Documentation

How Kepler works.

Architecture, build instructions, the automation protocol, and how to report a vulnerability. Written for people who'd rather read the implementation.

01

Architecture

Kepler runs a small trusted broker and a fleet of untrusted workers. The broker owns the filesystem, the network socket and the GPU handle; nothing else does. A renderer that gets compromised can ask the broker for things, and the broker says no.

// process topology kepler-broker // trusted · Rust · owns fs, net, gpu ├─ kepler-net // tls, dns, relay routing, egress ledger ├─ kepler-store // per-origin partitioned storage ├─ renderer[origin] // sandboxed, one per origin, no syscalls └─ wasm-ext[id] // extensions, capability-gated

The storage partitioner keys every cookie jar, cache entry and IndexedDB database on the top-level origin, not the requesting one. That single decision is what kills cross-site tracking rather than merely inconveniencing it.

02

Build from source

You need Rust 1.78 or newer, a C++17 toolchain, and roughly 6 GB of disk. The --locked flag is not optional for a reproducible build.

git clone https://example.invalid/kepler.git cd kepler rustup toolchain install 1.78.0 cargo build --release --locked --features reproduce # the binary lands here ./target/release/kepler --version

To serve this website together with the signed release manifest, run the small release server that lives in server/:

cargo run -p kepler-releases -- --serve 8080 --root ./site

03

Automation protocol

Kepler speaks a CDP-compatible protocol over a plain WebSocket. Start it with --remote-port and point any existing tooling at it. The additions Kepler makes are namespaced under Kepler.* so nothing else breaks.

MethodReturnsNotes
Kepler.egressRequest ledgerEvery outbound connection for the tab, with timings.
Kepler.burnvoidDestroys the tab's partition and its process.
Kepler.relaysHop listCurrent relay path; settable per profile.
Kepler.fingerprintProfile digestWhat the page would see if it probed you.
Kepler.attestBuild infoCommit, toolchain, and the digest of the running binary.

04

Profiles

A profile is a directory. There's no opaque database, no lock file that survives a crash, and nothing you can't inspect with a text editor. Copy one to clone a session; delete one to make it never have happened.

~/.config/kepler/profiles/throwaway/ profile.toml # relays, fingerprint mode, permissions origins/ # one partition per top-level origin extensions/ # wasm modules + capability manifests ledger.jsonl # append-only egress log

05

Changelog

VersionDateChanges
0.9.02026-09-22Public beta. Egress ledger, relay switching, reproducible release pipeline.
0.8.42026-08-30Storage partitioner rewritten in Rust; cross-origin cache probes closed.
0.8.02026-07-11WASM extension runtime with per-permission capability manifests.
0.7.22026-06-02Fingerprint flattening for canvas, audio and font enumeration.

06

Security disclosure

Report vulnerabilities privately first. We acknowledge within 72 hours, ship a fix or a mitigation within 90 days, and publish the advisory with credit unless you'd rather we didn't.

  • Sandbox escapes and partition bypasses are treated as critical.
  • Anything that de-anonymises a relay session is critical.
  • Self-XSS, clickjacking on unauthenticated pages and missing headers on static docs are out of scope.
security@kepler.invalid — PGP: 9F2C 4A11 8E70 D3B5