System architecture

Architecture in
service of trust.

Hubu decides whether agent spend is allowed. Gongbu performs provider work. One versioned contract connects them without merging credentials, state, or failure domains.

Interactive system map Executor contract v4.2 Unified MCP v1
02 · AUTHORIZE
hubu-system-map

Govern before execution

Hubu evaluates trusted identity, policy, targets, and budgets before it issues a scoped authorization.

HTTPexecutor contractv4.2
DEFINITIVE OUTCOME

allow · deny · needs approval

Every owner has one job.

Choose a component in the map or below. The guide keeps runtime ownership, operational responsibilities, and source together.

SYSTEM BOUNDARY

Separate by design

The repository and release are unified. The running systems are not. Hubu and Gongbu retain separate processes, state, credentials, and recovery paths.

INTERNAL FLOW

    Responsibilities

      Source & runbooks

      01

      Govern synchronously.

      Policy and budget decisions happen before external work starts, with canonical scope and retry-safe identity.

      02

      Execute separately.

      Provider credentials, workflows, artifacts, and retries stay inside Gongbu’s execution failure domain.

      03

      Reconcile explicitly.

      Receipts and settlement evidence tie execution back to authorizations without copying provider state into Hubu.