C10:OS_ ← the spine
What has been built

Rooms with something running in them.

A room is one project: its own repository, its own address, its own paper trail. Of roughly ninety of them, about forty hold a real running application and about eighteen are deployed to a public address. The rest are scaffolding, spec-stage, or retired — and saying so is more useful than a number that counts empty directories.

Everything below is described by what it does. Client and customer work is named by function only; none of it identifies a company or a person.

~90
rooms
~40
running apps
~18
publicly deployed
39
graduated

As of 2026-08-20.

Field and operations

Software for people who aren't at a desk.

Fire-safety inspection app

A technician scans an asset's QR code, runs the inspection, captures photos and a customer signature, and the system renders and archives a PDF certificate. The field entry point is deliberately auth-free — it shares a hostname with a single-sign-on office dashboard, because a technician on a ladder should not be typing a password. Three environments; each deploy emails its own patch notes, generated by diffing the source.

Live

Cafe and function-venue operations

Counter ordering through to end-of-day close-out, with station routing: bar items go to a bar screen, kitchen items to a kitchen screen, and a wall display runs the menu. Five surfaces, one per person who works there.

Live

Commercial cleaning back-office

Bids, invoices, routes, compliance, inventory and KPIs for a janitorial contractor — 205 API routes over a 51-table schema. The unglamorous end of business software, which is most of it.

Running

Journey-management and driver safety

Planning and monitoring work journeys across an API, a web console, and a native mobile app with background geolocation. Its audit log is hash-chained and verified hourly by a separate job, so tampering shows up without anyone going looking.

Prototype

Building-permit lead engine

Reads municipal permit filings across four metros and turns them into contractor sales leads, with a CRM on top. One adapter per city, so a new metro is onboarded by writing an adapter rather than a new product.

Dormant
Health and care

Where being wrong is expensive.

At-home screening platform

A phone app reads an at-home test kit and returns a stop-light risk score and a next step; clinicians get their own dashboard. Every piece of clinical logic is server-side, versioned and audited, and each production-write gate stays held down until it is explicitly signed off on a ledger. Multi-language, written for low health literacy.

Live

Medication tracker

Dose scheduling and adherence, with meal-relative timing — "30 minutes after breakfast" re-anchors the moment you tap that you're eating, instead of pretending everyone eats at 8:00.

Live

Caregiver behaviour co-pilot

Parents and carers log a behaviour incident and get help reading it, against a curated catalogue of behaviour codes users can't edit — because a shared vocabulary is the whole value. Design rule: every step readable in one breath, decidable in one tap.

Live
Education, events, commerce

Things with a date or a price on them.

School management system

Admissions, attendance, fees, exams and a parent portal — 332 of 336 requirements covered, 117 migrations, ~2,200 tests. The test suite is barred from running between 21:00 and 07:00, because it would send real notifications to real parents.

Live

Youth sports coaching

Watch a clip, record a practice rep, submit it, get graded — with the next skill locked until the last one passes. No backend at all; everything lives on the device.

Live

Local makers' marketplace

Makers subscribe monthly, list handmade goods, and get a public storefront. The north star was measurable: a non-technical seller lists their first product on a phone in under three minutes.

Live

Event ticketing with deposits

Card payment, QR ticket, scanner on the door — plus a deposit lane for the next, undated event: guests pay to hold a spot and a door tool settles the balance once the next date and price exist.

Archived

Subscription reference tool

A controlled-language dictionary for technical writers, with a three-tier ladder: anonymous visitors get fifty words, free accounts get the letter A, subscribers get everything. Two switchable corpora of ~2,000 entries load into memory at boot.

Running
Capture and everyday tools

Small apps that do one thing.

Family admin capture

A week-long instrument that logs every piece of school and family paperwork as it arrives, then produces a report on day seven. Registered as a share target, so a parent shares a screenshot straight in from any app. Offline-only by design.

Live

Product rating and catalogue

A phone-first rating app over a browsable catalogue. Its imagery syncs to a data volume rather than being baked into the image, so updating the catalogue doesn't mean rebuilding the app.

Live

Decision assistant

Standing in a shop or in front of a menu, you capture the shelf in one field — text, photo, or description — and get a pick, two or three alternates, why they fit, and what to avoid. The profile learns from every choice, and the scope contract aggressively excludes everything an app like this usually drifts into.

Prototype

Personal library tracker

Physical and digital books in one catalogue: an ISBN autofills the metadata and cover, and page-count and percentage sliders stay in sync — hitting 100% marks the book read.

Running

Sliding form builder

One question per screen, autosave, review and export. Its flagship template is a briefing form that exports Markdown written to eliminate the back-and-forth on a build request.

Running
The platform itself

Built with the same machinery.

