Groundskeeper
Architecture decisions

ADR 0005: Detector extension model

  • Status: Accepted
  • Date: 2026-10-03

Context

Initial checks need low latency and simple operations, while future detectors may use Python, GPUs, remote services, or untrusted portable code. Go native plugins share host privileges and are brittle across toolchains and platforms.

Decision

Start with compile-time Go built-ins behind one semantic detector contract. Add a supervised protobuf/gRPC subprocess adapter, then remote gRPC where justified, then WASM/wazero after its minimal ABI is validated. Never make Go .so plugins the public extension mechanism. Run the same conformance suite for every mode.

Consequences

  • V1 stays operationally simple without closing future extension paths.
  • Subprocess isolation is not called a security sandbox; OS/container controls are still required.
  • Remote execution requires explicit data destination policy, identity, mTLS, deadlines, and circuit breaking.
  • WASM capability access is denied by default and separately authorised.

On this page