; registry notary
- Phase
- runtime activation
- Rule
Serving requires the documented PostgreSQL durability settings for correctness state- Safe remediation
- restore the required PostgreSQL durability settings, run registry-notary state doctor, and retry activation
- Evidence scope
- PostgreSQL durability posture
- Evidence limitation
- The category confirms only the failed activation boundary; it does not disclose paths, URLs, hashes, credentials, identifiers, parser text, authored values, source responses, or country values.
- Value policy
- no runtime values
- Lifecycle
- unreleased, not released
notary.state.postgresql.role_incompatible
Registry Notary PostgreSQL runtime role contract is incompatible
- Family
- notary activation
- Product and owner
- registry notary; registry notary
- Phase
- runtime activation
- Rule
Serving requires the documented restricted runtime role and its attested schema binding- Safe remediation
- restore the documented runtime grants and role binding, run registry-notary state doctor, and retry activation
- Evidence scope
- PostgreSQL runtime-role attributes, grants, and schema binding
- Evidence limitation
- The category confirms only the failed activation boundary; it does not disclose paths, URLs, hashes, credentials, identifiers, parser text, authored values, source responses, or country values.
- Value policy
- no runtime values
- Lifecycle
- unreleased, not released
notary.state.postgresql.schema_incompatible
Registry Notary PostgreSQL state schema contract is incompatible
- Family
- notary activation
- Product and owner
- registry notary; registry notary
- Phase
- runtime activation
- Rule
Serving requires the exact product-owned schema, catalog, fingerprint, and privilege contract- Safe remediation
- restore or install the matching Registry Notary state schema, run registry-notary state doctor, and retry activation
- Evidence scope
- PostgreSQL state schema, catalog, fingerprint, and privilege contract
- Evidence limitation
- The category confirms only the failed activation boundary; it does not disclose paths, URLs, hashes, credentials, identifiers, parser text, authored values, source responses, or country values.
- Value policy
- no runtime values
- Lifecycle
- unreleased, not released
registryctl.preflight.product_validator_not_checked
A required linked product validator was not checked locally.
- Family
- operator preflight
- Product and owner
- registryctl; registryctl
- Phase
- product capability
- Rule
registryctl.preflight.product_validator_locally_available- Safe remediation
- Enable the linked product validator.
- Evidence scope
- offline local operator preflight
- Evidence limitation
- Preflight does not contact live sources or prove remote availability.
- Value policy
- no runtime values
- Lifecycle
- unreleased, not released
registryctl.preflight.report_capacity_exceeded
The preflight report reached its deterministic safety cap.
- Family
- operator preflight
- Product and owner
- registryctl; registryctl
- Phase
- report boundary
- Rule
registryctl.preflight.report_capacity- Safe remediation
- Reduce declared preflight inputs.
- Evidence scope
- offline local operator preflight
- Evidence limitation
- Preflight does not contact live sources or prove remote availability.
- Value policy
- no runtime values
- Lifecycle
- unreleased, not released
registryctl.preflight.runtime_file_empty
A declared runtime file is empty.
- Family
- operator preflight
- Product and owner
- registryctl; registryctl
- Phase
- runtime file posture
- Rule
registryctl.preflight.runtime_file_bounded_regular- Safe remediation
- Replace the runtime file.
- Evidence scope
- offline local operator preflight
- Evidence limitation
- Preflight does not contact live sources or prove remote availability.
- Value policy
- no runtime values
- Lifecycle
- unreleased, not released
- Static address pattern
<declared-field-address>
registryctl.preflight.runtime_file_missing
A declared runtime file is missing.
- Family
- operator preflight
- Product and owner
- registryctl; registryctl
- Phase
- runtime file posture
- Rule
registryctl.preflight.runtime_file_bounded_regular- Safe remediation
- Replace the runtime file.
- Evidence scope
- offline local operator preflight
- Evidence limitation
- Preflight does not contact live sources or prove remote availability.
- Value policy
- no runtime values
- Lifecycle
- unreleased, not released
- Static address pattern
<declared-field-address>
registryctl.preflight.runtime_file_not_checked
Runtime file posture could not be checked with the required local invariant.