The system's own infrastructure lives in rooms too, under the same rules — which is the honest test of whether the rules work.

Team hub and builder console

CRM, project builder, publisher, bounties and deploy announcements in one place. The largest codebase here, and the integration point other rooms call into with a service token.

Live

Egress gate and blind broker

The privacy perimeter: policy decides what leaves, and no model call may sit on the egress path. The broker exposes exactly four tools — adding a fifth that touches data is defined as a security incident, not a feature request.

Running

Browser-native builder gateway

Approved builders type a prompt in a web page; the system creates the room and drives a persistent host session. They never see a terminal and never install anything.

Running

UI verification runner

Other rooms invoke it to click through a build before release. It returns a defined result contract, and failures feed back into a repair loop rather than a report nobody reads.

Running

Self-hosted git and history browser

Code hosting and CI on our own hardware, with a web browser over the decision history — so the record has somewhere to live that isn't somebody else's platform.

Live

Ambient TV channel

An operations dashboard on a living-room TV. Because that platform bans web views, the server renders each slide as a headless-browser image and the TV simply plays pictures, refreshed four times a day.

Running

Internal points economy

Ledger, wallet, mint, treasury and exchange across several rooms: work is posted with a price, verified, and paid. An append-only log is the source of truth and the database is only a derived index — one state, never two.

Running
Not everything here is a success story. Two of the apps above are archived because their event happened; one lead engine is dormant; roughly twenty-five rooms never grew past scaffolding or spec. Rooms are cheap on purpose — the cost of an idea that doesn't work out should be a directory, not a quarter.
The stack

Boring on purpose.

There is a house default for every layer, and rooms are expected to take it unless they have a reason not to. The point isn't that these are the best tools in the world — it's that a system where every project picks its own stack cannot be operated by one small team. Deviations exist and are visible; several came in with imported codebases rather than being chosen.

Commands

Fish, and just

The spine is written in fish: every c10 <verb> is a shell function — fleet, deploy, gates, the reason chain. It is the largest body of first-party code here.

Roughly one hundred rooms carry a justfile exposing the same verbs: dev, build, test, publish, deploy. It's the most universal convention in the codebase, and it's why a room you've never opened is still operable.

Frontend

Vite, plain modules, hand-written CSS

No framework by default. Twenty-eight rooms build with Vite; a dozen are the canonical shape of index.html plus src/main.js with Vite as the only dependency.

React never appears at a room's root — only inside imported or special-purpose sub-projects. No Vue, Svelte, or Next.js anywhere. Shared tokens, themes and components are served centrally rather than copied.

Backend

Two defaults, split by job

A web app scaffolds to Bun — its own server, built-ins, rarely a framework (~17 rooms). An API service scaffolds to FastAPI with uv (~25 rooms). The scaffolder encodes both, so the choice is made once rather than argued per project.

No Flask, no Django. Express appears only in two imported codebases.

Data

SQLite, and append-only logs

SQLite is the default store in ~35 rooms, usually through the plain driver — ORMs are the exception, not the rule. Postgres appears only in larger imported projects.

Beside it, append-only JSONL carries anything that must never be rewritten: the reason chain, deploys, lifecycle, evidence. Where both exist, the log is the source of truth and the database is a derived index.

Deploy

Own hardware, one front door

A small Mac fleet, containers on OrbStack at a predictable port per room, and launchd as the supervisor — 79 agents keeping services, tunnels and scheduled jobs alive. A private mesh links the nodes.

Public addresses go through one Cloudflare tunnel: a single script adds the ingress rule, the DNS record, and an email-gated access policy in one call. No dashboard clicking. Static builds publish through the shared gallery server instead of each room running its own.

Agents

The CLI, not an SDK

The main integration is the coding CLI itself — rooms shell out to it, and the hub runs it inside its own container for automated work. The Python SDK appears where a service needs direct model calls; it isn't the default path.

Capability is packaged as skills and slash commands — scaffold a room, onboard it, deploy it, publish it — plus scout, lint and verify subagents. It is deliberately not single-vendor: a second coding CLI ships in the same image.

Verification

Gates, not vibes

bun test for JavaScript, pytest for Python — coverage is honestly uneven across rooms. Browser-driven checks run where they earn their keep rather than everywhere.

The distinctive part is the gates: a 13-point certification a room must pass to graduate, producing a hashed diploma; a build gate on every push; a software bill of materials emitted as a hard build step; guardrail hooks on destructive commands; and a sealed evidence record written at the end of every session.

One honest note from writing this page: the survey that produced it found a slash command still pointing at design-system files that no longer exist. Documentation rots faster than code, which is the argument for generating pages like this one from the system rather than from memory — and the reason the counts above carry a date.

Stack survey run 2026-08-20 against the working tree.