<?xml version="1.0" encoding="utf-8" standalone="yes"?><?xml-stylesheet type="text/xsl" href="https://projectious-work.github.io/ainfra/feed.xsl"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom"><channel><title>Documentation · ainfra</title><link>https://projectious-work.github.io/ainfra/docs/</link><description>Immutable, auditable infrastructure lifecycle orchestration.</description><language>en</language><lastBuildDate>Mon, 01 Jan 0001 00:00:00 +0000</lastBuildDate><atom:link href="https://projectious-work.github.io/ainfra/docs/" rel="self" type="application/rss+xml"/><item><title>Introduction</title><link>https://projectious-work.github.io/ainfra/docs/introduction/</link><pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate><guid>https://projectious-work.github.io/ainfra/docs/introduction/</guid><description>ainfra turns reusable infrastructure templates into repeatable, reviewable deployments. It validates explicit contracts, locks template content, and coordinates established provisioning and configuration tools.
Templates combine OpenTofu for infrastructure provisioning with Ansible for system configuration. ainfra verifies the boundary between lifecycle steps and retains sanitized evidence without …</description></item><item><title>Quick Start</title><link>https://projectious-work.github.io/ainfra/docs/quick-start/</link><pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate><guid>https://projectious-work.github.io/ainfra/docs/quick-start/</guid><description>The current alpha CLI can validate a local deployment, lock a local or Git template source, create a reviewed OpenTofu plan, and apply only that exact saved plan.
Install the latest release:
sh Copy curl -fsSL https://raw.githubusercontent.com/projectious-work/ainfra/v1.x-release/scripts/install.sh | bash If ~/.local/bin is not already on PATH, add it before continuing. See Installation for …</description></item><item><title>Installation</title><link>https://projectious-work.github.io/ainfra/docs/installation/</link><pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate><guid>https://projectious-work.github.io/ainfra/docs/installation/</guid><description>ainfra publishes archives for Linux and macOS on amd64 and arm64. The official installer detects the current platform, downloads the matching release, verifies its published checksum, and installs the binary:
sh Copy curl -fsSL https://raw.githubusercontent.com/projectious-work/ainfra/v1.x-release/scripts/install.sh | bash The default destination is ~/.local/bin. Ensure that directory is on PATH, …</description></item><item><title>Configuration</title><link>https://projectious-work.github.io/ainfra/docs/configuration/</link><pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate><guid>https://projectious-work.github.io/ainfra/docs/configuration/</guid><description>ainfra combines immutable, typed configuration layers without changing a deployment or template. From lowest to highest precedence, the layers are:
compiled defaults; system configuration; user configuration; deployment-local ainfra.config.yaml; an explicit --config file or AINFRA_CONFIG; and supported environment variables and command options. On Linux, the system and user files are …</description></item><item><title>Output, inventory, and Ansible</title><link>https://projectious-work.github.io/ainfra/docs/output-inventory-ansible/</link><pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate><guid>https://projectious-work.github.io/ainfra/docs/output-inventory-ansible/</guid><description>Validate OpenTofu output and configure hosts from a reviewed run.</description></item><item><title>Hetzner private K3s template</title><link>https://projectious-work.github.io/ainfra/docs/hetzner-k3s-template/</link><pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate><guid>https://projectious-work.github.io/ainfra/docs/hetzner-k3s-template/</guid><description>Phase 9 ships the live-certified provider-backed production candidate at templates/hetzner-kubernetes-baseline in v1.0.0-alpha.9.
It combines ownership-labelled Hetzner infrastructure, private management addresses, initial pinned K3s bootstrap, an externally managed Cloudflare Tunnel, and an optional temporary SSH bastion. It does not install workloads or provide day-two Kubernetes operations. …</description></item><item><title>Usage</title><link>https://projectious-work.github.io/ainfra/docs/usage/</link><pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate><guid>https://projectious-work.github.io/ainfra/docs/usage/</guid><description>The current alpha CLI validates local contracts, diagnoses deployments, resolves immutable local or Git template sources, creates and executes reviewed OpenTofu plans, configures hosts through Ansible, and retains sanitized lifecycle evidence. Static help and version inspection do not perform project discovery, network access, or child-tool execution:
sh Copy ainfra help ainfra help version ainfra …</description></item><item><title>Guarded MCP server</title><link>https://projectious-work.github.io/ainfra/docs/mcp/</link><pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate><guid>https://projectious-work.github.io/ainfra/docs/mcp/</guid><description>ainfra can serve its typed application operations to MCP clients over stdio. The server is bound to one deployment at startup, is read-only by default, and never treats tool annotations or conversational claims as authorization.
