Published in openvibe-contracts v0.107.0 (docs/adr/ADR-045-node-universal-runtime.md), rendered as is.

ADR-045: The Node is OpenVibe's universal runtime

Status: Proposed 2026-10-05 (plan §8: *"ADR-045 (Node; revise: Node is the universal runtime, not a Bot/Actor helper)"*; plan T14, lines 575–579). For the owner's review. Builds on ADR-043 (Bot — devices, pairing, control and safety), ADR-046 §5 (the worker:<class> capability names) and ADR-048 (OVRN and authority boundaries). ADR-043 stays the robot/device half of the same Node; this record is the runtime half, and amends ADR-043's credential paragraph: Network owns the node/device principal and the pairing credential, Bot keeps the robot binding and control link.

Context and current evidence

Decision

1. One Node, the universal runtime

The Node is OpenVibe's universal runtime — one agent for a person's computers, servers, Raspberry Pis, phones and robots. It is not a Bot helper or an Actor helper: Bot, Actor, Run and Media are all clients of the same Node, and each binds the capabilities it needs. ADR-043 remains the robot/device half (robots, robot profiles, operators, command leases and physical safety); this ADR is the runtime half. The one split this record draws inside ADR-043 is the credential: Network owns the node/device principal and issues the pairing credential; Bot keeps the robot binding and the control link. That amends ADR-043's credential paragraph (its decisions 1-2); the rest of ADR-043 stands.

2. One release binary, one pairing, one control link, one local policy

3. Execution worker (Run's need)

4. Computer control (Actor's need, T17)

5. Cache/storage/delivery (Media's need, T4)

6. Local policy always overrides cloud commands

Alternatives considered

Consequences

Open questions for the owner

  1. Control levels. Whether the set is exactly Observe / Ask / Trusted / Full control, how each maps to a local indicator and to recording, and the capability names they use, is plan wording; the contract is open.
  2. One principal or many. Whether a Node serving several products/projects is one Network principal with scoped grants or one principal per project is Network's decision and is open (ADR-048 OVRN).
  3. Cache/storage contracts. Which offer contracts carry the Node's cache/storage role — the existing platform.storage-offer@1 / platform.delivery-offer@1 or a Node-specific one — and whether placement policy stays Media's, is open.
  4. Other users' workloads. Whether a Node may run other users' jobs or serve other users' computer control, or only its owner's, mirrors ADR-046's user-owned question and is open.

What this ADR does not claim