3EOS Genesis sits above your hardened Linux hosts and reads the truth straight from systemd, cgroup v2,
and /proc. It gives every workload a stable 3e://family/component identity,
tracks declared vs. observed vs. enforced policy, and appends every observation to a tamper-evident,
hash-chained evidence ledger. No agent to trust blindly. No number it can't show its work for.
Genesis v0.1 is deliberately narrow. It does not replace your OS, does not enforce anything on production workloads, and never guesses a value it hasn't actually observed.
Genesis reads real system state through systemd, cgroup v2, and /proc. It never starts, stops, or reconfigures a production unit.
Every governed workload gets a 3e://family/component URI — because a PID is not an identity.
Every observation is appended to a SHA-256 hash-chained ledger. Nothing is ever edited in place; tampering is detectable.
DECLARED, OBSERVED, and 3EOS-ENFORCED are kept structurally separate — a declared limit is never presented as an enforced one.
Questions about 3EOS Genesis or access requests — this goes straight to the operator.