- Family
- operator preflight
- Product and owner
- registryctl; registryctl
- Phase
- runtime file posture
- Rule
registryctl.preflight.runtime_file_posture_supported- Safe remediation
- Run preflight on a supported Unix platform.
- Evidence scope
- offline local operator preflight
- Evidence limitation
- Preflight does not contact live sources or prove remote availability.
- Value policy
- no runtime values
- Lifecycle
- unreleased, not released
- Static address pattern
<declared-field-address>
registryctl.preflight.runtime_file_not_regular
A declared runtime file is not an acceptable bounded regular file.
- Family
- operator preflight
- Product and owner
- registryctl; registryctl
- Phase
- runtime file posture
- Rule
registryctl.preflight.runtime_file_bounded_regular- Safe remediation
- Replace the runtime file.
- Evidence scope
- offline local operator preflight
- Evidence limitation
- Preflight does not contact live sources or prove remote availability.
- Value policy
- no runtime values
- Lifecycle
- unreleased, not released
- Static address pattern
<declared-field-address>
registryctl.preflight.runtime_file_unsafe_mode
A declared runtime file has unsafe local access permissions.
- Family
- operator preflight
- Product and owner
- registryctl; registryctl
- Phase
- runtime file posture
- Rule
registryctl.preflight.runtime_file_safe_mode- Safe remediation
- Tighten runtime file permissions.
- Evidence scope
- offline local operator preflight
- Evidence limitation
- Preflight does not contact live sources or prove remote availability.
- Value policy
- no runtime values
- Lifecycle
- unreleased, not released
- Static address pattern
<declared-field-address>
registryctl.preflight.runtime_file_unsafe_owner
A declared runtime file has an unsafe owner.
- Family
- operator preflight
- Product and owner
- registryctl; registryctl
- Phase
- runtime file posture
- Rule
registryctl.preflight.runtime_file_safe_owner- Safe remediation
- Set the runtime file owner.
- Evidence scope
- offline local operator preflight
- Evidence limitation
- Preflight does not contact live sources or prove remote availability.
- Value policy
- no runtime values
- Lifecycle
- unreleased, not released
- Static address pattern
<declared-field-address>
registryctl.preflight.secret_empty
A required secret reference contains only whitespace.
- Family
- operator preflight
- Product and owner
- registryctl; registryctl
- Phase
- secret availability
- Rule
registryctl.preflight.secret_reference_available- Safe remediation
- Provide a non-empty secret to the process environment.
- Evidence scope
- offline local operator preflight
- Evidence limitation
- Preflight does not contact live sources or prove remote availability.
- Value policy
- no runtime values
- Lifecycle
- unreleased, not released
- Static address pattern
<declared-field-address>
registryctl.preflight.secret_missing
A required secret reference is unavailable to this process.
- Family
- operator preflight
- Product and owner
- registryctl; registryctl
- Phase
- secret availability
- Rule
registryctl.preflight.secret_reference_available- Safe remediation
- Provide the secret to the process environment.
- Evidence scope
- offline local operator preflight
- Evidence limitation
- Preflight does not contact live sources or prove remote availability.
- Value policy
- no runtime values
- Lifecycle
- unreleased, not released
- Static address pattern
<declared-field-address>
registryctl.preflight.static_validation_not_checked
Required authoritative static validation was not completed.
- Family
- operator preflight
- Product and owner
- registryctl; registryctl
- Phase
- static validation
- Rule
registryctl.preflight.authoritative_static_validation- Safe remediation
- Complete authoritative static validation.
- Evidence scope
- offline local operator preflight
- Evidence limitation
- Preflight does not contact live sources or prove remote availability.
- Value policy
- no runtime values
- Lifecycle
- unreleased, not released
- Static address pattern
<project-field-address>
relay.consultation.activation.artifact_registry_invalid
Relay could not compile the verified consultation artifact registry.
- Family
- relay activation
- Product and owner
- registry relay; registry relay
- Phase
- consultation activation
- Rule
The verified artifact closure must compile into one closed registry without conflicting public profiles.- Safe remediation
- Rebuild and verify the exact consultation artifact closure before restarting Relay.
- Evidence scope
- verified consultation artifact closure and compiled public profiles
- Evidence limitation
- The category does not disclose paths, URLs, parser excerpts, hashes, credentials, identifiers, or authored values.
