Facilities
Facilities
Facilities are how a host provides capabilities to a bolt. Workspace code reaches the database, storage, models, and durable tasks only through host-provided bindings — never direct credentials.
Facility ports
Bolt defines ten facility ports. A host implements the ones a workspace requires:
| Port | Provides |
|---|---|
database | the tenant Postgres database — required by every workspace |
files | object storage behind file() columns: read, write, delete, list |
ai | the model list and one model turn, for agents and api.infer |
communication | channel sends, inbound envelope verification, and per-person notification |
connector | named provider operations that integrations call |
tasks | durable work: register, enqueue, schedule, cancel, and signal |
hostTools | host-owned tools an agent may call |
transport | the connections the host holds — open, send, and publish to a topic |
identityHooks | identity lifecycle observations the host may project, never originate |
config | one host-supplied configuration key per read — the runtime only; tenant `+env.ts` values live in the tenant vault |
Notifications and secrets are not ports. They are runtime services backed by their own tables in the tenant database, so a host binds nothing for them.
Declaring requirements
Nobody hand-writes the requirement list. bolt sync compiles it into the artifact manifest as requiredFacilities , and activation checks that list against what the host actually bound: an unbound entry fails the bundle with missing_facility before any traffic reaches it. identityHooks is the one port that may stay unbound — it emits no-ops instead of failing.
Host bindings
Bindings are methods only — no data fields, no secrets. The rules:
- Workspace source declares requirements, never secret values.
- Client code cannot access private runtime facilities.
- A missing facility fails at boot, not at the first run.
Colony as a host
Colony binds all ten — Postgres pools, object storage, model APIs, channel delivery, provider connectors, durable tasks, sandboxed host tools, the stream a replica listens on, the identity projection behind the organization selector, and runtime configuration keys. See Colony platform for how the managed host wires them.