Skip to content

Managing extensions

Only authorized administrators should add or change extensions.

  1. Confirm the exact artifact, source, maintainer, license, notices, checksum or signature, and review record.
  2. Inspect requested data paths, permissions, network destinations, compute resources, and secrets.
  3. Validate the method scientifically with representative controls and known failure cases.
  4. Test failure, cancellation, restart, duplicate delivery, partial output, and upgrade behavior.
  5. Assign an operational owner, approved projects, resource limits, and review date.

Monitor health, queue age, errors, resource use, network activity, output quality, and version drift. Pause an extension when its provenance, license, security, scientific behavior, or maintainer status becomes uncertain.

Treat an update as a new artifact. Preserve the old version and workflow record long enough to reproduce prior results, then remove execution rights according to the facility retention policy.

The public catalog currently supplies metadata only; it does not supply installable binaries.