- Value policy
- no runtime values
- Lifecycle
- unreleased, not released
relay.consultation.activation.configuration_missing
Relay consultation activation requires configuration that is not present.
- Family
- relay activation
- Product and owner
- registry relay; registry relay
- Phase
- consultation activation
- Rule
The closed consultation configuration must exist before Relay compiles serving authority.- Safe remediation
- Provide a validated Relay consultation configuration and restart Relay.
- Evidence scope
- Relay consultation configuration and serving authority
- Evidence limitation
- The category does not disclose paths, URLs, parser excerpts, hashes, credentials, identifiers, or authored values.
- Value policy
- no runtime values
- Lifecycle
- unreleased, not released
relay.consultation.activation.protected_metadata_invalid
Relay could not construct bounded protected consultation metadata.
- Family
- relay activation
- Product and owner
- registry relay; registry relay
- Phase
- consultation activation
- Rule
Protected metadata must contain one strict bounded public contract and its reviewed binding.- Safe remediation
- Regenerate and verify the consultation artifact closure, then restart Relay.
- Evidence scope
- protected consultation metadata, public contract, and reviewed binding
- Evidence limitation
- The category does not disclose paths, URLs, parser excerpts, hashes, credentials, identifiers, or authored values.
- Value policy
- no runtime values
- Lifecycle
- unreleased, not released
relay.consultation.activation.pseudonym_material_unavailable
Relay could not activate the pseudonym material required for consultation audit evidence.
- Family
- relay activation
- Product and owner
- registry relay; registry relay
- Phase
- consultation activation
- Rule
The configured pseudonym material must be valid and bind to the current write authority.- Safe remediation
- Restore the reviewed pseudonym material and write authority, then restart Relay.
- Evidence scope
- consultation pseudonym material and current write authority
- Evidence limitation
- The category does not disclose paths, URLs, parser excerpts, hashes, credentials, identifiers, or authored values.
- Value policy
- no runtime values
- Lifecycle
- unreleased, not released
relay.consultation.activation.quota_limits_invalid
Relay could not activate the bounded consultation quota contract.
- Family
- relay activation
- Product and owner
- registry relay; registry relay
- Phase
- consultation activation
- Rule
Public and effective quota limits must remain representable, positive, and non-widening.- Safe remediation
- Correct the reviewed quota limits and rebuild the consultation artifacts.
- Evidence scope
- public and effective consultation quota limits
- Evidence limitation
- The category does not disclose paths, URLs, parser excerpts, hashes, credentials, identifiers, or authored values.
- Value policy
- no runtime values
- Lifecycle
- unreleased, not released
relay.consultation.activation.source_credentials_unavailable
Relay could not activate the source-credential capability required by the consultation registry.
- Family
- relay activation
- Product and owner
- registry relay; registry relay
- Phase
- consultation activation
- Rule
Every compiled source plan must have exactly the credential capability it declares.- Safe remediation
- Restore the reviewed source-credential references and restart Relay.
- Evidence scope
- compiled consultation source plans and credential capabilities
- Evidence limitation
- The category does not disclose paths, URLs, parser excerpts, hashes, credentials, identifiers, or authored values.
- Value policy
- no runtime values
- Lifecycle
- unreleased, not released
relay.consultation.activation.state_plane_unavailable
Relay could not activate the consultation state plane and its current authority.
- Family
- relay activation
- Product and owner
- registry relay; registry relay
- Phase
- consultation activation
- Rule
The state plane, durable audit boundary, quota state, and current write authority must activate together.- Safe remediation
- Restore the reviewed Relay state-plane dependencies and restart Relay.
- Evidence scope
- consultation state plane, audit boundary, quota state, and write authority
- Evidence limitation
- The category does not disclose paths, URLs, parser excerpts, hashes, credentials, identifiers, or authored values.
- Value policy
- no runtime values
- Lifecycle
- unreleased, not released
relay.consultation.activation.unsupported_plan
A compiled consultation plan requires a capability this Relay runtime cannot activate.
