Boruna Enterprise Platform Overview
Boruna is a deterministic execution platform for enterprise AI workflows. It provides policy-gated, auditable workflow execution with built-in governance, replay, and compliance evidence generation.
Core Capabilities
Workflow Execution
- DAG-based workflow definitions with typed data flow between steps
- Topological execution ordering with dependency resolution
- Approval gates for human-in-the-loop review
- Retry policies for transient failures
- Budget enforcement per step and per workflow
Determinism Guarantees
- Same inputs + same workflow + same policy = identical outputs
- BTreeMap-based ordering throughout (no HashMap non-determinism)
- Capability-gated side effects — all IO is declared and controlled
- Record/replay support via EventLog
Policy Enforcement
- Capability allowlists: declare which side effects each step may use
- Budget limits: token and call count budgets per step
- Model allowlists: restrict which LLM models may be invoked
- Network allowlists: restrict outbound HTTP destinations
Audit Trail
- Hash-chained audit log: tamper-evident, append-only record of all decisions
- Evidence bundles: self-contained compliance artifacts per workflow run
- Bundle verification: cryptographic integrity checking of all artifacts
Architecture
workflow.json → Validator → Runner → Evidence Bundle
↓ ↓
Topological Per-step:
Sort Compile .ax → VM → Output
Policy check
Audit log entry
Crate Map
boruna-orchestrator— Workflow engine, audit system, evidence bundlesboruna-compiler— Compiles .ax source to bytecodeboruna-vm— Executes bytecode with capability gatingboruna-bytecode— Bytecode format and Value typesboruna-effect— LLM integration with budget trackingboruna-framework— App protocol (Elm architecture)boruna-tooling— Diagnostics, repair, trace-to-tests, templatesboruna-pkg— Package system with integrity verificationboruna-cli— Theborunacommand-line binary (workflow, evidence, lang, framework, trace2tests, …)boruna-mcp— MCP server binary exposing the toolchain to AI coding agents over stdioboruna-lsp— Language server for.axfiles (diagnostics, completion, formatting)
Workflow Lifecycle
- Define — Write
workflow.jsonwith steps, edges, policies - Validate —
boruna workflow validate <dir>checks DAG structure - Run —
boruna workflow run <dir> --policy <policy>executes steps - Record —
--recordflag generates evidence bundle - Verify —
boruna evidence verify <dir>checks bundle integrity - Replay — There is no workflow-level replay command. For a single
.axprogram,boruna run <file> --record <log.json>saves the VM event log andboruna replay <file> <log.json>re-runs the program (.axor.axbc) against the recorded capability results and reports whether the replayed event log matches.
Schema Versioning
Versioned formats and their version fields:
- Workflow definition:
schema_version: 1(required; unsupported versions are rejected) - Policy:
schema_version: 1 - Evidence bundle manifest:
schema_version: 1plusformat_version: "1.1"(readers accept any1.x, reject a different major) - VM event log (
EventLog):version: 2 - Audit log: no version field. A verifier detects the entry form per entry: 1.1 commitment-chain entries carry
content_sha256, legacy 1.0 entries do not