Kore is a provider-neutral Kubernetes platform with a Node.js/TypeScript command
line. Desired state lives in infra/catalog, environment overlays, Helm charts,
Crossplane APIs, and policy/observability assets. kore coordinates Minikube,
Helm, kubectl, OpenTofu, and Kubernetes controllers without taking ownership of
their reconciliation loops.
mise install
mise exec -- npm --prefix tools/kore install
mise exec -- npm --prefix tools/kore test
mise exec -- npm --prefix tools/kore run test:opa
mise exec -- npm --prefix tools/kore run kore -- doctor --environment local
mise exec -- npm --prefix tools/kore run kore -- validate --environment local
mise exec -- npm --prefix tools/kore run kore -- local up --environment locallocal up starts/reuses the Minikube profile, reconciles the platform and local
trust, generates/reuses a local API token and syncs local secrets, builds each
locked application, publishes it to the in-cluster registry, signs and verifies
the registry digest, then deploys that exact digest. The token is stored at
.kore/state/reference-api-token with owner-only permissions and survives
local down --prune; it is never committed. Optional SOPS-encrypted local
secret documents can still be placed in infra/environments/local/secrets/.
It records per-machine image digests and its
local-only signing key under ignored .kore/ state; it does not edit the shared
release image lock. Local signatures have no Rekor entry and are not release
signatures. For a state-preserving teardown, run mise exec -- npm --prefix tools/kore run kore -- local down --environment local; this stops the cluster and tunnel without uninstalling
releases or deleting data. Add --prune to explicitly destroy the cluster and
purge retained data. platform up remains available when you want only platform
reconciliation, and kore tunnel start|status|stop manages the tunnel directly.
Status, validate, and render are read-only. Mutations require an explicit
environment and use the configured kube context, never the current kubectl
context. Direct destruction requires --yes; retained claims additionally
require --purge-data. local down --prune explicitly opts into both.
The local Gateway uses HTTPS port 8443. Port 443 is privileged inside the
Docker-backed Minikube node and cannot be exposed by a detached tunnel without
an interactive sudo prompt. The higher local port keeps the direct Minikube
tunnel fully automated; use https://kore.local:8443/ (or your route path).
Kore manages the detached minikube tunnel process for the explicit
kore-local profile:
# Start or reuse the tunnel after `platform up` has configured the Gateway
mise exec -- npm --prefix tools/kore run kore -- tunnel start --environment local
# Check both the managed process and its local listening port
mise exec -- npm --prefix tools/kore run kore -- tunnel status --environment local --json
# Stop the tunnel and remove its state
mise exec -- npm --prefix tools/kore run kore -- tunnel stop --environment localplatform up starts the tunnel after configuring the local Gateway and waits
for port 8443 to become reachable; local up does this automatically.
platform stop and platform destroy stop it automatically. A tunnel is
reported as running only when its process is alive and the configured port is
reachable. Stale tunnel processes are replaced on the next tunnel start.
Tunnel state is stored under .kore/state and should not be committed.
For the local profile, the focused cluster lifecycle commands are:
mise exec -- npm --prefix tools/kore run kore -- cluster status --environment local
mise exec -- npm --prefix tools/kore run kore -- cluster stop --environment local
mise exec -- npm --prefix tools/kore run kore -- cluster destroy --environment local --yes --purge-datacluster destroy is destructive. Omit --purge-data to preserve retained data;
the command will refuse to destroy a profile while retained data exists.
If a live integration or platform attempt fails, destroy the explicit local
profile before retrying from a clean cluster:
mise exec -- npm --prefix tools/kore run kore -- cluster destroy --environment local --yes --purge-datakore validate --environment <name> also checks that every application has
separate resources and workload charts with no provider-specific references.
The catalog and environment files intentionally use JSON-compatible YAML. This
makes schema failures deterministic before any cluster mutation while remaining
valid YAML for Helm/Kubernetes tooling. See infra/plans/1-initialize.md and
infra/plans/2-implementation.md for the lifecycle and capability contracts.