- Family
- relay activation
- Product and owner
- registry relay; registry relay
- Phase
- consultation activation
- Rule
Every plan, worker, transport, snapshot binding, and dispatch budget must use a compiled supported capability.- Safe remediation
- Use a Relay release that supports the reviewed plan or rebuild the plan with supported capabilities.
- Evidence scope
- compiled consultation plan and Relay runtime capabilities
- Evidence limitation
- The category does not disclose paths, URLs, parser excerpts, hashes, credentials, identifiers, or authored values.
- Value policy
- no runtime values
- Lifecycle
- unreleased, not released
relay.consultation.activation.workload_binding_invalid
The configured consultation workload binding is incompatible with Relay authentication.
- Family
- relay activation
- Product and owner
- registry relay; registry relay
- Phase
- consultation activation
- Rule
Issuer, audience, client binding, principal, and selector must satisfy the closed Relay workload contract.- Safe remediation
- Align the reviewed consultation workload binding with Relay authentication and restart Relay.
- Evidence scope
- consultation workload binding and Relay authentication contract
- Evidence limitation
- The category does not disclose paths, URLs, parser excerpts, hashes, credentials, identifiers, or authored values.
- Value policy
- no runtime values
- Lifecycle
- unreleased, not released
relay.startup.admin_listener_address_in_use
Relay could not open the administration listener because its binding is already in use.
- Family
- relay process startup
- Product and owner
- registry relay; registry relay
- Phase
- listener binding
- Rule
registry.relay.startup.admin_listener_binding_is_unused- Safe remediation
- Resolve the listener conflict for server.admin_bind in its owning deployment input; if generated, update the authored project and regenerate the Relay input, then retry.
- Evidence scope
- configured Relay administration listener and closed bind-failure category
- Evidence limitation
- The category names server.admin_bind and address-in-use status but does not disclose its address, port, or operating-system error.
- Value policy
- no runtime values
- Lifecycle
- unreleased, not released
relay.startup.admin_listener_permission_denied
Relay lacks permission to open the configured administration listener.
- Family
- relay process startup
- Product and owner
- registry relay; registry relay
- Phase
- listener binding
- Rule
registry.relay.startup.admin_listener_binding_is_permitted- Safe remediation
- Choose a permitted server.admin_bind and correct the service account or network policy in its owning deployment input; regenerate generated Relay input, then retry.
- Evidence scope
- configured Relay administration listener and closed bind-failure category
- Evidence limitation
- The category names server.admin_bind and permission-denied status but does not disclose its address, port, account identity, or operating-system error.
- Value policy
- no runtime values
- Lifecycle
- unreleased, not released
relay.startup.admin_listener_unavailable
Relay could not open the configured administration listener.
- Family
- relay process startup
- Product and owner
- registry relay; registry relay
- Phase
- listener binding
- Rule
registry.relay.startup.admin_listener_is_available- Safe remediation
- Check interface availability, address-family support, and deployment networking for server.admin_bind in its owning input; regenerate generated Relay input, then retry.
- Evidence scope
- configured Relay administration listener and closed bind-failure category
- Evidence limitation
- The fallback category names server.admin_bind but does not disclose its address, port, or operating-system error.
- Value policy
- no runtime values
- Lifecycle
- unreleased, not released
relay.startup.bundle_binding_rejected
The governed bundle does not match this Relay runtime target.
- Family
- relay process startup
- Product and owner
- registry relay; registry relay
- Phase
- bundle verification
- Rule
registry.relay.startup.bundle_binding_matches_runtime- Safe remediation
- Use a governed bundle issued for this Relay runtime target.
- Evidence scope
- governed bundle and Relay runtime binding
- Evidence limitation
- The category does not disclose configured or received binding values.
- Value policy
- no runtime values
- Lifecycle
- unreleased, not released
relay.startup.bundle_rollback_rejected
The governed bundle or override failed Relay anti-rollback checks.
- Family
- relay process startup
- Product and owner
- registry relay; registry relay
- Phase
- bundle activation
- Rule
registry.relay.startup.bundle_antirollback_satisfied- Safe remediation
- Use a monotonic governed bundle or an authorized break-glass selection.
- Evidence scope
- local anti-rollback state and governed bundle or override metadata
- Evidence limitation
- The category does not disclose sequences, hashes, paths, operators, or approval values.
