Ops and the projector
The single venue process, its actors and the read model used by the web app.
services/ops/src/main.ts starts the venue's long-running actors. They share ledger sessions, feeds and cash shards in one process. Each logical action uses a stable command id so retries can recover the same outcome.
| Actor | Responsibility |
|---|---|
| Window roller | Opens Windows from their Series and session policy. |
| Oracle and lane feeders | Fetch boundary prices, archive payloads and post PriceQuote contracts as oracle parties. |
| Resolver | Records opens, then resolves or voids with the frozen terms. |
| Pricer | Publishes the venue ladder. It does not write to the ledger. |
| Quote issuer | Creates firm Quote and BuyQuote contracts through signed internal routes. |
| Sweeper, rebalancer, netting | Expire offers, manage cash shards and merge compatible venue legs. |
| Settler | Pays resolved legs with Desk_SettleBatch. |
| Seat funding and drain | Credit new leases, clean released parties and wait until reuse is safe. |
| Ticket desk | Issue and settle Range, Moonshot, Parlay and Boost contracts. |
| Agents venue | Enrol bounded grants and handle strategy contracts and creator payouts. |
| Arena and game-room | Deal, match, score and settle duel play. |
| Reserve reporter | Reports held funds against obligations. Historical maker/Earn machinery remains in source; Earn is absent from public navigation. |
The default actor set also includes HTTP, halt-watch, earnings and push-clock. Strategy and X runners require explicit selection or all. Desk runner and Canton Coin rail require explicit opt-in. An actor's presence in source is not evidence that the hosted process selected or successfully ran it.
The projector
The projector follows the venue party's ledger updates at /v2/updates. It writes derived Windows, prices, quotes, legs, resolutions, receipts and games into Postgres. Web index routes read that projection. The projector does not submit ledger commands.
The projection stores its cursor with the rows it covers. It can replay from offset 0, or bootstrap from active contracts when earlier participant history has been pruned. In the second case it records history_from_offset; a rebuild cannot recover history the participant no longer serves.
Per-seat reads and receipts are scoped to the current lease and its start offset. Public profiles and leaderboards use opt-in publications. Projection tables contain the venue's counterparty view, so web access control remains necessary.
Failure and recovery
An actor that fails to start exits the process with code 78. A watchdog exits if a pass stays stuck; the deployment supervisor is expected to restart it. Actors then reconcile against ledger state.
When ops is unavailable, new Windows, quotes, resolution and settlement can stop. Existing ledger contracts still apply. From a leg's refund time its owner can use Leg_RefundStale without an ops actor; the web and participant must remain reachable to submit it.
Use Status for current service readings. See Deployment for the one-writer rule, and signed prints for voids and delays.