Start a read-only server#Run the server from a deployment directory:
sh Copy ainfra mcp serve --stdio Or bind it explicitly:</description></item><item><title>Templates</title><link>https://projectious-work.github.io/ainfra/docs/templates/</link><pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate><guid>https://projectious-work.github.io/ainfra/docs/templates/</guid><description>Templates are self-contained, reviewable infrastructure environments for specific AI-agent workloads. Phase 8 defines the released authoring contract; Phase 9 ships the first provider-backed production candidate after offline conformance and a cost-approved disposable live certification.
Hetzner private K3s production candidate#templates/hetzner-kubernetes-baseline provisions private-management …</description></item><item><title>AI template-authoring guide</title><link>https://projectious-work.github.io/ainfra/docs/template-authoring-ai/</link><pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate><guid>https://projectious-work.github.io/ainfra/docs/template-authoring-ai/</guid><description>This is the self-contained execution entry point for an AI agent authoring an ainfra v1 template. It is a conformance workflow, not permission to provision a live environment.
Objective#Produce a portable template whose ainfra documents, native OpenTofu and optional Ansible content can be validated from a clean room. Do not invent an ainfra variable language, generate credentials, contact a …</description></item><item><title>Reviewed OpenTofu Plans</title><link>https://projectious-work.github.io/ainfra/docs/reviewed-plans/</link><pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate><guid>https://projectious-work.github.io/ainfra/docs/reviewed-plans/</guid><description>ainfra separates OpenTofu planning from infrastructure mutation. plan creates a private saved plan and immutable review record. apply requires the exact run ID and executes only those saved bytes.
Prerequisites#The deployment must have a valid ainfra.yaml, a current ainfra.lock, and a verified template cache entry. OpenTofu is discovered only when plan or apply runs. Pin an explicit executable in …</description></item><item><title>References</title><link>https://projectious-work.github.io/ainfra/docs/references/</link><pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate><guid>https://projectious-work.github.io/ainfra/docs/references/</guid><description>Doctor commands# text Copy ainfra doctor [TARGET] ainfra doctor all [TARGET] ainfra doctor environment ainfra doctor deployment [TARGET] ainfra doctor template [LOCAL_TEMPLATE] ainfra doctor run [TARGET] Bare doctor is an exact alias of doctor all. The aggregate selects the applicable environment, deployment, already-resolved template, and latest-run checks. Missing optional evidence is skip, …</description></item><item><title>Tutorials</title><link>https://projectious-work.github.io/ainfra/docs/tutorials/</link><pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate><guid>https://projectious-work.github.io/ainfra/docs/tutorials/</guid><description>Validate a template in a clean room#Copy the reference template, make only the required local edits, then run:
sh Copy ainfra doctor template . --format json ./tests/validate.sh The first command validates the portable authoring contract. The test script runs the compatible native tool checks and fixture assertions. Do not create cloud resources as part of this tutorial: live lifecycle work …</description></item><item><title>Contributing</title><link>https://projectious-work.github.io/ainfra/docs/contributing/</link><pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate><guid>https://projectious-work.github.io/ainfra/docs/contributing/</guid><description>Contributions to ainfra should begin with the repository&rsquo;s contribution and security guidance.
The complete development workflow is maintained in the repository CONTRIBUTING.md .
The release command boundary is strict. All release lanes must first point to one exact commit; release-freeze records that commit and tree before any artifact production:</description></item><item><title>Roadmap</title><link>https://projectious-work.github.io/ainfra/docs/roadmap/</link><pubDate>Mon, 01 Jan 0001 00:00:00 +0000</pubDate><guid>https://projectious-work.github.io/ainfra/docs/roadmap/</guid><description>The ainfra v1 roadmap begins with the core lifecycle and expands through hardening, templates, integrations, and release readiness. It is generated directly from the authoritative specification.
Total23Shipped10Idea13 Confidential infrastructure attested platforms and confidential secret release
Phase 22 ◇ Idea Confidential computing and live attestation Provision and describe …</description></item></channel></rss>