- Value policy
- no runtime values
- Lifecycle
- unreleased, not released
relay.startup.bundle_signature_rejected
The governed bundle failed authenticity or content-integrity verification.
- Family
- relay process startup
- Product and owner
- registry relay; registry relay
- Phase
- bundle verification
- Rule
registry.relay.startup.bundle_authenticity_and_integrity_accepted- Safe remediation
- Rebuild and sign the complete bundle with an accepted trust configuration.
- Evidence scope
- bundle trust metadata, signature envelope, file closure, and content digests
- Evidence limitation
- The category does not disclose signer identifiers, file names, hashes, or trust-anchor values.
- Value policy
- no runtime values
- Lifecycle
- unreleased, not released
relay.startup.bundle_validation_rejected
The governed bundle or local acceptance metadata is invalid.
- Family
- relay process startup
- Product and owner
- registry relay; registry relay
- Phase
- bundle verification
- Rule
registry.relay.startup.bundle_inputs_are_valid- Safe remediation
- Regenerate the bundle and acceptance metadata using supported formats.
- Evidence scope
- bundle encoding, manifest, acceptance metadata, and required local inputs
- Evidence limitation
- The category does not disclose parser excerpts, local paths, hashes, identities, or supplied values.
- Value policy
- no runtime values
- Lifecycle
- unreleased, not released
relay.startup.config_deprecated_field_rejected
A Relay configuration document uses a field that the current runtime no longer accepts.
- Family
- relay process startup
- Product and owner
- registry relay; registry relay
- Phase
- config document validation
- Rule
registry.relay.startup.config_uses_current_fields- Safe remediation
- Compare the authored input with the current Relay schema and migration guidance, replace deprecated fields, regenerate generated Relay input, then retry.
- Evidence scope
- Relay configuration field names and the product-owned deprecated-field registry
- Evidence limitation
- The category does not disclose the configured field path, replacement, source path, or supplied values. Run authored-project validation for field-addressed guidance.
- Value policy
- no runtime values
- Lifecycle
- unreleased, not released
relay.startup.config_document_invalid
A Relay configuration or metadata document does not match its required syntax or typed schema.
- Family
- relay process startup
- Product and owner
- registry relay; registry relay
- Phase
- config document validation
- Rule
registry.relay.startup.config_document_is_typed- Safe remediation
- Compare the authored input with the current Relay schema, run authored-project validation when generated, correct the document, regenerate generated Relay input, then retry.
- Evidence scope
- Relay configuration and metadata document encoding, syntax, field grammar, and types
- Evidence limitation
- The category does not disclose parser excerpts, field paths, local paths, or supplied values. It does not claim field-level diagnostics were emitted.
- Value policy
- no runtime values
- Lifecycle
- unreleased, not released
relay.startup.config_environment_binding_rejected
A required Relay configuration environment binding could not be expanded safely.
- Family
- relay process startup
- Product and owner
- registry relay; registry relay
- Phase
- config environment expansion
- Rule
registry.relay.startup.config_environment_bindings_expand- Safe remediation
- Check the authored environment expressions and required deployment bindings, then run Relay doctor against the same configuration before retrying.
- Evidence scope
- Relay configuration environment expressions and deployment-provided bindings
- Evidence limitation
- The category does not disclose environment names, expansion errors, source paths, or supplied values. It does not claim field-level diagnostics were emitted.
- Value policy
- no runtime values
- Lifecycle
- unreleased, not released
relay.startup.config_source_unavailable
A required Relay configuration or metadata source could not be read.
- Family
- relay process startup
- Product and owner
- registry relay; registry relay
- Phase
- config loading
- Rule
registry.relay.startup.config_source_is_readable- Safe remediation
- Check the --config source and any configured metadata.source.path, restore readable input from its owner, regenerate generated Relay input instead of editing it in place, then retry.
- Evidence scope
- Relay configuration and metadata sources
- Evidence limitation
- The category does not disclose local paths, operating-system errors, or source contents.
- Value policy
- no runtime values
- Lifecycle
- unreleased, not released
relay.startup.config_validation_rejected
The parsed Relay configuration failed product validation.
