Managing extensions
Only authorized administrators should add or change extensions.
Before enabling
Section titled “Before enabling”- Confirm the exact artifact, source, maintainer, license, notices, checksum or signature, and review record.
- Inspect requested data paths, permissions, network destinations, compute resources, and secrets.
- Validate the method scientifically with representative controls and known failure cases.
- Test failure, cancellation, restart, duplicate delivery, partial output, and upgrade behavior.
- Assign an operational owner, approved projects, resource limits, and review date.
During operation
Section titled “During operation”Monitor health, queue age, errors, resource use, network activity, output quality, and version drift. Pause an extension when its provenance, license, security, scientific behavior, or maintainer status becomes uncertain.
Updating or retiring
Section titled “Updating or retiring”Treat an update as a new artifact. Preserve the old version and workflow record long enough to reproduce prior results, then remove execution rights according to the facility retention policy.
The public catalog currently supplies metadata only; it does not supply installable binaries.