PLUGIN PLATFORM · CONTRACT V1 FROZEN

KFIF Plugin Platform

Extend KFIF without weakening the core. Build signed, permission-bounded integrations behind a frozen contract, verified package boundary and isolated process protocol.

Build a KFIF plugin

Core Stable, Everything Else Extensible

KFIF integrations can evolve without hardcoded coupling to core internals. Trust, licensing, signing, evidence, baseline, projection and audit semantics remain controlled by KFIF.

  1. 01KFIF Core
  2. 02Plugin Contract
  3. 03Package Verification
  4. 04Isolated Runtime
  5. 05Plugin Implementations

Plugin Contract v1

FROZEN

Contract v1 was frozen on 30 July 2026. Compatible clarifications remain possible, but breaking manifest, permission, lifecycle, IPC or trust changes require Contract v2.

This status does not claim production certification or broad third-party interoperability.

Verified packages

  • ZIP and TAR.GZ packages
  • complete-archive SHA-256 identity
  • canonical payload manifest hashes
  • Ed25519 publisher signatures
  • purpose-approved publisher trust
  • safe archive inspection and atomic installation
  • installed-disabled default

Isolated by design

  • execution outside the main KFIF process
  • bounded kfif-plugin-ipc/1.0 JSON
  • no unrestricted core imports
  • no root, shell or ambient filesystem access
  • no direct host output publication
  • host validation and atomic publication

Plugin classifications

Official
Published and signed by Kelibatmu under the official publisher identity.
Third-party
Published by an external publisher whose key is explicitly trusted.
Experimental
Not guaranteed stable and may change or be withdrawn.
Development
Local testing only; production policy rejects it.
Internal
Private organizational integration not distributed publicly.

First reference plugin

DEVELOPMENT

KFIF KPanel Connector
com.kelibatmu.kfif.kpanel-connector

Reference implementation only. Live KPanel migration remains deferred pending shadow parity and controlled validation.