- Family
- relay process startup
- Product and owner
- registry relay; registry relay
- Phase
- config validation
- Rule
registry.relay.startup.config_product_invariants_hold- Safe remediation
- Run the authored-project validator, correct its field-addressed issues and governed bindings, regenerate the Relay input, then retry.
- Evidence scope
- parsed Relay configuration and governed runtime bindings
- Evidence limitation
- The category does not disclose configured identifiers, URLs, environment names, hashes, or source values.
- Value policy
- no runtime values
- Lifecycle
- unreleased, not released
relay.startup.consultation_artifacts_rejected
The governed consultation artifact closure failed startup validation.
- Family
- relay process startup
- Product and owner
- registry relay; registry relay
- Phase
- consultation activation
- Rule
registry.relay.startup.consultation_artifact_closure_is_valid- Safe remediation
- Rebuild the complete hash-covered consultation artifact closure and retry.
- Evidence scope
- governed consultation artifact closure and runtime bindings
- Evidence limitation
- The category does not disclose artifact paths, hashes, selectors, identities, or parser excerpts.
- Value policy
- no runtime values
- Lifecycle
- unreleased, not released
relay.startup.data_listener_address_in_use
Relay could not open the data-plane listener because its binding is already in use.
- Family
- relay process startup
- Product and owner
- registry relay; registry relay
- Phase
- listener binding
- Rule
registry.relay.startup.data_listener_binding_is_unused- Safe remediation
- Resolve the listener conflict for server.bind in its owning deployment input; if generated, update the authored project and regenerate the Relay input, then retry.
- Evidence scope
- configured Relay data-plane listener and closed bind-failure category
- Evidence limitation
- The category names server.bind and address-in-use status but does not disclose its address, port, or operating-system error.
- Value policy
- no runtime values
- Lifecycle
- unreleased, not released
relay.startup.data_listener_permission_denied
Relay lacks permission to open the configured data-plane listener.
- Family
- relay process startup
- Product and owner
- registry relay; registry relay
- Phase
- listener binding
- Rule
registry.relay.startup.data_listener_binding_is_permitted- Safe remediation
- Choose a permitted server.bind and correct the service account or network policy in its owning deployment input; regenerate generated Relay input, then retry.
- Evidence scope
- configured Relay data-plane listener and closed bind-failure category
- Evidence limitation
- The category names server.bind and permission-denied status but does not disclose its address, port, account identity, or operating-system error.
- Value policy
- no runtime values
- Lifecycle
- unreleased, not released
relay.startup.data_listener_unavailable
Relay could not open the configured data-plane listener.
- Family
- relay process startup
- Product and owner
- registry relay; registry relay
- Phase
- listener binding
- Rule
registry.relay.startup.data_listener_is_available- Safe remediation
- Check interface availability, address-family support, and deployment networking for server.bind in its owning input; regenerate generated Relay input, then retry.
- Evidence scope
- configured Relay data-plane listener and closed bind-failure category
- Evidence limitation
- The fallback category names server.bind but does not disclose its address, port, or operating-system error.
- Value policy
- no runtime values
- Lifecycle
- unreleased, not released
relay.startup.doctor_failed
Relay doctor found one or more blocking diagnostics.
- Family
- relay process startup
- Product and owner
- registry relay; registry relay
- Phase
- operator diagnostics
- Rule
registry.relay.startup.doctor_has_no_blocking_diagnostics- Safe remediation
- Use the static diagnostic codes and actions in the doctor report.
- Evidence scope
- offline Relay readiness and deployment diagnostics
- Evidence limitation
- The process failure does not repeat diagnostic source values or report internals.
- Value policy
- no runtime values
- Lifecycle
- unreleased, not released
relay.startup.runtime_initialization_failed
Relay runtime initialization failed.
- Family
- relay process startup
- Product and owner
- registry relay; registry relay
- Phase
- runtime initialization
- Rule
registry.relay.startup.runtime_initializes- Safe remediation
- Review preceding static diagnostic codes, correct the runtime inputs, and retry.
- Evidence scope
- Relay runtime dependencies and protected startup capabilities
- Evidence limitation
- The category does not disclose inner errors, paths, URLs, identities, hashes, or supplied values.
- Value policy
- no runtime values
- Lifecycle
- unreleased, not released